Skip to main content

CapabilityDir

Struct CapabilityDir 

Source
pub struct CapabilityDir { /* private fields */ }
Expand description

Handles scoped directory operations relative to a canonical checkout root.

Implementations§

Source§

impl CapabilityDir

Source

pub fn open(root: &Path) -> Result<Self, CapabilityError>

Opens one canonical directory without following a symlink root.

§Errors

Returns CapabilityError when the root cannot be canonicalized, is not a directory, or is a symbolic link.

Source

pub fn root(&self) -> &Path

Returns the canonical authorized root path.

Source

pub fn read_utf8_file_bounded( &self, relative: &Path, max_bytes: usize, ) -> Result<String, CapabilityError>

Reads a bounded UTF-8 file relative to the authorized root.

§Errors

Returns CapabilityError when the relative path is invalid, the file is unsafe, or the read exceeds max_bytes.

Source

pub fn read_file_bounded( &self, relative: &Path, max_bytes: usize, ) -> Result<Vec<u8>, CapabilityError>

Reads a bounded file relative to the authorized root.

§Errors

Returns CapabilityError when the relative path is invalid, the file is unsafe, or the read exceeds max_bytes.

Source

pub fn classify_regular_file_entry( &self, relative: &Path, ) -> Result<RegularFileEntry, CapabilityError>

Classifies whether a relative path is absent, a regular file, or an unsafe non-regular entry.

§Errors

Returns CapabilityError when the relative path is invalid, a symlink, or unreadable.

Source

pub fn regular_file_exists( &self, relative: &Path, ) -> Result<bool, CapabilityError>

Returns whether a regular file exists at a relative path.

§Errors

Returns CapabilityError when the relative path is invalid or resolves to an unsafe entry.

Source

pub fn atomic_write( &self, relative: &Path, bytes: &[u8], ) -> Result<(), CapabilityError>

Atomically writes bytes to a relative file, creating parent directories as needed.

§Errors

Returns CapabilityError when the relative path is invalid, a parent is unsafe, or the write fails.

Source

pub fn remove_file_if_exists( &self, relative: &Path, ) -> Result<bool, CapabilityError>

Removes a regular file relative to the authorized root when it exists.

§Errors

Returns CapabilityError when the relative path is invalid or the target is unsafe.

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more