Class SandboxedJRT
AwkSandboxException when sandboxed code
attempts operations that would escape the sandbox.-
Constructor Summary
ConstructorsConstructorDescriptionSandboxedJRT(VariableManager vm, Locale locale, AwkSink awkSink, PrintStream error) Creates a sandboxed runtime facade with explicit default output settings. -
Method Summary
Modifier and TypeMethodDescriptionprotected AwkSinkgetFileAwkSink(String filename, boolean append) Resolves the sink used by file redirection.protected AwkSinkgetPipeAwkSink(String cmd) Resolves the sink used by pipe redirection.booleanReads one record from the output of a command spawned by a redirectedgetline.booleanjrtConsumeFileInput(String filename) Reads one record from a file opened by a redirectedgetline.jrtGetPrintStream(String filename, boolean append) Retrieve the PrintStream which writes to a particular file, creating the PrintStream if necessary.jrtSpawnForOutput(String cmd) Retrieve the PrintStream which shuttles data to stdin for a process, executing the process if necessary.Executes the command specified by cmd and waits for termination, returning an Integer object containing the return code.Methods inherited from class io.jawk.jrt.JRT
add, advanceToNextFile, applyRS, applySpecialVariable, applySpecialVariables, assignEnvironmentVariables, assignInitialVariables, bindStandardInput, caseAwarePattern, compare, compare2, compare2, consumeCurrentFileInput, consumeCurrentFileInputToTarget, consumeInput, consumeInputForEval, consumeInputToTarget, containsAwkKey, copySpecialVariables, createAwkMap, dec, divide, dynamicPattern, getARGCVar, getARGIND, getAssocArrayValue, getAwkSink, getAwkStringEntry, getCONVFMTString, getCONVFMTVar, getERRNO, getFILENAME, getFNR, getFSString, getFSVar, getIGNORECASEVar, getInputLine, getLocale, getNF, getNR, getOFMTString, getOFSString, getOFSVar, getORSString, getORSVar, getOutputFiles, getPartitioningReader, getReplaceResult, getRLENGTH, getRSString, getRSTART, getRSVar, getSUBSEPString, getSUBSEPVar, hasInputFields, hasPendingInputFileError, inc, index, initializeInputFields, isActuallyLong, isGawkOnlySpecialVariable, isIgnoreCase, isJrtManagedSpecialVariable, isParseableNumber, jrtClose, jrtCloseAll, jrtConsumeCommandInputForGetline, jrtConsumeFileInputForGetline, jrtGetInputField, jrtGetInputField, jrtGetInputString, jrtParseFields, jrtSetInputField, jrtSetNF, matches, matchPosition, mod, multiply, negate, newRandom, parseFieldNumber, pow, prepareForExecution, prepareReplacement, prepareReplacement, printDefault, printfDefault, printfNoCatch, printfNoCatch, printfToFile, printfToProcess, printToFile, printToProcess, printWarning, rebuildDollarZeroFromFields, regexpFlags, replaceAll, replaceFirst, setARGC, setARGIND, setAwkSink, setCONVFMT, setERRNO, setErrorStream, setFILENAMEViaJrt, setFNR, setFS, setIGNORECASE, setInputLine, setNF, setNR, setOFMT, setOFS, setORS, setRLENGTH, setRS, setRSTART, setSpawnedProcessesInheritStandardInput, setSUBSEP, setWarningStream, split, split, splitTokenizer, sprintf, sprintfNoCatch, substr, substr, subtract, timeSeed, toAwkString, toBoolean, toDouble, toInputScalar, toJavaScalar, toLong, toScalarNumber, truncateToScalar, untypedToBlank
-
Constructor Details
-
SandboxedJRT
Creates a sandboxed runtime facade with explicit default output settings.- Parameters:
vm- Variable manager used by the sandboxed runtimelocale- locale to use for runtime formattingawkSink- default output sinkerror- error stream for spawned-process stderr
-
-
Method Details
-
getFileAwkSink
Description copied from class:JRTResolves the sink used by file redirection. The gawk special filenames/dev/stdoutand/dev/stderr(and their/dev/fd/1and/dev/fd/2spellings) are routed to the streams the process already holds open instead of being opened, and therefore truncated, as regular files, and/dev/nulldesignates the platform's null device on Windows too.- Overrides:
getFileAwkSinkin classJRT- Parameters:
filename- target file nameappend- whether output should be appended- Returns:
- the sink that writes to the requested file
-
getPipeAwkSink
Description copied from class:JRTResolves the sink used by pipe redirection.- Overrides:
getPipeAwkSinkin classJRT- Parameters:
cmd- command to execute- Returns:
- the sink connected to the process stdin
-
jrtGetPrintStream
Description copied from class:JRTRetrieve the PrintStream which writes to a particular file, creating the PrintStream if necessary.- Overrides:
jrtGetPrintStreamin classJRT- Parameters:
filename- The file which to write the contents of the PrintStream.append- true to append to the file, false to overwrite the file.- Returns:
- a
PrintStreamobject
-
jrtSpawnForOutput
Description copied from class:JRTRetrieve the PrintStream which shuttles data to stdin for a process, executing the process if necessary. Threads are created to shuttle the data to/from the process.- Overrides:
jrtSpawnForOutputin classJRT- Parameters:
cmd- The command to execute.- Returns:
- The PrintStream which to write to provide input data to the process.
-
jrtConsumeFileInput
Description copied from class:JRTReads one record from a file opened by a redirectedgetline.The reader is opened on first use and kept until it is explicitly closed or the VM exits. Unlike the main input loop, this transport leaves the current record (
$0and its fields), NR, FNR, and FILENAME untouched: gawk documentsgetline [var] < fileas setting only the target of the read. The consumed record is exposed throughJRT.jrtGetInputString().The gawk special filename
/dev/stdin(and its/dev/fd/0spelling) reads the standard input of the process rather than a file of that name, and/dev/nullreads the platform's null device, which reports end of input immediately on Windows too.- Overrides:
jrtConsumeFileInputin classJRT- Parameters:
filename- name of the file to read from- Returns:
truewhen a record was read;falseat end of input- Throws:
IOException- if the file cannot be opened or read; a failed open is not cached, so a latergetlinefrom the same name retries it
-
jrtConsumeCommandInput
Description copied from class:JRTReads one record from the output of a command spawned by a redirectedgetline.The process is spawned on first use and kept until the pipe is explicitly closed or the VM exits. As with file redirection, the current record (
$0and its fields), NR, FNR, and FILENAME are left untouched: gawk documentscmd | getline [var]as setting only the target of the read. The consumed record is exposed throughJRT.jrtGetInputString().- Overrides:
jrtConsumeCommandInputin classJRT- Parameters:
cmd- the command to execute- Returns:
truewhen a record was read;falseat end of input- Throws:
IOException- if the process cannot be spawned; a failed spawn is not cached, so a latergetlinefrom the same command retries it
-
jrtSystem
Description copied from class:JRTExecutes the command specified by cmd and waits for termination, returning an Integer object containing the return code. The command inherits the standard input of the JVM when Jawk reads the real standard input (CLI runs), as POSIX requires ofsystem(); otherwise its standard input is closed. Threads are created to shuttle stdout and stderr of the command to stdout/stderr of the calling process.
-