diff options
| author | Ophestra <cat@gensokyo.uk> | 2025-06-25 03:59:52 +0900 |
|---|---|---|
| committer | Ophestra <cat@gensokyo.uk> | 2025-06-25 04:57:41 +0900 |
| commit | 87e008d56de974947ebb99c2cc40b25d3c2cf43e (patch) | |
| tree | 31791911e5226d6ec04e3fac7d91b0bf53e63aa5 /fst/config.go | |
| parent | 399207321265307bb15f37d867f9370cd51c82a8 (diff) | |
treewide: rename to hakurei
Fortify makes little sense for a container tool.
Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'fst/config.go')
| -rw-r--r-- | fst/config.go | 83 |
1 files changed, 0 insertions, 83 deletions
diff --git a/fst/config.go b/fst/config.go deleted file mode 100644 index 62c85701..00000000 --- a/fst/config.go +++ /dev/null @@ -1,83 +0,0 @@ -// Package fst exports shared fortify types. -package fst - -import ( - "git.gensokyo.uk/security/fortify/dbus" - "git.gensokyo.uk/security/fortify/system" -) - -const Tmp = "/.fortify" - -// Config is used to seal an app implementation. -type Config struct { - // reverse-DNS style arbitrary identifier string from config; - // passed to wayland security-context-v1 as application ID - // and used as part of defaults in dbus session proxy - ID string `json:"id"` - - // absolute path to executable file - Path string `json:"path,omitempty"` - // final args passed to container init - Args []string `json:"args"` - - // system services to make available in the container - Enablements system.Enablement `json:"enablements"` - - // session D-Bus proxy configuration; - // nil makes session bus proxy assume built-in defaults - SessionBus *dbus.Config `json:"session_bus,omitempty"` - // system D-Bus proxy configuration; - // nil disables system bus proxy - SystemBus *dbus.Config `json:"system_bus,omitempty"` - // direct access to wayland socket; when this gets set no attempt is made to attach security-context-v1 - // and the bare socket is mounted to the sandbox - DirectWayland bool `json:"direct_wayland,omitempty"` - - // passwd username in container, defaults to passwd name of target uid or chronos - Username string `json:"username,omitempty"` - // absolute path to shell, empty for host shell - Shell string `json:"shell,omitempty"` - // absolute path to home directory in the init mount namespace - Data string `json:"data"` - // directory to enter and use as home in the container mount namespace, empty for Data - Dir string `json:"dir"` - // extra acl ops, dispatches before container init - ExtraPerms []*ExtraPermConfig `json:"extra_perms,omitempty"` - - // numerical application id, used for init user namespace credentials - Identity int `json:"identity"` - // list of supplementary groups inherited by container processes - Groups []string `json:"groups"` - - // abstract container configuration baseline - Container *ContainerConfig `json:"container"` -} - -// ExtraPermConfig describes an acl update op. -type ExtraPermConfig struct { - Ensure bool `json:"ensure,omitempty"` - Path string `json:"path"` - Read bool `json:"r,omitempty"` - Write bool `json:"w,omitempty"` - Execute bool `json:"x,omitempty"` -} - -func (e *ExtraPermConfig) String() string { - buf := make([]byte, 0, 5+len(e.Path)) - buf = append(buf, '-', '-', '-') - if e.Ensure { - buf = append(buf, '+') - } - buf = append(buf, ':') - buf = append(buf, []byte(e.Path)...) - if e.Read { - buf[0] = 'r' - } - if e.Write { - buf[1] = 'w' - } - if e.Execute { - buf[2] = 'x' - } - return string(buf) -} |
