CubeFsPolicy class final
The spec.filesystem: section: workspace root plus mount overrides.
Constructors
-
CubeFsPolicy({String workspace = '/workspace', List<
CubeMount> mounts = const []}) -
Creates a policy;
workspacemust be absolute (enforced at parse).const - CubeFsPolicy.fromYaml(Object? node)
-
Parses the
spec.filesystem:section.null(section absent) yields the default: workspace/workspace, no mounts.factory
Properties
- hashCode → int
-
The hash code for this object.
no setterinherited
-
mounts
→ List<
CubeMount> -
Mount overrides, longest prefix wins over workspace.
final
- runtimeType → Type
-
A representation of the runtime type of the object.
no setterinherited
- workspace → String
-
The read/write root; everything outside it is denied unless a mount
grants access.
final
Methods
-
accessFor(
String path, {String? homeDir, CubeFsProbe? probe}) → CubePathAccess -
Access level for
path: the longest matching mount, else read/write inside workspace, else CubePathAccess.deny.~paths with an unknownhomeDir, and paths that traverse above/, are denied. -
accessForResolved(
String path, {String? homeDir, CubeFsProbe? probe}) → ({CubePathAccess access, String? resolved}) -
accessFor plus the canonical path to open:
resolvedis the per-component real-path resolution ofpathwhen aprobeis given and the path is allowed (feed it to the delegate — resolve-then-open), andnullotherwise (denied, or the no-probe lexical mode). -
noSuchMethod(
Invocation invocation) → dynamic -
Invoked when a nonexistent method or property is accessed.
inherited
-
toString(
) → String -
A string representation of this object.
inherited
Operators
-
operator ==(
Object other) → bool -
The equality operator.
inherited