~/bend-docscommunity

package.bend relies on unsafe/foreign

raw source on the hub · import 0xb936378d6b717a2f9e6b5ff568004d36/package.bend as Package

bend-open-under: package entry for BendHub. Source: bendlang/bend PR #1106 (reviewed by VictorTaelin; closed as WONTFIX (CAPACITY) and rerouted here: "a clean and careful walk ... works just as well as a foreign effect in a hub package, with the same C code").

Open a path read-only, below a directory root, never through a symbolic link: one openat2 (RESOLVE_BENEATH, Linux 5.6+), else an openat walk, one component at a time, each with O_NOFOLLOW, every step re-checked so a swap between check and open cannot slip through. A link, a missing name, a directory, an empty, "." or ".." component and a path that climbs out of root all fail; the root is taken as given.

1 import
import Base

Effects (foreign code)

effect File.open_under source · line 17 · raw

@root:String -> @path:String -> IO(Result<&1, &1, Pair(U32, String), File>)

path, read-only, below root and never through a symbolic link: a link, a missing name, a directory, an empty, "." or ".." component and a climb out of root all fail. root is taken as given.

foreign: file_open_under.c, file_open_under.js