blob: 1d32d860a00d17cc085f8cdb14dc32d8248d3b14 [file] [log] [blame]
Spandan Dasa3639e62021-05-25 19:14:02 +00001// Copyright 2021 Google Inc. All rights reserved.
2//
3// Licensed under the Apache License, Version 2.0 (the "License");
4// you may not use this file except in compliance with the License.
5// You may obtain a copy of the License at
6//
7// http://www.apache.org/licenses/LICENSE-2.0
8//
9// Unless required by applicable law or agreed to in writing, software
10// distributed under the License is distributed on an "AS IS" BASIS,
11// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12// See the License for the specific language governing permissions and
13// limitations under the License.
14
15package build
16
17type SandboxConfig struct {
18 srcDirIsRO bool
19 srcDirRWAllowlist []string
20}
21
22func (sc *SandboxConfig) SetSrcDirIsRO(ro bool) {
23 sc.srcDirIsRO = ro
24}
25
26func (sc *SandboxConfig) SrcDirIsRO() bool {
27 return sc.srcDirIsRO
28}
29
Spandan Das2d997042022-11-04 20:58:18 +000030// Return the mount flag of the source directory in the nsjail command
31func (sc *SandboxConfig) SrcDirMountFlag() string {
32 ret := "-B" // Read-write
33 if sc.SrcDirIsRO() {
34 ret = "-R" // Read-only
35 }
36 return ret
37}
38
Spandan Dasa3639e62021-05-25 19:14:02 +000039func (sc *SandboxConfig) SetSrcDirRWAllowlist(allowlist []string) {
40 sc.srcDirRWAllowlist = allowlist
41}
42
43func (sc *SandboxConfig) SrcDirRWAllowlist() []string {
44 return sc.srcDirRWAllowlist
45}