fix(sync): preserve source and foreign files during atomic copy - #2
Merged
Merged
Conversation
|
Welcome! 👋 Thanks for your first pull request in this repository. A maintainer will review it soon. Please make sure:
Thanks for contributing! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The local copy helper deleted a source named
<destination>.prosync_tmpbefore copying it and overwrote unrelated files at that fixed temporary path. It now reserves a unique private stage in the destination directory, preserves Copy2 metadata, rejects source/destination identity aliases, and cleans only its own stage.Windows readonly destination replacement remains supported for regular, singly linked files. On publication failure, the original mode is restored if the destination still has the captured identity. Readonly hardlink/reparse destinations fail safely to avoid changing another original. No destination-delete fallback is used.
The first CI run also exposed missing Pillow in both test workflows and native-platform forcing during headless icon tests. Pillow is now installed for tests and declared as a development dependency. Only screenshot generation forces the native Qt platform; icon generation respects the existing platform. The screenshot font-rendering guard remains enforced, with a fresh-process regression test.
The Store readiness script now falls back to
tomlion Python 3.10, with the conditional development/CI dependency supplied. Final CI passes on Python 3.10–3.12, Linux and macOS, plus CodeQL. Independent reviews cover the copy helper, headless icon/screenshot guard delta and TOML compatibility delta.Validation: 209 tests passed locally on Windows, with three symlink cases skipped for missing privilege (WinError 1314); the smoke runner also passed. The 28 new copy cases include real hardlinks, junctions, sharing denial, readonly targets/sources, concurrent writers and copy/metadata/replace/close failures. They produce 21 failures against the unchanged upstream implementation (four passes, three skips). The headless icon regression also fails against upstream. Independent Windows copy review: 35 passes, three privilege skips. Ruff and
git diff --checkpass.COPY_SAFETY.mddocuments publication and recovery behavior. SFTP temporary names, overlapping folder scanners, external file-exchange races, live SQLite snapshots and power-loss durability remain separate work.