pub struct AtomicWrite { /* private fields */ }Expand description
A file being written through a temporary alongside its destination, replaced by an atomic rename only once the content is complete and durable.
Nothing partial ever appears at the destination path. If the process dies mid-write, the
destination is untouched and a .strypt-*.tmp file is left behind — visible, obviously
incomplete, and adjacent to where it belongs, rather than a silently truncated file the
user might publish.
Implementations§
Source§impl AtomicWrite
impl AtomicWrite
Sourcepub fn begin(
destination: &Path,
overwrite: Overwrite,
permissions: Permissions,
) -> Result<Self>
pub fn begin( destination: &Path, overwrite: Overwrite, permissions: Permissions, ) -> Result<Self>
Begin writing to destination.
§Errors
StryptError::OutputExists if the destination exists and overwrite is
Overwrite::Refuse; StryptError::Io if the temporary file cannot be created.
Sourcepub fn commit(self) -> Result<()>
pub fn commit(self) -> Result<()>
Flush, synchronise, and atomically move the temporary into place.
The sync_all is not ceremony. Without it the rename can be durable while the
content behind it is not, so a crash at the wrong moment leaves a file that exists,
has the right name, and contains nothing — which for this tool means a user with a
file they believe is a stripped copy of their document.
§Errors
StryptError::Io if syncing or renaming fails. The temporary is removed either way.
Trait Implementations§
Source§impl Debug for AtomicWrite
impl Debug for AtomicWrite
Source§impl Drop for AtomicWrite
impl Drop for AtomicWrite
Source§fn drop(&mut self)
fn drop(&mut self)
Removes the temporary if the writer was neither committed nor aborted.
This is the path taken when a handler returns Err mid-write, which is the normal way
a fail-closed handler gives up. Without it, every failed strip would litter a partial
file next to the user’s document.