diff --git a/CHANGELOG.md b/CHANGELOG.md index 5ea60c1..f5ae264 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -34,6 +34,43 @@ which records not just what changed but what each drill run proved. ### Fixed +- **`box restore` asks before it destroys — and the confirmation prompt is + now the row's, not rm's** (#105) — `restore` and `rm` both irreversibly + discard user state, and only one of them asked. The table gave `restore` + the preconditions `box,arg2`: the instance is ours, a snapshot name is + present, go. So `box restore work stale-label` silently threw away + everything done in the box since that snapshot, with no prompt, no + `--force`, and no way to take it back — a warning in `--help` is not a + gate. It has been that way since the verb shipped, and it is about to + become routine rather than rare (heavy-duty/rig#62's pristine snapshot), + which is the wrong time to still be relying on the operator typing the + right label. The reason it stayed ungated is worth recording, because it + is the actual bug: `confirm` was already a precondition token, but the + dispatch line hardcoded the *words* — `confirm "delete $inst and all its + snapshots"` — so the one-token fix would have gated restore behind a + prompt offering to DELETE the box the operator was trying to rescue. A + gate that names the wrong act is worse than no gate; it is how people + learn to answer `y` without reading. So the prompt moved into the table + as a seventh field, each row saying what it is about to do in its own + words, and `restore` now asks to "roll `` back to snapshot + `