aboutsummaryrefslogtreecommitdiffhomepage
path: root/internal/app/share.system.go
diff options
context:
space:
mode:
authorOphestra Umiker <cat@ophivana.moe>2024-11-16 21:19:45 +0900
committerOphestra Umiker <cat@ophivana.moe>2024-11-16 21:19:45 +0900
commitdf33123bd7f1e0cb4e98580b7e63818c82aa7206 (patch)
tree8b21831634e6169eb875cbfd359fa4006d6c66b3 /internal/app/share.system.go
parent1a09b55bd4753c6d5cbecf96d1b56f23b0e44b95 (diff)
app: integrate fsu
This removes the dependency on external user switchers like sudo/machinectl and decouples fortify user ids from the passwd database. Signed-off-by: Ophestra Umiker <cat@ophivana.moe>
Diffstat (limited to 'internal/app/share.system.go')
-rw-r--r--internal/app/share.system.go24
1 files changed, 15 insertions, 9 deletions
diff --git a/internal/app/share.system.go b/internal/app/share.system.go
index 08b006c3..7c97c48a 100644
--- a/internal/app/share.system.go
+++ b/internal/app/share.system.go
@@ -16,12 +16,12 @@ const (
func (seal *appSeal) shareSystem() {
// ensure Share (e.g. `/tmp/fortify.%d`)
// acl is unnecessary as this directory is world executable
- seal.sys.Ensure(seal.SharePath, 0701)
+ seal.sys.Ensure(seal.SharePath, 0711)
// ensure process-specific share (e.g. `/tmp/fortify.%d/%s`)
// acl is unnecessary as this directory is world executable
seal.share = path.Join(seal.SharePath, seal.id)
- seal.sys.Ephemeral(system.Process, seal.share, 0701)
+ seal.sys.Ephemeral(system.Process, seal.share, 0711)
// ensure child tmpdir parent directory (e.g. `/tmp/fortify.%d/tmpdir`)
targetTmpdirParent := path.Join(seal.SharePath, "tmpdir")
@@ -29,7 +29,7 @@ func (seal *appSeal) shareSystem() {
seal.sys.UpdatePermType(system.User, targetTmpdirParent, acl.Execute)
// ensure child tmpdir (e.g. `/tmp/fortify.%d/tmpdir/%d`)
- targetTmpdir := path.Join(targetTmpdirParent, seal.sys.user.Uid)
+ targetTmpdir := path.Join(targetTmpdirParent, seal.sys.user.as)
seal.sys.Ensure(targetTmpdir, 01700)
seal.sys.UpdatePermType(system.User, targetTmpdir, acl.Read, acl.Write, acl.Execute)
seal.sys.bwrap.Bind(targetTmpdir, "/tmp", false, true)
@@ -49,15 +49,21 @@ func (seal *appSeal) sharePasswd(os linux.System) {
// generate /etc/passwd
passwdPath := path.Join(seal.share, "passwd")
username := "chronos"
- if seal.sys.user.Username != "" {
- username = seal.sys.user.Username
- seal.sys.bwrap.SetEnv["USER"] = seal.sys.user.Username
+ if seal.sys.user.username != "" {
+ username = seal.sys.user.username
}
homeDir := "/var/empty"
- if seal.sys.user.HomeDir != "" {
- homeDir = seal.sys.user.HomeDir
- seal.sys.bwrap.SetEnv["HOME"] = seal.sys.user.HomeDir
+ if seal.sys.user.home != "" {
+ homeDir = seal.sys.user.home
}
+
+ // bind home directory
+ seal.sys.bwrap.Bind(homeDir, homeDir, false, true)
+ seal.sys.bwrap.Chdir = homeDir
+
+ seal.sys.bwrap.SetEnv["USER"] = username
+ seal.sys.bwrap.SetEnv["HOME"] = homeDir
+
passwd := username + ":x:" + seal.sys.mappedIDString + ":" + seal.sys.mappedIDString + ":Fortify:" + homeDir + ":" + sh + "\n"
seal.sys.Write(passwdPath, passwd)