]> git.ipfire.org Git - thirdparty/lxc.git/shortlog
thirdparty/lxc.git
2021-02-03  Christian Braunerutils: harden __safe_mount_beneath_at() 3650/head
2021-02-03  Christian Braunerconf: refactor transient procfs mounting
2021-02-03  Christian Braunerconf: restrict open call in lxc_mount_rootfs()
2021-02-03  Christian Braunerconf: make lxc_create_tmp_proc_mount() static
2021-02-03  Christian Braunerconf: coding style
2021-02-03  Stéphane GraberMerge pull request #3648 from brauner/2021-02-03/fixes
2021-02-03  Stéphane GraberMerge pull request #3649 from brauner/2021-02-03/attach...
2021-02-03  Christian Braunerattach: attach to namespaces via pidfds 3649/head
2021-02-03  Christian Braunerconf: fd-only devtps setup 3648/head
2021-02-03  Christian Braunerconf: fd-only pivot root
2021-02-03  Christian Braunerconf: restrict open for lxc_mount_rootfs()
2021-02-03  Christian Braunerconf: fd-only operations in lxc_setup_dev_symlinks()
2021-02-03  Christian Braunerconf: harden open in lxc_fill_autodev()
2021-02-03  Christian Braunerconf: restrict open of dev/
2021-02-03  Christian Braunerconf: remove unnecessary syscall
2021-02-03  Christian Braunerrexec: mark all fds as close-on-exec if possible
2021-02-03  Christian Braunersyscalls: add close_range()
2021-02-03  Christian Braunerrexec: check lseek() return value
2021-02-03  Christian Braunertests: check for NULL in device_add_remove
2021-02-02  Stéphane GraberMerge pull request #3647 from brauner/2021-02-02/fixes
2021-02-02  Christian Braunercgroups: improve parameter vetting 3647/head
2021-02-02  Christian Braunertests: support pure unified cgroup layouts in cgpath...
2021-02-02  Christian Braunertest: add logging to device_add_remove
2021-02-02  Christian Braunerfreezer: remove lxc_cmd_freeze() and lxc_cmd_unfreeze...
2021-02-02  Christian Braunercommands: use __cgroup_unfreeze() directly
2021-02-02  Christian Braunercgroups: export __cgroup_unfreeze() for use in commands
2021-02-02  Christian Braunercgroups: use lxc_cmd_get_limiting_cgroup2_fd()
2021-02-02  Christian Braunercommands: add missing lxc_cmd_get_limiting_cgroup2_fd...
2021-02-02  Christian Braunercgpath: add logging
2021-02-02  Christian Braunerattach: explicitly close seccomp notifier fd
2021-02-02  Christian Braunercgroups: switch back to returning ints
2021-02-02  Christian Braunerattach: check for ENOCGROUP2 explicitly
2021-02-02  Christian Braunercgroups: return ENOCGROUP2 from cgroup_attach()
2021-02-02  Christian Braunercgroups: stricter argument vetting for cgroup_attach()
2021-02-02  Christian Braunercgroups: move down cgroup_attach()
2021-02-02  Christian Braunerlxccontainer: use correct error checks
2021-02-02  Christian Braunercgroups: vet parameters
2021-02-02  Christian Braunercgroups: remove unused conf argument
2021-02-02  Christian Braunercgroups: rewind() file before polling again
2021-02-02  Christian Braunerlxccontainer: use cgroup_freeze() and cgroup_unfreeze()
2021-02-02  Christian Braunerfreezer: make methods return bool
2021-02-02  Christian Braunercgroups: add cgroup_freeze() and cgroup_unfreeze()
2021-02-02  Christian Braunerfreezer: use lxc_cmd_notify_state_listeners()
2021-02-02  Christian Braunercommands_utils: add lcx_cmd_notify_state_listeners()
2021-02-02  Christian Braunercgroups: annotate cgroup_get()/cgroup_set()
2021-02-02  Christian Braunercgroups: move functions after methods
2021-02-02  Christian Braunerlxccontainer: use cgroup_set()
2021-02-02  Christian Braunerlxccontainer: use correct variable ordering
2021-02-02  Christian Braunercgroups: add croup_set()
2021-02-02  Christian Braunercgroups: reorder cgroup_get() arguments
2021-02-02  Christian Braunerlxccontainer: use cgroup_get()
2021-02-02  Christian Braunercgroups: add cgroup_get()
2021-02-02  Christian Braunerfile_utils: add lxc_read_try_buf_at()
2021-02-02  Christian Braunermacro: abuse ENOMEDIUM as ENOCGROUP2
2021-02-02  Stéphane GraberMerge pull request #3646 from brauner/2021-02-02/fixes
2021-02-02  Christian Braunercgroups: switch controller delegation to fd-only operations 3646/head
2021-02-02  Christian Braunercgroups: add unified_cgroup_fd() helper
2021-02-02  Christian Braunerfile_utils: harden lxc_writeat()
2021-02-02  Christian Braunerfile_utils: harden lxc_open_dirfd()
2021-02-02  Christian Braunersyscall_wrappers: add PROTECT_OPEN_W_* variants
2021-02-02  Christian Braunermemory_utils: add close_prot_errno_mov()
2021-02-02  Christian Braunerattach: move loading seccomp as late as possible
2021-02-02  Christian Braunerattach: move file descriptor closing into attach_contex...
