Changes
9 changed files (+77/-59)
-
-
@@ -48,7 +48,7 @@]; }; vendorHash = "sha256-qSnRQIuHnUQit21232SsMY0LQVvcy0PqBPQVPjsNJWA="; vendorHash = "sha256-SWMJVv7QQt4gHaPjb5Q5m20jzFMPHqa+McI26EYg6Ak="; nativeBuildInputs = with pkgs; [ git ];
-
-
-
@@ -9,9 +9,10 @@ require (github.com/dustin/go-humanize v1.0.1 github.com/go-git/go-billy/v5 v5.6.2 github.com/go-git/go-git/v5 v5.13.2 github.com/landlock-lsm/go-landlock v0.9.0 github.com/microcosm-cc/bluemonday v1.0.27 github.com/russross/blackfriday/v2 v2.1.0 golang.org/x/sys v0.30.0 golang.org/x/sys v0.40.0 gopkg.in/yaml.v3 v3.0.1 )
-
@@ -35,6 +36,7 @@ require (golang.org/x/crypto v0.33.0 // indirect golang.org/x/net v0.35.0 // indirect gopkg.in/warnings.v0 v0.1.2 // indirect kernel.org/pub/linux/libs/security/libcap/psx v1.2.77 // indirect ) replace github.com/sergi/go-diff => github.com/sergi/go-diff v1.1.0
-
-
-
@@ -63,6 +63,8 @@ github.com/kr/pty v1.1.1/go.mod h1:pFQYn66WHrOpPYNljwOMqo10TkYh1fy3cYio2l3bCsQ=github.com/kr/text v0.1.0/go.mod h1:4Jbv+DJW3UT/LiOwJeYQe1efqtUx/iVham/4vfdArNI= github.com/kr/text v0.2.0 h1:5Nx0Ya0ZqY2ygV366QzturHI13Jq95ApcVaJBhpS+AY= github.com/kr/text v0.2.0/go.mod h1:eLer722TekiGuMkidMxC/pM04lWEeraHUUmBw8l2grE= github.com/landlock-lsm/go-landlock v0.9.0 h1:2q8G8yx9Hsd5bV+R6PJfgQl0zszNxC8KO+SIqGwfxlw= github.com/landlock-lsm/go-landlock v0.9.0/go.mod h1:mn5GSi81Jf7yMs5WSi+SUi4sUeNLUGVdbT4Id6wXNQw= github.com/microcosm-cc/bluemonday v1.0.27 h1:MpEUotklkwCSLeH+Qdx1VJgNqLlpY2KXwXFM08ygZfk= github.com/microcosm-cc/bluemonday v1.0.27/go.mod h1:jFi9vgW+H7c3V0lb6nR74Ib/DIB5OBs92Dimizgw2cA= github.com/onsi/gomega v1.34.1 h1:EUMJIKUjM8sKjYbtxQI9A4z2o+rruxnzNvpknOXie6k=
-
@@ -103,8 +105,8 @@ golang.org/x/sys v0.0.0-20210124154548-22da62e12c0c/go.mod h1:h1NjWce9XRLGQEsW7wgolang.org/x/sys v0.0.0-20210423082822-04245dca01da/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= golang.org/x/sys v0.0.0-20210615035016-665e8c7367d1/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= golang.org/x/sys v0.0.0-20220715151400-c0bba94af5f8/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= golang.org/x/sys v0.30.0 h1:QjkSwP/36a20jFYWkSue1YwXzLmsV5Gfq7Eiy72C1uc= golang.org/x/sys v0.30.0/go.mod h1:/VUhepiaJMQUp4+oa/7Zr1D23ma6VTLIYjOOTFZPUcA= golang.org/x/sys v0.40.0 h1:DBZZqJ2Rkml6QMQsZywtnjnnGvHza6BTfYFWY9kjEWQ= golang.org/x/sys v0.40.0/go.mod h1:OgkHotnGiDImocRcuBABYBEXf8A9a87e/uXjp9XT3ks= golang.org/x/term v0.0.0-20201126162022-7de9c90e9dd1/go.mod h1:bj7SfCRtBDWHUb9snDiAeCFNEtKQo2Wmx5Cou7ajbmo= golang.org/x/term v0.29.0 h1:L6pJp37ocefwRRtYPKSWOWzOtWSxVajvz2ldH/xi3iU= golang.org/x/term v0.29.0/go.mod h1:6bl4lRlvVuDgSf3179VpIxBF0o10JUpXWOnI7nErv7s=
-
