Compare commits
6 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 59d89bcd1b | |||
| 26adccce5b | |||
| 876ba8a8fc | |||
| 5cd528a4ef | |||
| c3fc029b1d | |||
| dc253e8da0 |
@@ -155,7 +155,7 @@ pub async fn download_container_file(
|
||||
/// Create a `.tar.gz` backup of the container and stream it to a host file.
|
||||
/// The archive contains:
|
||||
/// - the workspace (default /workspace), minus regenerable build artifacts
|
||||
/// (node_modules, target), at the archive root, and
|
||||
/// (node_modules, target), under `workspace/`, and
|
||||
/// - a sanitized copy of the home config under `home-claude/`: ~/.claude.json
|
||||
/// with secret-bearing keys removed (mcpServers/settings kept) and ~/.claude/
|
||||
/// minus the OAuth `.credentials.json`, so MCP servers, settings and skills
|
||||
@@ -204,6 +204,16 @@ pub async fn download_container_backup(
|
||||
// transient unreadable file from aborting the whole backup. If jq can't
|
||||
// parse ~/.claude.json we substitute an empty object — never the raw file —
|
||||
// so secrets can't leak through the sanitization fallback.
|
||||
// The `--transform` nests the workspace under `workspace/` (parallel to
|
||||
// `home-claude/`) so an extracted archive has both clearly labeled instead
|
||||
// of scattering the workspace files into the extraction dir. Rewriting the
|
||||
// leading `.` (rather than `./`) also renames tar's root member from `./` to
|
||||
// `workspace`, so the archive carries a proper `workspace/` dir entry rather
|
||||
// than a bare `./` that would stamp the source root's mode/mtime onto the
|
||||
// extraction directory. `flags=rh` rewrites regular member names AND
|
||||
// hardlink target names (so an intra-workspace hardlink pair still resolves
|
||||
// on extract) while leaving symlink targets untouched (rewriting those would
|
||||
// corrupt relative/absolute links).
|
||||
let script = r#"set -e
|
||||
STAGE=$(mktemp -d)
|
||||
trap 'rm -rf "$STAGE"' EXIT
|
||||
@@ -221,6 +231,7 @@ if [ -d "$HOME/.claude" ]; then
|
||||
fi
|
||||
tar czf - --ignore-failed-read \
|
||||
--exclude='*/node_modules' --exclude='*/target' \
|
||||
--transform='flags=rh;s,^\.,workspace,' \
|
||||
-C "$TC_BACKUP_SRC" . \
|
||||
-C "$STAGE" home-claude"#;
|
||||
|
||||
|
||||
Reference in New Issue
Block a user