|
1 | | -import { mkdir, readFile, writeFile } from "node:fs/promises"; |
| 1 | +import { writeFile } from "node:fs/promises"; |
2 | 2 | import { homedir } from "node:os"; |
3 | | -import { dirname, join } from "node:path"; |
| 3 | +import { join } from "node:path"; |
4 | 4 |
|
5 | 5 | import { getLogger } from "@intx/log"; |
6 | 6 |
|
7 | 7 | import { canonicalGrantTool } from "../agent/canonical-tool-name.js"; |
8 | 8 | import { LOG_NAMESPACE_ROOT, SETTINGS_DIR_NAME } from "../branding.js"; |
9 | 9 | import { sessionDir } from "../session/index.js"; |
| 10 | +import { chainObjectWrite } from "./store.js"; |
10 | 11 |
|
11 | 12 | const log = getLogger([LOG_NAMESPACE_ROOT, "permission", "approval-migration"]); |
12 | 13 |
|
@@ -64,75 +65,78 @@ function isFileExistsError(err: unknown): boolean { |
64 | 65 | // Purge update_plan keys from one approvals file (session, project, or |
65 | 66 | // global store shape: an `approvals` array plus, for the global file, a |
66 | 67 | // `providerModels` map of arrays). Backup-then-rewrite: the pre-migration |
67 | | -// bytes are saved to `<path>.bak` first (an existing backup is kept, so the |
| 68 | +// state is saved to `<path>.bak` first (an existing backup is kept, so the |
68 | 69 | // first backup always holds the true original), and a file with nothing to |
69 | | -// left untouched (no backup, byte-identical) so re-runs are no-ops. Entries |
70 | | -// that are not positive update_plan matches are kept verbatim — pure renames |
71 | | -// are never collapsed here; that stays the load-time normalizer's job. |
72 | | -// Missing, unreadable, or corrupt files are no-ops; write failures propagate. |
| 70 | +// purge is left untouched (no backup, byte-identical) so re-runs are no-ops. |
| 71 | +// Entries that are not positive update_plan matches are kept verbatim — pure |
| 72 | +// renames are never collapsed here; that stays the load-time normalizer's |
| 73 | +// job. Missing, unreadable, or corrupt files are no-ops; write failures |
| 74 | +// propagate. The rewrite goes through chainObjectWrite, so a concurrent grant |
| 75 | +// mint to the same file serializes with the migration instead of losing an |
| 76 | +// update, and the tmp+rename lands atomically so a reader never sees a torn |
| 77 | +// file. |
73 | 78 | export async function migrateApprovalStoreFile( |
74 | 79 | path: string, |
75 | 80 | ): Promise<ApprovalStoreMigrationFileResult> { |
76 | | - let raw: string; |
77 | | - try { |
78 | | - raw = await readFile(path, "utf-8"); |
79 | | - } catch { |
80 | | - return { path, purged: 0 }; |
81 | | - } |
82 | | - let parsed: unknown; |
83 | | - try { |
84 | | - parsed = JSON.parse(raw) as unknown; |
85 | | - } catch { |
86 | | - return { path, purged: 0 }; |
87 | | - } |
88 | | - if (typeof parsed !== "object" || parsed === null || Array.isArray(parsed)) { |
89 | | - return { path, purged: 0 }; |
90 | | - } |
91 | | - const record = parsed as Record<string, unknown>; |
92 | | - const next: Record<string, unknown> = { ...record }; |
93 | | - let purged = 0; |
94 | | - const onPurge = (): void => { |
95 | | - purged += 1; |
96 | | - }; |
97 | | - if (Array.isArray(record.approvals)) { |
98 | | - const { kept, changed } = purgeList(record.approvals, onPurge); |
99 | | - if (changed) next.approvals = kept; |
100 | | - } |
101 | | - const providerModels = record.providerModels; |
102 | | - if ( |
103 | | - typeof providerModels === "object" && |
