Robert Swiecki [Mon, 29 May 2017 17:24:14 +0000 (19:24 +0200)]
configs/home-documents-with-xorg-no-net: add /dev/null
Robert Swiecki [Mon, 29 May 2017 17:03:37 +0000 (19:03 +0200)]
configs:configs/home-documents-with-xorg-no-net Xorg socket as R/W
Robert Swiecki [Mon, 29 May 2017 16:08:23 +0000 (18:08 +0200)]
Readme
Robert Swiecki [Mon, 29 May 2017 16:02:58 +0000 (18:02 +0200)]
Merge branch 'master' of github.com:google/nsjail
Robert Swiecki [Mon, 29 May 2017 16:02:47 +0000 (18:02 +0200)]
Readm
Robert Swiecki [Mon, 29 May 2017 15:00:19 +0000 (17:00 +0200)]
Makefile: clean removes pb-c generated files
Robert Swiecki [Mon, 29 May 2017 14:57:04 +0000 (16:57 +0200)]
configs/bash-with-fake-geteuid: block ptrace, fix description
Robert Swiecki [Mon, 29 May 2017 14:52:24 +0000 (16:52 +0200)]
mount: introduce mountDescribeMountPt
Robert Swiecki [Mon, 29 May 2017 14:39:08 +0000 (16:39 +0200)]
mount: mount src_content files from other tmpfs, to avoid shadowing / of the root tmpfs with some other FS
Robert Swiecki [Mon, 29 May 2017 14:22:31 +0000 (16:22 +0200)]
Makefile: make compiling with libprotobuf-c more robust under different systems
Robert Swiecki [Mon, 29 May 2017 13:29:21 +0000 (15:29 +0200)]
Better compilation rules for protobuf-c-text
Robert Swiecki [Mon, 29 May 2017 13:01:34 +0000 (15:01 +0200)]
configs: typo
Robert Swiecki [Mon, 29 May 2017 02:50:29 +0000 (04:50 +0200)]
mount: remove tmp file after use
Robert Swiecki [Mon, 29 May 2017 01:29:14 +0000 (03:29 +0200)]
Simplify mountMount
Robert Swiecki [Mon, 29 May 2017 01:11:32 +0000 (03:11 +0200)]
Get rid of pivot_root_only - achieve the same in different way
Robert Swiecki [Sun, 28 May 2017 22:29:52 +0000 (00:29 +0200)]
Makefile: simplify kafel and protobuf-c-text building rules
Robert Swiecki [Sun, 28 May 2017 17:57:25 +0000 (19:57 +0200)]
Makefile: Use -fPIC when compiling protobuf-c-text
Robert Swiecki [Sun, 28 May 2017 17:30:34 +0000 (19:30 +0200)]
Makefile: autogen.sh protobuf-c-text once only
Robert Swiecki [Sun, 28 May 2017 17:22:03 +0000 (19:22 +0200)]
configs/bash-with-fake-geteuid set home
Robert Swiecki [Sun, 28 May 2017 17:21:22 +0000 (19:21 +0200)]
configs/bash-with-fake-geteuid skip_setsid for job control
Robert Swiecki [Sun, 28 May 2017 17:20:25 +0000 (19:20 +0200)]
configs/bash-with-fake-geteuid fancier PS1
Robert Swiecki [Sun, 28 May 2017 17:17:48 +0000 (19:17 +0200)]
config: implement keep caps
Robert Swiecki [Sun, 28 May 2017 17:07:01 +0000 (19:07 +0200)]
Readme
Robert Swiecki [Sun, 28 May 2017 17:01:53 +0000 (19:01 +0200)]
Readme
Robert Swiecki [Sun, 28 May 2017 16:59:50 +0000 (18:59 +0200)]
util: remove utilStrDupLen as it was unused
Robert Swiecki [Sun, 28 May 2017 16:58:47 +0000 (18:58 +0200)]
Makefile: also clean protobuf-c-text
Robert Swiecki [Sun, 28 May 2017 16:51:50 +0000 (18:51 +0200)]
Ini
Robert Swiecki [Sun, 28 May 2017 16:46:38 +0000 (18:46 +0200)]
Pass CFLAGS to protobuf-c-text
Robert Swiecki [Sun, 28 May 2017 16:37:50 +0000 (18:37 +0200)]
Makefile: remove stack-protector from CFLAGS
Robert Swiecki [Sun, 28 May 2017 15:42:15 +0000 (17:42 +0200)]
configs/imagemagick: increase rlimit_as
Robert Swiecki [Sun, 28 May 2017 15:37:01 +0000 (17:37 +0200)]
configs/bash-with-fake-geteuid.cfg set TERM
Robert Swiecki [Sun, 28 May 2017 15:32:14 +0000 (17:32 +0200)]
