package recoverytrust import ( "crypto/rand" "encoding/hex" "errors" "fmt" "os" "path/filepath" "gitgud.io/mike/mpv-manager/internal/fileops" ) // WritePrivateFile atomically publishes content from a file whose permissions // are private from creation, including its Windows DACL. Recovery journals must // not expose signed nonterminal intent for another user to replay later. func WritePrivateFile(path string, content []byte) error { var nonce [16]byte if _, err := rand.Read(nonce[:]); err != nil { return err } stage := filepath.Join(filepath.Dir(path), "."+filepath.Base(path)+".tmp-"+hex.EncodeToString(nonce[:])) file, err := CreatePrivateFile(stage) if err != nil { return err } defer func() { _ = file.Close(); _ = os.Remove(stage) }() if _, err := file.Write(content); err != nil { return fmt.Errorf("write private recovery file: %w", err) } if err := errors.Join(file.Sync(), file.Close()); err != nil { return err } return fileops.RenameDurable(stage, path) }