Repository navigation
feat(init): write a self-scoped .gitignore inside the index root - #270
Conversation
Init now drops a .gitignore containing only '*' in the index root (.codegraph by default, or the CODEGRAPH_DIR override). A nested .gitignore scopes only to the directory it sits in, so the project's own root .gitignore is never created or modified and the index disappears from git status on its own. The path is derived through a new IndexPaths::gitignore() accessor so the CODEGRAPH_DIR override keeps working and no production code reconstructs .codegraph* strings. The write is idempotent (an existing file is left byte-for-byte untouched) and runs on both exit paths of init, including the already-initialized early return, so pre-existing indexes are backfilled. A write failure logs a warning without failing the command: git never reads the index root as source, so it must not undo an index that index_project already completed.
|
@codex review |
sunerpy
left a comment
There was a problem hiding this comment.
The nested ignore file is a useful direction, but two filesystem-safety issues block merging.
-
crates/codegraph-cli/src/main.rs:1406-1412checksgitignore.exists()and then callsstd::fs::write(). A dangling.codegraph/.gitignoresymlink makesexists()return false, andwrite()follows the link: I reproducedcodegraph initcreating the link target outside the project, with*\nas its content. That breaks the project-containment invariant (AGENTS.md, invariant 5), and the separate check and write also leave a TOCTOU race. Please use a contained, atomic no-clobber creation path that refuses symlinks/reparse points and cannot follow a replaced parent.ensure_tombstoneincrates/codegraph-store/src/uninit.rs:251already does this for the file itself:symlink_metadatafirst, thencreate_new, under the exclusive index lease. Add a regression test proving that a dangling link stays untouched and its external target is never created. -
Writing
*hides every untracked file in an existing custom index root. WithCODEGRAPH_DIR=cacheand an existingcache/user-note.txt,initkeeps the file, but it drops out ofgit status. Please either ignore only CodeGraph-owned artifacts, or write a whole-directory*only wheninitcan prove it just created the root as a new, dedicated directory. Add a Git integration test showing that an unrelated file in an existing custom root stays visible ingit status --porcelain.
Once those are fixed, please rebase onto current main and update the docs that still tell users to add .codegraph/ to .gitignore by hand: the English and Chinese quick-start and FAQ pages (docs/site/en/guide/quick-start.md, docs/site/guide/quick-start.md, docs/site/en/reference/faq.md, docs/site/reference/faq.md). The "Data and network" pages (docs/site/en/privacy.md, docs/site/privacy.md) list what CodeGraph writes under the index root, so they need the new file too. Then run make check; CI Success is the required check. The install_init and index_paths tests pass with this patch applied on top of current main, but neither covers the two cases above.
- create the nested ignore only for a freshly created leased root\n- refuse raced aliases and leave every existing root untouched\n- cover Git visibility, custom roots, and bilingual user documentation
|
I updated this branch on top of current What changed:
Added coverage proves:
Verification on exact head
Issue #269 is unchanged and remains open; this PR does not close it. |
Codecov Report❌ Patch coverage is
❌ Your patch check has failed because the patch coverage (88.17%) is below the target coverage (95.00%). You can increase the patch coverage or adjust the target coverage. @@ Coverage Diff @@
## main #270 +/- ##
==========================================
- Coverage 95.07% 95.06% -0.02%
==========================================
Files 198 198
Lines 109033 109293 +260
==========================================
+ Hits 103659 103894 +235
- Misses 5374 5399 +25
... and 1 file with indirect coverage changes 🚀 New features to boost your workflow:
|
sunerpy
left a comment
There was a problem hiding this comment.
The two previously blocking issues are resolved on exact head e944b6dffd285de1c70b0f44e7e710f4d4e327e8: nested .gitignore creation is confined to the genuinely new-root lease path with no-follow/no-clobber handling, and existing/custom roots are never backfilled. The requested regression coverage and documentation updates are present. Both CI run 37746280160 (including CI Success) and Docs site run 37746280204 passed. Approved; issue #269 remains open and independent.
- create the initial namespace, lock, and nested ignore through retained directory handles - refuse project, index-root, and leaf alias replacement races without external writes - pin capability filesystem dependencies and document the no-follow boundary
sunerpy
left a comment
There was a problem hiding this comment.
Final approval on exact head f2fba45c445c12a5751544cfe340f8ad8a702705. The review-found parent-path replacement race is closed by capability-relative, no-follow creation from the retained project/root handles; project-root, index-root, lock-entry, and .gitignore-entry races have regression coverage. Local make check and pre-push make pre-ci passed. CI run 37758165611 (including Windows Clippy, Windows Tests, and CI Success) and Docs site run 37758165696 passed.
Summary
.gitignorecontaining*so the local index stays out ofgit statuswithout changing the repository's root.gitignore..codegraphroot and a safeCODEGRAPH_DIRoverride throughIndexPaths::gitignore()..gitignorebyte-for-byte.Filesystem safety
.gitignorerelative to retained directory handles, with atomiccreate_newand no symlink/reparse following..gitignorecreation as best effort: a warning never invalidates an otherwise completed index.Regression coverage includes replacement races at the project root, index root, permanent lock, and
.gitignoreentry, plus Git visibility and custom-root behavior.Verification
cargo test -p codegraph-rs --test install_init --locked— 16 passedcargo test -p codegraph-store --locked— passedmake check— passedmake pre-ci— passed, including UI 569 tests, viewer bundle byte-check, and release archive smokeIssue #269 remains open and independent.