fix(deps): update rust crate gix to 0.88 - #1202
ferrlabs-renovate[bot] wants to merge 1 commit into
Conversation
There was a problem hiding this comment.
One blocking finding: the bump moves gix to 0.88 but leaves the sibling gix-traverse and gix-diff pins behind, which splits the dependency graph into two incompatible copies of gix-object/gix-hash. Details and a suggested fix inline.
Also noting for the author: Cargo Security is failing on this head too. I could not read that job's log, so I do not know whether it shares the same cause.
| gix-traverse = { version = "0.61", optional = true } | ||
| gix-diff = { version = "0.67", default-features = false, features = ["sha1"], optional = true } |
There was a problem hiding this comment.
Blocking: gix 0.88 moved to gix-traverse 0.62 and gix-diff 0.68, but these two direct pins stay on 0.61/0.67. The lockfile therefore carries both trees side by side (gix-object 0.64.1 and 0.65.0, gix-hash 0.26.2 and 0.27.0, and so on), and the source passes values across that boundary:
changed_paths_between()insrc/git/diff.rsbuilds agix::objs::TreeRefIter(gix-object 0.65) withrepo.object_hash()(gix-hash 0.27) and hands both togix_diff::tree()from gix-diff 0.67, which expects the 0.64/0.26 types.find_matching_commit()insrc/git/tags.rswrapsgix_traverse::commit::simple::CommitTimeOrder(0.61) ingix::revision::walk::Sorting, which gix 0.88 re-exports from gix-traverse 0.62.
Both are E0308 under the default cli feature. Build Release Binary is already failing on this head.
I confirmed against the crates.io index that sha1 still exists as a feature on gix-diff 0.68.0 and gix-traverse 0.62.0, so the manifest side is just the version bump:
| gix-traverse = { version = "0.61", optional = true } | |
| gix-diff = { version = "0.67", default-features = false, features = ["sha1"], optional = true } | |
| gix-traverse = { version = "0.62", optional = true } | |
| gix-diff = { version = "0.68", default-features = false, features = ["sha1"], optional = true } |
That fixes the duplication, but gix 0.88 is a breaking release beyond the version numbers (public errors consolidated under gix::Error/Exn, error aliases removed), so expect the aligned build to surface further source changes in src/git/.
This PR contains the following updates:
0.87→0.88Release Notes
GitoxideLabs/gitoxide (gix)
v0.88.0: gix v0.88.0Compare Source
Bug Fixes (BREAKING)
preserve causes across fallible conversions
Rubber stamp, looked at diff. This is a cleanup commit.
There is going to be considerable cleanup done later as well.
Parsers and adapters discarded encoding, integer, date, signature, and
object-access failures when replacing them with context. Preserve their
concrete causes so classification and downcasting keep working after
conversion to
gix::Erroror an I/O error.Return
Exnfrom fallible path, command-line, gitdir, and pack-entryconversions where necessary, and adapt their consumers in the same change.
Packed-ref and reflog errors retain their parser sources and input details;
reflog recovery reports the actual recovery failure. Loose-object verification
now propagates lookup and enumeration failures instead of treating every
lookup error as retryable or silently skipping failed enumeration.
Remove unnecessary UTF-8 conversions for ASCII suffixes and check span bounds
before narrowing. Parsers that only return
()explicitly destructure it.No production
map_err()closure still discards a wildcard-bound error.Also preserve causes in formatting-only CLI and commit-graph adapters, where
stringification previously lost checksum corruption classifications.
locate
vi/vimin Git's core directory on Windows; changeRepository::editor() -> Option<gix_command::Prepare>On Windows, Git's bundled
vimay not be available through PATH. Resolve thedefault editor in Git's core directory first and retain the bare command as
fallback.
New Features (BREAKING)
return the local branches actually deleted
Callers that needed to know whether branch deletion removed anything had
to look up each reference separately. That duplicated reference reads and
could report stale existence information by the time deletion took its
locks.
Return sorted, deduplicated full names from the committed reference edits
whose previous values were observed under lock. Missing branches are
excluded while their stale local configuration is still removed. Expose
the same list as
deletedindelete::Error::Cleanupso callers can recoverit when only configuration cleanup fails; retain
referencesas the fullrequested batch.
The success value changes from
()toVec<FullName>, andCleanupgainsa
deletedfield. Strengthen the existing tests for loose, packed, danglingsymbolic, duplicate, missing, empty, and linked-worktree branch requests.
Changed (BREAKING)
remove redundant error aliases
rubberstamp
The crate-by-crate migration retained operation-specific error aliases to
limit downstream churn. With the migration complete, those names only hide
the shared error types and keep otherwise empty API namespaces alive.
Use the underlying
gix_errortypes directly throughout the workspace,including indirect aliases, renamed exports, test helpers, and the URL fuzz
target. Remove namespaces and files that only held forwarding aliases, and
update documentation and migration guidance to use the canonical types.
Adjust the source locations recorded in error snapshots after deleting the
alias declarations.
Keep
gix::{Error, Exn}andgix::erroras the central facade, along withunrenamed canonical re-exports, required associated types, concrete errors,
and aliases that add structure. Preserve each
Exnparameter, conditionalerror alternative, error message, and source chain. Include all downstream
adaptations in this breaking change so the stack remains buildable.
consolidate public API failures under gix::Error
rubberstamp
raise MSRV to Rust 1.88
The newly published
dua-core3.3 release used by linked-worktree removalrequires Rust 1.88, so raise every workspace crate and the advertised badge
together.
Keep the MSRV checks buildable by selecting the latest
sysinfoandrusqliterelease lines that support Rust 1.88.
New Features
add
Repository::config_path()Callers with a repository currently have to select local and worktree
configuration paths themselves before falling back to
gix::config_path().Expose that selection on
Repository, using its common directory forSource::Local, its Git directory forSource::Worktree, and its openingoptions with the existing resolver for global sources.
Keep the worktree path available even when
extensions.worktreeConfigisdisabled, so callers can locate and prepare that physical file. Preserve
the existing errors for disabled sources and sources without a file.
Git reference:
builtin/config.candDocumentation/git-config.adocinthe local Git checkout at
1630431f326e15fcde608827b5ff38422528eb59.The executable baseline was Git 2.50.1 (Apple Git-155).
expose standalone configuration paths with
config_path()Callers need to locate a configuration file before starting a
config_mut()transaction so they can inspect it, prepare its parentdirectory, or load it themselves.
Extract the existing path selection into
gix::config_path(source, options)and use it fromconfig_mut(). Preserve source and environmentpermissions, explicit path overrides, and current-directory anchoring.
Path lookup succeeds without existing parent directories or valid
configuration contents, and does not acquire a transaction lock or
evaluate transaction settings.
Git reference:
v2.55.0-782-g1630431f32,config.cfunctionsgit_system_config()andgit_global_config_paths(), plus the global andsystem override tests in
t/t1300-config.sh. The shared resolver retainsthe existing source-specific path and override behavior.
add standalone
config_mut()transactionsCallers can load global configuration with
gix::config(), but editingone physical file previously required a repository. Add a sibling that
accepts
config::Sourceandopen::Optionsand returns the existingconfig::FileTransaction.Share source-path resolution and
core.configLockTimeoutparsing withconfiguration loading and repository transactions. Honor source and
environment permissions, preserve source metadata, and keep physical
edits lossless without persisting includes or runtime overrides.
Global files use normal filesystem permissions; missing files can be
created on commit when their parent directory already exists.
allow presetting system configuration paths
Callers that already know the Git-installation and system configuration files
can now provide both paths through
gix::open::Options. The paths flow throughrepository opening and standalone configuration loading, while the existing
source permissions continue to decide whether each file is read.
Preset paths replace path discovery, but must not bypass Git's explicit
GIT_CONFIG_NOSYSTEMswitch. Read the permitted environment value once beforeselecting Git-installation and system sources, preserving the behavior already
implemented by
gix_config::Source::storage_location().add
worktreeProxy::is_prunable()+ fixExpose
worktree::Proxy::is_prunable()with Git-compatible semantics: lockedworktrees are retained, while unreadable
gitdirfiles and missing checkouttargets are prunable. Treat any filesystem entry at
lockedas a lock,including symlinks.
When opening a proxy as a repository, use the common directory already known
by its parent instead of relying on the linked worktree’s optional
commondirfile. This prevents incomplete administration from being mistaken for a
standalone repository and keeps
HEADaccess routed through the repository refstore for backend compatibility.
Fetch can consequently inspect linked-worktree heads without failing for missing
checkouts, locks, or missing and malformed
commondirfiles.edit physical configuration files atomically with
Repository::config_file_mut()Add
Repository::config_file_mut()as a transaction over one physicalconfiguration file. It acquires a symlink-aware lock before reading, parses
without expanding includes, preserves formatting and existing permissions, and
resolves relative paths against the opening CWD.
Lock acquisition honors the discoverable core.configLockTimeout key
with Git-compatible parsing and a 1000 ms default. New files also honor
core.sharedRepository after the process umask, including named, boolean,
compatibility, and explicit octal modes.
Committing only writes the file atomically. Repository state changes through
an explicit full reload, which retains normal Git-compatible validation and
rebuilds include- and bootstrap-dependent state without a second partial-refresh
path.
add
Repository::committer_or_set_fallback()Applications that configure
gitoxide.committer.*Fallbackunconditionally canoverride a complete
user.*identity because these keys resolve first.Add
Repository::committer_or_set_fallback()so callers can provide alast-resort identity without changing normal configured-user behavior. Keep the
generic helper as a wrapper, and document and test the precedence.
Bug Fixes
propagate failed fetch ancestry checks
Looked at this in detail to understand how error handling improvements
were made. It all makes sense, and teaches me to... not ignore or
skip over errors, ever, it's basically a bug unless there is a test
that proves it's not a bug.
Fetch ref updates discarded commit decoding and traversal setup errors,
treating any such failure as permission to force the update. A malformed
local or remote commit could therefore overwrite a ref without a force
refspec. Traversal errors were also ignored when looking for the ancestor.
Propagate those failures with their original causes and context. Check
object kinds explicitly to retain the existing behavior for non-commit
targets without mistaking corruption for an object-kind mismatch.
Keep rust workspace tests inside disposable repositories and isolated environments
Direct Git launches inherited repository selectors and user configuration even
when tests supplied a fixture working directory. Tests of default-environment
APIs and local Git transports also shared the runner's environment. A few
journey tests wrote beneath source directories or used the source checkout as
the repository under test.
Use the shared
gix-testtoolsGit command builder for subprocess setup, isolatedrepository options for fixtures, and isolated child processes where the real
environment-reading API must be exercised. Scope CWD changes, copy the fixture
used by an object-write test, and run shell journeys through
jtt run. Keepjourney worktrees and example output within their disposable sandboxes and
replace the attributes checkout test with a representative fixture repository.
Prompt examples also run in isolated children and must build successfully; the
old tests could ignore build failures and execute stale cached binaries.
The affected Rust crate suites, internal test-tool build, and
max-purejourneysuite pass from a source copy without Git metadata. Signing and Git-daemon
checks use only disposable keys, repositories, and local sockets.
find bundled signature programs on Windows
Git for Windows makes its bundled
gpg,gpgsm, andssh-keygenavailableby prepending installation directories to
PATH. Gitoxide can run outside thatprepared environment, so bare defaults may not resolve.
Use
gix_path::env::installation_program()for unconfigured defaults on Windowsand retain the bare name as fallback. Explicit configuration and non-Windows
behavior stay unchanged.
interpolate signature verifier program paths
Git treats
gpg.*.programvalues as pathnames and expands a leading tildebefore launching the verifier. Signing already did this, but verification kept
the raw configured string, which fails with direct program invocation.
Resolve OpenPGP, X.509, and SSH verifier programs through the existing
trusted-path handling while preserving defaults and the legacy
gpg.programfallback.
normalize safe-directory paths before trust checks
Windows canonicalization can produce verbatim paths with a
\\?\prefix whileincluded configuration metadata uses an ordinary drive path. Comparing those
representations directly prevents an explicitly safe config file from being
promoted to full trust, including after repository reloads.
Canonicalize both the path under test and configured safe-directory paths
through the filesystem before exact or wildcard comparison. Retain the existing
lexical realpath fallback for missing paths.
make identity fallbacks true last-resort values
gitoxide.{author,committer}.*Fallbackshared its configuration slot with thecorresponding environment overrides. This placed application fallbacks before
user.*, while also placingGIT_{AUTHOR,COMMITTER}_*after role-specificconfiguration.
Store environment overrides under
author.*andcommitter.*, then resolveexplicit fallback keys only after
user.*. This matches Git precedence and letsapplications configure fallbacks without replacing a valid user identity.
Commit Statistics
Commit Details
view details
worktreeProxy::is_prunable()+ fix (0af2f91)6356013)dcf08a4)0b2a5c4)9d0329a)gixAPI boundaries (ba2c7f2)daf73b5)2176245)b1e31eb)a5e8c4d)gixCargo example (2bab44c)4b9ff51)2fb9b8a)c609062)4e0f8ff)4f29e0c)92b6508)2742f05)dfc8e8c)283937b)Repository::config_path()(76502a0)be7bb02)config_path()(707818c)d7551f1)3b60097)config_mut()transactions (18ac842)6b2f33d)4a870be)36b6310)653c002)87727ee)c16300c)3c45a7d)b7bedcf)ec63505)a095334)4b42e0c)b14028d)c48fe1e)Repository::config_file_mut()(913f631)7e35849)888677a)ab66595)d23127a)Repository::committer_or_set_fallback()(c355827)e3a6fa1)a1d5a55)vi/vimin Git's core directory on Windows; changeRepository::editor() -> Option<gix_command::Prepare>(b76cc28)dda600d)Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate CLI.