~alip/sydbox

79d141b1 — Ⓐlï P☮lⒶtel 8 months ago main
tests: fix newfstatat deleted file reproducer

References: #4
Signed-off-by: Ⓐlï P☮lⒶtel <alip@exherbo.org>
3ca43e94 — Ⓐlï P☮lⒶtel 8 months ago
autotools: update addr.db source address

Signed-off-by: Ⓐlï P☮lⒶtel <alip@exherbo.org>
5d5cd9e3 — Ⓐlï P☮lⒶtel 8 months ago
tests: mark known failures in core abort tests

Signed-off-by: Ⓐlï P☮lⒶtel <alip@exherbo.org>
2dfcd76c — Ⓐlï P☮lⒶtel 8 months ago
sydbox: add test case to reproduce newfstatat on deleted file with AT_SYMLINK_NOFOLLOW issue

References: #4
Signed-off-by: Ⓐlï P☮lⒶtel <alip@exherbo.org>
1e20517d — Ⓐlï P☮latel 9 months ago
git: update gitignore

Signed-off-by: Ⓐlï P☮latel <alip@exherbo.org>
b0a607ee — Ⓐlï P☮latel 9 months ago
syd: do not needlessly deref pointers more than once in bsearch compare function

Signed-off-by: Ⓐlï P☮latel <alip@exherbo.org>
751539be — Ⓐlï P☮latel 9 months ago
addr: sort addresses by id before writing into the generated header file

Signed-off-by: Ⓐlï P☮latel <alip@exherbo.org>
18a80876 — Ⓐlï P☮latel 9 months ago
addr: implement syd addr to maintain the hblock ip address database

Signed-off-by: Ⓐlï P☮latel <alip@exherbo.org>
0a635f5e — Ⓐlï P☮latel 9 months ago
Merge branch 'hblock'

I hope this becomes a nice colloboration.
Thank you for the great software!
0dfe2225 — Ⓐlï P☮latel 9 months ago
hblock: move to hblock/

Signed-off-by: Ⓐlï P☮latel <alip@exherbo.org>
69b5f7af — Ⓐlï P☮latel 9 months ago
syd: time connect binary search in debug mode

Signed-off-by: Ⓐlï P☮latel <alip@exherbo.org>
fa0bdf95 — Ⓐlï P☮latel 10 months ago
syd: fix connect default denylist binary search

Signed-off-by: Ⓐlï P☮latel <alip@exherbo.org>
6698194c — Ⓐlï P☮latel 10 months ago
tests: mark known failures

Signed-off-by: Ⓐlï P☮latel <alip@exherbo.org>
67dfdcbe — Ⓐlï P☮latel 10 months ago
tests: fix core seccomp tests broken by new allow -> log change

Signed-off-by: Ⓐlï P☮latel <alip@exherbo.org>
93696a49 — Ⓐlï P☮latel 10 months ago
syd: further tweak signal handling

Signed-off-by: Ⓐlï P☮latel <alip@exherbo.org>
387e928c — Ⓐlï P☮latel 10 months ago
syd: further tweak seccomp, use log as default action, deny specific system calls such as ptrace, process_vm_{read,write}v with kill

Signed-off-by: Ⓐlï P☮latel <alip@exherbo.org>
63811356 — Ⓐlï P☮latel 10 months ago
syd: default seccomp mode is now deny, we pass through a list of allowed system calls, the rest is denied with EOWNERDEAD

Signed-off-by: Ⓐlï P☮latel <alip@exherbo.org>
111777d6 — Ⓐlï P☮latel 10 months ago
autotools: add missing check for close_range function

Signed-off-by: Ⓐlï P☮latel <alip@exherbo.org>
70a9d87d — Ⓐlï P☮latel 10 months ago
syd: use STDERR_FILENO rather than hardcoding 2

Signed-off-by: Ⓐlï P☮latel <alip@exherbo.org>
e951fbfe — Ⓐlï P☮latel 10 months ago
syd: fix yet another signal handling bug

This prevents a hang on double SIGCHILD on exit.

Signed-off-by: Ⓐlï P☮latel <alip@exherbo.org>
Next