Feature 10: import git repositories (docs/features/10) #22

Merged
crueber merged 2 commits from feat/repo-import into main 2026-09-04 12:16:11 +00:00
Owner

Implements Feature 10 per issue #21 plan + R1 (R1 normative on conflict).

New package internal/repoimport (NOT internal/import — Go keyword, R1 B1): RouteProvider on both lanes (POST /api/v1/repos/imports + browser twin → 202 + task; GET /api/v1/repos/imports/{id} + twin, JSON or SSE attach from the id-keyed replay ring), task kind repo-import on the core wal TaskTable via opsTasks-style wiring (RegisterKind panics on duplicate; no maintain.RegisterKind — does not exist), CLI walhub import --url through the same Service.

Task flow: scratch git clone --mirror → for-each-ref enumerate + S4 refmap → ingest via existing publish path (tier-0 packs + tier-2 base, with the .idx discipline AddPack lacks) → manifest PutCreate commit point → importer-admin via identity service → default policy (absent = default) → import.json provenance Create. B2 params-aware join-or-409, B3 409 on foreign manifest, S1 du-gate caps, S3 dynamic host-pinned credential argv, S8 timeouts, import.max_concurrent=2. Credentials never stored (params/packets/errors/logs/bucket grep-clean); embedded-URL creds refused 400; ssh/scp/git transports refused 400 in v1; SSRF defaults (deny-private, allowlist, allow_file_urls=false) + dangerous confirm.

UI /import page (form → running → done/error) + web/sdk/src/import.js, dark AND light, server-enforced gating; GitHub-shorthand normalize; LFS-as-pointers notice. EVIDENCE E11 (single-pack fixture, 6 GETs + 12 control PUTs + 0 LISTs flat across S/M). meta/import.json joins the frozen overwritable list + endpoints[] via api.RegisterExposed in the same change (law 12). Feature doc docs/features/10_git_import.md with Decisions recording every R1 resolution.

No list endpoint, no DELETE (cut in R1). Do NOT merge — review requested.

Implements Feature 10 per issue #21 plan + R1 (R1 normative on conflict). New package internal/repoimport (NOT internal/import — Go keyword, R1 B1): RouteProvider on both lanes (POST /api/v1/repos/imports + browser twin → 202 + task; GET /api/v1/repos/imports/{id} + twin, JSON or SSE attach from the id-keyed replay ring), task kind repo-import on the core wal TaskTable via opsTasks-style wiring (RegisterKind panics on duplicate; no maintain.RegisterKind — does not exist), CLI walhub import --url through the same Service. Task flow: scratch git clone --mirror → for-each-ref enumerate + S4 refmap → ingest via existing publish path (tier-0 packs + tier-2 base, with the .idx discipline AddPack lacks) → manifest PutCreate commit point → importer-admin via identity service → default policy (absent = default) → import.json provenance Create. B2 params-aware join-or-409, B3 409 on foreign manifest, S1 du-gate caps, S3 dynamic host-pinned credential argv, S8 timeouts, import.max_concurrent=2. Credentials never stored (params/packets/errors/logs/bucket grep-clean); embedded-URL creds refused 400; ssh/scp/git transports refused 400 in v1; SSRF defaults (deny-private, allowlist, allow_file_urls=false) + dangerous confirm. UI /import page (form → running → done/error) + web/sdk/src/import.js, dark AND light, server-enforced gating; GitHub-shorthand normalize; LFS-as-pointers notice. EVIDENCE E11 (single-pack fixture, 6 GETs + 12 control PUTs + 0 LISTs flat across S/M). meta/import.json joins the frozen overwritable list + endpoints[] via api.RegisterExposed in the same change (law 12). Feature doc docs/features/10_git_import.md with Decisions recording every R1 resolution. No list endpoint, no DELETE (cut in R1). Do NOT merge — review requested.
Implements Feature 10 per issue #21 plan + R1 (R1 normative on conflict):
new package internal/repoimport (RouteProvider both lanes, task kind
repo-import on the core wal TaskTable, CLI walhub import --url), POST +
GET one (+ SSE attach) twins, manifest-CAS commit point, S4 refmap,
never-stored credentials + SSRF gates, /import UI + import.js SDK,
[import] config, meta/import.json overwritable-list + endpoints[]
discovery amendments, E11 evidence entry.

Decisions appended: docs/features/10_git_import.md (R1 resolutions),
docs/go/04_git.md (pinned argv), docs/go/11_config_cli.md ([import] +
--url), docs/go/14_extensibility.md (list + RegisterExposed).
Review of Feature 10 (docs/features/10 §B3/B4/S12, 13_concurrency.md):
corrupt import.json is 409 (never adopt, B3) not 500; Begin no longer
holds the service lock across the probe store I/O; expired rings prune
lazily on Begin/Lookup (Janitor was unwired); SSE keepalive goroutine
exits via request ctx; GET guards nil service like POST. Doc: pruned
windows 404 per the §3 status table; E11 header names total (control).
Sign in to join this conversation.
No description provided.