Files
dsh_shenxian/src/isolation.ts
T

22 lines
914 B
TypeScript

/**
* Account-level isolation helpers. Linux-only: each user maps to a deterministic
* OS uid so the orchestrator can spawn its DSH as that account (via setuid) and
* per-user 0700 directories become a real boundary.
*
* `hashUid` is the *legacy* deterministic hash (stable across restarts and
* hosts); new users get `baseUid + row_id` from the DB instead (collision-free,
* see `src/db`). `hashUid` remains as the backfill value for pre-existing rows
* and the fallback when a uid is not yet assigned.
* @module dshs/isolation
*/
/**
* Deterministic OS uid for a user id (stable across restarts and hosts).
* `baseUid` should sit above the distro's system uid range (typically < 1000).
*/
export function hashUid(userId: string, baseUid: number): number {
let hash = 0
for (let i = 0; i < userId.length; i++) hash = (hash * 31 + userId.charCodeAt(i)) >>> 0
return baseUid + (hash % 100000)
}