chore(deps): update rust crate gix to 0.88 - #31
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/gix-0.x
branch
from
March 29, 2026 11:25
5bd6ac0 to
5b4d360
Compare
Benchmark Results
Download full results from the workflow artifacts. |
renovate
Bot
force-pushed
the
renovate/gix-0.x
branch
from
April 24, 2026 14:54
5b4d360 to
507e30f
Compare
renovate
Bot
force-pushed
the
renovate/gix-0.x
branch
from
April 28, 2026 05:14
507e30f to
d61bf25
Compare
renovate
Bot
force-pushed
the
renovate/gix-0.x
branch
from
May 18, 2026 19:15
d61bf25 to
10f21c4
Compare
renovate
Bot
force-pushed
the
renovate/gix-0.x
branch
from
May 26, 2026 04:40
10f21c4 to
50efbf9
Compare
renovate
Bot
force-pushed
the
renovate/gix-0.x
branch
from
June 22, 2026 18:44
50efbf9 to
b334323
Compare
renovate
Bot
force-pushed
the
renovate/gix-0.x
branch
2 times, most recently
from
July 23, 2026 18:27
cb0fc45 to
e3938a2
Compare
renovate
Bot
force-pushed
the
renovate/gix-0.x
branch
from
August 11, 2026 22:57
e3938a2 to
796f139
Compare
renovate
Bot
force-pushed
the
renovate/gix-0.x
branch
from
August 22, 2026 22:28
796f139 to
98dd39b
Compare
renovate
Bot
force-pushed
the
renovate/gix-0.x
branch
from
August 25, 2026 17:05
98dd39b to
1ba3832
Compare
renovate
Bot
force-pushed
the
renovate/gix-0.x
branch
from
September 2, 2026 19:16
1ba3832 to
554ed0b
Compare
renovate
Bot
force-pushed
the
renovate/gix-0.x
branch
from
September 15, 2026 13:11
554ed0b to
f8a878b
Compare
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
renovate
Bot
force-pushed
the
renovate/gix-0.x
branch
from
September 25, 2026 12:13
f8a878b to
ecd34cd
Compare
renovate
Bot
force-pushed
the
renovate/gix-0.x
branch
from
October 1, 2026 05:03
ecd34cd to
9bab0f9
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
0.80→0.88Release Notes
GitoxideLabs/gitoxide (gix)
v0.88.0: gix v0.88.0Compare Source
Bug Fixes (BREAKING)
preserve causes across fallible conversions
Rubber stamp, looked at diff. This is a cleanup commit.
There is going to be considerable cleanup done later as well.
Parsers and adapters discarded encoding, integer, date, signature, and
object-access failures when replacing them with context. Preserve their
concrete causes so classification and downcasting keep working after
conversion to
gix::Erroror an I/O error.Return
Exnfrom fallible path, command-line, gitdir, and pack-entryconversions where necessary, and adapt their consumers in the same change.
Packed-ref and reflog errors retain their parser sources and input details;
reflog recovery reports the actual recovery failure. Loose-object verification
now propagates lookup and enumeration failures instead of treating every
lookup error as retryable or silently skipping failed enumeration.
Remove unnecessary UTF-8 conversions for ASCII suffixes and check span bounds
before narrowing. Parsers that only return
()explicitly destructure it.No production
map_err()closure still discards a wildcard-bound error.Also preserve causes in formatting-only CLI and commit-graph adapters, where
stringification previously lost checksum corruption classifications.
locate
vi/vimin Git's core directory on Windows; changeRepository::editor() -> Option<gix_command::Prepare>On Windows, Git's bundled
vimay not be available through PATH. Resolve thedefault editor in Git's core directory first and retain the bare command as
fallback.
New Features (BREAKING)
return the local branches actually deleted
Callers that needed to know whether branch deletion removed anything had
to look up each reference separately. That duplicated reference reads and
could report stale existence information by the time deletion took its
locks.
Return sorted, deduplicated full names from the committed reference edits
whose previous values were observed under lock. Missing branches are
excluded while their stale local configuration is still removed. Expose
the same list as
deletedindelete::Error::Cleanupso callers can recoverit when only configuration cleanup fails; retain
referencesas the fullrequested batch.
The success value changes from
()toVec<FullName>, andCleanupgainsa
deletedfield. Strengthen the existing tests for loose, packed, danglingsymbolic, duplicate, missing, empty, and linked-worktree branch requests.
