P234 · Safety & trust

Resolve confinement and ownership before destruction

A well-formed derived path is a candidate target, not permission to delete it.

Editorially reviewed

These examples and illustrative results are independently authored teaching materials, not measured model results.

Use case

Cleanup receives a process-supplied job path under jobs/ for teaching identity J7. Other processes can write arguments; an apparent child may be a symlink or another job.

Mechanism

Canonicalize candidate and allowed roots, requiring a strict descendant/minimum depth, never root. Compare authenticated expected identity with protected ownership evidence, not writable .owner. Address check/use replacement using immutable controlled hierarchy or suitable safe handles. Reject without broader fallback; destructive action follows real authorization.

Bad example

Delete jobs/J7 because the OS supplied it; if absent delete jobs, trusting a self-written owner marker.

Good example

Treat the path as a candidate, resolve links and check scope/protected J7 ownership before race-safe operations. Stop on missing/mismatched/changed evidence without parent fallback. Verify in isolated fixtures, not by deleting real targets.

Why the change matters

Confinement answers where; ownership/authority answer whether. Resolution and race handling prevent benign names pointing outside scope or at someone else’s data.

Observable expectation

Teaching roots, external links, wrong owners and post-check substitution reject. A valid current-job child satisfies candidate conditions. Legitimate ..cache must not be rejected by a naive prefix check. Verify mechanisms, not names alone.

Limits

Handle/link behavior varies by platform and static checks cannot ensure race safety. Markers/digests are not authorization; disclose missing protection. No target was deleted/moved here.

Sources and evidence

Read the editorial criteria