Files
reasampler/src/shell/package/package_rollback.cpp
T
daniel 655159ceac Close package fs review findings: readRange bounds, picker ext, non-ASCII tests
Cap readRange's allocation and reject size_t overflow instead of truncating;
re-append .rsbank when the export picker omits it; add cafe coverage for
writeFileExclusive and writeLandedFile; loop write() on EINTR.
2026-08-02 17:19:29 -04:00

52 lines
1.7 KiB
C++

// package_rollback.cpp — see package_rollback.h. The rollback delete below runs under
// the ONE carve-out from prune's exclusive file-deletion authority, stated at
// src/shell/persist/prune_fs.cpp:5-11. That discriminator has two clauses and this
// journal makes only the FIRST structural: "did this call create it" is guaranteed by
// recording exclusively-created paths, but "did anything ever reference it" is a
// claim about the caller's ordering — hence markIndexCommitted(), which the import
// verb must fire at the index commit so a later rollback() refuses instead of
// deleting indexed files.
#include "shell/package/package_rollback.h"
#include <filesystem>
#include "shell/package/package_path.h"
namespace reasampler {
namespace fs = std::filesystem;
bool LandedFileJournal::writeLandedFile(const std::string& destPath,
const PayloadBuffer& payload) {
if (indexCommitted_) return false;
std::error_code ec;
const fs::path resolved = fs::absolute(utf8Path(destPath), ec);
if (ec) return false;
const std::string absPath = pathToUtf8(resolved);
if (!writeFileExclusive(absPath, payload)) return false;
paths_.push_back(absPath);
return true;
}
RollbackResult LandedFileJournal::rollback() {
RollbackResult result;
if (indexCommitted_) {
result.refused = true;
return result;
}
for (const std::string& path : paths_) {
std::error_code ec;
const bool removed = fs::remove(utf8Path(path), ec);
if (removed) ++result.deletedCount;
else if (ec) ++result.failedCount;
else ++result.alreadyAbsentCount; // no error, nothing there
}
paths_.clear();
return result;
}
} // namespace reasampler