Changed (BREAKING)
remove redundant error aliases
rubberstamp
The crate-by-crate migration retained operation-specific error aliases to
limit downstream churn. With the migration complete, those names only hide
the shared error types and keep otherwise empty API namespaces alive.
Use the underlying
gix_errortypes directly throughout the workspace,including indirect aliases, renamed exports, test helpers, and the URL fuzz
target. Remove namespaces and files that only held forwarding aliases, and
update documentation and migration guidance to use the canonical types.
Adjust the source locations recorded in error snapshots after deleting the
alias declarations.
Keep
gix::{Error, Exn}andgix::erroras the central facade, along withunrenamed canonical re-exports, required associated types, concrete errors,
and aliases that add structure. Preserve each
Exnparameter, conditionalerror alternative, error message, and source chain. Include all downstream
adaptations in this breaking change so the stack remains buildable.
consolidate public API failures under gix::Error
rubberstamp
raise MSRV to Rust 1.88
The newly published
dua-core3.3 release used by linked-worktree removalrequires Rust 1.88, so raise every workspace crate and the advertised badge
together.
Keep the MSRV checks buildable by selecting the latest
sysinfoandrusqliterelease lines that support Rust 1.88.
New Features
add
Repository::config_path()Callers with a repository currently have to select local and worktree
configuration paths themselves before falling back to
gix::config_path().Expose that selection on
Repository, using its common directory forSource::Local, its Git directory forSource::Worktree, and its openingoptions with the existing resolver for global sources.
Keep the worktree path available even when
extensions.worktreeConfigisdisabled, so callers can locate and prepare that physical file. Preserve
the existing errors for disabled sources and sources without a file.
Git reference:
builtin/config.candDocumentation/git-config.adocinthe local Git checkout at
1630431f326e15fcde608827b5ff38422528eb59.The executable baseline was Git 2.50.1 (Apple Git-155).
expose standalone configuration paths with
config_path()Callers need to locate a configuration file before starting a
config_mut()transaction so they can inspect it, prepare its parentdirectory, or load it themselves.
Extract the existing path selection into
gix::config_path(source, options)and use it fromconfig_mut(). Preserve source and environmentpermissions, explicit path overrides, and current-directory anchoring.
Path lookup succeeds without existing parent directories or valid
configuration contents, and does not acquire a transaction lock or
evaluate transaction settings.
Git reference:
v2.55.0-782-g1630431f32,config.cfunctionsgit_system_config()andgit_global_config_paths(), plus the global andsystem override tests in
t/t1300-config.sh. The shared resolver retainsthe existing source-specific path and override behavior.
add standalone
config_mut()transactionsCallers can load global configuration with
gix::config(), but editingone physical file previously required a repository. Add a sibling that
accepts
config::Sourceandopen::Optionsand returns the existingconfig::FileTransaction.Share source-path resolution and
core.configLockTimeoutparsing withconfiguration loading and repository transactions. Honor source and
environment permissions, preserve source metadata, and keep physical
edits lossless without persisting includes or runtime overrides.
Global files use normal filesystem permissions; missing files can be
created on commit when their parent directory already exists.
allow presetting system configuration paths
Callers that already know the Git-installation and system configuration files
can now provide both paths through
gix::open::Options. The paths flow throughrepository opening and standalone configuration loading, while the existing
source permissions continue to decide whether each file is read.
Preset paths replace path discovery, but must not bypass Git's explicit
GIT_CONFIG_NOSYSTEMswitch. Read the permitted environment value once beforeselecting Git-installation and system sources, preserving the behavior already
implemented by
gix_config::Source::storage_location().add
worktreeProxy::is_prunable()+ fixExpose
worktree::Proxy::is_prunable()with Git-compatible semantics: lockedworktrees are retained, while unreadable
gitdirfiles and missing checkouttargets are prunable. Treat any filesystem entry at
lockedas a lock,including symlinks.
When opening a proxy as a repository, use the common directory already known
by its parent instead of relying on the linked worktree’s optional
commondirfile. This prevents incomplete administration from being mistaken for a
standalone repository and keeps
HEADaccess routed through the repository refstore for backend compatibility.
Fetch can consequently inspect linked-worktree heads without failing for missing
checkouts, locks, or missing and malformed
commondirfiles.edit physical configuration files atomically with
Repository::config_file_mut()Add
Repository::config_file_mut()as a transaction over one physicalconfiguration file. It acquires a symlink-aware lock before reading, parses
without expanding includes, preserves formatting and existing permissions, and
resolves relative paths against the opening CWD.
Lock acquisition honors the discoverable core.configLockTimeout key
with Git-compatible parsing and a 1000 ms default. New files also honor
core.sharedRepository after the process umask, including named, boolean,
compatibility, and explicit octal modes.
Committing only writes the file atomically. Repository state changes through
an explicit full reload, which retains normal Git-compatible validation and
rebuilds include- and bootstrap-dependent state without a second partial-refresh
path.
add
Repository::committer_or_set_fallback()Applications that configure
gitoxide.committer.*Fallbackunconditionally canoverride a complete
user.*identity because these keys resolve first.Add
Repository::committer_or_set_fallback()so callers can provide alast-resort identity without changing normal configured-user behavior. Keep the
generic helper as a wrapper, and document and test the precedence.
Bug Fixes
propagate failed fetch ancestry checks
Looked at this in detail to understand how error handling improvements
were made. It all makes sense, and teaches me to... not ignore or
skip over errors, ever, it's basically a bug unless there is a test
that proves it's not a bug.
Fetch ref updates discarded commit decoding and traversal setup errors,
treating any such failure as permission to force the update. A malformed
local or remote commit could therefore overwrite a ref without a force
refspec. Traversal errors were also ignored when looking for the ancestor.
Propagate those failures with their original causes and context. Check
object kinds explicitly to retain the existing behavior for non-commit
targets without mistaking corruption for an object-kind mismatch.
Keep rust workspace tests inside disposable repositories and isolated environments
Direct Git launches inherited repository selectors and user configuration even
when tests supplied a fixture working directory. Tests of default-environment
APIs and local Git transports also shared the runner's environment. A few
journey tests wrote beneath source directories or used the source checkout as
the repository under test.
Use the shared
gix-testtoolsGit command builder for subprocess setup, isolatedrepository options for fixtures, and isolated child processes where the real
environment-reading API must be exercised. Scope CWD changes, copy the fixture
used by an object-write test, and run shell journeys through
jtt run. Keepjourney worktrees and example output within their disposable sandboxes and
replace the attributes checkout test with a representative fixture repository.
Prompt examples also run in isolated children and must build successfully; the
old tests could ignore build failures and execute stale cached binaries.
The affected Rust crate suites, internal test-tool build, and
max-purejourneysuite pass from a source copy without Git metadata. Signing and Git-daemon
checks use only disposable keys, repositories, and local sockets.
find bundled signature programs on Windows
Git for Windows makes its bundled
gpg,gpgsm, andssh-keygenavailableby prepending installation directories to
PATH. Gitoxide can run outside thatprepared environment, so bare defaults may not resolve.
Use
gix_path::env::installation_program()for unconfigured defaults on Windowsand retain the bare name as fallback. Explicit configuration and non-Windows
behavior stay unchanged.
interpolate signature verifier program paths
Git treats
gpg.*.programvalues as pathnames and expands a leading tildebefore launching the verifier. Signing already did this, but verification kept
the raw configured string, which fails with direct program invocation.
Resolve OpenPGP, X.509, and SSH verifier programs through the existing
trusted-path handling while preserving defaults and the legacy
gpg.programfallback.
normalize safe-directory paths before trust checks
Windows canonicalization can produce verbatim paths with a
\\?\prefix whileincluded configuration metadata uses an ordinary drive path. Comparing those
representations directly prevents an explicitly safe config file from being
promoted to full trust, including after repository reloads.
Canonicalize both the path under test and configured safe-directory paths
through the filesystem before exact or wildcard comparison. Retain the existing
lexical realpath fallback for missing paths.
make identity fallbacks true last-resort values
gitoxide.{author,committer}.*Fallbackshared its configuration slot with thecorresponding environment overrides. This placed application fallbacks before
user.*, while also placingGIT_{AUTHOR,COMMITTER}_*after role-specificconfiguration.
Store environment overrides under
author.*andcommitter.*, then resolveexplicit fallback keys only after
user.*. This matches Git precedence and letsapplications configure fallbacks without replacing a valid user identity.
Commit Statistics
Commit Details
view details
worktreeProxy::is_prunable()+ fix (0af2f91)6356013)dcf08a4)0b2a5c4)9d0329a)gixAPI boundaries (ba2c7f2)daf73b5)2176245)b1e31eb)a5e8c4d)gixCargo example (2bab44c)4b9ff51)2fb9b8a)c609062)4e0f8ff)4f29e0c)92b6508)2742f05)dfc8e8c)283937b)Repository::config_path()(76502a0)be7bb02)config_path()(707818c)d7551f1)3b60097)config_mut()transactions (18ac842)6b2f33d)4a870be)36b6310)653c002)87727ee)c16300c)3c45a7d)b7bedcf)ec63505)a095334)4b42e0c)b14028d)c48fe1e)Repository::config_file_mut()(913f631)7e35849)888677a)ab66595)d23127a)Repository::committer_or_set_fallback()(c355827)e3a6fa1)a1d5a55)vi/vimin Git's core directory on Windows; changeRepository::editor() -> Option<gix_command::Prepare>(b76cc28)dda600d)v0.87.1: gix v0.87.1Compare Source
New Features
add exact note-reference writes via
note::Platform::replace_at_ref()Add
Platform::replace_at_ref()for callers that already have a fully qualified notesreference and must avoid refs/notes shorthand expansion.
improve remote-name comparison and resolution
Remote-tracking ref names are not reliable ownership indicators because fetch
refspecs may use custom destinations. Reverse-map tracking refs against every
configured remote and require exactly one mapping, reporting both cross-remote
and within-remote ambiguity like Git.
Keep path-based inference limited to Reference::remote_name(): select the
longest configured prefix for names containing multiple slashes while avoiding a
remote-config query for ordinary one-slash names.
Allow remote::Name and the borrowed values returned by Remote::name() to compare
directly and symmetrically with str, String, BStr, and BString using exact byte
equality.
compare attached
Ids andReferences with textDelegate attached
Idtextual equality toObjectId, preserving symmetriccanonical comparisons. Let attached references compare directly with
text, byte strings, and full names by delegating to their stored plumbing
reference.
Reference comparisons remain directional because same-name
references may have different targets.
Commit Statistics
Commit Details
view details
fbebed7)note::Platform::add_to_ref()to::replace_at_ref()(2c8ddd4)note::Platform::replace_at_ref()(716b89b)6704303)e52fe9d)900a0f6)47536a5)Ids andReferences with text (23bd32d)b8914ff)v0.87.0: gix v0.87.0Compare Source
Bug Fixes (BREAKING)
need-more-recent-msrvas it's not required anymoreIt was mostly meant to be internal, but the name didn't indicate
this, hence the breaking change.
Test
assert fetched pack contents rather than pack checksums
fetch_packandfetch_pack_without_local_destinationasserted thedata_hash/index_hashof a pack produced by the hostgit. Those coverthe pack's compressed bytes, so they silently encode which zlib
implementation that
gitis linked against: with a zlib-ng-linked git(Arch, among others) the 219-byte commit in that pack deflates to 152 bytes
where stock zlib produces 153, making the pack 268 bytes instead of 269 and
changing both checksums.
Nothing about the fetch itself differs — re-deflating the very same object
payloads with stock zlib and re-hashing reproduces the expected checksum
byte for byte, and every other assertion in both tests already passes.
Assert the pack's object ids instead, read back from the index that was just
written. They hash uncompressed content, so they are identical on every host,
and they are what the checksums were standing in for.
num_objects,pack_versionandindex_versionare untouched;Entry::crc32isdeliberately not used, as it too is computed over compressed bytes.
New Features (BREAKING)
add Git-compatible commit signature verification with
Commit::verify()Breaking because it also adds
config::tree::Key::default_value(), which givesAnya
default_valuefield.Expose repository-aware verification on commits while delegating verifier
execution and result parsing to gix-object plumbing. Resolve supported
signature formats, configured programs, trust thresholds, SSH allowed
signers and revocations, repository-relative paths, and commit verification
time according to Git configuration.
add
commit::Info::generationThat way it's evident if a commit-graph was present for this node.
Breaking, as it adds a new public field to a structure.
Changed (BREAKING)
remove the
tree-editorfeature toggleThe workspace MSRV now exceeds Rust 1.75, which stabilized the language feature
that originally required tree editing to be gated.
Make tree-editing APIs available unconditionally.
New Features
expose git notes in
gix::RepositoryAdd the notes feature and
Repository::notesas the porcelain layer overgix-notefor repeated queries and mutations.
