pub struct TrustedDir(/* private fields */);Expand description
A directory opened by FOLLOWING symlinks normally — the command-line-named path’s trusted parent prefix.
The trusted-boundary model (docs/tocttou.md, “Trusted boundary”) trusts the path named on the
command line up to and including its container directory; only entries
strictly BELOW the named root are hardened with O_NOFOLLOW. A TrustedDir
is that trusted container, and it is the ONLY way in this crate to obtain a
directory fd that was opened following symlinks — its sole constructor is
Dir::open_parent_dir. Every other directory open (Dir::open_dir,
Dir::child, Dir::open_file_read, Dir::create_file,
Dir::make_dir, …) is O_NOFOLLOW.
Because the trusted/hardened distinction is a type rather than a convention,
the compiler enforces it: a parent-prefix slot typed TrustedDir can only be
filled by the follow-open, and a hardened Dir cannot be used where a trusted
parent is required. Crossing from the trusted prefix into the hardened tree is
the single explicit Self::into_tree step.
Under strict operand resolution (--require-toctou-safe) the “trusted”
prefix is additionally required to be symlink-free: the open resolves it
RESOLVE_NO_SYMLINKS, so a symlink component fails closed with ELOOP
rather than being followed (see enable_strict_operand_resolution).
Implementations§
Source§impl TrustedDir
impl TrustedDir
Sourcepub fn into_tree(self) -> Dir
pub fn into_tree(self) -> Dir
Cross from the trusted parent prefix into the hardened tree, consuming the TrustedDir and
handing back the owned hardened Dir (e.g. to wrap it in an Arc for the walk). Every open
below the returned Dir is O_NOFOLLOW, so nothing below the named root can be redirected
by a symlink swap. This is the one explicit trusted→hardened transition.
Trait Implementations§
Auto Trait Implementations§
impl Freeze for TrustedDir
impl RefUnwindSafe for TrustedDir
impl Send for TrustedDir
impl Sync for TrustedDir
impl Unpin for TrustedDir
impl UnsafeUnpin for TrustedDir
impl UnwindSafe for TrustedDir
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
Source§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoRequest<T> for T
impl<T> IntoRequest<T> for T
Source§fn into_request(self) -> Request<T>
fn into_request(self) -> Request<T>
T in a tonic::Request