--readonly ran `chmod -R a-w` over the workspace after copying, but
every banger guest boots as root, and root bypasses DAC mode checks.
So a user running `vm workspace prepare ... --readonly` got the
mode bits set to 0444 but `echo x >> file` in the guest still
succeeded. The flag promised enforcement it couldn't deliver.
The feature also doesn't match the product model: workspaces are
prepared precisely so the guest CAN edit them, and `workspace
export` exists to pull those edits back as a patch. A
"read-only workspace" contradicts that loop.
Removed:
- CLI flag `--readonly` on `vm workspace prepare`
- api.VMWorkspacePrepareParams.ReadOnly field
- model.WorkspacePrepareResult.ReadOnly field
- daemon chmod dispatch in prepareVMWorkspaceGuestIO
- smoke scenario pinning the (advisory) mode-bit behavior
- misleading "exportbox-readonly" VM name in an unrelated export
test (the test is about not mutating the real git index;
renamed to exportbox-noindex-mutation)
If real enforcement becomes a user need later, the right primitive
is `chattr +i` (immutable bit — root CAN'T write) or a ro bind-mount.
Reintroducing a new flag is cheaper than debugging what the current
one actually guarantees.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
235 lines
6.4 KiB
Go
235 lines
6.4 KiB
Go
package api
|
|
|
|
import (
|
|
"time"
|
|
|
|
"banger/internal/model"
|
|
)
|
|
|
|
type Empty struct{}
|
|
|
|
type PingResult struct {
|
|
Status string `json:"status"`
|
|
PID int `json:"pid"`
|
|
Version string `json:"version,omitempty"`
|
|
Commit string `json:"commit,omitempty"`
|
|
BuiltAt string `json:"built_at,omitempty"`
|
|
}
|
|
|
|
type ShutdownResult struct {
|
|
Status string `json:"status"`
|
|
}
|
|
|
|
type VMCreateParams struct {
|
|
Name string `json:"name,omitempty"`
|
|
ImageName string `json:"image_name,omitempty"`
|
|
VCPUCount *int `json:"vcpu_count,omitempty"`
|
|
MemoryMiB *int `json:"memory_mib,omitempty"`
|
|
SystemOverlaySize string `json:"system_overlay_size,omitempty"`
|
|
WorkDiskSize string `json:"work_disk_size,omitempty"`
|
|
NATEnabled bool `json:"nat_enabled,omitempty"`
|
|
NoStart bool `json:"no_start,omitempty"`
|
|
}
|
|
|
|
type VMCreateStatusParams struct {
|
|
ID string `json:"id"`
|
|
}
|
|
|
|
type VMCreateOperation struct {
|
|
ID string `json:"id"`
|
|
VMID string `json:"vm_id,omitempty"`
|
|
VMName string `json:"vm_name,omitempty"`
|
|
Stage string `json:"stage,omitempty"`
|
|
Detail string `json:"detail,omitempty"`
|
|
StartedAt time.Time `json:"started_at,omitempty"`
|
|
UpdatedAt time.Time `json:"updated_at,omitempty"`
|
|
Done bool `json:"done"`
|
|
Success bool `json:"success"`
|
|
Error string `json:"error,omitempty"`
|
|
VM *model.VMRecord `json:"vm,omitempty"`
|
|
}
|
|
|
|
type VMCreateBeginResult struct {
|
|
Operation VMCreateOperation `json:"operation"`
|
|
}
|
|
|
|
type VMCreateStatusResult struct {
|
|
Operation VMCreateOperation `json:"operation"`
|
|
}
|
|
|
|
type VMRefParams struct {
|
|
IDOrName string `json:"id_or_name"`
|
|
}
|
|
|
|
type VMKillParams struct {
|
|
IDOrName string `json:"id_or_name"`
|
|
Signal string `json:"signal,omitempty"`
|
|
}
|
|
|
|
type VMSetParams struct {
|
|
IDOrName string `json:"id_or_name"`
|
|
VCPUCount *int `json:"vcpu_count,omitempty"`
|
|
MemoryMiB *int `json:"memory_mib,omitempty"`
|
|
WorkDiskSize string `json:"work_disk_size,omitempty"`
|
|
NATEnabled *bool `json:"nat_enabled,omitempty"`
|
|
}
|
|
|
|
type VMListResult struct {
|
|
VMs []model.VMRecord `json:"vms"`
|
|
}
|
|
|
|
type VMShowResult struct {
|
|
VM model.VMRecord `json:"vm"`
|
|
}
|
|
|
|
type VMStatsResult struct {
|
|
VM model.VMRecord `json:"vm"`
|
|
Stats model.VMStats `json:"stats"`
|
|
}
|
|
|
|
type VMLogsResult struct {
|
|
LogPath string `json:"log_path"`
|
|
}
|
|
|
|
type VMSSHResult struct {
|
|
Name string `json:"name"`
|
|
GuestIP string `json:"guest_ip"`
|
|
}
|
|
|
|
type VMHealthResult struct {
|
|
Name string `json:"name"`
|
|
Healthy bool `json:"healthy"`
|
|
}
|
|
|
|
type VMPingResult struct {
|
|
Name string `json:"name"`
