A symlink whose target cannot be read is left out of the snapshot silently, even without --skip-errors #269

Closed
opened 2026-10-07 18:00:20 +02:00 by clawbot · 1 comment
Collaborator

internal/snapshot/scanner.go:1116-1121 returns nil after a debug log when Readlink fails, and :943-951 treats that nil as handled, so nothing is recorded. The run completes and reports success. The README promises that symlinks are backed up, and that an entry which cannot be read aborts the run unless --skip-errors is given.

Trigger: a symlink removed or replaced between the walk's Lstat and the Readlink, or any I/O error from readlink.

Found by the second-pass audit on next at e161343, by code trace.

Definition of done

  1. A Readlink failure is handled like an unreadable regular file: it aborts the run, or with --skip-errors it is skipped with the usual error line.
  2. A test covers both cases.
  3. make check passes.

Model: fable-5-1 (audit); opus-5-5 (issue)

`internal/snapshot/scanner.go:1116-1121` returns nil after a debug log when `Readlink` fails, and `:943-951` treats that nil as handled, so nothing is recorded. The run completes and reports success. The README promises that symlinks are backed up, and that an entry which cannot be read aborts the run unless `--skip-errors` is given. Trigger: a symlink removed or replaced between the walk's `Lstat` and the `Readlink`, or any I/O error from `readlink`. Found by the second-pass audit on `next` at `e161343`, by code trace. ## Definition of done 1. A `Readlink` failure is handled like an unreadable regular file: it aborts the run, or with `--skip-errors` it is skipped with the usual error line. 2. A test covers both cases. 3. `make check` passes. Model: fable-5-1 (audit); opus-5-5 (issue)
clawbot self-assigned this 2026-10-07 18:00:20 +02:00
Author
Collaborator

Fixed in #275. A symlink whose target cannot be read now aborts the run, or with --skip-errors is skipped with the Failed to access error line. Two tests reproduce the failure by deleting the symlink between the walk's lstat and the readlink; both failed on next before the fix.

Judgement call: a symlink deleted in that window also aborts the run without --skip-errors, as the definition of done asks for any readlink failure.

Model: opus-5-5

Fixed in https://git.eeqj.de/sneak/vaultik/pulls/275. A symlink whose target cannot be read now aborts the run, or with `--skip-errors` is skipped with the `Failed to access` error line. Two tests reproduce the failure by deleting the symlink between the walk's `lstat` and the `readlink`; both failed on `next` before the fix. Judgement call: a symlink deleted in that window also aborts the run without `--skip-errors`, as the definition of done asks for any `readlink` failure. Model: opus-5-5
Sign in to join this conversation.