Skip to main content

Module clean

Module clean 

Source
Expand description

rk stage clean: remove one stage that names itself, and nothing else.

The argument is resolved without following a final symlink, judged against the protected set, and then the parent directory and the stage directory are opened and held. Every removal goes through those descriptors, addressed as /proc/self/fd/<fd>/<name>, which resolves against the directory the descriptor holds and not against the path that was validated: a path swapped for a link after validation redirects no deletion. The crate forbids unsafe, so the descriptor walk uses the kernel’s own link to an open directory instead of openat and unlinkat through FFI.

Structs§

Validated
A stage validated and held open for removal.

Constants§

PAUSE_AFTER_QUARANTINE_VAR
The proof’s third seam: the name of one entry whose removal waits.
PAUSE_BEFORE_OPEN_VAR
The proof’s second seam: the name of one child directory whose open waits, after its check, for proceed-checked under the pause directory, having written checked there.
PAUSE_VAR
The proof’s seam: a directory where the run writes validated after it has opened the stage, then waits for proceed before it removes anything, so a test can swap the path in between.

Functions§

remove
Remove the validated stage through its held descriptors.
validate
Resolve argument without following a final symlink, refuse every protected or ambiguous path, and hold the stage and its parent open.