File: dot_sandbox.1

package info (click to toggle)
graphviz 14.0.5-2
  • links: PTS
  • area: main
  • in suites: forky, sid
  • size: 139,388 kB
  • sloc: ansic: 141,938; cpp: 11,957; python: 7,766; makefile: 4,043; yacc: 3,030; xml: 2,972; tcl: 2,495; sh: 1,388; objc: 1,159; java: 560; lex: 423; perl: 243; awk: 156; pascal: 139; php: 58; ruby: 49; cs: 31; sed: 1
file content (32 lines) | stat: -rw-r--r-- 888 bytes parent folder | download | duplicates (2)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
.TH DOT_SANDBOX 1
.SH NAME
dot_sandbox \- Graphviz sandbox
.SH SYNOPSIS
\fBdot_sandbox\fR \fIoptions...\fR
.SH DESCRIPTION
This program is a wrapper around Graphviz. It aims to provide a safe environment
for the processing of untrusted input graphs and command line options. More
precisely:
.RS
.IP \[bu] 2
No network access will be allowed.
.IP \[bu]
The file system will be read-only. Command line options like \fB\-o ...\fR and
\fB\-O\fR will not work. It is expected that the caller will render to
\fBstdout\fR and pipe the output to their desired file.
.RE
.PP
The command line options to \fBdot_sandbox\fR are command line options to be
passed to \fBdot\fR. Options are passed through unmodified.
.PP
The following sandboxing mechanisms are supported:
.RS
.IP \[bu] 2
Bubblewrap
.IP \[bu]
macOS \fBsandbox-exec\fR
.RE
.SH "SEE ALSO"
.BR dot (1),
.BR bwrap (1),
.BR sandbox-exec (1)