aboutsummaryrefslogtreecommitdiff
path: root/internal/apply/swap_test.go
Commit message (Collapse)AuthorAgeFilesLines
* a symlink in the sorted directory no longer redirects a stepLukasz Kasprzak2 days1-0/+63
| | | | | | | | | | | | | | | | | | | | | | | | | | Placeholders were already stopped from sending a file out of the directory a rule named. A symlink is a name too, and the directory krino sorts is by the threat model's own premise a place the internet writes into: a link named after a rule's destination sent moves and copies anywhere, and under (on-conflict overwrite) trashed a file OUTSIDE the sorted directory - while the plan showed the in-tree text and the run reported success. A step whose destination passes through a symlink at or below the directory being sorted now fails. A destination the configuration names outside it - ~/docs on another disk - is the user's own arrangement and is followed as before; both cases have a test. End to end, the review's scenario (Out -> ~/secret, overwrite): before: 1 applied, the user's file replaced and trashed after: 0 applied 1 failed, the file untouched, nothing trashed Two bookkeeping bugs in MkdirAllTracked went with it: a dangling symlink read as a missing directory and was then recorded as one krino had created - undo would have unlinked a link krino never made - and a directory created by someone else between the check and the mkdir was recorded the same way.
* a file trashed to make room is logged the moment it is trashedLukasz Kasprzak2 days1-2/+88
| | | | | | | | | | | | | | | | | | | The displace was carried out first and logged only when the whole step finished - for a copy or a cross-device move, the entire data transfer later. A process killed in that window left the user's file in the Trash with nothing recording it: krino log said "nothing applied" and undo offered nothing. It is its own action with its own line (spec §9), so it is now written the moment trash.Put returns, through a hook ChainLogged calls before the step that needed the name begins. A displace that cannot be logged fails the step rather than compounding an unrecorded destructive act with a second one. Verified by killing krino -9 mid-copy with 600 MB in flight: before: krino log "nothing applied", 0 displace lines after: krino log "1 displaced", 1 displace line
* the module path is git.labunix.xyz/krinoLukasz Kasprzak2 days1-2/+2
| | | | | | | | | | | So that go install can find it. cgit serves no go-import meta tag, so nginx answers a ?go-get=1 request for /NAME with one pointing at https://git.labunix.xyz/NAME.git; the alternative was carrying a .git suffix through every import line forever. One sed over the imports, both go.mod files, and the dependency gate's whitelist. Nothing else depends on the path. go install works from the next tag, the first release whose go.mod carries it.
* plan 10: an interrupt stops between steps; nohup keeps ignoring hangupsLukasz Kasprzak5 days1-1/+33
|
* plan 9: apply logs each step as it completes and stops a chain that landed ↵Lukasz Kasprzak5 days1-0/+86
| | | | elsewhere
* plan 8: apply refuses a source swapped for a symlink or another fileLukasz Kasprzak5 days1-0/+101