Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 0 additions & 2 deletions crates/walgit-config/src/lib.rs
Original file line number Diff line number Diff line change
Expand Up @@ -569,7 +569,6 @@ pub struct GitConfig {
pub binary: PathBuf,
pub upload_pack_engine: UploadPackEngine,
pub allow_filter: bool,
pub allow_any_sha1_in_want: bool,
/// Default object format for new repos.
pub object_format: ObjectFormat,
/// Maintain a split commit-graph chain per local repo: tier-2 packs that
Expand Down Expand Up @@ -927,7 +926,6 @@ impl Default for GitConfig {
binary: PathBuf::from("git"),
upload_pack_engine: UploadPackEngine::Auto,
allow_filter: true,
allow_any_sha1_in_want: false,
object_format: ObjectFormat::Sha1,
commit_graph: true,
commit_graph_changed_paths: false,
Expand Down
2 changes: 1 addition & 1 deletion crates/walgit-server/tests/e2e.rs
Original file line number Diff line number Diff line change
Expand Up @@ -1447,7 +1447,7 @@ async fn push_from_a_shallow_clone() -> TestResult {
/// `allow-any-sha1-in-want`), plus `--depth` + filter together.
#[tokio::test(flavor = "multi_thread", worker_threads = 4)]
async fn partial_clone_tree_zero_and_depth_with_filter() -> TestResult {
let server = Server::start_with_tweak(|c| c.git.allow_any_sha1_in_want = true).await?;
let server = Server::start().await?;
server.put_repo("t", "tree0").await?;
let src = TestRepo::synthetic(5, 4)?;
git_in(
Expand Down
1 change: 0 additions & 1 deletion crates/walgit-server/tests/maintain.rs
Original file line number Diff line number Diff line change
Expand Up @@ -330,7 +330,6 @@ async fn fsck_unit_records_missing_objects_and_repair_unit_fetches_them_from_ups
let server = step!(
"start",
Server::start_with_tweak(|c| {
c.git.allow_any_sha1_in_want = true;
c.maintenance.checkpoints = false;
c.packs.enabled = false;
c.maintenance.fsck_interval = std::time::Duration::from_hours(1);
Expand Down
6 changes: 5 additions & 1 deletion docs/INTEGRITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -33,14 +33,18 @@ Due right after checkpoint when `fsck.pb` lists missing objects, `repaired_seq =
**`upstream.git`** (D24 setting, `[upstream] git = "https://github.com/acme/monorepo.git"`, `token_env` shared with
`upstream.lfs`, `docs/LFS.md`). Steps (`walgit_git::repair::fetch_objects_as_pack`): scratch bare repo under
`cache.dir/repair/`, `git fetch --depth=1 <upstream> <oid>…` in batches of 500 (GitHub serves commit, tree **and
blob** wants by SHA — verified 2026-08-21; walgit does with `git.allow_any_sha1_in_want`), `pack-objects` of exactly
blob** wants by SHA — verified 2026-08-21; walgit enables arbitrary object wants for partial-clone lazy fetches), `pack-objects` of exactly
the requested oids, verify every oid is in the resulting idx (a refused want is an error, never a silent hole),
then `RepoHandle::add_pack(tier 0)` → one **COMPACT entry superseding nothing** (what `walgit wal add-pack … --tier
0` did by hand for a large repository, seq 11). `fsck.pb.repaired_seq` is set so the next pass re-audits instead of repairing
again. Counter `walgit_repair_objects_total{repo}`. Test: `tests/maintain.rs
fsck_unit_records_missing_objects_and_repair_unit_fetches_them_from_upstream` (hole → audit → repair over HTTP from
a second repository → re-audit clean → idle).

This does not widen repository access: a principal with read access can already fetch any stored object by ID,
including objects unreachable from an advertised ref. Removing `git.allow_any_sha1_in_want` only removes a
non-functional configuration switch.

## 4. Runbook (what was done for a large repository, 2026-08-21 03:40Z)
1. Enumerate: `git rev-list --objects --missing=print <advertised tips> --not <known-good tip>` on the complete copy
(or read `fsck.pb` / `/var/lib/walgit/monorepo-fsck.out`) → 1,952 blobs, 70 MB.
Expand Down
1 change: 0 additions & 1 deletion walgit.example.toml
Original file line number Diff line number Diff line change
Expand Up @@ -182,7 +182,6 @@ max_object_bytes = "16GiB"
binary = "git" # path to upstream git binary (>= 2.47 recommended: pack.writeReverseIndex)
upload_pack_engine = "auto" # "auto" = stock git when packs are local/mount-linked, gix only for remote-served bases | "git" | "gix"
allow_filter = true # uploadpack.allowFilter
allow_any_sha1_in_want = false # uploadpack.allowAnySHA1InWant
object_format = "sha1" # default for new repos: "sha1" | "sha256"
commit_graph = true # maintain a split commit-graph chain per repo (tier-2 layer from the WAL + incremental)
history_pack = true # base rebuild also publishes commits+trees as a local "history pack"
Expand Down