Skip to main content

is_safe_plugin_id

Function is_safe_plugin_id 

Source
pub fn is_safe_plugin_id(id: &str) -> bool
Expand description

Is id a single, safe path component — usable as a directory name that cannot escape its parent? The plugin id keys the per-plugin data dir, which is joined into a host path and mounted writable into the guest; a crafted id (/etc/cron.d, ../../.ssh, .) would otherwise relocate that writable mount outside the sandbox with no fs grant (the CRITICAL isolation contract, lib.rs build_plugin_wasi). Accepts exactly one Component::Normal; rejects empty, absolute, separators, and . / ...