fix(p7-output-fs): address c-review (fake-super mode sanitization HIGH; sparse/preallocate precedence; partial no_replace guard; stronger tests)
- fake_super_restore_fd now sanitizes mode like metadata_mode (never grants S_IWGRP|S_IWOTH; 0666 -> 0644), fixing a privilege regression - --sparse takes precedence over --preallocate (skip posix_fallocate when sparse) so holes are not re-allocated; docs corrected - --partial retention disabled under --no_replace (ignore/existing) and only marks write_attempted after the write begins (no empty-temp retention) - accept --block-size=SIZE / --delta-block=SIZE inline forms; neutral messages - fake-super EPERM/EACCES skipped silently (docs aligned); EINVAL still logged - sparse unit test now memcmp's the full buffer; TestBlockSize integration keeps the destination basis so delta is genuinely exercised - unit 37/37, cppcheck 0, clang-format 0
This commit is contained in:
@@ -250,6 +250,14 @@ static void test_fake_super_restore() {
|
||||
EXPECT_EQ_INT(fstat(fd, &st), 0);
|
||||
EXPECT_EQ_INT((int)(st.st_mode & 07777), 0751);
|
||||
|
||||
/* Mode sanitization: the normal metadata path never grants group/other write
|
||||
bits, and fake-super replay must not re-add them (a recorded 0666 restores
|
||||
as 0644, never as world-writable). */
|
||||
fake_super_store_fd(fd, 1001, 1002, 0666, 1700000000, 0);
|
||||
EXPECT_TRUE(fake_super_restore_fd(fd));
|
||||
EXPECT_EQ_INT(fstat(fd, &st), 0);
|
||||
EXPECT_EQ_INT((int)(st.st_mode & 0777), 0644);
|
||||
|
||||
/* Restore with a malformed record must skip without failing. */
|
||||
time_t before = st.st_mtime;
|
||||
int wfd = open(path, O_RDONLY);
|
||||
|
||||
Reference in New Issue
Block a user