CubeFsPolicy class final

The spec.filesystem: section: workspace root plus mount overrides.

Constructors

CubeFsPolicy({String workspace = '/workspace', List<CubeMount> mounts = const []})
Creates a policy; workspace must be absolute (enforced at parse).
const
CubeFsPolicy.fromYaml(Object? node)
Parses the spec.filesystem: section. null (section absent) yields the default: workspace /workspace, no mounts.
factory

Properties

hashCode → int
The hash code for this object.
no setterinherited
mounts → List<CubeMount>
Mount overrides, longest prefix wins over workspace.
final
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited
workspace → String
The read/write root; everything outside it is denied unless a mount grants access.
final

Methods

accessFor(String path, {String? homeDir, CubeFsProbe? probe}) → CubePathAccess
Access level for path: the longest matching mount, else read/write inside workspace, else CubePathAccess.deny. ~ paths with an unknown homeDir, and paths that traverse above /, are denied.
accessForResolved(String path, {String? homeDir, CubeFsProbe? probe}) → ({CubePathAccess access, String? resolved})
accessFor plus the canonical path to open: resolved is the per-component real-path resolution of path when a probe is given and the path is allowed (feed it to the delegate — resolve-then-open), and null otherwise (denied, or the no-probe lexical mode).
noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
toString() → String
A string representation of this object.
inherited

Operators

operator ==(Object other) → bool
The equality operator.
inherited