From 9ea551b60030f4eea6d94968ac4e02d399920a1b Mon Sep 17 00:00:00 2001 From: yyc12345 Date: Sun, 4 Oct 2026 10:11:48 +0800 Subject: [PATCH] docs: annotate safe delete and truncate operations with SAFETY comments --- YKanBan.Tests/TestUtilities/TempDirectory.cs | 5 +++++ YKanBan/Storage/Workspace/WorkspaceLock.cs | 3 +++ 2 files changed, 8 insertions(+) diff --git a/YKanBan.Tests/TestUtilities/TempDirectory.cs b/YKanBan.Tests/TestUtilities/TempDirectory.cs index e8017a2..fe5b79c 100644 --- a/YKanBan.Tests/TestUtilities/TempDirectory.cs +++ b/YKanBan.Tests/TestUtilities/TempDirectory.cs @@ -25,6 +25,9 @@ public sealed class TempDirectory : IDisposable { try { + // SAFETY: Recursive directory delete is safe: FullPath is the + // read-only, GUID-named directory this instance created under the + // OS temp folder, so it can never target user data or the temp root. Directory.Delete(FullPath, recursive: true); } catch (IOException) @@ -32,6 +35,8 @@ public sealed class TempDirectory : IDisposable Thread.Sleep(100); try { + // SAFETY: Retry of the same recursive delete, still confined to + // this instance's own temp directory. Directory.Delete(FullPath, recursive: true); } catch (IOException) diff --git a/YKanBan/Storage/Workspace/WorkspaceLock.cs b/YKanBan/Storage/Workspace/WorkspaceLock.cs index c689b94..8ac3753 100644 --- a/YKanBan/Storage/Workspace/WorkspaceLock.cs +++ b/YKanBan/Storage/Workspace/WorkspaceLock.cs @@ -39,6 +39,9 @@ public sealed class WorkspaceLock : IDisposable try { // FileShare.None gives the exclusive semantics; FileMode.Create empties any stale file. + // SAFETY: FileMode.Create truncates a pre-existing file, but the lock + // file is empty by design and the path always comes from + // WorkspacePaths.LockFile, so no user data is ever affected. stream = new FileStream(lockFilePath, FileMode.Create, FileAccess.Write, FileShare.None); } catch (DirectoryNotFoundException)