diff options
| author | Ophestra Umiker <cat@ophivana.moe> | 2024-10-10 14:33:58 +0900 |
|---|---|---|
| committer | Ophestra Umiker <cat@ophivana.moe> | 2024-10-10 14:33:58 +0900 |
| commit | a3aadd4146c0249b41e11691c2930b3ef3c321ba (patch) | |
| tree | 8805b3c0e971f47a8f144d8f28b22f71580bade2 /internal/app/share.runtime.go | |
| parent | 86cb5ac1dbd581078b10f5ec1eb723549c662a1b (diff) | |
app: tag ACL operations for revert
ACL operations are now tagged with the enablement causing them. At the end of child process's life, enablements of all remaining launchers are resolved and inverted. This allows Wait to only revert operations targeting resources no longer required by other launchers.
Signed-off-by: Ophestra Umiker <cat@ophivana.moe>
Diffstat (limited to 'internal/app/share.runtime.go')
| -rw-r--r-- | internal/app/share.runtime.go | 9 |
1 files changed, 5 insertions, 4 deletions
diff --git a/internal/app/share.runtime.go b/internal/app/share.runtime.go index 444d85a2..b015d45c 100644 --- a/internal/app/share.runtime.go +++ b/internal/app/share.runtime.go @@ -4,6 +4,7 @@ import ( "path" "git.ophivana.moe/cat/fortify/acl" + "git.ophivana.moe/cat/fortify/internal/state" ) const ( @@ -16,10 +17,10 @@ const ( func (seal *appSeal) shareRuntime() { // ensure RunDir (e.g. `/run/user/%d/fortify`) seal.sys.ensure(seal.RunDirPath, 0700) - seal.sys.updatePerm(seal.RunDirPath, acl.Execute) + seal.sys.updatePermTag(state.EnableLength, seal.RunDirPath, acl.Execute) // ensure runtime directory ACL (e.g. `/run/user/%d`) - seal.sys.updatePerm(seal.RuntimePath, acl.Execute) + seal.sys.updatePermTag(state.EnableLength, seal.RuntimePath, acl.Execute) // ensure Share (e.g. `/tmp/fortify.%d`) // acl is unnecessary as this directory is world executable @@ -40,12 +41,12 @@ func (seal *appSeal) shareRuntimeChild() string { // ensure child runtime parent directory (e.g. `/tmp/fortify.%d/runtime`) targetRuntimeParent := path.Join(seal.SharePath, "runtime") seal.sys.ensure(targetRuntimeParent, 0700) - seal.sys.updatePerm(targetRuntimeParent, acl.Execute) + seal.sys.updatePermTag(state.EnableLength, targetRuntimeParent, acl.Execute) // ensure child runtime directory (e.g. `/tmp/fortify.%d/runtime/%d`) targetRuntime := path.Join(targetRuntimeParent, seal.sys.Uid) seal.sys.ensure(targetRuntime, 0700) - seal.sys.updatePerm(targetRuntime, acl.Read, acl.Write, acl.Execute) + seal.sys.updatePermTag(state.EnableLength, targetRuntime, acl.Read, acl.Write, acl.Execute) // point to ensured runtime path seal.appendEnv(xdgRuntimeDir, targetRuntime) |
