Release Sized 2.0.0 on the pinned shared core #2

Open
gamertan wants to merge 11 commits from sizequeen-scan-hardening into main
38 changed files with 2972 additions and 333 deletions
+40
View File
@@ -0,0 +1,40 @@
name: Sized Linux checks
on:
push:
branches: [main, sizequeen-scan-hardening]
paths: ['Cargo.toml', 'Cargo.lock', 'CORE-SNAPSHOT.json', 'crates/**', 'src/**', 'tests/**', 'benches/**', 'scripts/**', '.gitea/workflows/**']
pull_request:
branches: [main]
paths: ['Cargo.toml', 'Cargo.lock', 'CORE-SNAPSHOT.json', 'crates/**', 'src/**', 'tests/**', 'benches/**', 'scripts/**', '.gitea/workflows/**']
workflow_dispatch:
permissions:
contents: read
jobs:
linux-amd64:
name: Linux AMD64 / Rust 1.88.0
# Keep the existing shared runner limited to owner-triggered, same-repo code.
if: ${{ gitea.actor == 'gamertan' && (gitea.event_name != 'pull_request' || gitea.event.pull_request.head.repo.full_name == gitea.repository) }}
runs-on: himesan-node24
timeout-minutes: 20
container:
image: sha256:271ca1d26057c95a6fd30df7ccc0c053ab394c0e81cd1e4efa182b5b0b60ee97
options: >-
--user 65532:65532
--tmpfs /tmp/sized-mount-test:rw,nosuid,nodev,noexec,size=16m,uid=65532,gid=65532,mode=0700
--tmpfs /tmp/sized-mount-test/foreign:rw,nosuid,nodev,noexec,size=16m,uid=65532,gid=65532,mode=0700
env:
CARGO_HOME: /tmp/sized-cargo
CARGO_BUILD_JOBS: '2'
SIZED_TEST_SOURCE: ${{ gitea.workspace }}
SIZED_TEST_MOUNT_ROOT: /tmp/sized-mount-test
steps:
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
with:
persist-credentials: false
- name: Unprivileged Linux tests, real mount boundary, Clippy and release smoke
run: ./scripts/check-linux-container.sh
- name: Require an unchanged checkout
run: test -z "$(git status --porcelain=v1 --untracked-files=all)"
+33
View File
@@ -5,6 +5,39 @@ All notable changes to this project will be documented in this file.
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/), The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/),
and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
## [2.0.0] - 2026-10-10
### Changed
- Use the exact shared core revision also pinned by SizeQueen, with a public
source snapshot and offline build inputs; the upstream forge stays private.
- Public Rust API and incomplete-scan exit-status changes are documented in
`docs/UPGRADING-2.md`. No private Git dependency is required.
- Distribute full dependency notices and matching vendored source alongside
platform-labelled packages. Mac delivery uses a signed, notarized disk image.
### Fixed
- Include the executable before creating release archives. Use explicit host
targets, build provenance and checksums; refuse existing outputs and symlinks.
- Replace stale installation links and unavailable package-manager claims with
verified Gitea availability and explicit source-build instructions.
- Count hard-link allocation once in a deterministic traversal order while
retaining apparent sizes per pathname. Filtered comparison has independent
allocation ownership, including when the first link is ignored.
- Report filesystem errors and incomplete ancestor totals instead of silently
dropping errors or treating vanished entries as accessible empty directories.
- Inherit ignore rules when scanning nested directories; accept dangling
symlinks as scan targets and distinguish special files from directories.
### Added
- Host archive extraction/executable checks on macOS and in Linux CI, plus
the Sized project page and its connection to SizeQueen's scanning core.
- A scanner module with structured reports, file identities, progress counters,
cooperative cancellation, and per-scan thread pools.
- Optional `-x` / `--one-file-system` boundary handling. Partial CLI reports
return a nonzero exit status and include `complete` in JSON output.
- Repeatable Linux ARM64/AMD64 Docker checks with unprivileged permission
tests, a real mounted-filesystem boundary and an optimized-binary smoke test.
## [1.0.0] - 2026-01-22 ## [1.0.0] - 2026-01-22
This stable release marks the official launch of `sized` under the GNU General Public License v3.0. This stable release marks the official launch of `sized` under the GNU General Public License v3.0.
+15
View File
@@ -0,0 +1,15 @@
{
"repository": "https://gitea.speelman.ca/gamertan/sized-core",
"revision": "fb63e96266dcb8ffbca53b73c6c0f738ac3e827d",
"files": {
"Cargo.toml": "c89c209b3a6cf08dd72eb9f80fabcd1f5686fecb457eecfc010db56f681bf645",
"LICENSE": "3972dc9744f6499f0f9b2dbf76696f2ae7ad8af9b23dde66d6af86c9dfb36986",
"README.md": "367d86ac8e21b7730d144d99fbf0e9f23c1050c40643e8be6e4cb5e59edf0b64",
"PROVENANCE.md": "0e640275d75ad33cadc2302245843fdfce6be17116110892a135089ea061ba15",
"examples/scan.rs": "33fb0c6ba090a0430c997229174482f261ffef64908f285f165307191a2b0a16",
"src/lib.rs": "b9cb7d71fb74f1005b61cf2e8dca0c3e9c97bc725ddb9d2c85b8b4dc912ed6c6",
"src/scan.rs": "a134f8f40bd0994f6ea332325e2b43ff47d558c42106135a951f2f8aa46be4ce",
"tests/linux_mount.rs": "e22bcc99a0b3bfe93ea9ab200e6312eb33390735e3b3b413aa904f45e6f8268a",
"tests/scanning.rs": "5fdb6ff3197aa24ceb2699f5787298b00ede69a87af07d7ca4fbdb911125a292"
}
}
Generated
+12 -4
View File
@@ -1182,7 +1182,7 @@ checksum = "e3a9fe34e3e7a50316060351f37187a3f546bce95496156754b601a5fa71b76e"
[[package]] [[package]]
name = "sized" name = "sized"
version = "1.0.0" version = "2.0.0"
dependencies = [ dependencies = [
"assert_cmd", "assert_cmd",
"byte-unit", "byte-unit",
@@ -1193,16 +1193,24 @@ dependencies = [
"comfy-table", "comfy-table",
"criterion", "criterion",
"csv", "csv",
"ignore",
"predicates", "predicates",
"rayon",
"serde",
"serde_json", "serde_json",
"sized-core",
"strum", "strum",
"tempfile", "tempfile",
"time", "time",
] ]
[[package]]
name = "sized-core"
version = "0.0.0"
dependencies = [
"ignore",
"rayon",
"serde",
"tempfile",
]
[[package]] [[package]]
name = "smallvec" name = "smallvec"
version = "1.15.1" version = "1.15.1"
+8 -5
View File
@@ -1,10 +1,12 @@
[package] [package]
name = "sized" name = "sized"
version = "1.0.0" version = "2.0.0"
edition = "2021" edition = "2021"
rust-version = "1.88"
description = "A modern, fast, and concurrent disk usage analyzer" description = "A modern, fast, and concurrent disk usage analyzer"
license = "GPL-3.0-only" license = "GPL-3.0-only"
repository = "https://gitlab.speelman.ca/gamertan/sized" repository = "https://gitea.speelman.ca/gamertan/sized"
homepage = "https://gamertan.com/projects/sized/"
readme = "README.md" readme = "README.md"
categories = ["command-line-utilities", "filesystem"] categories = ["command-line-utilities", "filesystem"]
@@ -30,13 +32,11 @@ assets = [
[dependencies] [dependencies]
clap = { version = "4.4", features = ["derive"] } clap = { version = "4.4", features = ["derive"] }
rayon = "1.8" scanner-core = { package = "sized-core", path = "crates/sized-core", version = "=0.0.0" }
colored = "2.0" colored = "2.0"
comfy-table = "7.0" comfy-table = "7.0"
byte-unit = "5.0" byte-unit = "5.0"
strum = { version = "0.25", features = ["derive"] } strum = { version = "0.25", features = ["derive"] }
ignore = "0.4"
serde = { version = "1.0", features = ["derive"] }
serde_json = "1.0" serde_json = "1.0"
csv = "1.3" csv = "1.3"
time = { version = "0.3", features = ["macros", "formatting"] } time = { version = "0.3", features = ["macros", "formatting"] }
@@ -53,3 +53,6 @@ criterion = "0.5"
name = "benchmark" name = "benchmark"
harness = false harness = false
[workspace]
members = ["crates/sized-core"]
resolver = "2"
+30 -9
View File
@@ -16,16 +16,22 @@
## Installation ## Installation
### From Binaries (Recommended) See the [README](README.md#installation) for signed Apple silicon Mac downloads,
Download the latest pre-compiled binaries from the [Releases](https://gitlab.speelman.ca/gamertan/sized/releases) page. Linux archives, checksums and source builds. The offline source archive includes
the exact shared core and registry dependencies, with no private forge login.
### From Source Rust 1.88 or newer and a C linker/toolchain are required for source builds:
```bash
git clone https://gitlab.speelman.ca/gamertan/sized.git ```sh
git clone --branch v2.0.0 https://gitea.speelman.ca/gamertan/sized.git
cd sized cd sized
make install # Installs binary and man page cargo install --locked --path .
``` ```
Cargo installs into `~/.cargo/bin`. To install the binary and man page together,
use `make install PREFIX="$HOME/.local"`. See [2.0 migration notes](docs/UPGRADING-2.md)
for changed exit statuses, accounting and public Rust APIs.
## Basic Usage ## Basic Usage
By default, `sized` analyzes the current directory recursively and displays a table of the immediate children. By default, `sized` analyzes the current directory recursively and displays a table of the immediate children.
@@ -35,9 +41,24 @@ sized [path]
``` ```
### Key Concepts ### Key Concepts
- **Disk Usage** (Default): The actual physical space consumed on disk (Blocks * 512 bytes). This is the "true" footprint and the metric `sized` prioritizes. - **Disk Usage** (Default): Filesystem-reported allocation (Blocks * 512 bytes), with hard links counted once per scan. Shared extents and snapshots can make this differ from the space recovered by deletion.
- **Apparent Size**: The logical size of the entry (file length). Available via the `-a` or `--apparent` flag. - **Apparent Size**: The logical size of the entry (file length). Available via the `-a` or `--apparent` flag.
- **Blocks**: The actual filesystem blocks allocated. - **Blocks**: Filesystem-reported 512-byte units of allocation. Directory metadata is included.
Symlinks are scanned as leaves, including dangling links; their targets are not
followed. Missing targets or unreadable entries are reported on stderr. Partial
scans return a nonzero exit status and JSON includes `complete: false`; inspect
that status before relying on a total.
### Filesystem Boundary (`-x` / `--one-file-system`)
Skip entries whose device differs from the scan root, useful when a directory
contains mounted filesystems. Boundary entries contribute no size, and JSON
marks them with `skipped_mount`.
```bash
sized -x /path/to/volume
```
### Path Display ### Path Display
- **Relative Path** (Default): `sized` shows paths relative to the current directory. - **Relative Path** (Default): `sized` shows paths relative to the current directory.
@@ -53,7 +74,7 @@ sized -d 1
``` ```
> [!NOTE] > [!NOTE]
> Regardless of the display depth, `sized` always calculates the *total* size of all subdirectories accurately by traversing the entire tree. > Display depth limits output, not scanning. The tree is traversed unless filtered or excluded by a filesystem boundary; scan errors mark totals incomplete.
## Filtering and Sorting ## Filtering and Sorting
+1 -1
View File
@@ -7,7 +7,7 @@ MANDIR = $(PREFIX)/share/man/man1
all: build all: build
build: build:
cargo build --release cargo build --locked --release
install: build install: build
install -d $(BINDIR) install -d $(BINDIR)
+103 -52
View File
@@ -1,11 +1,20 @@
# Sized # Sized
A fast, concurrent, and feature-rich command-line tool for visualizing disk usage, written in Rust. **Know what’s taking up space. Without leaving your terminal.**
Sized is a Rust command-line disk usage tool for macOS and Linux. Inspect large
folders, filter the noise, and export reports for your own scripts.
[Project page](https://gamertan.com/projects/sized/) ·
[Prefer a visual map? Meet SizeQueen](https://gamertan.com/projects/sizequeen/).
**Version 2.0.0** shares the pinned Sized core used by SizeQueen. Hard links,
partial scans and filesystem boundaries have explicit accounting and status.
See [upgrading from 1.0](docs/UPGRADING-2.md) for CLI and Rust API changes.
## Features ## Features
- **Physical by Default**: Prioritizes **Disk Usage** (actual blocks consumed) as the default metric, essential for accurately seeing how much storage is actually gone. - **Allocation by Default**: Prioritizes filesystem-reported allocated blocks; sparse files retain their separate apparent size, and hard-link allocation is counted once per scan. Reported allocation is not a promise of bytes freed by deletion on filesystems with shared extents or snapshots.
- **Fast & Concurrent**: Uses `rayon` to process directories in parallel, making it extremely fast on modern multi-core systems. - **Fast & Concurrent**: Processes directories in parallel with `rayon`; scan time depends on the filesystem and workload.
- **Rich Output**: Beautifully formatted tables with colors, distinguishing files and directories. - **Rich Output**: Beautifully formatted tables with colors, distinguishing files and directories.
- **Apparent Size**: Toggle logical file length with `-a` or `--apparent`. - **Apparent Size**: Toggle logical file length with `-a` or `--apparent`.
- **Unit Selection**: Switch between Binary (IEC) and Decimal (SI) unit systems via `--units`. - **Unit Selection**: Switch between Binary (IEC) and Decimal (SI) unit systems via `--units`.
@@ -18,55 +27,48 @@ A fast, concurrent, and feature-rich command-line tool for visualizing disk usag
## Installation ## Installation
### 🚀 Direct Download (macOS & Linux) ### Official downloads
Download the latest archive for your architecture from the [Releases](https://gitlab.speelman.ca/gamertan/sized/releases) page.
1. **Extract the archive**: Use the [Sized project page](https://gamertan.com/projects/sized/) or
```bash [v2.0.0 release](https://gitea.speelman.ca/gamertan/sized/releases/tag/v2.0.0).
tar -xzf sized-v1.0.0-Darwin-arm64.tar.gz Choose the archive for your CPU and OS. The Apple silicon download is a signed,
``` notarized DMG; Linux archives target glibc 2.36 or newer. Matching offline source,
full dependency notices and SHA-256 checksums accompany the downloads.
2. **Install Binary & Man Page**: Open the Mac disk image, or extract the Linux archive. From its directory, install
```bash without administrator privileges:
# Move binary to path
sudo mv sized /usr/local/bin/
# Install man page ```sh
sudo mkdir -p /usr/local/share/man/man1 mkdir -p "$HOME/.local/bin" "$HOME/.local/share/man/man1"
sudo cp sized.1 /usr/local/share/man/man1/ install -m 755 sized "$HOME/.local/bin/sized"
``` install -m 644 sized.1 "$HOME/.local/share/man/man1/sized.1"
"$HOME/.local/bin/sized" --version
3. **macOS Security (Gatekeeper)**:
Since the binary isn't code-signed for the App Store, macOS may block it. To allow it:
```bash
sudo xattr -d com.apple.quarantine /usr/local/bin/sized
```
*Alternatively, run `sized` once, let it fail, then go to **System Settings > Privacy & Security** and click **"Allow Anyway"**.*
### 🍺 Homebrew (macOS & Linux)
If you have a homebrew tap:
```bash
brew install gamertan/tap/sized
``` ```
### 📦 Debian / Ubuntu (.deb) Include `~/.local/bin` in your `PATH`. On a Mac, the mounted directory is
1. Download the `.deb` package from the [Releases](https://gitlab.speelman.ca/gamertan/sized/releases) page. `/Volumes/Sized 2.0.0`; this is a Terminal tool rather than an application icon.
2. Install using `dpkg`: The archive also includes Bash, Zsh and Fish completions. No Homebrew tap or
```bash Debian package is currently published. Intel Mac and Windows binaries are not
sudo dpkg -i sized_1.0.0_amd64.deb part of this release.
```
### 🦀 From Source (Rust toolchain required) ### Build from source
```bash
git clone https://gitlab.speelman.ca/gamertan/sized.git With Rust 1.88 or newer and a C linker/toolchain installed:
```sh
git clone --branch v2.0.0 https://gitea.speelman.ca/gamertan/sized.git
cd sized cd sized
make install # Installs binary and man page cargo install --locked --path .
sized --help
``` ```
Alternatively, via Cargo: The public checkout includes the exact core snapshot; no private credentials are
```bash needed. The matching source archive additionally includes registry dependencies:
cargo install --path . from its root, `cargo build --locked --offline --release` works without Cargo
``` network access. Source builds are unsigned unless you sign them yourself.
`make install PREFIX="$HOME/.local"` installs the binary and man page together.
Historical [v1.0.0 files](https://gitea.speelman.ca/gamertan/sized/releases/tag/v1.0.0)
remain available unchanged.
## Documentation ## Documentation
- **[Manual](MANUAL.md)**: Detailed explanations of all flags and features. - **[Manual](MANUAL.md)**: Detailed explanations of all flags and features.
@@ -98,6 +100,7 @@ sized /path/to/directory
| `-f`, `--path-full` | Force absolute paths in headers | `sized -f` | | `-f`, `--path-full` | Force absolute paths in headers | `sized -f` |
| `-i`, `--ignore` | Respect .gitignore files | `sized -i` | | `-i`, `--ignore` | Respect .gitignore files | `sized -i` |
| `-j`, `--threads` | Set number of threads | `sized -j 4` | | `-j`, `--threads` | Set number of threads | `sized -j 4` |
| `-x`, `--one-file-system` | Skip entries on other filesystems | `sized -x /` |
| `--format` | Output format (text, csv, json) | `sized --format json` | | `--format` | Output format (text, csv, json) | `sized --format json` |
| `--save` | Save output to file | `sized --save` | | `--save` | Save output to file | `sized --save` |
| `-c`, `--compare` | Compare total vs. non-ignored files | `sized -i -c` | | `-c`, `--compare` | Compare total vs. non-ignored files | `sized -i -c` |
@@ -137,17 +140,65 @@ autoload -Uz compinit && compinit
sized --completions fish > ~/.config/fish/completions/sized.fish sized --completions fish > ~/.config/fish/completions/sized.fish
``` ```
## Scan status and library API
Scans report missing or unreadable entries on stderr and return a nonzero status
when incomplete. JSON reports include `complete` so automation can distinguish
a partial report from a fully scanned tree. Symlinks are not followed.
Library users can call `scan_tree` with `ScanOptions` and a fresh `ScanControl`
for each request. Clones of the control expose progress and cancellation;
cancellation is cooperative between filesystem calls. `build_tree` remains as
a convenience helper, while `scan_tree` retains structured diagnostics.
## Development checks
Run `cargo test --locked --workspace` locally as an unprivileged user. For Linux build,
permission, filesystem-boundary and release smoke checks with Docker:
```bash
./scripts/check-linux.sh linux/arm64
./scripts/check-linux.sh linux/amd64
```
The script pins the official Rust 1.88.0 Bookworm image by digest, adds rustfmt
and Clippy, then runs as UID 65532 with dropped capabilities. Source is mounted
read-only and copied into the temporary container. Fixtures live on Linux
filesystems, including two distinct tmpfs mounts; no privileged container or
host directory scan is required. AMD64 on an ARM64 host requires emulation.
Logs are saved in `target/linux-checks/`; containers and their build output are
removed on exit. Docker retains the reusable check images/build cache.
`SIZED_LINUX_JOBS` changes the default two build workers; `SIZED_LINUX_IMAGE`
can select a different toolchain image for an explicit compatibility check.
These are backend checks; desktop X11/Wayland acceptance belongs to SizeQueen.
Gitea's `Sized Linux checks` workflow runs the same checks natively on cliff-mads
for main/review-branch source changes and owner-triggered, same-repository PRs.
It uses a pinned Rust job image, UID 65532 and real tmpfs boundaries without
Docker access inside the job. Fork contributions can run the local script;
maintainers can bring reviewed changes onto a repository branch for CI.
See SHIPMENT for runner-image setup. Documentation-only pushes skip builds.
Run `./scripts/check-release.sh` to verify the actual archive, checksum and
extracted executable on the host. Linux CI also runs this packaging check.
See [source review and release process](SHIPMENT.md) and the [live queue](TODO.md).
## Sized, SizeQueen and the shared scanner
Sized began as terminal tooling. Its filesystem scanner was extracted into
`sized-core`, which SizeQueen now uses directly beneath its native Mac interface.
SizeQueen adds the treemap and desktop interactions; it does not run the CLI.
Sized 2.0 uses the same pinned core revision through the exact public snapshot
in `crates/sized-core`. `CORE-SNAPSHOT.json` records its provenance and hashes.
The upstream core repository remains private; public Sized and both products'
matching source downloads build without access to it.
## License ## License
This project is licensed under the **GNU General Public License v3.0 (GPL-3.0)**. **GPL-3.0-only.** See [LICENSE](LICENSE) for the complete terms. All Sized features
are free; optional [support for Gamertan](https://gamertan.com/store/) does not
### Why GPL-3.0? (The "Insulin" Philosophy) unlock features.
We believe that core diagnostic tools like `sized` should remain a public good. Inspired by the philosophy behind open-access medicine like insulin, this license ensures that:
- The tool remains **free and open** for everyone to use.
- Any improvements or forks made by others **must also be shared** with the community.
- It prevents proprietary "vampire" versions from taking private credit for public efforts.
For more details, see the [LICENSE](LICENSE) file.
## Contributing ## Contributing
+127 -23
View File
@@ -2,6 +2,67 @@
This document defines the process for versioning and distributing the `sized` project independently of the Git hosting provider (GitHub, GitLab, Gitea). This document defines the process for versioning and distributing the `sized` project independently of the Git hosting provider (GitHub, GitLab, Gitea).
## Source review before a release
Use a named branch from `main` and keep a pull request focused on one outcome.
The `sizequeen-scan-hardening` branch corrects accounting/error handling and
adds the scan controls needed by SizeQueen; the scanner has also been
extracted into private `sized-core` for SizeQueen. Sized 2.0 includes its exact
pinned source snapshot as a path dependency. Verify `CORE-SNAPSHOT.json` before
packaging; no private Git fetch is part of a public build.
1. Run local locked tests and strict Clippy as an unprivileged user. Run
`./scripts/check-linux.sh linux/arm64` and
`./scripts/check-linux.sh linux/amd64` for the repeatable Linux checks,
including actual mount boundaries and an optimized-binary smoke test.
2. Push the review branch. Open a PR against `main` when its scope is ready,
explaining changed behaviour, test evidence and remaining limits. For this
branch, call out nonzero status on partial scans, added JSON status fields,
and library API changes. Record current work and evidence in `TODO.md`.
3. Review and merge independently of distribution. A branch push or PR merge
does not publish a package, change repository visibility or create a tag.
4. Choose the release version after reviewing library/API compatibility, then
use the release steps below when explicitly authorized. Verify the exact archive
contents, target and installation instructions before announcing a release.
### Gitea Linux CI
`.gitea/workflows/linux.yml` uses the existing `himesan-node24` label on
cliff-mads, overriding the job image with the pinned Sized Rust runtime.
The runner itself launches the two tmpfs mounts. Jobs have no Docker socket
and run `scripts/check-linux-container.sh` as UID 65532, using the checked-out
workspace as `SIZED_TEST_SOURCE`. Its tests, strict Clippy, formatting and
optimized-binary smoke test and extracted release-archive verification are the
same as the local Docker workflow.
The runtime contains Rust 1.88.0, rustfmt/Clippy and Node for the pinned checkout
action. On cliff-mads, rebuild it explicitly with:
```bash
ssh cliff-mads 'docker build --platform linux/amd64 --tag local/gamertan-ci:sized-rust188 -' < scripts/gitea-linux.Dockerfile
ssh cliff-mads 'docker image inspect local/gamertan-ci:sized-rust188 --format "{{.Id}}"'
```
Review and update the workflow's image ID after an intentional rebuild; images
stay local to the runner host. The image pre-owns `/workspace/gamertan/sized`
for UID 65532 so the runner's workspace setup permits unprivileged checkout.
No runner labels, global isolation settings or
publishing credentials are required. Repository Actions must be enabled.
Only owner-triggered, same-repository code runs on this shared homelab runner.
Source changes on main/the review branch and PRs to main trigger checks;
documentation-only pushes skip builds. Manual dispatch is also available.
This workflow does not publish or tag releases.
The first complete native AMD64 push check is
[Gitea run 1048 (number 2)](https://gitea.speelman.ca/gamertan/sized/actions/runs/1048),
at `74b30bbf750417121f3b0c26017d2f011a2a8286`. All 23 tests, formatting, strict
Clippy, release smoke and unchanged-checkout verification passed as UID 65532
on `cliff-himesan-linux-amd64`. The packaging source checkpoint `77b11a8`
subsequently passed [push run 1065](https://gitea.speelman.ca/gamertan/sized/actions/runs/1065)
and [PR run 1066](https://gitea.speelman.ca/gamertan/sized/actions/runs/1066),
including executable/archive checks and output/symlink refusal. Manual dispatch
is configured but not independently exercised. See `TODO.md` for current work.
## 1. Versioning and Tagging ## 1. Versioning and Tagging
The project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). The project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
@@ -10,43 +71,86 @@ The project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html
2. Update `CHANGELOG.md` with the release notes. 2. Update `CHANGELOG.md` with the release notes.
3. Commit and create a git tag: 3. Commit and create a git tag:
```bash ```bash
git tag -a v1.0.0 -m "Release v1.0.0" git tag -a v2.0.0 -m "Release Sized 2.0.0"
``` ```
## 2. Asset Generation ## 2. Asset generation and verification
The `scripts/release.sh` script is the authoritative way to generate release assets locally or in any CI environment.
```bash ```bash
./scripts/check-release.sh
./scripts/release.sh ./scripts/release.sh
``` ```
This script generates: `release.sh` uses the locked dependencies and the Rust toolchain's host target.
- **Optimized Binary**: The production-ready `sized` executable. It packages the executable **before** creating the archive, together with the
- **Documentation**: The `sized.1` man page. man page, Bash/Zsh/Fish completions, licence, README, manual and build metadata.
- **Shell Completions**: Scripts for Bash, Zsh, and Fish. Outputs are `dist/sized-v<VERSION>-<RUST-TARGET>-<REVISION>/`, a sibling `.tar.gz`
- **System Installers**: A `.deb` package for Debian-based Linux distributions. and `.tar.gz.sha256`, including complete dependency notices. Existing outputs are never replaced. Use
`--output-dir /absolute/new/path` for an explicitly named local candidate.
`CARGO_TARGET_DIR` is respected. The script does not sign, upload, tag or publish.
All assets are gathered in the `dist/v<VERSION>/` directory. `check-release.sh` creates temporary outputs, extracts the archive, checks all
required files and the checksum, then runs the packaged executable against an
owned fixture. It also checks the refusal to overwrite. Gitea's Linux check
runs this same test; a successful compile alone is insufficient.
## 3. Distribution Channels Only build from a clean, reviewed commit for distribution. `BUILD-INFO.txt`
records the commit, target, toolchain and whether tracked inputs were modified.
Exported source can provide `SIZED_SOURCE_REVISION`; verify that provenance
against the original checkout. Retain matching source and complete dependency
licences with any public binary distribution. A host build is unsigned; do not
advertise it as notarized or as a Mac App Store application.
### crates.io ### Matching source and Mac delivery
To update the project on the central Rust registry:
```bash From a clean committed source checkpoint, run:
cargo publish
```sh
scripts/package-source.sh /absolute/new/release-directory
``` ```
### System Package Managers This exports tracked source, includes all locked registry dependencies, verifies
For Homebrew, GitLab, or Gitea-based distribution: an empty-cache offline build, and retains the exact source archive. Build the
1. Push the git tag to your SCM. binaries from that exported `sized-source` directory with
2. Run the release script to generate assets. `CARGO_NET_OFFLINE=true` and `SIZED_SOURCE_REVISION` set to `SOURCE-REVISION.txt`.
3. Attach the contents of the `dist/` folder to your SCM's "Release" or "Tag" entry. Linux release checks can retain an archive when `SIZED_RELEASE_DIR` names a
4. Update downstream formulas (like `homebrew-tap`) with the new source URL and SHA256 of the generated tarball. writable output mount. Run on the architecture being released; keep both tmpfs
boundary mounts and UID 65532. This does not publish files.
## 4. Automation & Hooks For Mac, use `scripts/notarize-macos.sh PACKAGE_DIRECTORY NEW_DMG_PATH` with an
explicit `SIZED_SIGN_IDENTITY`. It signs the CLI and disk image, submits through
`SIZED_NOTARY_PROFILE` (default `sizequeen-notary`), staples and validates the
DMG. The notarization receipt stays with private build evidence. Distribute the
DMG; a raw command-line executable cannot carry a stapled ticket. Compute final
checksums only after signing/stapling, then exercise the mounted signed CLI and
verify the downloaded files. See Apple's
[custom workflow guidance](https://developer.apple.com/documentation/security/customizing-the-notarization-workflow).
To automate asset generation locally, you can use a git `post-checkout` or a wrapper script. Since gitea and gitlab use different CI formats, it is recommended to simply call `./scripts/release.sh` within your preferred CI runner (e.g., `gitlab-ci.yml` or `gitea-actions`). Publish versioned files on the Gitea release and link them from the existing
Gamertan CMS project. Keep forge privacy settings unchanged. Retain the exact
matching source and never overwrite a published asset with different bytes.
## 3. Distribution channels
The existing public Gitea v1.0.0 release contains a macOS arm64 executable,
man page and completions, plus generated source archives. It predates the
scanner hardening branch. No architecture-labelled binary archive, `.deb` or
verified Homebrew tap is currently offered.
Future public releases need their own reviewed version, source, target-specific
archives, checksums and installation acceptance. Do not replace historical
v1.0.0 assets with newly built bytes. Add a new version only after review.
Debian/Alpine packaging is separate from the portable host archive. Do not
implicitly invoke `cargo deb` or `abuild` just because they are installed: a Mac
binary is not a Debian package. Validate each installer on its target OS before
publishing it. Registry and Homebrew publication are separate decisions too.
## 4. Automation
CI tests and packages temporary candidates without publishing credentials.
Do not run release generation automatically from Git hooks. Publication remains
an intentional operation after the checks above.
## 5. Manual Installation ## 5. Manual Installation
For system-wide installation from source, use the `Makefile`: For system-wide installation from source, use the `Makefile`:
+169
View File
@@ -0,0 +1,169 @@
# Live queue
## Current scope
Harden Sized for reuse by the native SpaceMonger-inspired SizeQueen project.
The user authorized fixes and updates discovered during that investigation.
Keep the existing CLI useful and preserve the GPL-3.0-only license.
- [x] Correct allocated-size totals for hard links; retain apparent per-path
sizes and define deterministic ownership within each scan.
- [x] Preserve scan errors and expose incomplete results instead of silently
treating missing paths as accessible empty directories.
- [x] Expose cancellable scans, progress counters, per-scan worker selection,
and an optional filesystem boundary for the native UI.
- [x] Add accounting and control regressions; run the existing CLI tests and
compare bounded release-build scan measurements.
- [x] Run reproducible Linux ARM64 and AMD64 Docker checks as an unprivileged
user, including actual mount boundaries, strict Clippy and a release smoke test.
- [x] Commit the scanner hardening and Linux check tooling; push the existing
`sizequeen-scan-hardening` review branch. Remote equality is verified.
PR #2 is open; release/tag/package publication remains separate.
- [x] Enable repository Actions and run the same Linux checks on the existing
cliff-mads runner. Keep its container isolation and other jobs unchanged;
verify a real workflow result before treating CI as proven.
## Approved project page and release cleanup
The owner approved a Sized project page in the shared Gamertan CMS, truthful
installation/release guidance, packaging repairs, and a Built on Sized section
on SizeQueen. Website delivery is tracked in that repository's existing queue.
- [x] Inspect the public v1.0.0 assets; the unlabelled executable is macOS arm64,
ad hoc signed, SHA-256 `50fde4d8215babbb64f4a4f55e030dd5c941a97ed1bedfa80392e4301c52d2bf`.
There are no attached Linux binaries, labelled archives or Debian packages.
- [x] Replace stale GitLab/unsupported package-manager installation claims with
explicit review-branch source builds; explain the published release boundary.
- [x] Package the executable before the archive; include licence/docs/build
provenance, target-labelled names and checksums. Reject output replacement.
Remove incidental installer generation; host binaries must not become `.deb`s.
- [x] Verify archive contents/checksum, run the extracted CLI and test overwrite
refusal on macOS arm64. Add the same verification to Linux CI.
- [x] Verify the updated cliff-mads workflow, push the review checkpoint and
record the public CMS delivery. PR #2 is open; no new version, release assets
or merge. Historical v1.0.0 notes are corrected and asset bytes preserved.
## Approved Sized 2.0.0 release
The owner authorizes pinned core adoption, the public source snapshot while
keeping the core forge private, and merge/push/publication after checks pass.
- [ ] Replace the local scanner with the exact SizeQueen core pin, verify snapshot
hashes and review the CLI/API migration and 2.0 compatibility notes.
- [ ] Verify Mac arm64 and Linux binaries, source rebuilds without forge access,
dependency notices, package contents and installation. Sign/notarize the Mac DMG.
- [ ] Merge PR #2, tag 2.0.0, publish immutable binary/source assets and update the
shared CMS project. Verify downloaded bytes and record release evidence.
Windows, additional features and package-manager registries remain deferred.
## Resume note
Current: preparing the approved 2.0.0 migration and release above. No 2.0.0
assets or tag have been published yet. Previous delivery evidence follows.
The approved Sized project page and release cleanup are delivered. Source
checkpoint `77b11a8c29b5ca3435fdd962717f8e8285abe972` is pushed on
`sizequeen-scan-hardening`; [PR #2](https://gitea.speelman.ca/gamertan/sized/pulls/2)
is open against unchanged `main`. Repository visibility remains public.
Final cliff-mads checks passed for both events:
[push run 1065](https://gitea.speelman.ca/gamertan/sized/actions/runs/1065)
(4m 57s) and
[PR run 1066](https://gitea.speelman.ca/gamertan/sized/actions/runs/1066)
(5m 0s). Rust 1.88.0 / Linux AMD64 / UID 65532 passed all 23 tests, formatting,
strict Clippy, optimized smoke, archive extraction/checksum/executable and
existing-output/dangling-symlink guards, plus unchanged-checkout verification.
Mac arm64 passed the same package checks and documented Cargo/Make installs into
temporary prefixes. Ignored local evidence is in `target/release-audit/`,
including `gitea-run-1065.txt`, `package-macos.log` and `install-macos.log`.
[Sized](https://gamertan.com/projects/sized/) is published through the shared
Gamertan project template (CMS revision 6), with a compact status sidebar,
verified synthetic CLI example, source instructions and accurate release limits.
It appears on the homepage, project index and sitemap. SizeQueen's
[Built on Sized section](https://gamertan.com/projects/sizequeen/) is published
in revision 14; all prior sections and app downloads are preserved. Desktop
and 320px mobile checks passed. Website evidence and recovery are recorded in
`../gamertancom-web-foundations/docs/PRODUCTION_SANDBOX_2026-09-04.md` under
“Sized project and Built on Sized — 10 October 2026”.
Historical v1.0.0 release notes now identify the attached executable as macOS
arm64 and distinguish the newer review branch. Asset IDs, lengths and executable
SHA-256 above remain unchanged. No new binary release, tag, merge or private-core
source publication occurred. Next: review PR #2's CLI exit status, JSON and
library API changes, then choose a release version and complete corresponding
source/dependency notices before authorizing new binary publication.
### Earlier verification history
The records below describe previous checkpoints; current delivery and next
actions are above.
Previous CI checkpoint: repository Actions is enabled and a real native AMD64
push run passed on cliff-mads. [Gitea run 1048 (number 2)](https://gitea.speelman.ca/gamertan/sized/actions/runs/1048)
tested `74b30bbf750417121f3b0c26017d2f011a2a8286` on
`cliff-himesan-linux-amd64` (`gitea-runner v3.1.0`): all 23 tests, formatting,
strict Clippy, optimized-binary smoke and unchanged-checkout verification passed
as UID 65532 with Rust 1.88.0. It finished in 3m 30s. Filtered local evidence is
in ignored `target/linux-checks/gitea-run-1048.log`; full logs remain in Gitea.
The initial checkout failed because the repository directory was root-owned;
the corrected runtime pre-owns it for the job user. The workflow reuses the
existing `himesan-node24` label and a local, pinned Rust/Node image. Runner
configuration, other jobs and repository visibility are unchanged. Temporary
setup credentials were revoked and their files removed. Push execution is
proven; PR execution was subsequently proven in run 1066; manual dispatch remains
configured but not independently exercised.
Linux validation and the requested remote review branch are complete.
Scanner hardening is `8b177e2`; repeatable Linux checks and equivalent format
interpolations are `988aad9`. Both implementation commits are pushed to
`origin/sizequeen-scan-hardening`, followed by CI setup `67fe175` and the
unprivileged checkout fix `74b30bb`. The source checkpoint is verified remotely
at `74b30bbf750417121f3b0c26017d2f011a2a8286`; later documentation-only
checkpoint commits do not rerun the source checks. Gitea main remains `9c8d1d4`.
The repository was already public (`private: false`); visibility is unchanged.
At that checkpoint, no PR, merge, tag, package publication or release occurred.
`scripts/check-linux.sh` owns the container workflow. Linux ARM64 (native in
Docker's VM) and AMD64 (emulated on this Mac) each passed 23 tests as UID 65532:
5 library, 6 CLI, 11 scan integrations and one explicitly enabled real-mount
integration. `tests/linux_mount.rs` checks two distinct tmpfs devices through
the library and CLI, with boundaries enabled and disabled. Formatting, strict
all-target Clippy and an optimized-binary fixture smoke test passed on both.
