Skip to main content

ArchivePolicy

Struct ArchivePolicy 

Source
pub struct ArchivePolicy {
    pub allow_absolute_paths: bool,
    pub allow_parent_traversal: bool,
    pub allow_symlinks: bool,
    pub max_entry_size: Option<u64>,
    pub max_total_size: Option<u64>,
    pub max_entries: Option<usize>,
}
Expand description

Policy primitives for safe extraction planning.

Fields§

§allow_absolute_paths: bool

Whether absolute or root-anchored paths are allowed.

§allow_parent_traversal: bool

Whether parent traversal components are allowed.

§allow_symlinks: bool

Whether symbolic link entries are allowed.

§max_entry_size: Option<u64>

Maximum single entry payload size in bytes.

§max_total_size: Option<u64>

Maximum total known payload size in bytes.

§max_entries: Option<usize>

Maximum number of archive entries.

Implementations§

Source§

impl ArchivePolicy

Source

pub const fn strict() -> ArchivePolicy

Returns a strict extraction-oriented policy.

Examples found in repository?
examples/basic_usage.rs (line 14)
6fn main() {
7    let encoding = ArchiveEncoding::from_extension("release.tar.zst");
8
9    assert_eq!(encoding.archive, ArchiveFormat::Tar);
10    assert_eq!(encoding.compression, CompressionFormat::Zstd);
11    assert!(is_safe_relative_archive_path("docs/readme.md"));
12    assert!(!is_safe_relative_archive_path("../secrets.env"));
13
14    let policy = ArchivePolicy::strict();
15    let manifest = ArchiveManifest::new(encoding).with_entries(vec![
16        ArchiveEntry::new("docs/readme.md", ArchiveEntryKind::File).with_size(128),
17    ]);
18
19    assert!(policy.allows_entries(manifest.entries()));
20    assert_eq!(manifest.file_count(), 1);
21    assert_eq!(manifest.total_size(), 128);
22}
Source

pub const fn permissive() -> ArchivePolicy

Returns a permissive policy for trusted archive metadata.

Source

pub const fn list_only() -> ArchivePolicy

Returns a policy suitable for listing-only workflows.

Source

pub const fn with_max_entry_size(self, max_entry_size: u64) -> ArchivePolicy

Adds a maximum single entry size.

Source

pub const fn with_max_total_size(self, max_total_size: u64) -> ArchivePolicy

Adds a maximum total known size.

Source

pub const fn with_max_entries(self, max_entries: usize) -> ArchivePolicy

Adds a maximum entry count.

Source

pub fn allows_path(&self, path: &str) -> bool

Returns whether a path is allowed by this policy.

Source

pub fn entry_issues(&self, entry: &ArchiveEntry) -> Vec<ArchivePolicyIssue>

Returns policy issues for a single entry.

Source

pub fn allows_entry(&self, entry: &ArchiveEntry) -> bool

Returns whether a single entry is allowed by this policy.

Source

pub fn entries_issues( &self, entries: &[ArchiveEntry], ) -> Vec<ArchivePolicyIssue>

Returns policy issues for a complete entry listing.

Source

pub fn allows_entries(&self, entries: &[ArchiveEntry]) -> bool

Returns whether a complete entry listing is allowed by this policy.

Examples found in repository?
examples/basic_usage.rs (line 19)
6fn main() {
7    let encoding = ArchiveEncoding::from_extension("release.tar.zst");
8
9    assert_eq!(encoding.archive, ArchiveFormat::Tar);
10    assert_eq!(encoding.compression, CompressionFormat::Zstd);
11    assert!(is_safe_relative_archive_path("docs/readme.md"));
12    assert!(!is_safe_relative_archive_path("../secrets.env"));
13
14    let policy = ArchivePolicy::strict();
15    let manifest = ArchiveManifest::new(encoding).with_entries(vec![
16        ArchiveEntry::new("docs/readme.md", ArchiveEntryKind::File).with_size(128),
17    ]);
18
19    assert!(policy.allows_entries(manifest.entries()));
20    assert_eq!(manifest.file_count(), 1);
21    assert_eq!(manifest.total_size(), 128);
22}

Trait Implementations§

Source§

impl Clone for ArchivePolicy

Source§

fn clone(&self) -> ArchivePolicy

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for ArchivePolicy

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result<(), Error>

Formats the value using the given formatter. Read more
Source§

impl Default for ArchivePolicy

Source§

fn default() -> ArchivePolicy

Returns the “default value” for a type. Read more
Source§

impl Hash for ArchivePolicy

Source§

fn hash<__H>(&self, state: &mut __H)
where __H: Hasher,

Feeds this value into the given Hasher. Read more
1.3.0 · Source§

fn hash_slice<H>(data: &[Self], state: &mut H)
where H: Hasher, Self: Sized,

Feeds a slice of this type into the given Hasher. Read more
Source§

impl Ord for ArchivePolicy

Source§

fn cmp(&self, other: &ArchivePolicy) -> Ordering

This method returns an Ordering between self and other. Read more
1.21.0 (const: unstable) · Source§

fn max(self, other: Self) -> Self
where Self: Sized,

Compares and returns the maximum of two values. Read more
1.21.0 (const: unstable) · Source§

fn min(self, other: Self) -> Self
where Self: Sized,

Compares and returns the minimum of two values. Read more
1.50.0 (const: unstable) · Source§

fn clamp(self, min: Self, max: Self) -> Self
where Self: Sized,

Restrict a value to a certain interval. Read more
Source§

impl PartialEq for ArchivePolicy

Source§

fn eq(&self, other: &ArchivePolicy) -> bool

Tests for self and other values to be equal, and is used by ==.
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Tests for !=. The default implementation is almost always sufficient, and should not be overridden without very good reason.
Source§

impl PartialOrd for ArchivePolicy

Source§

fn partial_cmp(&self, other: &ArchivePolicy) -> Option<Ordering>

This method returns an ordering between self and other values if one exists. Read more
1.0.0 (const: unstable) · Source§

fn lt(&self, other: &Rhs) -> bool

Tests less than (for self and other) and is used by the < operator. Read more
1.0.0 (const: unstable) · Source§

fn le(&self, other: &Rhs) -> bool

Tests less than or equal to (for self and other) and is used by the <= operator. Read more
1.0.0 (const: unstable) · Source§

fn gt(&self, other: &Rhs) -> bool

Tests greater than (for self and other) and is used by the > operator. Read more
1.0.0 (const: unstable) · Source§

fn ge(&self, other: &Rhs) -> bool

Tests greater than or equal to (for self and other) and is used by the >= operator. Read more
Source§

impl Copy for ArchivePolicy

Source§

impl Eq for ArchivePolicy

Source§

impl StructuralPartialEq for ArchivePolicy

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.