pub fn grant_permits_write(grant: &CapabilityGrant, file: &Path) -> boolExpand description
grant_permits_read, restricted to the plugin’s writable prefixes.
Same ordering, for the same security reason: the file itself is canonicalized when it exists, so a symlink under a writable prefix that points outside it is refused.