@projectpac/artifacts-git
v0.6.0
Published
Part of PAC: @projectpac/artifacts-git.
Readme
@projectpac/artifacts-git
The artifact store two peers negotiate over, claiming ctx.artifacts: one
history per resource, each revision attributed to the node that authored it, and
agreement recorded as a mark on a revision.
git is used for what it is good at -- content-addressed history, a diff, and a bundle that moves a revision between two repositories that share no remote -- and trusted for nothing else:
- Authorship is proven here, not read from git. A commit is signed by the face its workspace's session presents; an import verifies the signature it was handed, checks that the author claimed is the id that key derives, and takes the author from the key. The author field git writes is not evidence and is never read. The proof lives beside the repository, where a commit cannot rewrite it -- and unlike the bare author list it replaced, what is stored is checkable rather than asserted.
- Authorship survives a relay. Because the proof travels with the revision, a node that receives one from somebody other than its author still records the author. Attributing to the sender could not express that.
- The session is read through the caller's own context, so the store holds no ambient access to sessions -- only to the ones the flow calling it already owns. A flow cannot attribute a revision to a peer it is not talking to.
- Verify before applying. A bundle's size and hash are checked, then git's
own
bundle verify, and only then may it near a ref. It must also continue the history it claims to: the head it names has to be the current head, and the revision has to descend from it. - A workspace is a copy, not a checkout. A run writes into a plain
directory, so nothing it does can reach the repository's objects, and it is
bounded by file size, file count, total size, and count per flow: it is
scratch space, not storage. Closing it (
closeWorkspace) is the flow's job the moment its round is over -- the negotiation engine does so after every commit and agreement -- and the TTL is only the backstop for one that was forgotten, not the way a slot against the cap comes back.
Resources are scoped to the calling flow, which is half of the path they live under, so one flow cannot reach another's by name.
The conformance suite both this and @projectpac/artifacts-memory must satisfy lives in tests/artifactSuite.ts.
