Skip to content

fix: add ambient coverage test and restrict open()/create() file handles - #17

Merged
bordumb merged 1 commit into
mainfrom
dev-ambientAttestation
Mar 18, 2026
Merged

bordumb merged 1 commit into
mainfrom
dev-ambientAttestation

Conversation

@bordumb

@bordumb bordumb commented Mar 18, 2026

Copy link
Copy Markdown
Collaborator

Ambient: compile-time test ensures Cap satisfies Has

for
every permission type — catches impl_ambient! omissions at build time.

File handles: open() now returns ReadFile (Read+Seek, no Write) and
create() returns WriteFile (Write+Seek, no Read), closing the capability
leak where FsRead holders could write to opened files via std::io::Write.

  Ambient: compile-time test ensures Cap<Ambient> satisfies Has<P> for
  every permission type — catches impl_ambient! omissions at build time.

  File handles: open() now returns ReadFile (Read+Seek, no Write) and
  create() returns WriteFile (Write+Seek, no Read), closing the capability
  leak where FsRead holders could write to opened files via std::io::Write.
@bordumb bordumb self-assigned this Mar 18, 2026
@bordumb
bordumb merged commit 5baf929 into main Mar 18, 2026
6 checks passed
@bordumb
bordumb deleted the dev-ambientAttestation branch March 18, 2026 23:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant