Documentation
¶
Overview ¶
Package filesystem implements cap/filesystem.Service over the local disk (filesystem/local) and host-absolute atomic replace for runtime sidecars that already hold a resolved path.
Index ¶
- func New(cfg Config, deps Deps) (capfs.Service, error)
- func NewSandboxed(_ SandboxConfig, deps SandboxDeps) (capfs.Service, error)
- func TrimRedundantFSRootPrefix(fsRoot, path string) string
- func WriteAtomic(path string, data []byte, perm os.FileMode) error
- type Config
- type Deps
- type IgnoreMatcher
- type SandboxConfig
- type SandboxDeps
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func New ¶ added in v0.3.33
New registers filesystem/local: local-disk cap/filesystem.Service over workspace.Resolve.
func NewSandboxed ¶ added in v0.3.48
func NewSandboxed(_ SandboxConfig, deps SandboxDeps) (capfs.Service, error)
NewSandboxed registers filesystem/sandbox: a cap/filesystem.Service decorator that enforces the sandbox/bwrap tenant view in-process (CheckRead/CheckWrite). bwrap only confines shell/ACP subprocesses; model file tools (tool/fs-workspace) run Go code inside the runner, so they go through this decorator to share the same view: neighbor tenants and masked paths are unreadable; only the tenant root and rwBinds are writable (everything else is denied, the in-process equivalent of EROFS).
func TrimRedundantFSRootPrefix ¶ added in v0.3.33
TrimRedundantFSRootPrefix drops a leading fsRoot/ prefix when the fs store root is already fsRoot. Used by filesystem/local when models pass paths like work/upload/foo while config.root is work.
Types ¶
type Config ¶ added in v0.3.33
type Config struct {
// Root is directory relative to the workspace root; may use global: or local: prefix.
Root string `json:"root"`
// Unrestricted disables path confinement to Root (absolute paths and .. are allowed).
Unrestricted bool `json:"unrestricted,omitempty"`
}
Config is filesystem/local: a workspace-rooted disk store.
func (*Config) SetDefaults ¶ added in v0.3.48
func (c *Config) SetDefaults()
SetDefaults implements pluginkit.Defaulter.
type IgnoreMatcher ¶
type IgnoreMatcher struct {
// contains filtered or unexported fields
}
IgnoreMatcher applies .gitignore-style patterns relative to a workspace root.
func LoadIgnoreMatcher ¶
func LoadIgnoreMatcher(workspaceRoot string) (*IgnoreMatcher, error)
LoadIgnoreMatcher reads the workspace-root .gitignore when present and always ignores .git, node_modules, and .env.
type SandboxConfig ¶ added in v0.3.48
type SandboxConfig struct{}
SandboxConfig configures filesystem/sandbox (the view config lives on the sandbox/bwrap instance).
type SandboxDeps ¶ added in v0.3.48
type SandboxDeps struct {
FS capfs.Service `json:"fs"`
Sandbox capsandbox.Service `json:"sandbox"`
}
SandboxDeps for filesystem/sandbox.