-
1
-
2
-
3
-
4
-
5
-
6
-
7
-
8
-
9
-
10
-
11
-
12
-
13
-
14
-
15
-
16
-
17
-
18
-
19
-
20
-
21
-
22
-
23
-
24
-
25
-
26
-
27
-
28
-
29
-
30
-
31
-
32
-
33
-
34
-
35
-
36
-
37
-
38
-
39
-
40
-
41
-
42
-
43
//go:build linux
// Copyright 2025 Shota FUJI <pockawoooh@gmail.com>
// SPDX-License-Identifier: MIT
package main
import (
"fmt"
"github.com/landlock-lsm/go-landlock/landlock"
)
func restrictFileAccessTo(allowList ...filesystemAccess) error {
rules := make([]landlock.Rule, 0, len(allowList))
for _, a := range allowList {
var rule landlock.Rule
if a.isDir {
if a.write {
rule = landlock.RWDirs(a.path)
} else {
rule = landlock.RODirs(a.path)
}
} else {
if a.write {
rule = landlock.RWFiles(a.path)
} else {
rule = landlock.ROFiles(a.path)
}
}
rules = append(rules, rule)
}
err := landlock.V9.BestEffort().RestrictPaths(rules...)
if err != nil {
return fmt.Errorf("Landlock error: %w", err)
}
return nil
}