pub fn validate_path(
path: &str,
root: &Path,
allowlist: Option<&[PathBuf]>,
blocklist: Option<&[PathBuf]>,
) -> GuardResultExpand description
Check that path is allowed by the project root, allowlist, and blocklist.
The path is first normalized (./.. resolved). The root is also normalized
so both sides are compared on equal footing.
Besides the project root and the explicit allowlist, paths under the
harness scratch directory (<OS temp>/cosh, where truncated tool-output
logs live) are allowed: the OS temp dir is ephemeral scratch by definition,
and blocking it would break the agent’s ability to read its own logs back.
The blocklist always takes priority, so even scratch paths can be denied.
Returns Allowed(normalized_path) when the path passes all checks,
Denied(reason) when it is blocked, and Mismatch(msg) when the
path appears in both the allowlist and blocklist simultaneously.