mirror of
				https://github.com/superseriousbusiness/gotosocial.git
				synced 2025-11-03 19:32:26 -06:00 
			
		
		
		
	Bumps [github.com/KimMachineGun/automemlimit](https://github.com/KimMachineGun/automemlimit) from 0.2.4 to 0.2.5. - [Release notes](https://github.com/KimMachineGun/automemlimit/releases) - [Commits](https://github.com/KimMachineGun/automemlimit/compare/v0.2.4...v0.2.5) --- updated-dependencies: - dependency-name: github.com/KimMachineGun/automemlimit dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
		
			
				
	
	
		
			92 lines
		
	
	
	
		
			2.1 KiB
		
	
	
	
		
			Go
		
	
	
	
	
	
			
		
		
	
	
			92 lines
		
	
	
	
		
			2.1 KiB
		
	
	
	
		
			Go
		
	
	
	
	
	
/*
 | 
						|
   Copyright The containerd Authors.
 | 
						|
 | 
						|
   Licensed under the Apache License, Version 2.0 (the "License");
 | 
						|
   you may not use this file except in compliance with the License.
 | 
						|
   You may obtain a copy of the License at
 | 
						|
 | 
						|
       http://www.apache.org/licenses/LICENSE-2.0
 | 
						|
 | 
						|
   Unless required by applicable law or agreed to in writing, software
 | 
						|
   distributed under the License is distributed on an "AS IS" BASIS,
 | 
						|
   WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
 | 
						|
   See the License for the specific language governing permissions and
 | 
						|
   limitations under the License.
 | 
						|
*/
 | 
						|
 | 
						|
package cgroup1
 | 
						|
 | 
						|
import (
 | 
						|
	"fmt"
 | 
						|
	"os"
 | 
						|
	"path/filepath"
 | 
						|
 | 
						|
	specs "github.com/opencontainers/runtime-spec/specs-go"
 | 
						|
)
 | 
						|
 | 
						|
const (
 | 
						|
	allowDeviceFile = "devices.allow"
 | 
						|
	denyDeviceFile  = "devices.deny"
 | 
						|
	wildcard        = -1
 | 
						|
)
 | 
						|
 | 
						|
func NewDevices(root string) *devicesController {
 | 
						|
	return &devicesController{
 | 
						|
		root: filepath.Join(root, string(Devices)),
 | 
						|
	}
 | 
						|
}
 | 
						|
 | 
						|
type devicesController struct {
 | 
						|
	root string
 | 
						|
}
 | 
						|
 | 
						|
func (d *devicesController) Name() Name {
 | 
						|
	return Devices
 | 
						|
}
 | 
						|
 | 
						|
func (d *devicesController) Path(path string) string {
 | 
						|
	return filepath.Join(d.root, path)
 | 
						|
}
 | 
						|
 | 
						|
func (d *devicesController) Create(path string, resources *specs.LinuxResources) error {
 | 
						|
	if err := os.MkdirAll(d.Path(path), defaultDirPerm); err != nil {
 | 
						|
		return err
 | 
						|
	}
 | 
						|
	for _, device := range resources.Devices {
 | 
						|
		file := denyDeviceFile
 | 
						|
		if device.Allow {
 | 
						|
			file = allowDeviceFile
 | 
						|
		}
 | 
						|
		if device.Type == "" {
 | 
						|
			device.Type = "a"
 | 
						|
		}
 | 
						|
		if err := os.WriteFile(
 | 
						|
			filepath.Join(d.Path(path), file),
 | 
						|
			[]byte(deviceString(device)),
 | 
						|
			defaultFilePerm,
 | 
						|
		); err != nil {
 | 
						|
			return err
 | 
						|
		}
 | 
						|
	}
 | 
						|
	return nil
 | 
						|
}
 | 
						|
 | 
						|
func (d *devicesController) Update(path string, resources *specs.LinuxResources) error {
 | 
						|
	return d.Create(path, resources)
 | 
						|
}
 | 
						|
 | 
						|
func deviceString(device specs.LinuxDeviceCgroup) string {
 | 
						|
	return fmt.Sprintf("%s %s:%s %s",
 | 
						|
		device.Type,
 | 
						|
		deviceNumber(device.Major),
 | 
						|
		deviceNumber(device.Minor),
 | 
						|
		device.Access,
 | 
						|
	)
 | 
						|
}
 | 
						|
 | 
						|
func deviceNumber(number *int64) string {
 | 
						|
	if number == nil || *number == wildcard {
 | 
						|
		return "*"
 | 
						|
	}
 | 
						|
	return fmt.Sprint(*number)
 | 
						|
}
 |