mirror of
https://github.com/abhigyanpatwari/GitNexus.git
synced 2026-10-03 02:21:44 +00:00
* feat(storage): add configurable index storage and content retention tiers Rebase #3060 onto current origin/main. Keep GITNEXUS_STORAGE_PATH, GITNEXUS_STORAGE_ROOT, and GITNEXUS_CONTENT_RETENTION, and fold in main's FTS skip, embed-session, and help-text updates. Co-authored-by: Cursor <cursoragent@cursor.com> * Address PR review feedback (#3060) Keep legacy registry rows on the local storage fallback, resolve symlinks before the destructive-path guard, and align hook lookup with CLI branch slugs, branch-slot metadata, and longest-path match. Co-authored-by: Cursor <cursoragent@cursor.com> * Address PR review feedback (#3060) Only list swept upload directories after a successful removal so callers cannot treat a permission or transient rm failure as gone. Co-authored-by: Cursor <cursoragent@cursor.com> * Address PR review feedback (#3060) Document that getStoragePath may consult registered storage while this module still does not mutate the global registry. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(storage): close review findings for external indexes and retention Re-inspect ownership under the analyze lock, fail-closed when the registry file is missing, and keep skip-git hook discovery plus retention fields on HTTP/MCP list surfaces. /api/file stays 410 unless contentRetention is full. Co-authored-by: Cursor <cursoragent@cursor.com> * chore(autofix): apply prettier + eslint fixes via /autofix command * Address PR review feedback (#3060) Treat lock-only index dirs as empty, honor HTTP --force storage policy, and prefer registered plus branch-aware slots in hooks and augment. Co-authored-by: Cursor <cursoragent@cursor.com> * Address PR review feedback (#3060) Keep hook fallbacks inside the current worktree, compare foreign-local slots canonically, and make storage fixtures survive ownership validation. Co-authored-by: Cursor <cursoragent@cursor.com> * Fix macOS hook test expecting realpath'd registry paths. resolveHookRepo returns the written registry path, not a filesystem realpath, so the assertion must match that. * Address gitnexus-check warnings on hook install docs and slot tests. The Cursor troubleshooting list omitted registry-query.cjs, and the writable-slot test only checked that isDirectory exists instead of that the path is a directory. * Align the HTTP catalog source-scan with skippable resolveRepo validation. resolveRepo lists fresh repos with validate: options.validateStorage !== false so DELETE can skip prune; the test still required a literal validate: true. * Harden storage path sinks so CodeQL path-injection and ReDoS alerts clear. Contain every filesystem probe inside the resolved storage slot with the inline path.relative idiom, reject filesystem-root slots, and trim slot basenames in linear time. * Settle bridge stamps before writing so CI size/mtime matches stay stable. LadybugDB can still flush into bridge.lbug after close+rename; persist whole-millisecond mtimes and wait for consecutive stats to agree so a freshly written pair matches. * Type the settled bridge stat as fs.Stats so tsc does not see bigint. Awaited<ReturnType<typeof fsp.stat>> collapsed the bigint overload and broke prepare/typecheck on CI. * Keep the bridge mtime stamp exact so same-size swaps still fail the pair check. Co-authored-by: Cursor <cursoragent@cursor.com> * Wrap the bridge stamp predicate so prettier --check stays green. Co-authored-by: Cursor <cursoragent@cursor.com> * Require a quiet interval before stamping a settled bridge file. Co-authored-by: Cursor <cursoragent@cursor.com> * Reuse shared storage and settle helpers instead of local copies. Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: Gergo Magyar <gergomagyar0@gmail.com> Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
350 lines
14 KiB
TypeScript
350 lines
14 KiB
TypeScript
/**
|
|
* Regression test for listRegisteredRepos({ validate: true }) bare catch bug.
|
|
*
|
|
* BEFORE FIX: bare catch {} dropped entries on ANY fs.access error (EIO, EAGAIN,
|
|
* EACCES, etc.) and persisted the pruned list → registry wiped to [].
|
|
*
|
|
* AFTER FIX: only prune on ENOENT/ENOTDIR (index genuinely gone). Transient I/O
|
|
* errors keep the entry alive.
|
|
*/
|
|
import { describe, it, expect, beforeEach, afterEach, vi } from 'vitest';
|
|
import path from 'path';
|
|
import fs from 'fs/promises';
|
|
import { registerRepo, listRegisteredRepos } from '../../src/storage/repo-manager.js';
|
|
import { createTempDir } from '../helpers/test-db.js';
|
|
|
|
// eslint-disable-next-line @typescript-eslint/no-explicit-any
|
|
const mockMeta: any = {
|
|
repoPath: '',
|
|
lastCommit: 'abc1234',
|
|
indexedAt: '2026-06-09T12:00:00.000Z',
|
|
stats: { files: 1, nodes: 1 },
|
|
};
|
|
|
|
const materializeLegacyIndex = async (repoPath: string): Promise<void> => {
|
|
const storagePath = path.join(repoPath, '.gitnexus');
|
|
await fs.mkdir(path.join(storagePath, 'lbug'), { recursive: true });
|
|
await fs.writeFile(
|
|
path.join(storagePath, 'meta.json'),
|
|
JSON.stringify({ ...mockMeta, repoPath }),
|
|
'utf8',
|
|
);
|
|
};
|
|
|
|
/**
|
|
* Read the persisted registry straight off disk so tests can assert what was
|
|
* actually written — the original bug was about *persisting* the wrong list,
|
|
* not just returning it. The registry lives at $GITNEXUS_HOME/registry.json
|
|
* (repo-manager getGlobalDir → getRegistryPath); readRegistry/writeRegistry
|
|
* use fs.readFile/fs.writeFile, NOT fs.access, so the fs.access mocks below
|
|
* never interfere with this read-back.
|
|
*/
|
|
// eslint-disable-next-line @typescript-eslint/no-explicit-any
|
|
const readRegistryFromDisk = async (): Promise<any[]> => {
|
|
const raw = await fs.readFile(
|
|
path.join(process.env.GITNEXUS_HOME as string, 'registry.json'),
|
|
'utf8',
|
|
);
|
|
return JSON.parse(raw);
|
|
};
|
|
|
|
describe('listRegisteredRepos({ validate: true }) — transient error safety (PR #2124)', () => {
|
|
let tmpHome: { dbPath: string; cleanup: () => Promise<void> };
|
|
let tmpRepo: { dbPath: string; cleanup: () => Promise<void> };
|
|
let savedGitnexusHome: string | undefined;
|
|
|
|
beforeEach(async () => {
|
|
tmpHome = await createTempDir('gitnexus-transient-home-');
|
|
tmpRepo = await createTempDir('gitnexus-transient-repo-');
|
|
savedGitnexusHome = process.env.GITNEXUS_HOME;
|
|
process.env.GITNEXUS_HOME = tmpHome.dbPath;
|
|
await materializeLegacyIndex(tmpRepo.dbPath);
|
|
});
|
|
|
|
afterEach(async () => {
|
|
vi.restoreAllMocks();
|
|
if (savedGitnexusHome === undefined) delete process.env.GITNEXUS_HOME;
|
|
else process.env.GITNEXUS_HOME = savedGitnexusHome;
|
|
await tmpRepo.cleanup();
|
|
await tmpHome.cleanup();
|
|
});
|
|
|
|
it('ENOENT prunes the entry (index genuinely removed)', async () => {
|
|
await registerRepo(tmpRepo.dbPath, mockMeta);
|
|
|
|
const before = await listRegisteredRepos({ validate: true });
|
|
expect(before).toHaveLength(1);
|
|
|
|
// Delete meta.json to simulate genuinely removed index
|
|
await fs.rm(path.join(tmpRepo.dbPath, '.gitnexus'), { recursive: true, force: true });
|
|
|
|
const after = await listRegisteredRepos({ validate: true });
|
|
expect(after).toHaveLength(0);
|
|
// The prune must be persisted — writeRegistry([]) ran.
|
|
expect(await readRegistryFromDisk()).toHaveLength(0);
|
|
});
|
|
|
|
it('ENOTDIR prunes the entry (structural removal)', async () => {
|
|
await registerRepo(tmpRepo.dbPath, mockMeta);
|
|
const before = await listRegisteredRepos();
|
|
expect(before).toHaveLength(1);
|
|
|
|
// Replace .gitnexus dir with a regular file — fs.access(path/meta.json)
|
|
// throws ENOTDIR because .gitnexus is now a file, not a directory
|
|
const dotGitnexus = path.join(tmpRepo.dbPath, '.gitnexus');
|
|
await fs.rm(dotGitnexus, { recursive: true, force: true });
|
|
await fs.writeFile(dotGitnexus, 'not-a-dir');
|
|
|
|
const after = await listRegisteredRepos({ validate: true });
|
|
expect(after).toHaveLength(0);
|
|
});
|
|
|
|
it('EACCES keeps the entry (transient permission error)', async () => {
|
|
await registerRepo(tmpRepo.dbPath, mockMeta);
|
|
const before = await listRegisteredRepos();
|
|
expect(before).toHaveLength(1);
|
|
|
|
// Mock fs.access to throw EACCES — simulates NFS hiccup or temp permission
|
|
const originalAccess = fs.access;
|
|
vi.spyOn(fs, 'access').mockImplementation(async (p, mode) => {
|
|
const pStr = typeof p === 'string' ? p : p.toString();
|
|
if (pStr.includes('.gitnexus') && pStr.includes('meta.json')) {
|
|
const err = new Error('permission denied') as NodeJS.ErrnoException;
|
|
err.code = 'EACCES';
|
|
throw err;
|
|
}
|
|
return (originalAccess as any).call(fs, p, mode);
|
|
});
|
|
|
|
const after = await listRegisteredRepos({ validate: true });
|
|
expect(after).toHaveLength(1);
|
|
expect(after[0].name).toBe(before[0].name);
|
|
// Keep path must NOT rewrite the registry — on-disk file is unchanged.
|
|
const onDisk = await readRegistryFromDisk();
|
|
expect(onDisk).toHaveLength(1);
|
|
expect(onDisk[0].name).toBe(before[0].name);
|
|
});
|
|
|
|
it('EIO keeps the entry (transient I/O error)', async () => {
|
|
await registerRepo(tmpRepo.dbPath, mockMeta);
|
|
const before = await listRegisteredRepos();
|
|
expect(before).toHaveLength(1);
|
|
|
|
const originalAccess = fs.access;
|
|
vi.spyOn(fs, 'access').mockImplementation(async (p, mode) => {
|
|
const pStr = typeof p === 'string' ? p : p.toString();
|
|
if (pStr.includes('.gitnexus') && pStr.includes('meta.json')) {
|
|
const err = new Error('input/output error') as NodeJS.ErrnoException;
|
|
err.code = 'EIO';
|
|
throw err;
|
|
}
|
|
return (originalAccess as any).call(fs, p, mode);
|
|
});
|
|
|
|
const after = await listRegisteredRepos({ validate: true });
|
|
expect(after).toHaveLength(1);
|
|
expect(await readRegistryFromDisk()).toHaveLength(1);
|
|
});
|
|
|
|
it('EAGAIN keeps the entry (resource temporarily unavailable)', async () => {
|
|
await registerRepo(tmpRepo.dbPath, mockMeta);
|
|
const before = await listRegisteredRepos();
|
|
expect(before).toHaveLength(1);
|
|
|
|
const originalAccess = fs.access;
|
|
vi.spyOn(fs, 'access').mockImplementation(async (p, mode) => {
|
|
const pStr = typeof p === 'string' ? p : p.toString();
|
|
if (pStr.includes('.gitnexus') && pStr.includes('meta.json')) {
|
|
const err = new Error('resource temporarily unavailable') as NodeJS.ErrnoException;
|
|
err.code = 'EAGAIN';
|
|
throw err;
|
|
}
|
|
return (originalAccess as any).call(fs, p, mode);
|
|
});
|
|
|
|
const after = await listRegisteredRepos({ validate: true });
|
|
expect(after).toHaveLength(1);
|
|
expect(await readRegistryFromDisk()).toHaveLength(1);
|
|
});
|
|
|
|
it('EBUSY keeps the entry (device/resource busy)', async () => {
|
|
await registerRepo(tmpRepo.dbPath, mockMeta);
|
|
const before = await listRegisteredRepos();
|
|
expect(before).toHaveLength(1);
|
|
|
|
const originalAccess = fs.access;
|
|
vi.spyOn(fs, 'access').mockImplementation(async (p, mode) => {
|
|
const pStr = typeof p === 'string' ? p : p.toString();
|
|
if (pStr.includes('.gitnexus') && pStr.includes('meta.json')) {
|
|
const err = new Error('resource busy') as NodeJS.ErrnoException;
|
|
err.code = 'EBUSY';
|
|
throw err;
|
|
}
|
|
return (originalAccess as any).call(fs, p, mode);
|
|
});
|
|
|
|
const after = await listRegisteredRepos({ validate: true });
|
|
expect(after).toHaveLength(1);
|
|
expect(await readRegistryFromDisk()).toHaveLength(1);
|
|
});
|
|
|
|
it.each(['EACCES', 'EIO', 'EBUSY'])(
|
|
'%s from gitnexus.json keeps the entry even when legacy meta.json is ENOENT',
|
|
async (newMetadataCode) => {
|
|
await registerRepo(tmpRepo.dbPath, mockMeta);
|
|
const before = await listRegisteredRepos();
|
|
expect(before).toHaveLength(1);
|
|
|
|
const newMetadataPath = path.join(tmpRepo.dbPath, '.gitnexus', 'gitnexus.json');
|
|
const legacyMetadataPath = path.join(tmpRepo.dbPath, '.gitnexus', 'meta.json');
|
|
|
|
const originalAccess = fs.access;
|
|
vi.spyOn(fs, 'access').mockImplementation(async (p, mode) => {
|
|
const pStr = typeof p === 'string' ? p : p.toString();
|
|
|
|
if (pStr === newMetadataPath) {
|
|
const err = new Error(newMetadataCode) as NodeJS.ErrnoException;
|
|
err.code = newMetadataCode;
|
|
throw err;
|
|
}
|
|
|
|
if (pStr === legacyMetadataPath) {
|
|
const err = new Error('no such file') as NodeJS.ErrnoException;
|
|
err.code = 'ENOENT';
|
|
throw err;
|
|
}
|
|
|
|
return (originalAccess as any).call(fs, p, mode);
|
|
});
|
|
|
|
const after = await listRegisteredRepos({ validate: true });
|
|
expect(after).toHaveLength(1);
|
|
expect(after[0].name).toBe(before[0].name);
|
|
|
|
const onDisk = await readRegistryFromDisk();
|
|
expect(onDisk).toHaveLength(1);
|
|
expect(onDisk[0].name).toBe(before[0].name);
|
|
},
|
|
);
|
|
|
|
it.each(['EACCES', 'EIO', 'EBUSY'])(
|
|
'%s from legacy meta.json keeps the entry when gitnexus.json is ENOENT',
|
|
async (legacyMetadataCode) => {
|
|
await registerRepo(tmpRepo.dbPath, mockMeta);
|
|
const before = await listRegisteredRepos();
|
|
expect(before).toHaveLength(1);
|
|
|
|
const newMetadataPath = path.join(tmpRepo.dbPath, '.gitnexus', 'gitnexus.json');
|
|
const legacyMetadataPath = path.join(tmpRepo.dbPath, '.gitnexus', 'meta.json');
|
|
|
|
const originalAccess = fs.access;
|
|
vi.spyOn(fs, 'access').mockImplementation(async (p, mode) => {
|
|
const pStr = typeof p === 'string' ? p : p.toString();
|
|
|
|
if (pStr === newMetadataPath) {
|
|
const err = new Error('no such file') as NodeJS.ErrnoException;
|
|
err.code = 'ENOENT';
|
|
throw err;
|
|
}
|
|
|
|
if (pStr === legacyMetadataPath) {
|
|
const err = new Error(legacyMetadataCode) as NodeJS.ErrnoException;
|
|
err.code = legacyMetadataCode;
|
|
throw err;
|
|
}
|
|
|
|
return (originalAccess as any).call(fs, p, mode);
|
|
});
|
|
|
|
const after = await listRegisteredRepos({ validate: true });
|
|
expect(after).toHaveLength(1);
|
|
expect(after[0].name).toBe(before[0].name);
|
|
|
|
const onDisk = await readRegistryFromDisk();
|
|
expect(onDisk).toHaveLength(1);
|
|
expect(onDisk[0].name).toBe(before[0].name);
|
|
},
|
|
);
|
|
|
|
it('mixed batch persists only the survivor (ENOENT pruned, EIO kept)', async () => {
|
|
// Two registered repos: one whose index is genuinely gone (ENOENT) and one
|
|
// that hits a transient I/O error (EIO) in the SAME validation call. This is
|
|
// the only path that persists a non-empty surviving SUBSET — exactly where
|
|
// an off-by-one would write the wrong list to disk.
|
|
const tmpRepoB = await createTempDir('gitnexus-transient-repo-b-');
|
|
try {
|
|
const nameA = await registerRepo(tmpRepo.dbPath, mockMeta);
|
|
const nameB = await registerRepo(tmpRepoB.dbPath, mockMeta);
|
|
await materializeLegacyIndex(tmpRepoB.dbPath);
|
|
|
|
const before = await listRegisteredRepos();
|
|
expect(before).toHaveLength(2);
|
|
|
|
// Repo A is genuinely gone: drop both metadata files so inspection
|
|
// cannot treat a leftover `gitnexus.json` from `registerRepo` as owned.
|
|
await fs.rm(path.join(tmpRepo.dbPath, '.gitnexus', 'gitnexus.json'), { force: true });
|
|
await fs.rm(path.join(tmpRepo.dbPath, '.gitnexus', 'meta.json'), { force: true });
|
|
|
|
// Branch on each repo's distinct temp-dir segment — both meta.json paths
|
|
// contain `.gitnexus`/`meta.json`, so matching those shared substrings
|
|
// alone would mis-route. repo B → EIO (keep).
|
|
const originalAccess = fs.access;
|
|
vi.spyOn(fs, 'access').mockImplementation(async (p, mode) => {
|
|
const pStr = typeof p === 'string' ? p : p.toString();
|
|
if (pStr.includes('meta.json') && pStr.includes(tmpRepoB.dbPath)) {
|
|
const err = new Error('input/output error') as NodeJS.ErrnoException;
|
|
err.code = 'EIO';
|
|
throw err;
|
|
}
|
|
return (originalAccess as any).call(fs, p, mode);
|
|
});
|
|
|
|
const after = await listRegisteredRepos({ validate: true });
|
|
// Return value: only the EIO survivor (repo B).
|
|
expect(after).toHaveLength(1);
|
|
expect(after[0].name).toBe(nameB);
|
|
expect(after.some((e) => e.name === nameA)).toBe(false);
|
|
|
|
// On-disk: the surviving subset was persisted correctly — exactly repo B,
|
|
// not [] (over-prune) and not both (no-op).
|
|
const onDisk = await readRegistryFromDisk();
|
|
expect(onDisk).toHaveLength(1);
|
|
expect(onDisk[0].name).toBe(nameB);
|
|
expect(onDisk.some((e) => e.name === nameA)).toBe(false);
|
|
} finally {
|
|
await tmpRepoB.cleanup();
|
|
}
|
|
});
|
|
|
|
it('returns only owned entries with a LadybugDB directory', async () => {
|
|
const foreignRepo = await createTempDir('gitnexus-validation-foreign-');
|
|
const missingDbRepo = await createTempDir('gitnexus-validation-no-db-');
|
|
try {
|
|
await registerRepo(tmpRepo.dbPath, mockMeta, { name: 'owned' });
|
|
await registerRepo(foreignRepo.dbPath, mockMeta, { name: 'foreign' });
|
|
await registerRepo(missingDbRepo.dbPath, mockMeta, { name: 'no-db' });
|
|
|
|
const foreignStorage = path.join(foreignRepo.dbPath, '.gitnexus');
|
|
await fs.mkdir(path.join(foreignStorage, 'lbug'), { recursive: true });
|
|
await fs.writeFile(
|
|
path.join(foreignStorage, 'meta.json'),
|
|
JSON.stringify({ ...mockMeta, repoPath: tmpRepo.dbPath }),
|
|
'utf8',
|
|
);
|
|
await fs.mkdir(path.join(missingDbRepo.dbPath, '.gitnexus'), { recursive: true });
|
|
await fs.writeFile(
|
|
path.join(missingDbRepo.dbPath, '.gitnexus', 'meta.json'),
|
|
JSON.stringify({ ...mockMeta, repoPath: missingDbRepo.dbPath }),
|
|
'utf8',
|
|
);
|
|
|
|
const entries = await listRegisteredRepos({ validate: true });
|
|
|
|
expect(entries.map((entry) => entry.name)).toEqual(['owned']);
|
|
expect(await readRegistryFromDisk()).toHaveLength(3);
|
|
} finally {
|
|
await foreignRepo.cleanup();
|
|
await missingDbRepo.cleanup();
|
|
}
|
|
});
|
|
});
|