index
:
~lukeshu/systemd
elogind/master
eudev/master
notsystemd/master
notsystemd/postmove
notsystemd/premove
notsystemd/wip/cgroup2
notsystemd/wip/nspawn
notsystemd/wip/nspawn-parse
systemd/master
systemd/parabola
Unnamed repository; edit this file 'description' to name the repository.
git-mirror
summary
refs
log
tree
commit
diff
log msg
author
committer
range
path:
root
/
man
/
systemd.exec.xml
Age
Commit message (
Expand
)
Author
2016-11-17
namespace: simplify, optimize and extend handling of mounts for namespace
Lennart Poettering
2016-11-15
doc: move ProtectKernelModules= documentation near ProtectKernelTunalbes=
Djalal Harouni
2016-11-15
doc: note when no new privileges is implied
Djalal Harouni
2016-11-04
core: add new RestrictNamespaces= unit file setting
Lennart Poettering
2016-11-03
Merge pull request #4548 from keszybz/seccomp-help
Zbigniew Jędrzejewski-Szmek
2016-11-03
doc: clarify NoNewPrivileges (#4562)
Kees Cook
2016-11-03
seccomp-util, analyze: export comments as a help string
Zbigniew Jędrzejewski-Szmek
2016-11-03
analyze: add syscall-filter verb
Zbigniew Jędrzejewski-Szmek
2016-11-02
man: document that too strict system call filters may affect the service manager
Lennart Poettering
2016-11-02
seccomp: add two new syscall groups
Lennart Poettering
2016-11-02
man: two minor fixes
Lennart Poettering
2016-11-02
seccomp: include pipes and memfd in @ipc
Lennart Poettering
2016-11-02
seccomp: drop execve() from @process list
Lennart Poettering
2016-11-02
seccomp: add clock query and sleeping syscalls to "@default" group
Lennart Poettering
2016-11-01
seccomp: allow specifying arm64, mips, ppc (#4491)
Zbigniew Jędrzejewski-Szmek
2016-10-31
man: fix typos (#4527)
Jakub Wilk
2016-10-28
Merge pull request #4495 from topimiettinen/block-shmat-exec
Djalal Harouni
2016-10-26
seccomp: also block shmat(..., SHM_EXEC) for MemoryDenyWriteExecute
Topi Miettinen
2016-10-24
man: document the default value of NoNewPrivileges=
Zbigniew Jędrzejewski-Szmek
2016-10-20
man: document default for User=
Lennart Poettering
2016-10-17
core/exec: add a named-descriptor option ("fd") for streams (#4179)
Luca Bruno
2016-10-17
man: avoid abbreviated "cgroups" terminology (#4396)
Lennart Poettering
2016-10-15
man: add crosslink between systemd.resource-control(5) and systemd.exec(5)
Zbigniew Jędrzejewski-Szmek
2016-10-13
Merge pull request #4243 from endocode/djalal/sandbox-first-protection-kernel...
Lennart Poettering
2016-10-12
man: typo fixes
Thomas Hindoe Paaboel Andersen
2016-10-12
core:sandbox: lets make /lib/modules/ inaccessible on ProtectKernelModules=
Djalal Harouni
2016-10-12
doc: minor hint about InaccessiblePaths= in regard of ProtectKernelTunables=
Djalal Harouni
2016-10-12
core:sandbox: remove CAP_SYS_RAWIO on PrivateDevices=yes
Djalal Harouni
2016-10-12
core:sandbox: Add ProtectKernelModules= option
Djalal Harouni
2016-10-11
Merge pull request #4348 from poettering/docfixes
Zbigniew Jędrzejewski-Szmek
2016-10-11
man: beef up documentation on per-unit resource limits a bit
Lennart Poettering
2016-10-07
core: add "invocation ID" concept to service manager
Lennart Poettering
2016-10-05
seccomp: add support for the s390 architecture (#4287)
hbrueckner
2016-10-03
man: remove consecutive duplicate words (#4268)
Stefan Schweter
2016-09-25
core: Use @raw-io syscall group to filter I/O syscalls when PrivateDevices= i...
Djalal Harouni
2016-09-25
core:sandbox: add more /proc/* entries to ProtectKernelTunables=
Djalal Harouni
2016-09-25
doc: explicitly document that /dev/mem and /dev/port are blocked by PrivateDe...
Djalal Harouni
2016-09-25
doc: documentation fixes for ReadWritePaths= and ProtectKernelTunables=
Djalal Harouni
2016-09-25
man: shorten the exit status table a bit
Lennart Poettering
2016-09-25
man: the exit code/signal is stored in $EXIT_CODE, not $EXIT_STATUS
Lennart Poettering
2016-09-25
man: rework documentation for ReadOnlyPaths= and related settings
Lennart Poettering
2016-09-25
man: in user-facing documentaiton don't reference C function names
Lennart Poettering
2016-09-25
core: imply ProtectHome=read-only and ProtectSystem=strict if DynamicUser=1
Lennart Poettering
2016-09-25
core: introduce ProtectSystem=strict
Lennart Poettering
2016-09-25
core: add two new service settings ProtectKernelTunables= and ProtectControlG...
Lennart Poettering
2016-08-19
core: add RemoveIPC= setting
Lennart Poettering
2016-08-11
man: add "timeout" to status table (#3919)
Zbigniew Jędrzejewski-Szmek
2016-08-07
Merge pull request #3914 from keszybz/fix-man-links
Lennart Poettering
2016-08-07
man: add a table of possible exit statuses (#3910)
Zbigniew Jędrzejewski-Szmek
2016-08-06
Merge pull request #3884 from poettering/private-users
Zbigniew Jędrzejewski-Szmek
[next]