pub fn replace_file(path: &Path, bytes: &[u8]) -> Result<()>Expand description
Put bytes where a file is, so that the file is either what it was or what was written and never half of each.
The bytes go into a temporary file beside the target, which is then renamed
over it: a rename within one filesystem is atomic, and a crash before it
leaves the original untouched and a stray .part file to delete. The
target’s permissions are carried over, because the rename replaces the
inode and would otherwise leave a document writable by whoever the
temporary file’s default said.
macOS writes in place. The sandbox grant a person gives by choosing a
file covers the file and not its directory, so a temporary file beside it
is refused with Operation not permitted. The safe rewrite there goes
through NSItemReplacementDirectory and replaceItemAtURL:, which is a
platform arm this build cannot verify and does not carry yet.
§Errors
The file could not be written, or not renamed into place.