Skip to content

History / nftables Monitoring Internals

Revisions

  • docs: sync from coipond/coi-wiki (binary, pre_launch, protected branches, health --fix) Mirror of coi-wiki c8a4cd8 (docs/binary-pre-launch-guard-health), flattened: [tool] binary and pre_launch, [git] protected_branches, `coi health --fix`, visudo-validated sudoers instructions, current reverse-shell detection behavior, and the large-UID subuid/subgid fix. Also renames Updating-COI.md -> Updating-Coi.md, matching coi-wiki and the existing [Updating Coi](Updating-Coi) links, which pointed at a page that didn't exist under that name here.

    @mensfeld mensfeld committed Oct 2, 2026
  • docs: update repo references mensfeld/coi -> coipond/coi (org transfer)

    @mensfeld mensfeld committed Sep 30, 2026
  • docs: align wiki to the Karafka writing style Style-only pass across 39 pages: reduce decorative bold to scannable labels and callouts, Title Case headings, expand contractions, present tense, US English, cut filler and --- separators, tag code fences. Commands, code, config, COI_* env vars, paths, URLs, wiki links/anchors, and tables left unchanged.

    @mensfeld mensfeld committed Sep 30, 2026
  • docs: point URLs at mensfeld/coi + fix leftover code-on-incus branding Repo renamed mensfeld/code-on-incus -> mensfeld/coi: update all wiki links (install.sh raw URL, issues/releases/tree/wiki links) and one leftover "code-on-incus" prose ref -> Coi.

    @mensfeld mensfeld committed Sep 29, 2026
  • docs: rebrand to Coi (drop all-caps COI; Coi primary, coi command) COI -> Coi across all pages; sidebar + Home first-mention use "Coi (Code on Incus)". Preserved: COI_* env-var names and the literal "# COI Sandbox ..." context markers (they document the actual on-disk marker text). Lowercase coi commands unchanged.

    @mensfeld mensfeld committed Sep 29, 2026
  • Align wiki with 0.11.1: OrbStack guide, filesystem-first UID mapping, dir-pool health warning, idempotent context injection, version-fix note - macOS Setup Guide: OrbStack is now a first-class documented option (setup steps, how COI handles the FUSE-backed macOS share via raw.idmap, the OrbStack >=2.2.2 silent-breakage background, storage notes); 'How It Works' rewritten around the v0.11.1 filesystem check with the reactive fallback; Manual Override reframed as rarely needed; Colima instructions now install Incus from Zabbly (Ubuntu's 6.0 is below the required 6.1). - Configuration/Architecture/File-Transfer/FAQ pages: UID-mapping mechanism descriptions updated (auto-selected shift vs raw.idmap), disable_shift comment rewritten, Colima-only framing widened to Colima/Lima/OrbStack. - System Health Check/Troubleshooting/Best Practices/Getting Started/ Linux Setup Guide: dir-pool driver warning documented (detection, cost, fix), example output shows the new 'pool (driver)' label, manual-setup example no longer recommends a dir pool, Zabbly note reframed around the automatic raw.idmap recovery, #673 version/update known-issue note added. - Troubleshooting/Supported-Tools/Profiles: idempotent marker-delimited sandbox-context injection documented incl. auto-healing of bloated files; tool interface snippets synced (AlwaysSetupConfig, full effort level list). - nftables internals: NFT monitoring is disabled by default. - Nav (Home/Sidebar/Footer): 0.10.1->0.11.0 migration links; FAQ count fix; IPv6 host-side blocking wording.

    @mensfeld mensfeld committed Aug 10, 2026
  • Add nftables Monitoring Internals page (ported from repo docs/NFT-MONITORING.md) Moves the nftables monitoring technical deep-dive out of the code repo and into the wiki as a dedicated internals page, cross-linked from Security-Monitoring and the sidebar. Fixed a stale detail from the original: LOG rules are inserted at the top of the ip filter FORWARD chain (priority 0 + nft insert), not placed via a per-rule priority -5/-10 (nftables has no per-rule priority).

    @mensfeld mensfeld committed Jul 27, 2026