seccomp.go 1.1 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667
  1. package runner
  2. import (
  3. "os"
  4. "os/exec"
  5. "path"
  6. "github.com/google/uuid"
  7. )
  8. type SeccompRunner struct {
  9. }
  10. func (s *SeccompRunner) WithTempDir(paths []string, closures func(path string) error) error {
  11. uuid, err := uuid.NewRandom()
  12. if err != nil {
  13. return err
  14. }
  15. // create a tmp dir
  16. tmp_dir := path.Join("/tmp", "sandbox-"+uuid.String())
  17. err = os.Mkdir(tmp_dir, 0755)
  18. if err != nil {
  19. return err
  20. }
  21. // copy files to tmp dir
  22. for _, file_path := range paths {
  23. // create path in tmp dir
  24. // check if it's a dir
  25. file_info, err := os.Stat(file_path)
  26. if err != nil {
  27. return err
  28. }
  29. if file_info.IsDir() {
  30. err = os.MkdirAll(path.Join(tmp_dir, file_path), 0755)
  31. if err != nil {
  32. return err
  33. }
  34. } else {
  35. err = os.MkdirAll(path.Join(tmp_dir, path.Dir(file_path)), 0755)
  36. if err != nil {
  37. return err
  38. }
  39. }
  40. err = exec.Command("cp", "-r", file_path, path.Join(tmp_dir, file_path)).Run()
  41. if err != nil {
  42. return err
  43. }
  44. }
  45. // chdir
  46. err = os.Chdir(tmp_dir)
  47. if err != nil {
  48. return err
  49. }
  50. err = closures(tmp_dir)
  51. if err != nil {
  52. return err
  53. }
  54. return nil
  55. }