aboutsummaryrefslogtreecommitdiffhomepage
path: root/helper/bwrap/arg.go
blob: 050643ef3166ff6ae6ab9402e673bb3d89d8b51c (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
package bwrap

import (
	"os"
	"slices"

	"git.gensokyo.uk/security/fortify/helper/proc"
)

type Builder interface {
	Len() int
	Append(args *[]string)
}

type FSBuilder interface {
	Path() string
	Builder
}

type FDBuilder interface {
	proc.File
	Builder
}

// Args returns a slice of bwrap args corresponding to c.
func (c *Config) Args() (args []string) {
	builders := []Builder{
		c.boolArgs(),
		c.intArgs(),
		c.stringArgs(),
		c.pairArgs(),
	}

	// copy FSBuilder slice to builder slice
	fb := make([]Builder, len(c.Filesystem)+1)
	for i, f := range c.Filesystem {
		fb[i] = f
	}
	fb[len(fb)-1] = c.Chmod
	builders = append(builders, fb...)

	// accumulate arg count
	argc := 0
	for _, b := range builders {
		argc += b.Len()
	}

	args = make([]string, 0, argc)
	for _, b := range builders {
		b.Append(&args)
	}

	return
}

func (c *Config) FDArgs(syncFd *os.File, args *[]string, extraFiles *proc.ExtraFilesPre, files *[]proc.File) {
	builders := []FDBuilder{
		c.seccompArgs(),
		newFile(positionalArgs[SyncFd], syncFd),
	}

	argc := 0
	fc := 0
	for _, b := range builders {
		l := b.Len()
		if l < 1 {
			continue
		}
		argc += l
		fc++

		proc.InitFile(b, extraFiles)
	}

	fc++ // allocate extra slot for stat fd
	*args = slices.Grow(*args, argc)
	*files = slices.Grow(*files, fc)

	for _, b := range builders {
		if b.Len() < 1 {
			continue
		}

		b.Append(args)
		*files = append(*files, b)
	}
	return
}