Skip to main content

validate_tld

Function validate_tld 

Source
pub fn validate_tld(tld: &str) -> Result<()>
Expand description

Reject a TLD that must not reach a privileged file path or a config file.

proxy.tld is an arbitrary user string that ends up joined onto /etc/resolver for a sudo write and delete, and interpolated into a systemd-resolved drop-in. A traversal component would aim those at a root-owned file elsewhere; a newline would inject directives into the drop-in. Only a real DNS suffix is allowed through.