Skip to main content

FsRoot

Struct FsRoot 

Source
pub struct FsRoot { /* private fields */ }
Expand description

What the filesystem API may touch.

Held by value in the app state; every filesystem path in the API is produced by one of these methods and by no other route.

Implementations§

Source§

impl FsRoot

Source

pub fn new(root: impl AsRef<Path>) -> Result<Self>

Anchor a jail at root, which must already exist.

Canonicalised once here so every later comparison is against a path with symlinks already resolved — otherwise a symlinked root would make every containment check compare unlike things.

Source

pub fn machine_wide() -> Self

Reach everything this account can, with no subtree restriction.

The default when --fs-root is not given. Anchors are enumerated once, here, so a drive that appears later is not silently reachable by a server that started before it existed.

Source

pub fn jail_path(&self) -> Option<&Path>

The jail’s own path, or None when the scope is the whole machine.

Returns an Option rather than a bare Path because machine-wide scope genuinely has no single path: on Windows there is nothing above C:\ and D:\ to name. A caller that needs one — the audit-log containment check at startup, say — has to say what it does when there isn’t one.

Source

pub fn describe(&self) -> String

One line naming the effective scope, for the startup banner.

The banner is the only thing standing between an operator and a scope wider than they assumed, now that the file API no longer needs a flag to exist — so this states what is reachable, not which flag was passed.

Source

pub fn resolve_existing(&self, rel: &str) -> Result<PathBuf, FsError>

Resolve a path that must already exist.

Containment is decided by canonicalising the deepest part of the path that exists, never by the kind of error a full canonicalisation returned. Branching on the error kind is what leaks: a path whose parent is a file fails with ENOTDIR while a path whose parent is absent fails with NotFound, so answering differently tells the caller which files exist outside the jail. It also mishandles a symlink that points out of the root — the link resolves, the target does not exist, and a lexical check sees a path that never left.

Walking down instead means every real directory on the way is resolved through its symlinks and checked, and the verdict never depends on an errno. resolve_for_create uses the same discipline.

Source

pub fn resolve_for_create(&self, rel: &str) -> Result<PathBuf, FsError>

Resolve a path that does not exist yet (an upload target).

The target itself cannot be canonicalised, so the nearest existing ancestor is canonicalised instead and the remaining segments are checked lexically. Those segments may not contain ..: with nothing on disk to resolve against, a traversal there would go unnoticed until the write.

Source

pub fn relative(&self, abs: &Path) -> Option<String>

Render an absolute path as the string the API names it by.

Inside a jail that is a root-relative POSIX string. Machine-wide it is the absolute path itself, with \ normalised to / so one separator style comes back regardless of which one went in — the value is echoed in responses, used as the list cursor, and keyed on to detect two uploads racing for one destination, so it has to be stable per file.

Returns None for anything outside the scope, so a caller cannot accidentally publish a path it should not have.

Trait Implementations§

Source§

impl Clone for FsRoot

Source§

fn clone(&self) -> FsRoot

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for FsRoot

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> Downcast for T
where T: Any,

Source§

fn into_any(self: Box<T>) -> Box<dyn Any>

Convert Box<dyn Trait> (where Trait: Downcast) to Box<dyn Any>. Box<dyn Any> can then be further downcast into Box<ConcreteType> where ConcreteType implements Trait.
Source§

fn into_any_rc(self: Rc<T>) -> Rc<dyn Any>

Convert Rc<Trait> (where Trait: Downcast) to Rc<Any>. Rc<Any> can then be further downcast into Rc<ConcreteType> where ConcreteType implements Trait.
Source§

fn as_any(&self) -> &(dyn Any + 'static)

Convert &Trait (where Trait: Downcast) to &Any. This is needed since Rust cannot generate &Any’s vtable from &Trait’s.
Source§

fn as_any_mut(&mut self) -> &mut (dyn Any + 'static)

Convert &mut Trait (where Trait: Downcast) to &Any. This is needed since Rust cannot generate &mut Any’s vtable from &mut Trait’s.
Source§

impl<T> DowncastSync for T
where T: Any + Send + Sync,

Source§

fn into_any_arc(self: Arc<T>) -> Arc<dyn Any + Sync + Send>

Convert Arc<Trait> (where Trait: Downcast) to Arc<Any>. Arc<Any> can then be further downcast into Arc<ConcreteType> where ConcreteType implements Trait.
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> FromRef<T> for T
where T: Clone,

Source§

fn from_ref(input: &T) -> T

Converts to this type from a reference to the input type.
Source§

impl<A, B, T> HttpServerConnExec<A, B> for T
where B: Body,

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more