diff options
| author | Ophestra <cat@gensokyo.uk> | 2025-01-22 02:01:01 +0900 |
|---|---|---|
| committer | Ophestra <cat@gensokyo.uk> | 2025-01-22 11:49:23 +0900 |
| commit | 8c51012ef5df1b421a21ae5117fcf66460087fd5 (patch) | |
| tree | 1c12c784a85c33e7b87ffd2356ff272d0e681a6e /dbus | |
| parent | 5a64cdaf4fedf4cc12f4574f07e1376e907aa7d8 (diff) | |
dbus: enable syscall filter
Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'dbus')
| -rw-r--r-- | dbus/dbus_test.go | 4 | ||||
| -rw-r--r-- | dbus/run.go | 7 |
2 files changed, 8 insertions, 3 deletions
diff --git a/dbus/dbus_test.go b/dbus/dbus_test.go index 717ded71..7128c08a 100644 --- a/dbus/dbus_test.go +++ b/dbus/dbus_test.go @@ -141,7 +141,7 @@ func testProxyStartWaitCloseString(t *testing.T, sandbox bool) { t.Run("unsealed start of "+id, func(t *testing.T) { want := "proxy not sealed" - if err := p.Start(nil, nil, sandbox); err == nil || err.Error() != want { + if err := p.Start(nil, nil, sandbox, false); err == nil || err.Error() != want { t.Errorf("Start() error = %v, wantErr %q", err, errors.New(want)) return @@ -175,7 +175,7 @@ func testProxyStartWaitCloseString(t *testing.T, sandbox bool) { } t.Run("sealed start of "+id, func(t *testing.T) { - if err := p.Start(nil, output, sandbox); err != nil { + if err := p.Start(nil, output, sandbox, false); err != nil { t.Fatalf("Start(nil, nil) error = %v", err) } diff --git a/dbus/run.go b/dbus/run.go index 0a554bfb..0dfe7f85 100644 --- a/dbus/run.go +++ b/dbus/run.go @@ -16,7 +16,7 @@ import ( // Start launches the D-Bus proxy and sets up the Wait method. // ready should be buffered and must only be received from once. -func (p *Proxy) Start(ready chan error, output io.Writer, sandbox bool) error { +func (p *Proxy) Start(ready chan error, output io.Writer, sandbox, seccomp bool) error { p.lock.Lock() defer p.lock.Unlock() @@ -67,11 +67,16 @@ func (p *Proxy) Start(ready chan error, output io.Writer, sandbox bool) error { Unshare: nil, Hostname: "fortify-dbus", Chdir: "/", + Syscall: &bwrap.SyscallPolicy{DenyDevel: true, Multiarch: true}, Clearenv: true, NewSession: true, DieWithParent: true, } + if !seccomp { + bc.Syscall = nil + } + // resolve proxy socket directories bindTarget := make(map[string]struct{}, 2) for _, ps := range []string{p.session[1], p.system[1]} { |
