mirror of
https://github.com/pchuan98/codex.git
synced 2026-07-01 00:31:56 +08:00
a few fixes based on testing feedback: * ensure cap_sid file is always written by elevated setup. * always log to same file whether using elevated sandbox or not * process potentially slow ACE write operations in parallel * dedupe write roots so we don't double process any * don't try to create read/write ACEs on the same directories, due to race condition
67 lines
1.9 KiB
Rust
67 lines
1.9 KiB
Rust
use anyhow::Context;
|
|
use anyhow::Result;
|
|
use rand::rngs::SmallRng;
|
|
use rand::RngCore;
|
|
use rand::SeedableRng;
|
|
use serde::Deserialize;
|
|
use serde::Serialize;
|
|
use std::fs;
|
|
use std::path::Path;
|
|
use std::path::PathBuf;
|
|
|
|
#[derive(Serialize, Deserialize, Clone, Debug)]
|
|
pub struct CapSids {
|
|
pub workspace: String,
|
|
pub readonly: String,
|
|
}
|
|
|
|
pub fn cap_sid_file(codex_home: &Path) -> PathBuf {
|
|
codex_home.join("cap_sid")
|
|
}
|
|
|
|
fn make_random_cap_sid_string() -> String {
|
|
let mut rng = SmallRng::from_entropy();
|
|
let a = rng.next_u32();
|
|
let b = rng.next_u32();
|
|
let c = rng.next_u32();
|
|
let d = rng.next_u32();
|
|
format!("S-1-5-21-{}-{}-{}-{}", a, b, c, d)
|
|
}
|
|
|
|
fn persist_caps(path: &Path, caps: &CapSids) -> Result<()> {
|
|
if let Some(dir) = path.parent() {
|
|
fs::create_dir_all(dir)
|
|
.with_context(|| format!("create cap sid dir {}", dir.display()))?;
|
|
}
|
|
let json = serde_json::to_string(caps)?;
|
|
fs::write(path, json).with_context(|| format!("write cap sid file {}", path.display()))?;
|
|
Ok(())
|
|
}
|
|
|
|
pub fn load_or_create_cap_sids(codex_home: &Path) -> Result<CapSids> {
|
|
let path = cap_sid_file(codex_home);
|
|
if path.exists() {
|
|
let txt = fs::read_to_string(&path)
|
|
.with_context(|| format!("read cap sid file {}", path.display()))?;
|
|
let t = txt.trim();
|
|
if t.starts_with('{') && t.ends_with('}') {
|
|
if let Ok(obj) = serde_json::from_str::<CapSids>(t) {
|
|
return Ok(obj);
|
|
}
|
|
} else if !t.is_empty() {
|
|
let caps = CapSids {
|
|
workspace: t.to_string(),
|
|
readonly: make_random_cap_sid_string(),
|
|
};
|
|
persist_caps(&path, &caps)?;
|
|
return Ok(caps);
|
|
}
|
|
}
|
|
let caps = CapSids {
|
|
workspace: make_random_cap_sid_string(),
|
|
readonly: make_random_cap_sid_string(),
|
|
};
|
|
persist_caps(&path, &caps)?;
|
|
Ok(caps)
|
|
}
|