Skip to main content

Module permissions

Module permissions 

Source

Structs§

FileSystemSandboxEntry
FileSystemSandboxPolicy
ReadDenyMatcher
Runtime matcher for read-deny entries in a filesystem sandbox policy.

Enums§

FileSystemAccessMode
Access mode for a filesystem entry.
FileSystemPath
FileSystemSandboxEntryMissingPathBehavior
FileSystemSandboxKind
FileSystemSpecialPath
NetworkSandboxPolicy

Constants§

PROTECTED_METADATA_PATH_NAMES
Top-level workspace metadata paths that stay protected under writable roots.

Functions§

forbidden_agent_metadata_write
Returns the protected workspace metadata name when an agent write to path should be blocked before execution.
is_protected_metadata_name
Returns true when a path basename is one of the protected workspace metadata names.
project_roots_glob_pattern