Skip to content

Add shared committed-tree base generation management - #169

Merged
Shengyu Fu (shengyfu) merged 4 commits into
mainfrom
shengyfu-shared-index-generations
Oct 5, 2026
Merged

Shengyu Fu (shengyfu) merged 4 commits into
mainfrom
shengyfu-shared-index-generations

Conversation

@shengyfu

@shengyfu Shengyu Fu (shengyfu) commented Oct 4, 2026 •

Copy link
Copy Markdown
Member

Scope

Implements layer 1 of the remaining shared worktree index design, on top of merged #168. This is a usable core generation manager, not worktree synchronization or shared-mode CLI/daemon integration.

  • Discover canonical Git common-directory identity (linked worktrees share; independent clones do not), preserving native paths and worktree-specific HEAD resolution.
  • Key generations by repository identity, exact committed tree, explicit indexing profile, and index/schema versions. Keep publishing/requested commit IDs for diagnostics.
  • Build from raw committed blobs using one Git batch process and existing decoding, binary classification, trigram extraction, spill sorting, and snapshot writing. No staged/dirty/untracked checkout content or checkout filters enter the base.
  • Reuse compatible predecessor postings/masks by blob identity, including copies/renames; recompute destination mode/size eligibility. Expose actual read/extraction/reuse counters and tracked membership/content identities.
  • Validate complete staged indexes and checksummed metadata before atomic publication; OS file locking deduplicates cross-process starters, and live pins share the same in-process Arc<Generation>/Arc<SharedBase>.
  • Retain all published generations explicitly. No unsafe GC, active-session migration, or overwrite of mapped/corrupt generations. Persist exact keys beside overlay checkpoints.

Compatibility and boundaries

Normal single-root CLI, RPC, on-disk index format, and existing SharedBase checkpoint validation/publication are unchanged. The new profile is a tracked regular-file superset, including hidden/ignored/extension-filtered paths. Binary/oversized/symlink/gitlink membership remains distinct from indexed empty/short files.

Raw Git blobs are not a proof of checkout equivalence: CRLF, working-tree encoding, LFS/smudge transformations, freshness and visibility still require layer-2 reconciliation or scanning. The manager reports unsupported/error states rather than silently substituting empty overlays. Storage must be trusted and immutable while in use; file synchronization plus atomic rename is not parent-directory power-loss durability.

Validation

  • cargo test -p tgrep-core --quiet — 325 tests passed, including 19 generation integration tests and the staged-publication rejection unit test.
  • cargo clippy --workspace --all-targets -- -D warnings — passed.
  • cargo fmt --all -- --check — passed.
  • git diff --check and staged diff check — passed.

Real temporary Git repositories/worktrees cover same-tree reuse, independent clones, differing profiles/trees, dirty/staged/untracked exclusion, incremental-vs-full snapshot equivalence, masks, renames/copies and mode changes, transformed clean worktrees, SHA-256, native/Unicode paths, thread/process races, killed starters, malformed metadata, missing objects, permission errors, and old reader/checkpoint retention. Tests do not modify the main checkout.

Cross-platform CI evidence

Linux's full workspace suite, including all 19 generation tests, passed in run 37168572044, attempt 2. macOS passed 18 generation tests but exposed a fixture assumption: APFS rejects non-UTF-8 directory names with EILSEQ before generation code runs. Test-only commit c5b70f99b090c48e4d0bbfb4442ec30a7098da00 handles only macOS EILSEQ/92 and asserts explicit discovery I/O failure; other fixture errors still fail. No production/API changes were needed. Local generation tests, all-target Clippy, formatting and diff checks were rerun successfully.

The latest CI run remains blocked before macOS Rust tests by the existing Python test_doctor_exercises_installed_mcp failure (Operation not permitted); matrix fail-fast cancelled Linux/Windows. Merged main also has the same Python EPERM failure class in run 37167713744. No unrelated Python scripts were modified. Full green macOS/Windows CI is not claimed.

Layer-2 handoff

Use generations::{Repository, GenerationManager, IndexingProfile} and retain EnsureResult.generation: Arc<Generation> with each view. key(), entries()/entry(), base(), content_id()/matches_worktree_bytes() expose the exact tree/profile, complete tracked records, shared reader and decoded identity proof. Supply a compatible predecessor to avoid full extraction for a new tree; unchanged trees reuse automatically. Persist GenerationKey with checkpoints and call open(key) before reconciliation. RetentionPolicy::RetainAll is intentional until daemon-level ownership and checkpoint eviction exist.

Do not merge as part of this task; the next dependent layer will branch from this pushed branch.

Build committed-tree bases with explicit raw-blob profiles, incremental posting reuse, cross-process publication locking, and conservative retention.

Co-authored-by: Copilot App <[email protected]>
Copilot AI balanced review requested due to automatic review settings October 4, 2026 01:37

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Effective storage validation can allow generations inside disposable worktrees, and unnecessary index scans and global cache locking need correction.

Review effort: Balanced
Findings: 1 High severity · 2 Medium severity

Open (3)
What changed in this PR

Adds committed-tree generation management on top of the shared-base APIs, without changing CLI or daemon behavior.

Changes:

  • Identifies repositories and keys immutable generations by tree and indexing profile.
  • Builds from raw Git blobs with predecessor reuse and locked, validated publication.
  • Adds integration coverage and documents retention and reconciliation boundaries.
File Description
tgrep-core/​tests/​generations.rs Tests generation identity, reuse, publication, and failures.
tgrep-core/​src/​shared.rs Exposes reader and fingerprint accessors.
tgrep-core/​src/​meta.rs Enables content-identity serialization.
tgrep-core/​src/​lib.rs Exports the generations module.
tgrep-core/​src/​generations/​mod.rs Implements generation management and retention.
tgrep-core/​src/​generations/​git.rs Adds Git discovery and raw-blob access.
tgrep-core/​src/​builder.rs Shares snapshot metadata writing internally.
SHARED_WORKTREE_INDEXES.md Documents implemented APIs and remaining layers.
README.md Adds usage and compatibility guidance.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread tgrep-core/src/generations/mod.rs Outdated
Comment thread tgrep-core/src/generations/mod.rs Outdated
Comment thread tgrep-core/src/generations/mod.rs Outdated
APFS rejects non-UTF-8 filenames before repository discovery. Verify explicit I/O failure there while keeping lossless native-path coverage on filesystems that support those names.

Co-authored-by: Copilot App <[email protected]>
Copilot AI balanced review requested due to automatic review settings October 4, 2026 01:45

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Cross-process locking and cross-platform publication of immutable mapped indexes warrant final human review.

Review effort: Balanced
Findings: 1 High severity · 2 Medium severity

Open (3)

Validate effective repository storage, load generations outside the global cache lock, and skip predecessor decoding when no indexed files can reuse postings. Add focused storage and concurrency regressions and an observable predecessor-read count.

Co-authored-by: Copilot App <[email protected]>
Copilot AI balanced review requested due to automatic review settings October 4, 2026 02:01

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Cross-platform locking and immutable publication need human validation, particularly with incomplete macOS and Windows Rust CI evidence.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
Resolved since last review (3)

Comment thread tgrep-core/src/generations/mod.rs Outdated
Collect per-file posting presence during strict snapshot validation, then preserve short-file membership and content identities without adding those files to posting reuse. Reopened generations need no metadata changes. Cover empty, short, BOM, UTF-16, and repaired invalid-byte content.

Co-authored-by: Copilot App <[email protected]>
Copilot AI balanced review requested due to automatic review settings October 4, 2026 02:38

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Cross-platform locking and immutable publication warrant human review, particularly while complete macOS/Windows CI validation remains unavailable.

Review effort: Balanced
Findings: None

Resolved since last review (1)

@shengyfu
Shengyu Fu (shengyfu) merged commit 2b65f0e into main Oct 5, 2026
12 checks passed
@shengyfu
Shengyu Fu (shengyfu) deleted the shengyfu-shared-index-generations branch October 5, 2026 22:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants