Documentation
¶
Overview ¶
Package safeopen provides the narrow no-follow opening boundary for local stores. Every directory component is opened atomically with O_DIRECTORY|O_NOFOLLOW.
Index ¶
- Constants
- func Control(f *os.File, fn func(uintptr) error) error
- func File(path string) (*os.File, error)
- func InDir(dir *os.File, name string, flags int, perm os.FileMode) (*os.File, error)
- func InRoot(root *os.Root, rel string, flags int, perm os.FileMode, directory bool) (*os.File, error)
- func PinDir(root *os.Root) (*os.File, error)
- func Root(path string) (*os.Root, error)
- func SubRoot(root *os.Root, rel string) (*os.Root, error)
Constants ¶
const Supported = true
Variables ¶
This section is empty.
Functions ¶
func InDir ¶
InDir opens one path component beneath a PinDir descriptor with the same validation, flags and errors as InRoot's final step. It never descends.
func InRoot ¶
func InRoot(root *os.Root, rel string, flags int, perm os.FileMode, directory bool) (*os.File, error)
InRoot opens through pinned directories; the final entry never follows a symlink and O_NONBLOCK prevents a replaced FIFO from blocking before Stat.
func PinDir ¶
PinDir opens the directory root pins as one descriptor, exactly as InRoot's traversal begins. A caller opening many basenames beneath the same root keeps it and uses InDir, paying one no-follow openat per file instead of three (CAL-V0-070). The caller closes it.
func Root ¶
Root pins the absolute directory, refusing symlinks in any component. The descriptor-only /dev/fd bridge is used because Go exposes no File-to-Root constructor. The source descriptor stays pinned until conversion AND identity comparison finish. An absent or non-equivalent bridge fails closed.
Types ¶
This section is empty.