Skip to content

Support multiple filesystem mappings with separate access modes #281

Description

Allow one NVX workload to access multiple host directories, with read-only or read-write access selected separately for each directory.

Example Expected behaviour
C:\projects\app and C:\build-output are read-write The workload can read and modify both directories.
C:\tools is read-only in the same workload The workload can read tools but cannot modify them.
C:\projects\private is not granted It remains inaccessible; sharing app must not expose sibling directories.

Keep denied-path restrictions enforced for every mapping. If a combination cannot be represented safely, reject it clearly rather than expanding access.

Verify simultaneous RO/RW mappings with real workload reads and writes.

MXC schema requirement: filesystem.readonlyPaths and filesystem.readwritePaths are lists of paths.

Related: #216 covers mounting host shares inside the sandbox. This request focuses on supporting multiple mappings and their individual access modes.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions