gitoriaLog in with ident

gitoria

All repositories: gitoria

ReadmeCodePull requestsReleasesTicketsSettings
Commit8660544686605446mission 002 (code order) 4/4: README file map + import order + 'Same output' test + gate run with a tickets HEAD copy, STATUS (entry, lessons), LOG, report; tests/realdata-baseline.mjs + realdata-compare.py (a cleanup answers the same on live data: pages, modules, API, git over HTTPS and SSH, faces), tests/letcount.pymre86605446/STATUS.md

31.1 KB

  1. # gitoria.worldapi.org — status
  2. ## Built
  3. - **002 (2026-10-03): code order — no behaviour change** (antcolony `docs/code-order.md`). Commits on main, not pushed, not
  4. deployed: 1/4 files out of the root, 2/4 topics + map + thin wrappers, 3/4 `let`, 4/4 docs + tests. File map: README "Files".
  5. - Counts (`python3 tests/letcount.py .`): root `.hl` 14 → **1**; project.hl 251 → **126** lines; `let` 530 → **213**, never
  6. reassigned 296 → **0** (the 213 left: 125 reassigned, 88 re-bound in a loop body — Hybriel refuses a plain one there).
  7. - Gates (ports 8750–8759, commands README "Test") after every step: browser **200/0**, push **46/0**, ssh **44/0**.
  8. - Same output (README "Test" → "Same output"; live copy 2026-10-03, deleted after): 758 answers (678 reads + 80 writes:
  9. faces, HTTPS clone/push with a token, SSH clone/push through the real sshd container); everything identical except
  10. **one intended difference**: a failed login in a browser that ALREADY has a session now shows its reason on /login/failed
  11. (old: the reason was parked in a copy of the session and lost → "the login did not finish"). Cause and fix: lesson below.
  12. - Removed: `jsoncheck.hl` (imported nowhere), `git.hl parseView` (called nowhere). Merged: three copies of the newest-first sort
  13. → `util.hl newestFirst`; the owner-may-push rule of HTTPS + SSH → `repos.hl mayPush`; the exchange + ensureUser of the
  14. login button and the selector face → `users.hl userOfLoginCode`.
  15. - Not run: `tests/short-id-switch.mjs` (historical, fixed ports 8724/8725 outside the range); the tool
  16. `tools/migrate-short-ids.hl` loads and refuses exactly as before (no storage / no key / ident down).
  17. - Lessons: (1) a route that writes the session must get `&req` and `&server.sessions` (project.hl wrappers → lib/api.hl):
  18. copied into a second call (route → helper) the session inside `req` is a copy and its writes are lost — gitoria's old
  19. `failed(req, why)` lost the login-failure reason that way. (2) A plain declaration inside a for/while body is refused on the
  20. 2nd pass: those 88 keep `let`. (3) Inside a component handler `x = …` assigns the MEMBER `x` if one exists — checked, no
  21. clash. (4) The browser module of a component carries the statics of every file it imports (as functions or refusing
  22. stubs naming the file): moving a static changes those tables and the `?v=` hashes, not the page; `realdata-compare.py`
  23. checks the component code and the kind of every imported name instead. (5) The tickets working tree can be mid-change by
  24. another worker: run the browser gate with `GITORIA_GATE_TICKETS_DIR` = a `git archive HEAD` copy of tickets (+ its bin).
  25. (6) A crashed gate leaves its servers running (ports busy for the next gate): `ss -ltnp | grep :875` and kill by PID.
  26. - **074 (2026-10-03): re-vendored hybriel master 06617221 — ADOPTED** (plugin allocators 3a781359 + 413f60e4, mpackdb
  27. 2cb7ae5e, http1 773de63e, event order f0ac2d2d). Old copy `.scratch/pre-074/` (190aa11d). Not deployed by me.
  28. - Gates (8760–8769): browser **200/0**, push **46/0**, ssh **44/0** (`.scratch/w074/gate-*.txt`). No lambda semantics change.
  29. - Tracker README `/` via curl, 20 loads: new 0.69–0.73 s, RSS 230 → 348 → 355 MB (flat); old 190aa11d 0.67–0.76 s, 228 → 343
  30. → 345 MB. Page body identical apart from the hashed asset URLs.
  31. - Chrome memtest 200 signed-in loads + 20 clones: new 224 → 279 → 316 MB, avg 2903 ms; old 223 → 329 → 356 MB, avg 3037 ms.
  32. - Long signed-in curl run (`longcurl.sh`, all 10 pages incl. tracker): new 2000 req 338 → 389 MB, 5000 req 353 (500) → 464 MB
  33. (~24 KB per request, time flat ~0.2 s); old 2000 req 339 → 416 MB (~40 KB per request). **Not fully flat** — watch live RSS.
  34. - Still open (also old): Chrome tracker `/code` 20–28 s from the 2nd load (browser-side; a 2000-load Chrome run was aborted after
  35. 58 min with the Chrome renderer at 330 % CPU / 2.6 GB while the server stayed at 300–350 MB).
