aboutsummaryrefslogtreecommitdiffhomepage
AgeCommit message (Collapse)Author
2025-03-17sandbox/mount: rename device flagOphestra
Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-17sandbox: mount container /dev/mqueueOphestra
Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-17sandbox: unwrap path stringOphestra
Mount proc and dev takes no additional parameters. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-17sandbox/seccomp: check for both partial read outcomesOphestra
This eliminates intermittent test failures. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-17nix: clean up flake outputsOphestra
Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-17sandbox: move out of internalOphestra
Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-17sandbox: move params setup functionsOphestra
Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-17sandbox: wrap fmsg interfaceOphestra
Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-17seccomp: install output atomicallyOphestra
Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-17dbus: run in native sandboxOphestra
Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-17ldd: always copy stderrOphestra
Dropping the buffer on success is unhelpful and could hide some useful information. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-17ldd: mount /proc in containerOphestra
This covers host /proc. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-16test: raise timeoutOphestra
Native container tooling is severely slowed down by race detector. Raise timeout so it reliably completes. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-16sandbox: check command function pointerOphestra
Setting default CommandContext on initialisation is somewhat of a footgun. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-16helper: implement native container backendOphestra
Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-16helper: raise WaitDelay during testsOphestra
Helper runs very slowly with race detector. This prevents it from timing out. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-16test: run go tests with race detectorOphestra
Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-16ldd: lib paths resolve functionOphestra
This is what always happens right after a ldd call, so implement it here. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-16helper/stub: copy args to stderrOphestra
Some helpers are implemented via go test itself in tests, and as a result stdout gets clobbered. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-16sandbox: return on zero length opsOphestra
This dodges potentially confusing behaviour where init fails due to Ops being clobbered during transfer. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-16helper: eliminate commandContext replacementOphestra
This is done more cleanly by modifying Args in cmdF. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-15sandbox/init: early params nil checkOphestra
Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-15sandbox: return error on doubled startOphestra
Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-15sandbox: expose cancel behaviourOphestra
Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-15helper: expose extra files to directOphestra
Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-15helper: combine helper ipc setupOphestra
The two-step args call is no longer necessary since stat is passed on initialisation. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-15helper: rearrange initialisation argsOphestra
This improves consistency across two different helper implementations. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-15helper: move process wrapper to directOphestra
Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-15helper: clean up interfaceOphestra
The helper interface was messy due to odd context acquisition order. That has changed, so this cleans it up. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-14helper/proc: pass extra files and startOphestra
For integration with native container tooling. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-14seccomp: move out of helperOphestra
Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-14helper: embed context on creationOphestra
Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-14ldd: run in native sandboxOphestra
Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-14sandbox: write uid/gid map as initOphestra
This avoids PR_SET_DUMPABLE in the parent process. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-14sandbox: invert seccomp ruleset defaultsOphestra
Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-14sandbox: mount container /devOphestra
Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-14sandbox/mount: pass custom tmpfs nameOphestra
The tmpfs driver allows arbitrary fsname. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-14sandbox: pass params to setup opsOphestra
Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-14sandbox/mount: fix source flag pathOphestra
Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-14sandbox: separate tmpfs function from opOphestra
This is useful in the implementation of various other ops. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-14sandbox: separate bind mount function from opOphestra
This is useful in the implementation of various other ops. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-13internal/app: rename init to init0Ophestra
This makes way for the new container init. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-13sandbox: native container toolingOphestra
This should eventually replace bwrap. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-13test: run go test under regular userOphestra
By default test vm commands run as root, this causes buildFHSEnv bwrap to cover some parts of /proc, making it impossible to mount proc in a mount namespace created under it. Running as a regular user gets around this issue. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-13test: print output of failed testOphestra
Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-13internal: pull EINTR loop from stdlibOphestra
Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-13sandbox: read overflow idsOphestra
Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-13test/sandbox: bypass fieldsOphestra
A field is bypassed if it contains a single null byte. This will never appear in the text format so is safe to use. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-12ldd: handle musl static behaviourOphestra
Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-03-12helper/seccomp: improve error handlingOphestra
This passes both errno and libseccomp return value. Signed-off-by: Ophestra <cat@gensokyo.uk>