Files
ProxMenux/oci/remote/oci_host_mounts.py
T
MacRimiandClaude Opus 5 bcabcb618c feat(oci): run official container images as native LXC containers
Adds the OCI manager: an engine that turns a Docker Compose file into an
LXC definition, a catalog of 365 applications drawn from LinuxServer.io
and other container image sources, and a per-instance registry recording
what each container was built from. Reachable from the main menu.

Catalog text is translated like every other string in the project: the
taglines go through translate() and land in lang/*.json, so the entries
read in all eight languages instead of only English.

Translation cache builder:
- a failed translation leaves the key absent rather than writing English,
  which previously made the string count as translated forever
- a result identical to a 3+ word source is rejected, catching a provider
  that silently returns the text it was given
- strings that are nothing but glossary terms keep their source spelling
  instead of being discarded as failures
- no backoff between attempts when the provider is deterministic
- application names are protected so "HAOS One" survives translation
- argos joins the provider list, and the workflow reads the OCI sources

Audit & Report:
- findings that moved in the wrong direction between runs are reported
  alongside the ones that improved
- an accepted risk can carry a review date and is flagged when it falls due
- backup checks explain in plain language what they looked at and what to
  do next

Monitor:
- disks can be excluded from periodic reads, and an idle disk says so
  instead of showing a stale temperature
- per-disk identity survives a controller or enclosure change
- scheduled Borg backups resolve their SSH key from the repository entry
- PVE upgrades log the package list and the resulting dpkg changes

The web build no longer copies scripts/ into public/: the documentation
links to GitHub, so nothing read that folder.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-22 18:24:59 +02:00

75 lines
3.1 KiB
Python

"""Read-only identity checks for directory bind mounts; never manage their data."""
from __future__ import annotations
from pathlib import Path, PurePosixPath
import re
import stat
from oci_installation_state import parse_config
from oci_ui import translate
def valid_path(value):
if (not isinstance(value, str) or not value.startswith('/') or value == '/'
or any(c.isspace() or ord(c) < 32 or c == ',' for c in value)
or any(p in ('.', '..') for p in value.split('/'))
or str(PurePosixPath(value)) != value or value.startswith('//')):
raise ValueError(translate('Invalid absolute mount path'))
return value
def snapshot(source, allow_missing=False):
path = Path(source)
resolved = str(path.resolve())
try:
info = path.stat()
except FileNotFoundError:
if not allow_missing or path.is_symlink():
raise ValueError(f"{translate('The container is not modified because a host directory is not available:')} {source}")
return {'resolved_path': resolved, 'exists': False}
if not stat.S_ISDIR(info.st_mode):
raise ValueError(translate('This profile only supports directory bind mounts'))
return {'resolved_path': resolved, 'exists': True, 'device': info.st_dev,
'inode': info.st_ino, 'uid': info.st_uid, 'gid': info.st_gid,
'mode': stat.S_IMODE(info.st_mode)}
def validate_source(source, allow_missing=False):
valid_path(source)
value = snapshot(source, allow_missing)
protected = ('/etc', '/usr', '/bin', '/sbin', '/lib', '/lib64', '/dev', '/proc', '/sys', '/run')
protected += tuple(str(Path(p).resolve()) for p in protected)
resolved = value['resolved_path']
if resolved == '/' or any(resolved == p or resolved.startswith(p + '/') for p in protected):
raise ValueError(translate('The shared directory points to a protected host path'))
return value
def same_source(a, b):
# Native application init may legitimately change permissions, not identity.
return all(a.get(k) == b.get(k) for k in ('resolved_path', 'exists', 'device', 'inode'))
def verify_sources(expected):
for source, previous in expected.items():
current = validate_source(source, allow_missing=not previous['exists'])
if not same_source(previous, current):
raise ValueError(f"{translate('The operation was stopped because a shared directory changed its identity:')} {source}")
def verify_observation(expected, observed):
actual = observed.get('host_bind_sources', {})
if actual.keys() != expected.keys() or any(not same_source(value, actual[source])
for source, value in expected.items()):
raise ValueError(translate('The mount evidence does not match the verified directories'))
def capture_sources(config):
result = {}
for key, value in parse_config(config).items():
if re.fullmatch(r'mp[0-9]+', key):
source = value.split(',', 1)[0]
if source.startswith('/'):
result[source] = snapshot(source)
return result