Skip to main content

SymlinkAwareSandbox

Struct SymlinkAwareSandbox 

Source
pub struct SymlinkAwareSandbox { /* private fields */ }
Expand description

Sandbox that follows symlinks in the root directory.

Like FsSandbox, but also allows access to targets of symlinks found directly under the root. This is designed for package managers (e.g. npm link / alc_pkg_link) where the root directory contains symlinks pointing to external source directories.

§How it works

At construction time, scans the root for symlink entries and records their canonical targets as additional allowed roots. During read(), a file is permitted if its canonical path is under the root or under any of the recorded symlink targets.

If both checks fail, the root is rescanned once before the read is rejected, so symlinks created after construction (e.g. a later mlua-pkg install in a long-running host) are picked up without rebuilding the sandbox. The rescan runs only on the path that would otherwise return ReadError::Traversal; successful reads never touch the filesystem beyond the file itself.

Rejection is therefore no longer free: it costs one read_dir plus a canonicalize per root entry. Reads that miss because the file does not exist are unaffected (they return Ok(None) before the boundary check), so the cost falls only on names that resolve to a real file outside the root — which then fail anyway.

§Security boundary

Same as FsSandbox: casual escape prevention for trusted directories. Note that the rescan widens the allowed set to whatever symlinks exist under the root at read time — the root directory itself must stay trusted.

Implementations§

Trait Implementations§

Source§

impl SandboxedFs for SymlinkAwareSandbox

Source§

fn read(&self, relative: &Path) -> Result<Option<FileContent>, ReadError>

Read a file by relative path. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> MaybeSend for T

Source§

impl<T> MaybeSync for T

Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.