safeopen

package
v1.0.0-rc.2 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 6, 2026 License: AGPL-3.0, AGPL-3.0-or-later Imports: 6 Imported by: 0

Documentation

Overview

SPDX-License-Identifier: AGPL-3.0-or-later Derived from internal/tasks/safeopen/at_linux.go at 25971bda1ca1664d8a546d751cb2bb9bbd454daf. Kept private to the Core observer to preserve decision 0397 component separation.

SPDX-License-Identifier: AGPL-3.0-or-later Derived from internal/tasks/safeopen/open_unix.go at 25971bda1ca1664d8a546d751cb2bb9bbd454daf. Kept private to the Core observer to preserve decision 0397 component separation. Package safeopen provides the narrow no-follow opening boundary for local stores. Every directory component is opened atomically with O_DIRECTORY|O_NOFOLLOW.

Index

Constants

View Source
const Supported = true

Variables

This section is empty.

Functions

This section is empty.

Types

type Directory

type Directory struct {
	// contains filtered or unexported fields
}

Directory retains a pinned root without exposing filesystem mutators.

func Root

func Root(path string) (*Directory, error)

Root pins the absolute directory, refusing symlinks in any component. The descriptor-only /dev/fd bridge is used because Go exposes no File-to-Root constructor. The source descriptor stays pinned until conversion AND identity comparison finish. An absent or non-equivalent bridge fails closed.

func SubRoot

func SubRoot(root *Directory, rel string) (*Directory, error)

func (*Directory) Close

func (d *Directory) Close() error

func (*Directory) Lstat

func (d *Directory) Lstat(name string) (os.FileInfo, error)
func (d *Directory) Readlink(name string) (string, error)

func (*Directory) Stat

func (d *Directory) Stat(name string) (os.FileInfo, error)

type File

type File struct {
	// contains filtered or unexported fields
}

File exposes only observation operations on a descriptor opened O_RDONLY.

func InRoot

func InRoot(root *Directory, rel string, directory bool) (*File, error)

InRoot opens through pinned directories; the final entry never follows a symlink and O_NONBLOCK prevents a replaced FIFO from blocking before Stat.

func (*File) Close

func (f *File) Close() error

func (*File) Read

func (f *File) Read(p []byte) (int, error)

func (*File) ReadDir

func (f *File) ReadDir(n int) ([]os.DirEntry, error)

func (*File) Stat

func (f *File) Stat() (os.FileInfo, error)

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL