- 25 Aug, 2020 1 commit
-
- 21 Aug, 2020 4 commits
-
-
Stéphane Graber authored
remove deprecated options in lxc.service fixes #3527
-
Stéphane Graber authored
cgfsng: fix cgroup attach cgroup creation
-
graysky authored
Signed-off-by:graysky <graysky@archlinux.us>
-
Christian Brauner authored
[01m[Kcgroups/cgfsng.c:[m[K In function ‘[01m[Kcgroup_attach_leaf.constprop[m[K’: [01m[Kcgroups/cgfsng.c:2221:10:[m[K [01;31m[Kerror: [m[Kwriting 1 byte into a region of size 0 [[01;31m[K-Werror=stringop-overflow=[m[K] 2221 | [01;31m[K*slash = '\0'[m[K; | [01;31m[K~~~~~~~^~~~~~[m[K [01m[Kcgroups/cgfsng.c:2213:8:[m[K [01;36m[Knote: [m[Kat offset -13 to object ‘[01m[Kattach_cgroup[m[K’ with size 23 declared here 2213 | char [01;36m[Kattach_cgroup[m[K[STRLITERALLEN(".lxc-1000/cgroup.procs") + 1]; | [01;36m[K^~~~~~~~~~~~~[m[K [01m[Kcgroups/cgfsng.c:2229:10:[m[K [01;31m[Kerror: [m[Kwriting 1 byte into a region of size 0 [[01;31m[K-Werror=stringop-overflow=[m[K] 2229 | [01;31m[K*slash = '/'[m[K; | [01;31m[K~~~~~~~^~~~~[m[K [01m[Kcgroups/cgfsng.c:2213:8:[m[K [01;36m[Knote: [m[Kat offset -13 to object ‘[01m[Kattach_cgroup[m[K’ with size 23 declared here 2213 | char [01;36m[Kattach_cgroup[m[K[STRLITERALLEN(".lxc-1000/cgroup.procs") + 1]; | [01;36m[K^~~~~~~~~~~~~[m[K [01m[Kcgroups/cgfsng.c:2229:10:[m[K [01;31m[Kerror: [m[Kwriting 1 byte into a region of size 0 [[01;31m[K-Werror=stringop-overflow=[m[K] 2229 | [01;31m[K*slash = '/'[m[K; | [01;31m[K~~~~~~~^~~~~[m[K [01m[Kcgroups/cgfsng.c:2213:8:[m[K [01;36m[Knote: [m[Kat offset -13 to object ‘[01m[Kattach_cgroup[m[K’ with size 23 declared here 2213 | char [01;36m[Kattach_cgroup[m[K[STRLITERALLEN(".lxc-1000/cgroup.procs") + 1]; | [01;36m[K^~~~~~~~~~~~~[m[K Link: https://launchpadlibrarian.net/494354168/buildlog_ubuntu-groovy-armhf.lxc_1%3A4.0.4-0ubuntu1_BUILDING.txt.gzSigned-off-by:Christian Brauner <christian.brauner@ubuntu.com>
-
- 17 Aug, 2020 1 commit
-
-
Stéphane Graber authored
Updated documentation to reflect lack of support for pure cgroupv2
-
- 15 Aug, 2020 1 commit
-
-
Arjun Ramachandrula authored
Signed-off-by:Arjun Ramachandrula <arjun.ramachandrula@gmail.com>
-
- 12 Aug, 2020 2 commits
-
-
Stéphane Graber authored
lsm: remove the need for atomic operations
-
Christian Brauner authored
Signed-off-by:Christian Brauner <christian.brauner@ubuntu.com>
-
- 11 Aug, 2020 3 commits
-
-
Stéphane Graber authored
lsm: rewrite
-
Christian Brauner authored
Signed-off-by:Christian Brauner <christian.brauner@ubuntu.com>
-
Christian Brauner authored
Signed-off-by:Christian Brauner <christian.brauner@ubuntu.com>
-
- 10 Aug, 2020 4 commits
-
-
Stéphane Graber authored
conf: terminal and /dev hardening
-
Christian Brauner authored
Signed-off-by:Christian Brauner <christian.brauner@ubuntu.com>
-
Christian Brauner authored
Signed-off-by:Christian Brauner <christian.brauner@ubuntu.com>
-
Stéphane Graber authored
openat2() and safe mounting
-
- 09 Aug, 2020 9 commits
-
-
Christian Brauner authored
Signed-off-by:Christian Brauner <christian.brauner@ubuntu.com>
-
Christian Brauner authored
Signed-off-by:Christian Brauner <christian.brauner@ubuntu.com>
-
Christian Brauner authored
Signed-off-by:Christian Brauner <christian.brauner@ubuntu.com>
-
Christian Brauner authored
This way we only need to open it _once_ per container startup. Signed-off-by:Christian Brauner <christian.brauner@ubuntu.com>
-
Christian Brauner authored
Signed-off-by:Christian Brauner <christian.brauner@ubuntu.com>
-
Christian Brauner authored
Signed-off-by:Christian Brauner <christian.brauner@ubuntu.com>
-
Christian Brauner authored
Signed-off-by:Christian Brauner <christian.brauner@ubuntu.com>
-
Christian Brauner authored
Signed-off-by:Christian Brauner <christian.brauner@ubuntu.com>
-
Christian Brauner authored
Signed-off-by:Christian Brauner <christian.brauner@ubuntu.com>
-
- 07 Aug, 2020 3 commits
-
-
Christian Brauner authored
lxc-download fixes
-
Stéphane Graber authored
Closes #3511 Signed-off-by:Stéphane Graber <stgraber@ubuntu.com>
-
Stéphane Graber authored
This reverts commit 409040e7. Testing of both options show identical behavior but receive-keys does not exist on older releases, so let's revert this. Closes #3510 Signed-off-by:
Stéphane Graber <stgraber@ubuntu.com>
-
- 06 Aug, 2020 7 commits
-
-
Stéphane Graber authored
api-extension: add missing seccomp_proxy_send_notify_fd extension
-
Christian Brauner authored
Signed-off-by:Christian Brauner <christian.brauner@ubuntu.com>
-
Stéphane Graber authored
seccomp: add seccomp_notify_fd_active api extension
-
Christian Brauner authored
Since we haven't made this official api yet: YOLO Signed-off-by:Christian Brauner <christian.brauner@ubuntu.com>
-
Christian Brauner authored
which allows to retrieve an active seccomp notifier fd from a running container. Signed-off-by:Christian Brauner <christian.brauner@ubuntu.com>
-
Stéphane Graber authored
seccomp: don't close the mainloop, simply remove the handler
-
Christian Brauner authored
Signed-off-by:Christian Brauner <christian.brauner@ubuntu.com>
-
- 05 Aug, 2020 5 commits
-
-
Stéphane Graber authored
macro: define TIOCGPTPEER if missing
-
Christian Brauner authored
Signed-off-by:Christian Brauner <christian.brauner@ubuntu.com>
-
Christian Brauner authored
Signed-off-by:Christian Brauner <christian.brauner@ubuntu.com>
-
Stéphane Graber authored
terminal: safely allocate pts devices from inside the container
-
Christian Brauner authored
This was a year long journey which seems to finally have come to an end. Closes: #1620. Signed-off-by:Christian Brauner <christian.brauner@ubuntu.com>
-