Add an AbsolutePathBuf conversion for FileSystemPath (#38460)

## What changed

Implement `From<AbsolutePathBuf>` for `FileSystemPath` and use the conversion
when constructing concrete filesystem permission paths.

GitOrigin-RevId: 244bcbd0c3f76cd87cc1240458fcac6c9ef0a8e3
This commit is contained in:
iceweasel-oai
2026-08-14 00:18:29 +00:00
committed by copyberry
parent 9341b38310
commit 18bbb585e7
10 changed files with 118 additions and 161 deletions
+1 -1
View File
@@ -2535,7 +2535,7 @@ fn apply_managed_filesystem_constraints(
continue;
};
codex_protocol::permissions::FileSystemSandboxEntry {
path: codex_protocol::permissions::FileSystemPath::Path { path },
path: path.into(),
access: codex_protocol::permissions::FileSystemAccessMode::Deny,
missing_path_behavior: None,
}
+2 -2
View File
@@ -599,7 +599,7 @@ fn compile_filesystem_path(
}
let path = parse_absolute_path(path)?;
Ok(FileSystemPath::Path { path })
Ok(path.into())
}
fn compile_scoped_filesystem_path(
@@ -636,7 +636,7 @@ fn compile_scoped_filesystem_path(
let subpath = parse_relative_subpath(subpath)?;
let base = parse_absolute_path(path)?;
let path = AbsolutePathBuf::resolve_path_against_base(&subpath, base.as_path());
Ok(FileSystemPath::Path { path })
Ok(path.into())
}
fn compile_scoped_filesystem_pattern(
+24 -31
View File
@@ -506,7 +506,7 @@ fn windows_elevated_allows_split_restricted_read_policies() {
std::fs::create_dir_all(docs.as_path()).expect("create docs");
let file_system_policy = FileSystemSandboxPolicy::restricted(vec![
codex_protocol::permissions::FileSystemSandboxEntry {
path: codex_protocol::permissions::FileSystemPath::Path { path: docs },
path: docs.into(),
access: codex_protocol::permissions::FileSystemAccessMode::Read,
missing_path_behavior: None,
},
@@ -543,10 +543,9 @@ fn windows_restricted_token_rejects_split_only_filesystem_policies() {
missing_path_behavior: None,
},
codex_protocol::permissions::FileSystemSandboxEntry {
path: codex_protocol::permissions::FileSystemPath::Path {
path: codex_utils_absolute_path::AbsolutePathBuf::from_absolute_path(&docs)
.expect("absolute docs"),
},
path: codex_utils_absolute_path::AbsolutePathBuf::from_absolute_path(&docs)
.expect("absolute docs")
.into(),
access: codex_protocol::permissions::FileSystemAccessMode::Read,
missing_path_behavior: None,
},
@@ -584,10 +583,9 @@ fn windows_restricted_token_rejects_root_write_read_only_carveouts() {
missing_path_behavior: None,
},
codex_protocol::permissions::FileSystemSandboxEntry {
path: codex_protocol::permissions::FileSystemPath::Path {
path: codex_utils_absolute_path::AbsolutePathBuf::from_absolute_path(&docs)
.expect("absolute docs"),
},
path: codex_utils_absolute_path::AbsolutePathBuf::from_absolute_path(&docs)
.expect("absolute docs")
.into(),
access: codex_protocol::permissions::FileSystemAccessMode::Read,
missing_path_behavior: None,
},
@@ -637,7 +635,7 @@ fn windows_restricted_token_supports_full_read_split_write_read_carveouts() {
missing_path_behavior: None,
},
codex_protocol::permissions::FileSystemSandboxEntry {
path: codex_protocol::permissions::FileSystemPath::Path { path: docs.clone() },
path: docs.clone().into(),
access: codex_protocol::permissions::FileSystemAccessMode::Read,
missing_path_behavior: None,
},
@@ -695,7 +693,7 @@ fn windows_restricted_token_rejects_unreadable_split_carveouts() {
missing_path_behavior: None,
},
codex_protocol::permissions::FileSystemSandboxEntry {
path: codex_protocol::permissions::FileSystemPath::Path { path: blocked },
path: blocked.into(),
