apparmor.d/pkg/prebuild/directive/exec.go

63 lines
1.4 KiB
Go
Raw Normal View History

2024-03-21 23:07:41 +01:00
// apparmor.d - Full set of apparmor profiles
// Copyright (C) 2021-2024 Alexandre Pujol <alexandre@pujol.io>
// SPDX-License-Identifier: GPL-2.0-only
package directive
import (
"slices"
2024-03-21 23:07:41 +01:00
"strings"
"github.com/roddhjav/apparmor.d/pkg/aa"
"github.com/roddhjav/apparmor.d/pkg/prebuild/cfg"
"github.com/roddhjav/apparmor.d/pkg/util"
2024-03-21 23:07:41 +01:00
)
type Exec struct {
cfg.Base
2024-03-21 23:07:41 +01:00
}
func init() {
RegisterDirective(&Exec{
Base: cfg.Base{
Keyword: "exec",
Msg: "Exec directive applied",
Help: Keyword + `exec [P|U|p|u|PU|pu|] profiles...`,
2024-03-21 23:07:41 +01:00
},
})
2024-03-21 23:07:41 +01:00
}
func (d Exec) Apply(opt *Option, profileRaw string) string {
2024-03-21 23:07:41 +01:00
transition := "Px"
transitions := []string{"P", "U", "p", "u", "PU", "pu"}
t := opt.ArgList[0]
if slices.Contains(transitions, t) {
transition = t + "x"
delete(opt.ArgMap, t)
}
profile := &aa.AppArmorProfile{}
p := profile.GetDefaultProfile()
for name := range opt.ArgMap {
profiletoTransition := util.MustReadFile(cfg.RootApparmord.Join(name))
dstProfile := aa.DefaultTunables()
dstProfile.ParseVariables(profiletoTransition)
for _, variable := range dstProfile.Variables {
2024-03-21 23:07:41 +01:00
if variable.Name == "exec_path" {
for _, v := range variable.Values {
p.Rules = append(p.Rules, &aa.File{
Path: v,
Access: transition,
})
2024-03-21 23:07:41 +01:00
}
break
2024-03-21 23:07:41 +01:00
}
}
}
profile.Sort()
rules := profile.String()
lenRules := len(rules)
rules = rules[:lenRules-1]
return strings.Replace(profileRaw, opt.Raw, rules, -1)
2024-03-21 23:07:41 +01:00
}