Seth Hoenig
05937ab75b
exec2: add client support for unveil filesystem isolation mode ( #20115 )
...
* exec2: add client support for unveil filesystem isolation mode
This PR adds support for a new filesystem isolation mode, "Unveil". The
mode introduces a "alloc_mounts" directory where tasks have user-owned
directory structure which are bind mounts into the real alloc directory
structure. This enables a task driver to use landlock (and maybe the
real unveil on openbsd one day) to isolate a task to the task owned
directory structure, providing sandboxing.
* actually create alloc-mounts-dir directory
* fix doc strings about alloc mount dir paths
2024-03-13 08:24:17 -05:00
..
2024-03-13 08:24:17 -05:00
2023-08-10 17:27:29 -05:00
2024-02-29 12:11:35 -06:00
2023-08-10 17:27:29 -05:00
2023-08-10 17:27:29 -05:00
2023-08-10 17:27:29 -05:00
2024-03-13 08:24:17 -05:00
2023-08-10 17:27:29 -05:00
2023-08-10 17:27:29 -05:00
2023-08-18 07:47:24 +01:00
2023-11-08 09:30:08 -05:00
2023-11-08 09:30:08 -05:00
2023-12-14 11:33:31 -08:00
2024-03-13 08:24:17 -05:00
2024-02-12 09:43:34 -05:00
2024-02-12 09:43:34 -05:00
2024-03-12 12:04:04 +01:00
2024-03-13 08:24:17 -05:00
2024-03-13 08:24:17 -05:00
2023-08-18 07:47:24 +01:00
2024-03-13 08:24:17 -05:00
2023-11-08 09:30:08 -05:00
2023-12-07 11:51:20 -05:00
2024-03-13 08:24:17 -05:00
2023-08-10 17:27:29 -05:00
2023-08-10 17:27:29 -05:00
2023-08-10 17:27:29 -05:00
2023-08-10 17:27:29 -05:00
2023-08-10 17:27:29 -05:00
2023-08-10 17:27:29 -05:00
2023-10-12 12:21:48 -04:00
2023-08-10 17:27:29 -05:00
2023-08-10 17:27:29 -05:00
2023-08-10 17:27:29 -05:00
2024-02-29 12:11:35 -06:00
2023-08-10 17:27:29 -05:00
2023-08-18 07:47:24 +01:00
2023-08-10 17:27:29 -05:00
2023-08-10 17:27:29 -05:00
2023-10-31 11:25:20 -07:00
2024-01-12 15:48:30 -05:00
2024-02-19 16:41:35 +01:00
2024-02-19 16:41:35 +01:00
2023-10-20 17:11:41 -07:00
2023-11-30 16:40:13 +00:00
2023-08-10 17:27:29 -05:00
2023-08-10 17:27:29 -05:00
2023-08-10 17:27:29 -05:00
2023-08-10 17:27:29 -05:00
2023-08-10 17:27:29 -05:00
2023-08-10 17:27:29 -05:00
2023-08-10 17:27:29 -05:00
2023-08-10 17:27:29 -05:00
2023-08-10 17:27:29 -05:00
2023-08-10 17:27:29 -05:00
2023-12-08 08:46:55 -05:00
2023-08-10 17:27:29 -05:00
2023-08-10 17:27:29 -05:00
2023-08-10 17:27:29 -05:00
2023-08-10 17:27:29 -05:00
2023-08-10 17:27:29 -05:00
2023-08-10 17:27:29 -05:00
2023-08-10 17:27:29 -05:00
2023-08-18 07:47:24 +01:00
2024-01-12 15:48:30 -05:00
2024-01-12 15:48:30 -05:00
2023-10-12 12:21:48 -04:00
2023-08-10 17:27:29 -05:00
2023-08-10 17:27:29 -05:00
2023-08-10 17:27:29 -05:00
2023-11-15 10:07:18 -05:00
2023-11-15 10:07:18 -05:00
2023-08-10 17:27:29 -05:00
2023-08-10 17:27:29 -05:00
2023-08-10 17:27:29 -05:00
2023-08-10 17:27:29 -05:00
2023-08-10 17:27:29 -05:00
2023-08-10 17:27:29 -05:00
2023-08-10 17:27:29 -05:00
2023-08-10 17:27:29 -05:00
2023-08-10 17:27:29 -05:00
2023-08-10 17:27:29 -05:00
2023-10-24 11:00:11 -04:00
2023-08-10 17:27:29 -05:00
2023-08-10 17:27:29 -05:00
2023-08-10 17:27:29 -05:00
2023-08-10 17:27:29 -05:00
2023-08-18 07:47:24 +01:00
2023-12-08 08:46:55 -05:00
2023-11-22 08:02:49 +00:00
2023-09-21 17:56:33 +02:00
2023-09-21 17:56:33 +02:00