1/* 2 * Copyright (C) 2014 Apple Inc. All rights reserved. 3 * 4 * Redistribution and use in source and binary forms, with or without 5 * modification, are permitted provided that the following conditions 6 * are met: 7 * 1. Redistributions of source code must retain the above copyright 8 * notice, this list of conditions and the following disclaimer. 9 * 2. Redistributions in binary form must reproduce the above copyright 10 * notice, this list of conditions and the following disclaimer in the 11 * documentation and/or other materials provided with the distribution. 12 * 13 * THIS SOFTWARE IS PROVIDED BY APPLE INC. AND ITS CONTRIBUTORS ``AS IS'' 14 * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, 15 * THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR 16 * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL APPLE INC. OR ITS CONTRIBUTORS 17 * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR 18 * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF 19 * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS 20 * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN 21 * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) 22 * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF 23 * THE POSSIBILITY OF SUCH DAMAGE. 24 */ 25 26#include "config.h" 27#include "SandboxUtilities.h" 28 29#include <array> 30#include <wtf/text/WTFString.h> 31 32#if __has_include(<sandbox/private.h>) 33#import <sandbox/private.h> 34#else 35enum sandbox_filter_type { 36 SANDBOX_FILTER_NONE, 37}; 38extern "C" { 39int sandbox_check(pid_t, const char *operation, enum sandbox_filter_type, ...); 40int sandbox_container_path_for_pid(pid_t, char *buffer, size_t bufsize); 41} 42#endif 43 44namespace WebKit { 45 46bool processIsSandboxed(pid_t pid) 47{ 48 return sandbox_check(pid, nullptr, SANDBOX_FILTER_NONE); 49} 50 51static bool processHasContainer(pid_t pid) 52{ 53 std::array<char, MAXPATHLEN> path; 54 55 if (sandbox_container_path_for_pid(pid, path.data(), path.size())) 56 return false; 57 58 if (!path[0]) 59 return false; 60 61 return true; 62} 63 64bool processHasContainer() 65{ 66 static bool hasContainer = processHasContainer(getpid()); 67 68 return hasContainer; 69} 70 71String pathForProcessContainer() 72{ 73 std::array<char, MAXPATHLEN> path; 74 path[0] = 0; 75 sandbox_container_path_for_pid(getpid(), path.data(), path.size()); 76 77 return String::fromUTF8(path.data()); 78} 79 80} 81