<feed xmlns='http://www.w3.org/2005/Atom'>
<title>hakurei/container/container.go, branch v0.4.0</title>
<subtitle>low-level userspace tooling for Rosa OS</subtitle>
<id>http://src.rosa.moe/hakurei/atom/container/container.go?h=v0.4.0</id>
<link rel='self' href='http://src.rosa.moe/hakurei/atom/container/container.go?h=v0.4.0'/>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/'/>
<updated>2026-04-10T14:56:45Z</updated>
<entry>
<title>internal/landlock: relocate from package container</title>
<updated>2026-04-10T14:56:45Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2026-04-10T14:56:45Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=b39064037625d1757a65913086ec3a247ad5bb29'/>
<id>urn:sha1:b39064037625d1757a65913086ec3a247ad5bb29</id>
<content type='text'>
This is not possible to use directly, so remove it from the public API.

Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
<entry>
<title>container: unexport PR_SET_NO_NEW_PRIVS wrapper</title>
<updated>2026-04-10T14:45:51Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2026-04-10T14:45:51Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=ad2c9f36cddfd8adcd06fbe9238d176a8eb89614'/>
<id>urn:sha1:ad2c9f36cddfd8adcd06fbe9238d176a8eb89614</id>
<content type='text'>
This is subtle to use correctly. It also does not make sense as part of the container API.

Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
<entry>
<title>container: do not set static deadline</title>
<updated>2026-04-07T08:00:20Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2026-04-07T07:50:33Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=0558032c2d6b467b4807e69db74e24c5577c34bc'/>
<id>urn:sha1:0558032c2d6b467b4807e69db74e24c5577c34bc</id>
<content type='text'>
This usually ends up in the buffer, or completes well before the deadline, however this can still timeout on a very slow system.

Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
<entry>
<title>container: remove setup pipe helper</title>
<updated>2026-04-07T07:05:33Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2026-04-07T06:50:59Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=062edb3487c1cc116cae78bf77420b65c43517d1'/>
<id>urn:sha1:062edb3487c1cc116cae78bf77420b65c43517d1</id>
<content type='text'>
The API forces use of finalizer to close the read end of the setup pipe, which is no longer considered acceptable. Exporting this as part of package container also imposes unnecessary maintenance burden.

Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
<entry>
<title>container: skip landlock on hostnet</title>
<updated>2026-04-07T05:36:44Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2026-04-07T05:36:44Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=c758e762bd0334b6f86fbc41ab3223b9115e9982'/>
<id>urn:sha1:c758e762bd0334b6f86fbc41ab3223b9115e9982</id>
<content type='text'>
This overlaps with net namespace, so can be skipped without degrading security.

Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
<entry>
<title>fhs: move from container</title>
<updated>2026-03-17T06:56:36Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2026-03-17T06:56:36Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=722989c68256469963aee963bed9c6ab4bf55b67'/>
<id>urn:sha1:722989c68256469963aee963bed9c6ab4bf55b67</id>
<content type='text'>
This package is not container-specific.

Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
<entry>
<title>check: move from container</title>
<updated>2026-03-17T06:39:03Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2026-03-17T06:35:58Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=6d015a949e27f20c86409c7d78053f0b0493f165'/>
<id>urn:sha1:6d015a949e27f20c86409c7d78053f0b0493f165</id>
<content type='text'>
This package is not container specific, and widely used across the project.

Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
<entry>
<title>container: set CLOEXEC via close_range</title>
<updated>2026-03-17T05:19:00Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2026-03-17T05:19:00Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=0a12d456ce5869042dc06c43c360c43cab942d6b'/>
<id>urn:sha1:0a12d456ce5869042dc06c43c360c43cab942d6b</id>
<content type='text'>
This is guarded behind the close_range build tag for now.

Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
<entry>
<title>ext: isolate from container/std</title>
<updated>2026-03-17T04:39:26Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2026-03-17T04:35:48Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=cd5959fe5ab04786cd5dee3cf09f725229ae7c7b'/>
<id>urn:sha1:cd5959fe5ab04786cd5dee3cf09f725229ae7c7b</id>
<content type='text'>
These are too general to belong in the container package. This targets the v0.4 release to reduce the wrapper maintenance burden.

Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
<entry>
<title>container: expose priority and SCHED_OTHER policy</title>
<updated>2026-03-11T16:14:03Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2026-03-11T16:14:03Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=196b200d0f19c41730db439c62db9b39e424f21f'/>
<id>urn:sha1:196b200d0f19c41730db439c62db9b39e424f21f</id>
<content type='text'>
The more explicit API removes the arbitrary limit preventing use of SCHED_OTHER (referred to as SCHED_NORMAL in the kernel). This change also exposes priority value to set.

Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
</feed>