Mac passed its 22 applicable tests, formatting and strict Clippy. Commands are
documented in README/SHIPMENT; full local logs are in ignored
`target/linux-checks/{arm64,amd64}.log`. Cargo.lock and unrelated `.DS_Store`
hashes are unchanged; only source inputs and owned fixtures enter the checks.
Rust 1.88 Clippy identified format-string style warnings; equivalent
interpolations fix those without suppressions. SizeQueen's included scanner
still matches `8b177e2` exactly; the follow-up changes only one scanner Display
format string, not scan behaviour. SizeQueen itself was unchanged in this pass.
The planned PR and packaging repairs are now complete; review and version
selection remain next. These checks do not prove desktop X11/Wayland interaction,
Windows allocation or performance on very large/cold/remote trees.
Previous local checkpoint: baseline `9c8d1d4` matched Gitea main;
branch `sizequeen-scan-hardening`.
All six baseline tests passed. SizeQueen's independent probe reproduced
hard-link overcount and missing-path misclassification, and confirmed sparse
allocation, symlink leaf handling, and hidden-file inclusion. Source inspection
found discarded walker errors and no scan control API. These scoped corrections
are implemented locally, with no push, tag, or release. `cargo test --locked`
passed 22 tests (5 library, 6 CLI, 11 scan integrations); strict all-target
Clippy passed. The independent SizeQueen probe passed 6 accounting tests.
Man page was regenerated. Cargo.lock is unchanged and unrelated `.DS_Store`
was preserved.
Release probes on the Mac took 49–56ms for 20,000 files; sorting, identity
tracking, diagnostics and control cost more than the baseline (29–39ms for
the grouped tree). Inline Node size grew from 88 to 136 bytes; whole-process
peak RSS was about 8.2MiB grouped / 16.7MiB wide. These are bounded warm-metadata
fixtures, not evidence for million-entry, cold-disk, or remote-filesystem speed.
Cancellation is cooperative between filesystem calls. Allocation is reported
blocks, not guaranteed bytes recoverable from shared extents or snapshots.
Detailed audit and bounded probes are maintained in the sibling SizeQueen
project at `../sizequeen/research/SIZED-AUDIT.md`; that project's product queue
remains separate from this backend's fix queue.
+3 -3
View File
@@ -10,12 +10,12 @@ fn setup_test_dir() -> TempDir {
// Create a moderately deep structure // Create a moderately deep structure
for i in 0..10 { for i in 0..10 {
let dir_path = base_path.join(format!("dir_{}", i)); let dir_path = base_path.join(format!("dir_{i}"));
fs::create_dir(&dir_path).unwrap(); fs::create_dir(&dir_path).unwrap();
for j in 0..10 { for j in 0..10 {
let file_path = dir_path.join(format!("file_{}.txt", j)); let file_path = dir_path.join(format!("file_{j}.txt"));
let mut file = File::create(file_path).unwrap(); let mut file = File::create(file_path).unwrap();
writeln!(file, "Some content for file {}-{}", i, j).unwrap(); writeln!(file, "Some content for file {i}-{j}").unwrap();
} }
} }
temp_dir temp_dir
+22
View File
@@ -0,0 +1,22 @@
[package]
name = "sized-core"
version = "0.0.0"
edition = "2021"
rust-version = "1.88"
description = "Shared Unix filesystem scanner for Sized and SizeQueen"
license = "GPL-3.0-only"
repository = "https://gitea.speelman.ca/gamertan/sized-core"
readme = "README.md"
publish = false
# Preserve the existing import name used by the included SizeQueen snapshot.
[lib]
name = "sized"
[dependencies]
ignore = "0.4.25"
rayon = "1.11"
serde = { version = "1.0.228", features = ["derive"] }
[dev-dependencies]
tempfile = "=3.24.0"
+674
View File
@@ -0,0 +1,674 @@
GNU GENERAL PUBLIC LICENSE
Version 3, 29 June 2007
Copyright (C) 2007 Free Software Foundation, Inc. <https://fsf.org/>
Everyone is permitted to copy and distribute verbatim copies
of this license document, but changing it is not allowed.
Preamble
The GNU General Public License is a free, copyleft license for
software and other kinds of works.
The licenses for most software and other practical works are designed
to take away your freedom to share and change the works. By contrast,
the GNU General Public License is intended to guarantee your freedom to
share and change all versions of a program--to make sure it remains free
software for all its users. We, the Free Software Foundation, use the
GNU General Public License for most of our software; it applies also to
any other work released this way by its authors. You can apply it to
your programs, too.
When we speak of free software, we are referring to freedom, not
price. Our General Public Licenses are designed to make sure that you
have the freedom to distribute copies of free software (and charge for
them if you wish), that you receive source code or can get it if you
want it, that you can change the software or use pieces of it in new
free programs, and that you know you can do these things.
To protect your rights, we need to prevent others from denying you
these rights or asking you to surrender the rights. Therefore, you have
certain responsibilities if you distribute copies of the software, or if
you modify it: responsibilities to respect the freedom of others.
For example, if you distribute copies of such a program, whether
gratis or for a fee, you must pass on to the recipients the same
freedoms that you received. You must make sure that they, too, receive
or can get the source code. And you must show them these terms so they
know their rights.
Developers that use the GNU GPL protect your rights with two steps:
(1) assert copyright on the software, and (2) offer you this License
giving you legal permission to copy, distribute and/or modify it.
For the developers' and authors' protection, the GPL clearly explains
that there is no warranty for this free software. For both users' and
authors' sake, the GPL requires that modified versions be marked as
changed, so that their problems will not be attributed erroneously to
authors of previous versions.
Some devices are designed to deny users access to install or run
modified versions of the software inside them, although the manufacturer
can do so. This is fundamentally incompatible with the aim of
protecting users' freedom to change the software. The systematic
pattern of such abuse occurs in the area of products for individuals to
use, which is precisely where it is most unacceptable. Therefore, we
have designed this version of the GPL to prohibit the practice for those
products. If such problems arise substantially in other domains, we
stand ready to extend this provision to those domains in future versions
of the GPL, as needed to protect the freedom of users.
Finally, every program is threatened constantly by software patents.
States should not allow patents to restrict development and use of
software on general-purpose computers, but in those that do, we wish to
avoid the special danger that patents applied to a free program could
make it effectively proprietary. To prevent this, the GPL assures that
patents cannot be used to render the program non-free.
The precise terms and conditions for copying, distribution and
modification follow.
TERMS AND CONDITIONS
0. Definitions.
"This License" refers to version 3 of the GNU General Public License.
"Copyright" also means copyright-like laws that apply to other kinds of
works, such as semiconductor masks.
"The Program" refers to any copyrightable work licensed under this
License. Each licensee is addressed as "you". "Licensees" and
"recipients" may be individuals or organizations.
To "modify" a work means to copy from or adapt all or part of the work
in a fashion requiring copyright permission, other than the making of an
exact copy. The resulting work is called a "modified version" of the
earlier work or a work "based on" the earlier work.
A "covered work" means either the unmodified Program or a work based
on the Program.
To "propagate" a work means to do anything with it that, without
permission, would make you directly or secondarily liable for
infringement under applicable copyright law, except executing it on a
computer or modifying a private copy. Propagation includes copying,
distribution (with or without modification), making available to the
public, and in some countries other activities as well.
To "convey" a work means any kind of propagation that enables other
parties to make or receive copies. Mere interaction with a user through
a computer network, with no transfer of a copy, is not conveying.
An interactive user interface displays "Appropriate Legal Notices"
to the extent that it includes a convenient and prominently visible
feature that (1) displays an appropriate copyright notice, and (2)
tells the user that there is no warranty for the work (except to the
extent that warranties are provided), that licensees may convey the
work under this License, and how to view a copy of this License. If
the interface presents a list of user commands or options, such as a
menu, a prominent item in the list meets this criterion.
1. Source Code.
The "source code" for a work means the preferred form of the work
for making modifications to it. "Object code" means any non-source
form of a work.
A "Standard Interface" means an interface that either is an official
standard defined by a recognized standards body, or, in the case of
interfaces specified for a particular programming language, one that
is widely used among developers working in that language.
The "System Libraries" of an executable work include anything, other
than the work as a whole, that (a) is included in the normal form of
packaging a Major Component, but which is not part of that Major
Component, and (b) serves only to enable use of the work with that
Major Component, or to implement a Standard Interface for which an
implementation is available to the public in source code form. A
"Major Component", in this context, means a major essential component
(kernel, window system, and so on) of the specific operating system
(if any) on which the executable work runs, or a compiler used to
produce the work, or an object code interpreter used to run it.
The "Corresponding Source" for a work in object code form means all
the source code needed to generate, install, and (for an executable
work) run the object code and to modify the work, including scripts to
control those activities. However, it does not include the work's
System Libraries, or general-purpose tools or generally available free
programs which are used unmodified in performing those activities but
which are not part of the work. For example, Corresponding Source
includes interface definition files associated with source files for
the work, and the source code for shared libraries and dynamically
linked subprograms that the work is specifically designed to require,
such as by intimate data communication or control flow between those
subprograms and other parts of the work.
The Corresponding Source need not include anything that users
can regenerate automatically from other parts of the Corresponding
Source.
The Corresponding Source for a work in source code form is that
same work.
2. Basic Permissions.
All rights granted under this License are granted for the term of
copyright on the Program, and are irrevocable provided the stated
conditions are met. This License explicitly affirms your unlimited
permission to run the unmodified Program. The output from running a
covered work is covered by this License only if the output, given its
content, constitutes a covered work. This License acknowledges your
rights of fair use or other equivalent, as provided by copyright law.
You may make, run and propagate covered works that you do not
convey, without conditions so long as your license otherwise remains
in force. You may convey covered works to others for the sole purpose
of having them make modifications exclusively for you, or provide you
with facilities for running those works, provided that you comply with
the terms of this License in conveying all material for which you do
not control copyright. Those thus making or running the covered works
for you must do so exclusively on your behalf, under your direction
and control, on terms that prohibit them from making any copies of
your copyrighted material outside their relationship with you.
Conveying under any other circumstances is permitted solely under
the conditions stated below. Sublicensing is not allowed; section 10
makes it unnecessary.
3. Protecting Users' Legal Rights From Anti-Circumvention Law.
No covered work shall be deemed part of an effective technological
measure under any applicable law fulfilling obligations under article
11 of the WIPO copyright treaty adopted on 20 December 1996, or
similar laws prohibiting or restricting circumvention of such
measures.
When you convey a covered work, you waive any legal power to forbid
circumvention of technological measures to the extent such circumvention
is effected by exercising rights under this License with respect to
the covered work, and you disclaim any intention to limit operation or
modification of the work as a means of enforcing, against the work's
users, your or third parties' legal rights to forbid circumvention of
technological measures.
4. Conveying Verbatim Copies.
You may convey verbatim copies of the Program's source code as you
receive it, in any medium, provided that you conspicuously and
appropriately publish on each copy an appropriate copyright notice;
keep intact all notices stating that this License and any
non-permissive terms added in accord with section 7 apply to the code;
keep intact all notices of the absence of any warranty; and give all
recipients a copy of this License along with the Program.
You may charge any price or no price for each copy that you convey,
and you may offer support or warranty protection for a fee.
5. Conveying Modified Source Versions.
You may convey a work based on the Program, or the modifications to
produce it from the Program, in the form of source code under the
terms of section 4, provided that you also meet all of these conditions:
a) The work must carry prominent notices stating that you modified
it, and giving a relevant date.
b) The work must carry prominent notices stating that it is
released under this License and any conditions added under section
7. This requirement modifies the requirement in section 4 to
"keep intact all notices".
c) You must license the entire work, as a whole, under this
License to anyone who comes into possession of a copy. This
License will therefore apply, along with any applicable section 7
additional terms, to the whole of the work, and all its parts,
regardless of how they are packaged. This License gives no
permission to license the work in any other way, but it does not
invalidate such permission if you have separately received it.
d) If the work has interactive user interfaces, each must display
Appropriate Legal Notices; however, if the Program has interactive
interfaces that do not display Appropriate Legal Notices, your
work need not make them do so.
A compilation of a covered work with other separate and independent
works, which are not by their nature extensions of the covered work,
and which are not combined with it such as to form a larger program,
in or on a volume of a storage or distribution medium, is called an
"aggregate" if the compilation and its resulting copyright are not
used to limit the access or legal rights of the compilation's users
beyond what the individual works permit. Inclusion of a covered work
in an aggregate does not cause this License to apply to the other
parts of the aggregate.
6. Conveying Non-Source Forms.
You may convey a covered work in object code form under the terms
of sections 4 and 5, provided that you also convey the
machine-readable Corresponding Source under the terms of this License,
in one of these ways:
a) Convey the object code in, or embodied in, a physical product
(including a physical distribution medium), accompanied by the
Corresponding Source fixed on a durable physical medium
customarily used for software interchange.
b) Convey the object code in, or embodied in, a physical product
(including a physical distribution medium), accompanied by a
written offer, valid for at least three years and valid for as
long as you offer spare parts or customer support for that product
model, to give anyone who possesses the object code either (1) a
copy of the Corresponding Source for all the software in the
product that is covered by this License, on a durable physical
medium customarily used for software interchange, for a price no
more than your reasonable cost of physically performing this
conveying of source, or (2) access to copy the
Corresponding Source from a network server at no charge.
c) Convey individual copies of the object code with a copy of the
written offer to provide the Corresponding Source. This
alternative is allowed only occasionally and noncommercially, and
only if you received the object code with such an offer, in accord
with subsection 6b.
d) Convey the object code by offering access from a designated
place (gratis or for a charge), and offer equivalent access to the
Corresponding Source in the same way through the same place at no
further charge. You need not require recipients to copy the
Corresponding Source along with the object code. If the place to
copy the object code is a network server, the Corresponding Source
may be on a different server (operated by you or a third party)
that supports equivalent copying facilities, provided you maintain
clear directions next to the object code saying where to find the
Corresponding Source. Regardless of what server hosts the
Corresponding Source, you remain obligated to ensure that it is
available for as long as needed to satisfy these requirements.
e) Convey the object code using peer-to-peer transmission, provided
you inform other peers where the object code and Corresponding
Source of the work are being offered to the general public at no
charge under subsection 6d.
A separable portion of the object code, whose source code is excluded
from the Corresponding Source as a System Library, need not be
included in conveying the object code work.
A "User Product" is either (1) a "consumer product", which means any
tangible personal property which is normally used for personal, family,
or household purposes, or (2) anything designed or sold for incorporation
into a dwelling. In determining whether a product is a consumer product,
doubtful cases shall be resolved in favor of coverage. For a particular
product received by a particular user, "normally used" refers to a
typical or common use of that class of product, regardless of the status
of the particular user or of the way in which the particular user
actually uses, or expects or is expected to use, the product. A product
is a consumer product regardless of whether the product has substantial
commercial, industrial or non-consumer uses, unless such uses represent
the only significant mode of use of the product.
"Installation Information" for a User Product means any methods,
procedures, authorization keys, or other information required to install
and execute modified versions of a covered work in that User Product from
a modified version of its Corresponding Source. The information must
suffice to ensure that the continued functioning of the modified object
code is in no case prevented or interfered with solely because
modification has been made.
If you convey an object code work under this section in, or with, or
specifically for use in, a User Product, and the conveying occurs as
part of a transaction in which the right of possession and use of the
User Product is transferred to the recipient in perpetuity or for a
fixed term (regardless of how the transaction is characterized), the
Corresponding Source conveyed under this section must be accompanied
by the Installation Information. But this requirement does not apply
if neither you nor any third party retains the ability to install
modified object code on the User Product (for example, the work has
been installed in ROM).
The requirement to provide Installation Information does not include a
requirement to continue to provide support service, warranty, or updates
for a work that has been modified or installed by the recipient, or for
the User Product in which it has been modified or installed. Access to a
network may be denied when the modification itself materially and
adversely affects the operation of the network or violates the rules and
protocols for communication across the network.
Corresponding Source conveyed, and Installation Information provided,
in accord with this section must be in a format that is publicly
documented (and with an implementation available to the public in
source code form), and must require no special password or key for
unpacking, reading or copying.
7. Additional Terms.
"Additional permissions" are terms that supplement the terms of this
License by making exceptions from one or more of its conditions.
Additional permissions that are applicable to the entire Program shall
be treated as though they were included in this License, to the extent
that they are valid under applicable law. If additional permissions
apply only to part of the Program, that part may be used separately
under those permissions, but the entire Program remains governed by
this License without regard to the additional permissions.
When you convey a copy of a covered work, you may at your option
remove any additional permissions from that copy, or from any part of
it. (Additional permissions may be written to require their own
removal in certain cases when you modify the work.) You may place
additional permissions on material, added by you to a covered work,
for which you have or can give appropriate copyright permission.
Notwithstanding any other provision of this License, for material you
add to a covered work, you may (if authorized by the copyright holders of
that material) supplement the terms of this License with terms:
a) Disclaiming warranty or limiting liability differently from the
terms of sections 15 and 16 of this License; or
b) Requiring preservation of specified reasonable legal notices or
author attributions in that material or in the Appropriate Legal
Notices displayed by works containing it; or
c) Prohibiting misrepresentation of the origin of that material, or
requiring that modified versions of such material be marked in
reasonable ways as different from the original version; or
d) Limiting the use for publicity purposes of names of licensors or
authors of the material; or
e) Declining to grant rights under trademark law for use of some
trade names, trademarks, or service marks; or
f) Requiring indemnification of licensors and authors of that
material by anyone who conveys the material (or modified versions of
it) with contractual assumptions of liability to the recipient, for
any liability that these contractual assumptions directly impose on
those licensors and authors.
All other non-permissive additional terms are considered "further
restrictions" within the meaning of section 10. If the Program as you
received it, or any part of it, contains a notice stating that it is
governed by this License along with a term that is a further
restriction, you may remove that term. If a license document contains
a further restriction but permits relicensing or conveying under this
License, you may add to a covered work material governed by the terms
of that license document, provided that the further restriction does
not survive such relicensing or conveying.
If you add terms to a covered work in accord with this section, you
must place, in the relevant source files, a statement of the
additional terms that apply to those files, or a notice indicating
where to find the applicable terms.
Additional terms, permissive or non-permissive, may be stated in the
form of a separately written license, or stated as exceptions;
the above requirements apply either way.
8. Termination.
You may not propagate or modify a covered work except as expressly
provided under this License. Any attempt otherwise to propagate or
modify it is void, and will automatically terminate your rights under
this License (including any patent licenses granted under the third
paragraph of section 11).
However, if you cease all violation of this License, then your
license from a particular copyright holder is reinstated (a)
provisionally, unless and until the copyright holder explicitly and
finally terminates your license, and (b) permanently, if the copyright
holder fails to notify you of the violation by some reasonable means
prior to 60 days after the cessation.
Moreover, your license from a particular copyright holder is
reinstated permanently if the copyright holder notifies you of the
violation by some reasonable means, this is the first time you have
received notice of violation of this License (for any work) from that
copyright holder, and you cure the violation prior to 30 days after
your receipt of the notice.
Termination of your rights under this section does not terminate the
licenses of parties who have received copies or rights from you under
this License. If your rights have been terminated and not permanently
reinstated, you do not qualify to receive new licenses for the same
material under section 10.
9. Acceptance Not Required for Having Copies.
You are not required to accept this License in order to receive or
run a copy of the Program. Ancillary propagation of a covered work
occurring solely as a consequence of using peer-to-peer transmission
to receive a copy likewise does not require acceptance. However,
nothing other than this License grants you permission to propagate or
modify any covered work. These actions infringe copyright if you do
not accept this License. Therefore, by modifying or propagating a
covered work, you indicate your acceptance of this License to do so.
10. Automatic Licensing of Downstream Recipients.
Each time you convey a covered work, the recipient automatically
receives a license from the original licensors, to run, modify and
propagate that work, subject to this License. You are not responsible
for enforcing compliance by third parties with this License.
An "entity transaction" is a transaction transferring control of an
organization, or substantially all assets of one, or subdividing an
organization, or merging organizations. If propagation of a covered
work results from an entity transaction, each party to that
transaction who receives a copy of the work also receives whatever
licenses to the work the party's predecessor in interest had or could
give under the previous paragraph, plus a right to possession of the
Corresponding Source of the work from the predecessor in interest, if
the predecessor has it or can get it with reasonable efforts.
You may not impose any further restrictions on the exercise of the
rights granted or affirmed under this License. For example, you may
not impose a license fee, royalty, or other charge for exercise of
rights granted under this License, and you may not initiate litigation
(including a cross-claim or counterclaim in a lawsuit) alleging that
any patent claim is infringed by making, using, selling, offering for
sale, or importing the Program or any portion of it.
11. Patents.
A "contributor" is a copyright holder who authorizes use under this
License of the Program or a work on which the Program is based. The
work thus licensed is called the contributor's "contributor version".
A contributor's "essential patent claims" are all patent claims
owned or controlled by the contributor, whether already acquired or
hereafter acquired, that would be infringed by some manner, permitted
by this License, of making, using, or selling its contributor version,
but do not include claims that would be infringed only as a
consequence of further modification of the contributor version. For
purposes of this definition, "control" includes the right to grant
patent sublicenses in a manner consistent with the requirements of
this License.
Each contributor grants you a non-exclusive, worldwide, royalty-free
patent license under the contributor's essential patent claims, to
make, use, sell, offer for sale, import and otherwise run, modify and
propagate the contents of its contributor version.
In the following three paragraphs, a "patent license" is any express
agreement or commitment, however denominated, not to enforce a patent
(such as an express permission to practice a patent or covenant not to
sue for patent infringement). To "grant" such a patent license to a
party means to make such an agreement or commitment not to enforce a
patent against the party.
If you convey a covered work, knowingly relying on a patent license,
and the Corresponding Source of the work is not available for anyone
to copy, free of charge and under the terms of this License, through a
publicly available network server or other readily accessible means,
then you must either (1) cause the Corresponding Source to be so
available, or (2) arrange to deprive yourself of the benefit of the
patent license for this particular work, or (3) arrange, in a manner
consistent with the requirements of this License, to extend the patent
license to downstream recipients. "Knowingly relying" means you have
actual knowledge that, but for the patent license, your conveying the
covered work in a country, or your recipient's use of the covered work
in a country, would infringe one or more identifiable patents in that
country that you have reason to believe are valid.
If, pursuant to or in connection with a single transaction or
arrangement, you convey, or propagate by procuring conveyance of, a
covered work, and grant a patent license to some of the parties
receiving the covered work authorizing them to use, propagate, modify
or convey a specific copy of the covered work, then the patent license
you grant is automatically extended to all recipients of the covered
work and works based on it.
A patent license is "discriminatory" if it does not include within
the scope of its coverage, prohibits the exercise of, or is
conditioned on the non-exercise of one or more of the rights that are
specifically granted under this License. You may not convey a covered
work if you are a party to an arrangement with a third party that is
in the business of distributing software, under which you make payment
to the third party based on the extent of your activity of conveying
the work, and under which the third party grants, to any of the
parties who would receive the covered work from you, a discriminatory
patent license (a) in connection with copies of the covered work
conveyed by you (or copies made from those copies), or (b) primarily
for and in connection with specific products or compilations that
contain the covered work, unless you entered into that arrangement,
or that patent license was granted, prior to 28 March 2007.
Nothing in this License shall be construed as excluding or limiting
any implied license or other defenses to infringement that may
otherwise be available to you under applicable patent law.
12. No Surrender of Others' Freedom.
If conditions are imposed on you (whether by court order, agreement or
otherwise) that contradict the conditions of this License, they do not
excuse you from the conditions of this License. If you cannot convey a
covered work so as to satisfy simultaneously your obligations under this
License and any other pertinent obligations, then as a consequence you may
not convey it at all. For example, if you agree to terms that obligate you
to collect a royalty for further conveying from those to whom you convey
the Program, the only way you could satisfy both those terms and this
License would be to refrain entirely from conveying the Program.
13. Use with the GNU Affero General Public License.
Notwithstanding any other provision of this License, you have
permission to link or combine any covered work with a work licensed
under version 3 of the GNU Affero General Public License into a single
combined work, and to convey the resulting work. The terms of this
License will continue to apply to the part which is the covered work,
but the special requirements of the GNU Affero General Public License,
section 13, concerning interaction through a network will apply to the
combination as such.
14. Revised Versions of this License.
The Free Software Foundation may publish revised and/or new versions of
the GNU General Public License from time to time. Such new versions will
be similar in spirit to the present version, but may differ in detail to
address new problems or concerns.
Each version is given a distinguishing version number. If the
Program specifies that a certain numbered version of the GNU General
Public License "or any later version" applies to it, you have the
option of following the terms and conditions either of that numbered
version or of any later version published by the Free Software
Foundation. If the Program does not specify a version number of the
GNU General Public License, you may choose any version ever published
by the Free Software Foundation.
If the Program specifies that a proxy can decide which future
versions of the GNU General Public License can be used, that proxy's
public statement of acceptance of a version permanently authorizes you
to choose that version for the Program.
Later license versions may give you additional or different
permissions. However, no additional obligations are imposed on any
author or copyright holder as a result of your choosing to follow a
later version.
15. Disclaimer of Warranty.
THERE IS NO WARRANTY FOR THE PROGRAM, TO THE EXTENT PERMITTED BY
APPLICABLE LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT
HOLDERS AND/OR OTHER PARTIES PROVIDE THE PROGRAM "AS IS" WITHOUT WARRANTY
OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO,
THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE PROGRAM
IS WITH YOU. SHOULD THE PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF
ALL NECESSARY SERVICING, REPAIR OR CORRECTION.
16. Limitation of Liability.
IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING
WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MODIFIES AND/OR CONVEYS
THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES, INCLUDING ANY
GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING OUT OF THE
USE OR INABILITY TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED TO LOSS OF
DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY YOU OR THIRD
PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER PROGRAMS),
EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF
SUCH DAMAGES.
17. Interpretation of Sections 15 and 16.
If the disclaimer of warranty and limitation of liability provided
above cannot be given local legal effect according to their terms,
reviewing courts shall apply local law that most closely approximates
an absolute waiver of all civil liability in connection with the
Program, unless a warranty or assumption of liability accompanies a
copy of the Program in return for a fee.
END OF TERMS AND CONDITIONS
How to Apply These Terms to Your New Programs
If you develop a new program, and you want it to be of the greatest
possible use to the public, the best way to achieve this is to make it
free software which everyone can redistribute and change under these terms.
To do so, attach the following notices to the program. It is safest
to attach them to the start of each source file to most effectively
state the exclusion of warranty; and each file should have at least
the "copyright" line and a pointer to where the full notice is found.
<one line to give the program's name and a brief idea of what it does.>
Copyright (C) <year> <name of author>
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation, either version 3 of the License, or
(at your option) any later version.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.
You should have received a copy of the GNU General Public License
along with this program. If not, see <https://www.gnu.org/licenses/>.
Also add information on how to contact you by electronic and paper mail.
If the program does terminal interaction, make it output a short
notice like this when it starts in an interactive mode:
<program> Copyright (C) <year> <name of author>
This program comes with ABSOLUTELY NO WARRANTY; for details type `show w'.
This is free software, and you are welcome to redistribute it
under certain conditions; type `show c' for details.
The hypothetical commands `show w' and `show c' should show the appropriate
parts of the General Public License. Of course, your program's commands
might be different; for a GUI interface, you would use an "about box".
You should also get your employer (if you work as a programmer) or school,
if any, to sign a "copyright disclaimer" for the program, if necessary.
For more information on this, and how to apply and follow the GNU GPL, see
<https://www.gnu.org/licenses/>.
The GNU General Public License does not permit incorporating your program
into proprietary programs. If your program is a subroutine library, you
may consider it more useful to permit linking proprietary applications with
the library. If this is what you want to do, use the GNU Lesser General
Public License instead of this License. But first, please read
<https://www.gnu.org/licenses/why-not-lgpl.html>.
+30
View File
@@ -0,0 +1,30 @@
# Source provenance
This initial extraction retains the existing GPL-3.0-only licence and credits
Cole Speelman / Gamertan's Sized scanner. Repository privacy does not change
the source licence. No new licensing or contributor agreement is introduced.
- `src/scan.rs`: byte-identical to Sized at
`9fd4e905b00ad23cea06bfaa1cc6a9608032266c` on `sizequeen-scan-hardening`.
Scanner behaviour was introduced in `8b177e2`; `988aad9` changed one Display
format string without changing behaviour.
SHA-256: `a134f8f40bd0994f6ea332325e2b43ff47d558c42106135a951f2f8aa46be4ce`.
- `src/lib.rs`: byte-identical to SizeQueen's included core at
`e17ef84` on `experiment/macos-native`, preserving its public re-exports and
legacy `build_tree` compatibility helper.
- `tests/scanning.rs`: copied unchanged from Sized. SHA-256:
`5fdb6ff3197aa24ceb2699f5787298b00ede69a87af07d7ca4fbdb911125a292`.
- `tests/linux_mount.rs`: Sized's real-mount regression adapted to test the
library independently; the original Sized test also checks CLI JSON output.
- Linux check scripts and pinned runtime: adapted from the checked Sized branch,
replacing the CLI smoke with a release-built library example.
SizeQueen's older scanner snapshot differs only in the equivalent Display
format string. It remains unchanged until a deliberate consumer migration.
The scanner's original baseline was Sized
`9c8d1d43fdb5f4f540d4bea14275bc51ef69f92c`.
The treemap layout and native bridge remain in SizeQueen. They are not part of
this extraction. Detailed accounting findings remain in SizeQueen's
`research/SIZED-AUDIT.md`; Sized's review and CI evidence remain in its
`TODO.md` and `SHIPMENT.md`.
+75
View File
@@ -0,0 +1,75 @@
# Sized core
Shared Rust filesystem scanning for [Sized](https://gitea.speelman.ca/gamertan/sized)
and [SizeQueen](https://gitea.speelman.ca/gamertan/sizequeen), by Gamertan.
This is a private extraction experiment. The existing applications still use
their current scanner copies; adopting this repository is a separate change.
The library reports apparent bytes and allocated 512-byte blocks, counts hard
links deterministically, preserves partial-scan issues, and supports cancellation,
progress, per-scan worker selection, ignore rules and filesystem boundaries.
It contains no desktop, terminal formatting, web or Swift dependencies.
Linux and macOS are supported; Windows allocation is not implemented.
## Use
The Cargo package is `sized-core`; its library import remains `sized` for
compatibility with the current SizeQueen snapshot. Pin a reviewed Git revision
when adopting it. Private Git dependencies require access to this repository.
```rust
use sized::{scan_tree, ScanControl, ScanError, ScanOptions, ScanReport};
use std::path::Path;
fn scan_chosen_path(path: &Path) -> Result<ScanReport, ScanError> {
scan_tree(path, &ScanOptions::default(), &ScanControl::default())
}
// Inspect report.issues and report.root.complete before calling a scan complete.
```
Use `scan_tree` for new consumers. The legacy `build_tree` helper converts a
failed scan to an unavailable node and does not preserve diagnostics.
Cancellation is cooperative between filesystem calls. Allocated blocks do not
predict recoverable space on filesystems with shared extents or snapshots.
## Check
Run tests as an ordinary user; permission regressions intentionally fail as root.
```sh
cargo fmt --all -- --check
cargo test --locked
cargo clippy --locked --all-targets -- -D warnings
./scripts/check-linux.sh linux/arm64
./scripts/check-linux.sh linux/amd64
```
The Linux script pins Rust 1.88.0, runs as UID 65532 with capabilities dropped,
creates two actual tmpfs devices, and checks a release-built example against an
owned fixture. The mount test is ignored in normal Cargo runs and explicitly
enabled by the script.
The example requires an explicit path: `cargo run --locked --example scan -- PATH`.
### Gitea CI
`.gitea/workflows/linux.yml` runs the same checks on the existing cliff-mads
runner's `himesan-node24` label with a pinned Rust/Node job image. The image
pre-owns `/workspace/gamertan/sized-core` for UID 65532, including checkout.
Jobs have no Docker socket or privileged mode; the runner mounts the two tmpfs
devices. No runner configuration, labels or unrelated jobs are changed.
Rebuild the local image intentionally with:
```sh
ssh cliff-mads 'docker build --platform linux/amd64 --tag local/gamertan-ci:sized-core-rust188 -' < scripts/gitea-linux.Dockerfile
ssh cliff-mads 'docker image inspect local/gamertan-ci:sized-core-rust188 --format "{{.Id}}"'
```
Review and update the workflow image ID after a rebuild. It stays local to
cliff-mads. Repository Actions must be enabled. Checks cover owner-triggered,
same-repository pushes on main/review branches and PRs to main; manual dispatch
is available. Documentation-only pushes skip builds. No package or release is
published. `TODO.md` records the actual provider result and tested source commit.
Source provenance and licence are in [PROVENANCE.md](PROVENANCE.md) and
[LICENSE](LICENSE). The live iteration queue is [TODO.md](TODO.md).
+25
View File
@@ -0,0 +1,25 @@
use sized::{scan_tree, ScanControl, ScanOptions};
use std::{error::Error, path::PathBuf};
fn main() -> Result<(), Box<dyn Error>> {
let Some(path) = std::env::args_os().nth(1).map(PathBuf::from) else {
eprintln!("Usage: scan PATH");
std::process::exit(2);
};
let report = scan_tree(&path, &ScanOptions::default(), &ScanControl::default())?;
println!(
"apparent={} allocated={} entries={} complete={} issues={}",
report.root.size_bytes,
report.root.blocks * 512,
report.entries_scanned,
report.root.complete,
report.issues.len()
);
if !report.root.complete {
for issue in report.issues {
eprintln!("{}: {}", issue.path.display(), issue.message);
}
std::process::exit(1);
}
Ok(())
}
+20
View File
@@ -0,0 +1,20 @@
//! Sized's scanner without its command-line presentation dependencies.
pub mod scan;
pub use scan::*;
use std::path::Path;
/// Compatibility entry point for the original accounting probes.
pub fn build_tree(path: &Path, ignore: bool, compare: bool) -> Node {
scan_tree(
path,
&ScanOptions {
respect_ignore: ignore,
compare_ignore: compare,
..ScanOptions::default()
},
&ScanControl::default(),
)
.map(|report| report.root)
.unwrap_or_else(|_| Node::unavailable(path))
}
+417
View File
@@ -0,0 +1,417 @@
//! Filesystem scanning, independent of CLI parsing and presentation.
//! Allocation is the filesystem's reported 512-byte blocks, not a prediction
//! of bytes freed by deletion (snapshots and shared extents can differ).
use ignore::WalkBuilder;
use rayon::prelude::*;
use serde::Serialize;
use std::{
collections::HashSet,
fs::{self, Metadata},
io,
os::unix::fs::MetadataExt,
path::{Path, PathBuf},
sync::{
atomic::{AtomicBool, AtomicU64, Ordering},
Arc, Mutex,
},
};
#[derive(Clone, Copy, Serialize, Debug, PartialEq, Eq)]
pub struct FileIdentity {
pub device: u64,
pub inode: u64,
pub links: u64,
}
#[derive(Clone, Serialize, Debug)]
pub struct Node {
pub path: PathBuf,
pub size_bytes: u64,
pub blocks: u64,
pub size_bytes_filtered: u64,
pub blocks_filtered: u64,
pub entry_type: EntryType,
pub accessible: bool,
/// False when this node or any descendant could not be scanned.
pub complete: bool,
pub symlink: bool,
pub skipped_mount: bool,
pub hard_link_duplicate: bool,
pub identity: Option<FileIdentity>,
#[serde(skip)]
pub children: Vec<Node>,
#[serde(skip)]
pub own_size_bytes: u64,
#[serde(skip)]
pub own_blocks: u64,
#[serde(skip)]
included_by_filter: bool,
}
#[derive(Clone, Serialize, Debug, PartialEq, Eq, PartialOrd, Ord)]
pub enum EntryType {
File,
Dir,
Special,
Unknown,
}
impl std::fmt::Display for EntryType {
fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
write!(f, "{self:?}")
}
}
impl Node {
pub(crate) fn unavailable(path: &Path) -> Self {
Self {
path: path.into(),
size_bytes: 0,
blocks: 0,
size_bytes_filtered: 0,
blocks_filtered: 0,
entry_type: EntryType::Unknown,
accessible: false,
complete: false,
symlink: false,
skipped_mount: false,
hard_link_duplicate: false,
identity: None,
children: Vec::new(),
own_size_bytes: 0,
own_blocks: 0,
included_by_filter: true,
}
}
fn from_metadata(path: &Path, meta: &Metadata) -> Self {
let mut node = Self::unavailable(path);
node.entry_type = if meta.is_dir() {
EntryType::Dir
} else if meta.is_file() || meta.is_symlink() {
EntryType::File
} else {
EntryType::Special
};
node.accessible = true;
node.complete = true;
node.symlink = meta.is_symlink();
node.identity = Some(FileIdentity {
device: meta.dev(),
inode: meta.ino(),
links: meta.nlink(),
});
node.own_size_bytes = meta.len();
node.own_blocks = meta.blocks();
node
}
}
#[derive(Clone, Debug, Default)]
pub struct ScanOptions {
pub respect_ignore: bool,
pub compare_ignore: bool,
pub stay_on_filesystem: bool,
/// None or zero selects Rayon's default worker count, scoped to this scan.
pub threads: Option<usize>,
}
/// Create a fresh control for each scan; clones share cancellation and progress.
#[derive(Clone, Debug, Default)]
pub struct ScanControl {
cancelled: Arc<AtomicBool>,
visited: Arc<AtomicU64>,
}
impl ScanControl {
pub fn cancel(&self) {
self.cancelled.store(true, Ordering::Relaxed);
}
pub fn is_cancelled(&self) -> bool {
self.cancelled.load(Ordering::Relaxed)
}
pub fn entries_scanned(&self) -> u64 {
self.visited.load(Ordering::Relaxed)
}
fn check(&self) -> Result<(), ScanError> {
if self.is_cancelled() {
Err(ScanError::Cancelled)
} else {
Ok(())
}
}
}
#[derive(Debug)]
pub struct ScanIssue {
pub path: PathBuf,
pub kind: io::ErrorKind,
pub message: String,
}
#[derive(Debug)]
pub struct ScanReport {
pub root: Node,
pub issues: Vec<ScanIssue>,
pub entries_scanned: u64,
}
#[derive(Debug)]
pub enum ScanError {
Root { path: PathBuf, source: io::Error },
WorkerPool(rayon::ThreadPoolBuildError),
Cancelled,
}
impl std::fmt::Display for ScanError {
fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
match self {
Self::Root { path, source } => {
write!(f, "cannot scan '{}': {}", path.display(), source)
}
Self::WorkerPool(e) => write!(f, "cannot start scan workers: {e}"),
Self::Cancelled => write!(f, "scan cancelled"),
}
}
}
impl std::error::Error for ScanError {}
/// The completed tree is published only after deterministic hard-link accounting.
/// Cancellation is cooperative between filesystem calls, not syscall preemption.
pub fn scan_tree(
path: &Path,
options: &ScanOptions,
control: &ScanControl,
) -> Result<ScanReport, ScanError> {
control.check()?;
let metadata = fs::symlink_metadata(path).map_err(|source| ScanError::Root {
path: path.into(),
source,
})?;
let pool = rayon::ThreadPoolBuilder::new()
.num_threads(options.threads.unwrap_or(0))
.build()
.map_err(ScanError::WorkerPool)?;
let context = Context {
options,
control,
root_device: metadata.dev(),
issues: Mutex::new(Vec::new()),
};
let mut root = pool.install(|| context.visit(path, Some(metadata)))?;
control.check()?;
reduce(
&mut root,
true,
&mut HashSet::new(),
&mut HashSet::new(),
control,
)?;
control.check()?;
let mut issues = context.issues.into_inner().unwrap();
issues.sort_by(|a, b| a.path.cmp(&b.path).then(a.message.cmp(&b.message)));
Ok(ScanReport {
root,
issues,
entries_scanned: control.entries_scanned(),
})
}
struct Context<'a> {
options: &'a ScanOptions,
control: &'a ScanControl,
root_device: u64,
issues: Mutex<Vec<ScanIssue>>,
}
impl Context<'_> {
fn issue(&self, path: &Path, kind: io::ErrorKind, message: String) {
self.issues.lock().unwrap().push(ScanIssue {
path: path.into(),
kind,
message,
});
}
fn visit(&self, path: &Path, metadata: Option<Metadata>) -> Result<Node, ScanError> {
self.control.check()?;
self.control.visited.fetch_add(1, Ordering::Relaxed);
let metadata = match metadata
.map(Ok)
.unwrap_or_else(|| fs::symlink_metadata(path))
{
Ok(meta) => meta,
Err(e) => {
self.issue(path, e.kind(), e.to_string());
return Ok(Node::unavailable(path));
}
};
let mut node = Node::from_metadata(path, &metadata);
if self.options.stay_on_filesystem && metadata.dev() != self.root_device {
node.skipped_mount = true;
node.own_size_bytes = 0;
node.own_blocks = 0;
return Ok(node);
}
if node.entry_type != EntryType::Dir {
return Ok(node);
}
if let Err(e) = fs::read_dir(path) {
self.issue(path, e.kind(), e.to_string());
node.accessible = false;
node.complete = false;
return Ok(node);
}
let total_ignore = self.options.respect_ignore && !self.options.compare_ignore;
let (paths, total_complete) = self.paths(path, total_ignore)?;
let (filtered, filtered_complete) = if self.options.compare_ignore {
let (paths, complete) = self.paths(path, true)?;
(paths.into_iter().collect::<HashSet<_>>(), complete)
} else {
(HashSet::new(), true)
};
node.complete = total_complete && filtered_complete;
node.children = paths
.par_iter()
.map(|child| {
let mut node = self.visit(child, None)?;
node.included_by_filter = !self.options.compare_ignore || filtered.contains(child);
Ok(node)
})
.collect::<Result<Vec<_>, ScanError>>()?;
Ok(node)
}
fn paths(&self, path: &Path, respect_ignore: bool) -> Result<(Vec<PathBuf>, bool), ScanError> {
let walker = WalkBuilder::new(path)
.standard_filters(false)
.hidden(false)
.parents(respect_ignore)
.git_ignore(respect_ignore)
.ignore(respect_ignore)
.max_depth(Some(1))
.build();
let mut paths = Vec::new();
let mut complete = true;
for entry in walker {
self.control.check()?;
match entry {
Ok(entry) if entry.path() != path => paths.push(entry.into_path()),
Ok(_) => {}
Err(e) => {
complete = false;
self.issue(
path,
e.io_error().map_or(io::ErrorKind::Other, |e| e.kind()),
e.to_string(),
);
}
}
}
// Parallel collection preserves this order; ownership of a shared inode
// is then stable across worker counts and repeated scans.
paths.sort();
Ok((paths, complete))
}
}
fn reduce(
node: &mut Node,
included: bool,
all_seen: &mut HashSet<(u64, u64)>,
filtered_seen: &mut HashSet<(u64, u64)>,
control: &ScanControl,
) -> Result<(), ScanError> {
control.check()?;
node.size_bytes = node.own_size_bytes;
node.blocks = node.own_blocks;
node.size_bytes_filtered = if included { node.own_size_bytes } else { 0 };
node.blocks_filtered = if included { node.own_blocks } else { 0 };
if node.entry_type != EntryType::Dir {
if let Some(id) = node.identity.filter(|id| id.links > 1) {
let key = (id.device, id.inode);
if !all_seen.insert(key) {
node.blocks = 0;
node.hard_link_duplicate = true;
}
if included && !filtered_seen.insert(key) {
node.blocks_filtered = 0;
}
}
}
for child in &mut node.children {
reduce(
child,
included && child.included_by_filter,
all_seen,
filtered_seen,
control,
)?;
node.size_bytes += child.size_bytes;
node.blocks += child.blocks;
node.size_bytes_filtered += child.size_bytes_filtered;
node.blocks_filtered += child.blocks_filtered;
node.complete &= child.complete;
}
Ok(())
}
#[cfg(test)]
mod tests {
use super::*;
use tempfile::tempdir;
#[test]
fn foreign_device_entry_is_marked_without_scanning_its_contents() {
let dir = tempdir().unwrap();
fs::write(dir.path().join("content"), b"not visited").unwrap();
let meta = fs::symlink_metadata(dir.path()).unwrap();
let control = ScanControl::default();
let options = ScanOptions {
stay_on_filesystem: true,
..ScanOptions::default()
};
// Inject the parent scan's different device; this exercises the boundary
// policy without creating mounts or requiring privileged test setup.
let context = Context {
options: &options,
control: &control,
root_device: meta.dev().wrapping_add(1),
issues: Mutex::new(Vec::new()),
};
let mut node = context.visit(dir.path(), Some(meta)).unwrap();
reduce(
&mut node,
true,
&mut HashSet::new(),
&mut HashSet::new(),
&control,
)
.unwrap();
assert!(node.skipped_mount);
assert!(node.children.is_empty());
assert_eq!(node.blocks, 0);
assert_eq!(control.entries_scanned(), 1);
assert!(node.complete);
}
#[test]
fn vanished_child_is_reported_without_fabricating_accessibility() {
let dir = tempdir().unwrap();
let path = dir.path().join("vanished-after-discovery");
let options = ScanOptions::default();
let control = ScanControl::default();
let context = Context {
options: &options,
control: &control,
root_device: fs::metadata(dir.path()).unwrap().dev(),
issues: Mutex::new(Vec::new()),
};
let node = context.visit(&path, None).unwrap();
assert!(!node.accessible);
assert!(!node.complete);
let issues = context.issues.into_inner().unwrap();
assert_eq!(issues[0].path, path);
assert_eq!(issues[0].kind, io::ErrorKind::NotFound);
}
}
+69
View File
@@ -0,0 +1,69 @@
#![cfg(target_os = "linux")]
use sized::{scan_tree, ScanControl, ScanOptions};
use std::{fs, io::Write, os::unix::fs::MetadataExt, path::PathBuf};
use tempfile::NamedTempFile;
#[test]
#[ignore = "requires the two owned tmpfs mounts from scripts/check-linux.sh"]
fn real_mount_boundary_is_respected_by_scanner() {
let root = PathBuf::from(
std::env::var_os("SIZED_TEST_MOUNT_ROOT").expect("missing mounted Linux fixture"),
);
let foreign = root.join("foreign");
let root_metadata = fs::metadata(&root).unwrap();
let foreign_metadata = fs::metadata(&foreign).unwrap();
assert_ne!(
root_metadata.dev(),
foreign_metadata.dev(),
"not a real boundary"
);
let mut local_file = NamedTempFile::new_in(&root).unwrap();
let mut mounted_file = NamedTempFile::new_in(&foreign).unwrap();
local_file.write_all(b"local allocation").unwrap();
mounted_file.write_all(&[7; 8192]).unwrap();
local_file.as_file().sync_all().unwrap();
mounted_file.as_file().sync_all().unwrap();
for bounded in [false, true] {
let report = scan_tree(
&root,
&ScanOptions {
stay_on_filesystem: bounded,
threads: Some(2),
..ScanOptions::default()
},
&ScanControl::default(),
)
.unwrap();
assert!(report.root.complete);
assert!(report.issues.is_empty());
let mount = report
.root
.children
.iter()
.find(|n| n.path == foreign)
.unwrap();
assert_eq!(mount.identity.unwrap().device, foreign_metadata.dev());
assert_eq!(mount.skipped_mount, bounded);
assert_eq!(report.entries_scanned, if bounded { 3 } else { 4 });
let expected_blocks =
root_metadata.blocks() + local_file.as_file().metadata().unwrap().blocks();
if bounded {
assert!(mount.children.is_empty());
assert_eq!(mount.blocks, 0);
assert_eq!(mount.size_bytes, 0);
assert_eq!(report.root.blocks, expected_blocks);
} else {
assert_eq!(mount.children.len(), 1);
assert_eq!(mount.children[0].path, mounted_file.path());
assert_eq!(mount.children[0].size_bytes, 8192);
assert_eq!(
report.root.blocks,
expected_blocks
+ foreign_metadata.blocks()
+ mounted_file.as_file().metadata().unwrap().blocks()
);
}
}
}
+254
View File
@@ -0,0 +1,254 @@
#![cfg(unix)]
use sized::{build_tree, scan_tree, EntryType, ScanControl, ScanError, ScanOptions};
use std::{
fs,
io::Write,
os::unix::fs::{symlink, MetadataExt, PermissionsExt},
};
use tempfile::tempdir;
fn scan(path: &std::path::Path) -> sized::ScanReport {
scan_tree(path, &ScanOptions::default(), &ScanControl::default()).unwrap()
}
#[test]
fn hard_links_count_allocation_once_but_keep_apparent_sizes() {
let dir = tempdir().unwrap();
let original = dir.path().join("a-original");
fs::write(&original, [9; 65536]).unwrap();
fs::hard_link(&original, dir.path().join("z-alias")).unwrap();
let expected =
fs::metadata(&original).unwrap().blocks() + fs::metadata(dir.path()).unwrap().blocks();
for threads in [1, 4] {
let report = scan_tree(
dir.path(),
&ScanOptions {
threads: Some(threads),
..ScanOptions::default()
},
&ScanControl::default(),
)
.unwrap();
assert_eq!(report.root.blocks, expected);
assert_eq!(report.root.children[0].size_bytes, 65536);
assert_eq!(report.root.children[1].size_bytes, 65536);
assert!(!report.root.children[0].hard_link_duplicate);
assert!(report.root.children[1].hard_link_duplicate);
assert_eq!(report.root.children[1].blocks, 0);
assert_eq!(report.entries_scanned, 3);
assert!(report.root.complete);
}
}
#[test]
fn ignored_hard_link_does_not_steal_filtered_allocation() {
let dir = tempdir().unwrap();
fs::write(dir.path().join(".ignore"), "a-ignored\n").unwrap();
let original = dir.path().join("a-ignored");
fs::write(&original, [9; 65536]).unwrap();
fs::hard_link(&original, dir.path().join("z-included")).unwrap();
let report = scan_tree(
dir.path(),
&ScanOptions {
compare_ignore: true,
..ScanOptions::default()
},
&ScanControl::default(),
)
.unwrap();
let expected = fs::metadata(&original).unwrap().blocks()
+ fs::metadata(dir.path()).unwrap().blocks()
+ fs::metadata(dir.path().join(".ignore")).unwrap().blocks();
assert_eq!(report.root.blocks, expected);
assert_eq!(report.root.blocks_filtered, expected);
assert_eq!(report.root.children.last().unwrap().blocks, 0);
assert!(report.root.children.last().unwrap().blocks_filtered > 0);
}
#[test]
fn hidden_files_are_counted_without_ignore_filtering() {
let dir = tempdir().unwrap();
fs::write(dir.path().join(".hidden"), b"hidden").unwrap();
fs::write(dir.path().join(".ignore"), "build\n").unwrap();
fs::write(dir.path().join("build"), b"build").unwrap();
assert_eq!(scan(dir.path()).root.children.len(), 3);
let report = scan_tree(
dir.path(),
&ScanOptions {
respect_ignore: true,
..ScanOptions::default()
},
&ScanControl::default(),
)
.unwrap();
assert_eq!(report.root.children.len(), 2);
assert!(report
.root
.children
.iter()
.any(|n| n.path.ends_with(".hidden")));
}
#[test]
fn ignore_rules_are_inherited_by_nested_directories() {
let dir = tempdir().unwrap();
fs::write(dir.path().join(".ignore"), "*.tmp\n").unwrap();
let nested = dir.path().join("nested");
fs::create_dir(&nested).unwrap();
fs::write(nested.join("skip.tmp"), b"ignored").unwrap();
fs::write(nested.join("keep.bin"), b"included").unwrap();
let report = scan_tree(
dir.path(),
&ScanOptions {
respect_ignore: true,
..ScanOptions::default()
},
&ScanControl::default(),
)
.unwrap();
let children = &report
.root
.children
.iter()
.find(|n| n.path == nested)
.unwrap()
.children;
assert_eq!(children.len(), 1);
assert!(children[0].path.ends_with("keep.bin"));
let compared = scan_tree(
dir.path(),
&ScanOptions {
compare_ignore: true,
..ScanOptions::default()
},
&ScanControl::default(),
)
.unwrap();
assert_eq!(compared.root.size_bytes_filtered, report.root.size_bytes);
assert_eq!(compared.root.blocks_filtered, report.root.blocks);
}
#[test]
fn sparse_file_reports_blocks_and_logical_length_separately() {
let dir = tempdir().unwrap();
let path = dir.path().join("sparse");
let mut file = fs::File::create(&path).unwrap();
file.write_all(&[7; 4096]).unwrap();
file.set_len(128 * 1024 * 1024).unwrap();
file.sync_all().unwrap();
let node = scan(&path).root;
assert_eq!(node.size_bytes, 128 * 1024 * 1024);
assert_eq!(node.blocks, fs::metadata(path).unwrap().blocks());
assert!(node.blocks * 512 < node.size_bytes);
}
#[test]
fn symlinks_including_loop_and_dangling_link_are_leaves() {
let dir = tempdir().unwrap();
symlink(dir.path(), dir.path().join("loop")).unwrap();
symlink(dir.path().join("missing"), dir.path().join("dangling")).unwrap();
let report = scan(dir.path());
assert_eq!(report.root.children.len(), 2);
for node in report.root.children {
assert!(node.symlink);
assert!(node.children.is_empty());
assert!(node.complete);
}
}
#[test]
fn missing_root_returns_error_and_legacy_helper_marks_unavailable() {
let dir = tempdir().unwrap();
let path = dir.path().join("vanished");
assert!(
matches!(scan_tree(&path, &ScanOptions::default(), &ScanControl::default()),
Err(ScanError::Root { source, .. }) if source.kind() == std::io::ErrorKind::NotFound)
);
let node = build_tree(&path, false, false);
assert_eq!(node.entry_type, EntryType::Unknown);
assert!(!node.accessible);
assert!(!node.complete);
}
#[test]
fn permission_error_propagates_incomplete_status_to_root() {
let dir = tempdir().unwrap();
let blocked = dir.path().join("blocked");
fs::create_dir(&blocked).unwrap();
fs::write(blocked.join("unreadable"), b"data").unwrap();
fs::set_permissions(&blocked, fs::Permissions::from_mode(0o000)).unwrap();
let result = std::panic::catch_unwind(|| {
assert!(
fs::read_dir(&blocked).is_err(),
"permission tests require an unprivileged user"
);
let report = scan(dir.path());
assert!(report.root.accessible);
assert!(!report.root.complete);
assert!(!report.root.children[0].accessible);
assert_eq!(report.issues.len(), 1);
assert_eq!(report.issues[0].path, blocked);
assert_eq!(report.issues[0].kind, std::io::ErrorKind::PermissionDenied);
});
fs::set_permissions(blocked, fs::Permissions::from_mode(0o700)).unwrap();
result.unwrap();
}
#[test]
fn cancelled_scan_never_returns_completed_tree() {
let dir = tempdir().unwrap();
let control = ScanControl::default();
control.cancel();
assert!(matches!(
scan_tree(dir.path(), &ScanOptions::default(), &control),
Err(ScanError::Cancelled)
));
assert_eq!(control.entries_scanned(), 0);
}
#[test]
fn cancellation_and_progress_work_during_scan() {
let dir = tempdir().unwrap();
for i in 0..2000 {
fs::write(dir.path().join(format!("file-{i}")), b"x").unwrap();
}
let control = ScanControl::default();
let watcher = control.clone();
let cancel = std::thread::spawn(move || {
let deadline = std::time::Instant::now() + std::time::Duration::from_secs(5);
while watcher.entries_scanned() < 10 {
assert!(
std::time::Instant::now() < deadline,
"scan made no progress"
);
std::thread::yield_now();
}
watcher.cancel();
});
let result = scan_tree(
dir.path(),
&ScanOptions {
threads: Some(1),
..ScanOptions::default()
},
&control,
);
cancel.join().unwrap();
assert!(matches!(result, Err(ScanError::Cancelled)));
assert!(control.entries_scanned() >= 10);
}
#[test]
fn special_file_is_not_treated_as_directory() {
let dir = tempdir().unwrap();
let path = dir.path().join("fifo");
assert!(std::process::Command::new("mkfifo")
.arg(&path)
.status()
.unwrap()
.success());
let node = scan(&path).root;
assert_eq!(node.entry_type, EntryType::Special);
assert!(node.children.is_empty());
assert!(node.complete);
}
+38
View File
@@ -0,0 +1,38 @@
# Sized 2.0 source and dependency notices
Sized and the exact public core snapshot retain GPL-3.0-only. The owner confirmed
that the first-party code was developed by Cole Speelman with Codex assistance.
