diff options
| author | Gabriel Schneider <[email protected]> | 2026-09-30 23:04:26 -0300 |
|---|---|---|
| committer | Gabriel Schneider <[email protected]> | 2026-10-01 00:12:17 -0300 |
| commit | 464b3033ac69f6c8256c2216ac385450144740bf (patch) | |
| tree | 76c4d2a6ce17e326e4e991a021d0088cb9094134 /docs/v9fs.md | |
| parent | 5e72bfc34cc97d12be5185930135b55c2eb001b4 (diff) | |
| download | pardes-464b3033ac69f6c8256c2216ac385450144740bf.tar.gz pardes-464b3033ac69f6c8256c2216ac385450144740bf.zip | |
Building gathers the platforms, options, tests, release gates and how the core, threads, detached sessions and 9P fit, from the old design notes checked against the code
Co-Authored-By: Claude Opus 5.5 <[email protected]>
Diffstat (limited to 'docs/v9fs.md')
| -rw-r--r-- | docs/v9fs.md | 56 |
1 files changed, 0 insertions, 56 deletions
diff --git a/docs/v9fs.md b/docs/v9fs.md deleted file mode 100644 index 26460658..00000000 --- a/docs/v9fs.md +++ /dev/null @@ -1,56 +0,0 @@ -# Tty9p: a terminal with a kernel 9P mount - -On Linux, `Tty9p` (`SPC n 9`) opens a terminal below this pane with the -session mounted through the kernel's v9fs. The pane asks for your sudo -password, mounts, and starts your shell as your normal user (with your -supplementary groups). The shell gets `PARDES_MOUNT`, the mountpoint: - -```sh -cat "$PARDES_MOUNT/index" -cat "$PARDES_MOUNT/pane/$PARDES_PANE/body" -echo 'Msg hello' > "$PARDES_MOUNT/exec" -n=$(cat "$PARDES_MOUNT/pane/new") -``` - -The files are those of [fs.md](fs.md). The mount lives in that pane's -private mount namespace: other panes and the editor do not see it, so a -Look at a path under `$PARDES_MOUNT` opens nothing. Each `Tty9p` makes its -own mount and takes one of the session's 16 Unix/TCP connection slots. It -works in TTY, SDL and detached sessions (the session host starts the shell, -not an attached frontend). Dump/Restore does not remake the mount. - -## Setup - -The build installs `pardes-v9fs` beside `pardes`; the host looks for it -beside its own executable, or at `PARDES_V9FS_HELPER` (an absolute path). -A running editor keeps the code it started with. - -Linux needs `9p` and its Unix transport (`9pnet_fd`); mounting needs -`CAP_SYS_ADMIN`, which sudo supplies. The launcher runs `sudo -E` (local -policy must allow it) and restores the caller's `PATH` after dropping -privileges. Nothing setuid, no passwordless sudo rule and no FUSE is -installed. The helper takes explicit mount paths and a command; it is not a -restricted privilege broker, so do not grant it passwordless sudo. - -## How it works - -`Tty9p` starts the normal shell and queues a quoted helper command, which -bash and fish run once their prompt is ready, as a foreground job, so sudo -uses the terminal. A failed or cancelled authentication returns to that -shell, as does exiting the mounted one. The unprivileged launcher makes a -private temporary mountpoint and runs sudo; the elevated helper makes a -private mount namespace, mounts the session's socket with -`trans=unix,version=9p2000,cache=none,access=any,nosuid,nodev,noexec`, drops -every root id and capability, and executes the shell. The namespace, and -the mount, go when its last process exits. Code: `src/linux/v9fs.zig`. - -Linux follows `O_TRUNC` with a `Twstat` of zero length and an `mtime` hint; -pardes takes the truncation and drops the hint. - -## Tests - -```sh -zig build v9fs-terminal-test -Dplatform=tty # builtin, launcher, cleanup; a sudo stand-in, no mount -zig build v9fs-driver-test -Dplatform=tty # the probe launcher, no privileges -sudo -v; zig build v9fs-test -Dplatform=tty # a real kernel mount (sudo -n); fails, not skips, without it -``` |
