pub struct PathProtectionRule {
pub protected: Vec<String>,
pub workspace_only: bool,
pub tool_allowed_paths: Vec<PathBuf>,
}Expand description
Priority 4: blocks access to protected path patterns and enforces workspace-only confinement for agent file tools.
Fields§
§protected: Vec<String>Path patterns that are not allowed in tool arguments.
workspace_only: boolWhen true, absolute paths outside /tmp and tool_allowed_paths are
denied (workspace-only mode).
tool_allowed_paths: Vec<PathBuf>Absolute paths that tools may access even in workspace_only mode.
Auto-populated from feature configs (e.g. obsidian.vault_path).
Implementations§
Source§impl PathProtectionRule
impl PathProtectionRule
pub fn new(protected: Vec<String>) -> Self
Sourcepub fn from_config(fs_cfg: &FilesystemSecurityConfig) -> Self
pub fn from_config(fs_cfg: &FilesystemSecurityConfig) -> Self
Build from the [security.filesystem] config section.
Merges protected_paths + extra_protected_paths, reads
workspace_only flag, and imports tool_allowed_paths so that
configured external directories (e.g. Obsidian vault) are reachable
even in workspace-only mode.
Trait Implementations§
Source§impl Default for PathProtectionRule
impl Default for PathProtectionRule
Source§impl PolicyRule for PathProtectionRule
impl PolicyRule for PathProtectionRule
fn name(&self) -> &str
fn priority(&self) -> u32
fn evaluate( &self, call: &ToolCallRequest, _ctx: &PolicyContext, ) -> PolicyDecision
Auto Trait Implementations§
impl Freeze for PathProtectionRule
impl RefUnwindSafe for PathProtectionRule
impl Send for PathProtectionRule
impl Sync for PathProtectionRule
impl Unpin for PathProtectionRule
impl UnsafeUnpin for PathProtectionRule
impl UnwindSafe for PathProtectionRule
Blanket Implementations§
Source§impl<T> ArchivePointee for T
impl<T> ArchivePointee for T
Source§type ArchivedMetadata = ()
type ArchivedMetadata = ()
The archived version of the pointer metadata for this type.
Source§fn pointer_metadata(
_: &<T as ArchivePointee>::ArchivedMetadata,
) -> <T as Pointee>::Metadata
fn pointer_metadata( _: &<T as ArchivePointee>::ArchivedMetadata, ) -> <T as Pointee>::Metadata
Converts some archived metadata to the pointer metadata for itself.
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
Source§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
Converts
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
Converts
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§impl<T> LayoutRaw for T
impl<T> LayoutRaw for T
Source§fn layout_raw(_: <T as Pointee>::Metadata) -> Result<Layout, LayoutError>
fn layout_raw(_: <T as Pointee>::Metadata) -> Result<Layout, LayoutError>
Returns the layout of the type.
Source§impl<T, N1, N2> Niching<NichedOption<T, N1>> for N2
impl<T, N1, N2> Niching<NichedOption<T, N1>> for N2
Source§unsafe fn is_niched(niched: *const NichedOption<T, N1>) -> bool
unsafe fn is_niched(niched: *const NichedOption<T, N1>) -> bool
Returns whether the given value has been niched. Read more
Source§fn resolve_niched(out: Place<NichedOption<T, N1>>)
fn resolve_niched(out: Place<NichedOption<T, N1>>)
Writes data to
out indicating that a T is niched.Source§impl<T> Pointable for T
impl<T> Pointable for T
Source§impl<T> PolicyExt for Twhere
T: ?Sized,
impl<T> PolicyExt for Twhere
T: ?Sized,
Source§impl<T> Upcastable for T
impl<T> Upcastable for T
Source§fn upcast_any_ref(&self) -> &(dyn Any + 'static)
fn upcast_any_ref(&self) -> &(dyn Any + 'static)
upcast ref
Source§fn upcast_any_mut(&mut self) -> &mut (dyn Any + 'static)
fn upcast_any_mut(&mut self) -> &mut (dyn Any + 'static)
upcast mut ref