Add a helper that opens a path relative to a directory fd while refusing
any resolution that escapes that directory. Each component is opened with
O_NOFOLLOW so symlinks are detected explicitly rather than transparently
followed; symlinks are then resolved manually and only honoured when their
(recursively resolved) target also stays beneath the base fd. Absolute
symlink targets, leading '/', and '..' past the base are rejected with
errno=ELOOP. Symlink chains are bounded by
PATH_UTIL_OPENAT_SAFE_MAX_SYMLINKS hops.
Anchoring resolution at a caller-held base_fd makes the lookup TOCTOU-safe
even when intermediate path components are mutated on disk concurrently:
the kernel resolves all openat() lookups relative to the original
directory inode that base_fd refers to, so an attacker mutating path
components on the filesystem cannot redirect resolution.
This is the portable counterpart to Linux's openat2() with RESOLVE_BENEATH
and is intended for callers that need to safely look up files under a
user-writable directory (e.g. a Sieve script storage directory).
Gbp-Pq: Name 0002-lib-path-util-Add-t_openat_safe-for-jailed-openat-re.patch