The core forge remains private; `crates/sized-core` includes the required source
at `fb63e96266dcb8ffbca53b73c6c0f738ac3e827d`. `CORE-SNAPSHOT.json` records the
upstream revision and exact file hashes; `scripts/check-core.py` checks them.
The snapshot preserves upstream README/provenance as historical source records.
Each binary download is accompanied by its exact source archive, including
Cargo.lock, all registry dependencies, core source, build scripts and original
notices. Recipients need no forge credentials. The archive is checked with an
empty Cargo cache and offline mode. Preserve it as long as the binaries remain
available. Source-only development dependencies retain their original bundled
notices and package licence metadata in the vendor directory.
`scripts/package-notices.py` uses Cargo's normal/build tree for the target and
locked metadata to produce `DEPENDENCIES.json` and complete `LICENCES.txt`.
Development-only and inactive optional dependencies are excluded from the binary
inventory. Missing notices and new licence expressions stop packaging. Where a
choice is offered, this distribution uses MIT, or Apache-2.0 when MIT is absent;
all bundled alternative licence texts and copyright notices are preserved.
Unicode-3.0 notices are retained along with MIT/Apache notices where required.
No third-party licence is replaced by the first-party licence.
The existing `colored` 2.2.0 dependency is MPL-2.0. Its sources and notices are
unmodified; inspection found no Exhibit B declaration in its source files or
README. The generic Exhibit B in the MPL licence text itself is not an applied
declaration. Under MPL section 3.3, colored is additionally distributed under
GPL-3.0-only as part of this Larger Work. Its original MPL rights and notices
remain available to recipients. This notice accompanies both binary and source.
See Mozilla's [MPL/GPL guidance](https://www.mozilla.org/en-US/MPL/2.0/combining-mpl-and-gpl/)
and [MPL FAQ](https://www.mozilla.org/en-US/MPL/2.0/FAQ/#q14-may-i-combine-mpl-licensed-code-and-lgpl-licensed-code-in-the-same-executable-program).
The Mac CLI links Apple's system libraries; Linux dynamically links system
libraries including glibc. Each target's requirements and linked libraries are
recorded with its release verification. A new dependency, target or licence
expression requires reviewing the affected notices before distribution.
+31
View File
@@ -0,0 +1,31 @@
# Moving from Sized 1.0 to 2.0
The existing flags and table/CSV/NDJSON workflows remain. Update automation to
handle incomplete scans: exit 0 means a complete result; exit 1 means a missing
root, an incomplete scan or another operation failure. CLI argument errors use
Clap's exit 2. An incomplete scan may still produce useful output. Diagnostics
go to stderr, and each JSON report includes `complete`.
Hard-linked files now contribute allocated blocks once, owned by the first path
in deterministic traversal order. Apparent sizes remain per pathname. Totals
may be lower than 1.0 for this reason. Ignore rules inherit through directories;
`--one-file-system` explicitly skips other mounted filesystems. Allocation is
filesystem-reported blocks, not guaranteed recoverable space.
## Rust consumers
The CLI package is version 2.0.0. Its scanner is the exact `sized-core` revision
recorded in `CORE-SNAPSHOT.json`, also used by SizeQueen. The core snapshot's
internal package version remains 0.0.0; the full Git revision and file hashes
identify it. It is an included path dependency, so no private forge access or
separate core installation is required.
Public scanner types and `sized::scan` are re-exported from that dependency.
`EntryType` adds `Special` and `Unknown`; update exhaustive matches. `Node` has
additional accounting/status fields and internal state; obtain nodes through
`scan_tree` instead of struct literals. `Args` adds `one_file_system`, and
`run` returns scan completeness as a boolean. `build_tree` remains a compatibility
helper, but use `scan_tree` to retain structured errors and diagnostics.
Use a fresh `ScanControl` per scan. Cancellation is cooperative between
filesystem calls. SizeQueen does not launch the CLI; both use the core in process.
+14
View File
@@ -0,0 +1,14 @@
#!/usr/bin/env python3
"""Verify the exact public core snapshot without contacting its private forge."""
import hashlib
import json
from pathlib import Path
root = Path(__file__).resolve().parent.parent
pin = json.loads((root / 'CORE-SNAPSHOT.json').read_text())
snapshot = root / 'crates/sized-core'
actual = {str(p.relative_to(snapshot)): hashlib.sha256(p.read_bytes()).hexdigest()
for p in snapshot.rglob('*') if p.is_file()}
if actual != pin['files']:
raise SystemExit('Core snapshot differs from CORE-SNAPSHOT.json; review the upstream pin and every changed file.')
print(f"Core snapshot verified: {pin['revision']} ({len(actual)} files)")
+41
View File
@@ -0,0 +1,41 @@
#!/usr/bin/env bash
set -euo pipefail
test "$(uname -s)" = Linux
test "$(id -u)" != 0
printf 'Linux checks: uid=%s architecture=%s\n' "$(id -u)" "$(uname -m)"
rustc --version
cargo --version
# Only source inputs are copied. Cargo output and all fixtures disappear with
# the container; the host checkout is read-only and no personal tree is scanned.
check_root=$(mktemp -d /tmp/sized-check.XXXXXX)
source_root=${SIZED_TEST_SOURCE:-/source}
cp "$source_root/Cargo.toml" "$source_root/Cargo.lock" "$check_root/"
cp -R "$source_root/src" "$source_root/tests" "$source_root/benches" "$source_root/crates" "$source_root/docs" "$check_root/"
cp "$source_root/CORE-SNAPSHOT.json" "$check_root/"
if [[ -d "$source_root/vendor" ]]; then
cp -R "$source_root/vendor" "$source_root/.cargo" "$check_root/"
export CARGO_NET_OFFLINE=true
fi
cp "$source_root/LICENSE" "$source_root/README.md" "$source_root/MANUAL.md" "$check_root/"
mkdir "$check_root/scripts"
cp "$source_root"/scripts/{release.sh,check-release.sh,check-core.py,package-notices.py} "$check_root/scripts/"
export SIZED_SOURCE_REVISION="${SIZED_SOURCE_REVISION:-$(git -C "$source_root" rev-parse HEAD 2>/dev/null || printf unknown)}"
cd "$check_root"
python3 scripts/check-core.py
cargo fmt --all -- --check
cargo test --locked --workspace
cargo test --locked --workspace --test linux_mount -- --ignored
cargo clippy --locked --workspace --all-targets -- -D warnings
cargo build --locked --release
fixture_root=$(mktemp -d /tmp/sized-release.XXXXXX)
printf 'Linux release smoke test\n' > "$fixture_root/payload"
./target/release/sized --version
./target/release/sized "$fixture_root" --threads 2 --one-file-system --apparent --format json
./scripts/check-release.sh
if [[ -n ${SIZED_RELEASE_DIR:-} ]]; then
./scripts/release.sh --output-dir "$SIZED_RELEASE_DIR/sized-v2.0.0-$(rustc -vV | sed -n 's/^host: //p')"
fi
printf 'Linux checks passed.\n'
+27
View File
@@ -0,0 +1,27 @@
#!/usr/bin/env bash
set -euo pipefail
# Pin the multi-platform official image, not a moving tag. Tests run on Linux
# filesystems rather than the source bind mount, whose permission semantics vary.
repo_root=$(cd "$(dirname "$0")/.." && pwd)
platform=${1:-linux/$(docker version --format '{{.Server.Arch}}')}
case "$platform" in
linux/arm64|linux/amd64) ;;
*) printf 'Usage: %s [linux/arm64|linux/amd64]\n' "$0" >&2; exit 2 ;;
esac
image=${SIZED_LINUX_IMAGE:-rust:1.88.0-bookworm@sha256:af306cfa71d987911a781c37b59d7d67d934f49684058f96cf72079c3626bfe0}
check_image="sized-linux-check:${platform#linux/}"
mkdir -p "$repo_root/target/linux-checks"
log_file="$repo_root/target/linux-checks/${platform#linux/}.log"
docker build --platform "$platform" --build-arg "BASE_IMAGE=$image" \
--tag "$check_image" - < "$repo_root/scripts/linux-check.Dockerfile"
docker run --rm --platform "$platform" \
--user 65532:65532 --cap-drop ALL --security-opt no-new-privileges \
--mount "type=bind,src=$repo_root,dst=/source,readonly" \
--tmpfs /tmp/sized-mount-test:rw,nosuid,nodev,noexec,size=16m,uid=65532,gid=65532,mode=0700 \
--tmpfs /tmp/sized-mount-test/foreign:rw,nosuid,nodev,noexec,size=16m,uid=65532,gid=65532,mode=0700 \
--env CARGO_HOME=/tmp/sized-cargo \
--env CARGO_BUILD_JOBS="${SIZED_LINUX_JOBS:-2}" \
--env SIZED_TEST_MOUNT_ROOT=/tmp/sized-mount-test \
"$check_image" bash /source/scripts/check-linux-container.sh 2>&1 | tee "$log_file"
+39
View File
@@ -0,0 +1,39 @@
#!/usr/bin/env bash
set -euo pipefail
repo_root=$(cd "$(dirname "$0")/.." && pwd)
check_root=$(mktemp -d "${TMPDIR:-/tmp}/sized-package.XXXXXX")
trap 'rm -rf "$check_root"' EXIT
"$repo_root/scripts/release.sh" --output-dir "$check_root/bundle"
mkdir "$check_root/extracted" "$check_root/fixture"
tar -xzf "$check_root/bundle.tar.gz" -C "$check_root/extracted"
for required in sized sized.1 sized.bash _sized sized.fish LICENSE README.md MANUAL.md BUILD-INFO.txt LICENCES.txt DEPENDENCIES.json CORE-SNAPSHOT.json docs/UPGRADING-2.md docs/RELEASE-LICENSING.md; do
test -s "$check_root/extracted/$required"
done
test -x "$check_root/extracted/sized"
(
cd "$check_root"
if command -v sha256sum >/dev/null 2>&1; then
sha256sum -c bundle.tar.gz.sha256
else
shasum -a 256 -c bundle.tar.gz.sha256
fi
)
printf 'owned package fixture\n' > "$check_root/fixture/payload"
"$check_root/extracted/sized" --version
"$check_root/extracted/sized" "$check_root/fixture" --apparent --format json > "$check_root/result.json"
grep -q 'payload' "$check_root/result.json"
grep -q '"complete":true' "$check_root/result.json"
if "$repo_root/scripts/release.sh" --output-dir "$check_root/bundle" > "$check_root/repeat.log" 2>&1; then
printf 'Packaging unexpectedly replaced an existing output.\n' >&2
exit 1
fi
grep -q 'Refusing to replace' "$check_root/repeat.log"
ln -s "$check_root/untouched" "$check_root/linked.tar.gz"
if "$repo_root/scripts/release.sh" --output-dir "$check_root/linked" > "$check_root/linked.log" 2>&1; then
printf 'Packaging unexpectedly followed an existing archive symlink.\n' >&2
exit 1
fi
grep -q 'Refusing to replace' "$check_root/linked.log"
test ! -e "$check_root/untouched"
printf 'Archive contents, checksum, extracted CLI and overwrite guard passed.\n'
+10
View File
@@ -0,0 +1,10 @@
# Node supports the pinned checkout action; application code remains Rust.
FROM node:24-bookworm@sha256:934240a162082fd8b8a2f90cd5114446443f1eba1c5378f6687167ca405e6584 AS node-runtime
FROM rust:1.88.0-bookworm@sha256:af306cfa71d987911a781c37b59d7d67d934f49684058f96cf72079c3626bfe0
RUN rustup component add rustfmt clippy
COPY --from=node-runtime /usr/local/bin/node /usr/local/bin/node
# A new runner workspace volume inherits this ownership. No setuid step or
# Docker socket is needed in jobs, even with all capabilities dropped.
RUN mkdir -p /workspace/gamertan/sized && chown -R 65532:65532 /workspace
USER 65532:65532
WORKDIR /workspace
+3
View File
@@ -0,0 +1,3 @@
ARG BASE_IMAGE=rust:1.88.0-bookworm@sha256:af306cfa71d987911a781c37b59d7d67d934f49684058f96cf72079c3626bfe0
FROM ${BASE_IMAGE}
RUN rustup component add rustfmt clippy
+18
View File
@@ -0,0 +1,18 @@
#!/usr/bin/env bash
set -euo pipefail
[[ $# == 2 ]] || { echo 'Usage: scripts/notarize-macos.sh PACKAGE_DIRECTORY NEW_DMG_PATH' >&2; exit 2; }
: "${SIZED_SIGN_IDENTITY:?Set a Developer ID Application identity.}"
package=$1
dmg=$2
[[ ! -e $dmg && ! -L $dmg ]] || { echo 'Refusing existing DMG.' >&2; exit 1; }
codesign --force --sign "$SIZED_SIGN_IDENTITY" --identifier com.gamertan.sized --options runtime --timestamp "$package/sized"
codesign --verify --strict --verbose=2 "$package/sized"
printf '\nMac distribution: Developer ID signed; see the notarized, stapled DMG.\n' >> "$package/BUILD-INFO.txt"
hdiutil create -quiet -volname 'Sized 2.0.0' -srcfolder "$package" -format UDZO "$dmg"
codesign --sign "$SIZED_SIGN_IDENTITY" --timestamp "$dmg"
xcrun notarytool submit "$dmg" --keychain-profile "${SIZED_NOTARY_PROFILE:-sizequeen-notary}" --wait --output-format json > "$dmg.notarization.json"
test "$(plutil -extract status raw "$dmg.notarization.json")" = Accepted
xcrun stapler staple "$dmg"
xcrun stapler validate "$dmg"
spctl --assess --type open --context context:primary-signature --verbose=2 "$dmg"
echo 'Signed, notarized and stapled disk image verified.'
+60
View File
@@ -0,0 +1,60 @@
#!/usr/bin/env python3
"""Preserve complete notices for the actual locked runtime/build crate graph."""
import argparse
import hashlib
import json
from pathlib import Path
import re
import subprocess
REVIEWED = {'GPL-3.0-only', 'MIT', 'MIT OR Apache-2.0', 'Apache-2.0 OR MIT',
'MIT/Apache-2.0', 'Unlicense OR MIT', 'Unlicense/MIT', 'MPL-2.0',
'Apache-2.0', 'Apache-2.0 OR BSL-1.0',
'Apache-2.0 WITH LLVM-exception OR Apache-2.0 OR MIT',
'BSD-2-Clause OR Apache-2.0 OR MIT',
'Zlib OR Apache-2.0 OR MIT', 'MIT OR Apache-2.0 OR Zlib',
'(MIT OR Apache-2.0) AND Unicode-3.0'}
NOTICE_NAME = re.compile(r'^(licen[cs]e|copying|notice|unlicense|copyright)([-.]|$)', re.I)
p = argparse.ArgumentParser(description=__doc__)
p.add_argument('destination', type=Path)
p.add_argument('--revision', required=True)
a = p.parse_args()
root = Path(__file__).resolve().parent.parent
host = next(x[6:] for x in subprocess.check_output(['rustc', '-vV'], text=True).splitlines() if x.startswith('host: '))
metadata = json.loads(subprocess.check_output(['cargo', 'metadata', '--locked', '--format-version', '1', '--filter-platform', host], cwd=root, text=True))
# Cargo metadata includes dev-unified/optional edges; use Cargo's actual normal
# and build tree to select the shipped graph instead of guessing feature edges.
tree = subprocess.check_output(['cargo', 'tree', '--locked', '-p', 'sized', '--target', host, '--edges', 'normal,build', '--prefix', 'none', '--format', '{p}'], cwd=root, text=True)
selected = {tuple(re.match(r'^(\S+) v(\S+)', line).groups()) for line in tree.splitlines()}
packages = sorted([x for x in metadata['packages'] if (x['name'], x['version']) in selected], key=lambda x: (x['name'], x['version']))
assert len(packages) == len(selected), 'Ambiguous or missing package identity'
texts, inventory = {}, []
for package in packages:
if package['license'] not in REVIEWED:
raise ValueError(f"Unreviewed licence: {package['name']} {package['license']}")
directory = Path(package['manifest_path']).parent
files = sorted(f for f in directory.iterdir() if f.is_file() and NOTICE_NAME.match(f.name))
if not files:
raise ValueError(f"Missing licence text: {package['name']}")
notices = []
for f in files:
data = f.read_bytes(); text = data.decode('utf-8'); assert text.strip()
digest = hashlib.sha256(data).hexdigest()
texts.setdefault(digest, {'labels': [], 'text': text})['labels'].append(f"{package['name']} {package['version']} / {f.name}")
notices.append({'file': f.name, 'sha256': digest})
inventory.append({'name': package['name'], 'version': package['version'], 'license': package['license'], 'notices': notices})
header = ['Sized - Licences and credits', '', f'Source revision: {a.revision}',
f'Target: {host}', '', 'Sized and its core are GPL-3.0-only, without warranty.',
'Matching source, including the pinned core and dependency sources, is available at:',
'https://gamertan.com/projects/sized/ and the matching Gitea release.',
'The colored 2.2.0 source remains under MPL-2.0 and is additionally distributed',
'under GPL-3.0-only as part of this Larger Work under MPL section 3.3.',
'All original notices are preserved. See docs/RELEASE-LICENSING.md in the source.', '',
'Runtime and build dependencies (development-only dependencies are excluded):']
header += [f" {x['name']} {x['version']} - {x['license']}" for x in inventory]
for x in texts.values():
header += ['', '='*72, '\n'.join(x['labels']), '='*72, x['text']]
a.destination.mkdir(parents=True, exist_ok=True)
(a.destination/'LICENCES.txt').write_text('\n'.join(header)+'\n')
(a.destination/'DEPENDENCIES.json').write_text(json.dumps({'revision': a.revision, 'target': host, 'packages': inventory}, indent=2)+'\n')
print(f'Packaged complete notices for {len(inventory)} runtime/build crates ({host}).')
+42
View File
@@ -0,0 +1,42 @@
#!/usr/bin/env bash
set -euo pipefail
repo_root=$(cd "$(dirname "$0")/.." && pwd)
cd "$repo_root"
[[ $# == 1 && $1 == /* ]] || { echo 'Usage: scripts/package-source.sh ABSOLUTE_NEW_DIRECTORY' >&2; exit 2; }
destination=$1
[[ ! -e $destination && ! -L $destination ]] || { echo 'Refusing existing source output.' >&2; exit 1; }
git diff --quiet HEAD -- || { echo 'Commit tracked changes before packaging.' >&2; exit 1; }
revision=$(git rev-parse HEAD)
mkdir -p "$destination"
source_dir="$destination/sized-source"
mkdir "$source_dir"
git archive "$revision" | tar -x -C "$source_dir"
mkdir -p "$source_dir/.cargo"
cargo vendor --locked --versioned-dirs --manifest-path "$source_dir/Cargo.toml" "$source_dir/vendor" > "$destination/vendor-config"
sed 's|directory = ".*"|directory = "vendor"|' "$destination/vendor-config" > "$source_dir/.cargo/config.toml"
printf '%s\n' "$revision" > "$source_dir/SOURCE-REVISION.txt"
cat > "$source_dir/BUILD-OFFLINE.txt" <<BUILD
Sized 2.0.0 source checkpoint: $revision
Requires Rust 1.88 or newer and the target platform's C linker/toolchain.