Select the default notes ref from
core.notesRef, including theGIT_NOTES_REFenvironment override represented in
config::tree, and fall back torefs/notes/commits. Discover additional display refs fromnotes.displayReforGIT_NOTES_DISPLAY_REF, expand glob patterns, preserve display order, and avoidduplicates.
For mutations, accept conventional short notes-ref names, write note blobs and
notes commits, and update refs with compare-and-swap expectations so concurrent
changes are not silently overwritten.
add
Repository::delete_local_branches().asdf
Validate the entire batch before changing references, reject branches checked
out in any worktree, and delete references and reflogs in one transaction
without requiring commit traversal.
Remove matching local branch configuration under lock and report when
configuration cleanup fails after reference deletion. Share checked-out branch
discovery with fetch updates and use restricted repository opening throughout
the affected tests.
add Git-compatible commit signing via
Commit::sign()Expose repository-aware commit signing while delegating signature creation
to gix-object plumbing. Resolve gpg.format, per-format programs, signing
keys, committer identity fallback, and gpg.ssh.defaultKeyCommand from Git
configuration, including trusted paths and shell commands.
Add commit_signing_options_if_enabled() so porcelain callers honor
commit.gpgSign without resolving signer configuration while signing is
disabled. Preserve caller control over resolved program arguments and
environment, including non-interactive GPG operation.
add commit signature verification to gix-object via
commit::SignedData::verify()Add feature-gated plumbing for verifying OpenPGP, X.509, and SSH commit
signatures with fully resolved programs, arguments, environments, trust
thresholds, and SSH policy inputs. Keep repository configuration out of
the object crate while exposing Git-compatible status, identity, key, and
fingerprint results.
Stream signed commit data directly to OpenPGP and SSH verifiers without
reconstructing it. Use a temporary payload only where gpgsm requires a
file, and cover Git status parsing plus unsupported and mismatched formats.
expose Git quoting utilities in gix
expose Git-compatible editor selection
Add `Repository::editor()`` to resolve the interactive editor with Git's
precedence rules. Honor GIT_EDITOR ahead of trusted core.editor, consider VISUAL
only for capable terminals, fall back through EDITOR to vi, and report no editor
for an unconfigured dumb terminal.
Route GIT_EDITOR through the configuration environment-override framework
so isolated repositories and environment permissions remain effective. Cover
precedence, dumb terminals, the no-op editor, and isolation.
recognize SHA-256 commit signature headers
Teach commit parsing and signature extraction about the gpgsig-sha256
header used by Git when signing SHA-256 commits. Treat it like gpgsig
when locating the embedded signature while preserving the actual header
name when reconstructing the signed payload.
Cover both full commit parsing and token iteration so callers observe
the signature consistently through either API.
add support for
GIT_ALLOW_PROTOCOLhonor
GIT_INDEX_FILEwhen opening repositories viadiscover_with_environment_overrides()Map
GIT_INDEX_FILEto the newgitoxide.core.indexFileconfiguration keyand use it for index reads and writes, allowing to implement hooks for the first time.
As a fix, Repository-local environment overrides are no longer inherited when opening
submodules, linked worktrees, or their main repository. This prevents an
alternate index, worktree, or Git directory from leaking into another
repository.
The selected index path remains stable until the repository is reloaded, and
empty index-file overrides are rejected.
support cloning a single revision
A full object ID passed through with_ref_name() produced an object-ID refspec
mapping and panicked while clone assumed every mapping had a name. Branch and
tag checkout also retained ordinary clone tracking semantics instead of offering
a single-revision mode.
Add PrepareFetch::with_revision() and gix clone --revision for full refs, HEAD,
and full object IDs. Revision clones use a one source-only implicit refspec,
detach HEAD to the fetched commit, create no ordinary refs, persist no fetch
refspec, and disable tag following. Existing with_ref_name() and --ref behavior
stays unchanged.
This follows Git commit
3378556(builtin/clone: teach git-clone(1) the--revision= option) and its t/t5621-clone-revision.sh behavior.
add
config()functionFactor the non-repository portion of configuration initialization out of
repository opening and expose it as gix::config(). The new API accepts a future
git directory and the same open::Options used by open and clone, preserving
source permissions, conditional includes, environment handling, and override
precedence.
Chore
Normalize the precomputed diff fixture assets to LF before writing blobs,
populating the index, and creating commits. Git for Windows may check these
assets out with CRLF, which changes their object IDs and adds carriage returns
to index paths, causing fixture setup to fail at
git mv cli c.Prevent Git Bash from rewriting revision arguments before Git sees them, and
normalize the two pathspec baseline cases where Git for Windows applies native
path validation to repository-format paths. Exclude a glob baseline whose
backslash behavior is specific to Git for Windows rather than Git paths.
