ObjFW
Instance Methods | Class Methods | Properties | List of all members
OFSandbox Class Reference

A class which describes a sandbox for the application. More...

#import <ObjFW/OFSandbox.h>

Inheritance diagram for OFSandbox:
Inheritance graph
[legend]
Collaboration diagram for OFSandbox:
Collaboration graph
[legend]

Instance Methods

(void) - unveilPath:permissions:
 "Unveils" the specified path, meaning that it becomes visible from the sandbox with the specified permissions. More...
 
- Instance Methods inherited from OFObject
(instancetype) - init
 Initializes an already allocated object. More...
 
(nullable OFMethodSignature *) - methodSignatureForSelector:
 Returns the method signature for the specified selector. More...
 
(void) - dealloc
 Deallocates the object. More...
 
(void) - performSelector:afterDelay:
 Performs the specified selector after the specified delay. More...
 
(void) - performSelector:withObject:afterDelay:
 Performs the specified selector with the specified object after the specified delay. More...
 
(void) - performSelector:withObject:withObject:afterDelay:
 Performs the specified selector with the specified objects after the specified delay. More...
 
(void) - performSelector:withObject:withObject:withObject:afterDelay:
 Performs the specified selector with the specified objects after the specified delay. More...
 
(void) - performSelector:withObject:withObject:withObject:withObject:afterDelay:
 Performs the specified selector with the specified objects after the specified delay. More...
 
(void) - performSelector:onThread:waitUntilDone:
 Performs the specified selector on the specified thread. More...
 
(void) - performSelector:onThread:withObject:waitUntilDone:
 Performs the specified selector on the specified thread with the specified object. More...
 
(void) - performSelector:onThread:withObject:withObject:waitUntilDone:
 Performs the specified selector on the specified thread with the specified objects. More...
 
(void) - performSelector:onThread:withObject:withObject:withObject:waitUntilDone:
 Performs the specified selector on the specified thread with the specified objects. More...
 
(void) - performSelector:onThread:withObject:withObject:withObject:withObject:waitUntilDone:
 Performs the specified selector on the specified thread with the specified objects. More...
 
(void) - performSelectorOnMainThread:waitUntilDone:
 Performs the specified selector on the main thread. More...
 
(void) - performSelectorOnMainThread:withObject:waitUntilDone:
 Performs the specified selector on the main thread with the specified object. More...
 
(void) - performSelectorOnMainThread:withObject:withObject:waitUntilDone:
 Performs the specified selector on the main thread with the specified objects. More...
 
(void) - performSelectorOnMainThread:withObject:withObject:withObject:waitUntilDone:
 Performs the specified selector on the main thread with the specified objects. More...
 
(void) - performSelectorOnMainThread:withObject:withObject:withObject:withObject:waitUntilDone:
 Performs the specified selector on the main thread with the specified objects. More...
 
(void) - performSelector:onThread:afterDelay:
 Performs the specified selector on the specified thread after the specified delay. More...
 
(void) - performSelector:onThread:withObject:afterDelay:
 Performs the specified selector on the specified thread with the specified object after the specified delay. More...
 
(void) - performSelector:onThread:withObject:withObject:afterDelay:
 Performs the specified selector on the specified thread with the specified objects after the specified delay. More...
 
(void) - performSelector:onThread:withObject:withObject:withObject:afterDelay:
 Performs the specified selector on the specified thread with the specified objects after the specified delay. More...
 
(void) - performSelector:onThread:withObject:withObject:withObject:withObject:afterDelay:
 Performs the specified selector on the specified thread with the specified objects after the specified delay. More...
 
(nullable id- forwardingTargetForSelector:
 This method is called when resolveClassMethod: or resolveInstanceMethod: returned false. It should return a target to which the message should be forwarded. More...
 
(void) - doesNotRecognizeSelector:
 Handles messages which are not understood by the receiver. More...
 
- Instance Methods inherited from <OFObject>
(unsigned long) - hash
 Returns a 32 bit hash for the object. More...
 
(unsigned int) - retainCount
 Returns the retain count. More...
 
(bool) - isProxy
 Returns whether the object is a proxy object. More...
 
(bool) - allowsWeakReference
 Returns whether the object allows weak references. More...
 
(bool) - isKindOfClass:
 Returns a boolean whether the object of the specified kind. More...
 
(bool) - isMemberOfClass:
 Returns a boolean whether the object is a member of the specified class. More...
 
(bool) - respondsToSelector:
 Returns a boolean whether the object responds to the specified selector. More...
 
(nullable IMP- methodForSelector:
 Returns the implementation for the specified selector. More...
 
(nullable id- performSelector:
 Performs the specified selector. More...
 
(nullable id- performSelector:withObject:
 Performs the specified selector with the specified object. More...
 
(nullable id- performSelector:withObject:withObject:
 Performs the specified selector with the specified objects. More...
 
(nullable id- performSelector:withObject:withObject:withObject:
 Performs the specified selector with the specified objects. More...
 
(nullable id- performSelector:withObject:withObject:withObject:withObject:
 Performs the specified selector with the specified objects. More...
 
(bool) - isEqual:
 Checks two objects for equality. More...
 
(instancetype) - retain
 Increases the retain count. More...
 
(void) - release
 Decreases the retain count. More...
 
(instancetype) - autorelease
 Adds the object to the topmost autorelease pool of the thread's autorelease pool stack. More...
 