  36. - **072 (2026-10-02): re-vendored hybriel master 190aa11d — ADOPTED** (fc838894 GC correctness, 04df4428 #127 mountKids by
  37. reference, #126, #48). Old copy `.scratch/pre-072/` (ff51cf46). Not deployed by me (conductor deploys).
  38. - Gates (ports 8720–8729): browser **200/0**, push **46/0**, ssh **44/0** (`.scratch/w072/gate-*.txt`); commands in the 072 report.
  39. - #48 (new for gitoria): `probe48.hl` → new `copy: 0`, old `copy: 1`; `lambdas*.py` re-run, no `.hl` change since the 069
  40. audit → nothing needs `&`.
  41. - Real-data copy (deleted): tracker `/` via curl, 20 loads: 0.54–0.61 s, RSS 232 MB boot → 298 after load 1 → 319 MB at load 20 / 10 s
  42. idle (flat). Old: 8.9 → 16.1 s over 8 loads, 4.7–6.2 GB. Page body identical old vs new (only css hash + client script differ).
  43. - Chrome memtest, signed in, 200 loads incl. tracker `/` + `/code`, 20 clones: 225 → 321 → 343 MB, avg 1951 ms. Without the
  44. tracker pages: 224 → 268 → 315 MB, avg 671 ms (069 old: 760 → 7448 → 7757 MB, avg 1736 ms).
  45. - **Open (pre-existing, also on old)**: in Chrome, tracker `/code` takes ~13 s from the 2nd load on (1st 0.7 s), gitoria
  46. `/code` up to 6.9 s; server answers `/code` in 0.04 s via curl and RSS doesn't move → browser-side (client/service worker?).
  47. Series: `.scratch/w072/mem-{new,old}-tracker.txt`.
  48. - **069 round 2 (2026-10-02): master 1a096ad3 (with #127 d98926c6) NOT adopted either, old vendor ff51cf46 kept**.
  49. - Gates on new: browser **200/0** (was 198/1 once, see below), push **46/0**, ssh **44/0**.
  50. - Repro `.scratch/w069/repro`, flat and child variants: now flat at 0.3–0.6 GB, 2.5 s per request (old 3.7–4.6 s, 3–8 GB).
  51. - **Still growing: gitoria's Markdown component** on the tracker README.
  52. - App, curl: +190 MB per load, 7.5 s → 14.6 s by load 30, 7.4 GB, nothing freed after 60 s idle. Old: 9 → 16 s, 7 GB.
  53. - Repro with only components/markdown.hl (`cp components/big-md.hl components/big.hl; ./run.sh <bin> <plugins> 8`): new
  54. +185 MB per request, 7.2 → 8.5 s. Old 9.6 → 11.9 s.
  55. - Chrome memtest without the tracker pages: new 227 → 2967 → 3106 MB, average 1267 ms; old 760 → 7448 → 7757 MB, 1736 ms.
  56. With the tracker pages it ran over 580 s.
  57. - Faster and smaller than old, but not flat, so not adopted (the condition was "≤ old speed and flat").
  58. New vendor: `.scratch/w069/vendor-1a096ad3/`.
  59. - **Gate fix**: browser.mjs waits until the server has the logout before it restarts the server. Once, the logout emit was cut
  60. off by `stopServer()` ("browsers: no console errors" red). New check: "logout: the server has it too". 200/0 on old and new.
  61. - **Re-vendor to hybriel master 8efba065 (#126 memory, #48 lambda copy) STOPPED, old vendor kept (antcolony mission 069,
  62. 2026-10-02)**: gates were green on the new binary (ports 8760–8769; 8765/8766 are taken by others, so Chrome gets 8763–8769
  63. and Firefox 8769 — Firefox is closed before the 5th Chrome opens): browser.mjs **199/0**, push.mjs **46/0**, ssh.mjs **44/0**
  64. (`.scratch/w069/gate-*.txt`). Lambda audit (#48, 221 lambdas, `.scratch/w069/lambdas*.py`): nothing needs `&`. No lambda
  65. writes to a parameter; session writes are in faces or call `server.sessions.save(s)` themselves; `withMerge`/`withRefParts`/
  66. `withPullParts` return their result (probe `.scratch/w069/probe48.hl`). **Stopped at the memory proof**: real-data copy, 200
  67. signed-in Chrome loads (`.scratch/w069/memtest.mjs`):
  68. - Without the tracker pages: new 398 MB at boot → 3508 MB after the loads → 3581 MB after 20 clones; old 760 → 7448 → 7757 MB.
  69. The README on gitoria `/` takes up to 17 s on new vs 8.7 s on old.
  70. - With tracker `/` and `/code` (104 KB README → 2.3 MB HTML): new 12 s on the 1st load, 47 s on the 17th, +350 MB per load
  71. (`curlloop.sh`), and Chrome times out at load #28. Old: 9–14 s per load, 4.6–6.6 GB.
  72. Repro without gitoria: `.scratch/w069/repro/run.sh <bin> <plugins> N`. 40k text nodes: new 9–10 s and 0.5–0.8 GB; old 3.3–4.3 s
  73. and 7.4–8.3 GB. The same rows passed to a child component: new 15 → 23 s and +40 MB per request; old 3.7–6.9 s.
