| 1194 | /*** Options ***/ |
| 1195 | |
| 1196 | static void __attribute__((format(printf,1,2))) |
| 1197 | usage(const char *msg, ...) |
| 1198 | { |
| 1199 | if (msg != NULL) |
| 1200 | { |
| 1201 | va_list args; |
| 1202 | va_start(args, msg); |
| 1203 | vfprintf(stderr, msg, args); |
| 1204 | va_end(args); |
| 1205 | fprintf(stderr, "Try 'isolate' --help' for more information.\n"); |
| 1206 | exit(2); |
| 1207 | } |
| 1208 | printf("\ |
| 1209 | Usage: isolate [<options>] <command>\n\ |
| 1210 | \n\ |
| 1211 | Options:\n\ |
| 1212 | --as-uid=<uid>\tPerform action on behalf of a given user (requires root)\n\ |
| 1213 | --as-gid=<gid>\tPerform action on behalf of a given group (requires root)\n\ |
| 1214 | -b, --box-id=<id>\tWhen multiple sandboxes are used in parallel, each must get a unique ID\n\ |
| 1215 | --cg\t\tEnable use of control groups\n\ |
| 1216 | --cg-mem=<size>\tLimit memory usage of the control group to <size> KB\n\ |
| 1217 | -c, --chdir=<dir>\tChange directory to <dir> before executing the program\n\ |
| 1218 | --core=<size>\tLimit core files to <size> KB (default: 0)\n\ |
| 1219 | -d, --dir=<dir>\t\tMake a directory <dir> visible inside the sandbox\n\ |
| 1220 | --dir=<in>=<out>\tMake a directory <out> outside visible as <in> inside\n\ |
| 1221 | --dir=<in>=\t\tDelete a previously defined directory rule (even a default one)\n\ |
| 1222 | --dir=...:<opt>\tSpecify options for a rule:\n\ |
| 1223 | \t\t\t\tdev\tAllow access to block/char devices\n\ |
| 1224 | \t\t\t\tfs\tMount a filesystem (e.g., --dir=/proc:proc:fs)\n\ |
| 1225 | \t\t\t\tmaybe\tSkip the rule if <out> does not exist\n\ |
| 1226 | \t\t\t\tnoexec\tDo not allow execution of binaries\n\ |
| 1227 | \t\t\t\tnorec\tDo not bind the directory recursively\n\ |
| 1228 | \t\t\t\trw\tAllow read-write access\n\ |
| 1229 | \t\t\t\ttmp\tCreate as a temporary directory (implies rw)\n\ |
| 1230 | -D, --no-default-dirs\tDo not add default directory rules\n\ |
| 1231 | -f, --fsize=<size>\tMax size (in KB) of files that can be created\n\ |
| 1232 | -E, --env=<var>\t\tInherit the environment variable <var> from the parent process\n\ |
| 1233 | -E, --env=<var>=<val>\tSet the environment variable <var> to <val>; unset it if <var> is empty\n\ |
| 1234 | -x, --extra-time=<time>\tSet extra timeout, before which a timing-out program is not yet killed,\n\ |
| 1235 | \t\t\tso that its real execution time is reported (seconds, fractions allowed)\n\ |
| 1236 | -e, --full-env\t\tInherit full environment of the parent process\n\ |
| 1237 | --inherit-fds\tInherit all file descriptors of the parent process\n\ |
| 1238 | -m, --mem=<size>\tLimit address space to <size> KB\n\ |
| 1239 | -M, --meta=<file>\tOutput process information to <file> (name:value)\n\ |
| 1240 | -n, --open-files=<max>\tLimit number of open files to <max> (default: 64, 0=unlimited)\n\ |
| 1241 | -q, --quota=<blk>,<ino>\tSet disk quota to <blk> blocks and <ino> inodes\n\ |
| 1242 | --share-net\t\tShare network namespace with the parent process\n\ |
| 1243 | -s, --silent\t\tDo not print status messages except for fatal errors\n\ |
| 1244 | --special-files\tKeep non-regular files (symlinks etc.) produced inside sandbox\n\ |
| 1245 | -k, --stack=<size>\tLimit stack size to <size> KB (default: 0=unlimited)\n\ |
| 1246 | -r, --stderr=<file>\tRedirect stderr to <file>\n\ |
| 1247 | --stderr-to-stdout\tRedirect stderr to stdout\n\ |
| 1248 | -i, --stdin=<file>\tRedirect stdin from <file>\n\ |
| 1249 | -o, --stdout=<file>\tRedirect stdout to <file>\n\ |
| 1250 | -p, --processes[=<max>]\tEnable multiple processes (at most <max> of them); needs --cg\n\ |
| 1251 | -t, --time=<time>\tSet run time limit (seconds, fractions allowed)\n\ |
| 1252 | --tty-hack\t\tAllow interactive programs in the sandbox (see man for caveats)\n\ |
| 1253 | -v, --verbose\t\tBe verbose (use multiple times for even more verbosity)\n\ |