Albert S. crtxcr
crtxcr hizo push a WIP/sandboxing en crtxcr/looqs 2021-12-26 19:44:44 +01:00
79c2731216 gui: Add pledge_promises to exile policy
crtxcr hizo push a WIP/argsfilter en crtxcr/exile.h 2021-12-26 19:40:58 +01:00
beeae95fe1 pledge: Add EXILE_SYSCALL_PLEDGE_IOCTL() to not filter ioctl()
crtxcr hizo push a WIP/argsfilter en crtxcr/exile.h 2021-12-26 19:34:19 +01:00
27d560c6af pledge: add prctl() default filter
crtxcr hizo push a WIP/sandboxing en crtxcr/looqs 2021-12-26 18:36:03 +01:00
6a41877a0c IpcServer: Fix off-by-one
b10093f907 Switch to exile.h
86b843e434 shared: looksquery: Fix incorrect varname in exception
Comparar 3 commits »
crtxcr hizo push a WIP/argsfilter en crtxcr/exile.h 2021-12-26 18:16:06 +01:00
d742397b52 Introduce clone filter and EXILE_SYSCALL_PLEDGE_THREAD
crtxcr hizo push a WIP/argsfilter en crtxcr/exile.h 2021-12-26 17:58:07 +01:00
45f5f16bb8 Introduce clone filter and EXILE_SYSCALL_PLEDGE_THREAD
crtxcr creó rama next en crtxcr/exile.h 2021-12-24 16:25:04 +01:00
crtxcr hizo push a next en crtxcr/exile.h 2021-12-24 16:25:04 +01:00
crtxcr hizo push a WIP/argsfilter en crtxcr/exile.h 2021-12-24 16:22:27 +01:00
34b58c5b32 Add EXILE_FS_ALLOW_ALL_{READ,WRITE}
7131b15d1f pledge: Begin filter for setsockopt() args
c61ad47817 pledge: Add PROT_EXEC
Comparar 3 commits »
crtxcr hizo push a WIP/argsfilter en crtxcr/exile.h 2021-12-24 16:21:59 +01:00
9a95ad0c6a Add EXILE_FS_ALLOW_ALL_{READ,WRITE}
9d1b62b249 pledge: Begin filter for setsockopt() args
Comparar 2 commits »
crtxcr creó rama WIP/readme en crtxcr/exile.h 2021-12-21 19:31:46 +01:00
crtxcr hizo push a WIP/readme en crtxcr/exile.h 2021-12-21 19:31:46 +01:00
d44ae8e74e fixup! Update README
be78f6a1c0 Update README
c41eb21ff6 Remove sys/capability.h inclusion, we only need linux/capability.h
Comparar 3 commits »
crtxcr hizo push a WIP/argsfilter en crtxcr/exile.h 2021-12-20 20:25:43 +01:00
bf0d6f9b8d fixup! pledge: Add PROT_EXEC
d502676ab7 pledge: Add PROT_EXEC
Comparar 2 commits »
crtxcr hizo push a WIP/argsfilter en crtxcr/exile.h 2021-12-20 17:30:48 +01:00
c7991ceefa Introduce EXILE_SYSCALL_PLEDGE_DENY_ERROR, remove exile_policy->pledge_policy
5c8de3d286 test: Add pledge socket test
28fc84e323 pledge: Begin EXILE_SYSCALL_PLEDGE_UNIX/EXILE_SYSCALL_PLEDGE_INET
70c831e142 test: Begin basic pledge test
9a356a9e71 Begin an pledge()-like implementation
Comparar 5 commits »
crtxcr hizo push a WIP/argsfilter en crtxcr/exile.h 2021-12-20 16:16:05 +01:00
eca3b3d622 test: Add pledge socket test
crtxcr hizo push a WIP/argsfilter en crtxcr/exile.h 2021-12-20 16:15:34 +01:00
fa473601d3 test: Add socket test
a068c3b0e3 pledge: Begin EXILE_SYSCALL_PLEDGE_UNIX/EXILE_SYSCALL_PLEDGE_INET
d3ebc6cabf fixup! Begin an pledge()-like implementation
Comparar 3 commits »
crtxcr hizo push a WIP/argsfilter en crtxcr/exile.h 2021-12-19 21:16:10 +01:00
656f43ee7a fixup! test: Begin basic pledge test
ccf940b476 fixup! Begin an pledge()-like implementation
ecb064158d test: Begin basic pledge test
3cd253a309 fixup! Begin an pledge()-like implementation
Comparar 4 commits »
crtxcr hizo push a WIP/argsfilter en crtxcr/exile.h 2021-12-19 20:27:12 +01:00
08a2445c26 fixup! Begin an pledge()-like implementation
e172c74a96 Retire syscall groups, will be replaced by superior pledge-like functionality
30a265d636 Begin an pledge()-like implementation
4dc67a5fa7 Begin low-level seccomp arg filter interface
Comparar 4 commits »
crtxcr hizo push a WIP/argsfilter en crtxcr/exile.h 2021-12-12 11:51:04 +01:00
7bfa7f5961 Begin EXILE_SYSCALL_PLEDGE_STDIO
43ad418932 append_syscall_to_bpf(): Introduce EXILE_SYSCALL_EXIT_BPF_RETURN
274372f78e pledge: add ioctl default args filter
Comparar 3 commits »
crtxcr hizo push a WIP/argsfilter en crtxcr/exile.h 2021-12-05 17:29:01 +01:00
6b70e33b8f Begin an pledge()-like implementation
a03c87732e append_syscall_to_bpf(): Apply EXILE_SYSCALL_EXIT_BPF_NO_MATCH also for sock_filter.jt
633c352608 Retire struct exile_syscall_arg_filter
Comparar 3 commits »