add dbus and dri
This commit is contained in:
+22
-8
@@ -1,16 +1,18 @@
|
||||
import os
|
||||
import args
|
||||
import json
|
||||
import strutils
|
||||
import options
|
||||
import config
|
||||
import utils
|
||||
import bwrap
|
||||
import config
|
||||
import options
|
||||
import args
|
||||
import json
|
||||
import dbus
|
||||
import os
|
||||
|
||||
proc sandboxExec*(args: Args) =
|
||||
var call = BwrapCall()
|
||||
var configPath = none(string)
|
||||
|
||||
let hostname = args.name.get(getProfile(argst ))
|
||||
let hostname = args.name.get(getProfile(args))
|
||||
|
||||
if args.name.isSome:
|
||||
let name = args.name.unsafeGet
|
||||
@@ -18,7 +20,6 @@ proc sandboxExec*(args: Args) =
|
||||
let sandboxFiles = sandboxPath.joinPath("files")
|
||||
let userConfig = sandboxPath.joinPath("config.json")
|
||||
|
||||
|
||||
createDir(sandboxFiles)
|
||||
call.addArg("--bind", sandboxFiles, getHomeDir())
|
||||
|
||||
@@ -35,10 +36,11 @@ proc sandboxExec*(args: Args) =
|
||||
config.extendConfig()
|
||||
|
||||
call
|
||||
.addMount("--dev-bind", "/dev/null")
|
||||
.addArg("--dev", "/dev")
|
||||
.addMount("--dev-bind", "/dev/random")
|
||||
.addMount("--dev-bind", "/dev/urandom")
|
||||
.addArg("--tmpfs", "/tmp")
|
||||
.addArg("--tmpfs", "/dev/shm")
|
||||
.addArg("--proc", "/proc")
|
||||
.addArg("--unshare-all")
|
||||
.addArg("--share-net")
|
||||
@@ -46,6 +48,18 @@ proc sandboxExec*(args: Args) =
|
||||
.addArg("--setenv", "BWSANDBOX", "1")
|
||||
.applyConfig(config)
|
||||
|
||||
if config.dbus.get(false):
|
||||
# todo: handle process and cleanup later
|
||||
let proxy = startDBusProxy(config, hostname)
|
||||
call.addArg("--ro-bind", proxy.socket,
|
||||
getEnv("DBUS_SESSION_BUS_ADDRESS").split('=')[1])
|
||||
|
||||
# todo: use fd signaling instead of this
|
||||
sleep(100)
|
||||
|
||||
if config.allowdri.get(false):
|
||||
enableDri(call)
|
||||
|
||||
if config.mountcwd.get(false):
|
||||
call
|
||||
.addMount("--bind", getCurrentDir())
|
||||
|
||||
Reference in New Issue
Block a user