Documentation
¶
Overview ¶
Package worktreesecure provides descriptor-held filesystem custody helpers. It owns no worktree policy, record format, Git behavior, or transaction flow.
Index ¶
- Variables
- func DirectoryEmpty(directory *os.File) (bool, error)
- func DirectoryEntryStillMatches(parent *os.File, name string, directory *os.File) bool
- func DirectoryExistsNoFollow(path string) (bool, error)
- func DirectoryStillMatches(path string, directory *os.File) bool
- func DuplicateDirectoryDescriptor(directory *os.File, name string) (*os.File, error)
- func MoveExpectedDirectoryNoReplace(fromDirectory *os.File, fromName string, toDirectory *os.File, toName string, ...) (*os.File, error)
- func MoveExpectedDirectoryNoReplaceAuthorized(fromDirectory *os.File, fromName string, toDirectory *os.File, toName string, ...) (*os.File, error)
- func NoFollowChildAbsent(parentFD int, name string) (bool, error)
- func OpenAbsoluteDirectoryNoFollow(path string, create bool) (*os.File, error)
- func OpenAbsoluteDirectoryNoFollowWith(opener secureopen.Opener, path string, create bool) (*os.File, error)
- func OpenDirectoryAtNoFollow(parentFD int, name, descriptorName, openContext string) (*os.File, error)
- func OpenOrCreateNoFollowDirectory(parentFD int, name string) (int, error)
- func OpenOrCreateNoFollowDirectoryFile(parentFD int, name, descriptorName string) (*os.File, error)
- func OpenOrCreateNoFollowDirectoryWith(opener secureopen.Opener, parentFD int, name string) (int, error)
- func OpenPrivateChild(parent *os.File, name string, create bool, valid ValidSegment) (*os.File, error)
- func OpenPrivateChildWith(opener secureopen.Opener, parent *os.File, name string, create bool, ...) (*os.File, error)
- func PathWithin(root, path string) bool
- func ReadPrivateRecordAt[T any](runDir *os.File, child, name string, valid ValidSegment) (T, error)
- func RequireAbsentNoFollowChild(parentFD int, name string) error
- type DirectoryIdentity
- type RenameNoReplace
- type ValidSegment
Constants ¶
This section is empty.
Variables ¶
var ErrDirectoryMoveIdentityChanged = errors.New("directory move identity changed")
ErrDirectoryMoveIdentityChanged reports a no-replace move whose identity no longer matches.
Functions ¶
func DirectoryEmpty ¶
DirectoryEmpty reports whether a held directory has no entries.
func DirectoryEntryStillMatches ¶
DirectoryEntryStillMatches checks a child entry against a held directory descriptor.
func DirectoryExistsNoFollow ¶
DirectoryExistsNoFollow classifies a directory without accepting a symlink.
func DirectoryStillMatches ¶
DirectoryStillMatches checks a lexical path against a held directory descriptor.
func DuplicateDirectoryDescriptor ¶
DuplicateDirectoryDescriptor duplicates an owned directory descriptor.
func MoveExpectedDirectoryNoReplace ¶
func MoveExpectedDirectoryNoReplace(fromDirectory *os.File, fromName string, toDirectory *os.File, toName string, expected *os.File, rename RenameNoReplace, afterAuthorization func(), afterMove ...func()) (*os.File, error)
MoveExpectedDirectoryNoReplace moves expected only after an authorization callback.
func MoveExpectedDirectoryNoReplaceAuthorized ¶
func MoveExpectedDirectoryNoReplaceAuthorized(fromDirectory *os.File, fromName string, toDirectory *os.File, toName string, expected *os.File, rename RenameNoReplace, authorize func() error, afterMove ...func()) (*os.File, error)
MoveExpectedDirectoryNoReplaceAuthorized moves expected through a caller-owned no-replace primitive.
func NoFollowChildAbsent ¶
NoFollowChildAbsent reports whether a child is absent without following links.
func OpenAbsoluteDirectoryNoFollow ¶
OpenAbsoluteDirectoryNoFollow walks an absolute path through real no-follow opens.
func OpenAbsoluteDirectoryNoFollowWith ¶
func OpenAbsoluteDirectoryNoFollowWith(opener secureopen.Opener, path string, create bool) (*os.File, error)
OpenAbsoluteDirectoryNoFollowWith walks an absolute path through opener-held descriptors.
func OpenDirectoryAtNoFollow ¶
func OpenDirectoryAtNoFollow(parentFD int, name, descriptorName, openContext string) (*os.File, error)
OpenDirectoryAtNoFollow opens a single child directory under parentFD.
func OpenOrCreateNoFollowDirectory ¶
OpenOrCreateNoFollowDirectory opens or creates one child directory through real no-follow opens.
func OpenOrCreateNoFollowDirectoryFile ¶
OpenOrCreateNoFollowDirectoryFile opens one child with a held, owned descriptor.
func OpenOrCreateNoFollowDirectoryWith ¶
func OpenOrCreateNoFollowDirectoryWith(opener secureopen.Opener, parentFD int, name string) (int, error)
OpenOrCreateNoFollowDirectoryWith opens or creates one child directory through opener.
func OpenPrivateChild ¶
func OpenPrivateChild(parent *os.File, name string, create bool, valid ValidSegment) (*os.File, error)
OpenPrivateChild opens a caller-validated child and hardens only create paths.
func OpenPrivateChildWith ¶
func OpenPrivateChildWith(opener secureopen.Opener, parent *os.File, name string, create bool, valid ValidSegment) (*os.File, error)
OpenPrivateChildWith opens a caller-validated child through opener and hardens create paths.
func PathWithin ¶
PathWithin reports whether path is lexical root or a descendant of root.
func ReadPrivateRecordAt ¶
ReadPrivateRecordAt opens one private child and decodes its immutable JSON record.
func RequireAbsentNoFollowChild ¶
RequireAbsentNoFollowChild rejects every existing child without following links.
Types ¶
type DirectoryIdentity ¶
type DirectoryIdentity struct {
// contains filtered or unexported fields
}
DirectoryIdentity is the device/inode identity of a directory entry.
func IdentityAt ¶
func IdentityAt(parentFD int, name string) (DirectoryIdentity, error)
IdentityAt returns the no-follow device/inode identity of a directory child.
func (DirectoryIdentity) Device ¶
func (identity DirectoryIdentity) Device() uint64
Device returns the identity device number.
func (DirectoryIdentity) Inode ¶
func (identity DirectoryIdentity) Inode() uint64
Inode returns the identity inode number.
type RenameNoReplace ¶
type RenameNoReplace func(fromDirectoryFD int, fromName string, toDirectoryFD int, toName string) error
RenameNoReplace publishes one directory entry without replacing another.
type ValidSegment ¶
ValidSegment decides whether a caller-owned path component is admissible.