Read reads a regular file whose permission bits deny group and other access.
Symlinks are allowed; the opened target is checked. This does not inspect ACLs
or establish file ownership. Errors omit paths and file contents so callers
can safely add their own configuration context.