Cri::PathSecurity
Canonicalizes filesystem paths before authorization and I/O. Lexical prefix checks are insufficient because a path inside a trusted directory can be a symlink to an object outside it.
Class methods
Permission checks may run before a file is created. Preserve the normalized lexical path for a missing target, but canonicalize every existing target so an existing symlink cannot pass by spelling alone.
Resolves a path that may not exist yet by canonicalizing its nearest existing parent. If the final component already exists, realpath follows it so callers can still enforce the final target's boundary.