Add named and scoped checkpoint restore - #300
Conversation
|
Verdict: request changes F-1 [MAJOR] — Fix: validate |
|
Fixed in 6972470. Scoped restore patterns are now fully validated before the safety checkpoint is created, so traversal and no-match failures leave no stray checkpoint. The CLI also catches these validation errors and reports the normal ERROR message with exit code 1 instead of a traceback. Added regressions for both no-side-effect failures and the CLI error path. |
|
Updated review findings — merge blockers remain
|
|
Re-reviewed the current head (
The new traversal validation and malformed-metadata handling do address those portions of the earlier feedback. |
|
Addressed the latest blockers in fe46a88: scoped restore now rejects root/recovery paths and validates physical containment against symlinks/junctions before mutation. Regression suite: 13 checkpoint tests passed. |
|
Re-reviewed the latest head ( I found no remaining critical blocker. Good to merge. |
|
Follow-up PR: Consider rejecting a reparse point at the configured checkpoint root itself and bringing scoped restore's Windows locked-file handling to parity with the full restore path. These are additional hardening improvements, not blockers for this PR. |
Summary
Adds precise checkpoint restoration needed by resumable integration setup:
This is replacement PR 1 of the PR #290 split.
Validation
python -m pytest tests/scripts/test_checkpoint.py -q— 5 passedgit diff --check