pub enum PathPolicy {
Unrestricted,
Within(Vec<PathBuf>),
}Expand description
Where a tool may write when the caller names a path on this machine.
In this release the tier is what confines host filesystem access: those tools sit at the write tier and no higher, so a read-only session reaches none of them. The allow-list is the mechanism meant to confine them further, and it is here rather than in a comment so that switching it on is a matter of populating one value: every tool that takes a path already asks.
Variants§
Unrestricted
Any path the caller names. What this release ships.
Within(Vec<PathBuf>)
Only paths under one of these roots.
Implementations§
Trait Implementations§
Source§impl Clone for PathPolicy
impl Clone for PathPolicy
Source§impl Debug for PathPolicy
impl Debug for PathPolicy
Source§impl Default for PathPolicy
impl Default for PathPolicy
impl Eq for PathPolicy
Source§impl PartialEq for PathPolicy
impl PartialEq for PathPolicy
impl StructuralPartialEq for PathPolicy
Auto Trait Implementations§
impl Freeze for PathPolicy
impl RefUnwindSafe for PathPolicy
impl Send for PathPolicy
impl Sync for PathPolicy
impl Unpin for PathPolicy
impl UnsafeUnpin for PathPolicy
impl UnwindSafe for PathPolicy
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
Compare self to
key and return true if they are equal.