Skip to content

Report source commit, public images, unsafe pulls - #15

Merged
jserv merged 4 commits into
mainfrom
improve
Oct 7, 2026
Merged

jserv merged 4 commits into
mainfrom
improve

Conversation

@jserv

@jserv jserv commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Four independent changes, one commit each. --version and the self-check report now name the source commit (marked -dirty when src/, build.rs, or the Cargo manifest or lockfile differ from it), so an installed binary older than its checkout is visible instead of silently running old code. An image upload refused for want of a workspace root now gives the real reason, suggests a root that would admit the file, and says a restart is needed. A successful upload reports publicly_readable from one signed-out HEAD of the link (no token, no redirects followed, only to the API's own site), so an agent learns before publishing that an image on a non-guest-readable note will fail for readers. A pull over a file with no usable sync record whose content differs from the note now needs discard_local_changes, and is reported under a new error kind, unverified_local_content, because pushing first cannot help a file with no record.

Behavior change: overwrite_local: true alone no longer replaces such an unrecorded, differing file. A file that already matches the note is still adopted, which is how a broken record is repaired.

Verified with cargo clippy --all-targets --all-features -- -D warnings and make check at every commit (tip: 297 lib tests, 11 stdio tests, live suites ignored), plus cargo build --release and commentflow --check. A second cargo build after a clean one reports the crate Fresh, so the build script does not force rebuilds.


Summary by cubic

The PR adds four independent changes: --version and the self-check report now name the source commit, image-upload refusals explain the cause and fix, uploads report whether the returned link is publicly readable, and pulls over unrecorded local edits require an explicit discard.

  • The reported commit is marked -dirty when src/, build.rs, or the Cargo manifest or lockfile differ from it, even when git settings would hide the edits or name another checkout; a build outside a git checkout omits it, and a failed read inside one is reported rather than passing as a tarball build.
  • An upload refused for want of a workspace root now says whether the setting came only from a working-directory .env, suggests a root that would admit the file, and notes that a restart is needed.
  • A successful upload now reports publicly_readable from one signed-out HEAD of the link, sent with no token, with no redirects followed, and only to the API's own site; only an image response, or a redirect to presigned storage carrying an access key, signature, and expiry, counts as readable, so an agent learns before publishing that an image on a non-guest-readable note will fail for readers.
  • A pull over a file with no usable sync record (none or broken) whose content differs from the note now needs discard_local_changes and fails with the new error kind unverified_local_content, since pushing first cannot help a file with no record.

Behavior change: overwrite_local: true alone no longer replaces such an unrecorded, differing file. A file that already matches the note is still adopted, which is how a broken record is repaired.

Written for commit 6481842. Summary will update on new commits.

Review in cubic Turn on auto-fix

cubic-dev-ai[bot]

This comment was marked as resolved.

jserv added 4 commits October 7, 2026 13:35
Every build of one release reports the same package version, so an
installed binary older than its checkout looked current while its tools
behaved as the old source did. A build script now records the commit,
marked dirty when the sources differ from it, and both --version and
the self-check report show it.

Cargo reruns the script only when the commit or the sources change, git
runs without optional locks so a build never races a commit, and git
settings or a hook's environment cannot hide a new source file or point
it at another checkout. When git fails inside the checkout, the build
warns instead of reporting no commit as if built from a tarball.
An upload refused for want of a workspace root only said the variable
was unset, even when a root came from the working-directory .env, which
does not count for publishing. The refusal now gives the actual reason,
suggests the directory holding the image as a root, and says the server
reads the setting only at startup, so a change needs a restart.
An image on a note others cannot read is refused to them too, and the
upload reply never said so, so an agent could publish an article whose
images fail for every reader. Right after an upload the server now
sends one signed-out HEAD for the link and reports publicly_readable:
true for an image or a redirect to presigned storage, false for a
refusal, null when the check proved nothing.

The request carries no token, follows no redirect, and goes only to the
API's own site, so an upload reply cannot aim it anywhere else. A
redirect counts as storage only with an access key, a signature, and an
expiry, and the check gives up after three seconds rather than hold up
an upload that already succeeded.
overwrite_local alone replaced a file with no usable sync record even
when its content differed from the note, such as one fetched by other
means and edited since, losing edits nothing showed were ever pushed.
Such a pull now also needs discard_local_changes. A file that already
matches the note is adopted, which is how a broken record is repaired.

The refusal has its own error kind, unverified_local_content, since
pushing first cannot help a file that has no record.
@jserv
jserv merged commit e844fa0 into main Oct 7, 2026
11 checks passed
@jserv
jserv deleted the improve branch October 7, 2026 05:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant