Expand description
Bounded reading and atomic writing.
This module holds the two file operations that can hurt a user independently of any parser bug: reading an input large enough to exhaust memory, and writing an output in a way that can leave a half-sanitised file where the original was.
§Where temporary files go, and why it matters
The temporary file is created in the destination’s own directory, never in TMPDIR.
Two reasons, and the second is the important one:
renameis only atomic within a filesystem. A temp file on a different mount turns the final step into a copy, which is precisely the non-atomic behaviour being avoided.TMPDIRis somewhere else on the disk. Writing a copy of a sensitive document to somewhere the user did not choose — and did not know to clean up — is a leak in its own right, and on an amnesic system such as Tails it may be the one location that is not what the user assumed it was (docs/ARCHITECTURE.md§8).
The temporary file is removed on every failure path.
Structs§
- Atomic
Write - A file being written through a temporary alongside its destination, replaced by an atomic rename only once the content is complete and durable.
- Limits
- Resource ceilings applied before and during parsing.
Enums§
- Overwrite
- What to do when the destination already exists.
- Permissions
- Whether output permissions are tightened.
Functions§
- read_
bounded - Read
pathinto memory, refusing anything abovelimits.max_input_bytes.