ABC-22: Plugin sandboxing for linux/amd64 (#8068)
* plugin sandboxing * remove unused type * better symlink handling, better remounting, better test, whitespace fixes, and comment on the remounting * fix test compile error * big simplification for getting mount flags * mask statfs flags to the ones we're interested in
Этот коммит содержится в:
коммит произвёл
Christopher Speller
родитель
7e5ce97668
Коммит
f5c8a71698
34
plugin/rpcplugin/sandbox/sandbox.go
Обычный файл
34
plugin/rpcplugin/sandbox/sandbox.go
Обычный файл
@@ -0,0 +1,34 @@
|
||||
// Copyright (c) 2017-present Mattermost, Inc. All Rights Reserved.
|
||||
// See License.txt for license information.
|
||||
|
||||
package sandbox
|
||||
|
||||
import (
|
||||
"context"
|
||||
"io"
|
||||
|
||||
"github.com/mattermost/mattermost-server/plugin/rpcplugin"
|
||||
)
|
||||
|
||||
type MountPoint struct {
|
||||
Source string
|
||||
Destination string
|
||||
Type string
|
||||
ReadOnly bool
|
||||
}
|
||||
|
||||
type Configuration struct {
|
||||
MountPoints []*MountPoint
|
||||
WorkingDirectory string
|
||||
}
|
||||
|
||||
// NewProcess is like rpcplugin.NewProcess, but launches the process in a sandbox.
|
||||
func NewProcess(ctx context.Context, config *Configuration, path string) (rpcplugin.Process, io.ReadWriteCloser, error) {
|
||||
return newProcess(ctx, config, path)
|
||||
}
|
||||
|
||||
// CheckSupport inspects the platform and environment to determine whether or not there are any
|
||||
// expected issues with sandboxing. If nil is returned, sandboxing should be used.
|
||||
func CheckSupport() error {
|
||||
return checkSupport()
|
||||
}
|
||||
Ссылка в новой задаче
Block a user