From 250db41743f77ce3d8421f729bdea0065aa6bc79 Mon Sep 17 00:00:00 2001 From: Gabriel Schneider Date: Thu, 1 Oct 2026 05:01:31 -0300 Subject: A name under a directory that may not be searched or written is refused, permission denied, and a Save there says so, not no such directory `pardes noperm/a/b/c` and `pardes /proc/1/root/x` took the missing directory for one Save would make, opened a pane and exited 0; its Save then said "no such directory". fs.deniedAbove finds the nearest directory there and asks whether it may be searched and written: forwarding refuses such a name, exit 1, "permission denied", and a failed Save says "permission denied", which the writer's 9P error carries as EPERM (9ns: EACCES). Co-Authored-By: Claude Opus 5.5 --- src/main.zig | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) (limited to 'src/main.zig') diff --git a/src/main.zig b/src/main.zig index a7d354b5..86558bae 100644 --- a/src/main.zig +++ b/src/main.zig @@ -256,7 +256,7 @@ fn forwardWords(err: anyerror, buf: []u8) []const u8 { error.NotOneLine => "a file name is one line, and this one holds a newline", error.NotAFileName => "names a directory, not a file", error.NoWorkingDirectory => "this shell's working directory is gone", - error.DirectoryNotWritable => "its directory may not be read or written, so it could never be saved", + error.DirectoryNotWritable => "permission denied: its directory may not be read or written, so it could never be saved", error.NotAPaneAddress => "not a pane address: @p and a pane's number", error.NoSuchPane => "this session has no such pane", else => if (pardes.Messages.dialReason(err)) |why| why else words: { @@ -653,7 +653,11 @@ fn nativeMain(init: std.process.Init) !void { var cwd_buf: [4096]u8 = undefined; if (std.c.getcwd(&cwd_buf, cwd_buf.len) == null) Refuse.with(init.io, word, error.NoWorkingDirectory); const cwd = std.mem.sliceTo(&cwd_buf, 0); - break :named std.fs.path.resolvePosix(arena, &.{ cwd, target.path }) catch |err| Refuse.with(init.io, word, err); + const absolute = std.fs.path.resolvePosix(arena, &.{ cwd, target.path }) catch |err| Refuse.with(init.io, word, err); + // Missing because one above may not be searched or written: + // its Save could never make it, so refused now. + if (pardes.filesystem.deniedAbove(std.fs.path.dirname(absolute) orelse "/")) Refuse.with(init.io, word, error.DirectoryNotWritable); + break :named absolute; }; // A directory that is there but may not be read or written: a // pane for the name could only fail at its Save, so refused now. -- cgit v1.3