Generate pathological .gitmodules entries as configuration data instead
of trying to create module directories whose names cannot be represented
on Windows. Use Git Bash bundled Perl for binary fixture construction so
regeneration does not depend on a separately installed Python interpreter.
Also pass a literal carriage return to sed through Bash ANSI-C quoting when
normalizing the jj diff assets. Unlike GNU sed, BSD sed does not interpret
backslash-r in a single-quoted expression, so the previous spelling could remove
a trailing letter r on macOS instead of stripping CRLF endings.
Bug Fixes
don't limit
is_dirty()to the current working directoryresolve the empty pattern in
<rev>^{/}like Git, instead of skipping it.The parser dropped the
find()delegate call whenever the pattern in<rev>^{/<pattern>}was empty, turning the whole navigation step into ano-op on the grounds that an empty pattern matches everything.
That reasoning only holds for a commit anchor and a non-negated pattern.
Git routes
<rev>^{/...}throughGET_OID_COMMITTISHand searches fromthe peeled commit even when the pattern is empty - object-name.c notes
"$commit^{/}. Some regex implementation may reject empty regex, but this
is safe". Thus
git rev-parse 'b-tag^{/}'yields the commit theannotated tag points at, while
gixreturned the tag object itself. Anegated empty pattern matches no commit at all, so Git fails
HEAD^{/!-}while
gixsilently succeeded with HEAD.Now the parser always forwards the pattern to
Navigate::find(), whoseimplementation in
gixalready handles the empty case correctly on boththe
revparse-regexand the substring fallback paths: it peels theanchor to a commit first and treats an empty pattern as match-all, which
fails naturally when negated. The delegate behind
gix revision explainmakes no assumption about patterns and needs no change.
The
make_rev_spec_parse_reposfixture gains baselines for@^{/},@^{/!-}andb-tag^{/}; its archive needs regeneration.correctly handdle GIT_PROTOCOL_FROM_USER when evaluating protocol permissions
Align helper protocol permissions with Git by applying policy by transport
name, using the known-safe, ext, and user defaults, and parsing
GIT_PROTOCOL_FROM_USERas a Git boolean.peel annotated tags before navigating a rev-spec, like in Git.
<tag>^,<tag>^<n>,<tag>~<n>and<tag>^{/<text>}navigated from the tagobject itself rather than from the commit it points at. In a repository whose
annotated
b-tagnames the merge commitb, Git resolvesb-tag^tod,while
gixreported "Object212d0f0was a tag, but needed it to be a commit",and
b-tag^{/G}failed with a kind mismatch instead of resolving tog.Git routes these forms through
GET_OID_COMMITTISH, which dereferences tagsfirst. The three navigation sites now peel to a commit the way
^{commit}already did, keeping the original object id as the replacement key. Peeling is
the identity on a commit, so commit anchors resolve and fail exactly as before.
A blob or tree anchor now reports that it could not be peeled to a commit.
<tag>~0still yields the tag. The parser ingix-revisionskips the delegatecall entirely for a zero-length ancestor walk, which is correct for a commit
anchor and is pinned by a test there; changing it touches the public
Navigatecontract and belongs in its own change.
reject
./..revspec paths that leave the worktree, like in Git.At the worktree root,
HEAD:./../thisresolved to the blob atthiswhileHEAD:../thiscorrectly failed. Git rejects both:Containment is delegated to
Repository::normalize_path(), which normalizesagainst an empty
current_dirso that a..with nothing left to consumefails. In
gix_path'snormalize_inner()a leading.stays in the buffer,so
..pushes the emptycurrent_dironto it,pop()removes the.andsucceeds — where the same path without the leading
.pops an empty buffer,gets
false, and correctly yieldsNone. Only the worktree root is affected;from
some/very,HEAD:./../../thisalready resolved andHEAD:./../../../thisalready failed.Dropping the current-directory components before normalizing keeps the fix
inside the revspec parser.
The alternative is
normalize_inner()itself, which is a two-line change andwould make the documented promise of
Repository::normalize_path()— "Pathswhich traverse outside of the repository are rejected" — true for every
caller. I left it alone because it also changes callers unrelated to this
work:
gix_submodule::File::path()would start rejecting a.gitmodulespath = ./../evilthat it accepts today, andgix_pathspec::Pattern::normalize()would start rejecting
./../x. Both look like improvements, but they belongin a change against
gix-path, not in this one.resolve
./and../revspec paths against the current directory, like in Git.gitrevisions(7)states that a path starting with./or../is relative to thecurrent working directory and gets converted to be relative to the working tree's root
directory.
gixpassed these paths on verbatim, so in a repository withdir/g1.txtcommitted, and with the current directory being
dir/, git 2.50.1 and gix disagreed:HEAD:./g1.txtCould not find path "./g1.txt" in treeHEAD:../f1.txtCould not find path "../f1.txt" in tree:./g1.txtPath "./g1.txt" did not exist in index at stage 0HEAD:./dirdelegate.peel_until(Path("./")) failedgix-revision's parser forwards such paths intact on purpose, and theNavigatedelegate documentation promises the conversion, but the
giximplementation of itnever performed one.
The tree lookup in
peel_until()andindex_lookup()now route paths with eitherprefix through
Repository::normalize_path(). Like Git, this requires the currentdirectory to be inside a worktree, and paths traversing above the worktree stay
rejected.
respect filter driver configuration precedence
A filter driver declared in user configuration incorrectly won over a
repository-local declaration with the same name. A regression test demonstrates
both the local property override and inheritance of a user-level property that
is not overridden.
Merge repeated named filter sections in configuration order and replace
only the properties present in each later section. This matches Git's
read_convert_config() behavior in convert.c as inspected at
cf5497b.respect inherited core.symlinks when cloning.
Load global configuration with the clone open options before repository
initialization, and preserve an effective core.symlinks=false as a
high-precedence override. Combine that result with probed filesystem
capabilities so either source can disable symlinks.
Match Git initialization by persisting core.symlinks=false only when the
filesystem probe fails; never write a local true that masks inherited
configuration. Add a portable plumbing-built symlink fixture and cover both
configuration-false/probe-true and configuration-true/probe-false clones.
let GIT_WORK_TREE override core.bare
Commit Statistics
Commit Details
view details
ed9a650)b1174b6)ebe9095)7424676)gix::Repository(d934f5b)b2d919a)is_dirty()-to-the-current-working-directory (ea9a6d4)44ba4b4)is_dirty()to the current working directory (cb74ef6)f3bbfad)Repository::delete_local_branches(). (61c5e1e)gix-object(object signing) (723d3de)Commit::sign()(8017175)Commit::verify()(15809f9)commit::SignedData::verify()(5b90699)a9f090e)e1c56e4)a30f442)gix-testtools(0cbe539)e5452ba)gix-ref(5810922)dd8c759)gix-odb(1dc741f)gix-odb(a0b93a3)05f905e)566fea1)a8b1be5)<rev>^{/}like Git, instead of skipping it. (6746715)gix-date(613ff86)dbd162d)GIT_ALLOW_PROTOCOL(287ab8f)77b5848)gix-url(2648dc1)gix-url(62e140d)GIT_INDEX_FILE-via-gitoxide.core.indexFile(aa3b006)tree-editorfeature toggle (3a4350c)need-more-recent-msrvas it's not required anymore (f1c8911)GIT_INDEX_FILEwhen opening repositories viadiscover_with_environment_overrides()(f9b3891)GIT_INDEX_FILEviagitoxide.core.indexFile(e1856d0)ef41caa)gix-refspec. (9fa50a5)95e0213)gix-blame(93d4019)7a34c17)0760b60)368438c)d14aefb)e99f637)232dd1c)5510bce)dffd5ef)./..revspec paths that leave the worktree, like in Git. (92e3133)./and../revspec paths against the current directory, like in Git. (6171a05)cc3ee80)ab4fcb0)a7e0a2e)4f480b9)5708de4)make_clone_with_symlinkfixture archive (18e42fa)4a6cf9d)gix-packuses the parallel feature (79e3478)b049777)file://URL in the same fixture (3dabe4a)gitpath and the URL in the credential-helper baseline (951f40f)command -vrather thanwhichto locategitin a fixture (51afc13)50713b0)config()function (9923d76)da71d06)f03905e)275c26a)639535e)93ad8f9)03ef906)29aa7cd)4b3bf5a)commit::Info::generation(e768682)82711e1)75444cb](https://redirect.github.com/GitoxConfiguration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.