diff options
| author | Ophestra <cat@gensokyo.uk> | 2025-02-17 19:00:43 +0900 |
|---|---|---|
| committer | Ophestra <cat@gensokyo.uk> | 2025-02-17 19:00:43 +0900 |
| commit | 90cb01b2748550228d0bc179691a19ebb996fc36 (patch) | |
| tree | 06a2e17b578312c3f0734bf4c476e3c2eb5f6908 /system/acl.go | |
| parent | b1e1d5627e6532ec719c761846d7f38fe93fcadd (diff) | |
system: move out of internal
Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'system/acl.go')
| -rw-r--r-- | system/acl.go | 65 |
1 files changed, 65 insertions, 0 deletions
diff --git a/system/acl.go b/system/acl.go new file mode 100644 index 00000000..840c3971 --- /dev/null +++ b/system/acl.go @@ -0,0 +1,65 @@ +package system + +import ( + "fmt" + "slices" + + "git.gensokyo.uk/security/fortify/acl" +) + +// UpdatePerm appends an ephemeral acl update Op. +func (sys *I) UpdatePerm(path string, perms ...acl.Perm) *I { + sys.UpdatePermType(Process, path, perms...) + + return sys +} + +// UpdatePermType appends an acl update Op. +func (sys *I) UpdatePermType(et Enablement, path string, perms ...acl.Perm) *I { + sys.lock.Lock() + defer sys.lock.Unlock() + + sys.ops = append(sys.ops, &ACL{et, path, perms}) + + return sys +} + +type ACL struct { + et Enablement + path string + perms acl.Perms +} + +func (a *ACL) Type() Enablement { return a.et } + +func (a *ACL) apply(sys *I) error { + sys.println("applying ACL", a) + return sys.wrapErrSuffix(acl.UpdatePerm(a.path, sys.uid, a.perms...), + fmt.Sprintf("cannot apply ACL entry to %q:", a.path)) +} + +func (a *ACL) revert(sys *I, ec *Criteria) error { + if ec.hasType(a) { + sys.println("stripping ACL", a) + return sys.wrapErrSuffix(acl.UpdatePerm(a.path, sys.uid), + fmt.Sprintf("cannot strip ACL entry from %q:", a.path)) + } else { + sys.println("skipping ACL", a) + return nil + } +} + +func (a *ACL) Is(o Op) bool { + a0, ok := o.(*ACL) + return ok && a0 != nil && + a.et == a0.et && + a.path == a0.path && + slices.Equal(a.perms, a0.perms) +} + +func (a *ACL) Path() string { return a.path } + +func (a *ACL) String() string { + return fmt.Sprintf("%s type: %s path: %q", + a.perms, TypeString(a.et), a.path) +} |
