Package io.jawk.jrt

Class SandboxedJRT

java.lang.Object
io.jawk.jrt.JRT
io.jawk.jrt.SandboxedJRT

public class SandboxedJRT extends JRT
Runtime component that raises AwkSandboxException when sandboxed code attempts operations that would escape the sandbox.
  • Constructor Details

    • SandboxedJRT

      public SandboxedJRT(VariableManager vm, Locale locale, AwkSink awkSink, PrintStream error)
      Creates a sandboxed runtime facade with explicit default output settings.
      Parameters:
      vm - Variable manager used by the sandboxed runtime
      locale - locale to use for runtime formatting
      awkSink - default output sink
      error - error stream for spawned-process stderr
  • Method Details

    • getFileAwkSink

      protected AwkSink getFileAwkSink(String filename, boolean append)
      Description copied from class: JRT
      Resolves the sink used by file redirection. The gawk special filenames /dev/stdout and /dev/stderr (and their /dev/fd/1 and /dev/fd/2 spellings) are routed to the streams the process already holds open instead of being opened, and therefore truncated, as regular files, and /dev/null designates the platform's null device on Windows too.
      Overrides:
      getFileAwkSink in class JRT
      Parameters:
      filename - target file name
      append - whether output should be appended
      Returns:
      the sink that writes to the requested file
    • getPipeAwkSink

      protected AwkSink getPipeAwkSink(String cmd)
      Description copied from class: JRT
      Resolves the sink used by pipe redirection.
      Overrides:
      getPipeAwkSink in class JRT
      Parameters:
      cmd - command to execute
      Returns:
      the sink connected to the process stdin
    • jrtGetPrintStream

      public PrintStream jrtGetPrintStream(String filename, boolean append)
      Description copied from class: JRT
      Retrieve the PrintStream which writes to a particular file, creating the PrintStream if necessary.
      Overrides:
      jrtGetPrintStream in class JRT
      Parameters:
      filename - The file which to write the contents of the PrintStream.
      append - true to append to the file, false to overwrite the file.
      Returns:
      a PrintStream object
    • jrtSpawnForOutput

      public PrintStream jrtSpawnForOutput(String cmd)
      Description copied from class: JRT
      Retrieve the PrintStream which shuttles data to stdin for a process, executing the process if necessary. Threads are created to shuttle the data to/from the process.
      Overrides:
      jrtSpawnForOutput in class JRT
      Parameters:
      cmd - The command to execute.
      Returns:
      The PrintStream which to write to provide input data to the process.
    • jrtConsumeFileInput

      public boolean jrtConsumeFileInput(String filename) throws IOException
      Description copied from class: JRT
      Reads one record from a file opened by a redirected getline.

      The reader is opened on first use and kept until it is explicitly closed or the VM exits. Unlike the main input loop, this transport leaves the current record ($0 and its fields), NR, FNR, and FILENAME untouched: gawk documents getline [var] < file as setting only the target of the read. The consumed record is exposed through JRT.jrtGetInputString().

      The gawk special filename /dev/stdin (and its /dev/fd/0 spelling) reads the standard input of the process rather than a file of that name, and /dev/null reads the platform's null device, which reports end of input immediately on Windows too.

      Overrides:
      jrtConsumeFileInput in class JRT
      Parameters:
      filename - name of the file to read from
      Returns:
      true when a record was read; false at end of input
      Throws:
      IOException - if the file cannot be opened or read; a failed open is not cached, so a later getline from the same name retries it
    • jrtConsumeCommandInput

      public boolean jrtConsumeCommandInput(String cmd) throws IOException
      Description copied from class: JRT
      Reads one record from the output of a command spawned by a redirected getline.

      The process is spawned on first use and kept until the pipe is explicitly closed or the VM exits. As with file redirection, the current record ($0 and its fields), NR, FNR, and FILENAME are left untouched: gawk documents cmd | getline [var] as setting only the target of the read. The consumed record is exposed through JRT.jrtGetInputString().

      Overrides:
      jrtConsumeCommandInput in class JRT
      Parameters:
      cmd - the command to execute
      Returns:
      true when a record was read; false at end of input
      Throws:
      IOException - if the process cannot be spawned; a failed spawn is not cached, so a later getline from the same command retries it
    • jrtSystem

      public Integer jrtSystem(String cmd)
      Description copied from class: JRT
      Executes the command specified by cmd and waits for termination, returning an Integer object containing the return code. The command inherits the standard input of the JVM when Jawk reads the real standard input (CLI runs), as POSIX requires of system(); otherwise its standard input is closed. Threads are created to shuttle stdout and stderr of the command to stdout/stderr of the calling process.
      Overrides:
      jrtSystem in class JRT
      Parameters:
      cmd - The command to execute.
      Returns:
      Integer(return_code) of the created process. Integer(-1) is returned on an IO error.