ServeFile's built-in ".." rejection only covers r.URL.Path, not a path handed to it explicitly from a query param — validate p resolves to a real, regular file before serving.