aboutsummaryrefslogtreecommitdiffhomepage
AgeCommit message (Collapse)Author
2026-01-03internal/pkg: compute identifier from depsOphestra
This provides infrastructure for computing a deterministic identifier based on current artifact kind, opaque parameters data, and optional dependency kind and identifiers. Signed-off-by: Ophestra <cat@gensokyo.uk>
2026-01-03internal/pkg: create work directoryOphestra
This is used for artifacts that cure into directories. Signed-off-by: Ophestra <cat@gensokyo.uk>
2026-01-03internal/pkg: optionally validate flat pathnamesOphestra
This makes the decoder safe against untrusted input without hurting performance for a trusted stream. This should still not be called against untrusted input though. Signed-off-by: Ophestra <cat@gensokyo.uk>
2026-01-03internal/pkg: implement http artifactOphestra
This is useful for downloading source tarballs from the internet. Signed-off-by: Ophestra <cat@gensokyo.uk>
2026-01-03go: 1.25Ophestra
Signed-off-by: Ophestra <cat@gensokyo.uk>
2026-01-02internal/pkg: relocate cache test helperOphestra
This is useful for other tests that need a cache instance. Signed-off-by: Ophestra <cat@gensokyo.uk>
2026-01-02internal/pkg: encode entry in custom formatOphestra
The fact that Gob serialisation is deterministic is an implementation detail. This change replaces Gob with a simple custom format. Signed-off-by: Ophestra <cat@gensokyo.uk>
2026-01-02internal/pkg: implement caching for filesOphestra
This change contains primitives for validating and caching single-file artifacts. Signed-off-by: Ophestra <cat@gensokyo.uk>
2026-01-02dist: install sharefsOphestra
This also removes the deprecated hpkg program. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-12-27cmd/sharefs: prepare directory earlyOphestra
This change also checks against filesystem daemon running as root early. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-12-27nix: configure sharefs via fileSystemsOphestra
Turns out this did not work because in the vm test harness, virtualisation.fileSystems completely and silently overrides fileSystems, causing its contents to not even be evaluated anymore. This is not documented as far as I can tell, and is not obvious by any stretch of the imagination. The current hack is cargo culted from nix-community/impermanence and hopefully lasts until this project fully replaces nix. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-12-27cmd/sharefs: create directory as rootOphestra
This optional behaviour is required on NixOS as it is otherwise impossible to set this up: systemd.mounts breaks startup order somehow even though my unit looks identical to generated ones, fileSystems does not support any kind of initialisation or ordering other than against other mount points. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-12-27cmd/sharefs: handle mount -t fuse.sharefsOphestra
This should have been handled in a custom option parsing function, but that much extra complexity is unnecessary for this edge case. Honestly I do not know why libfuse does not handle this itself. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-12-27cmd/sharefs: check option parsing behaviourOphestra
This change makes it possible to check parseOpts behaviour as part of Go tests. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-12-27cmd/sharefs: containerise filesystem daemonOphestra
This replaces the forking daemonise libfuse function which prevents Go callbacks from calling into the runtime. This also enforces least privilege on the daemon process. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-12-27container: optionally allow orphanOphestra
This is required for the typical daemonise use case. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-12-27cmd/sharefs: opaque setup stateOphestra
This allows unrestricted use of the type system and prepares setup code for cross-process initialisation. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-12-27cmd/sharefs: expand fuse_mainOphestra
This change should not change behaviour other than making output more consistent. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-12-27cmd/sharefs: improve help messageOphestra
This improves consistency with the fuse_main help message. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-12-26cmd/sharefs: allocate sharefs_private earlyOphestra
This also removes global state used by sharefs_init. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-12-26nix: set noatime on sharefsOphestra
Could improve performance, atime is not useful for this filesystem anyway. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-12-26cmd/sharefs/test: check option handlingOphestra
This verifies behaviour related to setuid/setgid when starting as root. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-12-26nix: do not restart sharefsOphestra
This avoids disrupting running containers. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-12-26cmd/sharefs: rename fuse-helper to fuse-operationsOphestra
This is not really just library wrapper functions, but instead implements the callbacks, so fuse-operations makes more sense. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-12-26cmd/sharefs: move translate_pathname body to macro wrapperOphestra
This is never called directly anywhere and it is simple enough to be included in the macro. This avoids passing the pointer around and dereferencing errno location, resulting in over 5% increase in throughput on the clang build. No change in the gcc build though. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-12-25cmd/sharefs: remove readlinkOphestra
This filesystem does not support symbolic links, so readlink is not useful, and unreachable in this case because of the check in getattr. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-12-25cmd/sharefs: implement shared filesystemOphestra
This is for passing files between applications, similar to android /sdcard. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-12-21nix: disable source fortification in devShellOphestra
This generates warnings when compiling without optimisation. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-12-19internal/pipewire: raise Core::Sync timeoutOphestra
Hopefully relieves spurious failures on a very overloaded system. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-12-19internal/pipewire: EPOLL_CTL_ADD instead of EPOLL_CTL_MODOphestra
Implementation is no longer tied down by the limitations of SyscallConn. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-12-19internal/pipewire: hold socket fd directlyOphestra
The interface provided by net is not used here and is a leftover from a previous implementation. This change removes it. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-12-19internal/pipewire: inform conn of blocking intentOphestra
The interface does not expose underlying kernel notification mechanisms. This change removes the need to poll in situations were the next call might block. This is made cumbersome by the SyscallConn interface left over from a previous implementation, it will be replaced in a later commit as the current implementation does not make use of any net.Conn methods other than Close. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-12-18internal/pipewire: sendmsg/recvmsg errors are fatalOphestra
When returned wrapped as a syscall error, these are impossible to recover from, so wrap them as a fatal error. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-12-15release: 0.3.3v0.3.3Ophestra
Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-12-15test: check shim private dir cleanupOphestra
This asserts that no shim private dir was left behind after all containers terminate. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-12-15internal/outcome: expose pipewire via pipewire-pulseOphestra
This no longer exposes the pipewire socket to the container, and instead mediates access via pipewire-pulse. This makes insecure parts of the protocol inaccessible as explained in the doc comment in hst. Closes #29. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-12-15internal/outcome: look up pipewire-pulse pathOphestra
This is for setting up the pipewire-pulse container in shim, for #29. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-12-15internal/outcome: optional shim private dirOphestra
This is a private work directory owned by the specific shim. Useful for sockets owned by this instance of the shim and requires no direct assistance from the priv-side process. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-12-15hst: add direct hardware optionOphestra
This is unfortunately the only possible setup to securely expose PipeWire to the container. Further explanation explained in the doc comment and #29. This will be implemented in a future commit. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-12-14container: sync stubbed wait4 loop after notifyOphestra
This ensures consistent state observed by wait4 loop when running against stub. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-12-14internal/pipewire: handle SecurityContext::Create errorOphestra
This method can result in an error targeting it, so it is handled here. This change also causes a call to Create to also Core::Sync, as it should have done. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-12-14internal/pipewire: SecurityContext as destructibleOphestra
This proxy can be destroyed by sending a Core::Destroy targeting it. This change implements the Destroy method by embedding destructible. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-12-14internal/pipewire: reorder context structOphestra
This change reorders and groups struct elements. This improves readability since this struct holds a lot of state loosely related to each other. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-12-14internal/pipewire: implement Core::DestroyOphestra
This change also implements pending destructible check on Sync. Destruction method should always be implemented as a wrapper of destructible.destroy. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-12-14internal/pipewire: do not emit None for spa_dictOphestra
Turns out the PipeWire server does not expect a value of type None here at all. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-12-14internal/pipewire: implement Core::CreateObjectOphestra
Nothing uses this right now, this would have to be called by wrapper methods on Registry that would search the objects Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-12-14internal/pipewire: handle nil spa_dict correctlyOphestra
This now marshals into a value of type None when the slice is nil, and correctly unmarshals from type None. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-12-14internal/pipewire: unmarshal nil pointer correctlyOphestra
This now calls unmarshalCheckTypeBounds to advance to the next message. Additionally, handling for None value is relocated to a function for reuse by other types. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-12-14internal/pipewire: return correct size for nil spa_dictOphestra
A nil spa_dict results in a None type value being sent over the wire. Signed-off-by: Ophestra <cat@gensokyo.uk>
2025-12-14internal/pipewire: move Core wrapper methods under CoreOphestra
These do not belong under Context, and is an early implementation limitation that carried over. Signed-off-by: Ophestra <cat@gensokyo.uk>