晋太元中,武陵人捕鱼为业。缘溪行,忘路之远近。忽逢桃花林,夹岸数百步,中无杂树,芳草鲜美,落英缤纷。渔人甚异之,复前行,欲穷其林。 林尽水源,便得一山,山有小口,仿佛若有光。便舍船,从口入。初极狭,才通人。复行数十步,豁然开朗。土地平旷,屋舍俨然,有良田、美池、桑竹之属。阡陌交通,鸡犬相闻。其中往来种作,男女衣着,悉如外人。黄发垂髫,并怡然自乐。 见渔人,乃大惊,问所从来。具答之。便要还家,设酒杀鸡作食。村中闻有此人,咸来问讯。自云先世避秦时乱,率妻子邑人来此绝境,不复出焉,遂与外人间隔。问今是何世,乃不知有汉,无论魏晋。此人一一为具言所闻,皆叹惋。余人各复延至其家,皆出酒食。停数日,辞去。此中人语云:“不足为外人道也。”(间隔 一作:隔绝) 既出,得其船,便扶向路,处处志之。及郡下,诣太守,说如此。太守即遣人随其往,寻向所志,遂迷,不复得路。 南阳刘子骥,高尚士也,闻之,欣然规往。未果,寻病终。后遂无问津者。
| DIR:/opt/cloudlinux/venv/lib/python3.11/site-packages/lve_utils/ |
| Current File : //opt/cloudlinux/venv/lib/python3.11/site-packages/lve_utils/cagefs.py |
# coding=utf-8
#
# Copyright © Cloud Linux GmbH & Cloud Linux Software, Inc 2010-2026 All Rights Reserved
#
# Licensed under CLOUD LINUX LICENSE AGREEMENT
# http://cloudlinux.com/docs/LICENCE.TXT
#
"""Helpers for CageFS interaction from lvectl / lvdctl.
Kept in python_lve to avoid a hard dependency on securelve: lve-utils
is installed on systems without CageFS, so anything we call here must
degrade to a no-op when CageFS is absent.
"""
import logging
import os
import subprocess
import tempfile
CAGEFSCTL_TOOL = "/usr/sbin/cagefsctl"
PROXY_COMMANDS_PATH = "/etc/cagefs/proxy.commands"
# proxyexec aliases that map an in-CageFS path to a host-side SUID binary.
# Without these entries, isolatectl inside CageFS fails with
# "No such file or directory: '/usr/share/lve-utils/lvd-registry-helper'".
LVD_PROXY_ENTRIES = {
"LVD_REGISTRY_HELPER": "/usr/share/lve-utils/lvd-registry-helper",
"LVD_LIMITS_HELPER": "/usr/share/lve-utils/lvd-limits-helper",
"LVD_STATS_HELPER": "/usr/share/lve-utils/lvd-stats-helper",
}
def ensure_lvd_proxy_commands():
"""Register LVD helper proxyexec entries in /etc/cagefs/proxy.commands.
No-op when CageFS is not installed (cagefsctl binary absent) or when
the entries are already present. When entries are added, runs
``cagefsctl --update-wrappers`` so the in-CageFS proxyexec wrappers
appear immediately.
"""
if not os.path.exists(CAGEFSCTL_TOOL):
return
try:
with open(PROXY_COMMANDS_PATH, "r", encoding="utf-8") as f:
content = f.read()
except FileNotFoundError:
content = ""
new_content = content
for key, binary in LVD_PROXY_ENTRIES.items():
if key in new_content:
continue
if not os.path.exists(binary):
continue
if new_content and not new_content.endswith("\n"):
new_content += "\n"
new_content += f"{key}={binary}\n"
if new_content == content:
return
logging.info("Registering LVD helpers in %s", PROXY_COMMANDS_PATH)
proxy_dir = os.path.dirname(PROXY_COMMANDS_PATH)
os.makedirs(proxy_dir, exist_ok=True)
fd, tmp_path = tempfile.mkstemp(dir=proxy_dir, prefix=".proxy.commands.")
try:
with os.fdopen(fd, "w", encoding="utf-8") as f:
f.write(new_content)
os.replace(tmp_path, PROXY_COMMANDS_PATH)
except BaseException:
if os.path.exists(tmp_path):
os.unlink(tmp_path)
raise
subprocess.run(
[CAGEFSCTL_TOOL, "--update-wrappers"],
stdout=subprocess.DEVNULL,
stderr=subprocess.DEVNULL,
check=False,
)
|