返回 DeepSeek-Reasonix
package_grants.go
根目录 / desktop / package_grants.go
1 package main
2
3 import (
4 "encoding/json"
5 "fmt"
6 "io"
7 "os"
8 "path/filepath"
9 "strings"
10
11 "reasonix/internal/packagegrant"
12 )
13
14 const (
15 stripPackageGrantsFlag = "-strip-package-grants"
16 stripPackageGrantsApp = "-app"
17 )
18
19 // stripPackageGrantsRequest reports whether args ask for the grant pass, and the
20 // application executable it names.
21 func stripPackageGrantsRequest(args []string) (string, bool) {
22 requested, app := false, ""
23 for i := 0; i < len(args); i++ {
24 name := "-" + strings.TrimLeft(args[i], "-")
25 switch {
26 case name == stripPackageGrantsFlag:
27 requested = true
28 case name == stripPackageGrantsApp && i+1 < len(args):
29 app = args[i+1]
30 i++
31 default:
32 if value, ok := strings.CutPrefix(name, stripPackageGrantsApp+"="); ok {
33 app = value
34 }
35 }
36 }
37 return app, requested
38 }
39
40 // stripPackageGrants works on the directory the application runs from and is
41 // never handed a directory directly: the grants it removes are the ones that
42 // stop that application's own sandboxed children from loading, and no other
43 // tree is this mode's to change. The report goes to out as one JSON line.
44 func stripPackageGrants(out, logs io.Writer, app string) int {
45 if strings.TrimSpace(app) == "" {
46 fmt.Fprintln(logs, "strip-package-grants: -app names no application")
47 return 2
48 }
49 exe, err := filepath.EvalSymlinks(app)
50 if err != nil {
51 fmt.Fprintf(logs, "strip-package-grants: %v\n", err)
52 return 2
53 }
54 if info, err := os.Stat(exe); err != nil || !info.Mode().IsRegular() {
55 fmt.Fprintf(logs, "strip-package-grants: %s is not an application executable\n", exe)
56 return 2
57 }
58 report, err := packagegrant.Strip(filepath.Dir(exe))
59 if err != nil {
60 fmt.Fprintf(logs, "strip-package-grants: %v\n", err)
61 return 1
62 }
63 for _, refused := range report.Refused {
64 fmt.Fprintf(logs, "strip-package-grants: kept a grant at %s: %v\n", refused.Path, refused.Err)
65 }
66 for _, unread := range report.Unread {
67 fmt.Fprintf(logs, "strip-package-grants: could not read %s: %v\n", unread.Path, unread.Err)
68 }
69 if err := json.NewEncoder(out).Encode(report); err != nil {
70 return 1
71 }
72 return 0
73 }
74
74 lines GO