| 文件 | 最后提交记录 | 最后更新时间 |
|---|---|---|
network: enforce IPv4-only sandbox networking Conch network policies currently accept only IPv4 destinations, but guest IPv6 remained enabled during cold boot and CNI results were not checked comprehensively for IPv6 data. This could leave traffic outside the documented IPv4 policy boundary. Disable IPv6 on StratoVirt and Cloud Hypervisor cold boots. Reject CNI results containing IPv6 addresses, gateways, routes, or DNS servers before accepting a slot; existing slot-creation cleanup then performs CNI rollback. Document the IPv4-only contract and add focused command-generation and CNI result validation tests. Fixes Issue #167: https://github.com/ConchSandbox/Conch/issues/167 | 1 个月前 | |
fix(vmm): broadcast process exit state Preserve the VMM exit result for all readiness, stop, and wait paths. Use a shared completion signal and guard adapter cleanup so concurrent observers cannot consume or lose the exit result. Assisted-by: Codex:GPT-5.6-sol Signed-off-by: hu-zhangying <huzhangying@huawei.com> | 1 个月前 | |
network: enforce IPv4-only sandbox networking Conch network policies currently accept only IPv4 destinations, but guest IPv6 remained enabled during cold boot and CNI results were not checked comprehensively for IPv6 data. This could leave traffic outside the documented IPv4 policy boundary. Disable IPv6 on StratoVirt and Cloud Hypervisor cold boots. Reject CNI results containing IPv6 addresses, gateways, routes, or DNS servers before accepting a slot; existing slot-creation cleanup then performs CNI rollback. Document the IPv4-only contract and add focused command-generation and CNI result validation tests. Fixes Issue #167: https://github.com/ConchSandbox/Conch/issues/167 | 1 个月前 | |
docs: improve project documentation Documentation mixed user and developer guidance and still described outdated dependencies, commands, and runtime behavior. Organize documentation by audience, remove obsolete pages and assets, and align setup, template, network, and VMM guidance with the current implementation. Assisted-by: Codex:GPT-5.6-sol Signed-off-by: Yifan Zhao <stopire@gmail.com> | 1 个月前 | |
docs: improve project documentation Documentation mixed user and developer guidance and still described outdated dependencies, commands, and runtime behavior. Organize documentation by audience, remove obsolete pages and assets, and align setup, template, network, and VMM guidance with the current implementation. Assisted-by: Codex:GPT-5.6-sol Signed-off-by: Yifan Zhao <stopire@gmail.com> | 1 个月前 | |
refactor(sandbox): make resource cleanup explicit and idempotent | 20 天前 | |
refactor(sandbox): make resource cleanup explicit and idempotent | 20 天前 | |
fix(recovery): persist VMM state before startup Persist a CREATING sandbox record before starting runtime resources, then update it with the VMM PID and READY state after creation completes. Remove the CREATING record when creation returns, including failure paths after Conch has attempted its normal cleanup. Use recorded VMM PIDs as the primary cleanup path. Only scan /proc for configured VMM binaries when at least one stale record has no PID, covering a daemon exit before the PID update without scanning unnecessarily when every record is complete. Validate both recorded and scanned processes against configured VMM binary paths, and keep stale socket cleanup for legacy resources. Assisted-by: Codex:GPT-5.6-sol Signed-off-by: hu-zhangying <huzhangying@huawei.com> | 1 个月前 |
| 文件 | 最后提交记录 | 最后更新时间 |
|---|---|---|
| 1 个月前 | ||
| 1 个月前 | ||
| 1 个月前 | ||
| 1 个月前 | ||
| 1 个月前 | ||
| 20 天前 | ||
| 20 天前 | ||
| 1 个月前 |