configs/home-documents-with-xorg-no-net.cfg: increase rlimit_as
Robert Swiecki [Sun, 28 May 2017 15:30:51 +0000 (17:30 +0200)]
configs/home-documents-with-xorg-no-net.cfg: increase rlimit_as
Robert Swiecki [Sun, 28 May 2017 14:56:16 +0000 (16:56 +0200)]
add configs/firefox-with-cloned-net.cfg
Robert Swiecki [Sun, 28 May 2017 13:27:13 +0000 (15:27 +0200)]
configs: smaller profile for xorg tools
Robert Swiecki [Sun, 28 May 2017 13:15:48 +0000 (15:15 +0200)]
configs: set cwd to /usr
Robert Swiecki [Sun, 28 May 2017 12:53:16 +0000 (14:53 +0200)]
mount: fewer warnings in a mount pt is non-mandatory #2
Robert Swiecki [Sun, 28 May 2017 12:51:09 +0000 (14:51 +0200)]
mount: fewer warnings in a mount pt is non-mandatory
Robert Swiecki [Sun, 28 May 2017 12:41:03 +0000 (14:41 +0200)]
protobuf-c-text: compile with -fPIC
Robert Swiecki [Sun, 28 May 2017 12:34:28 +0000 (14:34 +0200)]
makefile: incorrect libprotobuf-c check
Robert Swiecki [Sun, 28 May 2017 01:30:27 +0000 (03:30 +0200)]
configs/firefox: add /usr/bin/firefox bind mount
Robert Swiecki [Sun, 28 May 2017 01:29:01 +0000 (03:29 +0200)]
configs/firefox description fix
Robert Swiecki [Sun, 28 May 2017 01:22:11 +0000 (03:22 +0200)]
add configs/imagemagick-convert.cfg
Robert Swiecki [Sun, 28 May 2017 01:19:13 +0000 (03:19 +0200)]
mount: canonicalize paths
Robert Swiecki [Sun, 28 May 2017 00:55:50 +0000 (02:55 +0200)]
configs: tigher policy for firefox
Robert Swiecki [Sat, 27 May 2017 23:30:26 +0000 (01:30 +0200)]
configs: small tweaks
Robert Swiecki [Sat, 27 May 2017 23:24:55 +0000 (01:24 +0200)]
config: switch is_ro to rw
Robert Swiecki [Sat, 27 May 2017 23:16:48 +0000 (01:16 +0200)]
user: better check for uids/gids existence
Robert Swiecki [Sat, 27 May 2017 23:05:27 +0000 (01:05 +0200)]
Simplify uids/gids maps
Robert Swiecki [Sat, 27 May 2017 22:40:04 +0000 (00:40 +0200)]
readme
Robert Swiecki [Sat, 27 May 2017 22:17:51 +0000 (00:17 +0200)]
readme
Robert Swiecki [Sat, 27 May 2017 22:17:18 +0000 (00:17 +0200)]
configs: small tweaks for bash
Robert Swiecki [Sat, 27 May 2017 22:15:53 +0000 (00:15 +0200)]
Support envvars on mount path definitions
Robert Swiecki [Sat, 27 May 2017 20:01:46 +0000 (22:01 +0200)]
configs: sandboxed firefox + readme - improvements
Robert Swiecki [Sat, 27 May 2017 19:54:01 +0000 (21:54 +0200)]
configs: tweaks for geeqie
Robert Swiecki [Sat, 27 May 2017 19:50:15 +0000 (21:50 +0200)]
configs: Xauthority is not required
Robert Swiecki [Sat, 27 May 2017 19:43:56 +0000 (21:43 +0200)]
sandboxed firefox + readme
Robert Swiecki [Sat, 27 May 2017 18:59:17 +0000 (20:59 +0200)]
readme
Robert Swiecki [Sat, 27 May 2017 18:55:29 +0000 (20:55 +0200)]
readme: more examples
Robert Swiecki [Sat, 27 May 2017 18:50:30 +0000 (20:50 +0200)]
readme
Robert Swiecki [Sat, 27 May 2017 18:50:11 +0000 (20:50 +0200)]
readme
Robert Swiecki [Sat, 27 May 2017 18:48:49 +0000 (20:48 +0200)]
config: remove exec_bin as it should be specified with cmd-line
Robert Swiecki [Sat, 27 May 2017 18:47:42 +0000 (20:47 +0200)]
new config + readme
Robert Swiecki [Sat, 27 May 2017 18:19:36 +0000 (20:19 +0200)]
mount: less logging from mountIsDir
Robert Swiecki [Sat, 27 May 2017 17:18:56 +0000 (19:18 +0200)]
mountIsDir: PLOG_E() -> PLOG_W()
