返回 DeepSeek-Reasonix
host_secret_paths.go
根目录 / internal / config / host_secret_paths.go
1 package config
2
3 import (
4 "path/filepath"
5 "slices"
6 "strings"
7 "sync"
8 )
9
10 var hostSecretPaths struct {
11 sync.Mutex
12 paths []string
13 }
14
15 // RegisterHostSecretPath records a file this process holds a secret in, such
16 // as serve's --token-file, so runtime sandboxes deny reads of it.
17 func RegisterHostSecretPath(path string) {
18 path = strings.TrimSpace(path)
19 if path == "" {
20 return
21 }
22 if abs, err := filepath.Abs(path); err == nil {
23 path = abs
24 }
25 hostSecretPaths.Lock()
26 defer hostSecretPaths.Unlock()
27 if slices.Contains(hostSecretPaths.paths, path) {
28 return
29 }
30 hostSecretPaths.paths = append(hostSecretPaths.paths, path)
31 }
32
33 // HostSecretReadRoots lists what runtime sandboxes must not read: the remote
34 // serve state directory, which holds serve launch tokens, and every path
35 // passed to RegisterHostSecretPath.
36 func HostSecretReadRoots() []string {
37 var out []string
38 if dir := RemoteStateDir(); dir != "" {
39 out = append(out, dir)
40 }
41 hostSecretPaths.Lock()
42 defer hostSecretPaths.Unlock()
43 return append(out, hostSecretPaths.paths...)
44 }
45
45 lines GO