aboutsummaryrefslogtreecommitdiff
path: root/docs/design.md
Commit message (Collapse)AuthorAgeFilesLines
* a symlink in the sorted directory no longer redirects a stepLukasz Kasprzak2 days1-1/+7
| | | | | | | | | | | | | | | | | | | | | | | | | | Placeholders were already stopped from sending a file out of the directory a rule named. A symlink is a name too, and the directory krino sorts is by the threat model's own premise a place the internet writes into: a link named after a rule's destination sent moves and copies anywhere, and under (on-conflict overwrite) trashed a file OUTSIDE the sorted directory - while the plan showed the in-tree text and the run reported success. A step whose destination passes through a symlink at or below the directory being sorted now fails. A destination the configuration names outside it - ~/docs on another disk - is the user's own arrangement and is followed as before; both cases have a test. End to end, the review's scenario (Out -> ~/secret, overwrite): before: 1 applied, the user's file replaced and trashed after: 0 applied 1 failed, the file untouched, nothing trashed Two bookkeeping bugs in MkdirAllTracked went with it: a dangling symlink read as a missing directory and was then recorded as one krino had created - undo would have unlinked a link krino never made - and a directory created by someone else between the check and the mkdir was recorded the same way.
* a duplicate test in an exclude protects like one in a ruleLukasz Kasprzak2 days1-4/+6
| | | | | | | | | | | | The scopes that drive "no rule deletes a file krino found to be a duplicate" were collected from rules only. A directory whose duplicate tests lived in (exclude ...) forms had no scopes at all, so the protection never engaged: krino explain said "yes duplicate" and the next rule permanently deleted every copy. The README's promise was false in that shape, and the spec's wording permitted it. What matters is what krino knows, not which form taught it. The spec and krino.conf(5) now say so too.
* the module path is git.labunix.xyz/krinoLukasz Kasprzak2 days1-4/+5
| | | | | | | | | | | So that go install can find it. cgit serves no go-import meta tag, so nginx answers a ?go-get=1 request for /NAME with one pointing at https://git.labunix.xyz/NAME.git; the alternative was carrying a .git suffix through every import line forever. One sed over the imports, both go.mod files, and the dependency gate's whitelist. Nothing else depends on the path. go install works from the next tag, the first release whose go.mod carries it.
* comments that explain the code, not how it was writtenLukasz Kasprzak2 days1-18/+7
| | | | | | | | | | | | | | | | | | About 340 comments cited the development process: task and plan numbers, fix waves, rulings, reviewers, and the author in the third person with a date. None of that exists outside the work itself, so to a reader it pointed at nothing. Each one now states the engineering reason it was standing in front of; where a comment was provenance and nothing else, it is gone. References to docs/design.md and docs/gui-design.md by section stay: both ship with the repository. The design documents lose their amendment diaries - CHANGELOG.md is that record - and the GUI's says plainly that the window has gone further than the document. Only comments changed. Every .go file was parsed and its code printed with comments stripped, before and after: the two hashes are identical across all 175 files.
* release notes and version mentions for 0.0.9v0.0.9Lukasz Kasprzak4 days1-1/+2
|
* krino.conf(5): WRITING RULES guide; reference corrected against the codeLukasz Kasprzak4 days1-3/+9
|
* docs: make ci passes on OpenBSD and FreeBSD; OpenBSD's go needs GOTOOLCHAIN=autoLukasz Kasprzak5 days1-1/+4
|
* release notes and version mentions for 0.0.8v0.0.8Lukasz Kasprzak5 days1-1/+5
|
* only where an earlier directory's files ended up stays claimedLukasz Kasprzak5 days1-2/+2
|
* a permanently deleted file's steps do not keep a run partly undoneLukasz Kasprzak5 days1-1/+2
|
* (matched) is unknown after an undecided rule, so a catch-all leaves an ↵Lukasz Kasprzak5 days1-1/+3
| | | | unreadable file alone
* an earlier directory's applied results stay claimed for later onesLukasz Kasprzak5 days1-1/+3
|
* tests read real documents from LibreOffice and pandoc; antiword's ↵Lukasz Kasprzak5 days1-3/+8
| | | | short-document limit documented
* krino log marks a run partly undone while reversible steps remainLukasz Kasprzak5 days1-2/+4
|
* build: VERSION checked for build and install, cross names without v, ↵Lukasz Kasprzak5 days1-4/+8
| | | | dependency gate covers tests and BSDs, tarball install, examples and extractor list tested
* main excludes checked with the defaults' case and fold; Latin-1 decoding ↵Lukasz Kasprzak5 days1-1/+4
| | | | memory; hardlink election documented
* output: wrap by terminal columns, names cannot fake step lines, -v lists ↵Lukasz Kasprzak5 days1-2/+4
| | | | unscanned destinations
* a real run's later directories are not blocked by earlier claims; -n across ↵Lukasz Kasprzak5 days1-4/+9
| | | | directories documented
* content tests are three-valued: unknown when unreadable or read in partLukasz Kasprzak5 days1-8/+18
|
* captures keep the name's diacriticsLukasz Kasprzak5 days1-4/+4
|
* text that turns binary further on has no content, like an imageLukasz Kasprzak5 days1-4/+4
|
* plan 10 re-check: cut run column, damaged undo run, emptied directory ↵v0.0.7Lukasz Kasprzak5 days1-3/+6
| | | | cleanup, text turning binary, explain flags, interrupt docs
* plan 10: docs (-n, README version and scope, trash identity, --json U+FFFD, ↵Lukasz Kasprzak5 days1-4/+16
| | | | limitations, changelog)
* plan 10: an interrupt stops between steps; nohup keeps ignoring hangupsLukasz Kasprzak5 days1-2/+5
|
* plan 10: a damaged log line refuses only its file, not the runLukasz Kasprzak5 days1-0/+4
|
* plan 10: a format with no text is no match, not unreadableLukasz Kasprzak5 days1-2/+5
|
* plan 9: docs and changelog describe what 0.0.7 doesLukasz Kasprzak5 days1-11/+27
|
* plan 9: undo review matches review, --min-age validated, future mtimes, rule ↵Lukasz Kasprzak5 days1-2/+3
| | | | names, conflict enum, dependency gate, absolute tool paths
* plan 9: content excludes fail closed; krino.conf excludes checked without ↵Lukasz Kasprzak5 days1-1/+9
| | | | directories
* plan 9: keyword cache keys on extension, max-read and Unicode tables, trims ↵Lukasz Kasprzak5 days1-11/+17
| | | | removed keywords
* plan 9: an interrupted or failed undo can be finishedLukasz Kasprzak5 days1-3/+13
|
* plan 8: fuzz decoders; fold ẞ and invalid UTF-8 correctly, refuse ↵Lukasz Kasprzak5 days1-2/+3
| | | | non-UTF-8 paths in krino new
* go 1.25, toolchain go1.26.8, x/text v0.41.0: fixes GO-2026-5970 and the ↵Lukasz Kasprzak5 days1-1/+5
| | | | reachable stdlib vulnerabilities
* plan 8: threat model, make fuzz, race and vulncheckLukasz Kasprzak5 days1-1/+40
|
* krino: 0.0.6 — w applies and quits, choices echoed in redv0.0.6Lukasz Kasprzak5 days1-3/+14
|
* krino: 0.0.5 — keyword cache, t and d in reviewv0.0.5Lukasz Kasprzak5 days1-4/+49
|
* 0.0.4: max-size, exclude forms, --min-agev0.0.4Lukasz Kasprzak5 days1-2/+30
|
* krino: 0.0.3 — the plan as one block per file, wrapped, and -Pv0.0.3Lukasz Kasprzak5 days1-15/+56
| | | | | | | | Each file shows its steps, then the rule and the reason it matched, one field per line; on a terminal every line wraps to its width with continuation lines under their own column, and piped output is never wrapped. Choosing per file shows the same block. -P / --no-pager prints the plan without the pager. A duplicate's original is shown with ~.
* krino: coloured output, and --no-colorLukasz Kasprzak5 days1-3/+26
| | | | | | | Lukasz, 2026-09-14: colour the output for ease of reading, with an option of no colour. Section 8.2 now lists what is styled, from the 16-colour ANSI palette plus bold and faint only, so the terminal theme decides the look; section 11 adds --no-color; section 15 adds the colour tests.
* krino: duplicates are found, never deletedLukasz Kasprzak5 days1-1/+3
| | | | | | | | | A rule combining (duplicate) with a delete action is refused at load, and a file that is a duplicate under any duplicate scope its directory uses gets no delete step from any rule: the plan shows it skipped and the chain continues. A failed duplicate check blocks the delete too. Tests cover (matched), another rule's own condition, a test evaluation skipped, two scopes and a failed check, each checking every copy is still on disk.
* krino: duplicates are found, never deletedLukasz Kasprzak5 days1-9/+55
| | | | | | | | | Lukasz, 2026-09-14: leave deleting duplicates to the user or jdupes. Section 5.5 now forbids a delete action in any rule using (duplicate), and skips any delete step for a file that is a duplicate under a scope its directory uses, which closes the (matched) and other-rule routes. Two scopes that elect different originals can then only move copies aside, never delete them. The consequences land in 4.5, 7.1, the 8.2 example, 15 and 17.
* krino: release 0.0.1 — man pages, install, examples, cross and release, ↵v0.0.1Lukasz Kasprzak7 days1-18/+33
| | | | | | | | | README, changelog Also: undo removes the directories its run created; a hardlink is never a duplicate of its own other name; a flag written before "undo" is honoured; --version prints no leading v. Duplicate conditions with different scopes not sharing an original is documented as a known limitation.
* krino: no performance target for 0.0.1Lukasz Kasprzak7 days1-2/+8
| | | | | | | | | | Lukasz: "no performance goal". Section 13s "under 2 s on a 4-core laptop" is replaced with the decision and its evidence, so it is not reinstated later: measured throughput is dominated by the external extractors, not by krino. A real folder of 265 files with 164 needing pdftotext at roughly 80 ms each takes 12-17 s; a synthetic 4405-file tree needing no extraction takes 1.09 s. A single threshold would describe popplers speed and the shape of one folder. The measurement is still reported in the release notes; nothing is promised.
* krino: acting — trash, journal, apply, lock, review, undoLukasz Kasprzak7 days1-2/+4
|
* krino: planning — chains, placeholders, conflicts, JSONLukasz Kasprzak7 days1-1/+12
|
* krino: matching — scan, ignore, conditions, extraction, duplicates, ↵Lukasz Kasprzak8 days1-4/+11
| | | | explain, dry run
* krino: foundation — sexp reader, config language, init/new/checkLukasz Kasprzak8 days1-0/+626