pub enum PathShapeViolation {
Empty,
Absolute,
ParentEscape,
}Expand description
Tagged reason a caixa-author-supplied path can fail the
sandboxed-relative shape gate every callback / script path must
pass for the layout checker’s root.join(p) to stay inside the
caixa root.
Returned by is_sandboxed_relative_path so each per-axis caller
— crate::BehaviorSpec::validate on :behavior :on-* paths
(b0c8389), crate::UpgradeInstruction::validate’s StateChange
arm on :upgrade-from :state-change :script (26da2c7), every
future axis admitting a user-supplied path — match-and-wraps the
tag into its own typed *Invalid { slot, path } enum variant so
the diagnostic still names which slot carried the malformed
value. The tag is axis-agnostic; the wrapping per-axis variant
carries the slot identity.
Sibling discriminator-style of the per-arm reason substrings every
value-shape predicate already exposes (is_dns_1123_label,
is_gateway_api_http_path, …) — but typed rather than string-
shaped, because the per-axis variants for path violations were
already split three ways (EmptyPath / AbsolutePath /
ParentEscape in BehaviorError; EmptyScript / AbsoluteScript
/ ParentEscapeScript in UpgradeError), so collapsing them to a
single *PathInvalid { reason } variant would regress the
diagnostic shape rather than preserve it.
Variants§
Empty
The path string is empty — PathBuf::new() or the
canonical “I declared the slot but left the value blank”
authoring footgun. root.join(PathBuf::new()) resolves to
root itself, silently pointing the runtime’s LisleLoader
at the project root rather than a file.
Absolute
The path is absolute — Path::join replaces the base
with an absolute right-hand side, so root.join("/etc/passwd")
resolves to "/etc/passwd" and escapes the project sandbox
entirely. The Lunatic-style sandbox discipline
(theory/INSPIRATIONS.md §III.1) requires every
author-supplied path to live under the caixa root.
ParentEscape
The path contains a Component::ParentDir component anywhere
— root.join("../sibling/x") traverses above the caixa root,
the same sandbox-escape vector via parent-directory traversal.
Caught regardless of where the .. component sits (leading,
mid-path, trailing) so a future relaxation that only checks
one position surfaces at this one predicate.
Trait Implementations§
Source§impl Clone for PathShapeViolation
impl Clone for PathShapeViolation
Source§fn clone(&self) -> PathShapeViolation
fn clone(&self) -> PathShapeViolation
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreimpl Copy for PathShapeViolation
Source§impl Debug for PathShapeViolation
impl Debug for PathShapeViolation
impl Eq for PathShapeViolation
Source§impl Hash for PathShapeViolation
impl Hash for PathShapeViolation
Source§impl PartialEq for PathShapeViolation
impl PartialEq for PathShapeViolation
impl StructuralPartialEq for PathShapeViolation
Auto Trait Implementations§
impl Freeze for PathShapeViolation
impl RefUnwindSafe for PathShapeViolation
impl Send for PathShapeViolation
impl Sync for PathShapeViolation
impl Unpin for PathShapeViolation
impl UnsafeUnpin for PathShapeViolation
impl UnwindSafe for PathShapeViolation
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
key and return true if they are equal.