2015-04-22 13:50:49 +01:00
|
|
|
{ writeText, writeScriptBin, stdenv, ruby } : { env, runScript } :
|
2015-02-05 15:14:28 +00:00
|
|
|
|
|
|
|
let
|
|
|
|
name = env.pname;
|
|
|
|
|
|
|
|
# Sandboxing script
|
2015-04-22 13:50:49 +01:00
|
|
|
chroot-user = writeScriptBin "chroot-user" ''
|
|
|
|
#! ${ruby}/bin/ruby
|
|
|
|
${builtins.readFile ./chroot-user.rb}
|
|
|
|
'';
|
2015-02-05 15:14:28 +00:00
|
|
|
|
2015-04-22 13:50:49 +01:00
|
|
|
init = writeText "init" ''
|
2015-08-23 23:59:20 +01:00
|
|
|
# Make /tmp directory
|
|
|
|
mkdir -m 1777 /tmp
|
|
|
|
|
2015-08-23 23:42:40 +01:00
|
|
|
# Expose sockets in /tmp
|
|
|
|
for i in /host-tmp/.*-unix; do
|
|
|
|
ln -s "$i" "/tmp/$(basename "$i")"
|
|
|
|
done
|
|
|
|
|
2015-04-22 13:50:49 +01:00
|
|
|
[ -d "$1" ] && [ -r "$1" ] && cd "$1"
|
|
|
|
shift
|
|
|
|
exec "${runScript}" "$@"
|
|
|
|
'';
|
2015-02-05 15:14:28 +00:00
|
|
|
|
2015-04-22 13:50:49 +01:00
|
|
|
in writeScriptBin name ''
|
|
|
|
#! ${stdenv.shell}
|
|
|
|
exec ${chroot-user}/bin/chroot-user ${env} bash -l ${init} "$(pwd)" "$@"
|
|
|
|
''
|