@@ -122,3 +124,5 @@ gopkg.in/yaml.v2 v2.2.2/go.mod h1:hI93XBmqTisBFMUTm0b8Fm+jr3Dg1NNxqwp+5A1VGuI=gopkg.in/yaml.v2 v2.2.4/go.mod h1:hI93XBmqTisBFMUTm0b8Fm+jr3Dg1NNxqwp+5A1VGuI= gopkg.in/yaml.v3 v3.0.1 h1:fxVm/GzAzEWqLHuvctI91KS9hhNmmWOoWu0XTYJS7CA= gopkg.in/yaml.v3 v3.0.1/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM= kernel.org/pub/linux/libs/security/libcap/psx v1.2.77 h1:Z06sMOzc0GNCwp6efaVrIrz4ywGJ1v+DP0pjVkOfDuA= kernel.org/pub/linux/libs/security/libcap/psx v1.2.77/go.mod h1:+l6Ee2F59XiJ2I6WR5ObpC1utCQJZ/VLsEbQCD8RG24=
-
-
-
@@ -44,13 +44,19 @@ func main() {c.UI.CommitsPageSize = 30 } if err := UnveilPaths([]string{ c.Dirs.Static, c.Repo.ScanPath, c.Dirs.Templates, }, "r"); err != nil { log.Fatalf("unveil: %s", err) allowedDirs := make([]string, 1, 3) allowedDirs[0] = c.Repo.ScanPath if c.Dirs.Static != "" { allowedDirs = append(allowedDirs, c.Dirs.Static) } if c.Dirs.Templates != "" { allowedDirs = append(allowedDirs, c.Dirs.Templates) } if err := restrictFileAccessTo(allowedDirs...); err != nil { log.Fatalf("Unable to restrict filesystem access: %s", err) } var staticDir fs.FS
-
-
restrictfs_linux.go (new)
-
@@ -0,0 +1,22 @@//go:build linux // Copyright 2025 Shota FUJI <pockawoooh@gmail.com> // SPDX-License-Identifier: MIT package main import ( "fmt" "github.com/landlock-lsm/go-landlock/landlock" ) func restrictFileAccessTo(dirs ...string) error { err := landlock.V9.BestEffort().RestrictPaths(landlock.RODirs(dirs...)) if err != nil { return fmt.Errorf("Landlock error: %w", err) } return nil }
-
-
restrictfs_noop.go (new)
-
@@ -0,0 +1,9 @@//go:build !(openbsd || linux) // Stub functions for GOOS that don't support filesystem restriction. package main func restrictFileAccessTo(_dirs ...string) error { return nil }
-
-
restrictfs_openbsd.go (new)
-
@@ -0,0 +1,23 @@//go:build openbsd package main import ( "fmt" "golang.org/x/sys/unix" ) func restrictFileAccessTo(dirs ...string) error { for _, dir := range dirs { if err := unix.Unveil(dir, "r"); err != nil { return fmt.Errorf("Unveil error (%s): %w", dir, err) } } if err := unix.UnveilBlock(); err != nil { return fmt.Errorf("Unveil block error: %w", err) } return nil }
-
-
unveil.go (deleted)
-
@@ -1,31 +0,0 @@//go:build openbsd package main import ( "golang.org/x/sys/unix" "log" ) func Unveil(path string, perms string) error { log.Printf("unveil: \"%s\", %s", path, perms) return unix.Unveil(path, perms) } func UnveilBlock() error { log.Printf("unveil: block") return unix.UnveilBlock() } func UnveilPaths(paths []string, perms string) error { for _, path := range paths { if path == "" { continue } if err := Unveil(path, perms); err != nil { return err } } return UnveilBlock() }
-
-
unveil_stub.go (deleted)
-
@@ -1,17 +0,0 @@//go:build !openbsd // Stub functions for GOOS that don't support unix.Unveil() package main func Unveil(path string, perms string) error { return nil } func UnveilBlock() error { return nil } func UnveilPaths(paths []string, perms string) error { return nil }
-