pub fn nofollow(opts: &mut OpenOptions) -> &mut OpenOptionsExpand description
Apply O_NOFOLLOW to opts on Unix, so opening an existing symlink at the
path’s final component fails atomically (ELOOP) instead of following it.
This closes the file-level half of the reject_symlink check-then-open
TOCTOU window: even if an attacker swaps the leaf for a symlink in the gap
between the symlink_metadata check and this open, the kernel refuses to
traverse it at open time. The complementary directory-level half — a
swapped intermediate component — is still covered only by the per-level
symlink_metadata checks (O_NOFOLLOW does not constrain intermediate
components; that needs Linux-only openat2(RESOLVE_BENEATH|RESOLVE_NO_SYMLINKS),
deliberately deferred). Together the two guards cover the practical attack
surface under the MVP per-user-0700 trust model.
Returns opts for call-chaining. No-op on non-Unix, where the
symlink_metadata check is the only guard (Windows reparse points are out
of scope — taskfleet targets darwin/linux).