Repository navigation
Drop comments that restate the code - #5
Merged
Merged
Conversation
Comment-only. No code line changes. - engine.rs: four inline comments restating the serde_json round-trip that the two lines below them already say. One doc line kept because it records why the order matters (the hash covers this form). - keys.rs add_to_index: a trailing question to yourself about rotation. The next line is keys.push, and the code below it pushes. - mount.rs: an empty 'Public mount helper' banner above the FUSE impl with no helper under it. - cli.rs: '// Handlers' had lost its opening rule; 'Validate has_breaking helper stays consistent' narrates the debug_assert on the next line. 4 insertions, 12 deletions.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
Comment-only. Not one line of code moved, so no behavior can change.
src/engine.rsserde_jsonround-trip on the two lines under it. The doc comment onto_canonical_jsonstays, trimmed to the one fact a reader cannot get from the code: the hash covers this form, so key order has to be stable.src/keys.rsadd_to_indexcarried a note to self about deactivating keys on rotation, ending in a question mark. The code pushes, androtatetwo hundred lines down is where deactivation actually happens.src/mount.rsPublic mount helpersection banner with no helper under it.mount_readonlysits directly above.src/cli.rs// Handlershad lost its opening---rule and sat glued to the previous function.// Validate has_breaking helper stays consistentnarrates thedebug_assert!on the next line.Gate
cargo fmt --check && cargo clippy -- -D warnings && cargo test --locked && cargo build --locked106 tests, same counts as
origin/main.Not shipped
Behavior changes from the same review run. Each needs a decision, so none are in this PR.
1. Policy fields are stored and never enforced.
src/server.rs:71Policycarriesallowed_branchesandblocked_env_keys.push_statereadspolicy.require_signedatsrc/server.rs:75and nothing else. Grep for both fields acrosssrc/returns only the struct, the two setters, and the round-trip test.Reproduced against a live server with a policy of
allowed_branches: ["main"]:A state on a forbidden branch is accepted and a ref is written for it. Same path for
blocked_env_keys: the sync loop adopts a state carryingSECRET=sk_live_...into a signed state file with no check against policy.Minimal fix, both in
push_statenext to the existingrequire_signedcheck: reject whenallowed_branchesis non-empty and does not containsigned.state.base.branch, and reject when any key ofsigned.state.env_varsis inblocked_env_keys. Four lines each. Decide first whether a blocked key should reject the push or be stripped from the state.2.
sync --dry-rundeletes the drift file.src/cli.rs:1211The no-drift branch runs before the
args.dry_runcheck at line 1241:--dry-runpromises nothing is adopted, and it deletes a file.tests/cli.rs:489covers dry-run with real drift and never reaches this branch, so the suite is green while the file is gone.Minimal fix: hoist the
if args.dry_runreturn above thediffs.is_empty()branch, or guard theremove_filewith!args.keep && !args.dry_run. One line.3. README shows output the binary does not produce.
README.md:42The sample
taproot mountblock printsmaterialized: 2.4 GB (lazy), a[s]ync · [f]ork · [d]etachprompt, and a container list.print_mount_headerinsrc/cli.rs:525prints none of those. Measured against the built binary:The stats are also wrong regardless of the CLI. The state pins zero bytes of container, so "2.4 GB (lazy)" describes nothing the code has. Trimming the block to the real output needs no code change.