Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.
| Catching up with main takes seconds when the two sides touched different files | 1 | //! Bringing a pull request up to date with the branch it would merge into, |
| 2 | //! without a sandbox, when that is safe. | |
| 3 | //! | |
| 4 | //! When the pull request and the default branch changed different files | |
| 5 | //! since they last agreed, the merge cannot conflict, and its result is | |
| 6 | //! known without merging any file: the default branch's tree, with the | |
| 7 | //! files the pull request changed taken from the pull request. Only the | |
| 8 | //! trees on the way to those files change. They are rebuilt here, with one | |
| 9 | //! merge commit on top whose parents are the pull request's head and the | |
| 10 | //! default branch's head, written as a pack of whole objects and pushed to | |
| 11 | //! the pull request's branch, if it is still where it was. | |
| 12 | //! | |
| 13 | //! When both sides changed a file, the merge needs git itself (and maybe an | |
| 14 | //! agent), so the answer is that a sandbox is needed, and nothing is pushed. | |
| 15 | ||
| 16 | use std::collections::{BTreeMap, BTreeSet, HashMap, HashSet}; | |
| 17 | ||
| 18 | use futures_util::future::{try_join, try_join_all}; | |
| 19 | use g1t_contracts::audit::{AuditActor, NewAuditEntry, Surface}; | |
| 20 | use g1t_contracts::credentials::Decision; | |
| 21 | use g1t_contracts::repos::{ | |
| 22 | EntryKind, NeedsAgentReason, PullBranchUpdate, RepoPath, TreeEntry, UpdatePullBranchArgs, | |
| 23 | }; | |
| 24 | use g1t_contracts::{FailureCode, Outcome}; | |
| 25 | use g1t_kit::now_ms; | |
| 26 | use g1t_scan::pack::{ObjectKind, TreeItem, encode_tree, extend_pack, object_id, write_pack}; | |
| 27 | use worker::Result; | |
| 28 | ||
| 29 | use crate::registry::{can_read, can_write, store_key}; | |
| 30 | use crate::store::{GitRepo, GitStore, Scope}; | |
| 31 | use crate::{MAX_ANCESTRY, Repos, UNVERIFIED, descends_from, diff, land, nearest_ancestor_in, not_found}; | |
| 32 | ||
| 33 | /// The mode git writes for an entry of each kind. | |
| 34 | fn mode(kind: EntryKind) -> &'static str { | |
| 35 | match kind { | |
| 36 | EntryKind::Tree => "40000", | |
| 37 | EntryKind::Blob => "100644", | |
| 38 | EntryKind::Exec => "100755", | |
| 39 | EntryKind::Symlink => "120000", | |
| 40 | EntryKind::Gitlink => "160000", | |
| 41 | } | |
| 42 | } | |
| 43 | ||
| 44 | /// Git orders a tree's entries by name, comparing a subtree's name as if | |
| 45 | /// it ended in `/`. | |
| 46 | fn sort_key(entry: &TreeEntry) -> Vec<u8> { | |
| 47 | let mut key = entry.name.as_bytes().to_vec(); | |
| 48 | if entry.kind == EntryKind::Tree { | |
| 49 | key.push(b'/'); | |
| 50 | } | |
| 51 | key | |
| 52 | } | |
| 53 | ||
| 54 | /// A tree object's bytes, its entries in git's order. | |
| 55 | pub(crate) fn encode_entries(entries: &[TreeEntry]) -> Vec<u8> { | |
| 56 | let mut sorted: Vec<&TreeEntry> = entries.iter().collect(); | |
| 57 | sorted.sort_by_key(|entry| sort_key(entry)); | |
| 58 | let items: Vec<TreeItem> = sorted | |
| 59 | .into_iter() | |
| 60 | .map(|entry| TreeItem { | |
| 61 | mode: mode(entry.kind).to_owned(), | |
| 62 | name: entry.name.clone(), | |
| 63 | id: entry.hash.clone(), | |
| 64 | }) | |
| 65 | .collect(); | |
| 66 | encode_tree(&items) | |
| 67 | } | |
| 68 | ||
| 69 | /// The directories above a path, nearest the root first: `a/b/c` is in | |
| 70 | /// `a` and `a/b`. | |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 71 | pub(crate) fn ancestors(path: &str) -> impl Iterator<Item = &str> { |
| Catching up with main takes seconds when the two sides touched different files | 72 | path.match_indices('/').map(move |(at, _)| &path[..at]) |
| 73 | } | |
| 74 | ||
| 75 | /// The paths at which the two sides' changes meet, so that the merge is not | |
| 76 | /// a matter of taking each side's files: a file both changed, or a file on | |
| 77 | /// one side where the other has a directory (a file `a` against `a/b`). | |
| 78 | pub(crate) fn overlapping(ours: &[String], theirs: &[String]) -> Vec<String> { | |
| 79 | let their_files: HashSet<&str> = theirs.iter().map(String::as_str).collect(); | |
| 80 | let their_dirs: HashSet<&str> = theirs.iter().flat_map(|path| ancestors(path)).collect(); | |
| 81 | let mut met: BTreeSet<String> = BTreeSet::new(); | |
| 82 | for path in ours { | |
| 83 | if their_files.contains(path.as_str()) || their_dirs.contains(path.as_str()) { | |
| 84 | met.insert(path.clone()); | |
| 85 | } | |
| 86 | for dir in ancestors(path) { | |
| 87 | if their_files.contains(dir) { | |
| 88 | met.insert(dir.to_owned()); | |
| 89 | } | |
| 90 | } | |
| 91 | } | |
| 92 | met.into_iter().collect() | |
| 93 | } | |
| 94 | ||
| 95 | /// One file the pull request changed, as it is on the pull request: its | |
| 96 | /// kind and blob, or `None` when it deleted it. | |
| 97 | #[derive(Clone, Debug)] | |
| 98 | pub(crate) struct Change { | |
| 99 | pub path: String, | |
| 100 | pub entry: Option<(EntryKind, String)>, | |
| 101 | } | |
| 102 | ||
| 103 | /// The merged tree's id, and the tree objects written for it. | |
| 104 | #[derive(Debug)] | |
| 105 | pub(crate) struct Merged { | |
| 106 | pub tree: String, | |
| 107 | pub objects: Vec<Vec<u8>>, | |
| 108 | } | |
| 109 | ||
| 110 | enum Node { | |
| 111 | Leaf(EntryKind, String), | |
| 112 | /// A subtree left as it is. | |
| 113 | Subtree(String), | |
| 114 | /// A subtree being changed. | |
| 115 | Dir(Dir), | |
| 116 | } | |
| 117 | ||
| 118 | #[derive(Default)] | |
| 119 | struct Dir { | |
| 120 | entries: BTreeMap<String, Node>, | |
| 121 | } | |
| 122 | ||
| 123 | /// A tree, ready to change. Its entries are checked to write back to | |
| 124 | /// exactly its id: a tree holding something this cannot write, such as an | |
| 125 | /// unusual file mode, is refused rather than changed. | |
| 126 | fn load(id: &str, trees: &HashMap<String, Vec<TreeEntry>>) -> std::result::Result<Dir, String> { | |
| 127 | let entries = trees | |
| 128 | .get(id) | |
| 129 | .ok_or_else(|| format!("tree {id} was not read"))?; | |
| 130 | if object_id(ObjectKind::Tree, &encode_entries(entries)) != id { | |
| 131 | return Err(format!("tree {id} holds entries g1t cannot write back exactly")); | |
| 132 | } | |
| 133 | Ok(Dir { | |
| 134 | entries: entries | |
| 135 | .iter() | |
| 136 | .map(|entry| { | |
| 137 | let node = match entry.kind { | |
| 138 | EntryKind::Tree => Node::Subtree(entry.hash.clone()), | |
| 139 | kind => Node::Leaf(kind, entry.hash.clone()), | |
| 140 | }; | |
| 141 | (entry.name.clone(), node) | |
| 142 | }) | |
| 143 | .collect(), | |
| 144 | }) | |
| 145 | } | |
| 146 | ||
| 147 | /// The directory at `node`, read if it was not yet. | |
| 148 | fn open<'a>( | |
| 149 | node: &'a mut Node, | |
| 150 | trees: &HashMap<String, Vec<TreeEntry>>, | |
| 151 | ) -> std::result::Result<&'a mut Dir, String> { | |
| 152 | if let Node::Subtree(id) = node { | |
| 153 | *node = Node::Dir(load(id, trees)?); | |
| 154 | } | |
| 155 | match node { | |
| 156 | Node::Dir(dir) => Ok(dir), | |
| 157 | _ => Err("a file is where a directory was expected".to_owned()), | |
| 158 | } | |
| 159 | } | |
| 160 | ||
| 161 | /// Removes the file at `parts`, and any directory that leaves empty. | |
| 162 | fn remove( | |
| 163 | dir: &mut Dir, | |
| 164 | parts: &[&str], | |
| 165 | trees: &HashMap<String, Vec<TreeEntry>>, | |
| 166 | ) -> std::result::Result<(), String> { | |
| 167 | let (name, rest) = parts.split_first().ok_or("an empty path")?; | |
| 168 | if rest.is_empty() { | |
| 169 | return match dir.entries.get(*name) { | |
| 170 | Some(Node::Leaf(..)) => { | |
| 171 | dir.entries.remove(*name); | |
| 172 | Ok(()) | |
| 173 | } | |
| 174 | Some(_) => Err(format!("{name} is a directory, not a file")), | |
| 175 | None => Err(format!("{name} is not there to remove")), | |
| 176 | }; | |
| 177 | } | |
| 178 | let child = dir | |
| 179 | .entries | |
| 180 | .get_mut(*name) | |
| 181 | .ok_or_else(|| format!("{name} is not there"))?; | |
| 182 | let inner = open(child, trees)?; | |
| 183 | remove(inner, rest, trees)?; | |
| 184 | if inner.entries.is_empty() { | |
| 185 | dir.entries.remove(*name); | |
| 186 | } | |
| 187 | Ok(()) | |
| 188 | } | |
| 189 | ||
| 190 | /// Puts a file at `parts`, making the directories it needs. | |
| 191 | fn insert( | |
| 192 | dir: &mut Dir, | |
| 193 | parts: &[&str], | |
| 194 | kind: EntryKind, | |
| 195 | hash: &str, | |
| 196 | trees: &HashMap<String, Vec<TreeEntry>>, | |
| 197 | ) -> std::result::Result<(), String> { | |
| 198 | let (name, rest) = parts.split_first().ok_or("an empty path")?; | |
| 199 | if rest.is_empty() { | |
| 200 | if matches!(dir.entries.get(*name), Some(Node::Subtree(_) | Node::Dir(_))) { | |
| 201 | return Err(format!("{name} is a directory, not a file")); | |
| 202 | } | |
| 203 | dir.entries.insert((*name).to_owned(), Node::Leaf(kind, hash.to_owned())); | |
| 204 | return Ok(()); | |
| 205 | } | |
| 206 | let child = dir | |
| 207 | .entries | |
| 208 | .entry((*name).to_owned()) | |
| 209 | .or_insert_with(|| Node::Dir(Dir::default())); | |
| 210 | insert(open(child, trees)?, rest, kind, hash, trees) | |
| 211 | } | |
| 212 | ||
| 213 | /// Writes a changed directory and those in it; returns its id. | |
| 214 | fn write(dir: Dir, objects: &mut Vec<Vec<u8>>) -> String { | |
| 215 | let mut entries = Vec::with_capacity(dir.entries.len()); | |
| 216 | for (name, node) in dir.entries { | |
| 217 | let (kind, hash) = match node { | |
| 218 | Node::Leaf(kind, hash) => (kind, hash), | |
| 219 | Node::Subtree(hash) => (EntryKind::Tree, hash), | |
| 220 | // Git keeps no empty directories. | |
| 221 | Node::Dir(inner) if inner.entries.is_empty() => continue, | |
| 222 | Node::Dir(inner) => (EntryKind::Tree, write(inner, objects)), | |
| 223 | }; | |
| 224 | entries.push(TreeEntry { name, hash, kind }); | |
| 225 | } | |
| 226 | let bytes = encode_entries(&entries); | |
| 227 | let id = object_id(ObjectKind::Tree, &bytes); | |
| 228 | objects.push(bytes); | |
| 229 | id | |
| 230 | } | |
| 231 | ||
| 232 | /// The tree of `base_root` with `changes` applied: deletions first, so a | |
| 233 | /// file can take the place of a directory the pull request emptied. | |
| 234 | /// `trees` holds every tree of the base on the way to a changed path. | |
| 235 | pub(crate) fn merge_tree( | |
| 236 | base_root: &str, | |
| 237 | trees: &HashMap<String, Vec<TreeEntry>>, | |
| 238 | changes: &[Change], | |
| 239 | ) -> std::result::Result<Merged, String> { | |
| 240 | let mut root = load(base_root, trees)?; | |
| 241 | for change in changes.iter().filter(|change| change.entry.is_none()) { | |
| 242 | let parts: Vec<&str> = change.path.split('/').collect(); | |
| 243 | remove(&mut root, &parts, trees).map_err(|why| format!("{}: {why}", change.path))?; | |
| 244 | } | |
| 245 | for change in changes { | |
| 246 | if let Some((kind, hash)) = &change.entry { | |
| 247 | let parts: Vec<&str> = change.path.split('/').collect(); | |
| 248 | insert(&mut root, &parts, *kind, hash, trees) | |
| 249 | .map_err(|why| format!("{}: {why}", change.path))?; | |
| 250 | } | |
| 251 | } | |
| 252 | let mut objects = Vec::new(); | |
| 253 | let tree = write(root, &mut objects); | |
| 254 | // A subtree that came out as it was is already stored. | |
| 255 | let mut seen = HashSet::new(); | |
| 256 | objects.retain(|bytes| seen.insert(object_id(ObjectKind::Tree, bytes))); | |
| 257 | Ok(Merged { tree, objects }) | |
| 258 | } | |
| 259 | ||
| 260 | /// Who a commit is by, and when. | |
| 261 | pub(crate) struct Signature<'a> { | |
| 262 | pub name: &'a str, | |
| 263 | pub email: &'a str, | |
| 264 | /// Seconds since the epoch, in UTC. | |
| 265 | pub seconds: u64, | |
| 266 | } | |
| 267 | ||
| 268 | /// A commit object's bytes, authored and committed by `by`. | |
| 269 | pub(crate) fn commit_object(tree: &str, parents: &[&str], by: &Signature, message: &str) -> Vec<u8> { | |
| 270 | let mut out = format!("tree {tree}\n"); | |
| 271 | for parent in parents { | |
| 272 | out.push_str(&format!("parent {parent}\n")); | |
| 273 | } | |
| 274 | // Git takes everything up to `<` as the name. | |
| 275 | let name: String = by.name.chars().filter(|c| !matches!(c, '<' | '>' | '\n')).collect(); | |
| 276 | let email: String = by.email.chars().filter(|c| !matches!(c, '<' | '>' | '\n')).collect(); | |
| 277 | let line = format!("{name} <{email}> {} +0000", by.seconds); | |
| 278 | out.push_str(&format!("author {line}\ncommitter {line}\n\n{message}\n")); | |
| 279 | out.into_bytes() | |
| 280 | } | |
| 281 | ||
| 282 | /// What the merge commit says. | |
| 283 | pub(crate) fn merge_message(base: &str, branch: &str, number: u32) -> String { | |
| 284 | if branch == base { | |
| 285 | // A fork carries its change on a branch named like the default. | |
| 286 | format!("Merge {base} into pull request #{number}") | |
| 287 | } else { | |
| 288 | format!("Merge {base} into {branch}") | |
| 289 | } | |
| 290 | } | |
| 291 | ||
| 292 | /// The trees at `dirs` (and the root, `""`) under `root`, by path: each | |
| 293 | /// one's id and entries. A directory that is not there is left out. Each | |
| 294 | /// level is read at once. | |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 295 | pub(crate) async fn read_dirs<R: GitRepo>( |
| Catching up with main takes seconds when the two sides touched different files | 296 | repo: &R, |
| 297 | root: &str, | |
| 298 | dirs: &BTreeSet<String>, | |
| 299 | ) -> Result<HashMap<String, (String, Vec<TreeEntry>)>> { | |
| 300 | let mut found: HashMap<String, (String, Vec<TreeEntry>)> = HashMap::new(); | |
| 301 | if let Some(entries) = repo.read_tree(root).await? { | |
| 302 | found.insert(String::new(), (root.to_owned(), entries)); | |
| 303 | } | |
| 304 | let depth = |path: &str| path.matches('/').count(); | |
| 305 | let deepest = dirs.iter().map(|dir| depth(dir)).max().unwrap_or(0); | |
| 306 | for level in 0..=deepest { | |
| 307 | let wanted: Vec<(String, String)> = dirs | |
| 308 | .iter() | |
| 309 | .filter(|dir| !dir.is_empty() && depth(dir) == level) | |
| 310 | .filter_map(|dir| { | |
| 311 | let (parent, name) = dir.rsplit_once('/').unwrap_or(("", dir.as_str())); | |
| 312 | let (_, entries) = found.get(parent)?; | |
| 313 | entries | |
| 314 | .iter() | |
| 315 | .find(|entry| entry.name == name && entry.kind == EntryKind::Tree) | |
| 316 | .map(|entry| (dir.clone(), entry.hash.clone())) | |
| 317 | }) | |
| 318 | .collect(); | |
| 319 | let read = try_join_all(wanted.iter().map(|(_, id)| repo.read_tree(id))).await?; | |
| 320 | for ((dir, id), entries) in wanted.into_iter().zip(read) { | |
| 321 | if let Some(entries) = entries { | |
| 322 | found.insert(dir, (id, entries)); | |
| 323 | } | |
| 324 | } | |
| 325 | } | |
| 326 | Ok(found) | |
| 327 | } | |
| 328 | ||
| g1t is one name: its agent's work, commits and comments show as @g1t, and nobody can claim g1t or g1t-agent | 329 | /// g1t's own name and address, for a commit g1t's agent or g1t itself |
| 330 | /// makes. None for anyone else. | |
| 331 | pub(crate) fn g1t_commit_identity(actor: &g1t_contracts::User) -> Option<g1t_contracts::accounts::CommitIdentity> { | |
| 332 | use g1t_contracts::{PrincipalKind, system}; | |
| 333 | matches!(actor.kind, PrincipalKind::Agent | PrincipalKind::System).then(|| g1t_contracts::accounts::CommitIdentity { | |
| 334 | name: system::USERNAME.to_owned(), | |
| 335 | email: system::EMAIL.to_owned(), | |
| 336 | }) | |
| 337 | } | |
| 338 | ||
| Catching up with main takes seconds when the two sides touched different files | 339 | fn needs_agent(reason: NeedsAgentReason, detail: impl Into<String>, paths: Vec<String>) -> Outcome<PullBranchUpdate> { |
| 340 | Outcome::Ok(PullBranchUpdate::NeedsAgent { | |
| 341 | reason, | |
| 342 | detail: detail.into(), | |
| 343 | paths, | |
| 344 | }) | |
| 345 | } | |
| 346 | ||
| 347 | impl<S: GitStore> Repos<S> { | |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 348 | /// The name and address a commit made for `actor` carries: their |
| g1t is one name: its agent's work, commits and comments show as @g1t, and nobody can claim g1t or g1t-agent | 349 | /// noreply address unless they chose to show their own. What g1t's |
| 350 | /// agent or g1t itself commits is g1t's, whoever it works for. Without | |
| 351 | /// identity, the noreply address all the same. | |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 352 | pub(crate) async fn commit_identity(&self, actor: &g1t_contracts::User) -> g1t_contracts::accounts::CommitIdentity { |
| g1t is one name: its agent's work, commits and comments show as @g1t, and nobody can claim g1t or g1t-agent | 353 | if let Some(g1t) = g1t_commit_identity(actor) { |
| 354 | return g1t; | |
| 355 | } | |
| 356 | let person = (actor.id.clone(), actor.username.clone()); | |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 357 | let found = match &self.identity { |
| 358 | Some(identity) => g1t_kit::call::<_, Option<g1t_contracts::accounts::CommitIdentity>>( | |
| 359 | identity, | |
| 360 | "commit_identity", | |
| 361 | &g1t_contracts::accounts::CommitIdentityArgs { user_id: person.0.clone() }, | |
| 362 | ) | |
| 363 | .await | |
| 364 | .ok() | |
| 365 | .flatten(), | |
| 366 | None => None, | |
| 367 | }; | |
| 368 | found.unwrap_or_else(|| g1t_contracts::accounts::CommitIdentity { | |
| 369 | name: person.1.clone(), | |
| 370 | email: g1t_contracts::accounts::noreply_address(&person.0, &person.1), | |
| 371 | }) | |
| 372 | } | |
| 373 | ||
| Catching up with main takes seconds when the two sides touched different files | 374 | pub(crate) async fn update_pull_branch(&self, a: UpdatePullBranchArgs) -> Result<Outcome<PullBranchUpdate>> { |
| 375 | let actor = Some(a.actor.clone()); | |
| 376 | let Some(source) = self.registry.by_id(&a.source_id).await? else { | |
| 377 | return Ok(not_found()); | |
| 378 | }; | |
| 379 | let target = match &source.fork_of { | |
| 380 | Some(id) => self.registry.by_id(id).await?, | |
| 381 | None => Some(source.clone()), | |
| 382 | }; | |
| 383 | let Some(target) = target.filter(|repo| can_read(repo, &actor)) else { | |
| 384 | return Ok(not_found()); | |
| 385 | }; | |
| 386 | // The merge is pushed as the person asking, so they must be able to push. | |
| 387 | if !can_write(&source, &actor) { | |
| 388 | return Ok(Outcome::fail( | |
| 389 | FailureCode::Forbidden, | |
| 390 | if source.fork_of.is_some() { | |
| Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look | 391 | "Only whoever opened this pull request can update it.".to_owned() |
| Catching up with main takes seconds when the two sides touched different files | 392 | } else { |
| Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look | 393 | g1t_contracts::access::needs( |
| 394 | g1t_contracts::access::Capability::Push, | |
| 395 | &format!("{}/{}", source.namespace, source.name), | |
| 396 | ) | |
| Catching up with main takes seconds when the two sides touched different files | 397 | }, |
| 398 | )); | |
| 399 | } | |
| 400 | if !a.actor.verified { | |
| 401 | return Ok(Outcome::fail(FailureCode::Forbidden, UNVERIFIED)); | |
| 402 | } | |
| Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look | 403 | if let Some((code, message)) = crate::lifecycle::archived_refusal(&target) { |
| 404 | return Ok(Outcome::fail(code, message)); | |
| 405 | } | |
| Catching up with main takes seconds when the two sides touched different files | 406 | let from_fork = source.id != target.id; |
| 407 | let base_branch = target.default_branch.clone(); | |
| 408 | let branch = a.branch.clone().unwrap_or_else(|| base_branch.clone()); | |
| 409 | if !from_fork && branch == base_branch { | |
| 410 | return Ok(Outcome::fail( | |
| 411 | FailureCode::Invalid, | |
| 412 | format!("{base_branch} cannot be merged into itself."), | |
| 413 | )); | |
| 414 | } | |
| 415 | ||
| Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily | 416 | // A working copy removed after its pull request closed is made again. |
| 417 | self.live(&source).await?; | |
| Catching up with main takes seconds when the two sides touched different files | 418 | let source_git = self.store.open(&store_key(&source)).await?; |
| 419 | let target_git = self.store.open(&store_key(&target)).await?; | |
| 420 | let (history, target_history) = try_join( | |
| 421 | source_git.log(&branch, MAX_ANCESTRY), | |
| 422 | target_git.log(&base_branch, MAX_ANCESTRY), | |
| 423 | ) | |
| 424 | .await?; | |
| 425 | let (Some(head), Some(base)) = (history.first(), target_history.first()) else { | |
| 426 | return Ok(Outcome::fail( | |
| 427 | FailureCode::Conflict, | |
| 428 | "This pull request has no commits to bring up to date.", | |
| 429 | )); | |
| 430 | }; | |
| 431 | if descends_from(&source_git, &history, &base.hash).await? { | |
| 432 | return Ok(Outcome::Ok(PullBranchUpdate::UpToDate { | |
| 433 | commit: head.hash.clone(), | |
| 434 | })); | |
| 435 | } | |
| 436 | let shared: HashSet<String> = target_history.iter().map(|commit| commit.hash.clone()).collect(); | |
| 437 | let merge_base = nearest_ancestor_in(&source_git, &history, &shared).await?; | |
| 438 | let Some((merge_base, merge_base_tree)) = merge_base.and_then(|hash| { | |
| 439 | target_history | |
| 440 | .iter() | |
| 441 | .find(|commit| commit.hash == hash) | |
| 442 | .map(|commit| (hash, commit.tree_hash.clone())) | |
| 443 | }) else { | |
| 444 | return Ok(needs_agent( | |
| 445 | NeedsAgentReason::Unsupported, | |
| 446 | format!("g1t could not find where this pull request left {base_branch}."), | |
| 447 | Vec::new(), | |
| 448 | )); | |
| 449 | }; | |
| 450 | ||
| 451 | let ((ours, ours_cut), (theirs, theirs_cut)) = try_join( | |
| 452 | diff::changed_paths(&source_git, Some(&merge_base_tree), &head.tree_hash), | |
| 453 | diff::changed_paths(&target_git, Some(&merge_base_tree), &base.tree_hash), | |
| 454 | ) | |
| 455 | .await?; | |
| 456 | if ours_cut || theirs_cut { | |
| 457 | return Ok(needs_agent( | |
| 458 | NeedsAgentReason::Unsupported, | |
| 459 | "The change is too large to merge without a sandbox.", | |
| 460 | Vec::new(), | |
| 461 | )); | |
| 462 | } | |
| 463 | let met = overlapping(&ours, &theirs); | |
| 464 | if !met.is_empty() { | |
| 465 | return Ok(needs_agent( | |
| 466 | NeedsAgentReason::Overlap, | |
| 467 | format!("This pull request and {base_branch} both changed some of the same files."), | |
| 468 | met, | |
| 469 | )); | |
| 470 | } | |
| 471 | ||
| 472 | // The trees on the way to each changed file, on both sides. | |
| 473 | let dirs: BTreeSet<String> = ours | |
| 474 | .iter() | |
| 475 | .flat_map(|path| ancestors(path).map(str::to_owned)) | |
| 476 | .collect(); | |
| 477 | let (on_pull, on_base) = try_join( | |
| 478 | read_dirs(&source_git, &head.tree_hash, &dirs), | |
| 479 | read_dirs(&target_git, &base.tree_hash, &dirs), | |
| 480 | ) | |
| 481 | .await?; | |
| 482 | let changes: Vec<Change> = ours | |
| 483 | .iter() | |
| 484 | .map(|path| { | |
| 485 | let (parent, name) = path.rsplit_once('/').unwrap_or(("", path.as_str())); | |
| 486 | let entry = on_pull.get(parent).and_then(|(_, entries)| { | |
| 487 | entries | |
| 488 | .iter() | |
| 489 | .find(|entry| entry.name == name && entry.kind != EntryKind::Tree) | |
| 490 | .map(|entry| (entry.kind, entry.hash.clone())) | |
| 491 | }); | |
| 492 | Change { | |
| 493 | path: path.clone(), | |
| 494 | entry, | |
| 495 | } | |
| 496 | }) | |
| 497 | .collect(); | |
| 498 | let trees: HashMap<String, Vec<TreeEntry>> = on_base.into_values().collect(); | |
| 499 | let merged = match merge_tree(&base.tree_hash, &trees, &changes) { | |
| 500 | Ok(merged) => merged, | |
| 501 | Err(why) => { | |
| 502 | return Ok(needs_agent( | |
| 503 | NeedsAgentReason::Unsupported, | |
| 504 | format!("g1t could not merge this itself: {why}."), | |
| 505 | Vec::new(), | |
| 506 | )); | |
| 507 | } | |
| 508 | }; | |
| 509 | ||
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 510 | let author = self.commit_identity(&a.actor).await; |
| Catching up with main takes seconds when the two sides touched different files | 511 | let commit = commit_object( |
| 512 | &merged.tree, | |
| 513 | &[&head.hash, &base.hash], | |
| 514 | &Signature { | |
| Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look | 515 | name: &author.name, |
| 516 | email: &author.email, | |
| Catching up with main takes seconds when the two sides touched different files | 517 | seconds: now_ms() / 1000, |
| 518 | }, | |
| 519 | &merge_message(&base_branch, &branch, a.number), | |
| 520 | ); | |
| 521 | let commit_id = object_id(ObjectKind::Commit, &commit); | |
| 522 | let mut objects: Vec<(ObjectKind, Vec<u8>)> = merged | |
| 523 | .objects | |
| 524 | .into_iter() | |
| 525 | .map(|bytes| (ObjectKind::Tree, bytes)) | |
| 526 | .collect(); | |
| 527 | objects.push((ObjectKind::Commit, commit)); | |
| 528 | ||
| 529 | // A fork lacks what the default branch gained since it was made: | |
| 530 | // those objects come from the repository, with the merge after them. | |
| 531 | let pack = if from_fork { | |
| 532 | let target_access = target_git.access(Scope::Read).await?; | |
| 533 | let fetched = land::fetch_pack(&target_access, &base.hash, Some(&merge_base)).await?; | |
| 534 | extend_pack(&fetched, &objects).map_err(worker::Error::RustError)? | |
| 535 | } else { | |
| 536 | write_pack(&objects) | |
| 537 | }; | |
| 538 | let source_access = source_git.access(Scope::Write).await?; | |
| 539 | // Only if the branch is still where it was: a push that landed | |
| 540 | // meanwhile is kept, and this is refused. | |
| 541 | let pushed = land::push_pack(&source_access, &branch, Some(&head.hash), &commit_id, pack).await?; | |
| Mission control shows where you are needed and what agents landed without you; git answers in about 200ms | 542 | self.refs_moved(&source.id).await; |
| Catching up with main takes seconds when the two sides touched different files | 543 | let git_ref = format!("refs/heads/{branch}"); |
| 544 | let path = RepoPath { | |
| 545 | namespace: source.namespace.clone(), | |
| 546 | name: source.name.clone(), | |
| 547 | }; | |
| 548 | let mut target_entry = self.audit_target(&path).await?; | |
| 549 | target_entry.git_ref = Some(git_ref.clone()); | |
| 550 | let mut entry = NewAuditEntry::new( | |
| 551 | AuditActor::of(&a.actor), | |
| 552 | "git.push", | |
| 553 | Surface::Git, | |
| 554 | target_entry, | |
| 555 | &Decision::allow("person"), | |
| 556 | g1t_contracts::new_id("req", now_ms()), | |
| 557 | ); | |
| 558 | if let Err(reason) = pushed { | |
| 559 | entry.result = Some("conflict".to_owned()); | |
| 560 | entry.message = Some(reason); | |
| 561 | self.record_git(entry).await; | |
| 562 | return Ok(Outcome::fail( | |
| 563 | FailureCode::Conflict, | |
| 564 | format!("{branch} moved while it was being brought up to date. Nothing was lost; try again."), | |
| 565 | )); | |
| 566 | } | |
| 567 | entry.result = Some("ok".to_owned()); | |
| 568 | self.record_git(entry).await; | |
| 569 | // As any push does: the pull request's head moves, its checks run | |
| 570 | // again, and whether it merges cleanly is worked out anew. | |
| 571 | self.publish_push(&source, &git_ref, Some(&head.hash), &commit_id, Some(a.actor.id.clone())) | |
| 572 | .await?; | |
| 573 | Ok(Outcome::Ok(PullBranchUpdate::Updated { | |
| 574 | commit: commit_id, | |
| 575 | previous: head.hash.clone(), | |
| 576 | })) | |
| 577 | } | |
| 578 | } | |
| 579 | ||
| 580 | #[cfg(test)] | |
| 581 | mod tests { | |
| 582 | use super::*; | |
| 583 | ||
| 584 | fn entry(name: &str, kind: EntryKind, hash: &str) -> TreeEntry { | |
| 585 | TreeEntry { | |
| 586 | name: name.to_owned(), | |
| 587 | hash: hash.to_owned(), | |
| 588 | kind, | |
| 589 | } | |
| 590 | } | |
| 591 | ||
| 592 | fn paths(list: &[&str]) -> Vec<String> { | |
| 593 | list.iter().map(|path| (*path).to_owned()).collect() | |
| 594 | } | |
| 595 | ||
| 596 | #[test] | |
| g1t is one name: its agent's work, commits and comments show as @g1t, and nobody can claim g1t or g1t-agent | 597 | fn g1ts_commits_are_g1ts_whoever_asked() { |
| 598 | use g1t_contracts::{PrincipalKind, User}; | |
| 599 | let agent = User { id: "usr_g1t_agent".into(), username: "g1t".into(), kind: PrincipalKind::Agent, ..User::default() }; | |
| 600 | let made = g1t_commit_identity(&agent).unwrap(); | |
| 601 | assert_eq!((made.name.as_str(), made.email.as_str()), ("g1t", "g1t@users.noreply.g1t.sh")); | |
| 602 | let made = g1t_commit_identity(&User::system("acme")).unwrap(); | |
| 603 | assert_eq!((made.name.as_str(), made.email.as_str()), ("g1t", "g1t@users.noreply.g1t.sh")); | |
| 604 | let person = User { id: "usr_1".into(), username: "ana".into(), ..User::default() }; | |
| 605 | assert!(g1t_commit_identity(&person).is_none()); | |
| 606 | } | |
| 607 | ||
| 608 | #[test] | |
| Catching up with main takes seconds when the two sides touched different files | 609 | fn different_files_do_not_meet() { |
| 610 | assert!(overlapping(&paths(&["src/a.rs", "README.md"]), &paths(&["src/b.rs", "docs/x.md"])).is_empty()); | |
| 611 | } | |
| 612 | ||
| 613 | #[test] | |
| 614 | fn the_same_file_meets() { | |
| 615 | assert_eq!(overlapping(&paths(&["src/a.rs", "b"]), &paths(&["src/a.rs"])), ["src/a.rs"]); | |
| 616 | } | |
| 617 | ||
| 618 | #[test] | |
| 619 | fn a_file_against_a_directory_meets() { | |
| 620 | // Ours made `a` a file where theirs put files under `a/`. | |
| 621 | assert_eq!(overlapping(&paths(&["a"]), &paths(&["a/b"])), ["a"]); | |
| 622 | // And the other way round. | |
| 623 | assert_eq!(overlapping(&paths(&["a/b/c"]), &paths(&["a/b"])), ["a/b"]); | |
| 624 | // A shared prefix of a name is not a directory. | |
| 625 | assert!(overlapping(&paths(&["ab"]), &paths(&["a/b"])).is_empty()); | |
| 626 | } | |
| 627 | ||
| 628 | #[test] | |
| 629 | fn modes_are_written_as_git_writes_them() { | |
| 630 | assert_eq!(mode(EntryKind::Tree), "40000"); | |
| 631 | assert_eq!(mode(EntryKind::Blob), "100644"); | |
| 632 | assert_eq!(mode(EntryKind::Exec), "100755"); | |
| 633 | assert_eq!(mode(EntryKind::Symlink), "120000"); | |
| 634 | assert_eq!(mode(EntryKind::Gitlink), "160000"); | |
| 635 | } | |
| 636 | ||
| 637 | // Ids below come from git itself (`git mktree --missing`, | |
| 638 | // `git hash-object`, `git commit-tree`) in a scratch repository. | |
| 639 | const EMPTY: &str = "e69de29bb2d1d6434b8b29ae775ad8c2e48c5391"; | |
| 640 | const HELLO: &str = "ce013625030ba8dba906f756967f9e9ca394464a"; | |
| 641 | const SUBMODULE: &str = "1111111111111111111111111111111111111111"; | |
| 642 | ||
| 643 | #[test] | |
| 644 | fn entries_sort_as_git_sorts_them() { | |
| 645 | // `a` as a directory sorts after `a.b` and `a-c` but before `a0`: | |
| 646 | // it compares as `a/`. | |
| 647 | let entries = vec![ | |
| 648 | entry("a0", EntryKind::Exec, HELLO), | |
| 649 | entry("a", EntryKind::Tree, "4b825dc642cb6eb9a060e54bf8d69288fbee4904"), | |
| 650 | entry("a.b", EntryKind::Blob, EMPTY), | |
| 651 | entry("a-c", EntryKind::Symlink, HELLO), | |
| 652 | entry("vendor", EntryKind::Gitlink, SUBMODULE), | |
| 653 | ]; | |
| 654 | let id = object_id(ObjectKind::Tree, &encode_entries(&entries)); | |
| 655 | assert_eq!(id, "59710ac869a643ad7e179b924af6fb3009b84859"); | |
| 656 | } | |
| 657 | ||
| 658 | #[test] | |
| 659 | fn the_empty_tree_is_gits() { | |
| 660 | assert_eq!( | |
| 661 | object_id(ObjectKind::Tree, &encode_entries(&[])), | |
| 662 | "4b825dc642cb6eb9a060e54bf8d69288fbee4904" | |
| 663 | ); | |
| 664 | } | |
| 665 | ||
| 666 | /// A base with `README.md`, `bin/run` (executable), `docs/old.md`, | |
| 667 | /// `src/lib.rs` and a submodule `vendor/dep`. | |
| 668 | fn base() -> (String, HashMap<String, Vec<TreeEntry>>) { | |
| 669 | let mut trees = HashMap::new(); | |
| 670 | let bin = vec![entry("run", EntryKind::Exec, HELLO)]; | |
| 671 | let docs = vec![entry("old.md", EntryKind::Blob, HELLO)]; | |
| 672 | let src = vec![entry("lib.rs", EntryKind::Blob, EMPTY)]; | |
| 673 | let vendor = vec![entry("dep", EntryKind::Gitlink, SUBMODULE)]; | |
| 674 | let mut id = |entries: Vec<TreeEntry>| { | |
| 675 | let id = object_id(ObjectKind::Tree, &encode_entries(&entries)); | |
| 676 | trees.insert(id.clone(), entries); | |
| 677 | id | |
| 678 | }; | |
| 679 | let root = vec![ | |
| 680 | entry("README.md", EntryKind::Blob, HELLO), | |
| 681 | entry("bin", EntryKind::Tree, &id(bin)), | |
| 682 | entry("docs", EntryKind::Tree, &id(docs)), | |
| 683 | entry("src", EntryKind::Tree, &id(src)), | |
| 684 | entry("vendor", EntryKind::Tree, &id(vendor)), | |
| 685 | ]; | |
| 686 | let root = id(root); | |
| 687 | (root, trees) | |
| 688 | } | |
| 689 | ||
| 690 | #[test] | |
| 691 | fn the_base_tree_matches_git() { | |
| 692 | assert_eq!(base().0, "cdbaeedd6c31387975e65e67f9d453589d3c73d1"); | |
| 693 | } | |
| 694 | ||
| 695 | #[test] | |
| 696 | fn changes_are_applied_to_the_base() { | |
| 697 | let (root, trees) = base(); | |
| 698 | let changes = vec![ | |
| 699 | // Added in a new directory. | |
| 700 | Change { path: "src/net/http.rs".into(), entry: Some((EntryKind::Blob, HELLO.into())) }, | |
| 701 | // Made executable: the same blob. | |
| 702 | Change { path: "src/lib.rs".into(), entry: Some((EntryKind::Exec, EMPTY.into())) }, | |
| 703 | // Deleted, leaving its directory empty. | |
| 704 | Change { path: "docs/old.md".into(), entry: None }, | |
| 705 | // A symlink added at the top. | |
| 706 | Change { path: "latest".into(), entry: Some((EntryKind::Symlink, HELLO.into())) }, | |
| 707 | ]; | |
| 708 | let merged = merge_tree(&root, &trees, &changes).unwrap(); | |
| 709 | assert_eq!(merged.tree, "3097aeb8d4a86f097eca63da84e432ebeb456158"); | |
| 710 | // The root, src and src/net; docs is gone, bin and vendor untouched. | |
| 711 | assert_eq!(merged.objects.len(), 3); | |
| 712 | } | |
| 713 | ||
| 714 | #[test] | |
| 715 | fn a_file_can_replace_a_directory_the_pull_request_emptied() { | |
| 716 | let (root, trees) = base(); | |
| 717 | let changes = vec![ | |
| 718 | Change { path: "docs".into(), entry: Some((EntryKind::Blob, HELLO.into())) }, | |
| 719 | Change { path: "docs/old.md".into(), entry: None }, | |
| 720 | ]; | |
| 721 | let merged = merge_tree(&root, &trees, &changes).unwrap(); | |
| 722 | assert_eq!(merged.tree, "088fc1bb6d44a71fcd0c33d4022e7bb1628b7202"); | |
| 723 | } | |
| 724 | ||
| 725 | #[test] | |
| 726 | fn a_tree_that_cannot_be_written_back_is_refused() { | |
| 727 | let (root, mut trees) = base(); | |
| 728 | // Entries that do not hash to the id they are filed under, as a | |
| 729 | // tree with a mode g1t does not know would not. | |
| 730 | let entries = trees.remove(&root).unwrap(); | |
| 731 | trees.insert(root.clone(), entries[1..].to_vec()); | |
| 732 | let changes = vec![Change { path: "x".into(), entry: Some((EntryKind::Blob, HELLO.into())) }]; | |
| 733 | assert!(merge_tree(&root, &trees, &changes).is_err()); | |
| 734 | } | |
| 735 | ||
| 736 | #[test] | |
| 737 | fn a_file_is_not_put_where_a_directory_still_is() { | |
| 738 | let (root, trees) = base(); | |
| 739 | let changes = vec![Change { path: "src".into(), entry: Some((EntryKind::Blob, HELLO.into())) }]; | |
| 740 | assert!(merge_tree(&root, &trees, &changes).is_err()); | |
| 741 | } | |
| 742 | ||
| 743 | #[test] | |
| 744 | fn the_merge_commit_matches_git() { | |
| 745 | let commit = commit_object( | |
| 746 | "cdbaeedd6c31387975e65e67f9d453589d3c73d1", | |
| 747 | &["74257edb70e8dc5d2f31af4b76fe898608f829da", "110bda84f45f58e44d3699be9efe91276381b43d"], | |
| 748 | &Signature { name: "octo", email: "octo@users.g1t.sh", seconds: 1_700_000_000 }, | |
| 749 | &merge_message("main", "feature", 7), | |
| 750 | ); | |
| 751 | assert_eq!(object_id(ObjectKind::Commit, &commit), "f8d35e9d454b11a179215ee1283ac71b7216f024"); | |
| 752 | } | |
| 753 | ||
| 754 | #[test] | |
| 755 | fn a_fork_on_the_default_branch_is_named_by_number() { | |
| 756 | assert_eq!(merge_message("main", "main", 12), "Merge main into pull request #12"); | |
| 757 | assert_eq!(merge_message("main", "fix-login", 12), "Merge main into fix-login"); | |
| 758 | } | |
| 759 | ||
| 760 | #[test] | |
| 761 | fn a_pack_of_the_merge_reads_back() { | |
| 762 | let (root, trees) = base(); | |
| 763 | let changes = vec![Change { path: "src/new.rs".into(), entry: Some((EntryKind::Blob, HELLO.into())) }]; | |
| 764 | let merged = merge_tree(&root, &trees, &changes).unwrap(); | |
| 765 | let mut objects: Vec<(ObjectKind, Vec<u8>)> = | |
| 766 | merged.objects.iter().map(|bytes| (ObjectKind::Tree, bytes.clone())).collect(); | |
| 767 | let pack = write_pack(&objects); | |
| 768 | let read = g1t_scan::pack::Pack::parse(&pack).unwrap(); | |
| 769 | assert!(read.tree(&merged.tree).is_some()); | |
| 770 | ||
| 771 | // Extended with a commit, it still reads, and its checksum holds. | |
| 772 | let commit = commit_object( | |
| 773 | &merged.tree, | |
| 774 | &[&root], | |
| 775 | &Signature { name: "octo", email: "octo@users.g1t.sh", seconds: 1 }, | |
| 776 | "m", | |
| 777 | ); | |
| 778 | let commit_id = object_id(ObjectKind::Commit, &commit); | |
| 779 | objects.clear(); | |
| 780 | objects.push((ObjectKind::Commit, commit)); | |
| 781 | let extended = extend_pack(&pack, &objects).unwrap(); | |
| 782 | let read = g1t_scan::pack::Pack::parse(&extended).unwrap(); | |
| 783 | assert!(read.tree(&merged.tree).is_some()); | |
| 784 | assert_eq!(read.commits(), [commit_id]); | |
| 785 | } | |
| 786 | } |