pub fn is_safe_plugin_name(name: &str) -> boolExpand description
Is name a single safe path component?
A required plugin’s name becomes a directory under the cache root and the
user’s plugin root, so an unchecked name is a path-traversal write with the
editor’s full authority — ../../.ssh is a plausible entry in a config
file someone copy-pasted. Same gate the untrusted manifest.id already
gets before it keys the writable data mount; this is the second untrusted
string to reach a path, so it gets the same treatment rather than a
bespoke one.