<feed xmlns='http://www.w3.org/2005/Atom'>
<title>hakurei/test/sandbox/case/default.nix, branch master</title>
<subtitle>low-level userspace tooling for Rosa OS</subtitle>
<id>http://src.rosa.moe/hakurei/atom/test/sandbox/case/default.nix?h=master</id>
<link rel='self' href='http://src.rosa.moe/hakurei/atom/test/sandbox/case/default.nix?h=master'/>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/'/>
<updated>2025-10-18T19:11:38Z</updated>
<entry>
<title>hst/container: optional runtime and tmpdir sharing</title>
<updated>2025-10-18T19:11:38Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2025-10-18T18:53:20Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=699c19e972a3cbcc714403aedffcb5ff74386cfc'/>
<id>urn:sha1:699c19e972a3cbcc714403aedffcb5ff74386cfc</id>
<content type='text'>
Sharing and persisting these directories do not always make sense. Make it optional here.

Closes #16.

Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
<entry>
<title>test/sandbox: create marker in /var/tmp</title>
<updated>2025-09-14T07:45:17Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2025-09-14T07:45:17Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=1cdc6b4246ac82adb0c9ed7620d3f7225f1a3e7f'/>
<id>urn:sha1:1cdc6b4246ac82adb0c9ed7620d3f7225f1a3e7f</id>
<content type='text'>
This prepares the test suite for private TMPDIR.

Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
<entry>
<title>test/sandbox: bind /var/tmp writable</title>
<updated>2025-09-14T05:59:53Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2025-09-14T05:59:53Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=d0ddd7193407af4162312469f19bd02af4d4bce1'/>
<id>urn:sha1:d0ddd7193407af4162312469f19bd02af4d4bce1</id>
<content type='text'>
This makes it possible to place markers with private tmpdir.

Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
<entry>
<title>app/seal: leave $DISPLAY as is on host abstract</title>
<updated>2025-08-27T11:42:03Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2025-08-27T11:40:30Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=acb6931f3e4af62f92dc2ef85ef7c1ac9f7867e4'/>
<id>urn:sha1:acb6931f3e4af62f92dc2ef85ef7c1ac9f7867e4</id>
<content type='text'>
This helps work around faulty software that misinterprets unix: DISPLAY string.

Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
<entry>
<title>app: set up acl on X11 socket</title>
<updated>2025-08-18T02:30:58Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2025-08-17T17:24:56Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=83a1c75f1ac4d2d611b3a96474ed07df3cb557b6'/>
<id>urn:sha1:83a1c75f1ac4d2d611b3a96474ed07df3cb557b6</id>
<content type='text'>
The socket is typically owned by the priv-user, and inaccessible by the target user, so just allowing access to the directory is not enough. This change fixes this oversight and add checks that will also be useful for merging https://git.gensokyo.uk/security/hakurei/pulls/1.

Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
<entry>
<title>test/sandbox: check pd behaviour</title>
<updated>2025-07-31T18:27:02Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2025-07-31T17:11:19Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=987981df7313d0a121121be36f5c8cf86ffeacd1'/>
<id>urn:sha1:987981df7313d0a121121be36f5c8cf86ffeacd1</id>
<content type='text'>
Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
<entry>
<title>test/sandbox: add arm64 constants</title>
<updated>2025-07-08T20:36:35Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2025-07-08T19:45:54Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=749a2779f5ba8b2c575d1459db04c9209d914627'/>
<id>urn:sha1:749a2779f5ba8b2c575d1459db04c9209d914627</id>
<content type='text'>
Most of these are differences in qemu.

Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
<entry>
<title>test/sandbox: verify seccomp on all test cases</title>
<updated>2025-07-08T19:21:35Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2025-07-08T18:47:16Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=e574042d765f135814c5afabaf24cb7109fab175'/>
<id>urn:sha1:e574042d765f135814c5afabaf24cb7109fab175</id>
<content type='text'>
This change also makes seccomp hashes cross-platform.

Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
<entry>
<title>treewide: rename to hakurei</title>
<updated>2025-06-24T19:57:41Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2025-06-24T18:59:52Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=87e008d56de974947ebb99c2cc40b25d3c2cf43e'/>
<id>urn:sha1:87e008d56de974947ebb99c2cc40b25d3c2cf43e</id>
<content type='text'>
Fortify makes little sense for a container tool.

Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
<entry>
<title>nix: use reverse-DNS style id as unique identifier</title>
<updated>2025-05-25T11:12:30Z</updated>
<author>
<name>Ophestra</name>
<email>cat@gensokyo.uk</email>
</author>
<published>2025-05-25T11:12:30Z</published>
<link rel='alternate' type='text/html' href='http://src.rosa.moe/hakurei/commit/?id=2ffca6984a03b2daa3bb114f70ea84e71439559a'/>
<id>urn:sha1:2ffca6984a03b2daa3bb114f70ea84e71439559a</id>
<content type='text'>
Signed-off-by: Ophestra &lt;cat@gensokyo.uk&gt;
</content>
</entry>
</feed>