access: codex_protocol::permissions::FileSystemAccessMode::Deny,
missing_path_behavior: None,
},
@@ -727,10 +725,9 @@ fn windows_elevated_supports_split_restricted_read_roots() {
let expected_docs = dunce::canonicalize(&docs).expect("canonical docs");
let file_system_policy = FileSystemSandboxPolicy::restricted(vec![
codex_protocol::permissions::FileSystemSandboxEntry {
path: codex_protocol::permissions::FileSystemPath::Path {
path: codex_utils_absolute_path::AbsolutePathBuf::from_absolute_path(&docs)
.expect("absolute docs"),
},
path: codex_utils_absolute_path::AbsolutePathBuf::from_absolute_path(&docs)
.expect("absolute docs")
.into(),
access: codex_protocol::permissions::FileSystemAccessMode::Read,
missing_path_behavior: None,
},
@@ -781,10 +778,9 @@ fn windows_elevated_supports_split_write_read_carveouts() {
missing_path_behavior: None,
},
codex_protocol::permissions::FileSystemSandboxEntry {
path: codex_protocol::permissions::FileSystemPath::Path {
path: codex_utils_absolute_path::AbsolutePathBuf::from_absolute_path(&docs)
.expect("absolute docs"),
},
path: codex_utils_absolute_path::AbsolutePathBuf::from_absolute_path(&docs)
.expect("absolute docs")
.into(),
access: codex_protocol::permissions::FileSystemAccessMode::Read,
missing_path_behavior: None,
},
@@ -884,10 +880,9 @@ fn windows_elevated_supports_unreadable_split_carveouts() {
missing_path_behavior: None,
},
codex_protocol::permissions::FileSystemSandboxEntry {
path: codex_protocol::permissions::FileSystemPath::Path {
path: codex_utils_absolute_path::AbsolutePathBuf::from_absolute_path(&blocked)
.expect("absolute blocked"),
},
path: codex_utils_absolute_path::AbsolutePathBuf::from_absolute_path(&blocked)
.expect("absolute blocked")
.into(),
access: codex_protocol::permissions::FileSystemAccessMode::Deny,
missing_path_behavior: None,
},
@@ -1002,18 +997,16 @@ fn windows_elevated_rejects_reopened_writable_descendants() {
missing_path_behavior: None,
},
codex_protocol::permissions::FileSystemSandboxEntry {
path: codex_protocol::permissions::FileSystemPath::Path {
path: codex_utils_absolute_path::AbsolutePathBuf::from_absolute_path(&docs)
.expect("absolute docs"),
},
path: codex_utils_absolute_path::AbsolutePathBuf::from_absolute_path(&docs)
.expect("absolute docs")
.into(),
access: codex_protocol::permissions::FileSystemAccessMode::Read,
missing_path_behavior: None,
},
codex_protocol::permissions::FileSystemSandboxEntry {
path: codex_protocol::permissions::FileSystemPath::Path {
path: codex_utils_absolute_path::AbsolutePathBuf::from_absolute_path(&nested)
.expect("absolute nested"),
},
path: codex_utils_absolute_path::AbsolutePathBuf::from_absolute_path(&nested)
.expect("absolute nested")
.into(),
access: codex_protocol::permissions::FileSystemAccessMode::Write,
missing_path_behavior: None,
},
+2 -4
View File
@@ -233,9 +233,7 @@ fn add_helper_runtime_permissions(
}
file_system_policy.entries.push(FileSystemSandboxEntry::new(
FileSystemPath::Path {
path: helper_read_root.clone(),
},
helper_read_root.clone().into(),
FileSystemAccessMode::Read,
));
}
@@ -758,7 +756,7 @@ mod tests {
fn path_entry(path: AbsolutePathBuf, access: FileSystemAccessMode) -> FileSystemSandboxEntry {
FileSystemSandboxEntry {
path: FileSystemPath::Path { path },
path: path.into(),
access,
missing_path_behavior: None,
}
+28 -59
View File
@@ -1561,12 +1561,12 @@ mod tests {
let real_blocked_str = path_to_string(&blocked);
let policy = FileSystemSandboxPolicy::restricted(vec![
FileSystemSandboxEntry {
