mirror of
https://github.com/abhigyanpatwari/GitNexus.git
synced 2026-10-05 02:43:32 +00:00
* feat(storage): add configurable index storage and content retention tiers Rebase #3060 onto current origin/main. Keep GITNEXUS_STORAGE_PATH, GITNEXUS_STORAGE_ROOT, and GITNEXUS_CONTENT_RETENTION, and fold in main's FTS skip, embed-session, and help-text updates. Co-authored-by: Cursor <cursoragent@cursor.com> * Address PR review feedback (#3060) Keep legacy registry rows on the local storage fallback, resolve symlinks before the destructive-path guard, and align hook lookup with CLI branch slugs, branch-slot metadata, and longest-path match. Co-authored-by: Cursor <cursoragent@cursor.com> * Address PR review feedback (#3060) Only list swept upload directories after a successful removal so callers cannot treat a permission or transient rm failure as gone. Co-authored-by: Cursor <cursoragent@cursor.com> * Address PR review feedback (#3060) Document that getStoragePath may consult registered storage while this module still does not mutate the global registry. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(storage): close review findings for external indexes and retention Re-inspect ownership under the analyze lock, fail-closed when the registry file is missing, and keep skip-git hook discovery plus retention fields on HTTP/MCP list surfaces. /api/file stays 410 unless contentRetention is full. Co-authored-by: Cursor <cursoragent@cursor.com> * chore(autofix): apply prettier + eslint fixes via /autofix command * Address PR review feedback (#3060) Treat lock-only index dirs as empty, honor HTTP --force storage policy, and prefer registered plus branch-aware slots in hooks and augment. Co-authored-by: Cursor <cursoragent@cursor.com> * Address PR review feedback (#3060) Keep hook fallbacks inside the current worktree, compare foreign-local slots canonically, and make storage fixtures survive ownership validation. Co-authored-by: Cursor <cursoragent@cursor.com> * Fix macOS hook test expecting realpath'd registry paths. resolveHookRepo returns the written registry path, not a filesystem realpath, so the assertion must match that. * Address gitnexus-check warnings on hook install docs and slot tests. The Cursor troubleshooting list omitted registry-query.cjs, and the writable-slot test only checked that isDirectory exists instead of that the path is a directory. * Align the HTTP catalog source-scan with skippable resolveRepo validation. resolveRepo lists fresh repos with validate: options.validateStorage !== false so DELETE can skip prune; the test still required a literal validate: true. * Harden storage path sinks so CodeQL path-injection and ReDoS alerts clear. Contain every filesystem probe inside the resolved storage slot with the inline path.relative idiom, reject filesystem-root slots, and trim slot basenames in linear time. * Settle bridge stamps before writing so CI size/mtime matches stay stable. LadybugDB can still flush into bridge.lbug after close+rename; persist whole-millisecond mtimes and wait for consecutive stats to agree so a freshly written pair matches. * Type the settled bridge stat as fs.Stats so tsc does not see bigint. Awaited<ReturnType<typeof fsp.stat>> collapsed the bigint overload and broke prepare/typecheck on CI. * Keep the bridge mtime stamp exact so same-size swaps still fail the pair check. Co-authored-by: Cursor <cursoragent@cursor.com> * Wrap the bridge stamp predicate so prettier --check stays green. Co-authored-by: Cursor <cursoragent@cursor.com> * Require a quiet interval before stamping a settled bridge file. Co-authored-by: Cursor <cursoragent@cursor.com> * Reuse shared storage and settle helpers instead of local copies. Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: Gergo Magyar <gergomagyar0@gmail.com> Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
119 lines
4.2 KiB
TypeScript
119 lines
4.2 KiB
TypeScript
/**
|
|
* Regression for PR #3060: ordinary `clean --force` must not trust a
|
|
* registry entry that redirects repository A to repository B's external index.
|
|
*
|
|
* This deliberately drives the real clean command, resolver, registry reader,
|
|
* and filesystem. Guard-only tests cannot catch a future bypass in clean.ts.
|
|
*/
|
|
import fs from 'node:fs/promises';
|
|
import path from 'node:path';
|
|
import { afterEach, beforeEach, describe, expect, it, vi } from 'vitest';
|
|
import { cleanCommand } from '../../src/cli/clean.js';
|
|
import { createTempDir, type TestDBHandle } from '../helpers/test-db.js';
|
|
import { initGitRepo } from '../helpers/temp-git-repo.js';
|
|
|
|
describe('cleanCommand external storage ownership', () => {
|
|
let fixture: TestDBHandle;
|
|
let previousGitNexusHome: string | undefined;
|
|
let repoA: string;
|
|
let repoB: string;
|
|
let storageB: string;
|
|
let registryPath: string;
|
|
|
|
beforeEach(async () => {
|
|
fixture = await createTempDir();
|
|
previousGitNexusHome = process.env.GITNEXUS_HOME;
|
|
|
|
const home = path.join(fixture.dbPath, 'home');
|
|
repoA = path.join(fixture.dbPath, 'repo-a');
|
|
repoB = path.join(fixture.dbPath, 'repo-b');
|
|
storageB = path.join(fixture.dbPath, 'external-index-b');
|
|
registryPath = path.join(home, 'registry.json');
|
|
|
|
await Promise.all([fs.mkdir(home, { recursive: true }), fs.mkdir(repoA), fs.mkdir(repoB)]);
|
|
initGitRepo(repoA);
|
|
initGitRepo(repoB);
|
|
|
|
await fs.mkdir(storageB);
|
|
const metadata = {
|
|
repoPath: repoB,
|
|
storagePath: storageB,
|
|
lastCommit: 'b-indexed-commit',
|
|
indexedAt: '2026-09-05T00:00:00.000Z',
|
|
};
|
|
await Promise.all([
|
|
fs.writeFile(path.join(storageB, 'gitnexus.json'), JSON.stringify(metadata)),
|
|
fs.writeFile(path.join(storageB, 'meta.json'), JSON.stringify(metadata)),
|
|
fs.writeFile(path.join(storageB, 'ownership-sentinel'), 'must survive\n'),
|
|
]);
|
|
|
|
// Deliberately corrupted registry: repository A names B's valid index.
|
|
await fs.writeFile(
|
|
registryPath,
|
|
JSON.stringify([
|
|
{
|
|
name: 'repo-a',
|
|
path: repoA,
|
|
storagePath: storageB,
|
|
lastCommit: 'a-indexed-commit',
|
|
indexedAt: '2026-09-05T00:00:00.000Z',
|
|
},
|
|
]),
|
|
);
|
|
|
|
process.env.GITNEXUS_HOME = home;
|
|
vi.spyOn(process, 'cwd').mockReturnValue(repoA);
|
|
vi.spyOn(console, 'log').mockImplementation(() => {});
|
|
});
|
|
|
|
afterEach(async () => {
|
|
vi.restoreAllMocks();
|
|
if (previousGitNexusHome === undefined) delete process.env.GITNEXUS_HOME;
|
|
else process.env.GITNEXUS_HOME = previousGitNexusHome;
|
|
await fixture.cleanup();
|
|
});
|
|
|
|
it('deletes a foreign repository-local .gitnexus on clean --all --force', async () => {
|
|
const localStorage = path.join(repoA, '.gitnexus');
|
|
await fs.mkdir(localStorage, { recursive: true });
|
|
const metadata = {
|
|
repoPath: repoB,
|
|
storagePath: localStorage,
|
|
lastCommit: 'foreign-local-commit',
|
|
indexedAt: '2026-09-05T00:00:00.000Z',
|
|
};
|
|
await fs.writeFile(path.join(localStorage, 'gitnexus.json'), JSON.stringify(metadata));
|
|
await fs.writeFile(path.join(localStorage, 'ownership-sentinel'), 'local-foreign\n');
|
|
await fs.writeFile(
|
|
registryPath,
|
|
JSON.stringify([
|
|
{
|
|
name: 'repo-a',
|
|
path: repoA,
|
|
storagePath: localStorage,
|
|
lastCommit: 'a-indexed-commit',
|
|
indexedAt: '2026-09-05T00:00:00.000Z',
|
|
},
|
|
]),
|
|
);
|
|
|
|
await cleanCommand({ force: true, all: true });
|
|
|
|
await expect(fs.access(localStorage)).rejects.toBeTruthy();
|
|
expect(JSON.parse(await fs.readFile(registryPath, 'utf-8'))).toEqual([]);
|
|
});
|
|
|
|
it('preserves a foreign external index and registry entry on ordinary clean --force', async () => {
|
|
await cleanCommand({ force: true });
|
|
|
|
await expect(fs.access(storageB)).resolves.toBeUndefined();
|
|
await expect(fs.access(path.join(storageB, 'gitnexus.json'))).resolves.toBeUndefined();
|
|
await expect(fs.access(path.join(storageB, 'meta.json'))).resolves.toBeUndefined();
|
|
await expect(fs.readFile(path.join(storageB, 'ownership-sentinel'), 'utf-8')).resolves.toBe(
|
|
'must survive\n',
|
|
);
|
|
|
|
const [remainingEntry] = JSON.parse(await fs.readFile(registryPath, 'utf-8'));
|
|
expect(remainingEntry).toMatchObject({ path: repoA, storagePath: storageB });
|
|
});
|
|
});
|