From 72b0160aadac590bc479b9ec86e0378a95d2bdc0 Mon Sep 17 00:00:00 2001 From: Ophestra Date: Sat, 15 Feb 2025 03:12:28 +0900 Subject: helper/bwrap: implement file copy flags These are significantly more efficient and less error-prone than mounting an external tmpfile. This should also reduce attack surface as the resulting files are private to its specific sandbox. Signed-off-by: Ophestra --- helper/bwrap/builder.go | 27 ++++++++++++++++++++++++++- 1 file changed, 26 insertions(+), 1 deletion(-) (limited to 'helper/bwrap/builder.go') diff --git a/helper/bwrap/builder.go b/helper/bwrap/builder.go index 312295d6..d196bc06 100644 --- a/helper/bwrap/builder.go +++ b/helper/bwrap/builder.go @@ -1,6 +1,8 @@ package bwrap -import "os" +import ( + "os" +) /* Bind binds mount src on host to dest in sandbox. @@ -61,6 +63,29 @@ func (c *Config) Bind(src, dest string, opts ...bool) *Config { } } +// Write copy from FD to destination DEST +// (--file FD DEST) +func (c *Config) Write(dest string, payload []byte) *Config { + c.Filesystem = append(c.Filesystem, &DataConfig{Dest: dest, Data: payload, Type: DataWrite}) + return c +} + +/* +CopyBind copy from FD to file which is readonly bind-mounted on DEST +(--ro-bind-data FD DEST) + +CopyBind(dest, payload, true) copy from FD to file which is bind-mounted on DEST +(--bind-data FD DEST) +*/ +func (c *Config) CopyBind(dest string, payload []byte, opts ...bool) *Config { + t := DataROBind + if len(opts) > 0 && opts[0] { + t = DataBind + } + c.Filesystem = append(c.Filesystem, &DataConfig{Dest: dest, Data: payload, Type: t}) + return c +} + // Dir create dir in sandbox // (--dir DEST) func (c *Config) Dir(dest string) *Config { -- cgit v1.3.1