Iago Lopez Galeiras
b1994387d3
core: use LSM BPF functions to implement RestrictFileSystems=
...
It attaches the LSM BPF program when the system manager starts up.
It populates the hash of maps BPF map when services that have
RestrictFileSystems= set start.
It cleans up the hash of maps when the unit cgroup is pruned.
To pass the file descriptor of the BPF map we add it to the keep_fds
array.
2021-10-06 10:52:14 +02:00
..
2021-09-28 14:52:27 +01:00
2021-10-06 10:52:14 +02:00
2021-10-05 16:14:37 +02:00
2021-10-05 16:14:37 +02:00
2021-08-20 18:29:40 +01:00
2021-10-06 10:52:14 +02:00
2021-10-05 15:47:32 +02:00
2021-09-22 12:58:46 +02:00
2021-10-05 16:14:37 +02:00
2021-09-28 16:47:08 +02:00
2021-10-05 16:14:37 +02:00
2021-10-05 16:14:37 +02:00
2021-09-14 03:04:57 +09:00
2021-10-05 16:14:37 +02:00
2021-10-05 16:14:37 +02:00
2021-09-23 17:24:10 +02:00
2021-08-31 09:06:33 +01:00
2021-10-05 16:14:37 +02:00
2021-09-15 16:46:07 +02:00
2021-08-30 22:25:04 +09:00
2021-09-10 13:39:16 +02:00
2021-10-05 15:47:32 +02:00
2021-09-15 13:09:45 +02:00
2021-10-05 16:14:37 +02:00
2021-09-22 12:58:46 +02:00
2021-10-05 16:14:37 +02:00
2021-09-29 15:29:41 +09:00
2021-10-05 16:14:37 +02:00
2021-09-29 03:37:06 +09:00
2021-08-20 11:09:48 +02:00
2021-10-05 16:14:37 +02:00
2021-10-04 18:26:24 +09:00
2021-10-05 19:37:30 +01:00
2021-09-15 13:09:45 +02:00
2021-09-27 20:34:41 +02:00
2021-10-06 12:27:27 +09:00
2021-10-05 16:14:37 +02:00
2021-10-05 15:47:32 +02:00
2021-10-01 17:27:34 +01:00
2021-10-01 14:45:00 +02:00
2021-09-28 14:52:27 +01:00
2021-10-06 10:52:14 +02:00
2021-10-05 15:47:32 +02:00
2021-10-05 16:14:37 +02:00
2021-10-05 16:14:37 +02:00
2021-09-30 00:08:16 +09:00
2021-10-05 15:47:32 +02:00
2021-10-06 12:27:27 +09:00
2021-10-05 16:14:37 +02:00
2021-10-05 16:14:37 +02:00
2021-10-05 16:14:37 +02:00
2021-10-05 16:14:37 +02:00
2021-09-22 22:34:37 +01:00
2021-08-20 11:09:48 +02:00
2021-10-05 16:14:37 +02:00