From dfcdc5ce20fb163a729efc0ea960480dff129eae Mon Sep 17 00:00:00 2001 From: Ophestra Date: Tue, 21 Jan 2025 12:10:58 +0900 Subject: state: store config in separate gob stream This enables early serialisation of config. Signed-off-by: Ophestra --- internal/app/seal.go | 14 +++++++++++++- 1 file changed, 13 insertions(+), 1 deletion(-) (limited to 'internal/app/seal.go') diff --git a/internal/app/seal.go b/internal/app/seal.go index 35cd316e..bd0522a6 100644 --- a/internal/app/seal.go +++ b/internal/app/seal.go @@ -1,8 +1,11 @@ package app import ( + "bytes" + "encoding/gob" "errors" "fmt" + "io" "io/fs" "path" "regexp" @@ -47,6 +50,8 @@ type appSeal struct { // pass-through enablement tracking from config et system.Enablements + // initial config gob encoding buffer + ct io.WriterTo // pass-through seccomp config from config scmp *fst.SyscallConfig // wayland socket direct access @@ -87,6 +92,14 @@ func (a *app) Seal(config *fst.Config) error { // create seal seal := new(appSeal) + // encode initial configuration for state tracking + ct := new(bytes.Buffer) + if err := gob.NewEncoder(ct).Encode(config); err != nil { + return fmsg.WrapErrorSuffix(err, + "cannot encode initial config:") + } + seal.ct = ct + // fetch system constants seal.Paths = a.os.Paths() @@ -261,6 +274,5 @@ func (a *app) Seal(config *fst.Config) error { // seal app and release lock a.seal = seal - a.ct = newAppCt(config) return nil } -- cgit v1.3.1