Work around Sequoia's "Local Network" permission with a helper process (#302)

* Work around Sequoia's "Local Network" permission with a helper process

* README.md: macOS 15 (Sequoia) warning

* Make "orchard dev" unix-specific too, otherwise Release fails

* Fix typo in "localNetworkHerlper"

* Slightly improve the macOS 15 (Sequoia) note

* orchard worker run: better documentation for --user

* Make sure privilege dropping is the first step we do in runWorker()
This commit is contained in:
Nikolay Edigaryev
2025-04-10 18:01:19 +04:00
committed by GitHub
parent fa38fe72ed
commit abcfee677d
16 changed files with 201 additions and 32 deletions
+12 -4
View File
@@ -40,6 +40,8 @@ type Client struct {
serviceAccountName string
serviceAccountToken string
dialContext func(ctx context.Context, network, addr string) (net.Conn, error)
}
type Config struct {
@@ -77,15 +79,21 @@ func New(opts ...Option) (*Client, error) {
}
// Instantiate the HTTP client
transport := &http.Transport{
TLSClientConfig: client.tlsConfig,
}
if client.dialContext != nil {
transport.DialContext = client.dialContext
}
client.httpClient = &http.Client{
// The default is zero, which means no timeout, which means that
// the requests may hang indefinitely. See [1] for more details.
//
// [1]: https://github.com/cirruslabs/orchard/issues/152#issuecomment-1927091747
Timeout: 30 * time.Second,
Transport: &http.Transport{
TLSClientConfig: client.tlsConfig,
},
Timeout: 30 * time.Second,
Transport: transport,
}
url, err := url.Parse(client.address)
+8
View File
@@ -1,7 +1,9 @@
package client
import (
"context"
"crypto/x509"
"net"
)
type Option func(*Client)
@@ -24,3 +26,9 @@ func WithCredentials(serviceAccountName string, serviceAccountToken string) Opti
client.serviceAccountToken = serviceAccountToken
}
}
func WithDialContext(dialContext func(ctx context.Context, network, addr string) (net.Conn, error)) Option {
return func(client *Client) {
client.dialContext = dialContext
}
}