aboutsummaryrefslogtreecommitdiffhomepage
path: root/internal/app/share.system.go
diff options
context:
space:
mode:
authorOphestra Umiker <cat@ophivana.moe>2024-10-18 01:21:58 +0900
committerOphestra Umiker <cat@ophivana.moe>2024-10-18 01:21:58 +0900
commit65bd7d18dbf35216d0a70c102a732c6356caee85 (patch)
treeca3b54f9f2180d56042d335806dec7e3aec138f7 /internal/app/share.system.go
parent4ebb98649e8e05d88b71c629a9c1e023e51906ca (diff)
app/share: fix order to ensure SharePath before any of its subdirectories
shareTmpdirChild happened to request an ephemeral dir within SharePath and was called before shareRuntime which ensures that path. This commit moves SharePath initialisation to shareSystem and moves shareTmpdirChild into ShareSystem. Further cleanup and tests are desperately needed for the app package but for now this fix will have to do. Signed-off-by: Ophestra Umiker <cat@ophivana.moe>
Diffstat (limited to 'internal/app/share.system.go')
-rw-r--r--internal/app/share.system.go43
1 files changed, 25 insertions, 18 deletions
diff --git a/internal/app/share.system.go b/internal/app/share.system.go
index e4c848bb..9b2565a8 100644
--- a/internal/app/share.system.go
+++ b/internal/app/share.system.go
@@ -14,6 +14,31 @@ const (
// shareSystem queues various system-related actions
func (seal *appSeal) shareSystem() {
+ // ensure Share (e.g. `/tmp/fortify.%d`)
+ // acl is unnecessary as this directory is world executable
+ seal.sys.Ensure(seal.SharePath, 0701)
+
+ // ensure process-specific share (e.g. `/tmp/fortify.%d/%s`)
+ // acl is unnecessary as this directory is world executable
+ seal.share = path.Join(seal.SharePath, seal.id.String())
+ seal.sys.Ephemeral(system.Process, seal.share, 0701)
+
+ // ensure child tmpdir parent directory (e.g. `/tmp/fortify.%d/tmpdir`)
+ targetTmpdirParent := path.Join(seal.SharePath, "tmpdir")
+ seal.sys.Ensure(targetTmpdirParent, 0700)
+ seal.sys.UpdatePermType(system.User, targetTmpdirParent, acl.Execute)
+
+ // ensure child tmpdir (e.g. `/tmp/fortify.%d/tmpdir/%d`)
+ targetTmpdir := path.Join(targetTmpdirParent, seal.sys.user.Uid)
+ seal.sys.Ensure(targetTmpdir, 01700)
+ seal.sys.UpdatePermType(system.User, targetTmpdir, acl.Read, acl.Write, acl.Execute)
+ seal.sys.bwrap.Bind(targetTmpdir, "/tmp", false, true)
+
+ // mount tmpfs on inner shared directory (e.g. `/tmp/fortify.%d`)
+ seal.sys.bwrap.Tmpfs(seal.SharePath, 1*1024*1024)
+}
+
+func (seal *appSeal) sharePasswd() {
// look up shell
sh := "/bin/sh"
if s, ok := os.LookupEnv(shell); ok {
@@ -44,21 +69,3 @@ func (seal *appSeal) shareSystem() {
seal.sys.bwrap.Bind(passwdPath, "/etc/passwd")
seal.sys.bwrap.Bind(groupPath, "/etc/group")
}
-
-func (seal *appSeal) shareTmpdirChild() string {
- // ensure child tmpdir parent directory (e.g. `/tmp/fortify.%d/tmpdir`)
- targetTmpdirParent := path.Join(seal.SharePath, "tmpdir")
- seal.sys.Ensure(targetTmpdirParent, 0700)
- seal.sys.UpdatePermType(system.User, targetTmpdirParent, acl.Execute)
-
- // ensure child tmpdir (e.g. `/tmp/fortify.%d/tmpdir/%d`)
- targetTmpdir := path.Join(targetTmpdirParent, seal.sys.user.Uid)
- seal.sys.Ensure(targetTmpdir, 01700)
- seal.sys.UpdatePermType(system.User, targetTmpdir, acl.Read, acl.Write, acl.Execute)
- seal.sys.bwrap.Bind(targetTmpdir, "/tmp", false, true)
-
- // mount tmpfs on inner shared directory (e.g. `/tmp/fortify.%d`)
- seal.sys.bwrap.Tmpfs(seal.SharePath, 1*1024*1024)
-
- return targetTmpdir
-}