fix(delete): guard the per-directory delete commit against dry-run
delete_plan_session_commit() lacked the central no-mutation guard that manifest_delete_all() has, so a server-contacting -n run (or a hostile plan frame) could still remove --delete-missing-args mirrors on the per-directory timing path. Return DELETE_COMMIT_OK immediately when the session is a dry-run, and gate the receiver/server commit call sites too. Add a unit test that streams a plan naming an existing destination file and asserts it survives.
This commit is contained in:
@@ -850,6 +850,11 @@ static bool apply_deferred_path(DeletePlanSession* session, const Config* config
|
||||
DeleteCommitResult delete_plan_session_commit(DeletePlanSession* session, const Config* config) {
|
||||
if (!session || !config)
|
||||
return DELETE_COMMIT_ERROR;
|
||||
/* Central no-mutation guard (mirrors manifest_delete_all): a dry-run never
|
||||
deletes. The receive path already skips plan application, but a hostile or
|
||||
buggy peer could still reach the commit, so treat it as a no-op. */
|
||||
if (session->dry_run)
|
||||
return DELETE_COMMIT_OK;
|
||||
bool ok = true;
|
||||
if (session->defer) {
|
||||
for (int i = 0; i < session->deferred->size && ok; i++)
|
||||
|
||||
Reference in New Issue
Block a user