add sub-instance project permission & feat: max sub-process depth check

This commit is contained in:
MihailRis 2026-08-02 01:19:01 +03:00
parent 5a8fd3ceab
commit 4503455ae9
7 changed files with 36 additions and 6 deletions

View file

@ -3,5 +3,6 @@ name = "default"
base_packs = ["base"] base_packs = ["base"]
permissions = [ permissions = [
"network", "network",
"record-audio" "record-audio",
"sub-instances",
] ]

View file

@ -16,6 +16,8 @@ inline constexpr bool ENGINE_DEBUG_BUILD = true;
inline const std::string ENGINE_VERSION_STRING = "0.32"; inline const std::string ENGINE_VERSION_STRING = "0.32";
inline constexpr uint MAX_SUBPROCESS_DEPTH = 2;
/// @brief world regions format version /// @brief world regions format version
inline constexpr uint REGION_FORMAT_VERSION = 3; inline constexpr uint REGION_FORMAT_VERSION = 3;

View file

@ -13,6 +13,7 @@ struct Permissions {
static inline std::string NETWORK = "network"; static inline std::string NETWORK = "network";
static inline std::string RECORD_AUDIO = "record-audio"; static inline std::string RECORD_AUDIO = "record-audio";
static inline std::string WRITE_TO_USER = "write-to-user"; static inline std::string WRITE_TO_USER = "write-to-user";
static inline std::string SUB_INSTANCES = "sub-instances";
std::set<std::string> permissions; std::set<std::string> permissions;

View file

@ -14,5 +14,6 @@ struct CoreParameters {
std::filesystem::path projectFolder; std::filesystem::path projectFolder;
std::string debugServerString; std::string debugServerString;
int tps = 20; int tps = 20;
int subProcessDepth = 0;
std::unordered_map<std::string, std::string> projectArgs; std::unordered_map<std::string, std::string> projectArgs;
}; };

View file

@ -341,6 +341,10 @@ static int l_start_debug_instance(lua::State* L) {
if (!engine->getProject().permissions.has(Permissions::DEBUGGING)) { if (!engine->getProject().permissions.has(Permissions::DEBUGGING)) {
throw std::runtime_error("project has no debugging permission"); throw std::runtime_error("project has no debugging permission");
} }
const auto& params = engine->getCoreParameters();
if (params.subProcessDepth >= MAX_SUBPROCESS_DEPTH) {
throw std::runtime_error("max subprocess depth exceeded");
}
int port = lua::tointeger(L, 1); int port = lua::tointeger(L, 1);
if (port == 0) { if (port == 0) {
@ -361,6 +365,8 @@ static int l_start_debug_instance(lua::State* L) {
"--res", paths.getResourcesFolder().u8string(), "--res", paths.getResourcesFolder().u8string(),
"--dir", paths.getUserFilesFolder().u8string(), "--dir", paths.getUserFilesFolder().u8string(),
"--dbg-server", "tcp:" + std::to_string(port), "--dbg-server", "tcp:" + std::to_string(port),
"--sub-depth", std::to_string(engine->getCoreParameters()
.subProcessDepth + 1),
}; };
if (!projectPath.empty()) { if (!projectPath.empty()) {
args.emplace_back("--project"); args.emplace_back("--project");
@ -376,15 +382,25 @@ static int l_start_debug_instance(lua::State* L) {
} }
static int l_start_background_instance(lua::State* L) { static int l_start_background_instance(lua::State* L) {
if (!engine->getProject().permissions.has(Permissions::SUB_INSTANCES)) {
throw std::runtime_error("project has no sub-instances permission");
}
const auto& params = engine->getCoreParameters();
if (params.subProcessDepth >= MAX_SUBPROCESS_DEPTH) {
throw std::runtime_error("max subprocess depth exceeded");
}
auto scriptPath = lua::require_lstring(L, 1); auto scriptPath = lua::require_lstring(L, 1);
io::path outputPath = "user:background.log"; // TODO: io::path outputPath = lua::isstring(L, 2) ? lua::require_lstring(L, 2) : "";
const auto& paths = engine->getPaths(); const auto& paths = engine->getPaths();
std::vector<std::string> args { std::vector<std::string> args {
// "--headless", "--headless",
"--res", paths.getResourcesFolder().u8string(), "--res", paths.getResourcesFolder().u8string(),
"--dir", paths.getUserFilesFolder().u8string(), "--dir", paths.getUserFilesFolder().u8string(),
"--script", io::resolve(scriptPath).u8string(), "--script", io::resolve(scriptPath).u8string(),
"--sub-depth", std::to_string(engine->getCoreParameters()
.subProcessDepth + 1),
}; };
args.emplace_back("--project"); args.emplace_back("--project");
args.emplace_back(io::resolve(engine->getProject().path).u8string()); args.emplace_back(io::resolve(engine->getProject().path).u8string());

View file

@ -26,6 +26,8 @@ int main(int argc, char** argv) {
if (!parse_cmdline(argc, argv, coreParameters)) { if (!parse_cmdline(argc, argv, coreParameters)) {
return EXIT_SUCCESS; return EXIT_SUCCESS;
} }
logger.debug() << "sub-process depth: "
<< coreParameters.subProcessDepth;
} catch (const std::runtime_error& err) { } catch (const std::runtime_error& err) {
std::cerr << err.what() << std::endl; std::cerr << err.what() << std::endl;
return EXIT_FAILURE; return EXIT_FAILURE;

View file

@ -78,12 +78,19 @@ static bool perform_keyword(
params.debugServerString = reader.next(); params.debugServerString = reader.next();
return true; return true;
}, "<serv>", "open debugging server where <serv> is {transport}:{port}"), }, "<serv>", "open debugging server where <serv> is {transport}:{port}"),
ArgC("--sub-depth", [&params, &reader]() -> bool {
params.subProcessDepth = reader.nextInt();
return true;
}, "<depth>", "sub-process depth"),
ArgC("--help", []() -> bool { ArgC("--help", []() -> bool {
std::cout << "VoxelCore v" << ENGINE_VERSION_STRING << "\n\n"; std::cout << "VoxelCore v" << ENGINE_VERSION_STRING << "\n\n";
std::cout << "Command-line arguments:\n"; std::cout << "Command-line arguments:\n";
for (auto& a : argumentsCommandline) { for (auto& arg : argumentsCommandline) {
std::cout << std::setw(24) << std::left << (a.keyword + " " + a.args); if (arg.help.empty()) {
std::cout << "- " << a.help << std::endl; continue;
}
std::cout << std::setw(24) << std::left << (arg.keyword + " " + arg.args);
std::cout << "- " << arg.help << std::endl;
} }
std::cout << std::endl; std::cout << std::endl;
return false; return false;