| Commit message (Collapse) | Author | Age | Files | Lines |
| |
|
|
|
|
|
|
|
|
|
|
| |
The scopes that drive "no rule deletes a file krino found to be a
duplicate" were collected from rules only. A directory whose duplicate
tests lived in (exclude ...) forms had no scopes at all, so the
protection never engaged: krino explain said "yes duplicate" and the
next rule permanently deleted every copy. The README's promise was
false in that shape, and the spec's wording permitted it.
What matters is what krino knows, not which form taught it. The spec
and krino.conf(5) now say so too.
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
(on-conflict overwrite) trashes the file in the way; §7.4 promises undo
restores it. Walking a file's log entries stopped dead at a permanent
delete, so the displace written earlier in the same chain was never
reached: the user's file stayed in the Trash, the refusal named only
the file they did not care about, and krino log called the run undone.
The displaced file is a different file, so it is offered as its own
entry in the undo plan, keyed by its own path - the deleted file stays
refused, since nothing of it can come back, and the copy or move that
preceded the delete stays unreversed too (undoing a copy whose original
was then deleted would destroy the last remaining copy).
The accounting matched: every reversible step of a deleted file was
subtracted, its displace included, so the run read (undone). Only what
genuinely cannot come back is subtracted now.
End to end, the scenario from the review: the only copy of a file is
displaced by an incoming one that is then permanently deleted.
before: archive/ empty, "(undone)", nothing offered
after: archive/a.pdf restored, run reads partly undone
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
The displace was carried out first and logged only when the whole step
finished - for a copy or a cross-device move, the entire data transfer
later. A process killed in that window left the user's file in the
Trash with nothing recording it: krino log said "nothing applied" and
undo offered nothing.
It is its own action with its own line (spec §9), so it is now written
the moment trash.Put returns, through a hook ChainLogged calls before
the step that needed the name begins. A displace that cannot be logged
fails the step rather than compounding an unrecorded destructive act
with a second one.
Verified by killing krino -9 mid-copy with 600 MB in flight:
before: krino log "nothing applied", 0 displace lines
after: krino log "1 displaced", 1 displace line
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
Every file renamed onto one name probed stem_1, stem_2, ... from the
beginning, so N files cost N^2/2 Exists calls - a test here counts 1890
of them for 60 files. The search now continues from the highest suffix
already tried for that stem.
Within one plan that is the same answer: the taken set only grows while
a plan is built and the disk is not being written to, so a suffix taken
once stays taken. Proved rather than argued - with same_1 and same_3
already on disk and same_2 free, both versions put a file in the gap,
and the two plans are byte-identical.
1500 files renamed to one name: 2.63s -> 0.05s
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
Lookup walked the whole size group for every file in it, so N copies of
one file cost N walks of an N-member group, each taking the index's
lock at every step - which is why more workers made it slower rather
than faster. Every member of a class elects the same original (the
invariant identicalTo already documents and a test already pins), so
the class is memoised on the first walk and every later member is a
map lookup.
Measured over identical files, invented data, same machine:
500 files 0.17s -> 0.12s
2000 files 1.89s -> 0.58s
and the plans are byte-identical once the sandbox path is normalised.
The test counts walks: one per content class, not one per file.
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
flock(2) on the lock file's descriptor replaces "write my pid, and
decide whether the pid in the file is still alive". The kernel drops
the lock when the process ends, however it ends, so there is no stale
krino lock to detect and no takeover to race over.
What that fixes:
- Two runs that both judged a lock stale could remove and recreate it
and both believe they held it. Remove-then-create cannot be made
atomic; there is nothing to make atomic now. Pinned by a test with
eight callers over twenty rounds.
- A pid reused after a crash made the lock live for ever, and the
message named neither the file nor the pid, so there was nothing to
act on. The message now names both.
- Signal(0) reads EPERM as "not running", so a lock held by another
user was taken over. There is no such judgement left to get wrong.
A run that waits for a held lock now says so first. Waiting is what
the spec asks for, but the wait has no timeout, and in silence it is
indistinguishable from a hang - I spent two minutes on one myself
today, waiting on a lock the window was holding.
Tests that faked a held lock by writing a file now hold a real one.
|
| |
|
|
|
|
|
|
|
|
|
| |
So that go install can find it. cgit serves no go-import meta tag, so
nginx answers a ?go-get=1 request for /NAME with one pointing at
https://git.labunix.xyz/NAME.git; the alternative was carrying a .git
suffix through every import line forever.
One sed over the imports, both go.mod files, and the dependency gate's
whitelist. Nothing else depends on the path. go install works from the
next tag, the first release whose go.mod carries it.
|
| |
|
|
|
|
| |
https://git.labunix.xyz/krino.git, on cgit and clonable without an
account. About shows it and the README's status says how to clone;
go install still needs a module path that is a URL.
|
| |
|
|
|
| |
The same address the commits are authored from, rather than a second
one to keep working.
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
About 340 comments cited the development process: task and plan
numbers, fix waves, rulings, reviewers, and the author in the third
person with a date. None of that exists outside the work itself, so to
a reader it pointed at nothing. Each one now states the engineering
reason it was standing in front of; where a comment was provenance and
nothing else, it is gone.
References to docs/design.md and docs/gui-design.md by section stay:
both ship with the repository. The design documents lose their
amendment diaries - CHANGELOG.md is that record - and the GUI's says
plainly that the window has gone further than the document.
Only comments changed. Every .go file was parsed and its code printed
with comments stripped, before and after: the two hashes are identical
across all 175 files.
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
| |
It opened with a paragraph of version history and spent 148 of its 273
lines on a walkthrough. What sells the program is a rules file and the
plan it produces, so those come first, with a screenshot of the window
above them.
Every command and every pasted line was run again in a scratch config:
the plan, the apply, the log line and the undo are this morning's real
output, and the example rules file passes krino check as written (with
the paths pointed at a sandbox).
docs/krino-gui.png is from invented files under /tmp/krino-demo.
|
| |
|
|
|
|
|
|
|
|
|
| |
Squeezed, the toolbar's path label read "/t... ds". It now elides the
start, since the end of a path is the part that says which directory
this is, and will not shrink below about sixteen characters; the
tooltip still holds it in full.
The checklist gains the reordered bar, the About block, and the
sandbox trap that had every file skipped: krino's own (min-age 2m)
ignores a file written in the last two minutes.
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
| |
The Plan bar now reads left to right as the work does: which
directory, how it should be listed, what of it, where it is on disk -
then Scan, and only then what to do with what came back. Scan carries
the theme's accent, being the button that starts everything.
Settings ends with About: the program and the version it was built
as, what it is in a sentence, the licence, and who to write to. The
text is model.About so it is tested; ui.Version is stamped by main.
leak-check knows krino's own contact address, so the address check
stays useful without a per-clone setting.
|
| |
|
|
|
|
|
|
|
|
|
| |
Selecting the exclude row in Forms panicked: newFormEditor read the
form's rule for its when, name, action and stop, and an exclude has
only the when. The editor now takes the conditions from whichever of
the two the form holds and leaves out the fields an exclude has not
got. Checklist item 49 covers it.
Also the 0.0.11 changelog and README, and header floors wide enough
that the age heading is not clipped.
|
| | |
|
| | |
|
| | |
|
| |
|
|
| |
explanation
|
| | |
|
| | |
|
| |
|
|
| |
setting
|
| | |
|
| | |
|
| | |
|
| | |
|
| | |
|
| |
|
|
| |
list labels after an edit
|
| | |
|
| | |
|
| | |
|
| | |
|
| | |
|
| | |
|
| | |
|
| | |
|
| | |
|
| |
|
|
| |
one file are
|
| |
|
|
| |
own, overrides keyed by clean path, splice and enum guards
|
| | |
|
| | |
|
| | |
|
| | |
|
| | |
|
| | |
|
| |
|
|
| |
subdirectories
|
| | |
|
| | |
|
| | |
|
| | |
|
| | |
|