Skip to main content

safe_join

Function safe_join 

Source
pub fn safe_join(root: &Path, rel: &str) -> Result<PathBuf>
Expand description

Resolve a manifest path against root, refusing anything that would land outside it.

Rejected: absolute paths, any .. component, Windows prefixes such as C: or \\?\, and root components. Backslashes are treated as separators so a ..\.. payload cannot slip past on a platform that honours them. The check is on components, not on the resolved string, so it holds without touching the filesystem and cannot be defeated by a race.