Module: SecurityBox::Mounts
- Defined in:
- lib/security_box/configuration.rb
Overview
Validated collection of host-folder mounts (stage 5). A mount is a frozen
guest:, mode: hash; mounts in a Configuration is a frozen array
of these, so the value survives #with, #fingerprint and Ractor ports.
Validation (InvalidConfiguration on any violation):
- mode is :read_only or :read_write (wasmtime silently accepts unknown
symbols, so the mode is checked here, never trusted to the runtime)
- host: non-empty string; relative paths are against Dir.pwd
(existence/directory checks are per-eval, in EvalRun
Constant Summary collapse
- MODES =
i[read_only read_write].freeze
- RESERVED_GUEST_PATHS =
%w[/work /usr /src].freeze
- MAX_MOUNTS =
16
Class Method Summary collapse
-
.normalize(raw) ⇒ Object
Validates + normalizes
raw(an array of guest:, mode: hashes or nil) and returns a frozen array of frozen, normalized hashes.
Class Method Details
.normalize(raw) ⇒ Object
Validates + normalizes raw (an array of guest:, mode: hashes
or nil) and returns a frozen array of frozen, normalized hashes.
267 268 269 270 271 272 273 274 275 276 277 278 |
# File 'lib/security_box/configuration.rb', line 267 def normalize(raw) return [].freeze if raw.nil? raise InvalidConfiguration, "mounts must be an Array of {host:, guest:, mode:} hashes, got #{raw.class}" unless raw.is_a?(Array) mounts = raw.map { |entry| normalize_entry(entry) } check_duplicates(mounts) check_reserved(mounts) check_count(mounts) mounts.freeze end |