Module: SecurityBox::Mounts

Defined in:
lib/security_box/configuration.rb

Overview

Validated collection of host-folder mounts (stage 5). A mount is a frozen guest:, mode: hash; mounts in a Configuration is a frozen array of these, so the value survives #with, #fingerprint and Ractor ports.

Validation (InvalidConfiguration on any violation):

- mode is :read_only or :read_write (wasmtime silently accepts unknown
symbols, so the mode is checked here, never trusted to the runtime)
- host: non-empty string; relative paths are expanded against Dir.pwd
(existence/directory checks are per-eval, in EvalRun 

Constant Summary collapse

MODES =
i[read_only read_write].freeze
RESERVED_GUEST_PATHS =
%w[/work /usr /src].freeze
MAX_MOUNTS =
16

Class Method Summary collapse

Class Method Details

.normalize(raw) ⇒ Object

Validates + normalizes raw (an array of guest:, mode: hashes or nil) and returns a frozen array of frozen, normalized hashes.



267
268
269
270
271
272
273
274
275
276
277
278
# File 'lib/security_box/configuration.rb', line 267

def normalize(raw)
  return [].freeze if raw.nil?

  raise InvalidConfiguration,
        "mounts must be an Array of {host:, guest:, mode:} hashes, got #{raw.class}" unless raw.is_a?(Array)

  mounts = raw.map { |entry| normalize_entry(entry) }
  check_duplicates(mounts)
  check_reserved(mounts)
  check_count(mounts)
  mounts.freeze
end