feat: define P2 host workspace command contract
This commit is contained in:
@@ -4,9 +4,11 @@ package safeio
|
||||
import (
|
||||
"errors"
|
||||
"io"
|
||||
"io/fs"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"strings"
|
||||
"unicode/utf8"
|
||||
)
|
||||
|
||||
var ErrUnsafeFile = errors.New("unsafe file")
|
||||
@@ -33,3 +35,21 @@ func readBoundedRegularFile(file *os.File, maximum int64) ([]byte, error) {
|
||||
}
|
||||
return contents, nil
|
||||
}
|
||||
|
||||
// ReadCanonicalUTF8 reads a canonical regular file with a strict byte bound and UTF-8 validation.
|
||||
func ReadCanonicalUTF8(path string, maximum int64) ([]byte, error) {
|
||||
contents, err := ReadCanonicalRegular(path, maximum)
|
||||
if err != nil || !utf8.Valid(contents) {
|
||||
return nil, ErrUnsafeFile
|
||||
}
|
||||
return contents, nil
|
||||
}
|
||||
|
||||
// WriteCanonicalExclusive creates a canonical regular file without following links or replacing
|
||||
// an existing leaf. The file is private to the caller and is never opened in truncate mode.
|
||||
func WriteCanonicalExclusive(path string, contents []byte, mode fs.FileMode) error {
|
||||
return writeCanonicalExclusive(path, contents, mode)
|
||||
}
|
||||
|
||||
// ValidateCanonicalOutputPath verifies every parent directory without creating the leaf.
|
||||
func ValidateCanonicalOutputPath(path string) error { return validateCanonicalOutputPath(path) }
|
||||
|
||||
Reference in New Issue
Block a user