| Wed, 04 Nov 2020 14:18:48 +0000 |
Roy Marples |
Add --noconfigure option
draft
|
| Fri, 30 Oct 2020 03:43:51 +0000 |
Roy Marples |
privsep: Send all log messages to the privileged actioneer
draft
|
| Sun, 11 Oct 2020 08:47:31 +0100 |
Roy Marples |
privsep: Minor correction to prior logic
draft
|
| Sat, 10 Oct 2020 17:54:03 +0100 |
Roy Marples |
privsep: We need to ensure stderr is valid before testing if tty
draft
|
| Sat, 10 Oct 2020 15:07:38 +0100 |
Roy Marples |
privsep: Fix stderr redirection again
draft
|
| Wed, 07 Oct 2020 15:28:33 +0100 |
Roy Marples |
privsep: Only start network proxy if we need to
draft
|
| Wed, 07 Oct 2020 14:37:35 +0100 |
Roy Marples |
privsep: Only log chrooting from the launcher process
draft
|
| Sat, 03 Oct 2020 17:17:45 +0100 |
Roy Marples |
Don't log backticks.
draft
|
| Sat, 03 Oct 2020 17:00:56 +0100 |
Roy Marples |
privsep: We need getsockopt as well as setsockopt on the link socket
draft
|
| Fri, 02 Oct 2020 15:57:01 +0100 |
Roy Marples |
privsep: allow CAP_SETSOCKOPT for route(4) fd.
draft
|
| Mon, 21 Sep 2020 17:40:28 +0100 |
Roy Marples |
privsep: Don't log sandbox type twice
draft
|
| Sun, 20 Sep 2020 19:09:08 +0100 |
Roy Marples |
privsep: sandbox the launcher process
draft
|
| Sun, 20 Sep 2020 00:43:36 +0100 |
Roy Marples |
privsep: Don't be noisy about the sandbox
draft
|
| Sun, 20 Sep 2020 00:35:08 +0100 |
Roy Marples |
privsep: Log if the platform sandbox is unavailable or available
draft
|
| Sat, 19 Sep 2020 20:53:23 +0100 |
Roy Marples |
privsep: Add the SECCOMP BPF sandbox for Linux
draft
|
| Sat, 19 Sep 2020 18:58:52 +0100 |
Roy Marples |
privsep: Fold capsicum and pledge entry points into ps_entersandbox
draft
|
| Sat, 12 Sep 2020 20:14:47 +0100 |
Roy Marples |
dhcpcd: Only manipulate stdin, stdout and stderr when valid
draft
|
| Sun, 06 Sep 2020 13:53:08 +0100 |
Roy Marples |
privsep: dump leases in a sandbox
draft
|
| Sun, 06 Sep 2020 12:20:40 +0100 |
Roy Marples |
privsep: Dump leases from stdin in a limited sandbox
draft
|
| Sun, 06 Sep 2020 11:58:29 +0100 |
Roy Marples |
privsep: dropprivs can be static
draft
|
| Sun, 06 Sep 2020 11:57:19 +0100 |
Roy Marples |
privsep: limit rights for stdout/stderr/stdin using capsicum
draft
|
| Sun, 06 Sep 2020 02:41:08 +0100 |
Roy Marples |
dhcpcd: Redirect stdout/stderr to the launcher stderr descriptor
draft
|
| Sat, 05 Sep 2020 17:01:59 +0100 |
Roy Marples |
privsep: Fix prior for FreeBSD.
