aboutsummaryrefslogtreecommitdiff
path: root/internal/apply/fs.go
Commit message (Collapse)AuthorAgeFilesLines
* a symlink in the sorted directory no longer redirects a stepLukasz Kasprzak48 hours1-2/+57
| | | | | | | | | | | | | | | | | | | | | | | | | | Placeholders were already stopped from sending a file out of the directory a rule named. A symlink is a name too, and the directory krino sorts is by the threat model's own premise a place the internet writes into: a link named after a rule's destination sent moves and copies anywhere, and under (on-conflict overwrite) trashed a file OUTSIDE the sorted directory - while the plan showed the in-tree text and the run reported success. A step whose destination passes through a symlink at or below the directory being sorted now fails. A destination the configuration names outside it - ~/docs on another disk - is the user's own arrangement and is followed as before; both cases have a test. End to end, the review's scenario (Out -> ~/secret, overwrite): before: 1 applied, the user's file replaced and trashed after: 0 applied 1 failed, the file untouched, nothing trashed Two bookkeeping bugs in MkdirAllTracked went with it: a dangling symlink read as a missing directory and was then recorded as one krino had created - undo would have unlinked a link krino never made - and a directory created by someone else between the check and the mkdir was recorded the same way.
* comments that explain the code, not how it was writtenLukasz Kasprzak2 days1-8/+7
| | | | | | | | | | | | | | | | | | About 340 comments cited the development process: task and plan numbers, fix waves, rulings, reviewers, and the author in the third person with a date. None of that exists outside the work itself, so to a reader it pointed at nothing. Each one now states the engineering reason it was standing in front of; where a comment was provenance and nothing else, it is gone. References to docs/design.md and docs/gui-design.md by section stay: both ship with the repository. The design documents lose their amendment diaries - CHANGELOG.md is that record - and the GUI's says plainly that the window has gone further than the document. Only comments changed. Every .go file was parsed and its code printed with comments stripped, before and after: the two hashes are identical across all 175 files.
* plan 9: undo checks trash identity, groups by directory, re-checks at ↵Lukasz Kasprzak5 days1-3/+3
| | | | execution, removes directories it recreates
* krino: release 0.0.1 — man pages, install, examples, cross and release, ↵v0.0.1Lukasz Kasprzak6 days1-0/+35
| | | | | | | | | README, changelog Also: undo removes the directories its run created; a hardlink is never a duplicate of its own other name; a flag written before "undo" is honoured; --version prints no leading v. Duplicate conditions with different scopes not sharing an original is documented as a known limitation.
* krino: acting — trash, journal, apply, lock, review, undoLukasz Kasprzak7 days1-0/+197