Repository navigation
docs: replace invented mount output with real transcripts; drop dead guard - #7
Merged
Merged
Conversation
…guard
The README showed a `taproot mount` transcript that the CLI cannot produce:
a "materialized: 2.4 GB (lazy)" line, a `[s]ync · [f]ork · [d]etach`
prompt, and a claim that mount blocks execution on drift. None of that
exists. `grep` finds no fork or detach command, and `mount --no-fuse`
writes a 605-byte directory holding seven files. The transcript below is
pasted from a real run of the current binary.
Also drops an unreachable branch in validate_non_empty. An empty path
segment means the value starts with '/', ends with '/', or contains '//',
and all three are rejected before the loop. An exhaustive sweep over the
alphabet {a, /, ., empty} at lengths 1-6 (19530 inputs) finds no input
that reaches it, while the sibling '.'/'..' branch stays reachable. This
removes a check without weakening one: every value it would have rejected
is still rejected by an earlier guard.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
The README's headline transcript is not something
taprootcan print. It shows amaterialized: 2.4 GB (lazy)line, a[s]ync · [f]ork · [d]etachprompt, and claimsmount blocks execution when the state has drifted. None of that is in the code.
grep -rn 'Fork\|Detach' srcreturns nothing, andtaproot mount --no-fusewrites a605-byte directory containing seven files. The claim that mount blocks on drift is
also wrong: drift is what
taproot checkandtaproot syncare for.src/util.rsalso carried an unreachable guard insidevalidate_non_empty.What changed
The README transcript is now the verbatim output of the current binary, with a note on
what the tree actually contains and how drift is really handled.
The dead branch in
validate_non_emptyis deleted. An empty path segment requires thevalue to start with
/, end with/, or contain//, and all three cases alreadyreturn an error above the loop. An exhaustive sweep over the alphabet
{/, a, ., empty}at lengths 1 through 6 (19530 inputs) reaches that branch zero times. The sibling
"."/".."segment check stays: the same sweep finds 1630 inputs that reach it.No behavior changes. Every value the deleted branch rejected is still rejected, by an
earlier guard.
Verification
cargo fmt --all -- --checkexits 0.cargo clippy --locked -- -D warningsexits 0, which is the exact command CI runs.Not shipped
Three
Policyfields are settable but never enforced anywhere in the codebase:allowed_branches,blocked_env_keys, andrequire_check_strict. They can be writtenby
taproot fabric policy-setandPOST /v1/policy/:repo, they round-trip to JSON, andonly
require_signedis ever read (src/cli.rs:1888 and src/server.rs:75). A push to arepo whose policy lists
blocked_env_keys: ["SECRET"]succeeds today. That is a realgap but it is a behavior change, so it is not in this PR. See the report for the
reproduction.