diff options
| author | Ophestra Umiker <cat@ophivana.moe> | 2024-12-06 04:21:37 +0900 |
|---|---|---|
| committer | Ophestra Umiker <cat@ophivana.moe> | 2024-12-06 04:21:37 +0900 |
| commit | 8d0573405a8a58a57c39b008150d75d3be2894c2 (patch) | |
| tree | db64f6990a74e4e2007162634170a30ad86dc10f /helper/bwrap | |
| parent | 38e92edb8efd7cc74031d013a13af5c1c8ddd284 (diff) | |
helper/bwrap: implement sync fd
This is required by wayland security-context-v1.
Signed-off-by: Ophestra Umiker <cat@ophivana.moe>
Diffstat (limited to 'helper/bwrap')
| -rw-r--r-- | helper/bwrap/config.go | 11 | ||||
| -rw-r--r-- | helper/bwrap/config.set.go | 7 |
2 files changed, 17 insertions, 1 deletions
diff --git a/helper/bwrap/config.go b/helper/bwrap/config.go index 0aad6de0..9e15a29a 100644 --- a/helper/bwrap/config.go +++ b/helper/bwrap/config.go @@ -68,13 +68,16 @@ type Config struct { // (--as-pid-1) AsInit bool `json:"as_init"` + // keep this fd open while sandbox is running + // (--sync-fd FD) + sync *os.File + /* unmapped options include: --unshare-user-try Create new user namespace if possible else continue by skipping it --unshare-cgroup-try Create new cgroup namespace if possible else continue by skipping it --userns FD Use this user namespace (cannot combine with --unshare-user) --userns2 FD After setup switch to this user namespace, only useful with --userns --pidns FD Use this pid namespace (as parent namespace if using --unshare-pid) - --sync-fd FD Keep this fd open while sandbox is running --exec-label LABEL Exec label for the sandbox --file-label LABEL File label for temporary sandbox content --file FD DEST Copy from FD to destination DEST @@ -92,6 +95,12 @@ type Config struct { among which --args is used internally for passing arguments */ } +// Sync keep this fd open while sandbox is running +// (--sync-fd FD) +func (c *Config) Sync() *os.File { + return c.sync +} + type UnshareConfig struct { // (--unshare-user) // create new user namespace diff --git a/helper/bwrap/config.set.go b/helper/bwrap/config.set.go index 318ad7f2..e9d3e131 100644 --- a/helper/bwrap/config.set.go +++ b/helper/bwrap/config.set.go @@ -136,3 +136,10 @@ func (c *Config) SetGID(gid int) *Config { } return c } + +// SetSync sets the sync pipe kept open while sandbox is running +// (--sync-fd FD) +func (c *Config) SetSync(s *os.File) *Config { + c.sync = s + return c +} |
