Addresses the PR #100 review.
- HIGH data loss: sweep could overwrite an existing crash recovery before
the user ran recover-file. Reopen a file after a crash, edit it, and the
next autosave wrote the current buffer over the recovery key --- losing
exactly what autosave exists to protect. New ownership rule (Q#AS12): a
per-session `owned` set records which path hashes THIS session wrote or
adopted. A recovery file at a key we do not own is unclaimed crash data;
the sweep refuses to write that buffer, counts it `blocked`, and says so
("autosave paused for N file(s) with unclaimed recovery"). recover-file
ADOPTS the copy once its contents are in the buffer; discard-recovery
removes it. Either resumes normal autosave. sweep() now returns
(written, blocked).
- MEDIUM cleanup missed paths autosave can write. Kill/save cleanup now
goes through `discard_buffer(BufferId)`, which removes BOTH the buffer's
current-path key and the key its last sweep actually wrote (they differ
after a rename --- an LSP WorkspaceEdit changes the path while the
BufferId stays; a path-captured callback deleted the wrong key). And a
sweep-time GC deletes the recovery of any buffer that left the registry,
which is the backstop for argv `[new file]` buffers: they fire no
after-load, so no removal callback is ever registered for them.
- LOW/MEDIUM recover-file pinned only on the active path. Two buffers can
visit one path (pmacs.buffer.from_file does not dedup), so focus drift
could recover into the wrong buffer. It now captures and compares the
origin buffer handle as well as the path.
- LOW write_private left a pre-existing lax autosave/ directory alone. The
birth-mode only applies to dirs that call creates, so a 0755 autosave/
from an older run still leaked recovery-file names, sizes, and mtimes
despite 0600 contents. It is now tightened to 0700 --- but never `base`
itself, which is shared with history/recentf/desktop and may predate us.
New `state::exists` (an existence check, no read) backs the ownership
gate.
Tests (autosave_acceptance now 20): sweep_never_overwrites_unclaimed_
crash_recovery (blocked, crash copy byte-identical, adopt resumes),
discarding_an_unclaimed_recovery_unblocks_the_sweep,
killing_a_new_file_buffer_gcs_its_recovery,
saving_after_a_rename_removes_the_recovery_written_under_the_old_path,
a_pre_existing_lax_autosave_dir_is_tightened.
Gates: fmt + workspace clippy clean; lib 1499; crdt 1670; autosave 20;
desktop 11; persistence 5; m4 90; m7_8 5; GPU 58; git diff --check clean.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>