85 releases (26 stable)

new 3.4.2 Dec 4, 2024
3.4.1 Nov 5, 2024
3.4.0 Oct 30, 2024
3.2.0 Jul 8, 2024
0.0.0 Jun 25, 2020

#18 in Filesystem

Download history 41747/week @ 2024-08-20 41377/week @ 2024-08-27 44713/week @ 2024-09-03 44009/week @ 2024-09-10 42254/week @ 2024-09-17 44623/week @ 2024-09-24 45336/week @ 2024-10-01 49970/week @ 2024-10-08 38894/week @ 2024-10-15 49133/week @ 2024-10-22 51631/week @ 2024-10-29 56060/week @ 2024-11-05 48736/week @ 2024-11-12 60136/week @ 2024-11-19 48863/week @ 2024-11-26 50413/week @ 2024-12-03

217,516 downloads per month
Used in 250 crates (32 directly)

Apache-2.0…

575KB
12K SLoC

cap-std

Capability-based version of the Rust standard library

Github Actions CI Status crates.io page docs.rs docs

This crate provides a capability-based version of std, providing sandboxed filesystem, networking, and clock APIs. See the toplevel README.md for more information about sandboxing using capability-based security.

The filesystem module cap_std::fs, the networking module cap_std::net, and the time module cap_std::time currently support Linux, macOS, FreeBSD, and Windows. WASI support is in development, though not yet usable.

Example usage of Dir for filesystem access:

use std::io;
use cap_std::fs::Dir;

/// Open files relative to `dir`.
fn dir_example(dir: &Dir) -> io::Result<()> {
    // This works (assuming symlinks don't lead outside of `dir`).
    let file = dir.open("the/thing.txt")?;

    // This fails, since `..` leads outside of `dir`.
    let hidden = dir.open("../hidden.txt")?;

    // This fails, as creating symlinks to absolute paths is not permitted.
    dir.symlink("/hidden.txt", "misdirection.txt")?;

    // However, even if the symlink had succeeded, or, if there is a
    // pre-existing symlink to an absolute directory, following a
    // symlink which would lead outside the sandbox also fails.
    let secret = dir.open("misdirection.txt")?;

    Ok(())
}

Example usage of Pool for network access:

use std::io;
use cap_std::net::Pool;

/// Open network addresses within `pool`.
fn pool_example(pool: &Pool) -> io::Result<()> {
    // Connect to an address. This succeeds only if the given address and
    // port are present in `pool`.
    let stream = pool.connect_tcp_stream("localhost:3333")?;

    Ok(())
}

Dependencies

~1.8–10MB
~116K SLoC