pub struct ShellConfig {
pub allow: Vec<String>,
pub deny: Vec<String>,
pub timeout_ms: Option<u64>,
pub max_output_bytes: Option<usize>,
}Expand description
Package-level [shell] configuration: what a workflow’s script may be, and
how long it may run.
[shell]
# when non-empty, only a script matching one of these may run
allow = ["ls", "ls *", "cat *.txt", "nu *"]
# always refused, allow or not
deny = ["*rm -rf*", "*sudo *", "*> /etc/*"]
# deadline of one shell act; defaults to 300000 (1..=3600000)
timeout-ms = 300000
# bytes captured per stream before the act fails; default 1048576
# (1..=67108864)
max-output-bytes = 1048576Patterns are globs over the whole script text — * matches any run of
characters, newlines and / included, ? matches one, [abc] one of a
set — so rm * matches a script that starts with rm and *rm *
matches one that contains it anywhere. Matching the script rather than a
parsed command is deliberate: the package does not parse a shell (that is
the shell’s job, and no two shells agree), so the rule is the one thing it
can state exactly — “this text, or not”.
deny wins over allow. Both lists empty means no restriction, which is
the behaviour of a deployment that says nothing; the moment either is
written, the policy is the judgement. A pattern that does not compile is a
startup error, never a silent allow: a policy that cannot be enforced must
not run.
timeout-ms and max-output-bytes bound one act’s resources. They are the
deployment’s decision and always in force — no value disables them, a value
outside the range is a startup error rather than a silent clamp, and an act
has no param that widens them.
This is a policy, not a sandbox. A glob over script text cannot see
what the script will do — a=rm; $a -rf / names no forbidden word, and a
script can do anything the server’s own account may do that
confine_script does not name either. The lists are for making intent
explicit and for refusing the obvious, in the spirit of the workdir check
below them; a hostile workflow still needs an OS boundary (a container or a
namespace around the server).
Fields§
§allow: Vec<String>Script globs that may run. Empty means “anything not denied”.
deny: Vec<String>Script globs that never run; wins over ShellConfig::allow.
timeout_ms: Option<u64>Deadline of one shell act in milliseconds. None uses
DEFAULT_TIMEOUT_MS; the accepted range is 1..=MAX_TIMEOUT_MS.
max_output_bytes: Option<usize>Bytes captured from each of stdout and stderr before the act fails.
None uses DEFAULT_MAX_OUTPUT_BYTES; the accepted range is
1..=MAX_OUTPUT_BYTES.
Trait Implementations§
Source§impl Clone for ShellConfig
impl Clone for ShellConfig
Source§fn clone(&self) -> ShellConfig
fn clone(&self) -> ShellConfig
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read more