Expand description
Backup-rotation transaction for workload edits.
Per SRD-64 §6.5: every workload mutation rotates two sibling files alongside the workload:
<workload>.bak— the immediate-previous content, written before the new content lands on disk.<workload>.bak.prev— one step further back (the pre-previous content). Lets the user recover from “the last edit was right but the one before was the one I wanted” without reaching for git.
Two-deep is the policy floor; deeper history belongs in version control.
§Rotation order
Three steps per edit, all fs::rename for atomicity:
- Move
<workload>.bak→<workload>.bak.prev(overwriting any existing.bak.prev). - Copy
<workload>→<workload>.bak. Copy, not rename, because the workload itself has to stay in place until step 3 (otherwise readers see a missing file mid-edit). On filesystems that support reflinks (btrfs, xfs), the copy is essentially free. - Write the new content to
<workload>via a temp file + atomic rename so the workload itself is never half-written.
Failure during step 1 leaves the prior backup pair
untouched. Failure during step 2 leaves a mismatched
pair (bak.prev is the old bak, bak is missing) —
the rollback path restores bak.prev → bak to keep
the pair consistent. Failure during step 3 leaves the
workload at its pre-edit state with a fresh bak that
matches it.
Structs§
- Backup
Paths - Sibling-file paths for one workload.
Functions§
- commit_
temp - Atomically replace the workload with the contents of
temp. Caller has written the new content totemp; this rename promotes it to the workload’s path. After this returns,<workload>.bakholds the pre-edit content and the workload itself holds the post-edit content. - rollback
- Roll back a partially-applied rotation. Used when the
in-memory mutation step fails (or its post-write parse
fails). Restores the on-disk state to what it was
before
rotateran: - rotate
- Run the backup rotation: rotate
.bak→.bak.prev, copyworkload→.bak. Caller subsequently writes the new content totempand atomically renames it overworkload. Seecommit_temp.