Skip to content

fix(sync): preserve source and foreign files during atomic copy - #2

Merged
lukisch merged 3 commits into
masterfrom
fix/codex-copy-ownership-20261001
Oct 1, 2026
Merged

lukisch merged 3 commits into
masterfrom
fix/codex-copy-ownership-20261001

Conversation

@lukisch

@lukisch lukisch commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

The local copy helper deleted a source named <destination>.prosync_tmp before copying it and overwrote unrelated files at that fixed temporary path. It now reserves a unique private stage in the destination directory, preserves Copy2 metadata, rejects source/destination identity aliases, and cleans only its own stage.

Windows readonly destination replacement remains supported for regular, singly linked files. On publication failure, the original mode is restored if the destination still has the captured identity. Readonly hardlink/reparse destinations fail safely to avoid changing another original. No destination-delete fallback is used.

The first CI run also exposed missing Pillow in both test workflows and native-platform forcing during headless icon tests. Pillow is now installed for tests and declared as a development dependency. Only screenshot generation forces the native Qt platform; icon generation respects the existing platform. The screenshot font-rendering guard remains enforced, with a fresh-process regression test.

The Store readiness script now falls back to tomli on Python 3.10, with the conditional development/CI dependency supplied. Final CI passes on Python 3.10–3.12, Linux and macOS, plus CodeQL. Independent reviews cover the copy helper, headless icon/screenshot guard delta and TOML compatibility delta.

Validation: 209 tests passed locally on Windows, with three symlink cases skipped for missing privilege (WinError 1314); the smoke runner also passed. The 28 new copy cases include real hardlinks, junctions, sharing denial, readonly targets/sources, concurrent writers and copy/metadata/replace/close failures. They produce 21 failures against the unchanged upstream implementation (four passes, three skips). The headless icon regression also fails against upstream. Independent Windows copy review: 35 passes, three privilege skips. Ruff and git diff --check pass.

COPY_SAFETY.md documents publication and recovery behavior. SFTP temporary names, overlapping folder scanners, external file-exchange races, live SQLite snapshots and power-loss durability remain separate work.

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

Welcome! 👋 Thanks for your first pull request in this repository.

A maintainer will review it soon. Please make sure:

  • Your changes are tested
  • Documentation is updated if needed
  • The PR description explains what and why

Thanks for contributing!

@lukisch
lukisch merged commit ce50546 into master Oct 1, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant