From f95e0a7568e5115dd536f19834083bff392458b8 Mon Sep 17 00:00:00 2001 From: Ophestra Date: Tue, 14 Oct 2025 07:02:14 +0900 Subject: hst/config: hold acl struct by value Doc comments are also reworded for clarity. Signed-off-by: Ophestra --- hst/config.go | 22 ++++++++++++++-------- hst/hst.go | 2 +- 2 files changed, 15 insertions(+), 9 deletions(-) (limited to 'hst') diff --git a/hst/config.go b/hst/config.go index bc542ccf..1b07755c 100644 --- a/hst/config.go +++ b/hst/config.go @@ -26,8 +26,8 @@ type Config struct { // and the bare socket is made available to the container. DirectWayland bool `json:"direct_wayland,omitempty"` - // Extra acl update ops to perform before setuid. - ExtraPerms []*ExtraPermConfig `json:"extra_perms,omitempty"` + // Extra acl updates to perform before setuid. + ExtraPerms []ExtraPermConfig `json:"extra_perms,omitempty"` // Numerical application id, passed to hsu, used to derive init user namespace credentials. Identity int `json:"identity"` @@ -86,15 +86,21 @@ func (config *Config) Validate() error { return nil } -// ExtraPermConfig describes an acl update op. +// ExtraPermConfig describes an acl update to perform before setuid. type ExtraPermConfig struct { - Ensure bool `json:"ensure,omitempty"` - Path *check.Absolute `json:"path"` - Read bool `json:"r,omitempty"` - Write bool `json:"w,omitempty"` - Execute bool `json:"x,omitempty"` + // Whether to create Path as a directory if it does not exist. + Ensure bool `json:"ensure,omitempty"` + // Pathname to act on. + Path *check.Absolute `json:"path"` + // Whether to set ACL_READ for the target user. + Read bool `json:"r,omitempty"` + // Whether to set ACL_WRITE for the target user. + Write bool `json:"w,omitempty"` + // Whether to set ACL_EXECUTE for the target user. + Execute bool `json:"x,omitempty"` } +// String returns a checked string representation of [ExtraPermConfig]. func (e *ExtraPermConfig) String() string { if e == nil || e.Path == nil { return "" diff --git a/hst/hst.go b/hst/hst.go index 11b2b279..c1511f6e 100644 --- a/hst/hst.go +++ b/hst/hst.go @@ -88,7 +88,7 @@ func Template() *Config { }, DirectWayland: false, - ExtraPerms: []*ExtraPermConfig{ + ExtraPerms: []ExtraPermConfig{ {Path: fhs.AbsVarLib.Append("hakurei/u0"), Ensure: true, Execute: true}, {Path: fhs.AbsVarLib.Append("hakurei/u0/org.chromium.Chromium"), Read: true, Write: true, Execute: true}, }, -- cgit v1.3.1