Module: Gienah::Sandbox
- Defined in:
- lib/gienah/sandbox.rb,
sig/gienah.rbs
Constant Summary collapse
- DANGEROUS =
/\A(?:fs\.write:|net:|exec\z|process\.exec\z)/
Class Method Summary collapse
- .available? ⇒ Boolean
- .dangerous?(capabilities) ⇒ Boolean
- .ensure_safe!(capabilities) ⇒ void
- .policy_for(capabilities, root:) ⇒ Object
Class Method Details
.available? ⇒ Boolean
35 36 37 38 39 40 |
# File 'lib/gienah/sandbox.rb', line 35 def available? require "saiph" Saiph.available? rescue LoadError, StandardError false end |
.dangerous?(capabilities) ⇒ Boolean
9 10 11 |
# File 'lib/gienah/sandbox.rb', line 9 def dangerous?(capabilities) Array(capabilities).any? { |capability| capability.match?(DANGEROUS) } end |
.ensure_safe!(capabilities) ⇒ void
This method returns an undefined value.
42 43 44 |
# File 'lib/gienah/sandbox.rb', line 42 def ensure_safe!(capabilities) raise Error, "OS sandbox is unavailable for dangerous capabilities" if dangerous?(capabilities) && !available? end |
.policy_for(capabilities, root:) ⇒ Object
13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 |
# File 'lib/gienah/sandbox.rb', line 13 def policy_for(capabilities, root:) require "saiph" root = File.(root.to_s) reads = [] writes = [] network = false exec = false Array(capabilities).each do |capability| case capability when /\Afs\.read:(.+)/ reads << path_for(Regexp.last_match(1), root) when /\Afs\.write:(.+)/ writes << path_for(Regexp.last_match(1), root) when /\Anet:/ network = true when "exec", "process.exec" exec = true end end Saiph::Policy.new((reads + [root]).uniq, writes.uniq, network, exec, ENV.keys) end |