]> dgit.raspbian.org Git - git-annex.git/commitdiff
Call freezeContent after move into annex
authorReiko Asakura <asakurareiko@protonmail.ch>
Tue, 26 Oct 2021 19:46:38 +0000 (15:46 -0400)
committerJoey Hess <joeyh@joeyh.name>
Wed, 27 Oct 2021 18:05:57 +0000 (14:05 -0400)
This change better supports Windows ACL management using
annex.freezecontent-command and annex.thawcontent-command and matches
the behaviour of adding an unlocked file.

By calling freezeContent after the file has moved into the annex,
the file's delete permission can be denied. If the file's delete
permission is denied before moving into the annex, the file cannot
be moved or deleted. If the file's delete permission is not denied after
moving into the annex, it will likely inherit a grant for the delete
permission which allows it to be deleted irrespective of the permissions
of the parent directory.

Annex/Content.hs

index da65143ab46c710815ab1cdedca6c2b83ac094ae..89c36e612771e6fde7f9c9d91868a695a51ebd80 100644 (file)
@@ -346,6 +346,9 @@ moveAnnex key af src = ifM (checkSecureHashes' key)
                        liftIO $ moveFile
                                (fromRawFilePath src)
                                (fromRawFilePath dest)
+                       -- On Windows the delete permission must be denied only
+                       -- after the content has been moved in the annex.
+                       freezeContent dest
                        g <- Annex.gitRepo 
                        fs <- map (`fromTopFilePath` g)
                                <$> Database.Keys.getAssociatedFiles key