pub fn confine_to_dir(base: &Path, rel: &str) -> Result<PathBuf, String>Expand description
Resolve an operator-supplied relative path INSIDE base, refusing
anything that could name a location elsewhere: an absolute path, a
.. component, an empty path, or a Windows drive/prefix. Output
paths that a workload file can set (metrics-log, trace_log)
route through here, so a shared workload can only ever write into
the session’s own directory tree.