aboutsummaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAge
* added -g3 to default CFLAGS and some safe I/O syscalls to prevent SECCOMP ↵HEADmasterToni Uhlig2020-07-12
| | | | | | filtering Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
* fixed superfluous loop iterationToni Uhlig2020-07-09
| | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
* using official archlinux/base imageToni Uhlig2020-07-01
| | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
* force non-zero via setuid/setgidToni Uhlig2020-06-27
| | | | | | * added TODO for root user mapping (if someone logged in as root) Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
* welcome ASAN, LSAN and UBSANToni Uhlig2020-06-24
| | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
* added new libssh pre processor check for libssh versions >0.7.xlns2019-09-08
|
* fixed buffering issue for pkt_writeToni Uhlig2019-07-27
| | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
* event buffer valgrind memcheck supportToni Uhlig2019-07-23
| | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
* pevent documentation/ print warning on i/o buffer bloatToni Uhlig2019-07-20
| | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
* added Gitlab pipeline badgeToni Uhlig2019-07-16
| | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
* gitlab-ci: apt-get purge --allow-remove-essentialToni Uhlig2019-07-16
| | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
* do not try to link against an invalid sonameToni Uhlig2019-07-16
| | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
* added shell access check during selftestlns2019-03-16
| | | | Signed-off-by: lns <matzeton@googlemail.com>
* added --rootfs note in READMEslns2019-03-14
| | | | Signed-off-by: lns <matzeton@googlemail.com>
* gitlab-ci: install archlinux-keyringToni Uhlig2019-02-07
| | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
* gitlab-ci: switched to a working ArchLinux imageToni Uhlig2019-02-07
| | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
* Revert "gitlab-ci: removed ArchLinux non-seccomp build (systemd requires ↵Toni Uhlig2019-02-07
| | | | | | libseccomp)" This reverts commit 89608534f80c1d308e21af5af91300bf6762df56.
* gitlab-ci: removed ArchLinux non-seccomp build (systemd requires libseccomp)Toni Uhlig2019-02-07
| | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
* fixes merge related problems with branch feature/jail_packetlns2019-02-04
| | | | Signed-off-by: lns <matzeton@googlemail.com>
* Merge branch 'feature/jail_packet'lns2019-02-04
|\
| * Introduced the protocol->jail binary packet.feature/jail_packetlns2019-02-04
| | | | | | | | | | | | | | | | We are using a handler/callback functions to obtain additional information from the protocol handler and transmit it to the sandbox. Signed-off-by: lns <matzeton@googlemail.com>
| * event buffer fill/drainlns2018-08-22
| | | | | | | | Signed-off-by: lns <matzeton@googlemail.com>
| * basic jail packet parsing functionslns2018-08-13
| | | | | | | | Signed-off-by: lns <matzeton@googlemail.com>
| * setup basic jail packet structs/funcsToni Uhlig2018-08-11
| | | | | | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
* | x86/x86_64 require arch_prctl()lns2019-02-04
| | | | | | | | Signed-off-by: lns <matzeton@googlemail.com>
* | mount /proc readonly in sandboxToni Uhlig2019-01-24
| | | | | | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
* | adjusted allowed/disabled syscalls regarding OpenWrt compatibility, enable ↵Toni Uhlig2019-01-24
| | | | | | | | | | | | ptrace support for sandboxed apps (disabled by default), setsid/setpgrp during jail init Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
* | delegate/save errno in pevent forward_connectionToni Uhlig2019-01-24
| | | | | | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
* | pseccomp: allow old x32 chown32 syscall for default allowedToni Uhlig2019-01-22
| | | | | | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
* | Merge branch 'master' of github.com:lnslbrty/potdToni Uhlig2019-01-17
|\ \
| * | added potd sw arch image (copied from thesis paper)Toni Uhlig2018-11-21
| | | | | | | | | | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
| * | Update READMEdev02018-09-19
| | |
* | | Merge branch 'master' of ssh://git.lan:/git/potdToni Uhlig2019-01-17
|\ \ \
| * | | -ffunction-sections,-fdata-sections autoconf checklns2018-10-15
| |/ / | | | | | | | | | Signed-off-by: lns <matzeton@googlemail.com>
* / / SECCOMP: allow getdents for protocol/jailToni Uhlig2019-01-17
|/ / | | | | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
* | README.md ``` command blocklns2018-09-17
| | | | | | | | Signed-off-by: lns <matzeton@googlemail.com>
* | gitlab yaml installs git for git-version-genToni Uhlig2018-09-10
| | | | | | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
* | - use per target LIBS to skip linking other apps with superfluous libsToni Uhlig2018-09-10
| | | | | | | | | | | | - print ./configure (C|LD)FLAGS and LIBS Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
* | fake /sbin/init skeletonToni Uhlig2018-09-09
| | | | | | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
* | do not print an error if network namespace does not exist, which happens on ↵Toni Uhlig2018-08-30
| | | | | | | | | | | | purpose Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
* | enable SECCOMP text/bpf exportToni Uhlig2018-08-30
| | | | | | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
* | autogen.sh prints additional help messagelns2018-08-26
| | | | | | | | Signed-off-by: lns <matzeton@googlemail.com>
* | print usage if an invalid/missing config was detectedToni Uhlig2018-08-14
| | | | | | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
* | fixed some code style issues reported by codacyToni Uhlig2018-08-14
| | | | | | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
* | autogen.sh prints what to do nextToni Uhlig2018-08-13
| | | | | | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
* | log2syslogToni Uhlig2018-08-13
| | | | | | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
* | libssl >= 1.0.1f should be supported since it is supported by libssh == 0.7.5Toni Uhlig2018-08-11
| | | | | | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
* | improved xcompile dependency checkingToni Uhlig2018-08-11
| | | | | | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
* | Revert "check for host_tuple-pkg-config first and use system pkg-config as ↵Toni Uhlig2018-08-11
| | | | | | | | | | | | fallback" This reverts commit c201661484f668ecd7de0d05a2a6e4baf74d0e2c.
* | check for host_tuple-pkg-config first and use system pkg-config as fallbackToni Uhlig2018-08-11
|/ | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com>