fs-safe 0.19.0
Highlights
- Strict secret-file durability:
createSecretFileAtomic()acceptsdurable: "file"to require every file flush to succeed, including onEPERM; parent-directory synchronization remains best effort. (#644) - Literal
~names: keep FileStore keys, absolute Root reads, discovered walk entries, and ZIP/TAR entries literal instead of treating them as home-directory shorthand. Reads, writes, removal, pruning, extraction, and durable publication select the intended entry. (#633) - Native Unix descriptor safety: reject negative descriptors in low-level root, query, hash, copy, clone, staging, and cleanup calls without Rust panics or working-directory operations. Modern macOS beneath opens report
EBADFfor negative roots instead ofEIO. (#640, #643, #646)
Fixes
- Guest directory permissions: cross-device moves preserve mode
000, including nested directories, without changing other modes' umask behavior. Restore top-level permissions through the retained directory descriptor and preserve published entries on failure. Thanks @SebTardif. (#616) - ReFS clone cleanup: remove ordinary partial output when Windows rejects the ignore-readonly deletion flag. Keep readonly attributes intact and include cleanup failures in the original clone error; readonly files or other processes' open handles can still leave output behind. (#648)
Compatibility and documentation
- Secret creation's default and boolean durability options retain their behavior, and
writeSecretFileAtomic()remains boolean-only. Strict file synchronization preserves existing publication and cleanup semantics: a failure after publication can leave a complete file present. (#644) Root.walk("~")andRoot.walk("~/dir")expand home shorthand when iteration starts and return admitted canonical paths relative to the Root. Use./~/dirfor a literal tilde directory, and prefix returned entry paths with./when passing them to another Root method. Relative Root~/nameinputs still expand home; FileStore keys do not. (#633)- Guest moves still require OS permission to read mode-000 source directories; they do not widen source permissions. If permission restoration fails after publication, the source and published copy remain for caller reconciliation. (#616)
- Clarify that
Root.append()andopenWritable()creation modes remain subject to the process umask and do not chmod existing files. This documents existing behavior. (#636)
Published packages
| Package | Registry tarball | Verified integrity | Provenance |
|---|---|---|---|
| @openclaw/fs-safe-linux-x64-gnu@0.19.0 | tgz | sha512-ZPWb4zbUHRkBPCmpNY6dk+D1fO9U1+tq4xYwFpUILXSHAa8ESBDdzHXjrrEX2mLn3miVf6PLwuN1b3lJUNQXDQ== |
verified attestation |
| @openclaw/fs-safe-linux-x64-musl@0.19.0 | tgz | sha512-CmuvqfD7D9jXGZ387vKjPaxuzn2nW8MSNLrgDdbLUnLDk9n+df9lIeT7/RISUW9a8acJaPxIdbfc00JTnEhlew== |
verified attestation |
| @openclaw/fs-safe-linux-arm64-gnu@0.19.0 | tgz | sha512-IODKbsjNN+iDzeBqu16RBgyDRaX5nWSdENny3MiZF1kl4K4s/sw9GTxmKnhIeG06FlyGfb/BLjqDXT4nbEwcEQ== |
verified attestation |
| @openclaw/fs-safe-linux-arm64-musl@0.19.0 | tgz | sha512-7Qin04o5ncQOCyjopgvcSTYOracGI3jdM3svaaY7sHuPeB3DR+04bzg6ZtprG3oLagQ2VPRboCr+svfpgdk1QQ== |
verified attestation |
| @openclaw/fs-safe-darwin-x64@0.19.0 | tgz | sha512-uVfZWmk6R43uxRw0PXJB3zYa6pANCZgJ99zat7EedioZHyscAHG2LZIrXajn3mjsWCJqn5MYWo+U6hO5ijxP3Q== |
verified attestation |
| @openclaw/fs-safe-darwin-arm64@0.19.0 | tgz | sha512-Qh4RPjpSSCXeBQzlzIaOaSMOaTvKqKqVI+xJ9TaBr4VfW5hV6E0Wk2EBAjF/Z6pmYTBFgVMWNaK/+ILCcv8Sig== |
verified attestation |
| @openclaw/fs-safe-win32-x64-msvc@0.19.0 | tgz | sha512-dgvt0rTapHdZcy8dUAmVVmd58f3Z1sioejnDtdp9dVQq1Y0R2tMH9E8hnRdCpEAB2cAJ1VPb6lgT3jBRW8iU2w== |
verified attestation |
| @openclaw/fs-safe@0.19.0 | tgz | sha512-skoljavKmNulSdsu40HtSHNf39RfdZIZ4bfzxMJLT6n/7RK2PIPPMhxp0FoilRaeh1d8AHJRj6b2ZeDvTY1rSA== |
verified attestation |
Release proof: GitHub Actions run.