aboutsummaryrefslogtreecommitdiffhomepage
diff options
context:
space:
mode:
authorOphestra Umiker <cat@ophivana.moe>2024-11-09 11:57:36 +0900
committerOphestra Umiker <cat@ophivana.moe>2024-11-09 12:01:34 +0900
commit9a13b311ac9b180a9a24e0d99a0487fb1997de32 (patch)
tree0fead98ffa0eedd7b67d50e2c46129c32447046b
parent45fead18c377abcf5138f26b4908389f34d2ba60 (diff)
app/config: rename map_real_uid from use_real_uid
This option only changes mapped uid in the user namespace. Signed-off-by: Ophestra Umiker <cat@ophivana.moe>
-rw-r--r--internal/app/config.go6
-rw-r--r--internal/app/seal.go2
-rw-r--r--nixos.nix4
3 files changed, 6 insertions, 6 deletions
diff --git a/internal/app/config.go b/internal/app/config.go
index 0c173170..96c51ce7 100644
--- a/internal/app/config.go
+++ b/internal/app/config.go
@@ -55,7 +55,7 @@ type SandboxConfig struct {
// do not run in new session
NoNewSession bool `json:"no_new_session,omitempty"`
// map target user uid to privileged user uid in the user namespace
- UseRealUID bool `json:"use_real_uid"`
+ MapRealUID bool `json:"map_real_uid"`
// mediated access to wayland socket
Wayland bool `json:"wayland,omitempty"`
@@ -92,7 +92,7 @@ func (s *SandboxConfig) Bwrap(os linux.System) (*bwrap.Config, error) {
}
var uid int
- if !s.UseRealUID {
+ if !s.MapRealUID {
uid = 65534
} else {
uid = os.Geteuid()
@@ -185,7 +185,7 @@ func Template() *Config {
UserNS: true,
Net: true,
NoNewSession: true,
- UseRealUID: true,
+ MapRealUID: true,
Dev: true,
Wayland: false,
// example API credentials pulled from Google Chrome
diff --git a/internal/app/seal.go b/internal/app/seal.go
index 0b60920f..0846a7f8 100644
--- a/internal/app/seal.go
+++ b/internal/app/seal.go
@@ -130,7 +130,7 @@ func (a *app) Seal(config *Config) error {
seal.sys = new(appSealSys)
// mapped uid
- if config.Confinement.Sandbox != nil && config.Confinement.Sandbox.UseRealUID {
+ if config.Confinement.Sandbox != nil && config.Confinement.Sandbox.MapRealUID {
seal.sys.mappedID = a.os.Geteuid()
} else {
seal.sys.mappedID = 65534
diff --git a/nixos.nix b/nixos.nix
index b6d72d7b..4757dabd 100644
--- a/nixos.nix
+++ b/nixos.nix
@@ -130,7 +130,7 @@ in
Whether to allow userns within sandbox.
'';
- useRealUid = mkEnableOption ''
+ mapRealUid = mkEnableOption ''
Whether to map to fortify's real UID within the sandbox.
'';
@@ -330,7 +330,7 @@ in
dev
env
;
- use_real_uid = launcher.useRealUid;
+ map_real_uid = launcher.mapRealUid;
filesystem =
[
{ src = "/bin"; }