path: FileSystemPath::Path { path: link_root },
path: link_root.into(),
access: FileSystemAccessMode::Write,
missing_path_behavior: None,
},
FileSystemSandboxEntry {
path: FileSystemPath::Path { path: link_blocked },
path: link_blocked.into(),
access: FileSystemAccessMode::Deny,
missing_path_behavior: None,
},
@@ -1611,9 +1611,7 @@ mod tests {
let real_memories_str = path_to_string(&real_memories);
let logical_memories_str = path_to_string(&logical_memories);
let policy = FileSystemSandboxPolicy::restricted(vec![FileSystemSandboxEntry {
path: FileSystemPath::Path {
path: logical_memories_root,
},
path: logical_memories_root.into(),
access: FileSystemAccessMode::Write,
missing_path_behavior: None,
}]);
@@ -1653,7 +1651,7 @@ mod tests {
let root = AbsolutePathBuf::from_absolute_path(&root).expect("absolute root");
let agents_link_str = path_to_string(&agents_link);
let policy = FileSystemSandboxPolicy::restricted(vec![FileSystemSandboxEntry {
path: FileSystemPath::Path { path: root },
path: root.into(),
access: FileSystemAccessMode::Write,
missing_path_behavior: None,
}]);
@@ -1690,12 +1688,12 @@ mod tests {
let real_linked_private_str = path_to_string(&linked_private);
let policy = FileSystemSandboxPolicy::restricted(vec![
FileSystemSandboxEntry {
path: FileSystemPath::Path { path: link_root },
path: link_root.into(),
access: FileSystemAccessMode::Write,
missing_path_behavior: None,
},
FileSystemSandboxEntry {
path: FileSystemPath::Path { path: link_private },
path: link_private.into(),
access: FileSystemAccessMode::Deny,
missing_path_behavior: None,
},
@@ -1725,14 +1723,12 @@ mod tests {
let blocked_root = AbsolutePathBuf::from_absolute_path(&blocked).expect("absolute blocked");
let policy = FileSystemSandboxPolicy::restricted(vec![
FileSystemSandboxEntry {
path: FileSystemPath::Path {
path: workspace_root,
},
path: workspace_root.into(),
access: FileSystemAccessMode::Write,
missing_path_behavior: None,
},
FileSystemSandboxEntry {
path: FileSystemPath::Path { path: blocked_root },
path: blocked_root.into(),
access: FileSystemAccessMode::Read,
missing_path_behavior: None,
},
@@ -1773,9 +1769,7 @@ mod tests {
let workspace_root =
AbsolutePathBuf::from_absolute_path(&workspace).expect("absolute workspace");
let policy = FileSystemSandboxPolicy::restricted(vec![FileSystemSandboxEntry {
path: FileSystemPath::Path {
path: workspace_root,
},
path: workspace_root.into(),
access: FileSystemAccessMode::Write,
missing_path_behavior: None,
}]);
@@ -1823,9 +1817,7 @@ mod tests {
let workspace_root =
AbsolutePathBuf::from_absolute_path(&workspace).expect("absolute workspace");
let policy = FileSystemSandboxPolicy::restricted(vec![FileSystemSandboxEntry {
path: FileSystemPath::Path {
path: workspace_root,
},
path: workspace_root.into(),
access: FileSystemAccessMode::Write,
missing_path_behavior: None,
}]);
@@ -1870,9 +1862,7 @@ mod tests {
let link_workspace_root = AbsolutePathBuf::from_absolute_path(&link_workspace)
.expect("absolute symlinked workspace");
let policy = FileSystemSandboxPolicy::restricted(vec![FileSystemSandboxEntry {
path: FileSystemPath::Path {
path: link_workspace_root,
},
path: link_workspace_root.into(),
access: FileSystemAccessMode::Write,
missing_path_behavior: None,
}]);
@@ -2139,10 +2129,9 @@ mod tests {
std::fs::create_dir(&readable_root).expect("create readable root");
let policy = FileSystemSandboxPolicy::restricted(vec![FileSystemSandboxEntry {
path: FileSystemPath::Path {
path: AbsolutePathBuf::try_from(readable_root.as_path())