104 | | - providerModels !== null && |
105 | | - !Array.isArray(providerModels) |
106 | | - ) { |
107 | | - const map = providerModels as Record<string, unknown>; |
108 | | - const nextMap: Record<string, unknown> = {}; |
109 | | - let mapChanged = false; |
110 | | - for (const [key, list] of Object.entries(map)) { |
111 | | - const { kept, changed } = purgeList(list, onPurge); |
112 | | - if (changed) { |
113 | | - nextMap[key] = kept; |
114 | | - mapChanged = true; |
115 | | - } else { |
116 | | - nextMap[key] = list; |
117 | | - } |
118 | | - } |
119 | | - if (mapChanged) next.providerModels = nextMap; |
120 | | - } |
121 | | - if (purged === 0) return { path, purged: 0 }; |
122 | 81 | const backupPath = `${path}.bak`; |
| 82 | + let purged = 0; |
| 83 | + let rewrote = false; |
123 | 84 | try { |
124 | | - await writeFile(backupPath, raw, { flag: "wx" }); |
| 85 | + await chainObjectWrite(path, async (current) => { |
| 86 | + const next: Record<string, unknown> = { ...current }; |
| 87 | + let changed = 0; |
| 88 | + const onPurge = (): void => { |
| 89 | + changed += 1; |
| 90 | + }; |
| 91 | + if (Array.isArray(current.approvals)) { |
| 92 | + const { kept, changed: listChanged } = purgeList( |
| 93 | + current.approvals, |
| 94 | + onPurge, |
| 95 | + ); |
| 96 | + if (listChanged) next.approvals = kept; |
| 97 | + } |
| 98 | + const providerModels = current.providerModels; |
| 99 | + if ( |
| 100 | + typeof providerModels === "object" && |
| 101 | + providerModels !== null && |
| 102 | + !Array.isArray(providerModels) |
| 103 | + ) { |
| 104 | + const map = providerModels as Record<string, unknown>; |
| 105 | + const nextMap: Record<string, unknown> = {}; |
| 106 | + let mapChanged = false; |
| 107 | + for (const [key, list] of Object.entries(map)) { |
| 108 | + const { kept, changed: listChanged } = purgeList(list, onPurge); |
| 109 | + nextMap[key] = listChanged ? kept : list; |
| 110 | + mapChanged = mapChanged || listChanged; |
| 111 | + } |
| 112 | + if (mapChanged) next.providerModels = nextMap; |
| 113 | + } |
| 114 | + if (changed === 0) return undefined; |
| 115 | + try { |
| 116 | + await writeFile(backupPath, JSON.stringify(current, null, 2), { |
| 117 | + flag: "wx", |
| 118 | + }); |
| 119 | + } catch (err) { |
| 120 | + if (!isFileExistsError(err)) { |
| 121 | + log.warn("Skipping approval-store migration for {path}: {error}", { |
| 122 | + path, |
| 123 | + error: err instanceof Error ? err.message : String(err), |
| 124 | + }); |
| 125 | + return undefined; |
| 126 | + } |
| 127 | + } |
| 128 | + purged = changed; |
| 129 | + rewrote = true; |
| 130 | + return next; |
| 131 | + }); |
125 | 132 | } catch (err) { |
126 | | - if (!isFileExistsError(err)) { |
127 | | - log.warn("Skipping approval-store migration for {path}: {error}", { |
128 | | - path, |
129 | | - error: err instanceof Error ? err.message : String(err), |
130 | | - }); |
131 | | - return { path, purged: 0 }; |
132 | | - } |
| 133 | + log.warn("Skipping approval-store migration for {path}: {error}", { |
| 134 | + path, |
| 135 | + error: err instanceof Error ? err.message : String(err), |
| 136 | + }); |
| 137 | + return { path, purged: 0 }; |
133 | 138 | } |
134 | | - await mkdir(dirname(path), { recursive: true }); |
135 | | - await writeFile(path, JSON.stringify(next, null, 2)); |
| 139 | + if (!rewrote) return { path, purged: 0 }; |
136 | 140 | return { path, purged, backupPath }; |
137 | 141 | } |
138 | 142 |
|
|
0 commit comments