fn tighten(path: &Path) -> Result<()>Expand description
Clear group’s and other’s bits, keeping the owner’s and the setuid, setgid
and sticky bits, and only when group or other has one, so a file that is
already private costs a stat and nothing more.