.expect("absolute readable root"),
},
path: AbsolutePathBuf::try_from(readable_root.as_path())
.expect("absolute readable root")
.into(),
access: FileSystemAccessMode::Read,
missing_path_behavior: None,
}]);
@@ -2206,14 +2195,12 @@ mod tests {
let blocked_str = path_to_string(blocked.as_path());
let policy = FileSystemSandboxPolicy::restricted(vec![
FileSystemSandboxEntry {
path: FileSystemPath::Path {
path: writable_root,
},
path: writable_root.into(),
access: FileSystemAccessMode::Write,
missing_path_behavior: None,
},
FileSystemSandboxEntry {
path: FileSystemPath::Path { path: blocked },
path: blocked.into(),
access: FileSystemAccessMode::Deny,
missing_path_behavior: None,
},
@@ -2281,21 +2268,17 @@ mod tests {
AbsolutePathBuf::from_absolute_path(&docs_public).expect("absolute docs/public");
let policy = FileSystemSandboxPolicy::restricted(vec![
FileSystemSandboxEntry {
path: FileSystemPath::Path {
path: writable_root,
},
path: writable_root.into(),
access: FileSystemAccessMode::Write,
missing_path_behavior: None,
},
FileSystemSandboxEntry {
path: FileSystemPath::Path { path: docs.clone() },
path: docs.clone().into(),
access: FileSystemAccessMode::Read,
missing_path_behavior: None,
},
FileSystemSandboxEntry {
path: FileSystemPath::Path {
path: docs_public.clone(),
},
path: docs_public.clone().into(),
access: FileSystemAccessMode::Write,
missing_path_behavior: None,
},
@@ -2343,16 +2326,12 @@ mod tests {
missing_path_behavior: None,
},
FileSystemSandboxEntry {
path: FileSystemPath::Path {
path: blocked.clone(),
},
path: blocked.clone().into(),
access: FileSystemAccessMode::Deny,
missing_path_behavior: None,
},
FileSystemSandboxEntry {
path: FileSystemPath::Path {
path: allowed.clone(),
},
path: allowed.clone().into(),
access: FileSystemAccessMode::Write,
missing_path_behavior: None,
},
@@ -2415,16 +2394,12 @@ mod tests {
missing_path_behavior: None,
},
FileSystemSandboxEntry {
path: FileSystemPath::Path {
path: blocked.clone(),
},
path: blocked.clone().into(),
access: FileSystemAccessMode::Deny,
missing_path_behavior: None,
},
FileSystemSandboxEntry {
path: FileSystemPath::Path {
path: allowed_file.clone(),
},
path: allowed_file.clone().into(),
access: FileSystemAccessMode::Write,
missing_path_behavior: None,
},
@@ -2492,19 +2467,17 @@ mod tests {
let allowed_str = path_to_string(allowed.as_path());
let policy = FileSystemSandboxPolicy::restricted(vec![
FileSystemSandboxEntry {
path: FileSystemPath::Path {
path: writable_root,
},
path: writable_root.into(),
access: FileSystemAccessMode::Write,
missing_path_behavior: None,
},
FileSystemSandboxEntry {
path: FileSystemPath::Path { path: blocked },
path: blocked.into(),
access: FileSystemAccessMode::Deny,
missing_path_behavior: None,
},
FileSystemSandboxEntry {
path: FileSystemPath::Path { path: allowed },
path: allowed.into(),
access: FileSystemAccessMode::Write,
missing_path_behavior: None,
},
@@ -2551,9 +2524,7 @@ mod tests {
missing_path_behavior: None,
},
FileSystemSandboxEntry {
path: FileSystemPath::Path {
path: blocked.clone(),
},
path: blocked.clone().into(),
access: FileSystemAccessMode::Deny,
missing_path_behavior: None,
},
@@ -2597,9 +2568,7 @@ mod tests {
missing_path_behavior: None,
},
FileSystemSandboxEntry {
path: FileSystemPath::Path {
path: blocked_file.clone(),
},
path: blocked_file.clone().into(),
access: FileSystemAccessMode::Deny,
missing_path_behavior: None,
},
+11 -13
View File
@@ -101,20 +101,18 @@ impl FileSystemPermissions {
) -> Self {
let mut entries = Vec::new();
