Skip to main content

grant_permits_read

Function grant_permits_read 

Source
pub fn grant_permits_read(grant: &CapabilityGrant, file: &Path) -> bool
Expand description

The same check for a FILE — on the file itself when it exists, on its parent only when it does not.

The file itself first, and that ordering is a security property. Canonicalizing resolves symlinks, so <granted>/innocent.org pointing at /etc/passwd resolves outside the prefix and is refused. Gating on the parent alone would pass it — the parent is granted — and the read would then follow the link straight out of the sandbox. Pinned by a_symlink_out_of_the_grant_is_denied, which failed against exactly that mistake before this ordering existed.

The parent fallback exists only for a path that does not resolve, and there it fixes a different wrong answer. [grant_permits_walk] falls back to the raw path, and wherever the granted prefix canonicalizes elsewhere (macOS /var → /private/var) the comparison fails and the call is refused — so a file that simply does not exist yet reports as a permission problem, sending a plugin author to their manifest instead of their path. “Is there anything in this file yet?” is the ordinary first-capture case and deserves a truthful answer.

The fallback cannot be used to smuggle anything past the check: it only applies when nothing is there to read, so the subsequent read fails regardless. <granted>/../../etc/passwd resolves as a file and is denied on the first branch.