pub fn read_bounded(path: &Path, limits: Limits) -> Result<Vec<u8>>Expand description
Read path into memory, refusing anything above limits.max_input_bytes.
The size is checked twice: once against the directory entry, so an oversized file is refused without reading a byte of it, and again while reading, because the first answer came from metadata that a hostile or merely unusual source can misreport — a growing file, a named pipe, a synthetic filesystem. Trusting the first check alone would make the limit advisory.
§Errors
StryptError::InputTooLarge if the file exceeds the limit; StryptError::Io if it
cannot be measured or read.