<feed xmlns='http://www.w3.org/2005/Atom'>
<title>hakurei/sandbox, branch develop</title>
<subtitle>low-level userspace tooling for Rosa OS</subtitle>
<id>http://src.rosa.moe/hakurei/atom/sandbox?h=develop</id>
<link rel='self' href='http://src.rosa.moe/hakurei/atom/sandbox?h=develop'/>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/'/>
<updated>2025-07-02T12:52:07Z</updated>
<entry>
<title>system: move system access packages</title>
<updated>2025-07-02T12:52:07Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2025-07-02T12:52:07Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=82561d62b66f17c05604e87f18187bb3a91f00d2'/>
<id>urn:sha1:82561d62b66f17c05604e87f18187bb3a91f00d2</id>
<content type='text'>
These packages loosely belong in the "system" package and "system" provides high level wrappers for all of them.

Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
<entry>
<title>hakurei: move container helpers toplevel</title>
<updated>2025-07-02T12:31:29Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2025-07-02T12:31:29Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=eec021cc4b4eb42bc9c8311755826828bfba1996'/>
<id>urn:sha1:eec021cc4b4eb42bc9c8311755826828bfba1996</id>
<content type='text'>
Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
<entry>
<title>hakurei: move container toplevel</title>
<updated>2025-07-02T12:23:55Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2025-07-02T12:23:55Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=a1d98823f8d17b49b432508d071b62ccd426f1ce'/>
<id>urn:sha1:a1d98823f8d17b49b432508d071b62ccd426f1ce</id>
<content type='text'>
Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
<entry>
<title>sandbox/wl: track generated files</title>
<updated>2025-07-02T11:52:22Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2025-07-02T11:52:22Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=f84ec5a3f8d648031bc8e7c4baf6e31d67d2d5a4'/>
<id>urn:sha1:f84ec5a3f8d648031bc8e7c4baf6e31d67d2d5a4</id>
<content type='text'>
This allows the package to be imported.

Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
<entry>
<title>cmd/hakurei: move to cmd</title>
<updated>2025-07-02T11:42:51Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2025-07-02T11:42:51Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=eb22a8bcc1ac03357d4073e5d3ed6d0ab5246a37'/>
<id>urn:sha1:eb22a8bcc1ac03357d4073e5d3ed6d0ab5246a37</id>
<content type='text'>
Having it at the project root never made sense since the "ego" name was deprecated. This change finally addresses it.

Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
<entry>
<title>sandbox: expose seccomp interface</title>
<updated>2025-07-01T19:47:13Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2025-07-01T19:38:28Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=31aef905fa819310ee7694775a836c294ff742e4'/>
<id>urn:sha1:31aef905fa819310ee7694775a836c294ff742e4</id>
<content type='text'>
There's no point in artificially limiting and abstracting away these options. The higher level hakurei package is responsible for providing a secure baseline and sane defaults. The sandbox package should present everything to the caller.

Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
<entry>
<title>sandbox/seccomp: import dot for syscall</title>
<updated>2025-07-01T17:30:35Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2025-07-01T17:30:35Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=a6887f7253ae822357f0d4d019675acc8c3e0b4d'/>
<id>urn:sha1:a6887f7253ae822357f0d4d019675acc8c3e0b4d</id>
<content type='text'>
This significantly increases readability in some places.

Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
<entry>
<title>sandbox/seccomp: append suffix to ops</title>
<updated>2025-07-01T16:09:04Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2025-07-01T16:09:04Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=69bd581af78909ce924b810da67979b57c5b5747'/>
<id>urn:sha1:69bd581af78909ce924b810da67979b57c5b5747</id>
<content type='text'>
This avoids clashes with stdlib names to allow for . imports.

Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
<entry>
<title>sandbox/seccomp: prepare -&gt; export</title>
<updated>2025-07-01T15:32:48Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2025-07-01T15:32:48Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=26b7afc890e23af19fe6662fd27f46b47e9feea9'/>
<id>urn:sha1:26b7afc890e23af19fe6662fd27f46b47e9feea9</id>
<content type='text'>
Export makes a lot more sense, and also matches the libseccomp function.

Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
<entry>
<title>sandbox/seccomp: native rule slice in helpers</title>
<updated>2025-07-01T15:22:27Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2025-07-01T15:22:27Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=d5532aade0c3f042c5daa7d1c16e7cce2f4b524a'/>
<id>urn:sha1:d5532aade0c3f042c5daa7d1c16e7cce2f4b524a</id>
<content type='text'>
These helper functions took FilterPreset as input for ease of integration. This moves them to []NativeRule.

Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
</feed>
