Repository navigation
fix: reject missing default home before store initialization - #118
Conversation
|
Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 29 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configuration
📒 Files selected for processing (6)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Parent verification for PR #118Read the full independent report at fc1ec26. All six changed-file hashes match the manifest and current source. The confirmed RED has 29 passes and 12 failures; GREEN and full runs pass all 41 HOME fixtures. The complete full suite and Docker assembly comparison passed. APPROVE includes the mandatory checklist; no source defect was demonstrated. Corrections:
Required hosted CI 37283162891 remains pending. CodeRabbit is rate-limited and supplies no review approval. The authorized independent agy review supplies the actual review gate. No privileged bootstrap or power-loss proof is claimed by this fix. Full independent report (local evidence labels refer to retained execution receipts): Independent Adversarial Draft Review:
|
| Production Runtime Path | Source Module Path | Behavior & Invariants Verified |
|---|---|---|
bin/git-locks:597-602 |
lib/040-the-store.sh:82-87 |
Default store selection with missing HOME: When sel='' and GIT_LOCKS_HOME is absent or empty, checks [[ -n "${HOME:-}" ]]. If unset or empty, calls store_error emitting structured store-read JSON with exit code 2 before store initialization. Neither variable triggers nounset (set -u). |
bin/git-locks:597-598 |
lib/040-the-store.sh:82-83 |
GIT_LOCKS_HOME override bypass: When GIT_LOCKS_HOME is non-empty, sets home_root="${GIT_LOCKS_HOME}" without evaluating or requiring HOME. |
bin/git-locks:573-584,606-612 |
lib/040-the-store.sh:58-69,91-97 |
Explicit / Configured / Self Store bypass: When GIT_LOCKS_STORE or git config locks.store provides an authority (absolute, relative, or self), the case "${sel}" in '') branch is completely skipped; neither HOME nor GIT_LOCKS_HOME is referenced. |
bin/git-locks:585-594,603-604 |
lib/040-the-store.sh:70-79,88-89 |
Anchor preservation: Resolves main repo anchor key="${common%/.git}" for standard and linked worktrees, and key="$(pwd -P)" outside repos. Relative GIT_LOCKS_HOME remains anchored at ${key}/${home_root}. |
bin/git-locks:617-620 |
lib/040-the-store.sh:102-105 |
Early refusal before mutation: Refusal occurs before create_store (mkdir -p, temporary directory staging, git init) and before command dispatch in lib/990-main.sh:44-46. |
2.2 Merges and Integration Invariants
- Commit Structure:
git rev-list --parents ac42a88..fc1ec26confirmsfc1ec26is a single atomic commit on top of baseac42a887e841183b2e9e20de61494c76ba9c2cdd. No merge commits exist on branchfix/missing-home. - Base Commit Invariants:
- Base
ac42a88merged PR fix: avoid stray-path findings for undecodable records #116 (3ae42bd, doctor stray-path findings for unreadable records). - Preceding merges include PR fix: reject empty acquisition guards before release #114 (
4596826, release acquisition guards) and PR fix: reject NUL streams before reservation parsing #112 (54c7b24, NUL-delimited stream handling). - Verification:
fc1ec26does not touch or reroute logic inlib/080-state.sh,lib/110-release.sh, orlib/180-doctor.sh. Full test phase execution confirmed all existing doctor, release-guard, and NUL stream suites continue to pass green.
- Base
2.3 Verification of Claims and Parity
- Assembly Parity:
lib/040-the-store.shlines 79–90 diff matchesbin/git-lockslines 594–605 diff identically.- Assembled script comparison in
make lint-containerverified byte-for-byte equality betweenbin/git-locksandscripts/build.shoutput.
- Red-on-Parent Evidence Verification:
- Parent
ac42a88was tested withtest/store-home.pyin.test-results/home-selection-red-confirmed-latest.log. - Confirmed RED Result: 29 passed, 12 failed (out of 41 cases).
- Failure Mechanics on Parent:
- Unset
HOMEtripped nounset in Bash:bin/git-locks: line 597: HOME: unbound variable(exit code 1, raw unformatted stderr). - Empty
HOMEevaluated to/.git-stuntsand failed duringcreate_storewithstore-write:mkdir: cannot create directory '/.git-stunts': Read-only file system(exit code 2).
- Unset
- Initial Oracle Correction Documented: Initial run had 4 extra failures (25 passed, 16 failed in
home-selection-red-latest.log) because second-process verification forGIT_LOCKS_STORE=selfexecuted from outside the subject repository; changingsecond_cwd = subject if selector == 'self' else basefixed the oracle without altering production code.
- Parent
- Green Verification:
.test-results/home-selection-green-latest.logrecords:home selection: 41 passed, 0 failed.store selection: 24 cases passed, 0 failed.store bootstrap: 10 cases passed, 0 failed.- Shellcheck and shfmt: passed.
- Full Suite Run Completion:
- Full phase
home-selection-fullwas monitored to completion:.test-results/home-selection-full-result.json:{"exit_code": 0, "host_guard": false}..test-results/home-selection-full-latest.log: lines 318–360 confirmhome selection: 41 passed; 0 failed; all test suites and observation study passed (0 violations across 18 synthetic cases).
- Full phase
2.4 Constants, Budgets, and Evidence Coordinates
All SHA-256 digests in .test-results/home-selection-evidence.json match working tree files at fc1ec26c7cd2a40b367f6e1f0dc6897760b2f9a4:
| File | SHA-256 Digest | Status |
|---|---|---|
CHANGELOG.md |
87b5e04898e5ea0b422ebaa725edbee079d591842e68dc439c120db3b37a47fd |
Exact Match |
Makefile |
3f2c8a9fc78468b600a6b662bfba40006acc6f0851ed5367ff4878ba66e81dd2 |
Exact Match |
bin/git-locks |
084d9ebdb188b667b5f772cc905d44b04451ec516573a38a103bb0f4a350cf36 |
Exact Match |
docs/store-initialization.md |
6fb2b27aca4201be8eff1cf7cbb26870743028fbb789a4308483a4e2fd6b18c8 |
Exact Match |
lib/040-the-store.sh |
02ccc8a33b4d6f0dfcc20cef1fe04868a5df7d4f9c00eba4d16a92a75aa5420c |
Exact Match |
test/store-home.py |
1e9df125fef5c4bace1f6bbebe1165405e1a5c9c35910e4382391043dbb445dd |
Exact Match |
Resource Bounds and Measurements (.test-results/home-selection-full-resources.json):
- Declared Host Budgets: 20 GiB build cache, 4 GiB runtime data, 128 MiB aggregate logs.
- Measured Peak Runtime Data:
/work: 3,170,304 bytes (~3.0 MiB / 512 MiB limit)/tmp: 21,577,728 bytes (~20.6 MiB / 512 MiB limit)/evidence: 3,444,736 bytes (~3.3 MiB / 16 MiB limit)/home/node: 0 bytes/dev/shm: 0 bytes
- Minimum VM Free Storage: 665,532,268,544 bytes (~619.8 GiB, safely above the 50 GiB safety floor).
- Process & Container Output:
- Container log config:
max-file: 1,max-size: 1m. - Live log limit: 16 MiB.
- Aggregate stdout recorded: 89,994 bytes (~87.9 KiB).
- Container log config:
- Timeouts: Process timeout 10s per command invocation in
test/store-home.py:24,33; runner container timeout 1800s.
2.5 Documentation and Numeric Claims
- Numeric Claims Verified:
- 41 test cases in
store-home.py: 3 layouts (outside[11 cases],normal[15 cases],linked[15 cases]). - Refusal cases: 12 cases (unset/empty
HOMEwithdefaultandempty-overrideacross all 3 layouts). - Accepted cases: 29 cases (nonempty
GIT_LOCKS_HOME, explicit absolute/relative paths,config,self, and validHOME). - All numbers in
CHANGELOG.mdanddocs/store-initialization.mdare consistent.
- 41 test cases in
- Prose Formatting Standard:
- New documentation additions in
docs/store-initialization.md:13andCHANGELOG.md:23adhere to the repository house rule: one physical line per paragraph.
- New documentation additions in
2.6 State Machine, Refusal, and Durability Verification
- Schema Conformance: Error response conforms to
#/$defs/error_lineinschema/git-locks.schema.json:973-998(event: "error",reason: "store-read",detail: string). - Zero Mutation Invariant: On refusal, fixture inventory hash map remains identical (
inventory(base) == before). No temporary files, store git directories, or state refs are created. - Wrapper Invocation Interception: In
test/store-home.py:81-90,git locks with ... -- touch markerexits 2 on stderr without executing the wrapped touch command (marker.exists() == False).
3. Mandatory Verification Checklist
- Every code path traced: Traced from CLI entrypoint
lib/990-main.sh:44throughresolve_store()inlib/040-the-store.sh:79-90andbin/git-locks:594-605. Verified parallel path equivalence. - Every merge audited: Branch
fix/missing-homecontains 1 single commit (fc1ec26) overmain(ac42a88). Parent integration invariants checked and preserved. - Every constant and claim checked against evidence: Timeouts (10s), lease TTL (300s), memory limits (2 GiB), tmpfs limits (512 MiB), and log limits (128 MiB) verified against launch/isolation configs and evidence files.
- Every doc and evidence figure checked: 41 home cases, 24 selection cases, 10 bootstrap cases, 29 red passes / 12 red failures confirmed against raw logs.
- All source hashes checked: 6 changed files verified via SHA-256 against
home-selection-evidence.json. - Explicit Coverage Gaps & Distinctions:
- Static read-only code/hash/log inspection was conducted. Host test execution was prohibited and not performed.
- Container tests executed in Docker with a read-only root (
ReadonlyRootfs: true). This read-only root prevented actual creation of/.git-stuntsduring RED; refusal tests verified that no root creation occurs even when the parent directory is writable. - Process-death / power-loss crash injection was not instrumented for store resolution (only observation study root-CAS concurrency calibration is present).
- No performance/timing benchmark was instrumented for store resolution.
- Resource budgets are monitored upper bounds, not tmpfs quotas.
4. Execution State of Checks
- Inspected Only (Static Inspection):
- Working tree Git status, commits, commit parents, and diffs (
fc1ec26vsac42a88). - Source code in
lib/,bin/,schema/,test/, anddocs/. - Cryptographic hashes of all 6 modified files.
- Completed Docker test receipts and logs (
home-selection-red-confirmed-latest.log,home-selection-green-latest.log,home-selection-full-latest.log,resources.json,isolation.json,result.json).
- Working tree Git status, commits, commit parents, and diffs (
- Executed Directly:
- Read-only hash computations (
shasum -a 256). - Read-only process inspection (
ps) to observe completion ofhome-selection-full.
- Read-only hash computations (
- Prohibited / Skipped / Unavailable:
- Host test execution (strictly prohibited).
- Docker container mutation commands (strictly prohibited).
- Kernel-level power-loss or hardware crash testing (unavailable / uninstrumented).
APPROVE
Without an explicit store or a nonempty
GIT_LOCKS_HOME, unsetHOMEcaused a raw Bash error, while emptyHOMEattempted to initialize/.git-stunts.Default selection now refuses both cases with structured
store-readexit 2 before initialization. Explicit stores, configured stores,self, and nonemptyGIT_LOCKS_HOMEoverrides still work withoutHOME. Existing selection precedence and shared worktree anchors remain intact.Closes #117. Related to #68; broader argument-error wording remains there.
Validation: confirmed Docker RED on parent ac42a88 has 29 passes and 12 failures. GREEN passes all 41 HOME cases, 24 store-selection cases, ten initialization cases, lint and generated-script equality. Refusal fixtures remain unchanged and wrapped commands do not run. The full Docker lint/test suite passed at fc1ec26, including 1,099 shell checks, 760 capacity checks and 18 synthetic state-observation cases with zero violations plus negative CAS calibration. Independent agy review approved the exact head; full feedback and parent corrections: #118 (comment). Required hosted CI 37283162891 passed. CodeRabbit is rate-limited; its green status is not review approval.