pub struct SandboxConfig {
pub allowed_dirs: Vec<PathBuf>,
pub deny_globs: Vec<String>,
}Expand description
Application-layer filesystem sandbox configuration.
When present, a CorePathPolicy is built from allowed_dirs and
deny_globs and applied to all filesystem builtins (read, write, edit,
patch). On Linux with the sandbox feature, bash also gets a wrapped
SandboxPolicy for Landlock kernel enforcement.
Fields§
§allowed_dirs: Vec<PathBuf>Directories the agent is allowed to access. When empty, the policy denies all directory-level access (files may still pass glob checks).
deny_globs: Vec<String>Glob patterns for paths to deny regardless of allowed_dirs.
Example: ["**/.env", "**/secrets/**"].
Trait Implementations§
Source§impl Clone for SandboxConfig
impl Clone for SandboxConfig
Source§fn clone(&self) -> SandboxConfig
fn clone(&self) -> SandboxConfig
Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
Performs copy-assignment from
source. Read moreSource§impl Debug for SandboxConfig
impl Debug for SandboxConfig
Source§impl Default for SandboxConfig
impl Default for SandboxConfig
Source§fn default() -> SandboxConfig
fn default() -> SandboxConfig
Returns the “default value” for a type. Read more
Source§impl<'de> Deserialize<'de> for SandboxConfig
impl<'de> Deserialize<'de> for SandboxConfig
Source§fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
Deserialize this value from the given Serde deserializer. Read more
Auto Trait Implementations§
impl Freeze for SandboxConfig
impl RefUnwindSafe for SandboxConfig
impl Send for SandboxConfig
impl Sync for SandboxConfig
impl Unpin for SandboxConfig
impl UnsafeUnpin for SandboxConfig
impl UnwindSafe for SandboxConfig
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more