(instancetype) - self
 Returns the receiver. More...
 
(bool) - retainWeakReference
 Retain a weak reference to this object. More...
 
- Instance Methods inherited from <OFCopying>
(id- copy
 Copies the object. More...
 

Class Methods

(instancetype) + sandbox
 Create a new, autorelease OFSandbox.
 
- Class Methods inherited from OFObject
(void) + load
 A method which is called once when the class is loaded into the runtime. More...
 
(void) + unload
 A method which is called when the class is unloaded from the runtime. More...
 
(void) + initialize
 A method which is called the moment before the first call to the class is being made. More...
 
(instancetype) + alloc
 Allocates memory for an instance of the class and sets up the memory pool for the object. More...
 
(instancetype) + new
 Calls alloc on self and then init on the returned object. More...
 
(Class+ class
 Returns the class. More...
 
(OFString *) + className
 Returns the name of the class as a string. More...
 
(bool) + isSubclassOfClass:
 Returns a boolean whether the class is a subclass of the specified class. More...
 
(nullable Class+ superclass
 Returns the superclass of the class. More...
 
(bool) + instancesRespondToSelector:
 Checks whether instances of the class respond to a given selector. More...
 
(bool) + conformsToProtocol:
 Checks whether the class conforms to a given protocol. More...
 
(nullable IMP+ instanceMethodForSelector:
 Returns the implementation of the instance method for the specified selector. More...
 
(nullable OFMethodSignature *) + instanceMethodSignatureForSelector:
 Returns the method signature of the instance method for the specified selector. More...
 
(OFString *) + description
 Returns a description for the class, which is usually the class name. More...
 
(nullable IMP+ replaceClassMethod:withMethodFromClass:
 Replaces a class method with a class method from another class. More...
 
(nullable IMP+ replaceInstanceMethod:withMethodFromClass:
 Replaces an instance method with an instance method from another class. More...
 
(void) + inheritMethodsFromClass:
 Adds all methods from the specified class to the class that is the receiver. More...
 
(bool) + resolveClassMethod:
 Try to resolve the specified class method. More...
 
(bool) + resolveInstanceMethod:
 Try to resolve the specified instance method. More...
 
(id+ copy
 Returns the class. More...
 

Properties

bool allowsStdIO
 Allows IO operations on previously allocated file descriptors.
 
bool allowsReadingFiles
 Allows read access to the file system.
 
bool allowsWritingFiles
 Allows write access to the file system.
 
bool allowsCreatingFiles
 Allows creating files in the file system.
 
bool allowsCreatingSpecialFiles
 Allows creating special files in the file system.
 
bool allowsTemporaryFiles
 Allows creating, reading and writing temporary files in /tmp.
 
bool allowsIPSockets
 Allows using IP sockets.
 
bool allowsMulticastSockets
 Allows multicast sockets.
 
bool allowsChangingFileAttributes
 Allows explicit changes to file attributes.
 
bool allowsFileOwnerChanges
 Allows changing ownership of files.
 
bool allowsFileLocks
 Allows file locks.
 
bool allowsUNIXSockets
 Allows UNIX sockets.
 
bool allowsDNS
 Allows syscalls necessary for DNS lookups.
 
bool allowsUserDatabaseReading
 Allows to look up users and groups.
 
bool allowsFileDescriptorSending
 Allows sending file descriptors via sendmsg().
 
bool allowsFileDescriptorReceiving
 Allows receiving file descriptors via recvmsg().
 
bool allowsTape
 Allows MTIOCGET and MTIOCTOP operations on tape devices.
 
bool allowsTTY
 Allows read-write operations and ioctls on the TTY.
 
bool allowsProcessOperations
 Allows various process relationshop operations.
 
bool allowsExec
 Allows execve().
 
bool allowsProtExec
 Allows PROT_EXEC for mmap() and mprotect().
 
bool allowsSetTime
 Allows settime().
 
bool allowsPS
 Allows introspection of processes on the system.
 
bool allowsVMInfo
 Allows introspection of the system's virtual memory.
 
bool allowsChangingProcessRights
 Allows changing the rights of process, for example the UID.
 
bool allowsPF
 Allows certain ioctls on the PF device.
 
bool allowsAudio
 Allows certain ioctls on audio devices.
 
bool allowsBPF
 Allows BIOCGSTATS to collect statistics from a BPF device.
 
bool allowsUnveil
 Allows unveiling more paths.
 
bool returnsErrors
 Returns errors instead of killing the process.
 
OFArrayunveiledPaths
 A list of unveiled paths.
 
- Properties inherited from OFObject
OFStringclassName
 The name of the object's class.
 
OFStringdescription
 A description for the object. More...
 
OFStringstringBySerializing
 The object serialized as a string.
 

Detailed Description

A class which describes a sandbox for the application.

Method Documentation

◆ unveilPath:permissions:

- (void) unveilPath: (OFString *)  path
permissions: (OFString *)  permissions 

"Unveils" the specified path, meaning that it becomes visible from the sandbox with the specified permissions.

Parameters
pathThe path to unveil
permissionsThe permissions for the path. The following permissions can be combined:
Permission Description
r Make the path available for reading, like
| allowsReadingFiles w | Make the path available for writing, like | allowsWritingFiles x | Make the path available for executing, like | allowsExec c | Make the path available for creation and | deletion, like allowsCreatingFiles

The documentation for this class was generated from the following files: