feat: forge-v2 data plane — repos, pushes, membership on protocol 14 - #18
Merged
Merged
Conversation
|
Warning Review limit reachedNext included review available in 26 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (59)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Repositories are now forge-v2: a repo document plus the owner's maintainer membership and an initial config in the shared forge-core contract, created by one journaled, resumable session. Refs, config, pack manifests and chunks are addressed through a DocScope that adds repoId to every query and write; v1 repositories resolve read-only through the registry. Membership is writer/maintainer documents (dg collab add/remove/list); consensus refuses a non-member's write with 40120. Fetch reads each pack from its best verifying copy in the FORGE_RULES_V2 order, and repack consolidates without deleting anything. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
locator_pack_space and the push-index plan now use the shared rule: one entry per pack hash at its first upload, ranked representative copy, packRef counted within kind 0. Superseded packs keep their positions (v2 manifests are permanent), so a repack appends instead of renumbering; repack, reseed and fetch read every git pack from its best copy. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…r secret Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…eded Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…copies Review follow-ups: a consumed nonce is no longer taken as success (forge-v2 writes share one nonce counter per identity) — creates and deletes confirm by a proved read and re-prepare; the push chunk journal is keyed by repo and uploader; a dead or hostile copy of a pack no longer blocks an honest push (the pusher stores its own); a writer pushing a protected ref is refused before paying, and 40120 on a maintainer-only type says so; a create replay that provably never landed is discarded instead of stranding the journal, and a private repo is never adopted; fetch falls back to time order without the member list and ignores non-members' chunkless manifests; reseed skips unreadable packs; v1 names resolve to the slug. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…r landing check Re-review follow-ups: a writer's push refuses just the refs matching protected patterns (deletes included) and pushes the rest; the proved-read check after a consumed nonce waits ~15 s before signing a replacement; the maintainer-only error suggests an unprotected branch only for refs. The live lifecycle test now covers a writer on a protected ref (typed protectedRefUpdate refusal) and an unprotected one (lands). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
PastaPastaPasta
force-pushed
the
feat/forge-v2-data-plane
branch
from
September 25, 2026 18:27
da57f7c to
5578d5f
Compare
4 tasks done
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
PR "C" of the forge-v2 client migration. It moves the CLI's git data plane onto forge-v2 (protocol 14).
git-remote-dash,dg repo,dg collabanddg repacknow create, push to and clone repositories that live as documents in the shared forge-core contract. forge-v1 repositories (one contract each) can still be read but are now read only. Builds on #15 (SDK 4.2); rebased on #14 / #16.Model
RepoRef(forge_core::scope) is eitherV2 { forge, repo_id, owner_id, name, visibility }orV1 { contract_id, owner_id, name }(read only). Every write starts withrequire_v2(), which fails with E605 before anything is signed on a v1 repo.DocScopeis the contract plus an optionalrepoId.repoId == R, which is the first property of every forge-core index, and every write carriesrepoId.$ownerId). The locator format isplatform://<core>/<repoId>/<owner>/<packHash>.uris,protectedPatternsandbackend.urisare typed string arrays on v2 and JSON strings on v1.forge_core::resolve):dash://owner/name: check the name as a slug withrules::v2, then look up the forge-corerepoby($ownerId, name).dash://<id>: try a v2 repo document id first, then a v1 repo contract id. The forge contracts themselves and unrelated contracts are refused.forge_core::create) is one journaled, resumable session: it writesrepo, then the owner's ownmaintainerdocument, then the firstconfig.$XDG_STATE_HOME/dash-forge/journalsbefore it is broadcast.REPO_V1_TEMPLATE, the solo-owner token rules,contract_create, token writes, and orphan-contract recovery.forge_core::members):writer/maintainerdocument, revoke means the owner deletes it, and list queries byrepoId.dg collab add|remove|listwork on v2.suspend/unsuspendexplain thatremoverevokes access immediately.tokens.rsis now a read-only v1 collaborator list.ownerRefersTorefuses a non-member'srefUpdate,chunkorpackManifestwith 40120. That becomesError::NotAMember { document_type, .. }and E601, or "only maintainers …" on a maintainer-only type.dg collab add. It also refuses a writer updating a protected ref before any pack is paid for.DASH_FORGE_SKIP_WRITE_PRECHECK=1still bypasses it.BroadcastOutcome::NonceConsumed). The push chunk journal is keyed by repo and uploader.FORGE_RULES_V2order (maintainers, writers, others).$ownerIdis in the pack indexes.storage = 0manifest cannot fail a clone.v2_pack_list(Rust + TypeScript, 13 conformance vectors, forge-v2.md §4).packRefcounts within its kind, andsupersedesonly binds from a verified pack.locator_pack_spaceis built on it. It is its own commit (7073326) so the web port (PR E, feat(web): read forge-v2 repos (protocol 14) with v1 read-compat #17) can share it.dg repackno longer promises a refund, anddg repo deleteis gone.urisis a typed array, budgeted at 8 × 300 bytes (UriBudget).forge_core::private):RefNameHasher,RepoCodec,PackCipherandRepoKeyReader, with only the public implementation. Private repos are refused until the private-repo PR.refs.rs) is now scoped byDocScope.RepoRef::v1_contract_id(); forge-collab is PR D.Live verification (devnet moutai, protocol 14)
dg repo create(repo + maintainer + config)exists, 0 creditsgit push/git cloneround-tripfsck --strictcleanprotectedRefUpdateis maintainer-only) with the typed "only maintainers" error; the same writer's unprotected ref lands… document type writer … not found for path $ownerId)e2e/cli/storage-byo.sh, local MinIO + kubo)dash://v1 clonee2e/cli/run.shon moutaiBYO storage checks, all passing:
uris;reseed --from-localrestores the recorded copy.Review
An independent review covered the authorization assumptions, resumability and double-paying, ambiguity in URL resolution, and v1 read-compat. It found these problems:
supersedesclaims could hide packs;All are fixed, with unit tests, in 52a7e87, 5654715 and da57f7c. A re-review of the fixes confirmed them; its nits (refuse only the protected refs of a writer's push, a longer landing check) are in da57f7c. A simplification pass is folded into the feature commit:
create_landednow goes throughcreate_journaled, plusrole_doc,readable(), and removal of the dead v1 helpers.Gates
cargo fmt --all -- --check,cargo clippy --locked --workspace --all-targets -- -D warningsandcargo test --locked --workspaceall pass.pnpm typecheck, lint on the touched files, the conformance suite (206/206) andpnpm buildall pass. The only web changes are thev2PackListport and its conformance case.e2e / CI changes
e2e-clirepo created on first use.FORGE_MOUTAI_IDENTITY_OWNER,FORGE_MOUTAI_IDENTITY_COLLABandFORGE_MOUTAI_IDENTITY_CONTRIB, plus the existingFORGE_TEST_IDENTITY_CONTRIBfor scenario 08. Until they exist, the suite job reportsskipped.m1-5124) is a testnet v1 repo. Because v1 is read only,seed-read-fixture.shnow only verifies it; the fixture moves to forge-v2 with the web app.Known gaps
dg migrate(v1 → v2) is not written yet.dg repo createthere fails with E702.🤖 Generated with Claude Code