Robert Swiecki [Sat, 27 May 2017 17:17:25 +0000 (19:17 +0200)]
configs: better description for bash-with-fake-geteuid.cfg
Robert Swiecki [Sat, 27 May 2017 17:15:57 +0000 (19:15 +0200)]
configs: redirect to examples
Robert Swiecki [Sat, 27 May 2017 17:14:55 +0000 (19:14 +0200)]
mount: better logging for failed mounts #2
Robert Swiecki [Sat, 27 May 2017 17:11:19 +0000 (19:11 +0200)]
mount: better logging for failed mounts
Robert Swiecki [Sat, 27 May 2017 17:06:46 +0000 (19:06 +0200)]
config: add name and description
Robert Swiecki [Sat, 27 May 2017 17:05:42 +0000 (19:05 +0200)]
config: add name and description
Robert Swiecki [Sat, 27 May 2017 16:46:15 +0000 (18:46 +0200)]
configs: rename config1.example -> bash-with-fake-geteuid.cfg
Robert Swiecki [Sat, 27 May 2017 16:45:25 +0000 (18:45 +0200)]
configs: rename config1.example -> bash-with-fake-geteuid.cfg
Robert Swiecki [Sat, 27 May 2017 15:40:30 +0000 (17:40 +0200)]
cmdline: avoid using %s with nullptr
Robert Swiecki [Sat, 27 May 2017 14:47:12 +0000 (16:47 +0200)]
config: smaller fixes (logging/comments)
Robert Swiecki [Sat, 27 May 2017 13:40:24 +0000 (15:40 +0200)]
config: indent
Robert Swiecki [Sat, 27 May 2017 13:17:11 +0000 (15:17 +0200)]
mount: nonmandatory mounts
Robert Swiecki [Sat, 27 May 2017 13:01:34 +0000 (15:01 +0200)]
config: allow skipping arguments in mount points
Robert Swiecki [Sat, 27 May 2017 02:06:28 +0000 (04:06 +0200)]
config: support for envvars
Robert Swiecki [Sat, 27 May 2017 01:59:02 +0000 (03:59 +0200)]
clang-format on config.proto
Robert Swiecki [Sat, 27 May 2017 01:29:40 +0000 (03:29 +0200)]
config: description
Robert Swiecki [Sat, 27 May 2017 01:29:06 +0000 (03:29 +0200)]
config: description
Robert Swiecki [Sat, 27 May 2017 01:23:08 +0000 (03:23 +0200)]
config: description
Robert Swiecki [Sat, 27 May 2017 01:21:59 +0000 (03:21 +0200)]
config: description + make indent
Robert Swiecki [Sat, 27 May 2017 01:20:10 +0000 (03:20 +0200)]
config: description
Robert Swiecki [Sat, 27 May 2017 00:56:58 +0000 (02:56 +0200)]
Readme
Robert Swiecki [Sat, 27 May 2017 00:56:07 +0000 (02:56 +0200)]
Readme
Robert Swiecki [Sat, 27 May 2017 00:55:21 +0000 (02:55 +0200)]
Readme
Robert Swiecki [Sat, 27 May 2017 00:53:22 +0000 (02:53 +0200)]
Readme
Robert Swiecki [Sat, 27 May 2017 00:50:13 +0000 (02:50 +0200)]
Readme
Robert Swiecki [Sat, 27 May 2017 00:49:04 +0000 (02:49 +0200)]
Readme
Robert Swiecki [Sat, 27 May 2017 00:32:39 +0000 (02:32 +0200)]
Makefile: surround make -C kafel clean with ifdefs
Robert Swiecki [Sat, 27 May 2017 00:31:11 +0000 (02:31 +0200)]
config: warn about missing libprotobuf-c
Robert Swiecki [Sat, 27 May 2017 00:24:41 +0000 (02:24 +0200)]
config: executable in config
Robert Swiecki [Sat, 27 May 2017 00:09:21 +0000 (02:09 +0200)]
config: presumably all options
Robert Swiecki [Fri, 26 May 2017 23:35:00 +0000 (01:35 +0200)]
config: support seccomp filters
Robert Swiecki [Fri, 26 May 2017 23:17:09 +0000 (01:17 +0200)]
config: support mounts - fix for list insertion order
Robert Swiecki [Fri, 26 May 2017 23:16:12 +0000 (01:16 +0200)]
config: support mounts
Robert Swiecki [Fri, 26 May 2017 22:33:25 +0000 (00:33 +0200)]
config: compact-ize uid/gid map options
Robert Swiecki [Fri, 26 May 2017 22:16:28 +0000 (00:16 +0200)]
config: make inside_id and outside_id default to ''