diff options
| author | Ophestra <cat@gensokyo.uk> | 2025-03-16 23:29:14 +0900 |
|---|---|---|
| committer | Ophestra <cat@gensokyo.uk> | 2025-03-16 23:29:14 +0900 |
| commit | 48feca800f90136f5a2d6169299f4efe5a93822c (patch) | |
| tree | a2a86004a15c939c81eb4736b5ded7e770ff622b /ldd/exec.go | |
| parent | 42de09e896e083f2bac0b7293483dcd0b403fd64 (diff) | |
sandbox: check command function pointer
Setting default CommandContext on initialisation is somewhat of a footgun.
Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'ldd/exec.go')
| -rw-r--r-- | ldd/exec.go | 5 |
1 files changed, 1 insertions, 4 deletions
diff --git a/ldd/exec.go b/ldd/exec.go index 4f77ae30..94756930 100644 --- a/ldd/exec.go +++ b/ldd/exec.go @@ -26,16 +26,13 @@ func ExecFilter(ctx context.Context, c, cancel := context.WithTimeout(ctx, lddTimeout) defer cancel() container := sandbox.New(c, "ldd", p) + container.CommandContext = commandContext container.Hostname = "fortify-ldd" stdout, stderr := new(bytes.Buffer), new(bytes.Buffer) container.Stdout = stdout container.Stderr = stderr container.Bind("/", "/", 0).Dev("/dev") - if commandContext != nil { - container.CommandContext = commandContext - } - if err := container.Start(); err != nil { return nil, err } else if err = container.Serve(); err != nil { |
