?r5j
B d Z ddlZddlZddlZddlZdZdZdddZd ZdS ) zHelpers for CageFS interaction from lvectl / lvdctl.
Kept in python_lve to avoid a hard dependency on securelve: lve-utils
is installed on systems without CageFS, so anything we call here must
degrade to a no-op when CageFS is absent.
Nz/usr/sbin/cagefsctlz/etc/cagefs/proxy.commandsz(/usr/share/lve-utils/lvd-registry-helperz&/usr/share/lve-utils/lvd-limits-helper)LVD_REGISTRY_HELPERLVD_LIMITS_HELPERc n t j t sdS t t
dd 5 } | }ddd n# 1 swxY w Y n# t $ r d}Y nw xY w|}t D ]Q\ }}||v r
t j | s*|r|
d s|dz
}|| d| dz
}R||k rdS t j dt
t j
t
}t j |d
t j |d \ }} t j |d
d 5 } | | ddd n# 1 swxY w Y t j |t
nB# t( $ r5 t j | rt j | w xY wt- j t dgt, j t, j d dS )a5 Register LVD helper proxyexec entries in /etc/cagefs/proxy.commands.
No-op when CageFS is not installed (cagefsctl binary absent) or when
the entries are already present. When entries are added, runs
``cagefsctl --update-wrappers`` so the in-CageFS proxyexec wrappers
appear immediately.
Nrzutf-8)encoding
=zRegistering LVD helpers in %sT)exist_okz.proxy.commands.)dirprefixwz--update-wrappersF)stdoutstderrcheck)ospathexistsCAGEFSCTL_TOOLopenPROXY_COMMANDS_PATHreadFileNotFoundErrorLVD_PROXY_ENTRIESitemsendswithlogginginfodirnamemakedirstempfilemkstempfdopenwritereplace
BaseExceptionunlink
subprocessrunDEVNULL)fcontentnew_contentkeybinary proxy_dirfdtmp_paths py/lve_utils/cagefs.pyensure_lvd_proxy_commandsr4 ! s 7>>.))
%sW
=
=
= ffhhG K(..00 + +V+w~~f%% {33D99 4K#******gL02EFFF 344IK D))))# :LMMMLB
Yr3
1
1
1 !Q
GGK ! ! ! ! ! ! ! ! ! ! ! ! ! ! !
801111
7>>(## Ih
N ,-!! sd A, A A, A$$A, 'A$(A, ,A;:A;!G 8FG FG !F"G ?G?) __doc__r r r( r! r r r r4 r3