<feed xmlns='http://www.w3.org/2005/Atom'>
<title>hakurei/test/sandbox/assert.go, branch develop</title>
<subtitle>low-level userspace tooling for Rosa OS</subtitle>
<id>http://src.rosa.moe/hakurei/atom/test/sandbox/assert.go?h=develop</id>
<link rel='self' href='http://src.rosa.moe/hakurei/atom/test/sandbox/assert.go?h=develop'/>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/'/>
<updated>2025-11-12T14:03:22Z</updated>
<entry>
<title>test: move package sandbox internal</title>
<updated>2025-11-12T14:03:22Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2025-11-12T14:03:22Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=b5630f6883c874d458d9ae3c666cfb7ae5e3121d'/>
<id>urn:sha1:b5630f6883c874d458d9ae3c666cfb7ae5e3121d</id>
<content type='text'>
This should never be used outside vm tests.

Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
<entry>
<title>test/sandbox: check extra writable paths</title>
<updated>2025-09-14T06:12:51Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2025-09-14T06:12:09Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=83c4f8b767c31734a7e465e49ee0e23487ac22ca'/>
<id>urn:sha1:83c4f8b767c31734a7e465e49ee0e23487ac22ca</id>
<content type='text'>
This is not always obvious from mountinfo.

Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
<entry>
<title>internal/app: mount /dev/shm early</title>
<updated>2025-09-13T16:49:42Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2025-09-13T16:35:17Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=ca247b80378b7248ed4d1eda8a97e2a1d659ec7b'/>
<id>urn:sha1:ca247b80378b7248ed4d1eda8a97e2a1d659ec7b</id>
<content type='text'>
This avoids covering /dev/shm mounts from hst.

Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
<entry>
<title>app: set up acl on X11 socket</title>
<updated>2025-08-18T02:30:58Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2025-08-17T17:24:56Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=83a1c75f1ac4d2d611b3a96474ed07df3cb557b6'/>
<id>urn:sha1:83a1c75f1ac4d2d611b3a96474ed07df3cb557b6</id>
<content type='text'>
The socket is typically owned by the priv-user, and inaccessible by the target user, so just allowing access to the directory is not enough. This change fixes this oversight and add checks that will also be useful for merging https://git.gensokyo.uk/security/hakurei/pulls/1.

Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
<entry>
<title>test/sandbox: verify seccomp on all test cases</title>
<updated>2025-07-08T19:21:35Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2025-07-08T18:47:16Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=e574042d765f135814c5afabaf24cb7109fab175'/>
<id>urn:sha1:e574042d765f135814c5afabaf24cb7109fab175</id>
<content type='text'>
This change also makes seccomp hashes cross-platform.

Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
<entry>
<title>test/sandbox: guard on testtool tag</title>
<updated>2025-07-07T11:11:29Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2025-07-07T11:11:29Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=2b44493e8a255b40a9809208f5c751ca7c539027'/>
<id>urn:sha1:2b44493e8a255b40a9809208f5c751ca7c539027</id>
<content type='text'>
This tool should not show up when building hakurei normally.

Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
<entry>
<title>test/sandbox: treat ESRCH as temporary failure</title>
<updated>2025-03-29T18:50:59Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2025-03-29T18:50:59Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=f772940768d9cada256f8f3291a3b9e9685003c3'/>
<id>urn:sha1:f772940768d9cada256f8f3291a3b9e9685003c3</id>
<content type='text'>
This is an ugly fix that makes various assumptions guaranteed to hold true in the testing vm. The test package is filtered by the build system so some ugliness is tolerable here.

Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
<entry>
<title>test/sandbox: separate check filter</title>
<updated>2025-03-29T17:15:08Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2025-03-29T13:34:51Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=8886c40974bb64720a23a2ac9780a11e8910bd7f'/>
<id>urn:sha1:8886c40974bb64720a23a2ac9780a11e8910bd7f</id>
<content type='text'>
Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
<entry>
<title>test/sandbox: check seccomp outcome</title>
<updated>2025-03-27T17:24:27Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2025-03-27T17:24:27Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=ff3cfbb437795c7fee547b8340014071625a61a8'/>
<id>urn:sha1:ff3cfbb437795c7fee547b8340014071625a61a8</id>
<content type='text'>
This is as ugly as it is because it has to have CAP_SYS_ADMIN and not be in seccomp mode.

Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
<entry>
<title>test/sandbox/ptrace: dump seccomp bpf program</title>
<updated>2025-03-27T16:35:56Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2025-03-27T16:09:26Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=660a2898dc0dbfe9963d8f336e04582955b56b8a'/>
<id>urn:sha1:660a2898dc0dbfe9963d8f336e04582955b56b8a</id>
<content type='text'>
Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
</feed>
