is_path_owned_by_current_uid(const char *path) isn't symlink safe given a multi-component path.
Symlinks, the poisonous gift that keeps on giving.
Symlinks, the poisonous gift that keeps on giving.
That's why symlinks MUST die.
You can sort of think of a symlink as having 2 owners: the user that owns the symlink itself, and the user who owns the file pointed to by the symlink. One of those owners might be an attacker, so every time you interact with a file, you have to think "this file might be half-owned by an attacker, and half-owned by a victim".
And by "incredibly" I mean beyond the scope of human endeavour :-).
It's not just a whine, I'm also going to make some suggestions for fixing it :-).