if let Some(read) = read {
entries.extend(read.into_iter().map(|path| {
FileSystemSandboxEntry::new(
FileSystemPath::Path { path },
FileSystemAccessMode::Read,
)
}));
entries.extend(
read.into_iter().map(|path| {
FileSystemSandboxEntry::new(path.into(), FileSystemAccessMode::Read)
}),
);
}
if let Some(write) = write {
entries.extend(write.into_iter().map(|path| {
FileSystemSandboxEntry::new(
FileSystemPath::Path { path },
FileSystemAccessMode::Write,
)
}));
entries.extend(
write.into_iter().map(|path| {
FileSystemSandboxEntry::new(path.into(), FileSystemAccessMode::Write)
}),
);
}
Self {
entries,
@@ -2828,7 +2826,7 @@ mod tests {
.expect("absolute path");
let file_system_permissions = FileSystemPermissions {
entries: vec![FileSystemSandboxEntry {
path: FileSystemPath::Path { path },
path: path.into(),
access: FileSystemAccessMode::Read,
missing_path_behavior: None,
}],
+30 -21
View File
@@ -379,6 +379,12 @@ pub enum FileSystemPath {
},
}
impl From<AbsolutePathBuf> for FileSystemPath {
fn from(path: AbsolutePathBuf) -> Self {
Self::Path { path }
}
}
const PROJECT_ROOTS_GLOB_PATTERN_PREFIX: &str = "codex-project-roots://";
pub fn project_roots_glob_pattern(subpath: &Path) -> String {
@@ -607,9 +613,12 @@ impl FileSystemSandboxPolicy {
FileSystemAccessMode::Write,
));
}
entries.extend(writable_roots.iter().cloned().map(|path| {
FileSystemSandboxEntry::new(FileSystemPath::Path { path }, FileSystemAccessMode::Write)
}));
entries.extend(
writable_roots
.iter()
.cloned()
.map(|path| FileSystemSandboxEntry::new(path.into(), FileSystemAccessMode::Write)),
);
append_default_read_only_project_root_subpath_if_no_explicit_rule(&mut entries, ".git");
append_default_read_only_project_root_subpath_if_no_explicit_rule(&mut entries, ".agents");
@@ -767,7 +776,7 @@ impl FileSystemSandboxPolicy {
value: FileSystemSpecialPath::ProjectRoots { .. },
} => {
if let Some(path) = resolve_file_system_path(&entry.path, cwd.as_ref()) {
entry.path = FileSystemPath::Path { path };
entry.path = path.into();
}
}
FileSystemPath::GlobPattern { pattern } => {
@@ -799,15 +808,12 @@ impl FileSystemSandboxPolicy {
value: FileSystemSpecialPath::ProjectRoots { subpath },
} => {
entries.extend(workspace_roots.iter().map(|root| FileSystemSandboxEntry {
path: FileSystemPath::Path {
path: match subpath.as_ref() {
Some(subpath) => AbsolutePathBuf::resolve_path_against_base(
subpath,
root.as_path(),
),
None => root.clone(),
},
},
path: FileSystemPath::from(match subpath.as_ref() {
Some(subpath) => {
AbsolutePathBuf::resolve_path_against_base(subpath, root.as_path())
}
None => root.clone(),
}),
access: entry.access,
missing_path_behavior: entry.missing_path_behavior,
}));
@@ -831,7 +837,7 @@ impl FileSystemSandboxPolicy {
}
FileSystemPath::Path { path } => {
entries.push(FileSystemSandboxEntry {
path: FileSystemPath::Path { path },
path: path.into(),
access: entry.access,
missing_path_behavior: entry.missing_path_behavior,
});
@@ -881,7 +887,7 @@ impl FileSystemSandboxPolicy {
}
self.entries.push(FileSystemSandboxEntry::new(
FileSystemPath::Path { path: path.clone() },
path.clone().into(),
FileSystemAccessMode::Read,
));
}
@@ -900,7 +906,7 @@ impl FileSystemSandboxPolicy {
}
self.entries.push(FileSystemSandboxEntry::new(
FileSystemPath::Path { path: path.clone() },
path.clone().into(),
FileSystemAccessMode::Write,
));
}
@@ -928,7 +934,7 @@ impl FileSystemSandboxPolicy {
&& matches!(&entry.path, FileSystemPath::Path { path: existing } if existing == path)
}) {
self.entries.push(FileSystemSandboxEntry::new(
FileSystemPath::Path { path: path.clone() },
path.clone().into(),
FileSystemAccessMode::Write,
));
}
@@ -1689,9 +1695,12 @@ fn legacy_runtime_file_system_policy_for_cwd(
FileSystemAccessMode::Write,
));
}
entries.extend(writable_roots.iter().cloned().map(|path| {
FileSystemSandboxEntry::new(FileSystemPath::Path { path }, FileSystemAccessMode::Write)
}));
entries.extend(
writable_roots
.iter()
.cloned()
.map(|path| FileSystemSandboxEntry::new(path.into(), FileSystemAccessMode::Write)),
);
if let Ok(cwd_root) = AbsolutePathBuf::from_absolute_path(cwd) {
for protected_path in default_read_only_subpaths_for_writable_root(
@@ -1728,7 +1737,7 @@ fn append_default_read_only_path_if_no_explicit_rule(
entries: &mut Vec<FileSystemSandboxEntry>,
path: AbsolutePathBuf,
) {
append_default_read_only_entry_if_no_explicit_rule(entries, FileSystemPath::Path { path });
append_default_read_only_entry_if_no_explicit_rule(entries, path.into());
}
fn append_default_read_only_entry_if_no_explicit_rule(
+7 -11
View File
@@ -199,9 +199,7 @@ fn transform_additional_permissions_preserves_denied_entries() {
missing_path_behavior: None,
},
FileSystemSandboxEntry {
path: FileSystemPath::Path {
path: denied_path.clone(),
},
path: denied_path.clone().into(),
access: FileSystemAccessMode::Deny,
missing_path_behavior: None,
},
@@ -250,12 +248,12 @@ fn transform_additional_permissions_preserves_denied_entries() {
missing_path_behavior: None,
},
FileSystemSandboxEntry {
path: FileSystemPath::Path { path: denied_path },
path: denied_path.into(),
access: FileSystemAccessMode::Deny,
missing_path_behavior: None,
},
FileSystemSandboxEntry {
path: FileSystemPath::Path { path: allowed_path },
path: allowed_path.into(),
access: FileSystemAccessMode::Write,
missing_path_behavior: None,
},
@@ -279,7 +277,7 @@ fn managed_mitm_ca_bundle_becomes_readable_for_restricted_sandbox() {
.expect("absolute managed bundle path");
let permission_profile = PermissionProfile::from_runtime_permissions(
&FileSystemSandboxPolicy::restricted(vec![FileSystemSandboxEntry {
path: FileSystemPath::Path { path: cwd.clone() },
path: cwd.clone().into(),
access: FileSystemAccessMode::Read,
missing_path_behavior: None,
}]),
@@ -297,14 +295,12 @@ fn managed_mitm_ca_bundle_becomes_readable_for_restricted_sandbox() {
file_system_sandbox_policy,
FileSystemSandboxPolicy::restricted(vec![
FileSystemSandboxEntry {
path: FileSystemPath::Path { path: cwd },
path: cwd.into(),
access: FileSystemAccessMode::Read,
missing_path_behavior: None,
},
FileSystemSandboxEntry {
path: FileSystemPath::Path {
path: managed_bundle_path,
},
path: managed_bundle_path.into(),
access: FileSystemAccessMode::Read,
missing_path_behavior: None,
},
@@ -498,7 +494,7 @@ fn transform_for_direct_spawn_windows_materializes_inner_helper() {
missing_path_behavior: None,
},
FileSystemSandboxEntry {
path: FileSystemPath::Path { path: blocked },
path: blocked.into(),
access: FileSystemAccessMode::Deny,
missing_path_behavior: None,
},
+1 -1
View File
@@ -361,7 +361,7 @@ fn materialize_cwd_dependent_entry(
value: FileSystemSpecialPath::ProjectRoots { .. },
} => resolve_permission_path(&entry.path, cwd)
.map(|path| FileSystemSandboxEntry {
path: FileSystemPath::Path { path },
path: path.into(),
access: entry.access,
missing_path_behavior: entry.missing_path_behavior,
})
@@ -59,7 +59,7 @@ fn root_write_policy_with_carveouts_still_uses_platform_sandbox() {
missing_path_behavior: None,
},
FileSystemSandboxEntry {
path: FileSystemPath::Path { path: blocked },
