Skip to main content

nofollow

Function nofollow 

Source
pub fn nofollow(opts: &mut OpenOptions) -> &mut OpenOptions
Expand description

Apply O_NOFOLLOW to opts on Unix, so opening an existing symlink at the path’s final component fails atomically (ELOOP) instead of following it.

This closes the file-level half of the reject_symlink check-then-open TOCTOU window: even if an attacker swaps the leaf for a symlink in the gap between the symlink_metadata check and this open, the kernel refuses to traverse it at open time. The complementary directory-level half — a swapped intermediate component — is still covered only by the per-level symlink_metadata checks (O_NOFOLLOW does not constrain intermediate components; that needs Linux-only openat2(RESOLVE_BENEATH|RESOLVE_NO_SYMLINKS), deliberately deferred). Together the two guards cover the practical attack surface under the MVP per-user-0700 trust model.

Returns opts for call-chaining. No-op on non-Unix, where the symlink_metadata check is the only guard (Windows reparse points are out of scope — taskfleet targets darwin/linux).