fix(backup): percent-encode path in _query_ro_sqlite URI

verify_sqlite_integrity() (now the source gate in _safe_restore_db) opens
the file through _query_ro_sqlite with a raw f"file:{path}?mode=ro" URI.
Under a path containing '#', SQLite treats the rest as a fragment: the
?mode=ro is dropped, the pre-'#' prefix is opened read-write (and created
empty), and the integrity check passes a corrupt source. Use
Path.as_uri(), matching the other restore-flow sites.

Salvaged from PR #123374.

Co-authored-by: joaomarcos <joaomarcosdias444@gmail.com>
This commit is contained in:
salch-cred
2026-09-26 18:22:10 +05:30
committed by kshitij
parent a609bad294
commit 793c07ffaf

View File

@@ -348,7 +348,7 @@ def _query_ro_sqlite(path: Path, fn):
"""Run ``fn(conn)`` on a read-only connection to *path*; return ``(value, None)`` or ``(None, exc)``."""
conn = None
try:
conn = sqlite3.connect(f"file:{path}?mode=ro", uri=True, timeout=1.0)
conn = sqlite3.connect(f"{path.resolve().as_uri()}?mode=ro", uri=True, timeout=1.0)
return fn(conn), None
except Exception as exc:
return None, exc