Add java-vm_sandbox-predict for installing a sandbox control file along with any...
authorRalph Sennhauser <sera@gentoo.org>
Sat, 12 Nov 2011 13:05:33 +0000 (13:05 +0000)
committerRalph Sennhauser <sera@gentoo.org>
Sat, 12 Nov 2011 13:05:33 +0000 (13:05 +0000)
eclass/ChangeLog
eclass/java-vm-2.eclass

index b5d9f49afe210d44ddd3a6eca3af39059a15002d..6580f9f89ca832a38bb6d65295985d84c3441d34 100644 (file)
@@ -1,6 +1,10 @@
 # ChangeLog for eclass directory
 # Copyright 1999-2011 Gentoo Foundation; Distributed under the GPL v2
-# $Header: /var/cvsroot/gentoo-x86/eclass/ChangeLog,v 1.7 2011/11/11 07:06:25 dirtyepic Exp $
+# $Header: /var/cvsroot/gentoo-x86/eclass/ChangeLog,v 1.8 2011/11/12 13:05:33 sera Exp $
+
+  12 Nov 2011; Ralph Sennhauser <sera@gentoo.org> java-vm-2.eclass:
+  Add java-vm_sandbox-predict for installing a sandbox control file along with
+  any JVM that needs it. Bug 388937#c1
 
   11 Nov 2011; Ryan Hill <dirtyepic@gentoo.org> flag-o-matic.eclass:
   Test that appended flags are valid. This allows people to add flags that were
index a22f77673d9acdcd9ee27e27ef5cd94110ac270f..4435f447658eb8ad162f6983f004b63edee6d286 100644 (file)
@@ -1,6 +1,6 @@
-# Copyright 1999-2004 Gentoo Foundation
+# Copyright 1999-2011 Gentoo Foundation
 # Distributed under the terms of the GNU General Public License v2
-# $Header: /var/cvsroot/gentoo-x86/eclass/java-vm-2.eclass,v 1.36 2011/10/30 11:06:38 caster Exp $
+# $Header: /var/cvsroot/gentoo-x86/eclass/java-vm-2.eclass,v 1.37 2011/11/12 13:05:33 sera Exp $
 
 # -----------------------------------------------------------------------------
 # @eclass-begin
@@ -204,6 +204,28 @@ java-vm_revdep-mask() {
        elog "USE flags (typically X, alsa, odbc) and some Java code may fail without them."
 }
 
+# -----------------------------------------------------------------------------
+# @ebuild-function java-vm_sandbox-predict
+#
+# Install a sandbox control file. Specified paths won't cause a sandbox
+# violation if opened read write but no write takes place. See bug 388937#c1
+#
+# @example
+#   java-vm_sandbox-predict /dev/random /proc/self/coredump_filter
+# -----------------------------------------------------------------------------
+java-vm_sandbox-predict() {
+       debug-print-function ${FUNCNAME} "$*"
+       [[ -z "${1}" ]] && die "${FUNCNAME} takes at least one argument"
+
+       has ${EAPI:-0} 0 1 2 && ! use prefix && ED="${D}"
+
+       local path path_arr=("$@")
+       IFS=":" path="${path_arr[*]}"
+       dodir /etc/sandbox.d
+       echo "SANDBOX_PREDICT=\"${path}\"" > "${ED}/etc/sandbox.d/20${VMHANDLE}" \
+               || die "Failed to write sandbox control file"
+}
+
 java_get_plugin_dir_() {
        has ${EAPI:-0} 0 1 2 && ! use prefix && EPREFIX=
        echo "${EPREFIX}"/usr/$(get_libdir)/nsbrowser/plugins