-
Notifications
You must be signed in to change notification settings - Fork 0
All issues
Issue creation is restricted in this repository
Issues
is:issue state:open
is:issue state:open
Search results
A generated file under a read-only bind dies on bwrap's message, which names no fix
area:policyPolicy model, profiles, resolution, bwrap argvPolicy model, profiles, resolution, bwrap argvbugSomething isn't workingSomething isn't workingsev:lowConfirmed finding, low severity or papercutConfirmed finding, low severity or papercutStatus: Open.#580 In gomoni/snug;Review the builtin profile roster: @sys reads as /sys, @cwd-rw grants {target}, @git-ro binds nothing
area:policyPolicy model, profiles, resolution, bwrap argvPolicy model, profiles, resolution, bwrap argvenhancementNew feature or requestNew feature or requestquestionFurther information is requestedFurther information is requestedsev:lowConfirmed finding, low severity or papercutConfirmed finding, low severity or papercutStatus: Open.#578 In gomoni/snug;[identity] a signed commit reads as "No signature" inside the sandbox: gpg.ssh.allowedSignersFile is never authored
area:identityssh/git/gh identity pinning, the agent proxyssh/git/gh identity pinning, the agent proxyenhancementNew feature or requestNew feature or requestsev:lowConfirmed finding, low severity or papercutConfirmed finding, low severity or papercutStatus: Open.#576 In gomoni/snug;- Status: Open.#557 In gomoni/snug;
Research: what would Landlock add on top of bwrap + seccomp, and what would it cost
area:policyPolicy model, profiles, resolution, bwrap argvPolicy model, profiles, resolution, bwrap argvenhancementNew feature or requestNew feature or requestquestionFurther information is requestedFurther information is requestedStatus: Open.#551 In gomoni/snug;Redesign the secrets model: four per-tool adapters and a struct that grows a field per tool
area:identityssh/git/gh identity pinning, the agent proxyssh/git/gh identity pinning, the agent proxyenhancementNew feature or requestNew feature or requestStatus: Open.#549 In gomoni/snug;Idea: snug-in-snug — run a command in a stricter sandbox from inside a sandbox
area:supervisorThe stage, process topology, teardownThe stage, process topology, teardownenhancementNew feature or requestNew feature or requestquestionFurther information is requestedFurther information is requestedStatus: Open.#509 In gomoni/snug;Research: can systemd-nsresourced replace the /etc/subuid + newuidmap requirement for the engine's stage?
area:supervisorThe stage, process topology, teardownThe stage, process topology, teardownenhancementNew feature or requestNew feature or requestquestionFurther information is requestedFurther information is requestedStatus: Open.#482 In gomoni/snug;Idea, needs research: a profile cannot bind whichever host path exists AND point a variable at it
area:policyPolicy model, profiles, resolution, bwrap argvPolicy model, profiles, resolution, bwrap argvenhancementNew feature or requestNew feature or requestquestionFurther information is requestedFurther information is requestedStatus: Open.#477 In gomoni/snug;@http-proxy needs a staged adapter for servers that only bind a port (Java, .NET, containers)
area:proxyThe podman socket proxy and build filterThe podman socket proxy and build filterenhancementNew feature or requestNew feature or requestStatus: Open.#476 In gomoni/snug;Research: /login inside the sandbox — the callback, the browser, and what must not become a refresh token
area:identityssh/git/gh identity pinning, the agent proxyssh/git/gh identity pinning, the agent proxyenhancementNew feature or requestNew feature or requestquestionFurther information is requestedFurther information is requestedStatus: Open.#455 In gomoni/snug;- Status: Open.#417 In gomoni/snug;