prescript.py 959 B

12345678910111213141516171819202122232425262728293031323334353637383940
  1. if __name__ == "__main__":
  2. import ctypes
  3. import os
  4. import sys
  5. import json
  6. import time
  7. import traceback
  8. # setup sys.excepthook
  9. def excepthook(type, value, tb):
  10. sys.stderr.write("".join(traceback.format_exception(type, value, tb)))
  11. sys.stderr.flush()
  12. sys.exit(-1)
  13. sys.excepthook = excepthook
  14. if len(sys.argv) != 5:
  15. sys.exit(-1)
  16. lib = ctypes.CDLL("/tmp/sandbox-python/python.so")
  17. module = sys.argv[1]
  18. code = open(module).read()
  19. def sandbox(uid, gid, enable_network):
  20. lib.DifySeccomp.argtypes = [ctypes.c_uint32, ctypes.c_uint32, ctypes.c_bool]
  21. lib.DifySeccomp.restype = None
  22. lib.DifySeccomp(uid, gid, enable_network)
  23. uid = int(sys.argv[2])
  24. gid = int(sys.argv[3])
  25. if not uid or not gid:
  26. sys.exit(-1)
  27. options = json.loads(sys.argv[4])
  28. sandbox(uid, gid, options.get("enable_network", False))
  29. exec(code)