返回 DeepSeek-Reasonix
serve_launch_token.go
根目录 / internal / cli / serve_launch_token.go
1 package cli
2
3 import (
4 "errors"
5 "fmt"
6 "os"
7 "path/filepath"
8 "strings"
9
10 "reasonix/internal/config"
11 "reasonix/internal/fileutil"
12 )
13
14 // writeLaunchTokenFile leaves the launch token a serve's clients need
15 // in a 0600 file under the remote state directory, which runtime sandboxes
16 // deny. The terminal is no place for it: a sandboxed command can read back a
17 // multiplexer's scrollback.
18 func writeLaunchTokenFile(dir, token string) (string, error) {
19 if strings.TrimSpace(dir) == "" {
20 return "", errors.New("cannot store the launch token: Reasonix home is empty")
21 }
22 if err := os.MkdirAll(dir, 0o700); err != nil {
23 return "", err
24 }
25 path := filepath.Join(dir, fmt.Sprintf("launch-%d.token", os.Getpid()))
26 _ = os.Remove(path)
27 if err := fileutil.AtomicCreateFile(path, []byte(token+"\n"), 0o600); err != nil {
28 return "", err
29 }
30 config.RegisterHostSecretPath(path)
31 return path, nil
32 }
33
34 // launchTokenLocation is where serve tells the operator to
35 // find its launch token: the --token-file it was given, or a file it writes.
36 func launchTokenLocation(token string, opts serveFrontendOptions, resources *serveFrontendResources) (string, error) {
37 if opts.tokenFile != "" {
38 return opts.tokenFile, nil
39 }
40 path, err := writeLaunchTokenFile(config.RemoteStateDir(), token)
41 if err != nil {
42 return "", err
43 }
44 resources.artifacts = append(resources.artifacts, path)
45 return path, nil
46 }
47
47 lines GO