isWorkingTreePristine already rejects every sparse mode, because each one
marks left-out entries skip-worktree and `git ls-files -v` expands a sparse
index. Only no-cone was tested; cover cone and cone with a sparse index too.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
- removeCheckoutStorage: keep the lock-safe order (unregister and drop the
pointer under the slot lock, delete the slot last), but when the final
rm fails, throw an error that says the checkout was already unregistered,
names the leftover slot, and points at `gitnexus clean --gc --force`.
- clean --gc preview no longer sweeps staging files: acquireIndexLock
takes `sweep: false`, which the dry-run reclaim passes.
- listStoreMetaRoots reports completeness; a store directory that cannot
be listed (other than missing) makes the parse-cache prune retain every
chunk instead of evicting keys other members still use.
- clean.shared.kept says "could not be removed" rather than "still open".
- ARCHITECTURE.md describes the stores/<key>/ layout and store.json
pointer; README lists every GITNEXUS_SHARED_STORE off value and that it
also stops clone sharing.
- Tests: close the direct Ladybug connection in finally; fix a fixture
JSDoc.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Explain the keptStaging early return where it is checked, reuse the
exported EmbeddingCheckpoint type in the publish test, and drop
review-step labels from test comments. No behavior change.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Trigger: on Windows, storage-slot.ts sanitizeSlotBasename prefixes a
device-name basename that has an extension (`CON.txt` -> `repository-CON.txt`),
but the hook's copy in registry-query.cjs only matched the bare device name.
With GITNEXUS_STORAGE_ROOT set, a checkout named e.g. `con.txt` got a
different slot from the hook than from the CLI, so the hook could not see its
index.
Fix: mirror the platform branch (extension form on win32, bare form
elsewhere) in all four byte-identical registry-query.cjs copies, and point
their header comments at storage-slot.ts. Add a hook-vs-TS parity test over
device-name basenames on both stubbed platforms, and fix the byte-identity
test title to say four copies.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Trigger: `analyze --skip-git <clone>/pkg` inside a clone with a registered
sibling of the same origin joined, or founded, a clone store. getRemoteUrl
answers from any subdirectory, so siblingCloneStore saw the enclosing
clone's remote. That broke the shared-store invariant that only tree roots
participate.
Fix: resolveOptedInStore now returns undefined for a path with no `.git`
entry. It uses hasGitDir, which accepts a directory or a linked-worktree
file, the same as resolveSharedStore's readCommonDir gate and run-analyze's
repoHasGit. `--share-with` from such a path throws a clear error.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Trigger: two registered clones of one origin, both still on local storage,
analyzing at the same time each saw no sibling store yet and founded a store
keyed on their own checkout path. registeredStore() then kept each clone in
its own store for good, so they never shared a graph.
Fix: when no sibling store exists, siblingCloneStore keys the new store on
the canonical path that sorts first among this clone and its registered
siblings (case-folded on Windows, like registryPathEquals), so every sibling
computes the same key. An existing sibling store still wins. Clones that
already diverged into two stores are not migrated.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
DELETE /api/repo called removeCheckoutStorage(storagePath) with no
unregister callback and no checkout path, swallowed every error, and
unregistered later outside the slot lock. For a shared-store slot this
left the checkout's store.json pointer behind, let an analyze re-register
between the slot removal and the unregister, and reported {deleted} even
when the slot lock could not be taken because an analyze held it.
The handler now calls removeCheckoutStorage(storagePath,
() => unregisterRepo(entry.path), entry.path), matching `gitnexus remove`
and `gitnexus clean`, so the unregister and the pointer removal run under
the slot lock; non-shared storage is still removed, then unregistered.
The later standalone unregister is gone. An IndexLockTimeoutError answers
409 and leaves the entry registered; any other failure propagates to the
handler's 500, also with the entry kept so the delete can be retried,
instead of unregistering over leftover index files.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Trigger: reclaim counted commit-graph references with loadMeta, which
returns null for a torn or unreadable gitnexus.json as well as for a
missing one. A member whose metadata could not be read therefore
"referenced nothing", and the graph it still used was deleted. Separately,
in `clean --gc` an orphan slot that fs.rm could not delete threw out of
reclaim, aborting the collection of every store after it.
Fix: the reference loop reads slot metadata with a local loadMetaStrict.
Only absent metadata (ENOENT/ENOTDIR, same legacy-mirror fallback as
loadMeta) means no reference; any other read error or a parse failure
throws with the file path, like listDirStrict. Every caller already
treats a reclaim throw as best effort (analyze logs "skipped cleanup",
slot removal ignores it) or surfaces it (clean --gc). A failed orphan
slot delete is now kept: it stays a member, so the graph it names is
kept too, and it is reported in ReclaimResult.keptMembers and by a new
clean --gc line. loadMeta itself is unchanged.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
A publish interrupted between moving the checkout's graph into
`.publish-<uuid>` staging and renaming staging onto the commit dir left
slot metadata at HEAD with no graph and no graphPath; the next reclaim
deleted the orphaned staging. The up-to-date fast path never checked that
the graph exists, so every later analyze reported "Already up to date"
over a checkout with no index. A failed restore in publishSharedGraph's
catch had the same outcome, and also deleted the staging dir holding the
only copy of the graph.
- run-analyze: for a shared-store slot, stat the graph the checkout reads
(resolveGraphPath for the flat slot, the branch slot's own lbug
otherwise) before the fast path; if it is missing, force a full
rebuild. An incremental run would diff nothing into a fresh, empty
database. Private .gitnexus indexes are unchanged: they only lose their
graph by hand, and metadata-only fast-path fixtures rely on that path.
- publishSharedGraph: when moving the staged graph back fails and it is
still in staging, keep the staging dir, log its path, and skip this
run's reclaim, which would otherwise delete it. The next analyze finds
no graph and rebuilds.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Trigger: an analyze that finished with embeddings still owed (meta carries
embeddingCheckpoint) was published as the commit graph, because the
feature key ignores the checkpoint and publish never checked it. The
published meta kept the checkpoint while the graph could never change. The
next run healed the embeddings privately, found the commit graph already
there, wiped its own healed graph and pointed back at the partial one.
Fix: publishSharedGraph treats a checkpointed graph as not shareable, so it
stays private and no published commit graph carries a checkpoint. When the
target commit graph exists but records a checkpoint, has fewer
stats.embeddings than the private graph, or has unreadable metadata, the
checkout keeps its private graph instead of re-pointing. The commit graph
is left as is because other checkouts may read it. Embeddings sync and the
server embed job already privatize a pointer slot before writing
(ensurePrivateSharedGraph).
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Trigger: a sparse checkout, a skip-worktree/assume-unchanged entry, or an
uninitialized submodule leaves `git status` clean, and the run's
indexCoverage.dirtyPaths drops paths with no file hash, so publishSharedGraph
published a graph missing those files as the commit graph. seedSharedSlot
then copied the seed's lastCommit into the new pointer slot, so the next
analyze of a sibling hit the up-to-date fast path without hashing.
Fix: add isWorkingTreePristine (storage/git.ts): the unfiltered
listWorkingTreeDirtyPaths must be empty (null fails closed) and every
gitlink in the index must have a checked-out `.git`. publishSharedGraph
requires it instead of isWorkingTreeDirty. seedSharedSlot keeps the seed's
lastCommit only when the seed is at HEAD and the checkout is pristine, so a
clean sibling still fast-paths onto the shared graph; any other seeded
pointer gets an empty lastCommit, like seedFromLocalIndex, and its next run
hash-diffs, then re-points at the commit graph on publish.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
A checkout whose `.gitnexus` is a symlink (e.g. `.gitnexus -> ..`) made
the shared-store pointer helpers operate on whatever it pointed at:
findLegacyLocalIndex listed the target as a "legacy index", so
`clean --local-index --force` recursively deleted the checkout's
siblings; writeSharedStorePointer wrote store.json/.gitignore there; and
removeSharedStorePointer deleted store.json there and could rm -r the
target directory.
All four now go through probePointerDir, which lstats `.gitnexus` and
accepts it only when it is a real directory whose realpath is
realpath(checkout)/.gitnexus (mirroring stale-branch-slots.ts). Anything
else is left untouched: no legacy index is reported or removed, and no
pointer is written or removed. removeLegacyLocalIndex re-probes after
sizing, just before its delete loop.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Clones of one repository now share like linked worktrees. A clone whose
normalized origin URL matches another registered, still-present clone
joins that clone's store, or founds one (keyed on its own path) that the
sibling joins on its next analyze. A lone clone keeps its own .gitnexus.
Graphs stay keyed by commit and feature key, so clones only ever share a
graph built from the same commit with the same settings.
`analyze --no-share` now records a lasting opt-out (`shareOptOut` on the
registry entry, preserved across re-registration); `--share-with` clears
it. The analyze worker reports the storage it wrote over IPC so the
server settles a clone's first shared slot.
A query-time base-plus-overlay graph stays out: LadybugDB reads one
database per query. Instead, private graph copies record whether the
filesystem cloned them copy-on-write (sharing unchanged pages on disk)
or made a full copy, and `status` reports it.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
- removing a checkout's storage unregisters it and removes its store
pointer before deleting the slot directory, which the file lock
backend uses for its lock file; withCheckoutSlotLock becomes
removeCheckoutStorage, used by remove, clean, and DELETE /api/repo,
and analyze --no-share follows the same order
- the clean --gc preview skips a slot whose index lock is held, matching
what --force would drop
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
- clean --gc aborts when the registry cannot be read instead of treating
every member as orphaned; with no registry file it collects only
members whose checkout directory is gone
- seeding from a repository-local index re-reads its metadata under the
index lock, so the copied graph and the saved metadata match
- clean --gc skips a store another collector removed meanwhile, and
reports "no shared stores" when stores/ holds only stray files
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
- clean, remove, and analyze --no-share remove the checkout's store
pointer while still holding the slot's index lock, so an analyze that
takes the lock next cannot have its new pointer deleted
- clean --gc does not follow a symlink under stores/ (lstat)
- removing a store pointer keeps the checkout's .gitnexus directory when
it cannot be listed, instead of treating it as empty
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
- analyze --no-share leaves the shared store even when routed to a
branch sub-index (gate on sharedStore, not placement.branch)
- clean --gc aborts a store whose member listing is unreadable instead
of treating it as empty, and skips non-directory entries under stores/
- reusing an existing commit graph no longer fails a finished analyze
when the redundant private graph cannot be wiped
- a store pointer holding JSON null, a number, a string, or an array is
treated as invalid
- clean, remove, and DELETE /api/repo hold the checkout slot's index
lock while deleting the slot
- the server analyze launcher waits on the checkout slot the worker
actually writes
- sync the Factory hook copy; isolate hook tests from storage overrides;
use a junction for the Windows worktree alias; the relative
GITNEXUS_HOME test now sets a relative home
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
These two strings were meant for e2a9467 and d746675 but were left out
of the commit; the zh-CN side landed.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* feat(setup): add Factory Droid (MCP + skills) to gitnexus setup
Register 'droid' in the editor-targets abstraction so `gitnexus setup -c droid`
writes the MCP server to ~/.factory/mcp.json and installs skills to
~/.factory/skills/ from the single canonical skills/ source (no per-editor
copies). uninstall.ts is target-driven, so removal is covered automatically.
Adds unit + round-trip coverage.
* feat(plugin): add gitnexus-factory-plugin for droid plugin install
* docs: add Factory Droid to editor support table and setup docs
* fix(factory-plugin): guard augment hook against fan-out and DB contention
Reuse the Claude adapter's acquireHookSlot and LadybugDB owner probe
(bundled byte-identical, kept in lockstep by a drift test) instead of
running an unguarded augment. Add direct tests for the hook and manifests.
* docs: align Factory row in editor support table
* fix(factory-plugin): honor GITNEXUS_HOOK_CLI_PATH so augment runs on Windows
* docs(hooks): point bundled guard copies at their drift tests
* docs(factory-plugin): note the Execute tokenizer's quoting limit
* docs(readme): clarify the Full tier and group the Factory row
* docs(hooks): trim drift note to a single line
* test(ci): run factory-plugin tests on the windows cross-platform lane
* refactor(hooks): drop the drift-note comments, the tests already enforce it
* fix(factory-plugin): pin CLI version and parse quoted shell patterns
- Pin mcp.json and the hook's npx fallback to gitnexus@<version> from
the plugin manifest, registered with the release sync script so a
mutable @latest can never execute on MCP connect or augment fallback
- Port the #2938 shell tokenizer (tokenizeShellWords + parseRgGrepPattern)
so quoted, backslash-escaped, --regexp=, -eVALUE, and -- patterns survive
- Add the #2938 regression matrix and pin assertions to factory-plugin.test.ts
* docs: add Factory Droid to published npm README
* fix(factory-plugin): wire marketplace so droid installs the Factory plugin
Add .factory-plugin/marketplace.json sourcing ./gitnexus-factory-plugin.
Droid reads it before .claude-plugin/marketplace.json, so
`droid plugin install` now delivers the Factory plugin (Execute matcher,
pinned mcp.json) instead of the translated Claude plugin (Bash matcher,
gitnexus@latest). Register the surface in the version-sync script and
cover the wiring in the factory and sync test suites.
* fix(factory-plugin): use registry lookup for index resolution
Bundle registry-query.cjs so external indexes resolve (#3060); re-pin to 1.6.12.
* fix(factory-plugin): sync Execute parser with Cursor hook
Fixes echo-rg and -f false positives; tighten test env isolation.
* fix(factory-plugin): stop no-match augment from re-running via npx
A PATH `gitnexus` that finds no match exits 0 with empty stderr, which
fell through to a second `npx -y gitnexus@<pin> augment` with its own 8s
timeout (16s worst case vs the 10s hook budget). Fall through to npx only
when the PATH launcher is missing (ENOENT); any launched PATH binary,
including a timeout or non-zero exit, now ends the augment.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix(factory-plugin): filter augment stderr to the [GitNexus] block
runAugment returned raw child stderr, so npm/Node/LadybugDB warnings leaked
into additionalContext and noise-only stderr counted as success. Port the
Claude adapter's extractAugmentContext (verbatim, with isDebugEnabled) and
apply it on every launch tier before the success decision. Adds a drift test
against the Claude copy and PATH-tier noise/noise-only behavior tests.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix(factory-plugin): quote DROID_PLUGIN_ROOT in hook command
An unquoted plugin root containing spaces (e.g. a Windows user profile
path) split into multiple argv words, so the PostToolUse hook silently
never ran. Quote it like the Claude plugin does, and pin the exact
quoted command in the hooks.json wiring test.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix(release): stage Factory plugin manifests in the release commit
The rc release job stages only the original four manifest surfaces in the
detached release commit, so the v<version> tag tree carried the Factory
plugin.json, mcp.json and marketplace.json at the previous version while
--check (working tree) passed. Stage them too, and guard the git add block
against the synced surfaces in sync-plugin-manifests.test.ts.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* refactor(factory-plugin): simplify hook gates, spawn tiers and tests
- main(): resolve the repo only after the tool-name and pattern gates,
matching the Claude/Cursor hook order (skips fs/git work on no-op calls).
- runAugment(): share one spawnAugment helper between the
GITNEXUS_HOOK_CLI_PATH and npx tiers; PATH tier ENOENT logic unchanged.
- factory-plugin test: pre-filter comment lines instead of `continue`.
- sync-plugin-manifests test: hoist EXECUTABLE_MCP_FILES and derive
TOTAL_SURFACES from its length.
- fnSource(): throw when the function or its closing brace is not found.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix(cli): list Factory Droid in localized setup help
`localizeCliHelp` overwrites the `setup` command description with the
`help.command.setup.description` i18n key, so the literal edited in
index.ts never reached `gitnexus setup --help`. Add Factory Droid to the
en and zh-CN keys.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* Address PR review feedback (#2543)
- factory hook: run every augment tier under the bundled Unix timeout
guard (npx tier group-kills), keeping exactly-one-tier fall-through
- hook-db-lock-probe: trim GITNEXUS_HOOK_{LSOF,PS}_PATH once so a padded
override is used, not silently replaced (all 3 copies)
- hook-lock: evict a stale slot via rename-to-tombstone + identity check,
so a concurrently recreated fresh lock is never deleted (all 4 copies)
- registry-query: a set-but-invalid storage override resolves no repo
instead of falling back to the registry storagePath (all 4 copies)
- publish.yml: stage the ten skill mcp.json manifests in the rc release
commit; the staging test now requires every synced surface
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* Address PR review feedback round 2 (#2543)
- hook-lock: replace rename-to-tombstone eviction with an O_EXCL per-slot
`.evicting` marker plus an identity re-check before unlink, so a live
lock is never moved, and a crashed evictor leaves only a self-expiring
marker (all 4 copies)
- hook-db-lock-probe: clamp GITNEXUS_HOOK_PROC_CMDLINE_MAX to a named
256 KiB ceiling and require an integer, so an oversized override can
no longer fail the buffer allocation and miss a live owner (all 3 copies)
- registry-query: treat an empty GITNEXUS_STORAGE_PATH/ROOT as set but
invalid, matching the CLI's `!== undefined` rule (all 4 copies); the
factory test env now deletes those keys instead of blanking them
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* Address PR review feedback round 3 (#2543)
- hook-db-lock-probe: a capped /proc cmdline read stops early only once
both the GitNexus token and the mcp/serve mode are present (or at EOF,
the ceiling, or the budget), so a mode word such as `--require mcp`
before the GitNexus path no longer hides a live owner (all 3 copies)
- registry-query: correct the override comment; a filesystem root is
invalid only for GITNEXUS_STORAGE_PATH, not GITNEXUS_STORAGE_ROOT
(all 4 copies, comment only)
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* Address PR review feedback round 4 (#2543)
- hook-db-lock-probe: an fd-directory read error other than ENOENT or
ENOTDIR on an identified server candidate now fails closed ('timeout')
instead of reporting not-owned (EMFILE/ENFILE/ENOMEM/EINTR)
- hook-db-lock-probe: resolve GITNEXUS_HOOK_TIMEOUT_PATH to an absolute
path before validating and caching it, so callers that spawn with a
request cwd can still execute the guard
- hook-db-lock-probe: document the chunked cmdline read's actual stop
conditions (all 3 copies)
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* Harden hook-lock eviction marker lifecycle (#2543)
Per the chosen option (B) for the stale-slot eviction race:
- `.evicting` markers carry a per-call owner token (pid + random hex)
- an evictor re-reads its token immediately before the slot identity
check and unlink; a stalled evictor whose marker was broken backs off
- `finally` removes the marker only while it still holds our token
- an orphaned marker is broken only if, re-checked just before unlink,
its bigint identity and token are unchanged from when judged stale
- doc comment states the two remaining two-syscall windows (slot
lstat->unlink, marker token->unlink); POSIX has no conditional
unlink, and the worst case is one extra concurrent augment
All four byte-identical hook-lock copies updated.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* Fix CodeQL file-system race in hook-lock orphan-marker check (#2543)
breakOrphanedMarker stat'd the marker by path and then read it by path,
which CodeQL flags (js/file-system-race): the file could be replaced
between the two calls. Take the stat and the token from one open
descriptor (readMarkerSnapshot, O_NOFOLLOW where available) for both the
"judged stale" snapshot and the pre-unlink re-check. All four hook-lock
copies updated.
The replaced-marker test injected its swap via a readFileSync(path) spy,
which no longer fires; it now swaps the marker just before its second
open, counting opens of the marker path only (a per-path counter fired
early on slot-0 and let a mutant pass).
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* Unregister hook-lock exit listener on release (#2543)
Each acquireHookSlot registered `release` as a process 'exit' listener
that was never removed, so a long-lived process acquiring and releasing
slots repeatedly would accumulate listeners (MaxListenersExceededWarning)
and retain every closure. release() now removes itself. All four
hook-lock copies updated; a test asserts 12 acquire/release cycles leave
the 'exit' listener count unchanged.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Gergő Magyar <gergomagyar@icloud.com>
Co-authored-by: Gergo Magyar <gergomagyar0@gmail.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
- clean --gc never collects a slot whose index lock is held: an analyze
holds it until it registers the checkout, so a seeded but not yet
registered slot is busy, not orphaned.
- Reclaim compares absolute paths, so a relative GITNEXUS_HOME does not
make live commit graphs look unreferenced.
- graphPath is followed only into a published <commit>-<featureKey>
dir, never .publish-* staging (TS and all three hook copies).
- clean --gc fails on an unreadable stores root instead of reporting
nothing to collect.
- --no-share help states it is for opted-in clones.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
- Reject --no-share in a linked worktree before taking any lock or
indexing anything.
- clean --all and remove also delete each shared checkout's pointer.
- Delete an empty store only while also holding its cache lock, and
re-check emptiness under it.
- A store pointer is trusted only when the slot's own metadata names
this checkout; the editable pointer file just says where to look.
- Device names with an extension are prefixed on Windows only, so POSIX
slot names stay stable.
- Test fixtures use the gitnexus-test- prefix the stale-sidecar sweep
recognizes; help text and the private-graph label are accurate.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
- Hold the slot index lock for the whole server embedding job, not
just the graph copy.
- --no-share re-registers and deletes the old slot under that slot's
index lock, so a running shared analyze cannot re-register it.
- clean --gc previews without --force, like every other destructive arm.
- status reports a pinned branch index as private.
- Slot names prefix Windows device names that carry an extension.
- A slot or store named ..<name> is a legal direct child.
- Shared-store suites run in the serialized lbug-db vitest project and
clear an inherited GITNEXUS_SHARED_STORE.
- Doc and test accuracy fixes.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Address CodeQL js/path-injection and js/file-system-race on
shared-store.ts: every filesystem read rebuilds its path under a fixed
parent with an inline path.relative barrier, the .git probe is one read
(EISDIR marks a directory) instead of stat-then-read, and the graph
pointer cache stats and reads through one file descriptor.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The server embed job copies a shared checkout's graph under the slot's
index lock, so a CLI analyze in another process cannot interleave. A
forced rebuild with no embeddings to carry over drops the pointer
without copying a graph it would discard unread.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
--help renders option text from the i18n catalog, so --share-with,
--no-share, clean --gc and clean --local-index need keys in both
locales, not just index.ts literals.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
- Never publish a graph whose build saw dirty files, and never trust a
local-index seed on the up-to-date path; it may hold reverted edits.
- Record slot pointers and reclaim under the publish lock, and reclaim
right after each publish, so a commit graph is never deleted between
publish and pointer save and superseded graphs don't pile up.
- clean --gc decides membership from the registry, so opted-in clones
and a main checkout without worktrees are not dropped.
- Leaving a store re-registers first, so an up-to-date run cannot leave
the registry pointing at a deleted slot.
- Drop pinned branch summaries when an entry moves into a store slot.
- Keep run.cjs and the AGENTS.md runner path inside the checkout.
- MCP handles follow the slot's current graph, and branch scoping reads
the slot's own metadata.
- Cache resolveGraphPath by metadata file identity; look up opted-in
entries with canonical registry paths.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
One graph-clone helper replaces two copy-then-rename blocks; clean and
status reuse formatSlotSize; leaving a store reuses
removeSharedStorePointer; withStoreLock is imported from its own module
instead of a re-export.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
MCP, the HTTP API, group sync, augmentation, and the Claude hook (all
three byte-identical copies) resolve a flat slot's graph through
resolveGraphPath instead of joining 'lbug' onto the storage path, so
checkouts at one commit share one open database. The embeddings writers
(embeddings sync and the server embed job) take a private copy first
and never write an immutable commit graph. The post-analyze settle
probe accepts fresh metadata that points at an existing commit graph.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
A shared checkout gets <repo>/.gitnexus/store.json pointing at its store
slot; resolution follows it only when it names that checkout's own slot.
An existing local index seeds the slot and is left in place. status
(text and --json) and doctor report the store, whether the graph is
shared or private, and any leftover local index, which
clean --local-index removes while keeping the pointer. With
GITNEXUS_SHARED_STORE=off a previously shared checkout indexes into its
own .gitnexus again and never writes a commit graph.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
A clean shared checkout reads a commit graph and owns no graph file, so
the code-index presence check made status report it unindexed and
registry validation skip it. The check now follows the slot's
validated graphPath.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
An independent clone joins a linked worktree's shared store only with
analyze --share-with <repo>, and only when its normalized origin URL
matches that member's (credentials stripped, as #2054 compares). The
registry remembers the choice. --no-share moves an opted-in clone back
to its own .gitnexus and reclaims its old slot; linked worktrees always
share and are pointed at GITNEXUS_SHARED_STORE=off instead.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Deleting a shared checkout slot (clean, clean --all, remove, and the
server delete route) recounts references under the store's publish
lock and deletes commit graphs no member points at, then the store
itself once empty. A graph that cannot be deleted (open on Windows) is
reported and kept for the next pass. clean --gc also drops member slots
whose worktree is gone or no longer resolves to the store.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Linked worktrees read and write the parse cache and durable ParsedFile
store under the store's caches/ directory. Before pruning, a run folds
in the chunk keys recorded by every member slot and commit graph, and
the fold, prune and save run under a store-wide cache lock so one
member never evicts another's live chunks.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
A new shared slot is seeded from the store's commit graph nearest to
HEAD, else from this checkout's or the main checkout's
repository-local index (copied under that index's lock, source left in
place). The run that follows is up to date or incremental instead of a
full build. If a pointed-at shared graph has been removed, analyze
falls back to a full build instead of an incremental update over a
missing baseline.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
A linked worktree writes its own slot in the shared store. A new slot
is seeded with a pointer to the nearest commit graph, so a clean
checkout at an indexed commit takes the up-to-date path and writes no
graph. A checkout with local changes gets a copy-on-write private
graph before its first write. After a successful run, a clean checkout
at HEAD publishes its graph into commits/ under a store lock, or drops
it when that commit graph already exists. Commit graphs are never
written after publish.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
getStoragePaths reads a flat slot's recorded graphPath only for checkout
slots under the stores directory; other paths keep <storagePath>/lbug with
no I/O. A recorded path outside the store's commit graphs is ignored.
resolveStoragePath falls back to an existing store slot for an
unregistered checkout, so reads never move to an empty slot.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Linked worktrees of one repository resolve to one store under
GITNEXUS_HOME/stores/<key>, keyed by the canonical git common dir. The
resolver reads the .git entry directly, so hot paths spawn no git. Slot
naming moves to a leaf module so storage-resolver and shared-store do not
import each other.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix(query): send hub content once across process_symbols rows
With include_content, a symbol in several execution flows carried its
full source text on every (id, process_id) row. Keep content on the
first row for each symbol id and omit it from later rows. Membership
fields, is_entry_point, and symbol_count are unchanged.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix(query): point agents to the content row and lock the dedup in tests
The query tool text now says content is kept once per symbol id across
the whole process_symbols array, possibly under a different process_id,
and names context({uid, include_content: true}) as the fallback.
Tests: the integration suite asserts func:validate has two rows with
content on exactly one. Unit tests cover a later entry-point row that
is flagged and stripped, a hub in three processes, and that the shaper
does not mutate its input.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix(query): state the content-once rule on include_content and in the query hint
The query tool's include_content property now says content is sent once
per symbol id, on its first process_symbols row, and that
context({uid: "<id>", include_content: true}) returns it for any row.
When a query asked for content, the Next hint adds that same fallback;
without include_content the hint is unchanged. The example call now
uses the "<id>" placeholder style used elsewhere in the tool text.
Tests: pin the property sentence, check the hint with and without
include_content, and cover a max_symbols slice that moves the content
row to a later process and a first row that is also the entry point.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Gergo Magyar <gergomagyar0@gmail.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>