gitoriaLog in with ident

gitoria

All repositories: gitoria

ReadmeCodePull requestsReleasesTicketsSettings
Commitfd981932fd981932State of 2026-09-27; bin/ no longer tracked (Hybriel commit is in README)mrefd981932/STATUS.md

18.6 KB

  1. # gitoria.worldapi.org — status
  2. ## Built
  3. - **Tickets with projects and roles (gitoria#19, 2026-09-26)**: tickets #20 no longer makes a project with its first ticket and needs the role edit. `tickets.hl` `ensureProject`: before the first ticket of a repo gitoria creates the project (`POST /api/projects`, slug = title = `<slug>.<host>`); the creator is its admin (includes edit), so gitoria's user is a member. Existing projects are left as they are. `tests/browser.mjs` seeds its own direct ticket the same way: **157 passed, 0 failed** against the current tickets code (ports 8710–8713). Until the connect flow (tickets#21 → gitoria#18).
  4. - **Short ids (mission 039, ident#23, 2026-09-26)**: `users.hl`: the exchange answer is checked with the new `isIdentId` (lower-case letters/digits, 1–64) instead of
  5. `isHex(…, 64)`, which refused ident#23's short ids (`a68sz`) — without it nobody could log in after the switch (shown on
  6. tickets, whose code mission 039 could not change). New `tools/migrate-short-ids.hl` (users.identity old → short id via
  7. ident `POST /api/migrate-ids`, idempotent, never `finish`, prints `users seen / mapped / already short / unmapped /
  8. conflicts / failed`, key/secret from env only; non-zero exit on refusal/failed write/conflict). New gate
  9. `node tests/short-id-switch.mjs` (ports 8724/8725; old ident `ident.worldapi.org/.scratch/pre-023-ident` → data → copies →
  10. new ident → control copy = NEW empty user → tool twice → same user + same data, old session too): **18 passed, 0 failed**.
  11. `tests/browser.mjs` 157/0 — with `GITORIA_GATE_TICKETS_DIR` = a tickets copy that has the same users.hl change
  12. (tickets' own folder still refuses short ids: the gate's tickets login fails 400, gate crashes and LEAVES its tickets process on
  13. the tickets port — kill it); push.mjs 46/0, ssh.mjs 44/0 (ports 8728-8739).
  14. Runbook (architect, one go for all four apps): Loreana `antcolony-docs/docs/short-id-switch.md`. Deploy this code BEFORE
  15. ident#23 (accepts old ids too). Not deployed.
  16. - **Re-vendor to hybriel master 317d4754** (mission 038, 2026-09-26; includes 7cb9f8fc = hybriel#107 fix): copy binary + plugins
  17. (no local patch; old copy `.scratch/pre-038/` = 13ef4f9b). Gate change re-applied from 037: the logged-in folder step in
  18. `tests/browser.mjs` (`loggedSteps`, used by Chrome AND Firefox) waits for `#crumbs a` instead of `#crumbs strong` (which /code
  19. already has, so the step passed with /code/src still in flight). Gates (ports as below): browser.mjs **157/0** twice (both runs
  20. incl. `FIREFOX, navigation LOGGED IN` ok — #107 does not reproduce), push.mjs **46/0**, ssh.mjs **44/0**; outputs
  21. `.scratch/038-{browser-1,browser-2,push,ssh}.out`. Dev server (port 8726, scratch storage): `app.css`, `hl-runtime.js`,
  22. `web/client.js` `?v=5ceedf0b9850f8c7`, hashed app.css → `immutable`, bare → `no-cache`. Not deployed.
  23. - **Re-vendor to hybriel master e6720b1f** (mission 037, 2026-09-26; ROLLED BACK, superseded by 038): copy binary + plugins (no local patch; old copy
  24. `.scratch/pre-037/`). Gates (ports as below): browser.mjs **157/0** (2 runs, incl. Firefox), push.mjs **46/0**, ssh.mjs **44/0**.
  25. Dev server: `hl-runtime.js`, `web/client.js`, `app.css` `?v=c7398714992bf1de` (immutable), bare app.css no-cache, 0 unhashed refs.
  26. One gate change: the logged-in navigation step into a folder waited for `#crumbs strong`, which /code already has → the step
  27. passed with the page emit for /code/src still in flight; the next `ff.goto(gamma)` then failed with NS_BINDING_ABORTED
  28. (reproducible 2/2; 157/0 on 13ef4f9b). Now it waits for `#crumbs a` (only inside a folder). The cause is a HYBRIEL bug
  29. (new client `lost()`, #82): Firefox closes the page's WebSocket when a navigation away starts; `lost()` answers the
  30. in-flight `page` emit with null, and `showOne` then does `location.href = path` — a full load of the in-app page that
  31. cancels the navigation the user started (traced with WebDriver BiDi: navigationStarted gamma → warn "the socket closed before
  32. an emit was answered" 44 ms later → navigationStarted alpha/code/src). Reported to the architect for a hybriel ticket. Not deployed.
  33. - **Re-vendor to hybriel master 13ef4f9b** (mission 035, 2026-09-25): copy binary + plugins (no local patch). Consequence of #89
  34. (chunked request bodies): the push gate's "direct chunked push → 411" check failed (the push now works) → dropped the 411
  35. branch in `transport.hl`, the check now pushes a 4 MB commit straight to hl:http1 (`http.postBuffer=65536`, chunked) and
  36. expects it in the bare repo. Kept: temp files + `sh -c`, `base64 -d` (reasons in README "Behind nginx"). Gates (ports
  37. `GITORIA_GATE_PORT=8720 GITORIA_GATE_IDENT_PORT=8721 GITORIA_GATE_TICKETS_PORT=8722 GITORIA_GATE_PROXY=8722
  38. GITORIA_GATE_SSH_PORT=8723 GITORIA_GATE_FIREFOX=8724 GITORIA_GATE_CHROME=8725-8739`): browser.mjs **157/0** (incl. Firefox),
  39. push.mjs **46/0**, ssh.mjs **44/0**. Dev server serves `/__hl/app.css?v=<hash>` (immutable), bare → no-cache. Not deployed.
  40. - **Merge button for pull requests** (gitoria#17, 2026-09-25): on `/pulls` the repo owner (only) sees "Merge" on an open request whose source and target
  41. branches exist; the click (face `gitoriaMergePull` in `components/pulls.hl`, `git.hl mergePullNow`) merges the source into the target IN the bare repo:
  42. `merge-tree --write-tree` → `commit-tree` (merge commit, author = the owner's name) → `update-ref` with the old value (a push meanwhile = no merge).
  43. A conflict merges nothing and the page names the files. Never automatic (creator, gitoria#13). The request is found again on the server by its commit sha.
  44. Gate `node tests/browser.mjs`: **157 checks green** (buttons only for the owner on open requests, forged session, conflict → nothing merged, merge
  45. commit with two parents, request shows merged). Not deployed. Found: an `if` inside a `for` row is not re-evaluated when the list is reassigned
  46. (the button stayed) — the button is always rendered and hidden with a class (`.nomerge`). Not built: squash / rebase, closing a request without merging.
  47. - **Push and pull over SSH** (gitoria#7, 2026-09-25, second worker): `docker/sshd` (sshd container: `AuthorizedKeysCommand` → app, forced command `gitoria-shell`, host keys volume),
  48. `sshkeys.hl` + `components/sshkeys.hl` (SSH keys page: paste public key, `ssh-keygen -l` check, list, remove), `sshgate.hl` (`/__git/keys`, `/__git/access`, secret + no proxy),
  49. ssh commands in the "add code" box (`repohead.hl`), service `gitoria-sshd` in `docker-compose.yml`, `openssh-client` in the Dockerfile. Gate `node tests/ssh.mjs`: **44 checks green**
  50. with the real sshd container + real ssh/git (needs docker); `push.mjs` 46 and `browser.mjs` 149 still green. Not deployed. **Deploy needs** (README "Git over SSH"): `GITORIA_SSH_SECRET`
  51. in `.env`, firewall port (2222), DNS-only record for the ssh host (Cloudflare proxy carries no ssh), rebuild both images. SSH is hidden on the site until the secret is set.
  52. Not built (not decided): private repos, collaborators, protected branches, size limits.
  53. - **Push and pull over HTTPS + "Add code" box** (gitoria#7, 2026-09-25): `transport.hl` (smart-HTTP clone/fetch/push with `git upload-pack|receive-pack
  54. --stateless-rpc`, body via temp files, protocol v0/v1/v2, gzip requests), `tokens.hl` + `components/tokens.hl` (access tokens: shown once, sha256 stored,
  55. list/remove, on the main address), the box in `components/repohead.hl` (clone command, new/existing-project commands, open while the repo is empty),
  56. `git.hl isEmptyNow`, routes in `project.hl`, `styles.hl`. Read is public; only the owner's token may push. Gate `node tests/push.mjs`: **46 checks
  57. green** (real git: clone empty, push refused without / with wrong / another user's token, owner pushes a 4 MB pack, clone, gzip fetch with 300 local commits,
  58. pull, v0/v2, removed token stops at once, odd requests, layout 390/1280); `node tests/browser.mjs` still 149 green. Not deployed. **SSH: see the next entry.** Not built: collaborators / private repos / protected branches (not decided), SSH keys page.
  59. Deploy needs: nginx `client_max_body_size` (500m) and default request buffering on the `*.gitoria` vhost (README "Push and pull"); the Dockerfile has git, gzip, base64 (debian).
  60. Found: hl:http1 gives `body = null` for a chunked request (hence the proxy note); hybriel has no base64 decoder (the Basic header is decoded with `base64 -d`).
  61. - **Every repo view its own server-rendered page** (gitoria#16, mission 033, 2026-09-25): `components/index.hl` (`/`: list.hl on the
  62. main address, readme.hl on a repo address), `code.hl` / `branch.hl` / `commit.hl` (+ `codebrowser.hl`), `pulls.hl`, `releases.hl`,
  63. `tickets.hl`, `repohead.hl`, `loginfailed.hl` (was `htmlPage`). The repo comes from `host = null` (hybriel#74), git is read with
  64. hl:proc `run()` (hybriel#80, `git.hl` `*Now`): README, file list/file, branch, commit, pulls, releases and tickets are in the FIRST
  65. HTML, no "Loading". Gone: `components/home.hl`, `/host.js` (+ route), the hidden #hostslug/#loading inputs, `gitoriaOpen`,
  66. `gitoriaDocs/Code/Pulls/Releases` and their pushed answers; `?next=` moved into `login.js`. The rest of `/code/*path` etc. is the
  67. page member `path` (hybriel#81). Gate `node tests/browser.mjs`: **149 checks green**, incl. hybriel#43 (a code view in another tab
  68. keeps its elements through a login + logout) and NAVIGATION LOGGED IN in Chrome AND a real Firefox 155 (`tests/firefox.mjs`, BiDi):
  69. button login on a repo address, Readme → Code → Releases → Pulls → Tickets → Code → folder, an empty owned repo, and (Chrome) with
  70. the socket closed — no full page load anywhere. Not deployed.
  71. **Open — the creator's full page loads in Firefox 155 are NOT reproduced**: locally logged in (Chrome + Firefox) and on the LIVE site
  72. signed out (Firefox, h3 via Cloudflare, also with the socket closed) the marker survives. Not tested: live + logged in (it would
  73. write a user into live data). Found on the way: hl:web never reconnects a closed WebSocket (`client.hl` `close` → `socket = null`,
  74. no retry): after Cloudflare's ~100 s idle close every emit rides POST and live pushes (new repo, new ticket, login in another tab)
  75. no longer arrive — a hybriel ticket candidate.
  76. - **Hybriel re-vendored from master 2fbfe195** (mission 033; edf27bc1 → 6ae171af → 2fbfe195): binary sha256 `2a3c2b02…b565`
  77. (ReleaseFast from `git archive`), plugins core crypto data fetch fs http http1 mpackdb proc time **web** (every import `'hl:web'`).
