Skip to main content

Module backup

Module backup 

Source

Structsยง

BackupBundle ๐Ÿ”’
BackupFiles ๐Ÿ”’
BackupManifest ๐Ÿ”’
CommittedStage ๐Ÿ”’
Result of committing one staged action. Carries the path of the .pre-import.bak we parked the previous target at (if any) so we can either roll it back on a later failure or unlink it on finalize.
ImportGuard ๐Ÿ”’
RAII guard that flips Scheduler::import_in_progress on construction and restores it on drop, including on panic. The run loop checks the flag once per tick and short-circuits while itโ€™s set.
StagedFile ๐Ÿ”’

Enumsยง

StageAction ๐Ÿ”’
Per-file action staged for the commit phase. Writes land in .<name>.import.tmp alongside the final path so the rename is across a single directory entry (atomic on every filesystem we support). Removes have no temp โ€” theyโ€™re just deferred unlinks.

Constantsยง

BACKUP_SCHEMA_VERSION ๐Ÿ”’
BUNDLE_APP_ID ๐Ÿ”’
MAIN_WINDOW_LABEL ๐Ÿ”’
Only the settings window invokes backup IPC. Overlays never need it; gate at the command boundary so a future renderer bug that leaks the IPC handle to an overlay canโ€™t initiate a destructive import or exfiltrate state.
MAX_BACKUP_BYTES ๐Ÿ”’
Hard cap on the on-disk size of a bundle file weโ€™ll deserialize. Realistic worst case: ~300 B per logged event ร— ~50 events/day ร— a decade โ‰ˆ 55 MB. 64 MiB gives a generous multiple of that while keeping the peak allocation (read into String, then parse) low enough not to stress a 4 GB tray-app footprint. Larger files short-circuit before parse so an accidentally-picked 10 GiB blob canโ€™t OOM the deserializer.

Functionsยง

apply_bundle_to_scheduler ๐Ÿ”’
bak_path_for ๐Ÿ”’
Sibling path where the existing target is parked for the duration of the commit. If a later stageโ€™s commit fails we rename this back into place; if every stage succeeds we delete it during finalize.
commit_stage ๐Ÿ”’
Apply one staged action, parking the existing target at .pre-import.bak first so a later commit failure can be rolled back. A pre-existing .bak (residue from a previously-failed import) is unlinked first so the parking rename succeeds on Windows, which doesnโ€™t overwrite a present destination.
discard_all ๐Ÿ”’
discard_stage ๐Ÿ”’
ensure_main_window ๐Ÿ”’
export_backup_to_path
exportable_supporter ๐Ÿ”’
Filter what the export writes for the supporter file.
finalize_committed ๐Ÿ”’
Happy-path cleanup after every stage committed successfully. Unlinks the .pre-import.bak files we parked during commit so they donโ€™t linger as confusing sibling files.
import_audit_summary ๐Ÿ”’
Single-line breadcrumb the import flow drops into the log file on success. Pulled out of the log::info! call so the format arguments are exercised by a unit test even when no logger is installed in the test binary (the log crate short-circuits argument evaluation when log_enabled!(Info) is false).
import_backup_from_path
read_optional_text ๐Ÿ”’
rollback_committed ๐Ÿ”’
Reverse-restore every committed stage from its .pre-import.bak. Best-effort: each step swallows errors because a) weโ€™re already in a failure path and b) a failed individual rollback shouldnโ€™t abort the rest. Stale .bak files left by a catastrophic rollback failure are picked up by the next importโ€™s commit_stage (it unlinks the stale .bak before parking).
stage_path_for ๐Ÿ”’
stage_remove ๐Ÿ”’
stage_write ๐Ÿ”’
validate_bundle ๐Ÿ”’
warn_on_unparseable_events ๐Ÿ”’
Events are checked leniently: a line we canโ€™t parse โ€” e.g. an event type written by a newer Entracte โ€” must not brick the whole import. The events file is written verbatim and the stats reader (crate::stats::read_all) already drops lines it canโ€™t parse, so unknown events are preserved on disk and simply ignored when computing stats. We only count and warn so the drop isnโ€™t silent โ€” matching the runtime readerโ€™s tolerance rather than the old all-or-nothing reject.