Skip to main content

Module backup

Module backup 

Source
Expand description

Backup-rotation transaction for workload edits.

Per SRD-64 §6.5: every workload mutation rotates two sibling files alongside the workload:

  • <workload>.bak — the immediate-previous content, written before the new content lands on disk.
  • <workload>.bak.prev — one step further back (the pre-previous content). Lets the user recover from “the last edit was right but the one before was the one I wanted” without reaching for git.

Two-deep is the policy floor; deeper history belongs in version control.

§Rotation order

Three steps per edit, all fs::rename for atomicity:

  1. Move <workload>.bak → <workload>.bak.prev (overwriting any existing .bak.prev).
  2. Copy <workload> → <workload>.bak. Copy, not rename, because the workload itself has to stay in place until step 3 (otherwise readers see a missing file mid-edit). On filesystems that support reflinks (btrfs, xfs), the copy is essentially free.
  3. Write the new content to <workload> via a temp file + atomic rename so the workload itself is never half-written.

Failure during step 1 leaves the prior backup pair untouched. Failure during step 2 leaves a mismatched pair (bak.prev is the old bak, bak is missing) — the rollback path restores bak.prev → bak to keep the pair consistent. Failure during step 3 leaves the workload at its pre-edit state with a fresh bak that matches it.

Structs§

BackupPaths
Sibling-file paths for one workload.

Functions§

commit_temp
Atomically replace the workload with the contents of temp. Caller has written the new content to temp; this rename promotes it to the workload’s path. After this returns, <workload>.bak holds the pre-edit content and the workload itself holds the post-edit content.
rollback
Roll back a partially-applied rotation. Used when the in-memory mutation step fails (or its post-write parse fails). Restores the on-disk state to what it was before rotate ran:
rotate
Run the backup rotation: rotate .bak → .bak.prev, copy workload → .bak. Caller subsequently writes the new content to temp and atomically renames it over workload. See commit_temp.