Allow callers to expose a single existing host file to an NVX workload, without exposing its parent directory.
| Example |
Expected behaviour |
Grant read-only access to C:\config\settings.json |
The workload can read that file but cannot modify it. |
Grant read-write access to C:\results\output.txt |
The workload can read and update that file. |
| Other files exist beside the granted file |
They remain inaccessible unless separately granted. |
Do not replace a file grant with a broader directory grant. Keep denied-path restrictions enforced.
Verify reads, allowed writes, blocked writes and sibling-file isolation with real workloads.
MXC schema requirement: filesystem.readonlyPaths and filesystem.readwritePaths describe path grants; the current NVX export interface requires a directory root.
Allow callers to expose a single existing host file to an NVX workload, without exposing its parent directory.
C:\config\settings.jsonC:\results\output.txtDo not replace a file grant with a broader directory grant. Keep denied-path restrictions enforced.
Verify reads, allowed writes, blocked writes and sibling-file isolation with real workloads.
MXC schema requirement:
filesystem.readonlyPathsandfilesystem.readwritePathsdescribe path grants; the current NVX export interface requires a directory root.