Expand description
rk stage clean: remove one stage that names itself, and nothing else.
The argument is resolved without following a final symlink, judged
against the protected set, and then the parent directory and the
stage directory are opened and held. Every removal goes through those
descriptors, addressed as /proc/self/fd/<fd>/<name>, which resolves
against the directory the descriptor holds and not against the path
that was validated: a path swapped for a link after validation
redirects no deletion. The crate forbids unsafe, so the descriptor
walk uses the kernel’s own link to an open directory instead of
openat and unlinkat through FFI.
Structs§
- Validated
- A stage validated and held open for removal.
Constants§
- PAUSE_
AFTER_ QUARANTINE_ VAR - The proof’s third seam: the name of one entry whose removal waits.
- PAUSE_
BEFORE_ OPEN_ VAR - The proof’s second seam: the name of one child directory whose open
waits, after its check, for
proceed-checkedunder the pause directory, having writtencheckedthere. - PAUSE_
VAR - The proof’s seam: a directory where the run writes
validatedafter it has opened the stage, then waits forproceedbefore it removes anything, so a test can swap the path in between.