docs(shared): clarify authorized_root accessor contracts

Document on utils_get_authorized_root_path() that the returned pointer is
borrowed and invalidated by the next authorized-root setter, that the fd
and path are not read atomically (non-reentrant), and that the fd remains
caller-owned.  Add a matching single-threaded/set-before-threads note at
the accessor definitions in utils.c.

In server.c, drop the redundant utils_set_authorized_root(-1, NULL) after
a failed utils_set_authorized_root(): the setter already fail-closes the
state on allocation failure.  The following close(root_fd) is unchanged.
This commit is contained in:
2026-09-13 10:38:21 +02:00
parent 3260a39ab4
commit c78a21de57
3 changed files with 13 additions and 2 deletions
+1 -1
View File
@@ -231,7 +231,7 @@ static bool configure_authorization(const char* root) {
return false;
}
if (!utils_set_authorized_root(root_fd, resolved)) {
utils_set_authorized_root(-1, NULL);
/* The setter already cleared the fd/path state on allocation failure. */
close(root_fd);
return false;
}