2021-02-02  Christian Braunerattach: stricter lookup semantics for fdopen_at() calls
2021-02-01  Stéphane GraberMerge pull request #3645 from brauner/2021-02-01/fixes_4
2021-02-01  Christian Braunerconfile_utils: use lxc_log_trace() 3645/head
2021-02-01  Christian Braunerconf: use lxc_log_trace()
2021-02-01  Christian Braunercommands_utils: don't leak memory
2021-02-01  Christian Braunerattach: use correct put method
2021-02-01  Christian Braunerattach: prevent UAF
2021-02-01  Stéphane GraberMerge pull request #3644 from brauner/2021-02-01/fixes_3
2021-02-01  Christian Braunerattach: file descriptor based fdinfo handling 3644/head
2021-02-01  Christian Braunerfile_utils: remove O_NOFOLLOW from open_at() defaults
2021-02-01  Christian Braunerlsm: harden read_file_at()
2021-02-01  Christian Braunertree-wide: extend read_file_at()
2021-02-01  Christian Braunerattach: harden open calls
2021-02-01  Christian Braunersyscall_wrappers: add PROTECT_LOOKUP, PROTECT_OPEN...
2021-02-01  Christian Braunerfile_utils: add open_at()
2021-02-01  Stéphane GraberMerge pull request #3642 from brauner/2021-02-01/fixes
2021-02-01  Stéphane GraberMerge pull request #3643 from brauner/2021-02-01/fixes_2
2021-02-01  Christian Braunercgroups: initialize variable 3643/head
2021-02-01  Christian Braunercgroups: remove pointless NULL checks
2021-02-01  Christian Braunerattach: stash host uid and host gid in attach_context 3642/head
2021-02-01  Christian Braunerattach: fix error checking for dup2()
2021-02-01  Christian Braunerattach: fix logging for stdfd replacement
2021-02-01  Christian Braunerattach: log failues to dup2() with SYSDEBUG()
2021-02-01  Christian Braunerutils: use SYSTRACE() when logging stdio permission...
2021-02-01  Christian Braunerattach: document attach_context
2021-02-01  Christian Braunerattach: simplify opening of /proc/self
2021-02-01  Christian Braunerattach: move uid and gid handling to get_attach_context()
2021-02-01  Christian Braunerattach: initialize init_pid field to -ESRCH
2021-02-01  Christian Braunerattach: unifiy /proc/<init-pid>/status parsing
2021-02-01  Christian Braunerfile_utils: add fdopenat()
2021-01-31  Stéphane GraberMerge pull request #3641 from brauner/2021-01-30/fixes
2021-01-31  Christian Braunerlsm/apparmor: cleanup apparmor_process_label_set() 3641/head
2021-01-31  Christian Braunerattach: hardening through use of pidfds
2021-01-31  Christian Braunerattach: file descriptors based LSM handling
2021-01-31  Christian Braunercgroups: align methods
2021-01-30  Stéphane GraberMerge pull request #3639 from brauner/2021-01-28/fixes
2021-01-30  Christian Braunercgroups: use PTR_TO_U64() 3639/head
next