|
|
Alive bool `json:"alive"`
|
|
}
|
|
|
|
type VMPort struct {
|
|
Proto string `json:"proto"`
|
|
BindAddress string `json:"bind_address,omitempty"`
|
|
Port int `json:"port"`
|
|
PID int `json:"pid,omitempty"`
|
|
Process string `json:"process,omitempty"`
|
|
Command string `json:"command,omitempty"`
|
|
Endpoint string `json:"endpoint,omitempty"`
|
|
}
|
|
|
|
type VMPortsResult struct {
|
|
Name string `json:"name"`
|
|
DNSName string `json:"dns_name,omitempty"`
|
|
Ports []VMPort `json:"ports"`
|
|
}
|
|
|
|
type WorkspaceExportParams struct {
|
|
IDOrName string `json:"id_or_name"`
|
|
GuestPath string `json:"guest_path,omitempty"`
|
|
BaseCommit string `json:"base_commit,omitempty"`
|
|
}
|
|
|
|
type WorkspaceExportResult struct {
|
|
GuestPath string `json:"guest_path"`
|
|
BaseCommit string `json:"base_commit"`
|
|
Patch []byte `json:"patch"`
|
|
ChangedFiles []string `json:"changed_files"`
|
|
HasChanges bool `json:"has_changes"`
|
|
}
|
|
|
|
type VMWorkspacePrepareParams struct {
|
|
IDOrName string `json:"id_or_name"`
|
|
SourcePath string `json:"source_path"`
|
|
GuestPath string `json:"guest_path,omitempty"`
|
|
Branch string `json:"branch,omitempty"`
|
|
From string `json:"from,omitempty"`
|
|
Mode string `json:"mode,omitempty"`
|
|
IncludeUntracked bool `json:"include_untracked,omitempty"`
|
|
}
|
|
|
|
type VMWorkspacePrepareResult struct {
|
|
Workspace model.WorkspacePrepareResult `json:"workspace"`
|
|
}
|
|
|
|
type ImageRegisterParams struct {
|
|
Name string `json:"name,omitempty"`
|
|
RootfsPath string `json:"rootfs_path,omitempty"`
|
|
WorkSeedPath string `json:"work_seed_path,omitempty"`
|
|
KernelPath string `json:"kernel_path,omitempty"`
|
|
InitrdPath string `json:"initrd_path,omitempty"`
|
|
ModulesDir string `json:"modules_dir,omitempty"`
|
|
KernelRef string `json:"kernel_ref,omitempty"`
|
|
Docker bool `json:"docker,omitempty"`
|
|
}
|
|
|
|
type ImagePullParams struct {
|
|
Ref string `json:"ref"`
|
|
Name string `json:"name,omitempty"`
|
|
KernelPath string `json:"kernel_path,omitempty"`
|
|
InitrdPath string `json:"initrd_path,omitempty"`
|
|
ModulesDir string `json:"modules_dir,omitempty"`
|
|
KernelRef string `json:"kernel_ref,omitempty"`
|
|
SizeBytes int64 `json:"size_bytes,omitempty"`
|
|
}
|
|
|
|
type ImageRefParams struct {
|
|
IDOrName string `json:"id_or_name"`
|
|
}
|
|
|
|
type ImageListResult struct {
|
|
Images []model.Image `json:"images"`
|
|
}
|
|
|
|
type ImageShowResult struct {
|
|
Image model.Image `json:"image"`
|
|
}
|
|
|
|
type KernelEntry struct {
|
|
Name string `json:"name"`
|
|
Distro string `json:"distro,omitempty"`
|
|
Arch string `json:"arch,omitempty"`
|
|
KernelVersion string `json:"kernel_version,omitempty"`
|
|
SHA256 string `json:"sha256,omitempty"`
|
|
Source string `json:"source,omitempty"`
|
|
ImportedAt string `json:"imported_at,omitempty"`
|
|
KernelPath string `json:"kernel_path,omitempty"`
|
|
InitrdPath string `json:"initrd_path,omitempty"`
|
|
ModulesDir string `json:"modules_dir,omitempty"`
|
|
}
|
|
|
|
type KernelListResult struct {
|
|
Entries []KernelEntry `json:"entries"`
|
|
}
|
|
|
|
type KernelRefParams struct {
|
|
Name string `json:"name"`
|
|
}
|
|
|
|
type KernelShowResult struct {
|
|
Entry KernelEntry `json:"entry"`
|
|
}
|
|
|
|
type KernelImportParams struct {
|
|
Name string `json:"name"`
|
|
FromDir string `json:"from_dir"`
|
|
Distro string `json:"distro,omitempty"`
|
|
Arch string `json:"arch,omitempty"`
|
|
}
|
|
|
|
type KernelPullParams struct {
|
|
Name string `json:"name"`
|
|
Force bool `json:"force,omitempty"`
|
|
}
|
|
|
|
type KernelCatalogEntry struct {
|
|
Name string `json:"name"`
|
|
Distro string `json:"distro,omitempty"`
|
|
Arch string `json:"arch,omitempty"`
|
|
KernelVersion string `json:"kernel_version,omitempty"`
|
|
SizeBytes int64 `json:"size_bytes,omitempty"`
|
|
Description string `json:"description,omitempty"`
|
|
Pulled bool `json:"pulled"`
|
|
}
|
|
|
|
type KernelCatalogResult struct {
|
|
Entries []KernelCatalogEntry `json:"entries"`
|
|
}
|