# bend-open-under: package entry for BendHub. # Source: bendlang/bend PR #1106 (reviewed by VictorTaelin; closed as # WONTFIX (CAPACITY) and rerouted here: "a clean and careful walk ... works # just as well as a foreign effect in a hub package, with the same C code"). # # Open a path read-only, below a directory root, never through a symbolic # link: one openat2 (RESOLVE_BENEATH, Linux 5.6+), else an openat walk, one # component at a time, each with O_NOFOLLOW, every step re-checked so a swap # between check and open cannot slip through. A link, a missing name, a # directory, an empty, "." or ".." component and a path that climbs out of # root all fail; the root is taken as given. import Base # path, read-only, below root and never through a symbolic link: a link, # a missing name, a directory, an empty, "." or ".." component and a # climb out of root all fail. root is taken as given. def File.open_under(root: String, path: String) -> IO(Result<&1, &1, U32 & String, File>): import "./file_open_under.c" import "./file_open_under.js"