Several reasons:
* The user may not look at the trash anyway, and it would bloat their HD space
* Other sofware updaters don't move old versions to the trash either. Can confuse the user or not be seemly transparent experience.
* Moving app to trash will not work if user has to authenticate anyway
* Unclear how long and expensive this operation *could* take in all scenarios
* App replacements in Apple's new file system can be atomic-safe, but that may only be the case if the old app is no longer needed
Cons:
* Few tech savvy users may not be able to restore an app without re-downloading it. This would still be rarely done even amongst them.
I need to at least look at:
* Automatic downloaded / silent updates
* Running updates as root user from beginning
* Status info query service
* Add guided flag in the appcast
This changes the way we authorize & execute commands, and how we wait for their completion. In order to obtain the correct child to wait (instead of another one terminating intermediately), we use a wrapper tool (fileop) to output its pid onto the communication pipe that we read from the other end.
This fixes issues with updating modification/access time, and changing owner/group
where symbolic links used to be followed. Symbolic link tests are included.
The move operation now does an explict copy & remove.
We also copy items using FSCopyObjectSync due to issues
existing in copyfile (and NSFileManager).
Both of these fix bugs in some cases where items cannot be moved
from one network drive to another. In my testing before this patch,
I was unable to get the test application to launch and was unable
to move the old installation to the trash.
If we don't do this, Finder may not report the correct file size for the new update.
The system also may not register the new app in its database if we don't do this.
We may have been able to get away with not doing this before because we used to perform a copy
to install the update. However, now updates in some cases can be done with only move operations.
This should also be an alternative way of addressing issue #508
* Fix uid / gid not being applied to the root path or non-directory inputs
* Remove the code that released quarantines using the NSURL way.
It turned out not to be very reliable and didn't pass the tests.
More explanation is given in the code.
* Prefix private methods with _ and expose some of them to the tests