aboutsummaryrefslogtreecommitdiff
path: root/lib
diff options
context:
space:
mode:
authorDaniel Kahn Gillmor <dkg@fifthhorseman.net>2016-04-08 22:54:48 -0300
committerDavid Bremner <david@tethera.net>2016-04-15 07:07:23 -0300
commit604d1e0977c2ede365f87492d6b9bf9a83c3e1d3 (patch)
tree4b54122413b1d49543345366782256bdd3e531a6 /lib
parent92559ee3473381b0ba207ddb7db944d6ffadc2db (diff)
fix thread breakage via ghost-on-removal
implement ghost-on-removal, the solution to T590-thread-breakage.sh that just adds a ghost message after removing each message. It leaks information about whether we've ever seen a given message id, but it's a fairly simple implementation. Note that _resolve_message_id_to_thread_id already introduces new message_ids to the database, so i think just searching for a given message ID may introduce the same metadata leakage.
Diffstat (limited to 'lib')
-rw-r--r--lib/message.cc30
1 files changed, 27 insertions, 3 deletions
diff --git a/lib/message.cc b/lib/message.cc
index 8d72ea22..415eac1b 100644
--- a/lib/message.cc
+++ b/lib/message.cc
@@ -1037,20 +1037,44 @@ _notmuch_message_sync (notmuch_message_t *message)
message->modified = FALSE;
}
-/* Delete a message document from the database. */
+/* Delete a message document from the database, leaving a ghost
+ * message in its place */
notmuch_status_t
_notmuch_message_delete (notmuch_message_t *message)
{
notmuch_status_t status;
Xapian::WritableDatabase *db;
+ const char *mid, *tid;
+ notmuch_message_t *ghost;
+ notmuch_private_status_t private_status;
+ notmuch_database_t *notmuch;
+
+ mid = notmuch_message_get_message_id (message);
+ tid = notmuch_message_get_thread_id (message);
+ notmuch = message->notmuch;
status = _notmuch_database_ensure_writable (message->notmuch);
if (status)
return status;
- db = static_cast <Xapian::WritableDatabase *> (message->notmuch->xapian_db);
+ db = static_cast <Xapian::WritableDatabase *> (notmuch->xapian_db);
db->delete_document (message->doc_id);
- return NOTMUCH_STATUS_SUCCESS;
+
+ /* and reintroduce a ghost in its place */
+ ghost = _notmuch_message_create_for_message_id (notmuch, mid, &private_status);
+ if (private_status == NOTMUCH_PRIVATE_STATUS_NO_DOCUMENT_FOUND) {
+ private_status = _notmuch_message_initialize_ghost (ghost, tid);
+ if (! private_status)
+ _notmuch_message_sync (ghost);
+ } else if (private_status == NOTMUCH_PRIVATE_STATUS_SUCCESS) {
+ /* this is deeply weird, and we should not have gotten into
+ this state. is there a better error message to return
+ here? */
+ return NOTMUCH_STATUS_DUPLICATE_MESSAGE_ID;
+ }
+
+ notmuch_message_destroy (ghost);
+ return COERCE_STATUS (private_status, "Error converting to ghost message");
}
/* Transform a blank message into a ghost message. The caller must