pub fn safe_existing_path_under_root( root: &Path, stored_relative: &str, ) -> Result<PathBuf, String>
Resolve an existing DB-stored path and prove it still lives under the trusted root after following symlinks.