Repository navigation
Conversation
|
Reading your changes lead us to redesign how permission copying is implemented: If we are going to replace an existing file, we create the temporary file with permissions 0600 and copy the permissions when replacing the file. Could you please adapt your PR to that? There is a TODO comment where the ACL copy function should be called. Also, don't restrict it to Linux, other system also implement this API. And check for the functions you call, not the existence of the header file. If you need to check for multiple functions, define a USE_ACL at the top of the file if all requirements are met, and use that throughout the rest of the file (to avoid duplicating the logic). |
5ef3f43 to
cae933b
Compare
|
Thanks. I rebased onto the new permission-copy flow and adapted the PR. It now uses the portable |
|
Thanks. However, since acl_get_file is in a separate library on Linux, and we would like to avoid extra dependencies for libzip, I would prefer if you reverted to the previous API. |
|
Understood. I restored the dependency-free |
Signed-off-by: David Sarkisyan <281478990+srkyn@users.noreply.github.com>
When libzip replaces an archive, the new inode can lose the original POSIX access ACL even though its mode bits are restored. The converse also matters: a temporary file can inherit an access ACL from its directory when the original archive has none. Mode bits alone do not preserve the effective permissions of an extended ACL.
This fills the ACL-copy TODO in
copy_permissions()on top of the current temporary-file permission flow. It copies a source access ACL to the open temporary file withfsetxattr(), or clears an inherited ACL withfremovexattr()when the source has none. It then applies the final mode withfchmod()before closing and renaming the temporary file. Errors that would leave permissions uncertain stop the replacement. The Linux ACL path is feature-gated and adds no dependency.The regression covers an ordinary archive update, a direct named-source replacement, and removal of a directory-inherited ACL when the source has no access ACL. It runs as a direct CTest so unsupported filesystems can report a skip.
Validation on Linux:
clang-format --dry-run --Werrorand the PR delta whitespace check passed.