Skip to main content

resolve_executable

Function resolve_executable 

Source
pub fn resolve_executable(
    requested: &Path,
    current_dir: &Path,
    search_directories: &[PathBuf],
) -> Result<PathBuf, ResolutionError>
Expand description

Resolve one executable candidate without reading ambient PATH or running it.

Requests containing / are literal paths, including ./tool; absolute paths are used directly and relative paths are rooted at current_dir. Other names search only search_directories, in order. Relative search directories and explicitly supplied empty entries are rooted at current_dir; an empty list searches nothing. The working directory must be absolute, even if unused. No HOME/default installation directory, shell expansion or fallback is added.

Selection requires a regular file with at least one Unix execute permission bit. Search skips missing candidates (including dangling symlinks), directories and nonexecutable files, and stops on other filesystem errors. Once an eligible candidate is observed, canonicalization errors stop selection, including if that candidate disappears. All search directories are checked for NUL before a name search; literal requests ignore the unused search list. Symlinks are followed and the result is canonical and absolute. Permission bits do not prove effective user access or interpreter validity. Caller-owned trusted path trees and exclusion of concurrent writers remain necessary; this path is not a frozen file capability.

A selected path must still undergo super::AdmittedTool::admit with the consumer’s digest, byte bound and exact version authority before execution. No candidate is retried or replaced after that admission fails.

§Errors

Returns typed invalid-input, missing/nonexecutable or filesystem failures.