Replace the `realpath -m` confinement check with a POSIX sh script that
uses `readlink -f`, which BusyBox (Alpine) also provides. The script
walks up to the deepest existing path, resolves it, and appends the
missing rest. It fails closed on dangling symlinks and on `.`/`..` in
the missing part.
Send the script as a single `sh -c '<script>' sh <base> <path>` line so
the non-root sudo parser only adds sudo in front of it and does not
rewrite `$(...)`, `&&` or case statements.
Add unit tests that run the command with GNU and BusyBox tools, as root
and through the sudo parser, against a real symlink tree. Update the
feature test fakes to match the new command.