aboutsummaryrefslogtreecommitdiff
path: root/sandboxed_api/sandbox2/fork_client.h
blob: 842b1523a022b35aacd92152a3824f5913a87938 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
// Copyright 2020 Google LLC
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
//     https://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.

#ifndef SANDBOXED_API_SANDBOX2_FORK_CLIENT_H_
#define SANDBOXED_API_SANDBOX2_FORK_CLIENT_H_

#include <sys/types.h>

#include "absl/base/thread_annotations.h"
#include "absl/synchronization/mutex.h"
#include "sandboxed_api/util/fileops.h"

namespace sandbox2 {

// Envvar indicating that this process should not start the fork-server.
constexpr inline char kForkServerDisableEnv[] = "SANDBOX2_NOFORKSERVER";

class Comms;
class ForkRequest;

struct SandboxeeProcess {
  pid_t init_pid = -1;
  pid_t main_pid = -1;
  sapi::file_util::fileops::FDCloser status_fd;
};

class ForkClient {
 public:
  ForkClient(pid_t pid, Comms* comms) : pid_(pid), comms_(comms) {}
  ForkClient(const ForkClient&) = delete;
  ForkClient& operator=(const ForkClient&) = delete;

  // Sends the fork request over the supplied Comms channel.
  SandboxeeProcess SendRequest(const ForkRequest& request, int exec_fd,
                               int comms_fd);

  pid_t pid() { return pid_; }

 private:
  // Pid of the ForkServer.
  pid_t pid_;
  // Comms channel connecting with the ForkServer. Not owned by the object.
  Comms* comms_ ABSL_GUARDED_BY(comms_mutex_);
  // Mutex locking transactions (requests) over the Comms channel.
  absl::Mutex comms_mutex_;
};

}  // namespace sandbox2

#endif  // SANDBOXED_API_SANDBOX2_FORK_CLIENT_H_