1 package io.jawk.intermediate;
2
3 /*-
4 * ╱╲╱╲╱╲╱╲╱╲╱╲╱╲╱╲╱╲╱╲╱╲╱╲╱╲╱╲╱╲╱╲╱╲╱╲╱╲╱╲
5 * Jawk
6 * ჻჻჻჻჻჻
7 * Copyright (C) 2006 - 2026 MetricsHub
8 * ჻჻჻჻჻჻
9 * This program is free software: you can redistribute it and/or modify
10 * it under the terms of the GNU Lesser General Public License as
11 * published by the Free Software Foundation, either version 3 of the
12 * License, or (at your option) any later version.
13 *
14 * This program is distributed in the hope that it will be useful,
15 * but WITHOUT ANY WARRANTY; without even the implied warranty of
16 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
17 * GNU General Lesser Public License for more details.
18 *
19 * You should have received a copy of the GNU General Lesser Public
20 * License along with this program. If not, see
21 * <http://www.gnu.org/licenses/lgpl-3.0.html>.
22 * ╲╱╲╱╲╱╲╱╲╱╲╱╲╱╲╱╲╱╲╱╲╱╲╱╲╱╲╱╲╱╲╱╲╱╲╱╲╱╲╱
23 */
24
25 import io.jawk.AwkSandboxException;
26
27 /**
28 * Variant of {@link AwkTuples} that rejects tuple generation for operations not
29 * permitted in sandbox mode.
30 */
31 public class SandboxedAwkTuples extends AwkTuples {
32
33 private static final long serialVersionUID = 1L;
34
35 /**
36 * Creates an empty sandboxed tuple list.
37 */
38 public SandboxedAwkTuples() {
39 // Same initial state as AwkTuples: only the denied operations differ.
40 }
41
42 private static void deny(String message) {
43 throw new AwkSandboxException(message);
44 }
45
46 @Override
47 public void printToFile(int numExprs, boolean append) {
48 deny("Output redirection is disabled in sandbox mode");
49 }
50
51 @Override
52 public void printToPipe(int numExprs) {
53 deny("Command execution through pipelines is disabled in sandbox mode");
54 }
55
56 @Override
57 public void printfToFile(int numExprs, boolean append) {
58 deny("Output redirection is disabled in sandbox mode");
59 }
60
61 @Override
62 public void printfToPipe(int numExprs) {
63 deny("Command execution through pipelines is disabled in sandbox mode");
64 }
65
66 @Override
67 public void system() {
68 deny("system() is disabled in sandbox mode");
69 }
70
71 @Override
72 public void useAsCommandInput(Address noRecordAddress) {
73 deny("Command execution through pipelines is disabled in sandbox mode");
74 }
75
76 @Override
77 public void useAsFileInput(Address noRecordAddress) {
78 deny("Input redirection is disabled in sandbox mode");
79 }
80
81 /**
82 * In sandbox mode, ARGC is read-only. Block any script attempt to assign
83 * to ARGC at compile time.
84 */
85 @Override
86 public void assignARGC() {
87 deny("Assigning to ARGC is disabled in sandbox mode");
88 }
89
90 /**
91 * In sandbox mode, ARGC does not need to be materialized as a global
92 * variable because the script cannot alter it. The runtime falls back
93 * to the command-line argument count.
94 */
95 @Override
96 public void argcOffset(int offset) {
97 // no-op: keep argcOffset at NULL_OFFSET; AVM.getARGC() returns the
98 // command-line argument count when ARGC is not materialized.
99 }
100
101 /**
102 * In sandbox mode, ARGV does not need to be materialized as a global
103 * variable because the script cannot alter it. The runtime falls back
104 * to a synthetic ARGV built from command-line arguments.
105 */
106 @Override
107 public void argvOffset(int offset) {
108 // no-op: keep argvOffset at NULL_OFFSET; AVM.getARGV() returns a
109 // synthetic AssocArray when ARGV is not materialized.
110 }
111 }