From this directory: cargo build --locked --offline --release
Test: cargo test --locked --offline --workspace (run as an ordinary user)
Verify included core: python3 scripts/check-core.py
Make an unsigned host archive: SIZED_SOURCE_REVISION=$revision scripts/release.sh
Developer ID signing/notarization requires your own identity and is separate.
BUILD
(cd "$source_dir" && CARGO_HOME="$destination/empty-cargo-home" CARGO_TARGET_DIR="$destination/check-target" cargo check --locked --offline --workspace --all-targets)
(cd "$source_dir" && python3 scripts/check-core.py)
COPYFILE_DISABLE=1 tar --no-xattrs -czf "$destination/sized-v2.0.0-source.tar.gz" -C "$destination" sized-source
# Reject platform metadata sidecars before any publication or Linux rebuild.
python3 - "$destination/sized-v2.0.0-source.tar.gz" <<'PY_CHECK'
import sys, tarfile
from pathlib import PurePosixPath
with tarfile.open(sys.argv[1]) as archive:
for entry in archive:
if any(part.startswith('._') for part in PurePosixPath(entry.name).parts):
raise SystemExit(f'Unexpected AppleDouble metadata: {entry.name}')
if any('xattr' in key.lower() for key in entry.pax_headers):
raise SystemExit(f'Unexpected extended attributes: {entry.name}')
PY_CHECK
printf '%s\n' "$revision" > "$destination/SOURCE-REVISION.txt"
echo "Verified offline source: $destination/sized-v2.0.0-source.tar.gz"
+55 -49
View File
@@ -1,53 +1,59 @@
#!/bin/bash #!/usr/bin/env bash
set -e set -euo pipefail
VERSION=$(grep '^version =' Cargo.toml | cut -d '"' -f 2) # Build a host-target archive only. No tags, uploads, installers or signing.
DIST_DIR="dist/v$VERSION" repo_root=$(cd "$(dirname "$0")/.." && pwd)
cd "$repo_root"
echo "Building release assets for sized v$VERSION..." version=$(sed -n 's/^version = "\([^"]*\)"/\1/p' Cargo.toml)
target=$(rustc -vV | sed -n 's/^host: //p')
# 1. Clean and Prepare revision=${SIZED_SOURCE_REVISION:-$(git rev-parse HEAD 2>/dev/null || printf unknown)}
rm -rf "$DIST_DIR" destination="$repo_root/dist/sized-v$version-$target-${revision:0:12}"
mkdir -p "$DIST_DIR" if [[ $# == 2 && $1 == --output-dir ]]; then
destination=$2
# 2. Build Release Binary elif [[ $# != 0 ]]; then
cargo build --release printf 'Usage: %s [--output-dir ABSOLUTE_PATH]\n' "$0" >&2
exit 2
# 3. Generate Man Page
cargo run --release -- --generate-man-page "$DIST_DIR"
# 4. Generate Completions
cargo run --release -- --completions bash > "$DIST_DIR/sized.bash"
cargo run --release -- --completions zsh > "$DIST_DIR/_sized"
cargo run --release -- --completions fish > "$DIST_DIR/sized.fish"
# 5. Build Debian Package (if cargo-deb is installed)
if command -v cargo-deb &> /dev/null; then
echo "Building Debian package..."
# On macOS, we use --no-strip to avoid 'unrecognized option: --strip-unneeded'
# and --no-build because we already built the release binary.
cargo deb --no-build --no-strip
cp target/debian/*.deb "$DIST_DIR/"
echo "Note: .deb package contains the binary for $(uname -s)-$(uname -m)"
else
echo "Warning: cargo-deb not found. Skipping .deb packaging."
fi fi
[[ $destination == /* ]] || { printf 'Output directory must be absolute.\n' >&2; exit 2; }
for output in "$destination" "$destination.tar.gz" "$destination.tar.gz.sha256"; do
[[ ! -e $output && ! -L $output ]] || { printf 'Refusing to replace %s\n' "$output" >&2; exit 1; }
done
# 6. Build Alpine Package (Placeholder/Hook) target_dir=${CARGO_TARGET_DIR:-"$repo_root/target"}
# Note: For real .apk building, one usually uses a docker container or abuild. [[ $target_dir == /* ]] || target_dir="$repo_root/$target_dir"
# This serves as a reminder for Alpine users. python3 scripts/check-core.py
if [ -f "APKBUILD" ] && command -v abuild &> /dev/null; then cargo build --locked --release --target "$target" --target-dir "$target_dir"
echo "Building Alpine package..." binary="$target_dir/$target/release/sized"
abuild -r mkdir -p "$destination"
fi install -m 755 "$binary" "$destination/sized"
"$binary" --generate-man-page "$destination"
"$binary" --completions bash > "$destination/sized.bash"
"$binary" --completions zsh > "$destination/_sized"
"$binary" --completions fish > "$destination/sized.fish"
cp LICENSE README.md MANUAL.md CORE-SNAPSHOT.json "$destination/"
cp -R docs "$destination/"
python3 scripts/package-notices.py "$destination" --revision "$revision"
{
printf 'Version: %s\nTarget: %s\nSource revision: %s\n' "$version" "$target" "$revision"
printf 'Source worktree: '
if [[ $(git rev-parse --show-toplevel 2>/dev/null || true) == "$repo_root" ]]; then
if git diff --quiet HEAD --; then printf 'clean tracked files\n'; else printf 'modified tracked files\n'; fi
else
printf 'exported source; verify against supplied revision\n'
fi
rustc --version
cargo --version
printf 'Unsigned host build; not a notarized Mac application.\n'
} > "$destination/BUILD-INFO.txt"
# 7. Create General Release Tarball COPYFILE_DISABLE=1 tar --no-xattrs -czf "$destination.tar.gz" -C "$destination" .
echo "Creating release tarball..." (
tar -czf "dist/sized-v$VERSION-$(uname -s)-$(uname -m).tar.gz" -C "$DIST_DIR" . cd "$(dirname "$destination")"
archive="$(basename "$destination").tar.gz"
# 8. Copy Binary if command -v sha256sum >/dev/null 2>&1; then
cp target/release/sized "$DIST_DIR/" sha256sum "$archive" > "$archive.sha256"
else
echo "Success! Assets are ready in $DIST_DIR" shasum -a 256 "$archive" > "$archive.sha256"
ls -F "$DIST_DIR" fi
echo "Tarball: dist/sized-v$VERSION-$(uname -s)-$(uname -m).tar.gz" )
printf 'Archive: %s.tar.gz\nChecksum: %s.tar.gz.sha256\n' "$destination" "$destination"
+6 -6
View File
@@ -1,10 +1,10 @@
.ie \n(.g .ds Aq \(aq .ie \n(.g .ds Aq \(aq
.el .ds Aq ' .el .ds Aq '
.TH sized 1 "sized 1.0.0" .TH sized 1 "sized 2.0.0"
.SH NAME .SH NAME
sized \- A modern, fast, and concurrent disk usage analyzer sized \- A modern, fast, and concurrent disk usage analyzer
.SH SYNOPSIS .SH SYNOPSIS
\fBsized\fR [\fB\-v\fR|\fB\-\-version\fR] [\fB\-m\fR|\fB\-\-min\-size\fR] [\fB\-n\fR|\fB\-\-number\fR] [\fB\-\-sort\fR] [\fB\-a\fR|\fB\-\-apparent\fR] [\fB\-d\fR|\fB\-\-depth\fR] [\fB\-f\fR|\fB\-\-path\-full\fR] [\fB\-\-path\-relative\fR] [\fB\-j\fR|\fB\-\-threads\fR] [\fB\-\-completions\fR] [\fB\-i\fR|\fB\-\-ignore\fR] [\fB\-\-format\fR] [\fB\-\-save\fR] [\fB\-\-precision\fR] [\fB\-\-units\fR] [\fB\-c\fR|\fB\-\-compare\fR] [\fB\-h\fR|\fB\-\-help\fR] [\fIPATH\fR] \fBsized\fR [\fB\-v\fR|\fB\-\-version\fR] [\fB\-m\fR|\fB\-\-min\-size\fR] [\fB\-n\fR|\fB\-\-number\fR] [\fB\-\-sort\fR] [\fB\-a\fR|\fB\-\-apparent\fR] [\fB\-d\fR|\fB\-\-depth\fR] [\fB\-f\fR|\fB\-\-path\-full\fR] [\fB\-\-path\-relative\fR] [\fB\-j\fR|\fB\-\-threads\fR] [\fB\-x\fR|\fB\-\-one\-file\-system\fR] [\fB\-\-completions\fR] [\fB\-i\fR|\fB\-\-ignore\fR] [\fB\-\-format\fR] [\fB\-\-save\fR] [\fB\-\-precision\fR] [\fB\-\-units\fR] [\fB\-c\fR|\fB\-\-compare\fR] [\fB\-h\fR|\fB\-\-help\fR] [\fIPATH\fR]
.SH DESCRIPTION .SH DESCRIPTION
A modern, fast, and concurrent disk usage analyzer A modern, fast, and concurrent disk usage analyzer
.SH OPTIONS .SH OPTIONS
@@ -36,6 +36,9 @@ Display paths relative to current directory (default)
\fB\-j\fR, \fB\-\-threads\fR \fI<THREADS>\fR \fB\-j\fR, \fB\-\-threads\fR \fI<THREADS>\fR
Number of threads to use (defaults to available logical CPUs) Number of threads to use (defaults to available logical CPUs)
.TP .TP
\fB\-x\fR, \fB\-\-one\-file\-system\fR
Stay on the target\*(Aqs filesystem instead of descending into other mounts
.TP
\fB\-\-completions\fR \fI<COMPLETIONS>\fR \fB\-\-completions\fR \fI<COMPLETIONS>\fR
Generate shell completions Generate shell completions
.br .br
@@ -75,7 +78,4 @@ Print help
[\fIPATH\fR] [default: .] [\fIPATH\fR] [default: .]
Directory to analyze Directory to analyze
.SH VERSION .SH VERSION
v1.0.0 v2.0.0
.SH COPYRIGHT
sized is licensed under the GNU General Public License v3.0 (GPL-3.0).
+53 -177
View File
@@ -6,15 +6,17 @@ use colored::*;
use comfy_table::presets::UTF8_FULL; use comfy_table::presets::UTF8_FULL;
use comfy_table::{Attribute, Cell, CellAlignment, Color, ContentArrangement, Table}; use comfy_table::{Attribute, Cell, CellAlignment, Color, ContentArrangement, Table};
use csv::WriterBuilder; use csv::WriterBuilder;
use ignore::WalkBuilder;
use rayon::prelude::*;
use serde::Serialize;
use std::cmp::Ordering; use std::cmp::Ordering;
use std::io::Write; use std::io::Write;
use std::os::unix::fs::MetadataExt; use std::path::PathBuf;
use std::path::{Path, PathBuf};
use std::str::FromStr; use std::str::FromStr;
pub use scanner_core::{build_tree, scan};
pub use scanner_core::{
scan_tree, EntryType, FileIdentity, Node, ScanControl, ScanError, ScanIssue, ScanOptions,
ScanReport,
};
#[derive(Parser, Debug, Clone)] #[derive(Parser, Debug, Clone)]
#[command(author, version, about, long_about = None)] #[command(author, version, about, long_about = None)]
#[command(disable_version_flag = true)] #[command(disable_version_flag = true)]
@@ -61,6 +63,10 @@ pub struct Args {
#[arg(short = 'j', long = "threads")] #[arg(short = 'j', long = "threads")]
pub threads: Option<usize>, pub threads: Option<usize>,
/// Stay on the target's filesystem instead of descending into other mounts
#[arg(short = 'x', long)]
pub one_file_system: bool,
/// Generate shell completions /// Generate shell completions
#[arg(long, value_enum)] #[arg(long, value_enum)]
pub completions: Option<Shell>, pub completions: Option<Shell>,
@@ -125,7 +131,7 @@ impl FromStr for SortColumn {
"size" | "s" | "disk" | "d" => Ok(SortColumn::Disk), "size" | "s" | "disk" | "d" => Ok(SortColumn::Disk),
"apparent" | "a" => Ok(SortColumn::Apparent), "apparent" | "a" => Ok(SortColumn::Apparent),
"blocks" | "b" => Ok(SortColumn::Blocks), "blocks" | "b" => Ok(SortColumn::Blocks),
_ => Err(format!("Unknown column: {}", s)), _ => Err(format!("Unknown column: {s}")),
} }
} }
} }
@@ -142,45 +148,19 @@ impl FromStr for SortDirection {
match s.to_lowercase().as_str() { match s.to_lowercase().as_str() {
"asc" | "a" => Ok(SortDirection::Asc), "asc" | "a" => Ok(SortDirection::Asc),
"dsc" | "d" | "desc" => Ok(SortDirection::Dsc), "dsc" | "d" | "desc" => Ok(SortDirection::Dsc),
_ => Err(format!("Unknown direction: {}", s)), _ => Err(format!("Unknown direction: {s}")),
} }
} }
} }
#[derive(Clone, Serialize, Debug)] /// Returns whether the scan completed without missing entries. The caller
pub struct Node { /// chooses the exit status; partial reports remain available to the user.
