| Commit message (Collapse) | Author | Age | Lines | 
| |  | 
 | 
| | 
| 
| 
| 
| 
| 
| 
|  | 
The builddev script will build just the dev venv image. The testb
script will build the dev venv image, clean up dangling images, and
then run tests.
* Give the coverage commands their own header in the README
 | 
| | 
| 
| 
|  | 
Reflects the changes in 7a7eca52019bf21d21cdffcf03cd9c5eacd8363b
 | 
| | 
| 
| 
| 
| 
|  | 
* Make the report script do the normal coverage report instead of HTML
* Remove Docker image push scripts
* Add image build script for the venv image
 | 
| | 
| 
|  | 
Relock
 | 
| |\  
| | 
| |  | 
NsJail Tests
 | 
| | |  | 
 | 
| | |  | 
 | 
| | |  | 
 | 
| | | 
| | 
| | 
| | 
| |  | 
The error happens when either CONFIG_MEMCG_SWAP or
CONFIG_MEMCG_SWAP_ENABLED is disabled in the kernel.
 | 
| | | 
| | 
| | 
| | 
| | 
| | 
| | 
| | 
| |  | 
If memory swapping was enabled locally, the memory test would fail.
Explicitly disabling swapping also removes reliance on the assumption
that it'll be disabled in production.
* Add a constant for the maximum memory
* Simplify the timeout test; it'd otherwise first run out of memory now
 | 
| | | 
| | 
| | 
| |  | 
See microsoft/azure-pipelines-tasks#9704
 | 
| | |  | 
 | 
| | |  | 
 | 
| | |  | 
 | 
| | | 
| | 
| | 
| | 
| |  | 
* Add succeededOrFailed condition to code coverage publish task
* Rename test publish task for unit tests
 | 
| | |  | 
 | 
| | | 
| | 
| | 
| |  | 
* Exclude DEBUG checks from coverage reports
 | 
| | | 
| | 
| | 
| | 
| |  | 
* Add support for debug level to log regex
* Change type annotation of log_parse to Iterable
 | 
| | | 
| | 
| | 
| | 
| | 
| |  | 
* Fix SIGSEGV test
* Add embedded null byte test
* Return None for stderr when there's a ValueError
 | 
| | | 
| | 
| | 
| |  | 
Fixes #30
 | 
| | |  | 
 | 
| | | 
| | 
| | 
| | 
| | 
| |  | 
* Mount volume to the same path as the source directory on the host
* Keep the container up in the background so it doesn't have to be
  restarted or the ownership fix
 | 
| | | 
| | 
| | 
| | 
| | 
| |  | 
When coverage runs in a container, it is ran under root so the resulting
coverage file is owned by root. chown is used to change ownership to
be the same as the folder it is in.
 | 
| | | 
| | 
| | 
| |  | 
* Use unittest and directly use coverage.py instead of pytest
 | 
| | | 
| | 
| | 
| |  | 
* Put scripts in a new scripts folder
 | 
| | |  | 
 | 
| | | 
| | 
| | 
| | 
| | 
| | 
| |  | 
* Venv image can sync dev dependencies
* Copy tests to image
* Add a Pipenv script for running  a development shell in a container
* Add Pipenv scripts for building dev images
 | 
| |\| 
| | 
| |  | 
API Adjustments
 | 
| | | 
| | 
| | 
| | 
| | 
| | 
| | 
| |  | 
The handler now shares formats with the rest of the handlers. The
message is formatted to show the request method, URL + query, response
code, response size in bytes, and the request time in seconds.
* Use the default ISO 8601 date format for all handlers
 | 
| | | 
| | 
| | 
| | 
| | 
| | 
| |  | 
* Remove -S option from Python to re-enable importing of site module
* Add environment variable NSJAIL_PATH
* Remove environment variables that were passed to NsJail subprocess
* Add type annotations to NsJail.__init__()
 | 
| |/  
|   
|   
|   
|   
|    | 
Removes the need for redirecting stderr using contextlib in the input.
Furthermore, it captures errors which don't directly come from the
input, such as SyntaxErrors.
 | 
| |\  
| | 
| |  | 
Improve NsJail
 | 
| | | 
| | 
| | 
| | 
| | 
| | 
| | 
| | 
| |  | 
The previous implementation limited the client's flexibility in
presenting the results of the process. A process can write to both
stdout and stderr and do so even when the return code is not 0 or 1.
* Return a CompletedProcess from NsJail
* Don't check the return code; this should be done client-side now
 | 
| | | 
| | 
| | 
| | 
| |  | 
Gunicorn's access logger makes the middleware redundant.
This reverts commit c1c854e0ad4deb5c4fa8eb2a35b43a042f15255c.
 | 
| | | 
| | 
| | 
| | 
| | 
| | 
| | 
| | 
| | 
| | 
| |  | 
NsJail's is configured to log to a temporary file rather than stderr.
The contents of the file are parsed using regex after the process exits.
When not debugging, some blacklisted messages and most info-level
messages are skipped.
* Add a snekbox logger
* Log the Python code being executed if debugging
* Use nested single quotes in a test to fix a linter error
 | 
| | |\  
| |/  
|/|    | 
 | 
| |\ \  
| | | 
| | |  | 
Replace Flask with Falcon
 | 
| | | |  | 
 | 
| | | |  | 
 | 
| | | |  | 
 | 
| | | |  | 
 | 
| | | |  | 
 | 
| | | |  | 
 | 
| | | | 
| | | 
| | | 
| | | 
| | |  | 
This way, it is easier for tests to use the application because they
can instead create their own instances after patching.
 | 
| | | |  | 
 | 
| | | |  | 
 | 
| |/ /   | 
 | 
| | |  | 
 | 
| | | 
| | 
| | 
| | 
| |  | 
* Ignore D1xx for tests because they shouldn't require docstrings
* Update pre-commit-hooks repo to v2.2.3
 |