Skip to main content

normalize_unveil_path

Function normalize_unveil_path 

Source
fn normalize_unveil_path(path: &str) -> Result<String, SyscallError>
Expand description

Normalise an unveil path: collapse duplicate slashes, reject dot segments.

. and .. are rejected outright rather than resolved: rule matching is lexical prefix matching, so a query like /etc/../secret would match an /etc rule while the backing filesystem resolves a different path - a policy bypass waiting for a resolver that handles dot segments.