Allow one NVX workload to access multiple host directories, with read-only or read-write access selected separately for each directory.
| Example |
Expected behaviour |
C:\projects\app and C:\build-output are read-write |
The workload can read and modify both directories. |
C:\tools is read-only in the same workload |
The workload can read tools but cannot modify them. |
C:\projects\private is not granted |
It remains inaccessible; sharing app must not expose sibling directories. |
Keep denied-path restrictions enforced for every mapping. If a combination cannot be represented safely, reject it clearly rather than expanding access.
Verify simultaneous RO/RW mappings with real workload reads and writes.
MXC schema requirement: filesystem.readonlyPaths and filesystem.readwritePaths are lists of paths.
Related: #216 covers mounting host shares inside the sandbox. This request focuses on supporting multiple mappings and their individual access modes.
Allow one NVX workload to access multiple host directories, with read-only or read-write access selected separately for each directory.
C:\projects\appandC:\build-outputare read-writeC:\toolsis read-only in the same workloadC:\projects\privateis not grantedappmust not expose sibling directories.Keep denied-path restrictions enforced for every mapping. If a combination cannot be represented safely, reject it clearly rather than expanding access.
Verify simultaneous RO/RW mappings with real workload reads and writes.
MXC schema requirement:
filesystem.readonlyPathsandfilesystem.readwritePathsare lists of paths.Related: #216 covers mounting host shares inside the sandbox. This request focuses on supporting multiple mappings and their individual access modes.