mirror of
https://github.com/safedep/pmg.git
synced 2026-08-03 07:24:09 +02:00
* feat: add ProxyConfig struct with per-PM skip_commands and legacy fallback * feat: consolidate proxy config into structured section with backward compat Replaces flat proxy_mode/proxy_install_only keys with a structured proxy section supporting per-package-manager skip_commands. Legacy keys are respected via fallback when user's config lacks the new proxy section. Removes deprecated experimental_proxy_mode config and flag. * fix: env var resolution for nested config keys and deduplicate skip command matching - Add "." to "_" in Viper env key replacer so nested keys like sandbox.enabled resolve from PMG_SANDBOX_ENABLED (was silently broken) - Export IsFirstNonFlagArgInList and remove duplicate from proxy_flow.go - Add table-driven tests for skip command matching with real-world cases - Remove redundant env var test * docs: update proxy configuration and env var documentation Update config.md env var table to reflect new proxy.enabled and proxy.install_only keys. Add proxy configuration section to proxy.md covering config structure, per-PM skip commands, CLI flags, and env vars. * fix: legacy fallback precedence
72 lines
3.4 KiB
Go
72 lines
3.4 KiB
Go
package config
|
|
|
|
import (
|
|
"fmt"
|
|
|
|
"github.com/spf13/cobra"
|
|
)
|
|
|
|
var skipDependencyCooldown bool
|
|
|
|
// sandboxAllowRaw holds the raw --sandbox-allow flag values before parsing.
|
|
var sandboxAllowRaw []string
|
|
|
|
// ApplyCobraFlags applies the cobra flags to the command.
|
|
// These flags are local concern of the config package. This helper function is used
|
|
// to bind them to the Cobra. The default values are taken from the global configuration,
|
|
// allowing for overriding the configuration at runtime.
|
|
func ApplyCobraFlags(cmd *cobra.Command) {
|
|
cmd.PersistentFlags().BoolVar(&globalConfig.Config.Transitive, "transitive",
|
|
globalConfig.Config.Transitive, "Resolve transitive dependencies")
|
|
cmd.PersistentFlags().IntVar(&globalConfig.Config.TransitiveDepth, "transitive-depth",
|
|
globalConfig.Config.TransitiveDepth, "Maximum depth of transitive dependencies to resolve")
|
|
cmd.PersistentFlags().BoolVar(&globalConfig.Config.IncludeDevDependencies, "include-dev-dependencies",
|
|
globalConfig.Config.IncludeDevDependencies, "Include dev dependencies in the dependency graph (slows down resolution)")
|
|
cmd.PersistentFlags().BoolVar(&globalConfig.DryRun, "dry-run",
|
|
globalConfig.DryRun, "Dry run skips execution of package manager")
|
|
cmd.PersistentFlags().BoolVar(&globalConfig.Config.Paranoid, "paranoid",
|
|
globalConfig.Config.Paranoid, "Enable high-security defaults (treat suspicious as malicious)")
|
|
cmd.PersistentFlags().BoolVar(&globalConfig.Config.SkipEventLogging, "skip-event-log",
|
|
globalConfig.Config.SkipEventLogging, "Skip event logging")
|
|
cmd.PersistentFlags().BoolVar(&globalConfig.Config.Proxy.Enabled, "proxy-mode",
|
|
globalConfig.Config.Proxy.Enabled, "Use proxy based interception")
|
|
cmd.PersistentFlags().BoolVar(&globalConfig.Config.Sandbox.Enabled, "sandbox",
|
|
globalConfig.Config.Sandbox.Enabled, "Enable sandbox mode to isolate package manager processes (EXPERIMENTAL)")
|
|
cmd.PersistentFlags().BoolVar(&globalConfig.Config.Sandbox.EnforceAlways, "sandbox-enforce",
|
|
globalConfig.Config.Sandbox.EnforceAlways, "Apply sandbox to all commands, not just install commands (requires --sandbox)")
|
|
cmd.PersistentFlags().StringVar(&globalConfig.SandboxProfileOverride, "sandbox-profile",
|
|
globalConfig.SandboxProfileOverride, "Override sandbox policy profile (built-in name or path to custom YAML)")
|
|
cmd.PersistentFlags().StringArrayVar(&sandboxAllowRaw, "sandbox-allow",
|
|
nil, "Add runtime sandbox allow rule (type=value). Types: read, write, exec, net-connect, net-bind")
|
|
|
|
cmd.PersistentFlags().BoolVar(&skipDependencyCooldown, "skip-dependency-cooldown",
|
|
false, "Skip dependency cooldown enforcement")
|
|
|
|
}
|
|
|
|
// FinalizeDependencyCooldownOverride disables dependency cooldown in the global
|
|
// config when --skip-dependency-cooldown is set. Must be called after cobra
|
|
// flag parsing is complete.
|
|
func FinalizeDependencyCooldownOverride() {
|
|
if skipDependencyCooldown {
|
|
globalConfig.Config.DependencyCooldown.Enabled = false
|
|
}
|
|
}
|
|
|
|
// FinalizeSandboxAllowOverrides parses the raw --sandbox-allow flag values
|
|
// and stores the validated overrides in the global config. This must be called
|
|
// after cobra flag parsing is complete (e.g., in PersistentPreRun).
|
|
func FinalizeSandboxAllowOverrides() error {
|
|
if len(sandboxAllowRaw) == 0 {
|
|
return nil
|
|
}
|
|
|
|
overrides, err := parseSandboxAllowOverrides(sandboxAllowRaw)
|
|
if err != nil {
|
|
return fmt.Errorf("failed to parse --sandbox-allow flags: %w", err)
|
|
}
|
|
|
|
globalConfig.SandboxAllowOverrides = overrides
|
|
return nil
|
|
}
|