2 months ago
c013390Add shared atomic_download helper that downloads to a temp file, validates size/digest, fsyncs, and atomically renames to the destination. No partial file is ever visible at a final path. Add atomic_database_pull for SQLite databases: downloads the candidate to a temp file, runs PRAGMA quick_check + foreign_key_check, verifies schema compatibility (songs table + hash column), fsyncs, preserves the current verified DB as openkara.db.lkg, then atomically renames the candidate into place. On corruption or incompatibility the working copy is left untouched and the last-known-good remains usable. Add dirty working-copy protection to the refresh/bootstrap path. Before any refresh that would overwrite openkara.db, consult the durable control DB repository state. Dirty/Publishing/Conflicted/ReauthRequired working copies are preserved — automatic pulls no longer overwrite committed local edits. On network failure the existing local DB is used without blocking startup. Refactor ensure_remote_file_cached to use atomic_download with a minimal existence+revision+size fast-path. The full verified cache catalog is PR#6. Add stale partial-file recovery to the startup recovery pass: recursively scan remote library working copies for *.part.* temp files and remove them. Add restart reconciliation: if a prior pull completed the rename but not the control-DB state update, the next refresh updates local_db_digest to match the now-active database. PR#1's stems path is NOT refactored to use atomic_download because the all-or-nothing set semantics require delaying the rename until every stem passes the cross-set alignment check. Using atomic_download per-stem would rename immediately and reintroduce the partial-set problem PR#1 fixed. A seam with rationale is left for a future helper split.
Parent1f0304e