worktreesecure

package
v0.179.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 2, 2026 License: Apache-2.0 Imports: 9 Imported by: 0

Documentation

Overview

Package worktreesecure provides descriptor-held filesystem custody helpers. It owns no worktree policy, record format, Git behavior, or transaction flow.

Index

Constants

This section is empty.

Variables

View Source
var ErrDirectoryMoveIdentityChanged = errors.New("directory move identity changed")

ErrDirectoryMoveIdentityChanged reports a no-replace move whose identity no longer matches.

Functions

func DirectoryEmpty

func DirectoryEmpty(directory *os.File) (bool, error)

DirectoryEmpty reports whether a held directory has no entries.

func DirectoryEntryStillMatches

func DirectoryEntryStillMatches(parent *os.File, name string, directory *os.File) bool

DirectoryEntryStillMatches checks a child entry against a held directory descriptor.

func DirectoryExistsNoFollow

func DirectoryExistsNoFollow(path string) (bool, error)

DirectoryExistsNoFollow classifies a directory without accepting a symlink.

func DirectoryStillMatches

func DirectoryStillMatches(path string, directory *os.File) bool

DirectoryStillMatches checks a lexical path against a held directory descriptor.

func DuplicateDirectoryDescriptor

func DuplicateDirectoryDescriptor(directory *os.File, name string) (*os.File, error)

DuplicateDirectoryDescriptor duplicates an owned directory descriptor.

func MoveExpectedDirectoryNoReplace

func MoveExpectedDirectoryNoReplace(fromDirectory *os.File, fromName string, toDirectory *os.File, toName string, expected *os.File, rename RenameNoReplace, afterAuthorization func(), afterMove ...func()) (*os.File, error)

MoveExpectedDirectoryNoReplace moves expected only after an authorization callback.

func MoveExpectedDirectoryNoReplaceAuthorized

func MoveExpectedDirectoryNoReplaceAuthorized(fromDirectory *os.File, fromName string, toDirectory *os.File, toName string, expected *os.File, rename RenameNoReplace, authorize func() error, afterMove ...func()) (*os.File, error)

MoveExpectedDirectoryNoReplaceAuthorized moves expected through a caller-owned no-replace primitive.

func NoFollowChildAbsent

func NoFollowChildAbsent(parentFD int, name string) (bool, error)

NoFollowChildAbsent reports whether a child is absent without following links.

func OpenAbsoluteDirectoryNoFollow

func OpenAbsoluteDirectoryNoFollow(path string, create bool) (*os.File, error)

OpenAbsoluteDirectoryNoFollow walks an absolute path through real no-follow opens.

func OpenAbsoluteDirectoryNoFollowWith

func OpenAbsoluteDirectoryNoFollowWith(opener secureopen.Opener, path string, create bool) (*os.File, error)

OpenAbsoluteDirectoryNoFollowWith walks an absolute path through opener-held descriptors.

func OpenDirectoryAtNoFollow

func OpenDirectoryAtNoFollow(parentFD int, name, descriptorName, openContext string) (*os.File, error)

OpenDirectoryAtNoFollow opens a single child directory under parentFD.

func OpenOrCreateNoFollowDirectory

func OpenOrCreateNoFollowDirectory(parentFD int, name string) (int, error)

OpenOrCreateNoFollowDirectory opens or creates one child directory through real no-follow opens.

func OpenOrCreateNoFollowDirectoryFile

func OpenOrCreateNoFollowDirectoryFile(parentFD int, name, descriptorName string) (*os.File, error)

OpenOrCreateNoFollowDirectoryFile opens one child with a held, owned descriptor.

func OpenOrCreateNoFollowDirectoryWith

func OpenOrCreateNoFollowDirectoryWith(opener secureopen.Opener, parentFD int, name string) (int, error)

OpenOrCreateNoFollowDirectoryWith opens or creates one child directory through opener.

func OpenPrivateChild

func OpenPrivateChild(parent *os.File, name string, create bool, valid ValidSegment) (*os.File, error)

OpenPrivateChild opens a caller-validated child and hardens only create paths.

func OpenPrivateChildWith

func OpenPrivateChildWith(opener secureopen.Opener, parent *os.File, name string, create bool, valid ValidSegment) (*os.File, error)

OpenPrivateChildWith opens a caller-validated child through opener and hardens create paths.

func PathWithin

func PathWithin(root, path string) bool

PathWithin reports whether path is lexical root or a descendant of root.

func ReadPrivateRecordAt

func ReadPrivateRecordAt[T any](runDir *os.File, child, name string, valid ValidSegment) (T, error)

ReadPrivateRecordAt opens one private child and decodes its immutable JSON record.

func RequireAbsentNoFollowChild

func RequireAbsentNoFollowChild(parentFD int, name string) error

RequireAbsentNoFollowChild rejects every existing child without following links.

Types

type DirectoryIdentity

type DirectoryIdentity struct {
	// contains filtered or unexported fields
}

DirectoryIdentity is the device/inode identity of a directory entry.

func IdentityAt

func IdentityAt(parentFD int, name string) (DirectoryIdentity, error)

IdentityAt returns the no-follow device/inode identity of a directory child.

func (DirectoryIdentity) Device

func (identity DirectoryIdentity) Device() uint64

Device returns the identity device number.

func (DirectoryIdentity) Inode

func (identity DirectoryIdentity) Inode() uint64

Inode returns the identity inode number.

type RenameNoReplace

type RenameNoReplace func(fromDirectoryFD int, fromName string, toDirectoryFD int, toName string) error

RenameNoReplace publishes one directory entry without replacing another.

type ValidSegment

type ValidSegment func(string) bool

ValidSegment decides whether a caller-owned path component is admissible.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL