Documentation
¶
Overview ¶
Package readregular provides bounds-checked and type-checked file reads for regular files, rejecting non-regular files (such as FIFOs, devices, and sockets) and files that exceed an explicit size cap.
Governed by security#77 finding 3 (re-file of security#56 finding 3).
Index ¶
Constants ¶
const DefaultMax int64 = 16 << 20
DefaultMax is the default file size cap: 16 MiB.
Variables ¶
This section is empty.
Functions ¶
func Read ¶
Read reads path if and only if it is a regular file whose size does not exceed max. It follows symlinks when stating and opening the path, verifies that the target is a regular file, checks that its stated size is within max, opens the file, confirms os.SameFile between the handle and the initial stat, and reads through io.LimitReader(file, max+1).
If the target is not regular, it returns an error naming the path and mode. If the file exceeds max (either at stat or during read), it returns an error naming the cap.
Types ¶
This section is empty.