Skip to content

feat: add explicit read-write filesystem grants across APIs - #275

Draft
jamesboyzj-design wants to merge 1 commit into
multikernel:mainfrom
jamesboyzj-design:feat/explicit-rw-grants-150
Draft

jamesboyzj-design wants to merge 1 commit into
multikernel:mainfrom
jamesboyzj-design:feat/explicit-rw-grants-150

Conversation

@jamesboyzj-design

Copy link
Copy Markdown
Contributor

Adds an explicit read/execute + write grant so callers can state combined authority before #150 changes fs_write to pure-write semantics. Existing fs_write behavior is unchanged here; this preparatory PR does not close #150.

The entry point is available as Rust fs_read_write on SandboxBuilder and ConfinementBuilder, --fs-read-write in the CLI, sandlock_sandbox_builder_fs_read_write in C, fs_read_write in Python, FSReadWrite in Go, and [filesystem].read_write in TOML. Grants normalize to both read and write lists; profile export/reload preserves authority. Python forwards the new field, and Go includes it in NUL validation before allocating a builder.

Validation on exact commit 50d3707, based directly on main 1e697ce (independent of PR #274): Linux aarch64, Rust 1.96, tests run as uid/gid 65534 in a non-privileged Docker container with seccomp unconfined. Core unit tests: 881 passed; C ABI filesystem tests: 9 passed; CLI tests: 33 passed; Python profile/config tests: 96 passed; five Go profile/new-API tests passed, including actual creation and readback. C header matches cbindgen 0.29.2 output; git diff --check passes. Distinct x86_64 behavior and full workspace/SDK suites are left to CI; checkpoint restore is not validated locally.

Remaining #150 work is the coordinated pure-write enforcement and migration: Landlock, chroot, procfs, COW injected descriptors and upper-layer reads, existing defaults/examples, and overlapping-read diagnostics. No path-based append-only guarantee is introduced.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Feature: write-only / append-only filesystem grants (fs_write_only / fs_append)

1 participant