Commit 67cafd8
fix(recovery): harden backup walker + master backup (audit follow-up)
Adversarial audit of the Phase 2 recovery subsystem surfaced three genuine
hardening gaps; fixed here.
BackupChainWalker:
- Stable selection on mtime ties — added an ordinal path tiebreaker so the chosen
(and the prospect "second-newest") backup is deterministic across runs instead of
relying on LINQ's unspecified ordering for equal timestamps.
- Empty/whitespace-only backups are never treated as a clean restore source (a
zero-byte sibling could otherwise be considered before the parse check).
RecoveryService.CreateMasterBackup:
- Rejects a master-backup directory that lives inside the profile folder (would zip
itself) — fails fast with ArgumentException.
- Builds the snapshot with a filtered ZipArchive that excludes IUUT's own .iuut-tmp-*
and .iuut-recovery-* artifacts (only the save data is captured), and skips a file
locked mid-recovery rather than aborting the whole snapshot.
- A zip failure now degrades to MasterBackupZipPath=null and recovery still proceeds
(per-file SafeSaveWriter backups remain the safety net) instead of crashing.
Audit findings deliberately NOT actioned (with reasons): recomputing a prospect blob
SHA-1 over corrupt bytes is not recovery (it would let the game load a logically-broken
world) — refusing → restore-from-backup is correct; the walker is already blob-aware
(the planner passes a prospect predicate that includes the SHA-1 check); the
plan→execute TOCTOU is bounded by SafeSaveWriter's post-write re-parse, which rejects
any backup that changed to invalid content.
Tests (4 new, 173 total, all green): empty backup never chosen; equal-mtime selection
is deterministic; master-backup dir inside the profile folder throws; the snapshot zip
excludes .iuut-tmp-* but contains the corrupt save.
Verified: dotnet build -c Release 0/0, dotnet test 173/173, dotnet format clean,
governance-lint clean.
Agent: claude-code/2.1.149
Consulted: AGENTS.md, .agent/CONSTITUTION.md#III, .agent/CODE_STYLE.md#3, .agent/TESTING_CONTRACT.md#2,#5, docs/IUUT-PROJECT-DOCUMENTATION.md#12.1,#7.6
Co-Authored-By: Claude <noreply@anthropic.com>1 parent 1503dd1 commit 67cafd8
4 files changed
Lines changed: 112 additions & 13 deletions
File tree
- src/IUUT.Core/Recovery
- tests/IUUT.Core.Tests/Integration
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
31 | 31 | | |
32 | 32 | | |
33 | 33 | | |
34 | | - | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
35 | 38 | | |
36 | 39 | | |
37 | 40 | | |
| |||
58 | 61 | | |
59 | 62 | | |
60 | 63 | | |
| 64 | + | |
61 | 65 | | |
62 | 66 | | |
63 | 67 | | |
| |||
70 | 74 | | |
71 | 75 | | |
72 | 76 | | |
| 77 | + | |
73 | 78 | | |
74 | 79 | | |
75 | 80 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
58 | 58 | | |
59 | 59 | | |
60 | 60 | | |
61 | | - | |
| 61 | + | |
62 | 62 | | |
63 | | - | |
64 | | - | |
65 | | - | |
66 | | - | |
67 | | - | |
68 | | - | |
69 | | - | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
70 | 68 | | |
71 | | - | |
72 | | - | |
| 69 | + | |
| 70 | + | |
73 | 71 | | |
74 | 72 | | |
75 | | - | |
76 | | - | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
77 | 119 | | |
78 | 120 | | |
79 | 121 | | |
| |||
Lines changed: 26 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
120 | 120 | | |
121 | 121 | | |
122 | 122 | | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
| 135 | + | |
| 136 | + | |
| 137 | + | |
| 138 | + | |
| 139 | + | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
123 | 149 | | |
124 | 150 | | |
Lines changed: 26 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
104 | 104 | | |
105 | 105 | | |
106 | 106 | | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
107 | 133 | | |
108 | 134 | | |
0 commit comments