draft
|
| Sat, 05 Sep 2020 16:12:30 +0100 |
Roy Marples |
privsep: Use xsocketpair
draft
|
| Thu, 20 Aug 2020 16:28:47 +0100 |
Roy Marples |
privsep: Only the master process accepts signals
draft
|
| Sat, 08 Aug 2020 20:27:34 +0100 |
Roy Marples |
privsep: Improve some errors
draft
|
| Wed, 01 Jul 2020 11:45:06 +0100 |
Roy Marples |
privsep: Don't limit file writes if logging to a file
draft
|
| Mon, 29 Jun 2020 13:14:21 +0100 |
Roy Marples |
privsep: check return of freopen(3)
draft
|
| Mon, 15 Jun 2020 15:14:53 +0100 |
Roy Marples |
privsep: don't abort if setrlimit fails
draft
|
| Wed, 10 Jun 2020 16:32:04 +0100 |
Roy Marples |
privsep: Fix a shutdown race
draft
|
| Wed, 10 Jun 2020 08:30:28 +0100 |
Roy Marples |
privsep: RLIMIT_FSIZE works fine on pledge and capsicum
draft
|
| Wed, 10 Jun 2020 07:04:29 +0100 |
Roy Marples |
privsep: Disable RLIMIT_FSIZE when using the logfile option
draft
|
| Wed, 10 Jun 2020 05:46:19 +0100 |
Roy Marples |
privsep: Apply resource limits to OpenBSD as well where we can
draft
|
| Wed, 10 Jun 2020 05:27:25 +0100 |
Roy Marples |
privsep: Apply what resource limits we can to capsicum
draft
|
| Wed, 10 Jun 2020 04:57:02 +0100 |
Roy Marples |
privsep: control proxy is no longer optional
draft
|
| Tue, 09 Jun 2020 22:39:05 +0100 |
Roy Marples |
privsep: For Linux and Solaris, set RLIMIT_NOFILES to nevents
draft
|
| Tue, 09 Jun 2020 18:25:18 +0100 |
Roy Marples |
privsep: Implement a resource limited sandbox
draft
|
| Fri, 05 Jun 2020 20:24:21 +0100 |
Roy Marples |
privsep: Limit rights generically rather than Capsicum specifc
draft
|
| Fri, 05 Jun 2020 14:12:23 +0100 |
Roy Marples |
Linux: make resource limits work by using getifaddrs over privsep
draft
|
| Fri, 05 Jun 2020 13:51:51 +0100 |
Roy Marples |
Linux: resource limits don't easily work here either....
draft
|
| Fri, 05 Jun 2020 13:15:51 +0100 |
Roy Marples |
FreeBSD: Fix prior for capsicum as well.
draft
|
| Fri, 05 Jun 2020 13:02:32 +0100 |
Roy Marples |
OpenBSD: disable setting resource limits as we have pledge.
draft
|
| Fri, 05 Jun 2020 12:24:44 +0100 |
Roy Marples |
privsep: Set resource limits when dropping privs
draft
|
| Thu, 04 Jun 2020 12:36:10 +0100 |
Roy Marples |
privsep: Remove this error masking as well.
draft
|
| Thu, 04 Jun 2020 12:22:40 +0100 |
Roy Marples |
privsep: Set buffer sizes before setting rights.
draft
|
| Thu, 04 Jun 2020 12:15:20 +0100 |
Roy Marples |
privsep: Don't wait for the process to finish when stopping it
draft
|
| Wed, 03 Jun 2020 23:30:08 +0100 |
Roy Marples |
eloop: Just use ppoll(2)
draft
|
| Tue, 02 Jun 2020 15:50:17 +0100 |
Roy Marples |
privsep: harden process handling
draft
|
| Mon, 01 Jun 2020 15:33:05 +0100 |
Roy Marples |
privsep: Double the size of the send buffer.
draft
|
| Mon, 01 Jun 2020 15:03:46 +0100 |
Roy Marples |
privsep: Ensure socketpair IPC buffers are large enough.
draft
|
| Sat, 30 May 2020 10:36:20 +0000 |
Roy Marples |
Fix some Coverity isues
draft
|
| Sun, 24 May 2020 14:38:06 +0000 |
Roy Marples |
privsep: root and inet don't need arc4random
draft
|
| Sun, 24 May 2020 12:23:20 +0000 |
Roy Marples |
privsep: Init the arc4random seed before chrooting
draft
|
| Sun, 24 May 2020 11:49:58 +0100 |
Roy Marples |
privsep: Fix compile for prior without dev plugins
draft
|
| Sun, 24 May 2020 10:30:23 +0000 |
Roy Marples |
privsep: Allow dev plugins to work
draft
|
| Wed, 20 May 2020 21:43:20 +0100 |
Roy Marples |
privsep: Log the user chrooting as
draft
|
| Tue, 19 May 2020 16:09:35 +0000 |
Roy Marples |
Fix compile on Linux
draft
|
| Tue, 19 May 2020 16:19:05 +0100 |
Roy Marples |
privsep: Enable Capsicum for all processes.
draft
|
| Fri, 15 May 2020 20:23:55 +0100 |
Roy Marples |
BPF: Set write filters where supported
draft
|
| Wed, 13 May 2020 20:52:24 +0100 |
Roy Marples |
privsep: Add a generic wrapper for getifaddrs(3)
draft
|