pub fn validate_tld(tld: &str) -> Result<()>Expand description
Reject a TLD that must not reach a privileged file path or a config file.
proxy.tld is an arbitrary user string that ends up joined onto
/etc/resolver for a sudo write and delete, and interpolated into a
systemd-resolved drop-in. A traversal component would aim those at a
root-owned file elsewhere; a newline would inject directives into the
drop-in. Only a real DNS suffix is allowed through.