<feed xmlns='http://www.w3.org/2005/Atom'>
<title>hakurei/sandbox/ops.go, branch develop</title>
<subtitle>low-level userspace tooling for Rosa OS</subtitle>
<id>http://src.rosa.moe/hakurei/atom/sandbox/ops.go?h=develop</id>
<link rel='self' href='http://src.rosa.moe/hakurei/atom/sandbox/ops.go?h=develop'/>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/'/>
<updated>2025-07-02T12:23:55Z</updated>
<entry>
<title>hakurei: move container toplevel</title>
<updated>2025-07-02T12:23:55Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2025-07-02T12:23:55Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=a1d98823f8d17b49b432508d071b62ccd426f1ce'/>
<id>urn:sha1:a1d98823f8d17b49b432508d071b62ccd426f1ce</id>
<content type='text'>
Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
<entry>
<title>sandbox: expose seccomp interface</title>
<updated>2025-07-01T19:47:13Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2025-07-01T19:38:28Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=31aef905fa819310ee7694775a836c294ff742e4'/>
<id>urn:sha1:31aef905fa819310ee7694775a836c294ff742e4</id>
<content type='text'>
There's no point in artificially limiting and abstracting away these options. The higher level hakurei package is responsible for providing a secure baseline and sane defaults. The sandbox package should present everything to the caller.

Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
<entry>
<title>sandbox/seccomp: import dot for syscall</title>
<updated>2025-07-01T17:30:35Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2025-07-01T17:30:35Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=a6887f7253ae822357f0d4d019675acc8c3e0b4d'/>
<id>urn:sha1:a6887f7253ae822357f0d4d019675acc8c3e0b4d</id>
<content type='text'>
This significantly increases readability in some places.

Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
<entry>
<title>sandbox/seccomp: append suffix to ops</title>
<updated>2025-07-01T16:09:04Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2025-07-01T16:09:04Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=69bd581af78909ce924b810da67979b57c5b5747'/>
<id>urn:sha1:69bd581af78909ce924b810da67979b57c5b5747</id>
<content type='text'>
This avoids clashes with stdlib names to allow for . imports.

Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
<entry>
<title>sandbox: relative autoetc links</title>
<updated>2025-04-11T09:54:00Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2025-04-11T09:54:00Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=996790946092a9291eb21e297d1f0f04deab8b42'/>
<id>urn:sha1:996790946092a9291eb21e297d1f0f04deab8b42</id>
<content type='text'>
This allows nested containers to use autoetc, and increases compatibility with other implementations.

Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
<entry>
<title>sandbox: implement autoetc as setup op</title>
<updated>2025-04-10T09:54:25Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2025-04-10T09:54:25Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=c806f43881223a85ad888f434e078dcc68de028d'/>
<id>urn:sha1:c806f43881223a85ad888f434e078dcc68de028d</id>
<content type='text'>
This significantly reduces setup op count and the readdir call now happens in the context of the init process.

Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
<entry>
<title>sandbox: document less obvious parts of setup</title>
<updated>2025-03-31T16:21:04Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2025-03-31T16:21:04Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=0ba8be659f0bb22065824190e2d872d869a2fe92'/>
<id>urn:sha1:0ba8be659f0bb22065824190e2d872d869a2fe92</id>
<content type='text'>
Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
</feed>