pub path: PathBuf, pub fn run(args: Args, mut writer: &mut dyn Write) -> bool {
pub size_bytes: u64,
pub blocks: u64,
pub size_bytes_filtered: u64,
pub blocks_filtered: u64,
pub entry_type: EntryType,
pub accessible: bool,
#[serde(skip)]
pub children: Vec<Node>,
}
#[derive(Clone, Serialize, Debug, PartialEq, Eq, PartialOrd, Ord)]
pub enum EntryType {
File,
Dir,
}
impl std::fmt::Display for EntryType {
fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
match self {
EntryType::File => write!(f, "File"),
EntryType::Dir => write!(f, "Dir"),
}
}
}
pub fn run(args: Args, mut writer: &mut dyn Write) {
if let Some(shell) = args.completions { if let Some(shell) = args.completions {
let mut cmd = Args::command(); let mut cmd = Args::command();
let name = cmd.get_name().to_string(); let name = cmd.get_name().to_string();
generate(shell, &mut cmd, name, &mut std::io::stdout()); generate(shell, &mut cmd, name, &mut std::io::stdout());
return; return true;
} }
if let Some(out_dir) = args.generate_man_page { if let Some(out_dir) = args.generate_man_page {
@@ -193,28 +173,16 @@ pub fn run(args: Args, mut writer: &mut dyn Write) {
let file_path = out_dir.join("sized.1"); let file_path = out_dir.join("sized.1");
std::fs::write(&file_path, buffer).expect("Failed to write man page"); std::fs::write(&file_path, buffer).expect("Failed to write man page");
println!("Man page generated at {}", file_path.display()); println!("Man page generated at {}", file_path.display());
return; return true;
}
if let Some(threads) = args.threads {
rayon::ThreadPoolBuilder::new()
.num_threads(threads)
.build_global()
.ok(); // Ignore error if initialized called multiple times (e.g. in tests)
} }
let target_path = args.path.clone(); let target_path = args.path.clone();
if !target_path.exists() {
eprintln!("Error: Path '{}' does not exist.", target_path.display());
std::process::exit(1);
}
let min_bytes = if let Some(size_str) = &args.min_size { let min_bytes = if let Some(size_str) = &args.min_size {
match Byte::parse_str(size_str, true) { match Byte::parse_str(size_str, true) {
Ok(byte) => byte.as_u64(), Ok(byte) => byte.as_u64(),
Err(e) => { Err(e) => {
eprintln!("Error parsing size '{}': {}", size_str, e); eprintln!("Error parsing size '{size_str}': {e}");
std::process::exit(1); std::process::exit(1);
} }
} }
@@ -234,134 +202,40 @@ pub fn run(args: Args, mut writer: &mut dyn Write) {
} }
} }
let root_node = build_tree(&target_path, args.ignore, args.compare); let report = match scan_tree(
&target_path,
&ScanOptions {
respect_ignore: args.ignore,
compare_ignore: args.compare,
stay_on_filesystem: args.one_file_system,
threads: args.threads,
},
&ScanControl::default(),
) {
Ok(report) => report,
Err(e) => {
eprintln!("Error: {e}");
return false;
}
};
for issue in &report.issues {
eprintln!(
"Warning: incomplete scan at '{}': {}",
issue.path.display(),
issue.message
);
}
let root_node = report.root;
if root_node.size_bytes < min_bytes { if root_node.size_bytes < min_bytes {
if args.format == OutputFormat::Text { if args.format == OutputFormat::Text {
writeln!(writer, "Root directory is smaller than minimum size.").ok(); writeln!(writer, "Root directory is smaller than minimum size.").ok();
} }
return; return root_node.complete;
} }
process_node_recursive(&mut writer, &root_node, 0, &args, min_bytes, &sort_criteria); process_node_recursive(&mut writer, &root_node, 0, &args, min_bytes, &sort_criteria);
} root_node.complete
pub fn build_tree(path: &Path, ignore: bool, compare: bool) -> Node {
let metadata = path.symlink_metadata();
if let Ok(meta) = metadata {
// Treat symlinks as files (nodes) but do not recurse
if meta.is_file() || meta.is_symlink() {
return Node {
path: path.to_path_buf(),
size_bytes: meta.len(),
blocks: meta.blocks(),
size_bytes_filtered: meta.len(), // Single file is its own filtered size for now
blocks_filtered: meta.blocks(),
entry_type: EntryType::File,
accessible: true,
children: vec![],
};
}
}
// Check if we can read the directory (handle permissions)
if let Err(e) = std::fs::read_dir(path) {
if e.kind() == std::io::ErrorKind::PermissionDenied {
// Return an "empty" directory node marked as inaccessible
let meta = path.symlink_metadata().ok();
let size = meta.as_ref().map(|m| m.len()).unwrap_or(0);
let blocks = meta.as_ref().map(|m| m.blocks()).unwrap_or(0);
return Node {
path: path.to_path_buf(),
size_bytes: size,
blocks,
size_bytes_filtered: size,
blocks_filtered: blocks,
entry_type: EntryType::Dir,
accessible: false,
children: vec![],
};
}
}
// Total walker (always everything if compare is true, else respects 'ignore' arg)
let total_ignore = if compare { false } else { ignore };
let walker_total = WalkBuilder::new(path)
.standard_filters(false)
.hidden(false)
.git_ignore(total_ignore)
.ignore(total_ignore)
.max_depth(Some(1))
.build();
let child_paths_total: Vec<PathBuf> = walker_total
.into_iter()
.filter_map(|e| e.ok())
.filter(|e| e.path() != path)
.map(|e| e.path().to_path_buf())
.collect();
// Filtered set (only if compare is true)
let non_ignored_set: std::collections::HashSet<PathBuf> = if compare {
let walker_filtered = WalkBuilder::new(path)
.standard_filters(false)
.hidden(false)
.git_ignore(true)
.ignore(true)
.max_depth(Some(1))
.build();
walker_filtered
.into_iter()
.filter_map(|e| e.ok())
.filter(|e| e.path() != path)
.map(|e| e.path().to_path_buf())
.collect()
} else {
std::collections::HashSet::new()
};
let children: Vec<Node> = child_paths_total
.par_iter()
.map(|p| build_tree(p, ignore, compare))
.collect();
let mut size_bytes = 0;
let mut blocks = 0;
let mut size_bytes_filtered = 0;
let mut blocks_filtered = 0;
for child in &children {
size_bytes += child.size_bytes;
blocks += child.blocks;
if compare {
if non_ignored_set.contains(&child.path) {
size_bytes_filtered += child.size_bytes_filtered;
blocks_filtered += child.blocks_filtered;
}
} else {
size_bytes_filtered += child.size_bytes_filtered;
blocks_filtered += child.blocks_filtered;
}
}
let (self_size, self_blocks) = path
.symlink_metadata()
.map(|m| (m.len(), m.blocks()))
.unwrap_or((0, 0));
Node {
path: path.to_path_buf(),
size_bytes: size_bytes + self_size,
blocks: blocks + self_blocks,
size_bytes_filtered: size_bytes_filtered + self_size, // self is always part of self
blocks_filtered: blocks_filtered + self_blocks,
entry_type: EntryType::Dir,
accessible: true,
children,
}
} }
fn process_node_recursive( fn process_node_recursive(
@@ -372,8 +246,6 @@ fn process_node_recursive(
min_bytes: u64, min_bytes: u64,
sort_criteria: &[(SortColumn, SortDirection)], sort_criteria: &[(SortColumn, SortDirection)],
) { ) {
if node.children.is_empty() && node.entry_type == EntryType::Dir {}
let mut display_children: Vec<&Node> = node let mut display_children: Vec<&Node> = node
.children .children
.iter() .iter()
@@ -406,7 +278,7 @@ fn process_node_recursive(
print_output( print_output(
writer, writer,
&node, node,
&display_children, &display_children,
args, args,
&relative_path, &relative_path,
@@ -591,7 +463,7 @@ fn print_text(
} }
} }
writeln!(writer, "{}", summary).ok(); writeln!(writer, "{summary}").ok();
} else { } else {
writeln!(writer, "Total size: {}", "Access Denied".bold().red()).ok(); writeln!(writer, "Total size: {}", "Access Denied".bold().red()).ok();
} }
@@ -735,7 +607,7 @@ fn print_text(
Cell::new("N/A") Cell::new("N/A")
.fg(Color::Red) .fg(Color::Red)
.set_alignment(CellAlignment::Right), .set_alignment(CellAlignment::Right),
Cell::new("Access Denied") Cell::new("Unavailable")
.fg(Color::Red) .fg(Color::Red)
.set_alignment(CellAlignment::Right), .set_alignment(CellAlignment::Right),
]; ];
@@ -762,7 +634,7 @@ fn print_text(
table.add_row(row); table.add_row(row);
} }
} }
writeln!(writer, "{}", table).ok(); writeln!(writer, "{table}").ok();
} }
fn print_csv(writer: &mut dyn Write, children: &[&Node], args: &Args) { fn print_csv(writer: &mut dyn Write, children: &[&Node], args: &Args) {
@@ -794,6 +666,9 @@ fn print_json(writer: &mut dyn Write, parent_node: &Node, children: &[&Node], ar
"path": &c.path, "path": &c.path,
"entry_type": c.entry_type.to_string(), "entry_type": c.entry_type.to_string(),
"accessible": c.accessible, "accessible": c.accessible,
"complete": c.complete,
"hard_link_duplicate": c.hard_link_duplicate,
"skipped_mount": c.skipped_mount,
"disk_usage": c.blocks * 512, "disk_usage": c.blocks * 512,
"blocks": c.blocks, "blocks": c.blocks,
}); });
@@ -831,6 +706,7 @@ fn print_json(writer: &mut dyn Write, parent_node: &Node, children: &[&Node], ar
"total_blocks": parent_node.blocks, "total_blocks": parent_node.blocks,
"entries": entries_view, "entries": entries_view,
"accessible": parent_node.accessible, "accessible": parent_node.accessible,
"complete": parent_node.complete,
}); });
if args.apparent { if args.apparent {
+4 -2
View File
@@ -18,7 +18,7 @@ fn main() {
OutputFormat::Json => "json", OutputFormat::Json => "json",
_ => "txt", _ => "txt",
}; };
PathBuf::from(format!("{}_{}.{}", timestamp, dir_name, ext)) PathBuf::from(format!("{timestamp}_{dir_name}.{ext}"))
} else { } else {
path_arg.clone() path_arg.clone()
}; };
@@ -29,5 +29,7 @@ fn main() {
Box::new(std::io::stdout()) Box::new(std::io::stdout())
}; };
run(args, &mut writer); if !run(args, &mut writer) {
std::process::exit(1);
}
} }
+53 -1
View File
@@ -11,7 +11,7 @@ fn test_basic_cli_run() {
cmd.arg("--version") cmd.arg("--version")
.assert() .assert()
.success() .success()
.stdout(predicate::str::contains("sized 1.0.0")); .stdout(predicate::str::contains("sized 2.0.0"));
} }
#[test] #[test]
@@ -45,3 +45,55 @@ fn test_json_output() {
.stdout(predicate::str::contains("\"entry_type\":\"File\"")) .stdout(predicate::str::contains("\"entry_type\":\"File\""))
.stdout(predicate::str::contains("\"path\":")); .stdout(predicate::str::contains("\"path\":"));
} }
#[test]
fn missing_path_fails_without_a_success_report() {
let dir = TempDir::new().unwrap();
Command::new(env!("CARGO_BIN_EXE_sized"))
.arg(dir.path().join("missing"))
.args(["--format", "json"])
.assert()
.failure()
.stdout(predicate::str::is_empty())
.stderr(predicate::str::contains("cannot scan"));
}
#[cfg(unix)]
#[test]
fn partial_scan_has_nonzero_status_and_explicit_json_flag() {
use std::{fs, os::unix::fs::PermissionsExt};
let dir = TempDir::new().unwrap();
let blocked = dir.path().join("blocked");
fs::create_dir(&blocked).unwrap();
fs::set_permissions(&blocked, fs::Permissions::from_mode(0o000)).unwrap();
let result = std::panic::catch_unwind(|| {
assert!(
fs::read_dir(&blocked).is_err(),
"permission tests require an unprivileged user"
);
Command::new(env!("CARGO_BIN_EXE_sized"))
.arg(dir.path())
.args(["--format", "json"])
.assert()
.failure()
.stdout(predicate::str::contains("\"complete\":false"))
.stderr(predicate::str::contains("incomplete scan"));
});
fs::set_permissions(blocked, fs::Permissions::from_mode(0o700)).unwrap();
result.unwrap();
}
#[cfg(unix)]
#[test]
fn dangling_symlink_is_a_valid_scan_target() {
use std::os::unix::fs::symlink;
let dir = TempDir::new().unwrap();
let path = dir.path().join("dangling");
symlink(dir.path().join("missing"), &path).unwrap();
Command::new(env!("CARGO_BIN_EXE_sized"))
.arg(path)
.args(["--format", "json"])
.assert()
.success()
.stdout(predicate::str::contains("\"complete\":true"));
}
+96
View File
@@ -0,0 +1,96 @@
#![cfg(target_os = "linux")]
use sized::{scan_tree, ScanControl, ScanOptions};
use std::{fs, io::Write, os::unix::fs::MetadataExt, path::PathBuf, process::Command};
use tempfile::NamedTempFile;
#[test]
#[ignore = "requires the two owned tmpfs mounts from scripts/check-linux.sh"]
fn real_mount_boundary_is_respected_by_scanner_and_cli() {
let root = PathBuf::from(
std::env::var_os("SIZED_TEST_MOUNT_ROOT").expect("missing mounted Linux fixture"),
);
let foreign = root.join("foreign");
let root_metadata = fs::metadata(&root).unwrap();
let foreign_metadata = fs::metadata(&foreign).unwrap();
assert_ne!(
root_metadata.dev(),
foreign_metadata.dev(),
"not a real boundary"
);
let mut local_file = NamedTempFile::new_in(&root).unwrap();
let mut mounted_file = NamedTempFile::new_in(&foreign).unwrap();
local_file.write_all(b"local allocation").unwrap();
mounted_file.write_all(&[7; 8192]).unwrap();
local_file.as_file().sync_all().unwrap();
mounted_file.as_file().sync_all().unwrap();
for bounded in [false, true] {
let report = scan_tree(
&root,
&ScanOptions {
stay_on_filesystem: bounded,
threads: Some(2),
..ScanOptions::default()
},
&ScanControl::default(),
)
.unwrap();
assert!(report.root.complete);
assert!(report.issues.is_empty());
let mount = report
.root
.children
.iter()
.find(|n| n.path == foreign)
.unwrap();
assert_eq!(mount.identity.unwrap().device, foreign_metadata.dev());
assert_eq!(mount.skipped_mount, bounded);
assert_eq!(report.entries_scanned, if bounded { 3 } else { 4 });
let expected_blocks =
root_metadata.blocks() + local_file.as_file().metadata().unwrap().blocks();
if bounded {
assert!(mount.children.is_empty());
assert_eq!(mount.blocks, 0);
assert_eq!(mount.size_bytes, 0);
assert_eq!(report.root.blocks, expected_blocks);
} else {
assert_eq!(mount.children.len(), 1);
assert_eq!(mount.children[0].path, mounted_file.path());
assert_eq!(mount.children[0].size_bytes, 8192);
assert_eq!(
report.root.blocks,
expected_blocks
+ foreign_metadata.blocks()
+ mounted_file.as_file().metadata().unwrap().blocks()
);
}
let mut command = Command::new(env!("CARGO_BIN_EXE_sized"));
command
.arg(&root)
.args(["--format", "json", "--apparent", "--threads", "2"]);
if bounded {
command.arg("--one-file-system");
}
let output = command.output().unwrap();
assert!(
output.status.success(),
"{}",
String::from_utf8_lossy(&output.stderr)
);
assert!(output.stderr.is_empty());
let json: serde_json::Value = serde_json::from_slice(&output.stdout).unwrap();
assert_eq!(json["complete"], true);
assert_eq!(json["total_blocks"], report.root.blocks);
let mount_json = json["entries"]
.as_array()
.unwrap()
.iter()
.find(|entry| entry["path"] == foreign.to_str().unwrap())
.unwrap();
assert_eq!(mount_json["skipped_mount"], bounded);
assert_eq!(mount_json["blocks"], mount.blocks);
assert_eq!(mount_json["apparent_size"], mount.size_bytes);
}
}
+254
View File
@@ -0,0 +1,254 @@
#![cfg(unix)]
use sized::{build_tree, scan_tree, EntryType, ScanControl, ScanError, ScanOptions};
use std::{
fs,
io::Write,
os::unix::fs::{symlink, MetadataExt, PermissionsExt},
};
use tempfile::tempdir;
fn scan(path: &std::path::Path) -> sized::ScanReport {
scan_tree(path, &ScanOptions::default(), &ScanControl::default()).unwrap()
}
#[test]
fn hard_links_count_allocation_once_but_keep_apparent_sizes() {
let dir = tempdir().unwrap();
let original = dir.path().join("a-original");
fs::write(&original, [9; 65536]).unwrap();
fs::hard_link(&original, dir.path().join("z-alias")).unwrap();
let expected =
fs::metadata(&original).unwrap().blocks() + fs::metadata(dir.path()).unwrap().blocks();
for threads in [1, 4] {
let report = scan_tree(
dir.path(),
&ScanOptions {
threads: Some(threads),
..ScanOptions::default()
},
&ScanControl::default(),
)
.unwrap();
assert_eq!(report.root.blocks, expected);
assert_eq!(report.root.children[0].size_bytes, 65536);
assert_eq!(report.root.children[1].size_bytes, 65536);
assert!(!report.root.children[0].hard_link_duplicate);
assert!(report.root.children[1].hard_link_duplicate);
assert_eq!(report.root.children[1].blocks, 0);
assert_eq!(report.entries_scanned, 3);
assert!(report.root.complete);
}
}
#[test]
fn ignored_hard_link_does_not_steal_filtered_allocation() {
let dir = tempdir().unwrap();
fs::write(dir.path().join(".ignore"), "a-ignored\n").unwrap();
let original = dir.path().join("a-ignored");
fs::write(&original, [9; 65536]).unwrap();
fs::hard_link(&original, dir.path().join("z-included")).unwrap();
let report = scan_tree(
dir.path(),
&ScanOptions {
compare_ignore: true,
..ScanOptions::default()
},
&ScanControl::default(),
)
.unwrap();
let expected = fs::metadata(&original).unwrap().blocks()
+ fs::metadata(dir.path()).unwrap().blocks()
+ fs::metadata(dir.path().join(".ignore")).unwrap().blocks();
assert_eq!(report.root.blocks, expected);
assert_eq!(report.root.blocks_filtered, expected);
assert_eq!(report.root.children.last().unwrap().blocks, 0);
assert!(report.root.children.last().unwrap().blocks_filtered > 0);
}
#[test]
fn hidden_files_are_counted_without_ignore_filtering() {
let dir = tempdir().unwrap();
fs::write(dir.path().join(".hidden"), b"hidden").unwrap();
fs::write(dir.path().join(".ignore"), "build\n").unwrap();
fs::write(dir.path().join("build"), b"build").unwrap();
assert_eq!(scan(dir.path()).root.children.len(), 3);
let report = scan_tree(
dir.path(),
&ScanOptions {
respect_ignore: true,
..ScanOptions::default()
},
&ScanControl::default(),
)
.unwrap();
assert_eq!(report.root.children.len(), 2);
assert!(report
.root
.children
.iter()
.any(|n| n.path.ends_with(".hidden")));
}
#[test]
fn ignore_rules_are_inherited_by_nested_directories() {
let dir = tempdir().unwrap();
fs::write(dir.path().join(".ignore"), "*.tmp\n").unwrap();
let nested = dir.path().join("nested");
fs::create_dir(&nested).unwrap();
fs::write(nested.join("skip.tmp"), b"ignored").unwrap();
fs::write(nested.join("keep.bin"), b"included").unwrap();
let report = scan_tree(
dir.path(),
&ScanOptions {
respect_ignore: true,
..ScanOptions::default()
},
&ScanControl::default(),
)
.unwrap();
let children = &report
.root
.children
.iter()
.find(|n| n.path == nested)
.unwrap()
.children;
assert_eq!(children.len(), 1);
assert!(children[0].path.ends_with("keep.bin"));
let compared = scan_tree(
dir.path(),
&ScanOptions {
compare_ignore: true,
..ScanOptions::default()
},
&ScanControl::default(),
)
.unwrap();
assert_eq!(compared.root.size_bytes_filtered, report.root.size_bytes);
assert_eq!(compared.root.blocks_filtered, report.root.blocks);
}
#[test]
fn sparse_file_reports_blocks_and_logical_length_separately() {
let dir = tempdir().unwrap();
let path = dir.path().join("sparse");
let mut file = fs::File::create(&path).unwrap();
file.write_all(&[7; 4096]).unwrap();
file.set_len(128 * 1024 * 1024).unwrap();
file.sync_all().unwrap();
let node = scan(&path).root;
assert_eq!(node.size_bytes, 128 * 1024 * 1024);
assert_eq!(node.blocks, fs::metadata(path).unwrap().blocks());
assert!(node.blocks * 512 < node.size_bytes);
}
#[test]
fn symlinks_including_loop_and_dangling_link_are_leaves() {
let dir = tempdir().unwrap();
symlink(dir.path(), dir.path().join("loop")).unwrap();
symlink(dir.path().join("missing"), dir.path().join("dangling")).unwrap();
let report = scan(dir.path());
assert_eq!(report.root.children.len(), 2);
for node in report.root.children {
assert!(node.symlink);
assert!(node.children.is_empty());
assert!(node.complete);
}
}
#[test]
fn missing_root_returns_error_and_legacy_helper_marks_unavailable() {
let dir = tempdir().unwrap();
let path = dir.path().join("vanished");
assert!(
matches!(scan_tree(&path, &ScanOptions::default(), &ScanControl::default()),
Err(ScanError::Root { source, .. }) if source.kind() == std::io::ErrorKind::NotFound)
);
let node = build_tree(&path, false, false);
assert_eq!(node.entry_type, EntryType::Unknown);
assert!(!node.accessible);
assert!(!node.complete);
}
#[test]
fn permission_error_propagates_incomplete_status_to_root() {
let dir = tempdir().unwrap();
let blocked = dir.path().join("blocked");
fs::create_dir(&blocked).unwrap();
fs::write(blocked.join("unreadable"), b"data").unwrap();
fs::set_permissions(&blocked, fs::Permissions::from_mode(0o000)).unwrap();
let result = std::panic::catch_unwind(|| {
assert!(
fs::read_dir(&blocked).is_err(),
"permission tests require an unprivileged user"
);
let report = scan(dir.path());
assert!(report.root.accessible);
assert!(!report.root.complete);
assert!(!report.root.children[0].accessible);
assert_eq!(report.issues.len(), 1);
assert_eq!(report.issues[0].path, blocked);
assert_eq!(report.issues[0].kind, std::io::ErrorKind::PermissionDenied);
});
fs::set_permissions(blocked, fs::Permissions::from_mode(0o700)).unwrap();
result.unwrap();
}
#[test]
fn cancelled_scan_never_returns_completed_tree() {
let dir = tempdir().unwrap();
let control = ScanControl::default();
control.cancel();
assert!(matches!(
scan_tree(dir.path(), &ScanOptions::default(), &control),
Err(ScanError::Cancelled)
));
assert_eq!(control.entries_scanned(), 0);
}
#[test]
fn cancellation_and_progress_work_during_scan() {
let dir = tempdir().unwrap();
for i in 0..2000 {
fs::write(dir.path().join(format!("file-{i}")), b"x").unwrap();
}
let control = ScanControl::default();
let watcher = control.clone();
let cancel = std::thread::spawn(move || {
let deadline = std::time::Instant::now() + std::time::Duration::from_secs(5);
while watcher.entries_scanned() < 10 {
assert!(
std::time::Instant::now() < deadline,
"scan made no progress"
);
std::thread::yield_now();
}
watcher.cancel();
});
let result = scan_tree(
dir.path(),
&ScanOptions {
threads: Some(1),
..ScanOptions::default()
},
&control,
);
cancel.join().unwrap();
assert!(matches!(result, Err(ScanError::Cancelled)));
assert!(control.entries_scanned() >= 10);
}
#[test]
fn special_file_is_not_treated_as_directory() {
let dir = tempdir().unwrap();
let path = dir.path().join("fifo");
assert!(std::process::Command::new("mkfifo")
.arg(&path)
.status()
.unwrap()
.success());
let node = scan(&path).root;
assert_eq!(node.entry_type, EntryType::Special);
assert!(node.children.is_empty());
assert!(node.complete);
}