Repository navigation
Post private contribution bases from a local checkout - #1098
Merged
Merged
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Open-pool sellers fetch the base from target_repo_url before any seller is picked, so a base read from a local checkout would never reach them and the job would silently get zero claims. Refuse it at post time, before staging or upload, with a message pointing at seller_pubkey. Test fails with the check disabled.
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this does
Adds
base_local_pathtopost_job. It is an absolute checkout, linked-worktree or bare-repo path on the buyer daemon machine, and is accepted only with the four contribution pins. For private posts, the buyer stages the pinned commit and its entire reachable history from that repository, then runs the existing quota/type checks, uploads, and keeps the collect seed.If no path is supplied, it cannot be opened, the commit is missing, or its history cannot be staged, one plain log line explains the fallback and the existing
target_repo_urldownload runs. Relative paths are rejected. Public contribution posts do not upload a base. There is no CLI post command to extend; MCP forwards the new field through the daemon params intoPostJobRequest.job/ContributionSpec.Why unrelated code stays private
base_oid. Build a new pack from that walk; never copy source packs, refs, working files, or enumerate all source objects for upload.pack_forwardcan send it unchanged into the empty job repository. The original quota and symlink/submodule checks still run before provisioning/upload.Measurements
8-core Linux VPS; public
MakePrisms/agicashat89cda15345f4113d2be9962a37bea9c4d80483c6; 14,922 reachable objects. Release-mode standalone Rust probe using git2 0.19.0 / libgit2 1.8.1. Wall times below cover selecting objects, packing and indexing for libgit2; CLI rows are pack creation only. They exclude clone, HTTP upload and relay processing. Sizes are decimal MB. All libgit2 outputs were checked againstgit rev-list --objects <pin>: exact set, no extras.pack-objects --stdout --revs --delta-base-offset(reuse)--no-reuse-delta --threads=8set_threads(0), default delta windowpack.windowMemory=1pack.windowMemory=1pack.windowMemory=65536pack.windowMemory=1048576libgit2 1.8.1
pack-objects.creadspack.windowMemory, but ignorespack.window/pack.depthand does not reuse deltas. The selected limited-search option is the fastest measured supported option by the three-run median of the two leading candidates and adds about 3.7 MB versus the default. It changes config only in the temporary view. It is not a claimed universal optimum or a Mac result. Buyer-input fallback pushes also get the isolatedpackbuilder_parallelism(0)setting; seller pushes keep their current setting.Tests and mutation evidence
check_objects_after→ forbidden symlink post unexpectedly succeeds; remove contribution-only guard → from-scratch refusal assertion fails; addbase_local_pathto offer tags → event equality fails; remove MCP schema field → expected string schema becomes null; allow only submodule mode through the existing policy → the submodule refusal assertion fails. Every case compiled and failed at its intended assertion, not a compiler/fixture error.cargo clippy -p maxplayer-core --features acp,gateway,git-delivery,wallet --no-depsandcargo clippy -p maxplayer --features acp,wallet --no-depscompleted; pre-existing repository warnings remain. Only touched Rust files were formatted, with no workspace-wide cargo fmt.Limits
A checked-out private upstream can now be posted to a targeted seller, which reads the uploaded job base. Without a usable checkout the old downloader still needs to read the URL and can fail on a private upstream.
Open pool is not fixed end to end. The buyer can post using a local copy, but
seller_node/privacy.rs::preflightrewrites the base URL to the private job repo only for targeted discovery. Open-pool sellers still fetch the original upstream before claiming. No seller/preflight behaviour changed.Uncommitted changes are not inputs. Existing quotas and symlink/submodule refusal remain. Mac, production, and a real seller's full award/deliver/collect cycle are unverified. No merge or deployment is requested.
Advisor review
Independent read-only advisor verdict: approve, no actionable defects, at exact head
7b84495586f527cb9517c6a953963ec65ceebc84. Jobeed31a5f9efb9ca2a79af7278067fdecf3106ee7f64288cb200da58f4b86f203was posted with the requested seat andamount_sats=0,payment=none,visibility=public,output=text/markdown; result was read throughget_job(wait_for=result)and collected successfully for 0 sats.The reviewer inspected surrounding code and pinned libgit2 source; it did not rerun tests or timings. Optional further coverage noted: a non-repo subdirectory inside a checkout, a merge's second parent, forbidden modes only in ancestor trees, and an over-object-quota local history. These were not findings or approval conditions; the existing guards cover them by code inspection. No fixes or re-review were needed.
CI: all eight jobs passed in run 37244326981, verified against head
7b84495586f527cb9517c6a953963ec65ceebc84. Vercel checks also passed. No CI failures or reruns. PR remains OPEN / CLEAN; no merge or production deployment performed.Open-pool refusal (e495ba3)
An open-pool (
untargeted=true) post withbase_local_pathis now refused at post time, before any staging or upload, with a message pointing atseller_pubkey. Open-pool sellers fetch the base fromtarget_repo_urlbefore claiming, so a base read from a local checkout would never reach them and the job would silently get zero claims. Testpost_job_refuses_local_base_on_open_poolfails with the check disabled (confirmed locally). Docs and MCP schema updated to match.Note:
cargo clippy --all-targetsreportsunused_io_amountatgit_transport.rs:2129(test code). It is identical on main (:2122) and not touched here.