feat: exclude basis directories from --delete

Generalize the delete walker's protected-root-child skip into a prefix list.
The receiver now passes both the --delay-updates staging directory and every
basis-dir path, so a --delete run can never treat a basis snapshot (which a
--link-dest run just linked from) as destination content to remove.
This commit is contained in:
2026-09-06 18:47:29 +02:00
parent d38920c972
commit 8f846a43b8
2 changed files with 34 additions and 17 deletions
+7 -5
View File
@@ -10,12 +10,14 @@ char* output_escape(const char* string, bool eight_bit_output);
char* path_cat(const char* path1, const char* path2);
bool glob_match(const char* pattern, const char* str);
bool delete_extras(const char* dest_root, ArrayList* manifest);
/* Remove files/dirs under dest_root that are not listed in manifest. When
skip_root_child is non-NULL, a direct child of dest_root with that exact
name is left untouched (used to protect the --delay-updates staging
directory, which holds files that are still to be published). */
/* Remove files/dirs under dest_root that are not listed in manifest. The
delete walker never descends into (and so never removes) an entry whose
relative path equals one of the skip_prefixes or lies below one: used to
protect the --delay-updates staging directory (files still to be published)
and the --compare-dest/--copy-dest/--link-dest basis trees (snapshots the
transfer links from, never destination content). */
bool delete_extras_limited(const char* dest_root, ArrayList* manifest, size_t max_delete,
const char* skip_root_child);
const char* const* skip_prefixes, int skip_prefix_count);
bool utils_set_authorized_root(int fd, const char* canonical_path);
/* The fd-only compatibility form is fail-closed for path-based operations;
* callers should use utils_set_authorized_root with the canonical identity. */