diff options
| author | Ophestra <cat@gensokyo.uk> | 2025-03-17 02:48:32 +0900 |
|---|---|---|
| committer | Ophestra <cat@gensokyo.uk> | 2025-03-17 02:48:32 +0900 |
| commit | 9ce4706a0766880c072cccd2643d66f614a6a16b (patch) | |
| tree | 075e4cf906065ca9c3eb6bacb6820b5786b6d496 /internal/sandbox | |
| parent | 9a1f8e129fe0f9919981b8a1d345a9b455bd76de (diff) | |
sandbox: move params setup functions
Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'internal/sandbox')
| -rw-r--r-- | internal/sandbox/container.go | 3 | ||||
| -rw-r--r-- | internal/sandbox/init.go | 7 | ||||
| -rw-r--r-- | internal/sandbox/params.go | 47 |
3 files changed, 51 insertions, 6 deletions
diff --git a/internal/sandbox/container.go b/internal/sandbox/container.go index f243ffd9..afbcc4fd 100644 --- a/internal/sandbox/container.go +++ b/internal/sandbox/container.go @@ -13,7 +13,6 @@ import ( "syscall" "time" - "git.gensokyo.uk/security/fortify/helper/proc" "git.gensokyo.uk/security/fortify/seccomp" ) @@ -163,7 +162,7 @@ func (p *Container) Start() error { } // place setup pipe before user supplied extra files, this is later restored by init - if fd, e, err := proc.Setup(&p.cmd.ExtraFiles); err != nil { + if fd, e, err := Setup(&p.cmd.ExtraFiles); err != nil { return wrapErrSuffix(err, "cannot create shim setup pipe:") } else { diff --git a/internal/sandbox/init.go b/internal/sandbox/init.go index 058fe9a2..a6fac1a3 100644 --- a/internal/sandbox/init.go +++ b/internal/sandbox/init.go @@ -13,7 +13,6 @@ import ( "syscall" "time" - "git.gensokyo.uk/security/fortify/helper/proc" "git.gensokyo.uk/security/fortify/seccomp" ) @@ -56,11 +55,11 @@ func Init(prepare func(prefix string), setVerbose func(verbose bool)) { setupFile *os.File offsetSetup int ) - if f, err := proc.Receive(setupEnv, ¶ms, &setupFile); err != nil { - if errors.Is(err, proc.ErrInvalid) { + if f, err := Receive(setupEnv, ¶ms, &setupFile); err != nil { + if errors.Is(err, ErrInvalid) { log.Fatal("invalid setup descriptor") } - if errors.Is(err, proc.ErrNotSet) { + if errors.Is(err, ErrNotSet) { log.Fatal("FORTIFY_SETUP not set") } diff --git a/internal/sandbox/params.go b/internal/sandbox/params.go new file mode 100644 index 00000000..5b698747 --- /dev/null +++ b/internal/sandbox/params.go @@ -0,0 +1,47 @@ +package sandbox + +import ( + "encoding/gob" + "errors" + "os" + "strconv" +) + +var ( + ErrNotSet = errors.New("environment variable not set") + ErrInvalid = errors.New("bad file descriptor") +) + +// Setup appends the read end of a pipe for setup params transmission and returns its fd. +func Setup(extraFiles *[]*os.File) (int, *gob.Encoder, error) { + if r, w, err := os.Pipe(); err != nil { + return -1, nil, err + } else { + fd := 3 + len(*extraFiles) + *extraFiles = append(*extraFiles, r) + return fd, gob.NewEncoder(w), nil + } +} + +// Receive retrieves setup fd from the environment and receives params. +func Receive(key string, e any, v **os.File) (func() error, error) { + var setup *os.File + + if s, ok := os.LookupEnv(key); !ok { + return nil, ErrNotSet + } else { + if fd, err := strconv.Atoi(s); err != nil { + return nil, err + } else { + setup = os.NewFile(uintptr(fd), "setup") + if setup == nil { + return nil, ErrInvalid + } + if v != nil { + *v = setup + } + } + } + + return setup.Close, gob.NewDecoder(setup).Decode(e) +} |