  74. New vendor ready to re-apply: `.scratch/w069/vendor-8efba065/{bin,plugins}`.
  75. - **Re-vendor to hybriel master ff51cf46 (antcolony mission 048, 2026-10-01)**: binary + plugins copied (old copy `.scratch/pre-048/`
  76. = 317d4754 bin/plugins + the pre-048 tests/). Gates on ports 8750–8758: browser.mjs **199/0** (twice), push.mjs **46/0**,
  77. ssh.mjs **44/0** (outputs `.scratch/048-*.out`). Found + fixed:
  78. - **Rows listed twice** (tokens, SSH keys): since hybriel 64527baa a face taking `session` syncs the session-derived members
  79. (`tokens`, `keyItems`) in its ack, so `makeToken`/`makeKey` prepended a row the list already had (ssh gate: 2 `li` with the
  80. same id; old binary 44/0, new one red — checked by swapping bin/plugins back). `components/tokens.hl`, `sshkeys.hl`: skip a
  81. row with the new id. push.mjs: new check "the first token is listed ONCE".
  82. - push.mjs + ssh.mjs still expected the pre-gitoria#20 "add code" `<details>` on every repo page (were red on the old binary
  83. too, never re-run after #20): now the box on the empty repo's `/code`, plain text; none on Readme / `/code` after a push.
  84. - browser.mjs tickets: the server pushes `ticketOpened` before the face answers, so the list row can come before the notice
  85. (failed once) — the check now waits for `#ticketnotice`.
  86. Duplicate `@id`s in the LIVE data (copy of Byrodin `storage/mpackdb`, deleted after): repos 13 rows / 0 dup, sshkeys 1/0,
  87. tokens 1/0, users 1/0, ticketlinks 0/0. Workarounds: none of #115/#116/#118 kind in gitoria (component helpers are plain
  88. lambdas already, no literal-list loops); no SVG built in the browser. Kept: `.nomerge` class (if-in-for), netProbe, temp
  89. files + `sh -c`, `base64 -d`. `short-id-switch.mjs` not run (fixed ports 8724/8725, one-off migration gate). Not deployed.
  90. - **Installable app (PWA) + icons (antcolony mission 046, 2026-10-01)**: `icons/` (`icon.svg` source = a git branch in blue
  91. `#569bd4` on rgb(25,30,35), inside the maskable safe zone → `icon-192.png`, `icon-512.png`, `apple-touch-icon.png` 180;
  92. `favicon.svg`, `favicon.ico` 16/32/48 — commands in README "PWA"). `project.hl`: `appIcons` (192/512 × any/maskable),
  93. `appTouchIcon`, `appFavicon`, `appThemeColor = darker.value` (header), `appBackgroundColor = dark.value`,
  94. `offline = [ Index ]`, file routes for the icons, `/favicon.ico` now a real file (was `direct = ""`).
  95. `components/main.hl`: offline note + `netProbe` tick (as tracker#10); `styles.hl`: `offlineNote`, `netProbe`,
  96. `@keyframes gitoria-net-tick`. Gate +15 checks at the end (see README "Test", PWA block): **199 passed, 0 failed**
  97. (`GITORIA_GATE_PORT=8720 GITORIA_GATE_IDENT_PORT=8721 GITORIA_GATE_TICKETS_PORT=8722 GITORIA_GATE_CHROME=8723-8727
  98. GITORIA_GATE_FIREFOX=8728 node tests/browser.mjs`). Looked at: Loreana `/tmp/w046-gitoria/` (`icon-48/192/512.png`,
  99. `maskable-circle.png`, `small-on-white.png`, `sheet.png`, `gate-pwa-phone-{online,offline}.png`).
  100. Offline `/` is the page AS LAST SEEN (repo list / Readme — possibly stale, and the logged-in view if that was the last
  101. visit); offline the header's ident selector still shows "choose ident" (script from ident's origin). Real-phone install
  102. test after deploy: https://gitoria.worldapi.org → "Add to home screen". Not deployed.
  103. - **"Add code" only on the Code page of an empty repo (gitoria#20, 2026-09-27)**: the help was a `<details>` open by
  104. default on every repo tab; the creator wants it plain text (no toggle) and only where it makes sense — the Code page,
  105. while the repo has no commits yet. `components/repohead.hl`: new `onCodePage` (default `false`, only `code.hl` sets it
  106. `true`); `showAddCode = onCodePage && emptyRepo`; the `<details>/<summary>` is gone, `addCode` is now the outer box
  107. (`id="addcode"`) rendered only when `showAddCode`. `styles.hl`: dropped the `summary` rule. `components/readme.hl`'s
  108. "no README.md yet" message now links to the Code page instead of "the box above" (which no longer stands there);
  109. `git.hl`'s two "no commits yet" messages (shared by `/code`, `/branch`, `/commit`) point to the Code page the same way.
  110. `tests/browser.mjs`: 12 new checks — an empty repo (gamma) shows the plain-text box only on `/code`, not on Readme /
  111. Pull requests / Releases / Tickets / Settings; a filled repo (alpha, has commits) shows it nowhere. **184 passed, 0
  112. failed** (was 172; ports 8700–8703 server/ident/tickets/Firefox, 8704–8709 Chrome). Not deployed.
  113. - **Tickets with projects and roles (gitoria#19, 2026-09-26)**: tickets #20 no longer makes a project with its first ticket and needs the role edit. `tickets.hl` `ensureProject`: before the first ticket of a repo gitoria creates the project (`POST /api/projects`, slug = title = `<slug>.<host>`); the creator is its admin (includes edit), so gitoria's user is a member. Existing projects are left as they are. `tests/browser.mjs` seeds its own direct ticket the same way: **157 passed, 0 failed** against the current tickets code (ports 8710–8713). Until the connect flow (tickets#21 → gitoria#18).
  114. - **Short ids (antcolony mission 039, ident#23, 2026-09-26)**: `users.hl`: the exchange answer is checked with the new `isIdentId` (lower-case letters/digits, 1–64) instead of
  115. `isHex(…, 64)`, which refused ident#23's short ids (`a68sz`) — without it nobody could log in after the switch (shown on
  116. tickets, whose code antcolony mission 039 could not change). New `tools/migrate-short-ids.hl` (users.identity old → short id via
  117. ident `POST /api/migrate-ids`, idempotent, never `finish`, prints `users seen / mapped / already short / unmapped /
  118. conflicts / failed`, key/secret from env only; non-zero exit on refusal/failed write/conflict). New gate
  119. `node tests/short-id-switch.mjs` (ports 8724/8725; old ident `ident.worldapi.org/.scratch/pre-023-ident` → data → copies →
  120. new ident → control copy = NEW empty user → tool twice → same user + same data, old session too): **18 passed, 0 failed**.
  121. `tests/browser.mjs` 157/0 — with `GITORIA_GATE_TICKETS_DIR` = a tickets copy that has the same users.hl change
  122. (tickets' own folder still refuses short ids: the gate's tickets login fails 400, gate crashes and LEAVES its tickets process on
  123. the tickets port — kill it); push.mjs 46/0, ssh.mjs 44/0 (ports 8728-8739).
  124. Runbook (architect, one go for all four apps): Loreana `antcolony-docs/docs/short-id-switch.md`. Deploy this code BEFORE
  125. ident#23 (accepts old ids too). Not deployed.
  126. - **Re-vendor to hybriel master 317d4754** (mission 038, 2026-09-26; includes 7cb9f8fc = hybriel#107 fix): copy binary + plugins
  127. (no local patch; old copy `.scratch/pre-038/` = 13ef4f9b). Gate change re-applied from 037: the logged-in folder step in
  128. `tests/browser.mjs` (`loggedSteps`, used by Chrome AND Firefox) waits for `#crumbs a` instead of `#crumbs strong` (which /code
  129. already has, so the step passed with /code/src still in flight). Gates (ports as below): browser.mjs **157/0** twice (both runs
  130. incl. `FIREFOX, navigation LOGGED IN` ok — #107 does not reproduce), push.mjs **46/0**, ssh.mjs **44/0**; outputs
  131. `.scratch/038-{browser-1,browser-2,push,ssh}.out`. Dev server (port 8726, scratch storage): `app.css`, `hl-runtime.js`,
  132. `web/client.js` `?v=5ceedf0b9850f8c7`, hashed app.css → `immutable`, bare → `no-cache`. Not deployed.
  133. - **Re-vendor to hybriel master e6720b1f** (antcolony mission 037, 2026-09-26; ROLLED BACK, superseded by 038): copy binary + plugins (no local patch; old copy
  134. `.scratch/pre-037/`). Gates (ports as below): browser.mjs **157/0** (2 runs, incl. Firefox), push.mjs **46/0**, ssh.mjs **44/0**.
  135. Dev server: `hl-runtime.js`, `web/client.js`, `app.css` `?v=c7398714992bf1de` (immutable), bare app.css no-cache, 0 unhashed refs.
  136. One gate change: the logged-in navigation step into a folder waited for `#crumbs strong`, which /code already has → the step
  137. passed with the page emit for /code/src still in flight; the next `ff.goto(gamma)` then failed with NS_BINDING_ABORTED
  138. (reproducible 2/2; 157/0 on 13ef4f9b). Now it waits for `#crumbs a` (only inside a folder). The cause is a HYBRIEL bug
  139. (new client `lost()`, #82): Firefox closes the page's WebSocket when a navigation away starts; `lost()` answers the
  140. in-flight `page` emit with null, and `showOne` then does `location.href = path` — a full load of the in-app page that
  141. cancels the navigation the user started (traced with WebDriver BiDi: navigationStarted gamma → warn "the socket closed before
  142. an emit was answered" 44 ms later → navigationStarted alpha/code/src). Reported to the architect for a hybriel ticket. Not deployed.
  143. - **Re-vendor to hybriel master 13ef4f9b** (antcolony mission 035, 2026-09-25): copy binary + plugins (no local patch). Consequence of #89
  144. (chunked request bodies): the push gate's "direct chunked push → 411" check failed (the push now works) → dropped the 411
  145. branch in `transport.hl`, the check now pushes a 4 MB commit straight to hl:http1 (`http.postBuffer=65536`, chunked) and
  146. expects it in the bare repo. Kept: temp files + `sh -c`, `base64 -d` (reasons in README "Behind nginx"). Gates (ports
  147. `GITORIA_GATE_PORT=8720 GITORIA_GATE_IDENT_PORT=8721 GITORIA_GATE_TICKETS_PORT=8722 GITORIA_GATE_PROXY=8722
  148. GITORIA_GATE_SSH_PORT=8723 GITORIA_GATE_FIREFOX=8724 GITORIA_GATE_CHROME=8725-8739`): browser.mjs **157/0** (incl. Firefox),
  149. push.mjs **46/0**, ssh.mjs **44/0**. Dev server serves `/__hl/app.css?v=<hash>` (immutable), bare → no-cache. Not deployed.
  150. - **Merge button for pull requests** (gitoria#17, 2026-09-25): on `/pulls` the repo owner (only) sees "Merge" on an open request whose source and target
  151. branches exist; the click (face `gitoriaMergePull` in `components/pulls.hl`, `git.hl mergePullNow`) merges the source into the target IN the bare repo:
  152. `merge-tree --write-tree` → `commit-tree` (merge commit, author = the owner's name) → `update-ref` with the old value (a push meanwhile = no merge).
  153. A conflict merges nothing and the page names the files. Never automatic (creator, gitoria#13). The request is found again on the server by its commit sha.
  154. Gate `node tests/browser.mjs`: **157 checks green** (buttons only for the owner on open requests, forged session, conflict → nothing merged, merge
  155. commit with two parents, request shows merged). Not deployed. Found: an `if` inside a `for` row is not re-evaluated when the list is reassigned
  156. (the button stayed) — the button is always rendered and hidden with a class (`.nomerge`). Not built: squash / rebase, closing a request without merging.
  157. - **Push and pull over SSH** (gitoria#7, 2026-09-25, second worker): `docker/sshd` (sshd container: `AuthorizedKeysCommand` → app, forced command `gitoria-shell`, host keys volume),
  158. `sshkeys.hl` + `components/sshkeys.hl` (SSH keys page: paste public key, `ssh-keygen -l` check, list, remove), `sshgate.hl` (`/__git/keys`, `/__git/access`, secret + no proxy),
  159. ssh commands in the "add code" box (`repohead.hl`), service `gitoria-sshd` in `docker-compose.yml`, `openssh-client` in the Dockerfile. Gate `node tests/ssh.mjs`: **44 checks green**
  160. with the real sshd container + real ssh/git (needs docker); `push.mjs` 46 and `browser.mjs` 149 still green. Not deployed. **Deploy needs** (README "Git over SSH"): `GITORIA_SSH_SECRET`
  161. in `.env`, firewall port (2222), DNS-only record for the ssh host (Cloudflare proxy carries no ssh), rebuild both images. SSH is hidden on the site until the secret is set.
  162. Not built (not decided): private repos, collaborators, protected branches, size limits.
  163. - **Push and pull over HTTPS + "Add code" box** (gitoria#7, 2026-09-25): `transport.hl` (smart-HTTP clone/fetch/push with `git upload-pack|receive-pack
  164. --stateless-rpc`, body via temp files, protocol v0/v1/v2, gzip requests), `tokens.hl` + `components/tokens.hl` (access tokens: shown once, sha256 stored,
  165. list/remove, on the main address), the box in `components/repohead.hl` (clone command, new/existing-project commands, open while the repo is empty),
  166. `git.hl isEmptyNow`, routes in `project.hl`, `styles.hl`. Read is public; only the owner's token may push. Gate `node tests/push.mjs`: **46 checks
  167. green** (real git: clone empty, push refused without / with wrong / another user's token, owner pushes a 4 MB pack, clone, gzip fetch with 300 local commits,
  168. pull, v0/v2, removed token stops at once, odd requests, layout 390/1280); `node tests/browser.mjs` still 149 green. Not deployed. **SSH: see the next entry.** Not built: collaborators / private repos / protected branches (not decided), SSH keys page.
  169. Deploy needs: nginx `client_max_body_size` (500m) and default request buffering on the `*.gitoria` vhost (README "Push and pull"); the Dockerfile has git, gzip, base64 (debian).
  170. Found: hl:http1 gives `body = null` for a chunked request (hence the proxy note); hybriel has no base64 decoder (the Basic header is decoded with `base64 -d`).
