Skip to main content

ReadPathSet

Struct ReadPathSet 

Source
pub struct ReadPathSet { /* private fields */ }
Expand description

A compiled set of allowlist entries, bound to the run they were compiled for (tilde and relative entries were resolved at compile time).

Implementations§

Source§

impl ReadPathSet

Source

pub fn compile( raw: &[String], workdir: &Path, home: Option<&Path>, windows: bool, ) -> Result<Self, String>

Compile raw [read_paths] allow strings against a run’s workdir and home. windows selects Windows path semantics: /-normalization of the matched string and case-insensitive glob/regex matching (production passes cfg!(windows)).

Any invalid entry is a hard error naming the entry - a skipped entry would degrade the agent silently mid-run, and refusing loudly at compile (spawn) time is the same posture the sandbox config takes.

Source

pub fn is_empty(&self) -> bool

Whether the set has no entries at all.

Source

pub fn entries(&self) -> &[ReadPathEntry]

The compiled entries, for callers that report or display them.

Source

pub fn matches(&self, canonical: &Path) -> bool

Whether the already-canonicalized canonical path matches any entry.

Source

pub fn matches_lexically(&self, path: &Path) -> bool

Whether path matches any entry, comparing text instead of the filesystem: an Exact entry is a component-wise prefix test on the path as written, with no canonicalization.

matches is the enforcement path and must resolve symlinks; this is the reporting path, which must not. A grant naming a directory that does not exist yet, or one behind macOS’s /tmp -> /private/tmp link, is still a grant the user wrote, and telling them it is missing would be wrong. The trade is the other way too: a report is a pattern-level answer, so a run can still be refused at a path this says is covered.

Trait Implementations§

Source§

impl Clone for ReadPathSet

Source§

fn clone(&self) -> ReadPathSet

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for ReadPathSet

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Default for ReadPathSet

Source§

fn default() -> ReadPathSet

Returns the “default value” for a type. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more