25 lines
1023 B
Bash
Executable File
25 lines
1023 B
Bash
Executable File
#!/bin/bash
|
|
# Trial parity: limit DNS to the model endpoint and the toolkit's telemetry, so a session
|
|
# captured here cannot depend on network the trial agent will not have. Opt-in, best-effort.
|
|
#
|
|
# Its own lifecycle step, NOT part of post-start.sh: post-create.sh calls post-start to get
|
|
# postgres up before it installs the repo's dependencies, so a jail applied there breaks
|
|
# `bundle install` on every fresh container. postStartCommand runs after postCreateCommand.
|
|
set -u
|
|
|
|
[ -f /workspace/.devcontainer/dns-jail.sh ] || exit 0
|
|
# Read the one line rather than sourcing: with the jail off this must not execute the
|
|
# worker's .env as a side effect.
|
|
if [ "${RACCOON_DNS_JAIL:-0}" != "1" ] &&
|
|
! grep -qE '^[[:space:]]*(export[[:space:]]+)?RACCOON_DNS_JAIL[[:space:]]*=[[:space:]]*"?1"?[[:space:]]*(#.*)?$' \
|
|
/workspace/.env 2>/dev/null; then
|
|
exit 0
|
|
fi
|
|
(
|
|
set -a
|
|
# shellcheck disable=SC1091
|
|
. /workspace/.env 2>/dev/null || true
|
|
set +a
|
|
bash /workspace/.devcontainer/dns-jail.sh
|
|
) || true
|