Skip to main content

Module io

Module io 

Source
Expand description

Bounded reading and atomic writing.

This module holds the two file operations that can hurt a user independently of any parser bug: reading an input large enough to exhaust memory, and writing an output in a way that can leave a half-sanitised file where the original was.

§Where temporary files go, and why it matters

The temporary file is created in the destination’s own directory, never in TMPDIR. Two reasons, and the second is the important one:

  1. rename is only atomic within a filesystem. A temp file on a different mount turns the final step into a copy, which is precisely the non-atomic behaviour being avoided.
  2. TMPDIR is somewhere else on the disk. Writing a copy of a sensitive document to somewhere the user did not choose — and did not know to clean up — is a leak in its own right, and on an amnesic system such as Tails it may be the one location that is not what the user assumed it was (docs/ARCHITECTURE.md §8).

The temporary file is removed on every failure path.

Structs§

AtomicWrite
A file being written through a temporary alongside its destination, replaced by an atomic rename only once the content is complete and durable.
Limits
Resource ceilings applied before and during parsing.

Enums§

Overwrite
What to do when the destination already exists.
Permissions
Whether output permissions are tightened.

Functions§

read_bounded
Read path into memory, refusing anything above limits.max_input_bytes.