Skip to content

Safety Model

Alexander Phillips edited this page Sep 20, 2026 · 1 revision

Safety Model

Safe Mode

Safe Mode is enabled by default. Eligible ordinary folders are moved to quarantine. Disabling it enables permanent folder deletion after explicit confirmation; it does not remove hard safety checks.

Condition Safe Mode on Safe Mode off
Eligible ordinary folder Quarantine Permanent delete after confirmation
Exact eligible ZFS dataset Cannot quarantine Dataset destroy after impact review and confirmation
Specific container/Compose or protected managed path Blocked Blocked
Incomplete ownership verification Blocked/unverified Blocked/unverified
Ignored row Not selectable Not selectable

Purge permanently removes already-quarantined data through its own explicit confirmation flow. Enabling Safe Mode does not cancel existing purge schedules.

Guardrails

Requests use server-issued candidate or quarantine IDs. Cleanup resolves them against server-side state, validates the same-host request and CSRF token, acquires an operation lock, and rechecks current paths and ownership.

Scan snapshots are session-scoped and expire after 30 minutes in the reviewed version. Rescan when a selection expires or belongs to an old session.

Protected targets include share/source roots, unsafe mount points, live or stopped specific container references, VM-managed locations, quarantine roots, traversal and symlinked path segments. Exact ZFS operations have separate dataset and descendant checks.

A restore cannot silently overwrite an existing destination. Recursive deletion must not follow symlinks outside the validated entry. State writes use locking and atomic JSON helpers.

Limits

The plugin cannot determine whether you personally need an unreferenced folder. Directory age, an “Empty” size, a missing container and a Ready badge are not backup guarantees.

Plugin locks serialize plugin operations; they do not freeze external Docker, mover, backup or filesystem activity. A dry run is a point-in-time preview, not a reservation. Keep independent backups and review final action results.

These protections are not intended to be bypassed through handwritten requests, edited state or altered source roots.

Clone this wiki locally