-
-
Notifications
You must be signed in to change notification settings - Fork 17k
Tracking Issue for directory handles #120426
Copy link
Copy link
Open
Labels
A-ioArea: `std::io`, `std::fs`, `std::net` and `std::path`Area: `std::io`, `std::fs`, `std::net` and `std::path`C-tracking-issueCategory: An issue tracking the progress of sth. like the implementation of an RFCCategory: An issue tracking the progress of sth. like the implementation of an RFCO-fuchsiaOperating system: FuchsiaOperating system: FuchsiaT-libsRelevant to the library team, which will review and decide on the PR/issue.Relevant to the library team, which will review and decide on the PR/issue.
Description
Activity
Metadata
Metadata
Assignees
Labels
A-ioArea: `std::io`, `std::fs`, `std::net` and `std::path`Area: `std::io`, `std::fs`, `std::net` and `std::path`C-tracking-issueCategory: An issue tracking the progress of sth. like the implementation of an RFCCategory: An issue tracking the progress of sth. like the implementation of an RFCO-fuchsiaOperating system: FuchsiaOperating system: FuchsiaT-libsRelevant to the library team, which will review and decide on the PR/issue.Relevant to the library team, which will review and decide on the PR/issue.
View all comments
Feature gate:
#![feature(dirfd)]This is a tracking issue for directory handles. Such handles provide a stable reference to an underlying filesystem object (typically directories) that are less vulnerable to TOCTOU attacks and similar races. These security properties will be platform-dependent. Platforms that don't provide the necessary primitives will fall back to operations on absolute paths.
Additionally they may also provide performance benefits by avoiding repeated path lookups when performing many operations on a directory.
Sandboxing is a non-goal. If a platform supports upwards path traversal via
..or symlinks then directory handles will not prevent that. ProvidingO_BENEATH-style traversal is left to 3rd-party crates or future extensions.Public API
Steps / History
getdentsto get free conversion between dirfds andReadDir*atcallsUnresolved Questions
AdRawFdcan only be implemented on platforms that use actual directory handles, not allfdplatforms. Is this fine?Diroperations that take paths accept absolute paths (whereselfis effectively irrelevant)?Dirmethod for getting the metadata of the directory itself be called (if we have such an operation at all)?Dir::metadataalready corresponds tofs::metadata. For now, it is calledself_metadata.Dir::open_file_with(and likely moreDirmethods) on Windows does not support/#163032Footnotes
https://std-dev-guide.rust-lang.org/feature-lifecycle/stabilization.html ↩