Class: SecurityBox::Configuration::Builder

Inherits:
Object
  • Object
show all
Defined in:
lib/security_box/configuration.rb

Overview

Mutable collector for the register DSL. Setter names match the Configuration options (no =, e.g. c.fuel 100); only changed values are collected and merged over the base profile.

Instance Method Summary collapse

Constructor Details

#initialize ⇒ Builder

Returns a new instance of Builder.



123
124
125
# File 'lib/security_box/configuration.rb', line 123

def initialize
  @changes = {}
end

Instance Method Details

#changes ⇒ Object



127
128
129
# File 'lib/security_box/configuration.rb', line 127

def changes
  @changes
end

#env(value) ⇒ Object

Replaces the guest environment (it is not merged with the base).



171
172
173
# File 'lib/security_box/configuration.rb', line 171

def env(value)
  @changes[:env] = value
end

#epoch_interval_ms(value) ⇒ Object



166
167
168
# File 'lib/security_box/configuration.rb', line 166

def epoch_interval_ms(value)
  @changes[:epoch_interval_ms] = value
end

#fuel(value) ⇒ Object



135
136
137
138
139
# File 'lib/security_box/configuration.rb', line 135

def fuel(value)
  raise InvalidConfiguration, "fuel and fuel_ms are mutually exclusive" if @changes.key?(:fuel_ms)

  @changes[:fuel] = value
end

#fuel_ms(value) ⇒ Object

Rate-based fuel ergonomics: sets fuel from an approximate millisecond budget (see Configuration#effective_fuel). Mutually exclusive with an explicit :fuel.



144
145
146
147
148
# File 'lib/security_box/configuration.rb', line 144

def fuel_ms(value)
  raise InvalidConfiguration, "fuel and fuel_ms are mutually exclusive" if @changes.key?(:fuel)

  @changes[:fuel_ms] = value
end

#image_path(value) ⇒ Object



131
132
133
# File 'lib/security_box/configuration.rb', line 131

def image_path(value)
  @changes[:image_path] = value
end

#memory_size(value) ⇒ Object



154
155
156
# File 'lib/security_box/configuration.rb', line 154

def memory_size(value)
  @changes[:memory_size] = value
end

#mount(mapping) ⇒ Object

Mounts a host directory into the guest, read-only by default:

c.mount "host/path" => "/data"

Each call appends one mount; use #mount_rw for a writable mount.



178
179
180
# File 'lib/security_box/configuration.rb', line 178

def mount(mapping)
  add_mount(mapping, :read_only)
end

#mount_rw(mapping) ⇒ Object

Opt-in writable mount — the only way to expose a writable host path besides the sandbox-private /work tmpdir:

c.mount_rw "host/path" => "/data"


185
186
187
# File 'lib/security_box/configuration.rb', line 185

def mount_rw(mapping)
  add_mount(mapping, :read_write)
end

#rpc(mapping = nil, **kwargs) ⇒ Object

Registers a guest-callable RPC handler (stage 6):

c.rpc "github.search" => ->(args) { ... }
c.rpc github_search: ->(args) { ... }

Each call appends one handler; the per-call :rpcs override replaces the whole set. See SecurityBox::Rpcs for the validation rules.



194
195
196
197
198
199
200
201
202
203
204
205
206
207
# File 'lib/security_box/configuration.rb', line 194

def rpc(mapping = nil, **kwargs)
  unless kwargs.empty?
    raise InvalidConfiguration, 'rpc expects exactly one pair: c.rpc "name" => handler' unless kwargs.size == 1 && mapping.nil?

    name, handler = kwargs.first
    mapping = { name.to_s => handler }
  end
  unless mapping.is_a?(Hash) && mapping.size == 1
    raise InvalidConfiguration,
          'rpc expects exactly one pair: c.rpc "name" => handler'
  end

  @changes[:rpcs] = Array(@changes[:rpcs]) + [mapping]
end

#stderr_limit(value) ⇒ Object



162
163
164
# File 'lib/security_box/configuration.rb', line 162

def stderr_limit(value)
  @changes[:stderr_limit] = value
end

#stdout_limit(value) ⇒ Object



158
159
160
# File 'lib/security_box/configuration.rb', line 158

def stdout_limit(value)
  @changes[:stdout_limit] = value
end

#timeout_ms(value) ⇒ Object



150
151
152
# File 'lib/security_box/configuration.rb', line 150

def timeout_ms(value)
  @changes[:timeout_ms] = value
end