1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
//! Where a command may write a directory, and where it may not.
//!
//! One rule, shared: an output directory must not be inside the repository.
//! A stray entry in a segment store is a surprise the next administrator has
//! to investigate, and the open path would have to decide whether it is
//! damage.
//!
//! It lives here rather than in `froe-export`, where it was written, because
//! `froe index dump` needs the same rule and `froe-export` depends on
//! `froe` — a call the other way is a cycle cargo refuses.
//!
//! The file-case rule in `froe_export::output_file::create_export_output`
//! deliberately stays where it is. It canonicalizes the *parent* only and
//! names a file rather than a directory, and each form has its own landed
//! test; the duplication is recorded at both sites rather than resolved by
//! forcing one shape onto both.
use Path;
use crate;
/// Refuses `directory` when it resolves inside `repository_path`.
///
/// Creates nothing: the caller decides whether the directory should exist
/// and makes it. An already existing directory outside the repository is
/// fine — `froe export` and its refresh both depend on that.
///
/// The directory may not exist yet, and only existing paths canonicalize, so
/// the check runs against the nearest existing ancestor. That is what stops
/// a symlink on the way in from smuggling the target into the repository.