  171. - **Every repo view its own server-rendered page** (gitoria#16, mission 001 (old 033), 2026-09-25): `components/index.hl` (`/`: list.hl on the
  172. main address, readme.hl on a repo address), `code.hl` / `branch.hl` / `commit.hl` (+ `codebrowser.hl`), `pulls.hl`, `releases.hl`,
  173. `tickets.hl`, `repohead.hl`, `loginfailed.hl` (was `htmlPage`). The repo comes from `host = null` (hybriel#74), git is read with
  174. hl:proc `run()` (hybriel#80, `git.hl` `*Now`): README, file list/file, branch, commit, pulls, releases and tickets are in the FIRST
  175. HTML, no "Loading". Gone: `components/home.hl`, `/host.js` (+ route), the hidden #hostslug/#loading inputs, `gitoriaOpen`,
  176. `gitoriaDocs/Code/Pulls/Releases` and their pushed answers; `?next=` moved into `login.js`. The rest of `/code/*path` etc. is the
  177. page member `path` (hybriel#81). Gate `node tests/browser.mjs`: **149 checks green**, incl. hybriel#43 (a code view in another tab
  178. keeps its elements through a login + logout) and NAVIGATION LOGGED IN in Chrome AND a real Firefox 155 (`tests/firefox.mjs`, BiDi):
  179. button login on a repo address, Readme → Code → Releases → Pulls → Tickets → Code → folder, an empty owned repo, and (Chrome) with
  180. the socket closed — no full page load anywhere. Not deployed.
  181. **Open — the creator's full page loads in Firefox 155 are NOT reproduced**: locally logged in (Chrome + Firefox) and on the LIVE site
  182. signed out (Firefox, h3 via Cloudflare, also with the socket closed) the marker survives. Not tested: live + logged in (it would
  183. write a user into live data). Found on the way: hl:web never reconnects a closed WebSocket (`client.hl` `close` → `socket = null`,
  184. no retry): after Cloudflare's ~100 s idle close every emit rides POST and live pushes (new repo, new ticket, login in another tab)
  185. no longer arrive — a hybriel ticket candidate.
  186. - **Hybriel re-vendored from master 2fbfe195** (mission 001 (old 033); edf27bc1 → 6ae171af → 2fbfe195): binary sha256 `2a3c2b02…b565`
  187. (ReleaseFast from `git archive`), plugins core crypto data fetch fs http http1 mpackdb proc time **web** (every import `'hl:web'`).
  188. Older copies in `.scratch/pre-033/`, `pre-033b/`, `pre-033d/`. **No local patch left**: the cookie Domain is `sessionDomain`
  189. (#44) in project.hl. Dropped earlier: patches for #34/#39, HL_HOST listener (#24), `server.sessions.cookie` (#10), `realSession()`
  190. (#16), URL encoders (#14), `sessions.resolve` in the callback (#11). Master refuses `if (!x)` in a View → `noSource` for pulls.
  191. - **Identity selector** (gitoria#14, 2026-09-25): ident's `<ident-selector>` in the header beside "Log in with ident", like tickets
  192. (`components/main.hl` face `gitoriaLogin`, `login.js`, `users.hl selectorScript`, `styles.hl`, route `/login.js`). Gate `node tests/browser.mjs`:
  193. 122 checks green (choose identity → logged in without reload, logout resets it, hidden on a repo address, button unchanged). The gate now
  194. serves ident as `ident.gitoria.test` (same site as gitoria.test, else ident's Lax cookie never reaches the selector's fetch). Not deployed.
  195. - **Releases from commit messages** (gitoria#12, 2026-09-25): `/releases` of a repo address lists them (`git.hl` `parseRelease`, `releases`,
  196. `components/home.hl`, face `gitoriaReleases`, pushed `releasesReady`). Gate `node tests/browser.mjs`: 116 checks green (patch / `med` / `mj` /
  197. by-hand versions counted up, newest first, marker inside text / bad version / repeated version / other branch ignored, HTML as text,
  198. empty repo, forged face, 390/1280px). Not deployed. Not built: real git tags, downloadable archives, release notes page, API.
  199. - **Pull requests from commit messages** (gitoria#11, 2026-09-24): `/pulls` of a repo address lists them (`git.hl` `parsePull`, `pulls`,
  200. `components/home.hl`, face `gitoriaPulls`, pushed `pullsReady`). Gate `node tests/browser.mjs`: 108 checks green (marker parsing,
  201. target `|||PR|branch] `, merged vs open, missing target, one per source branch, HTML as text, empty repo, forged face, 390/1280px).
  202. Not deployed. Not built: merging in gitoria (open question to the creator), a PR page with diff/comments, PR numbers, API, a settings page
  203. for the default target (the repo's main branch is used).
  204. - **Connect a repo to a tickets project; #N links** (gitoria#18, 2026-09-26): `/settings` "Tickets: connect" (tickets' connect flow, key per repo),
  205. `/tickets` and open-ticket use the key + the user's ident id, `#N` links in commits / pull requests, "mentioned in commit" comments and
  206. "fixes #N" → review on push / merge (`tickets.hl`, `components/settings.hl`, `project.hl` /settings/connect(ed)).
  207. Gate `node tests/browser.mjs` (ports 8700-8708; `GITORIA_GATE_FIREFOX=8708 GITORIA_GATE_CHROME=8703-8707`): **172 passed, 0 failed** against
  208. a real tickets copy: the owner connects (button → tickets' project choice → back), opens a ticket (created by the person); a REAL git push
  209. over HTTP with "fix login, #1" → ticket 1 shows "Mentioned in commit …" (once); a merged `|||PR … fixes #1` pushed → ticket 1 in review
  210. (once); #N links on the commit page and /pulls; forget + connect again; a replaced tickets copy. `tests/ticketskit.mjs` takes `origins`
  211. (TICKETS_CONNECT_ORIGINS) and returns the session cookie; the token flow is gone from the gate. Fixed on the way: the Merge click built the
  212. ticket-link pieces in the browser (tickets.hl reads the environment, so the list stayed stale); the face now sends them. Decided: #99 (a
  213. ticket that does not exist) is still a link. Not deployed.
  214. - **Tickets inside a repo** (gitoria#10, 2026-09-24): `/tickets` of a repo address lists the tickets of its project in tickets.worldapi.org
  215. (`<slug>.<host>`), any named user opens one (gitoria's own API token; the text says who), the first ticket creates the project there.
  216. `tickets.hl`, `components/home.hl`, `git.hl parseView`, `tests/ticketskit.mjs`. Gate `node tests/browser.mjs`: 99 checks green (own tickets
  217. copy: 404 → first ticket creates the project, text as text, live to another viewer, ticket made in tickets shows on reload, forged
  218. session refused, tickets down message, 390/1280px). Not deployed: needs `GITORIA_TICKETS_TOKEN` in `.env` (README "Tickets").
  219. Not built: ticket text/comments inside gitoria, real author in tickets (tickets has no act-on-behalf).
  220. - **Browse code** (gitoria#9, 2026-09-24): `/code`, `/branch/<name>`, `/commit/<id>` (+ a path), `git.hl` `browse`, `components/home.hl`, `host.js`,
  221. `repos.hl` (`branch` field, `setMainBranch`), routes in `project.hl`. Gate `node tests/browser.mjs`: 79 checks green (main branch tree,
  222. folder/file/crumbs, old commit incl. short id, branch with a slash, binary file, unknown branch/commit/path messages, empty repo,
  223. "Make main" for the owner only, homepage follows the setting, 390/1280px). Not deployed. Not built: API / Markdown read view of code,
  224. commit diff, syntax highlighting. Found: hl:proc lines cannot carry non-UTF-8 bytes (breaks the socket) — files are checked with
  225. `git grep` first; a non-UTF-8 author name / branch name is not handled.
  226. - **Repo homepage from README and $docs** (gitoria#8, 2026-09-24): `git.hl`, `markdown.hl`, `components/markdown.hl`, `components/home.hl`;
  227. repo creation makes a bare git repo. Gate `node tests/browser.mjs`: 54 checks green (README as HTML incl. table/quote/rule/code,
  228. unsafe HTML and `javascript:` links stay text, `$docs` replaces README, empty repo message, 390/1280px). Not deployed:
  229. the Dockerfile now installs `git`; repos created before this have no bare repo yet (they show "no README.md yet").
  230. Not built: Markdown read view of the homepage in the API, images in Markdown, per-repo branch setting (#9).
  231. - **Repos with their own address** (gitoria#6, 2026-09-24): the app (`project.hl`, `components/`, `repos.hl`, `users.hl`),
  232. README "How a repo gets its address". Gate `node tests/browser.mjs`: 46 checks green (create, refusals, unique slug, live
  233. list, `<slug>.gitoria.test` pages, login from a repo address, shared cookie, restart, 390/1280px). Not deployed.
  234. Not built: git data (#7), homepage (#8), code browsing (#9), tickets (#10), pulls (#11), releases (#12), API creation, settings.
  235. ## Research done
  236. - [`docs/differ-from-custom-ide.md`](docs/differ-from-custom-ide.md) — gitoria#2: whether to reuse
  237. custom-ide's diff/editor (CodeJar-based) as a Hybriel component. Verdict: the diff **algorithm**
  238. (`lineDiff.js`, pure, no DOM) is directly reusable as a native Hybriel module; the CodeJar-based
  239. editing **surface** is real engineering (~3,400 LOC total, not "simple") and a native rewrite is blocked on
  240. open webex tickets (hybriel#31/#32/#33/#17/#41). Final plan (see Decision below): native Hybriel only,
  241. no JS-asset interim.
  242. - [`docs/git-backend.md`](docs/git-backend.md) — gitoria#5: how to use git from Hybriel. Verdict: the `git`
  243. binary, no `hl:git` library plugin (libgit2 has no server side). Reads via `hl:proc`; HTTPS clone/push
  244. served by Hybriel itself (`git upload-pack|receive-pack --stateless-rpc` through hl:proc stdin/binary, after
  245. hybriel#42); only SSH needs a small sshd container. Tested: byte-exact blobs, upload-pack over stdin, hl:http1
  246. byte-safe bodies. Full endpoint (#7) and SSH not run.
  247. ## Decision (gitoria#4, rejected 2026-09-24)
  248. Embedding custom-ide's JS bundle is **not** wanted. Editor and differ are built natively in Hybriel as
  249. shared components in layouts.worldapi.org (as ticket #2 said). Not started: the native port; the editing
  250. surface is blocked on hybriel#31/#32/#33/#17.
