Skip to content

sync: "Keep mine" no longer deletes files; hold syncs that would delete a large part of a save - #22

Open
ChakraFusion wants to merge 1 commit into
Liquid-co:mainfrom
ChakraFusion:pr/keep-mine-safety
Open

ChakraFusion wants to merge 1 commit into
Liquid-co:mainfrom
ChakraFusion:pr/keep-mine-safety

Conversation

@ChakraFusion

Copy link
Copy Markdown

Part of #21.

The bug

"Keep mine" (and "Keep both", which ends the same way) records every local file as shared with the peer before the peer has pulled any of it (persistLineage(local, local) in markResolvedLocal). If that pull doesn't finish (a large save, a timeout, the other PC going to sleep), the next sync sees files that were "shared before and are missing on the peer now". It reads them as the peer's deletions and deletes them on the device whose version the user just chose to keep.

On a Project Zomboid save (~240k files) this removed tens of thousands of files. Because the folders then differed again, the conflict came back, and answering "Keep mine" again repeated the deletion.

Reproduced by the new TestKeepLocal_PeerThatNeverPulled_DeletesNothingHere. On v2.4.1, the device keeping its 300-file save is left with 100 files.

The fix

  • markResolvedLocal records as shared only what both sides verifiably hold: the intersection of the two manifests. A file only this device has is new to the peer, not deleted by it. If the peer can't be asked, nothing is recorded as shared. Extra save locations (ResolveRootConflict) get the same fix.
  • Mass-deletion guard: a sync that would delete more than 100 files and more than 10% of a save, on either side, is held as a conflict instead of applied. A deletion confirmed on purpose (the existing emptied-folder flow, DeletionConfirmed / handOverEmptying) is not held. Either change alone makes the test above pass, and together they are defence in depth.
  • The conflict dialog says what each answer deletes. diffFiles is capped at 100, so counts taken from it were wrong on big saves: "Keep theirs" claimed a few dozen deletions and removed tens of thousands. The conflict now carries uncapped onlyLocalTotal / onlyRemoteTotal / changedTotal. The dialog says that "Keep mine"/"Keep both" delete nothing, and that "Keep theirs" deletes N files only this device has, shown in red when that is ≥100. A daemon without the new fields falls back to counting the capped list.

Tests

  • keeplocal_safety_test.go: the reproduction above.
  • partial_safety_test.go: an interrupted pull that is resumed, and a peer holding only part of a save, never turn into deletions.
  • massdelete_test.go: a large deletion is held for a decision, and ordinary small deletions still sync.
  • go test ./... passes; npm test and npm run build pass. CI run on the fork (all jobs green): https://github.com/ChakraFusion/OpenSave/actions/runs/37161965250

Not in this PR

ConflictModal.svelte isn't extracted for i18n yet, so the new strings are in English like the rest of that file. Happy to move them into the locale files if you'd prefer.

🤖 Generated with Claude Code

…te a large part of a save

"Keep mine" (and "Keep both", which ends the same way) recorded every local
file as shared with the peer before the peer had pulled any of it. When that
pull did not finish - a large save, a request that timed out, a device that
went away - the next sync read the files the peer was missing as deletions
made over there, and deleted them on the device whose version had just been
kept. On a save of ~240k files this removed tens of thousands; the folders
then differed again, the conflict came back, and the same answer did it
again.

- markResolvedLocal records as shared only what both sides verifiably hold
  (the intersection of the two manifests). A file only this device has is
  new to the peer, not deleted by it. If the peer cannot be asked, nothing
  is recorded as shared. Same for extra save locations
  (ResolveRootConflict).
- A sync that would delete more than 100 files and more than 10% of a
  save, on either side, is held as a conflict instead of applied. A deletion
  confirmed on purpose (the emptied-folder flow) is not held.
- The conflict carries uncapped counts of what differs (diffFiles stops at
  100), and the dialog says what each answer does: "Keep mine"/"Keep both"
  delete nothing; "Keep theirs" deletes N files only this device has, shown
  in red when that is many. Older builds without the counts fall back to
  counting the capped list.

TestKeepLocal_PeerThatNeverPulled_DeletesNothingHere fails on v2.4.1
(300 files -> 100); either change alone makes it pass.
Also adds tests that an interrupted pull or a peer holding part of a save
never turns into deletions.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@vercel

vercel Bot commented Oct 4, 2026

Copy link
Copy Markdown

@ChakraFusion is attempting to deploy a commit to the sivadaboi's projects Team on Vercel.

A member of the Team first needs to authorize it.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant