safeopen

package
v1.0.0-rc.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 27, 2026 License: AGPL-3.0, AGPL-3.0-or-later Imports: 6 Imported by: 0

Documentation

Overview

Package safeopen provides the narrow no-follow opening boundary for local stores. Every directory component is opened atomically with O_DIRECTORY|O_NOFOLLOW.

Index

Constants

View Source
const Supported = true

Variables

This section is empty.

Functions

func Control

func Control(f *os.File, fn func(uintptr) error) error

Control keeps the descriptor alive, including against concurrent Close, for fn.

func File

func File(path string) (*os.File, error)

func InRoot

func InRoot(root *os.Root, rel string, flags int, perm os.FileMode, directory bool) (*os.File, error)

InRoot opens through pinned directories; the final entry never follows a symlink and O_NONBLOCK prevents a replaced FIFO from blocking before Stat.

func Root

func Root(path string) (*os.Root, error)

Root pins the absolute directory, refusing symlinks in any component. The descriptor-only /dev/fd bridge is used because Go exposes no File-to-Root constructor. The source descriptor stays pinned until conversion AND identity comparison finish. An absent or non-equivalent bridge fails closed.

func SubRoot

func SubRoot(root *os.Root, rel string) (*os.Root, error)

Types

This section is empty.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL