In plugins/fs/src/lib.rs OpenOptions, custom_flags was deserializable
from the `open` command arguments even though it is not in the TS types,
so a webview with a read-only permission set could pass arbitrary open(2)
flags such as O_TRUNC.
The field is now #[serde(skip)]; Rust callers still set it through
OpenOptionsExt. Rejecting write/truncate/create options of `open` under
read-only sets changes permission semantics and is deferred to v3.