Documentation
¶
Overview ¶
Package safeopen provides the narrow no-follow opening boundary for local stores. Every directory component is opened atomically with O_DIRECTORY|O_NOFOLLOW.
Index ¶
- Constants
- func Control(f *os.File, fn func(uintptr) error) error
- func File(path string) (*os.File, error)
- func InRoot(root *os.Root, rel string, flags int, perm os.FileMode, directory bool) (*os.File, error)
- func Root(path string) (*os.Root, error)
- func SubRoot(root *os.Root, rel string) (*os.Root, error)
Constants ¶
View Source
const Supported = true
Variables ¶
This section is empty.
Functions ¶
func InRoot ¶
func InRoot(root *os.Root, rel string, flags int, perm os.FileMode, directory bool) (*os.File, error)
InRoot opens through pinned directories; the final entry never follows a symlink and O_NONBLOCK prevents a replaced FIFO from blocking before Stat.
func Root ¶
Root pins the absolute directory, refusing symlinks in any component. The descriptor-only /dev/fd bridge is used because Go exposes no File-to-Root constructor. The source descriptor stays pinned until conversion AND identity comparison finish. An absent or non-equivalent bridge fails closed.
Types ¶
This section is empty.
Click to show internal directories.
Click to hide internal directories.