Repository navigation
Add shared committed-tree base generation management - #169
Merged
Merged
Conversation
Build committed-tree bases with explicit raw-blob profiles, incremental posting reuse, cross-process publication locking, and conservative retention. Co-authored-by: Copilot App <[email protected]>
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Effective storage validation can allow generations inside disposable worktrees, and unnecessary index scans and global cache locking need correction.
Review effort: Balanced
Findings: 1
Open (3)
What changed in this PR
Adds committed-tree generation management on top of the shared-base APIs, without changing CLI or daemon behavior.
Changes:
- Identifies repositories and keys immutable generations by tree and indexing profile.
- Builds from raw Git blobs with predecessor reuse and locked, validated publication.
- Adds integration coverage and documents retention and reconciliation boundaries.
| File | Description |
|---|---|
tgrep-core/tests/generations.rs |
Tests generation identity, reuse, publication, and failures. |
tgrep-core/src/shared.rs |
Exposes reader and fingerprint accessors. |
tgrep-core/src/meta.rs |
Enables content-identity serialization. |
tgrep-core/src/lib.rs |
Exports the generations module. |
tgrep-core/src/generations/mod.rs |
Implements generation management and retention. |
tgrep-core/src/generations/git.rs |
Adds Git discovery and raw-blob access. |
tgrep-core/src/builder.rs |
Shares snapshot metadata writing internally. |
SHARED_WORKTREE_INDEXES.md |
Documents implemented APIs and remaining layers. |
README.md |
Adds usage and compatibility guidance. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
APFS rejects non-UTF-8 filenames before repository discovery. Verify explicit I/O failure there while keeping lossless native-path coverage on filesystems that support those names. Co-authored-by: Copilot App <[email protected]>
Validate effective repository storage, load generations outside the global cache lock, and skip predecessor decoding when no indexed files can reuse postings. Add focused storage and concurrency regressions and an observable predecessor-read count. Co-authored-by: Copilot App <[email protected]>
Shengyu Fu (shengyfu)
added this pull request to stack #172
October 4, 2026 02:35
Collect per-file posting presence during strict snapshot validation, then preserve short-file membership and content identities without adding those files to posting reuse. Reopened generations need no metadata changes. Cover empty, short, BOM, UTF-16, and repaired invalid-byte content. Co-authored-by: Copilot App <[email protected]>
Contributor
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
Cross-platform locking and immutable publication warrant human review, particularly while complete macOS/Windows CI validation remains unavailable.
Review effort: Balanced
Findings: None
Resolved since last review (1)
baopingz
approved these changes
Oct 5, 2026
baopingz
approved these changes
Oct 5, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Scope
Implements layer 1 of the remaining shared worktree index design, on top of merged #168. This is a usable core generation manager, not worktree synchronization or shared-mode CLI/daemon integration.
HEADresolution.Arc<Generation>/Arc<SharedBase>.Compatibility and boundaries
Normal single-root CLI, RPC, on-disk index format, and existing
SharedBasecheckpoint validation/publication are unchanged. The new profile is a tracked regular-file superset, including hidden/ignored/extension-filtered paths. Binary/oversized/symlink/gitlink membership remains distinct from indexed empty/short files.Raw Git blobs are not a proof of checkout equivalence: CRLF, working-tree encoding, LFS/smudge transformations, freshness and visibility still require layer-2 reconciliation or scanning. The manager reports unsupported/error states rather than silently substituting empty overlays. Storage must be trusted and immutable while in use; file synchronization plus atomic rename is not parent-directory power-loss durability.
Validation
cargo test -p tgrep-core --quiet— 325 tests passed, including 19 generation integration tests and the staged-publication rejection unit test.cargo clippy --workspace --all-targets -- -D warnings— passed.cargo fmt --all -- --check— passed.git diff --checkand staged diff check — passed.Real temporary Git repositories/worktrees cover same-tree reuse, independent clones, differing profiles/trees, dirty/staged/untracked exclusion, incremental-vs-full snapshot equivalence, masks, renames/copies and mode changes, transformed clean worktrees, SHA-256, native/Unicode paths, thread/process races, killed starters, malformed metadata, missing objects, permission errors, and old reader/checkpoint retention. Tests do not modify the main checkout.
Cross-platform CI evidence
Linux's full workspace suite, including all 19 generation tests, passed in run 37168572044, attempt 2. macOS passed 18 generation tests but exposed a fixture assumption: APFS rejects non-UTF-8 directory names with EILSEQ before generation code runs. Test-only commit
c5b70f99b090c48e4d0bbfb4442ec30a7098da00handles only macOS EILSEQ/92 and asserts explicit discovery I/O failure; other fixture errors still fail. No production/API changes were needed. Local generation tests, all-target Clippy, formatting and diff checks were rerun successfully.The latest CI run remains blocked before macOS Rust tests by the existing Python
test_doctor_exercises_installed_mcpfailure (Operation not permitted); matrix fail-fast cancelled Linux/Windows. Mergedmainalso has the same Python EPERM failure class in run 37167713744. No unrelated Python scripts were modified. Full green macOS/Windows CI is not claimed.Layer-2 handoff
Use
generations::{Repository, GenerationManager, IndexingProfile}and retainEnsureResult.generation: Arc<Generation>with each view.key(),entries()/entry(),base(),content_id()/matches_worktree_bytes()expose the exact tree/profile, complete tracked records, shared reader and decoded identity proof. Supply a compatible predecessor to avoid full extraction for a new tree; unchanged trees reuse automatically. PersistGenerationKeywith checkpoints and callopen(key)before reconciliation.RetentionPolicy::RetainAllis intentional until daemon-level ownership and checkpoint eviction exist.Do not merge as part of this task; the next dependent layer will branch from this pushed branch.