Add a full host filesystem browser reachable from the sidebar (/files):
breadcrumb navigation, browse-root chips, show-hidden toggle, and a table
with size/permissions/mtime. Text files open in a Monaco editor (language by
extension); binary/oversized files fall back to download. Admins can create
folders/files, rename, delete (recursive for dirs), upload, and save edits;
download is available to all users. Every mutation is audit-logged.
Backend: new services/file_service.py reuses device_service's sandbox helpers
(confined to ALLOWED_BROWSE_ROOTS, mapped via HOST_ROOT_PREFIX) and rejects
path traversal and deleting a browse root. routers/files.py exposes
/api/files/{list,read,download,write,mkdir,touch,rename,upload,DELETE}
(reads: any user; mutations: admin). device_service.browse entries gained
mtime + symlink (non-breaking).
Deployment: ALLOWED_BROWSE_ROOTS + HOST_ROOT_PREFIX are now env-wired in
docker-compose.yml and .env.example, with a commented /:/host_root mount to
browse/manage the real host filesystem.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
157 lines
4.8 KiB
Python
157 lines
4.8 KiB
Python
"""Host device detection (USB, serial/TTY, DRI) and host filesystem browser."""
|
|
from __future__ import annotations
|
|
|
|
import glob
|
|
import os
|
|
from dataclasses import asdict, dataclass
|
|
from typing import Optional
|
|
|
|
from config import settings
|
|
|
|
|
|
@dataclass
|
|
class HostDevice:
|
|
path: str
|
|
kind: str # "usb" | "tty" | "dri" | "other"
|
|
name: str = ""
|
|
|
|
def to_dict(self) -> dict:
|
|
return asdict(self)
|
|
|
|
|
|
def _read(path: str) -> str:
|
|
try:
|
|
with open(path, "r", encoding="utf-8", errors="replace") as fh:
|
|
return fh.read().strip()
|
|
except OSError:
|
|
return ""
|
|
|
|
|
|
def _usb_devices() -> list[HostDevice]:
|
|
devices: list[HostDevice] = []
|
|
# /dev/bus/usb/<bus>/<dev>
|
|
for path in sorted(glob.glob("/dev/bus/usb/*/*")):
|
|
name = ""
|
|
# Best-effort name lookup via sysfs is non-trivial to map; leave generic.
|
|
devices.append(HostDevice(path=path, kind="usb", name=name or "USB device"))
|
|
return devices
|
|
|
|
|
|
def _usb_names_from_sysfs() -> list[HostDevice]:
|
|
"""Richer USB list from sysfs with product/manufacturer strings."""
|
|
out: list[HostDevice] = []
|
|
for dev in sorted(glob.glob("/sys/bus/usb/devices/*")):
|
|
busnum = _read(os.path.join(dev, "busnum"))
|
|
devnum = _read(os.path.join(dev, "devnum"))
|
|
if not busnum or not devnum:
|
|
continue
|
|
product = _read(os.path.join(dev, "product"))
|
|
manufacturer = _read(os.path.join(dev, "manufacturer"))
|
|
label = " ".join(p for p in (manufacturer, product) if p) or "USB device"
|
|
path = f"/dev/bus/usb/{int(busnum):03d}/{int(devnum):03d}"
|
|
out.append(HostDevice(path=path, kind="usb", name=label))
|
|
return out
|
|
|
|
|
|
def _tty_devices() -> list[HostDevice]:
|
|
devices: list[HostDevice] = []
|
|
patterns = ["/dev/ttyUSB*", "/dev/ttyACM*", "/dev/ttyAMA*", "/dev/serial/by-id/*"]
|
|
for pattern in patterns:
|
|
for path in sorted(glob.glob(pattern)):
|
|
base = os.path.basename(path)
|
|
driver = _read(f"/sys/class/tty/{base}/device/driver/module/name") or ""
|
|
devices.append(
|
|
HostDevice(path=path, kind="tty", name=driver or "Serial device")
|
|
)
|
|
return devices
|
|
|
|
|
|
def _dri_devices() -> list[HostDevice]:
|
|
return [
|
|
HostDevice(path=p, kind="dri", name="GPU render node")
|
|
for p in sorted(glob.glob("/dev/dri/*"))
|
|
]
|
|
|
|
|
|
def detect_devices() -> dict:
|
|
usb = _usb_names_from_sysfs() or _usb_devices()
|
|
return {
|
|
"usb": [d.to_dict() for d in usb],
|
|
"tty": [d.to_dict() for d in _tty_devices()],
|
|
"dri": [d.to_dict() for d in _dri_devices()],
|
|
}
|
|
|
|
|
|
# --------------------------------------------------------------------------- #
|
|
# Host filesystem browser (sandboxed)
|
|
# --------------------------------------------------------------------------- #
|
|
|
|
|
|
def _real_root(path: str) -> str:
|
|
"""Map a logical host path into the container view (HOST_ROOT_PREFIX)."""
|
|
prefix = settings.HOST_ROOT_PREFIX.rstrip("/")
|
|
if prefix:
|
|
return prefix + path
|
|
return path
|
|
|
|
|
|
def _is_allowed(path: str) -> bool:
|
|
norm = os.path.normpath(path)
|
|
for root in settings.ALLOWED_BROWSE_ROOTS:
|
|
root = os.path.normpath(root)
|
|
if root == "/" or norm == root or norm.startswith(root + os.sep):
|
|
return True
|
|
return False
|
|
|
|
|
|
class BrowseError(Exception):
|
|
pass
|
|
|
|
|
|
def browse(path: str = "/", show_hidden: bool = False) -> dict:
|
|
path = os.path.normpath(path or "/")
|
|
if not path.startswith("/"):
|
|
raise BrowseError("Path must be absolute")
|
|
if not _is_allowed(path):
|
|
raise BrowseError("Path is outside the allowed browse roots")
|
|
|
|
real = _real_root(path)
|
|
if not os.path.isdir(real):
|
|
raise BrowseError(f"Not a directory: {path}")
|
|
|
|
entries = []
|
|
try:
|
|
names = os.listdir(real)
|
|
except PermissionError as exc:
|
|
raise BrowseError(f"Permission denied: {path}") from exc
|
|
|
|
for name in sorted(names):
|
|
if not show_hidden and name.startswith("."):
|
|
continue
|
|
full_real = os.path.join(real, name)
|
|
try:
|
|
st = os.lstat(full_real)
|
|
is_dir = os.path.isdir(full_real)
|
|
entries.append(
|
|
{
|
|
"name": name,
|
|
"type": "dir" if is_dir else "file",
|
|
"size": st.st_size if not is_dir else None,
|
|
"permissions": oct(st.st_mode & 0o777),
|
|
"mtime": st.st_mtime,
|
|
"symlink": os.path.islink(full_real),
|
|
}
|
|
)
|
|
except OSError:
|
|
continue
|
|
|
|
# Sort: dirs first, then files, both alphabetical.
|
|
entries.sort(key=lambda e: (e["type"] != "dir", e["name"].lower()))
|
|
parent = os.path.dirname(path) if path != "/" else None
|
|
return {
|
|
"path": path,
|
|
"parent": parent,
|
|
"roots": settings.ALLOWED_BROWSE_ROOTS,
|
|
"entries": entries,
|
|
}
|