diff options
| author | Ophestra <cat@gensokyo.uk> | 2025-07-02 21:23:55 +0900 |
|---|---|---|
| committer | Ophestra <cat@gensokyo.uk> | 2025-07-02 21:23:55 +0900 |
| commit | a1d98823f8d17b49b432508d071b62ccd426f1ce (patch) | |
| tree | cacbe2d42f9ff3fd49b455e849770840e34d076a /path.go | |
| parent | 255b77d91dc40736b7bbd7d96b22500076b098e5 (diff) | |
hakurei: move container toplevel
Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'path.go')
| -rw-r--r-- | path.go | 94 |
1 files changed, 94 insertions, 0 deletions
diff --git a/path.go b/path.go new file mode 100644 index 00000000..bc4cccb8 --- /dev/null +++ b/path.go @@ -0,0 +1,94 @@ +package hakurei + +import ( + "errors" + "fmt" + "io/fs" + "os" + "path" + "strconv" + "strings" + "syscall" + + "git.gensokyo.uk/security/hakurei/sandbox/vfs" +) + +const ( + hostPath = "/" + hostDir + hostDir = "host" + sysrootPath = "/" + sysrootDir + sysrootDir = "sysroot" +) + +func toSysroot(name string) string { + name = strings.TrimLeftFunc(name, func(r rune) bool { return r == '/' }) + return path.Join(sysrootPath, name) +} + +func toHost(name string) string { + name = strings.TrimLeftFunc(name, func(r rune) bool { return r == '/' }) + return path.Join(hostPath, name) +} + +func createFile(name string, perm, pperm os.FileMode, content []byte) error { + if err := os.MkdirAll(path.Dir(name), pperm); err != nil { + return wrapErrSelf(err) + } + f, err := os.OpenFile(name, syscall.O_CREAT|syscall.O_EXCL|syscall.O_WRONLY, perm) + if err != nil { + return wrapErrSelf(err) + } + if content != nil { + _, err = f.Write(content) + if err != nil { + err = wrapErrSelf(err) + } + } + return errors.Join(f.Close(), err) +} + +func ensureFile(name string, perm, pperm os.FileMode) error { + fi, err := os.Stat(name) + if err != nil { + if !os.IsNotExist(err) { + return err + } + return createFile(name, perm, pperm, nil) + } + + if mode := fi.Mode(); mode&fs.ModeDir != 0 || mode&fs.ModeSymlink != 0 { + err = msg.WrapErr(syscall.EISDIR, + fmt.Sprintf("path %q is a directory", name)) + } + return err +} + +var hostProc = newProcPats(hostPath) + +func newProcPats(prefix string) *procPaths { + return &procPaths{prefix + "/proc", prefix + "/proc/self"} +} + +type procPaths struct { + prefix string + self string +} + +func (p *procPaths) stdout() string { return p.self + "/fd/1" } +func (p *procPaths) fd(fd int) string { return p.self + "/fd/" + strconv.Itoa(fd) } +func (p *procPaths) mountinfo(f func(d *vfs.MountInfoDecoder) error) error { + if r, err := os.Open(p.self + "/mountinfo"); err != nil { + return wrapErrSelf(err) + } else { + d := vfs.NewMountInfoDecoder(r) + err0 := f(d) + if err = r.Close(); err != nil { + return wrapErrSuffix(err, + "cannot close mountinfo:") + } else if err = d.Err(); err != nil { + return wrapErrSuffix(err, + "cannot parse mountinfo:") + } + return err0 + } +} |
