Record file mode in the manifest: 0000 by default, real permissions on request #161

Open
opened 2026-10-06 01:45:14 +02:00 by clawbot · 0 comments
Collaborator

Ruling from sneak (#81 (comment), question 2): add the file-mode field and use it in 1.0. By default the manifest records the mode as 0000; it records each file's real permissions only when the creator asks. Standing rule for the format: nothing goes in the 1.0 manifest that 1.0 does not read or write.

Behaviour of check and fetch follows the recommended reading in #81 (comment) (question A) until sneak says otherwise.

Definition of done

  • mfer/mf.proto: MFFilePath gains the mode field (uint32), regenerated with make generate. The writer always fills it: 0000 by default, the file's permission bits (0777 mask only; never setuid, setgid or sticky) when the creator opts in through a CLI flag on gen and freshen (named like --include-timestamps, for example --include-permissions) and a library option in the ScannerOptions style.
  • Readers expose it: the library, list -l, export.
  • check: a recorded mode other than 0000 that differs from the file on disk is a failure; 0000 is never checked.
  • fetch: a recorded mode other than 0000 is set on each file it writes, masked to 0777; a mode outside 0777 in a manifest is refused before any file is requested.
  • docs/FORMAT.md states the field, its 0000 default, the 0777 range, and the rule that nothing goes in the 1.0 manifest that 1.0 does not read or write. The test pinning MFFilePath to the spec (#158) includes the new field.
  • Tests: default 0000; opt-in records real modes; reading back through the library and list/export; check catches a changed mode and ignores 0000; fetch applies a mode and refuses one outside 0777.
  • make check passes. Commit title ends with (closes #N) for this issue's number.

Model: opus-5-5

Ruling from sneak (https://git.eeqj.de/sneak/mfer/issues/81#issuecomment-127074, question 2): add the file-mode field and use it in 1.0. By default the manifest records the mode as `0000`; it records each file's real permissions only when the creator asks. Standing rule for the format: nothing goes in the 1.0 manifest that 1.0 does not read or write. Behaviour of `check` and `fetch` follows the recommended reading in https://git.eeqj.de/sneak/mfer/issues/81#issuecomment-127088 (question A) until sneak says otherwise. ## Definition of done - `mfer/mf.proto`: `MFFilePath` gains the mode field (`uint32`), regenerated with `make generate`. The writer always fills it: `0000` by default, the file's permission bits (`0777` mask only; never setuid, setgid or sticky) when the creator opts in through a CLI flag on `gen` and `freshen` (named like `--include-timestamps`, for example `--include-permissions`) and a library option in the `ScannerOptions` style. - Readers expose it: the library, `list -l`, `export`. - `check`: a recorded mode other than `0000` that differs from the file on disk is a failure; `0000` is never checked. - `fetch`: a recorded mode other than `0000` is set on each file it writes, masked to `0777`; a mode outside `0777` in a manifest is refused before any file is requested. - `docs/FORMAT.md` states the field, its `0000` default, the `0777` range, and the rule that nothing goes in the 1.0 manifest that 1.0 does not read or write. The test pinning `MFFilePath` to the spec (https://git.eeqj.de/sneak/mfer/issues/158) includes the new field. - Tests: default `0000`; opt-in records real modes; reading back through the library and `list`/`export`; `check` catches a changed mode and ignores `0000`; `fetch` applies a mode and refuses one outside `0777`. - `make check` passes. Commit title ends with ` (closes #N)` for this issue's number. Model: opus-5-5
clawbot self-assigned this 2026-10-06 01:45:15 +02:00
Sign in to join this conversation.