path: blocked.into(),
access: FileSystemAccessMode::Deny,
missing_path_behavior: None,
},
@@ -433,7 +433,7 @@ fn intersect_permission_profiles_deduplicates_materialized_grants() {
missing_path_behavior: None,
},
FileSystemSandboxEntry {
path: FileSystemPath::Path { path: cwd.clone() },
path: cwd.clone().into(),
access: FileSystemAccessMode::Write,
missing_path_behavior: None,
},
@@ -496,7 +496,7 @@ fn intersect_permission_profiles_materializes_cwd_deny_entries() {
missing_path_behavior: None,
},
FileSystemSandboxEntry {
path: FileSystemPath::Path { path: request_cwd },
path: request_cwd.into(),
access: FileSystemAccessMode::Deny,
missing_path_behavior: None,
},
@@ -530,7 +530,7 @@ fn intersect_permission_profiles_drops_deny_entries_without_filesystem_grants()
missing_path_behavior: None,
},
FileSystemSandboxEntry {
path: FileSystemPath::Path { path: secret },
path: secret.into(),
access: FileSystemAccessMode::Deny,
missing_path_behavior: None,
},
@@ -633,9 +633,7 @@ fn intersect_permission_profiles_materializes_relative_deny_globs_for_reuse() {
file_system: Some(FileSystemPermissions {
entries: vec![
FileSystemSandboxEntry {
path: FileSystemPath::Path {
path: request_cwd.clone(),
},
path: request_cwd.clone().into(),
access: FileSystemAccessMode::Write,
missing_path_behavior: None,
},
@@ -838,9 +836,7 @@ fn merge_file_system_policy_with_additional_permissions_preserves_unreadable_roo
missing_path_behavior: None,
},
FileSystemSandboxEntry {
path: FileSystemPath::Path {
path: denied_path.clone(),
},
path: denied_path.clone().into(),
access: FileSystemAccessMode::Deny,
missing_path_behavior: None,
},
@@ -853,7 +849,7 @@ fn merge_file_system_policy_with_additional_permissions_preserves_unreadable_roo
assert_eq!(
merged_policy.entries.contains(&FileSystemSandboxEntry {
path: FileSystemPath::Path { path: denied_path },
path: denied_path.into(),
access: FileSystemAccessMode::Deny,
missing_path_behavior: None,
}),
@@ -861,7 +857,7 @@ fn merge_file_system_policy_with_additional_permissions_preserves_unreadable_roo
);
assert_eq!(
merged_policy.entries.contains(&FileSystemSandboxEntry {
path: FileSystemPath::Path { path: allowed_path },
path: allowed_path.into(),
access: FileSystemAccessMode::Read,
missing_path_behavior: None,
}),
@@ -925,7 +921,7 @@ fn effective_file_system_sandbox_policy_returns_base_policy_without_additional_p
missing_path_behavior: None,
},
FileSystemSandboxEntry {
path: FileSystemPath::Path { path: denied_path },
path: denied_path.into(),
access: FileSystemAccessMode::Deny,
missing_path_behavior: None,
},
@@ -955,9 +951,7 @@ fn effective_file_system_sandbox_policy_merges_additional_write_roots() {
missing_path_behavior: None,
},
FileSystemSandboxEntry {
path: FileSystemPath::Path {
path: denied_path.clone(),
},
path: denied_path.clone().into(),
access: FileSystemAccessMode::Deny,
missing_path_behavior: None,
},
@@ -975,7 +969,7 @@ fn effective_file_system_sandbox_policy_merges_additional_write_roots() {
assert_eq!(
effective_policy.entries.contains(&FileSystemSandboxEntry {
path: FileSystemPath::Path { path: denied_path },
path: denied_path.into(),
access: FileSystemAccessMode::Deny,
missing_path_behavior: None,
}),
@@ -983,7 +977,7 @@ fn effective_file_system_sandbox_policy_merges_additional_write_roots() {
);
assert_eq!(
effective_policy.entries.contains(&FileSystemSandboxEntry {
path: FileSystemPath::Path { path: allowed_path },
path: allowed_path.into(),
access: FileSystemAccessMode::Write,
missing_path_behavior: None,
}),