From b9e2003d5b078a0704ee751aec80cfe8b4434646 Mon Sep 17 00:00:00 2001 From: Ophestra Date: Sat, 28 Dec 2024 14:07:49 +0900 Subject: app: ensure extra paths The primary use case for extra perms is app-specific state directories, which may or may not exist (first run of any app). Signed-off-by: Ophestra --- internal/app/seal.go | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) (limited to 'internal/app/seal.go') diff --git a/internal/app/seal.go b/internal/app/seal.go index 82b7983e..27663771 100644 --- a/internal/app/seal.go +++ b/internal/app/seal.go @@ -63,8 +63,9 @@ type appSeal struct { } type sealedExtraPerm struct { - name string - perms acl.Perms + name string + perms acl.Perms + ensure bool } // Seal seals the app launch context @@ -169,6 +170,7 @@ func (a *app) Seal(config *fst.Config) error { if p.Execute { seal.extraPerms[i].perms = append(seal.extraPerms[i].perms, acl.Execute) } + seal.extraPerms[i].ensure = p.Ensure } // map sandbox config to bwrap -- cgit v1.3.1