  251. Note: `DECISIONS.md` is generated by the librarian and still says "no decisions recorded yet"; it does not yet hold this decision.
  252. - **How to get code in, said where the creator looks** (gitoria#8 sent back 2026-09-25: "no description how i get a repo in at the /code page"): the "Add code to this repository" box (gitoria#7, `repohead.hl`, open while the repo is empty) was built but not yet deployed when the creator tested. The empty messages of the Readme and Code views now point to it (`components/readme.hl`, `git.hl`). Gate `node tests/browser.mjs`: 149 green. Needs the gitoria#7 deploy.
  253. ## 2026-09-26 antcolony mission 037 rolled back
  254. The re-vendor to hybriel master e6720b1f was ROLLED BACK (bin/ plugins/ tests/browser.mjs from .scratch/pre-037): the new client pulls Firefox users back during a navigation (hybriel#107). gitoria stays on 13ef4f9b until #107 is fixed; then re-vendor and use the stricter code-browser check (#crumbs a) from antcolony mission 037.
  255. **Done in mission 038** (see Built): master 317d4754 with the #107 fix, stricter check applied, all gates green.

Branches

Latest commits

  • 86605446mission 002 (code order) 4/4: README file map + import order + 'Same output' test + gate run with a tickets HEAD copy, STATUS (entry, lessons), LOG, report; tests/realdata-baseline.mjs + realdata-compare.py (a cleanup answers the same on live data: pages, modules, API, git over HTTPS and SSH, faces), tests/letcount.pymre
  • cc7bf7bamission 002 (code order) 3/4: let only where a variable is reassigned or re-bound in a loop body (289 lets → plain declarations; 213 left: 125 reassigned, 88 loop-bound; no member/import/param clash). gates 200/0, 46/0, 44/0; real-data reads + writes identical (browser modules: var → const only)mre
  • 090a20c6mission 002 (code order) 2/4: one lib/ file per topic — git.hl split into git (calls, branches, init, temp folder) / homepage / code / pulls / releases (+ git-helpers: paths, ids, |||PR/|||RL markers); repos-helpers, tickets-helpers, transport-helpers; util.hl = localtime + env, storage dir, addresses, lists, text checks, one newest-first sort (was 3 copies); the function routes out of project.hl into lib/api.hl (thin; plumbing in api-helpers.hl), sshgate.hl folded into api.hl + sshkeys.hl keyLine + repos.hl mayPush; 'Make main' and the merge answer out of the faces (code.hl makeMain, pulls.hl pullsView), one login helper (users.hl userOfLoginCode); project.hl is the map. Session-writing routes get &req + &server.sessions. gates 200/0, 46/0, 44/0; real-data identical except /login/failed now shows the parked reason for a browser that already had a session (the old copy-of-req lost it)mre
  • 110c2799mission 002 (code order) 1/4: .hl files out of the root — lib/ (api, git, localtime, markdown, repos, sshgate, sshkeys, tickets, tokens, transport, users), components/styles.hl; jsoncheck.hl removed (imported nowhere); import paths only. gates 200/0, 46/0, 44/0; real-data reads + writes identicalmre
  • fdfb4b1bgitoria: Hybriel master 06617221 (plugin allocators 3a781359 + 413f60e4, mpackdb 2cb7ae5e, http1 773de63e); gates 200/0, 46/0, 44/0mre
  • 5b46ac84antcolony#40: LOG.md — missions 069/072 are antcolony missions (report paths on Byrodin)mre
  • 5602ff41gitoria: Hybriel master 190aa11d (fc838894 GC correctness, #127 mountKids by reference, #126, #48) — tracker README flat; gates 200/0, 46/0, 44/0mre
  • e85eaf01gitoria: 069 round 2 — hybriel 1a096ad3 not adopted (Markdown SSR still grows); browser gate waits for the server-side logout before restartmre
  • 09ce4f3fgitoria: mission 069 re-vendor hybriel 8efba065 stopped (big SSR pages grow + slow down); lambda audit clean; old vendor keptmre
  • 3dc43108antcolony#40: mission references point to the moved missionsmre
  • 8d9450fdantcolony#40: history (LOG.md), worker briefs (missions/) and reports moved here from antcolony, numbered per project; old numbers in antcolony docs/mission-map.mdmre
  • 205d5fe4gitoria: Hybriel master ff51cf46; ssh keys/tokens no double rows (session sync); gates follow #20mre
  • 9b27cb26gitoria#21: installable app (manifest, service worker, offline start page), own iconmre
  • 68dcb603deploy.sh: back up live storage/.sessions/.env before every deploy (newest 5 kept)mre
  • e2deed6dgitoria#20: "Add code" only on the Code page of an empty repository, no collapsiblemre
  • 8bb97ffddeploy.sh: never send .git or .gitignore to Byrodinmre
  • fd981932State of 2026-09-27; bin/ no longer tracked (Hybriel commit is in README)mre
  • 4a2d7125initial commitmre