WIP pledge/low-level seccomp arg filter interface #22

已关闭
crtxcr 请求将 0 次代码提交从 WIP/argsfilter 合并至 master
所有者
没有提供说明。
crtxcr2021-11-30 18:33:22 +01:00 强制推送 WIP/argsfilter,从 89749bd03b371c6a94b6 比较
crtxcr2021-12-01 23:55:57 +01:00 强制推送 WIP/argsfilter,从 371c6a94b6ac3e84ed16 比较
作者
所有者

Test for blacklist:

  • syscall without args
  • syscall with args
  • syscall without args
Test for blacklist: - syscall without args - syscall with args - syscall without args
crtxcr2021-12-05 17:32:21 +01:00 修改标题 WIP low-level seccomp arg filter interfaceWIP pledge/low-level seccomp arg filter interface
crtxcr2021-12-19 20:27:13 +01:00 强制推送 WIP/argsfilter,从 7bfa7f596108a2445c26 比较
crtxcr2021-12-20 16:16:06 +01:00 强制推送 WIP/argsfilter,从 fa473601d3eca3b3d622 比较
crtxcr2021-12-20 17:30:51 +01:00 强制推送 WIP/argsfilter,从 eca3b3d622c7991ceefa 比较
crtxcr2021-12-24 16:22:28 +01:00 强制推送 WIP/argsfilter,从 9a95ad0c6a34b58c5b32 比较
crtxcr2021-12-26 18:16:07 +01:00 强制推送 WIP/argsfilter,从 45f5f16bb8d742397b52 比较
crtxcr2021-12-27 00:44:44 +01:00 强制推送 WIP/argsfilter,从 beeae95fe172ee3b3d74 比较
crtxcr2021-12-27 12:00:41 +01:00 强制推送 WIP/argsfilter,从 72ee3b3d74a7a9c6962a 比较
crtxcr2021-12-27 12:36:32 +01:00 强制推送 WIP/argsfilter,从 3e4ae74203ca0f82790c 比较
crtxcr2021-12-27 14:18:15 +01:00 推送 2 个提交
Some distros put sys/capability.h into libcap-dev or
similiar, which is a bit unforunate, we don't need
libcap-dev or anything like that.

Since we anyway only used the capget()/capset(), we can
just define a simple wrapper and call the syscall directly
and therefore avoid above mentioned issue.
crtxcr2021-12-27 14:26:47 +01:00 推送 1 个提交
crtxcr2021-12-27 17:03:42 +01:00 推送 1 个提交
We cannot assume that landlock is enabled if we can compile it.
Even if it's enabled in the kernel it may still not be loaded.

We fill fallback to chroot/bind-mounts if we can.

If we can't (because path policies have landlock-specific options),
we can't do that either.

Closes: #21
作者
所有者

Merged

Merged
crtxcr2021-12-27 17:14:56 +01:00 关闭此合并请求

合并请求已关闭

登录 并参与到对话中。
无评审人
1 名参与者
通知
截止日期
未设置截止日期。
依赖工单

未设置依赖工单。

引用:crtxcr/exile.h#22