Documentation
¶
Overview ¶
Package gitstatus observes status with frozen configuration and explicit repository paths. Git status must never execute repository-owned filters.
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
Index ¶
- Constants
- func CloseScratch()
- func CommonDirectory(root string) (string, error)
- func EnableOwnedWorker() error
- func Executable() string
- func Isolated(ctx context.Context) bool
- func OwnedWorker() bool
- func Pin() (string, error)
- func RefusalClass(err error) string
- func RefusalMessage(err error) string
- func RefusalReason(err error) (string, bool)
- func ScratchOutside(ctx context.Context, candidate string, roots ...string) error
- func Status(ctx context.Context, root string, limit int, run Runner, arguments ...string) ([]byte, error)
- func StatusIn(ctx context.Context, root, temporaryParent string, limit int, run Runner, ...) ([]byte, error)
- func WithIsolation(ctx context.Context) context.Context
- func WithProbeReuse(ctx context.Context) context.Context
- type MetadataProbeError
- type Runner
Constants ¶
const MaxProcesses = 7
MaxProcesses is the most Git processes one Status call starts: a config probe for each of config and config.worktree, the two index probes of validateIndex, and the status run, plus a tree read and private gitlink status when gitlinks are present. A caller's process budget covers it.
Variables ¶
This section is empty.
Functions ¶
func CloseScratch ¶
func CloseScratch()
CloseScratch removes every scratch directory still in use and refuses new ones. A process calls it once, just before it exits, since a status read it abandoned would otherwise leave its directory behind: os.Exit runs no deferred cleanup.
func CommonDirectory ¶ added in v0.8.0
CommonDirectory resolves root's Git common directory from the `.git` marker and `commondir` pointer the way Status does, and spawns no Git process. It refuses a `.git` marker that is a symlink and reads each pointer file with a bounded no-follow open, but it follows symlinks when it resolves the gitdir and commondir paths those pointers name. A plain clone's common directory is its `.git`.
func EnableOwnedWorker ¶
func EnableOwnedWorker() error
EnableOwnedWorker is startup-only: call before Git resolution, Core work, or goroutines. It permanently selects inheritance of the enclosing native worker group. It is not an environment/configuration option or hostile-code sandbox.
func Executable ¶
func Executable() string
Executable returns the path to spawn for Git. It is the executable `git` names on PATH, except that Apple's xcrun shim is resolved to the Git it would execute, so each spawn runs the same binary without paying the shim again. The result is memoised per PATH and DEVELOPER_DIR value; when `git` cannot be resolved the literal name is returned so the spawn fails as it did before. After Pin, it returns the pinned path.
func OwnedWorker ¶
func OwnedWorker() bool
OwnedWorker reports the immutable startup choice for Core launchers.
func Pin ¶ added in v0.8.0
Pin resolves Git once and fixes that absolute path for the rest of the process, so a later PATH or DEVELOPER_DIR change, or a git planted earlier on PATH after start, cannot change which binary a kernel spawns. It refuses when Git does not resolve to an absolute path.
func RefusalClass ¶
RefusalClass is the closed class of a failed isolated status (decision 0383). It is read only from the typed refusal or by identity with errDrift, never from message text; any other error is "unclassified".
func RefusalMessage ¶ added in v0.8.1
RefusalMessage is the caller-facing text for a failed isolated status: the fixed refusal sentence plus the specific reason when one is known.
func RefusalReason ¶ added in v0.8.1
RefusalReason is the specific reason behind a failed isolated status, when one is known. It is fixed text plus at most a closed config key, a Git metadata name, or a filter driver name bounded by plainToken.
func ScratchOutside ¶
ScratchOutside refuses an existing, symlink-resolved candidate directory that is, or lies under, any of roots. EvalSymlinks can preserve case and Unicode aliases, so directory identity is compared throughout the bounded ancestry before any private metadata is created.
func Status ¶
func Status(ctx context.Context, root string, limit int, run Runner, arguments ...string) ([]byte, error)
Status runs only against private metadata. All failures are closed: callers must not retry status against the live Git directory.
func StatusIn ¶
func StatusIn(ctx context.Context, root, temporaryParent string, limit int, run Runner, arguments ...string) ([]byte, error)
StatusIn preserves a caller's existing scratch ownership instead of consulting ambient TMPDIR. The parent must remain outside the observed repository.
func WithIsolation ¶
WithIsolation also confines Git's repository discovery at external consumption boundaries. Status always uses private metadata, including standalone calls.
func WithProbeReuse ¶
WithProbeReuse lets a status read answer a metadata probe from an earlier successful probe in this process over the same captured bytes (proposed GPK-V0-065; opt-in, never the default). Each probe is a pure function of the private copy: `config --list` of one config file, and `ls-files --stage` plus `rev-parse --shared-index-path` of one index under one config pair, all against the same root and Git directory. Only a success is remembered, so a failure of any kind is asked again, and the status run itself is never reused. The reuse assumes one Git executable for the whole process.
Types ¶
type MetadataProbeError ¶
type MetadataProbeError struct {
// contains filtered or unexported fields
}
MetadataProbeError identifies failure while Git validates a private metadata copy. Final status execution errors remain unwrapped for caller compatibility.
func (*MetadataProbeError) Error ¶
func (err *MetadataProbeError) Error() string
func (*MetadataProbeError) Unwrap ¶
func (err *MetadataProbeError) Unwrap() error