  78. Older copies in `.scratch/pre-033/`, `pre-033b/`, `pre-033d/`. **No local patch left**: the cookie Domain is `sessionDomain`
  79. (#44) in project.hl. Dropped earlier: patches for #34/#39, HL_HOST listener (#24), `server.sessions.cookie` (#10), `realSession()`
  80. (#16), URL encoders (#14), `sessions.resolve` in the callback (#11). Master refuses `if (!x)` in a View → `noSource` for pulls.
  81. - **Identity selector** (gitoria#14, 2026-09-25): ident's `<ident-selector>` in the header beside "Log in with ident", like tickets
  82. (`components/main.hl` face `gitoriaLogin`, `login.js`, `users.hl selectorScript`, `styles.hl`, route `/login.js`). Gate `node tests/browser.mjs`:
  83. 122 checks green (choose identity → logged in without reload, logout resets it, hidden on a repo address, button unchanged). The gate now
  84. serves ident as `ident.gitoria.test` (same site as gitoria.test, else ident's Lax cookie never reaches the selector's fetch). Not deployed.
  85. - **Releases from commit messages** (gitoria#12, 2026-09-25): `/releases` of a repo address lists them (`git.hl` `parseRelease`, `releases`,
  86. `components/home.hl`, face `gitoriaReleases`, pushed `releasesReady`). Gate `node tests/browser.mjs`: 116 checks green (patch / `med` / `mj` /
  87. by-hand versions counted up, newest first, marker inside text / bad version / repeated version / other branch ignored, HTML as text,
  88. empty repo, forged face, 390/1280px). Not deployed. Not built: real git tags, downloadable archives, release notes page, API.
  89. - **Pull requests from commit messages** (gitoria#11, 2026-09-24): `/pulls` of a repo address lists them (`git.hl` `parsePull`, `pulls`,
  90. `components/home.hl`, face `gitoriaPulls`, pushed `pullsReady`). Gate `node tests/browser.mjs`: 108 checks green (marker parsing,
  91. target `|||PR|branch] `, merged vs open, missing target, one per source branch, HTML as text, empty repo, forged face, 390/1280px).
  92. Not deployed. Not built: merging in gitoria (open question to the creator), a PR page with diff/comments, PR numbers, API, a settings page
  93. for the default target (the repo's main branch is used).
  94. - **Connect a repo to a tickets project; #N links** (gitoria#18, 2026-09-26): `/settings` "Tickets: connect" (tickets' connect flow, key per repo),
  95. `/tickets` and open-ticket use the key + the user's ident id, `#N` links in commits / pull requests, "mentioned in commit" comments and
  96. "fixes #N" → review on push / merge (`tickets.hl`, `components/settings.hl`, `project.hl` /settings/connect(ed)).
  97. Gate `node tests/browser.mjs` (ports 8700-8708; `GITORIA_GATE_FIREFOX=8708 GITORIA_GATE_CHROME=8703-8707`): **172 passed, 0 failed** against
  98. a real tickets copy: the owner connects (button → tickets' project choice → back), opens a ticket (created by the person); a REAL git push
  99. over HTTP with "fix login, #1" → ticket 1 shows "Mentioned in commit …" (once); a merged `|||PR … fixes #1` pushed → ticket 1 in review
  100. (once); #N links on the commit page and /pulls; forget + connect again; a replaced tickets copy. `tests/ticketskit.mjs` takes `origins`
  101. (TICKETS_CONNECT_ORIGINS) and returns the session cookie; the token flow is gone from the gate. Fixed on the way: the Merge click built the
  102. ticket-link pieces in the browser (tickets.hl reads the environment, so the list stayed stale); the face now sends them. Decided: #99 (a
  103. ticket that does not exist) is still a link. Not deployed.
  104. - **Tickets inside a repo** (gitoria#10, 2026-09-24): `/tickets` of a repo address lists the tickets of its project in tickets.worldapi.org
  105. (`<slug>.<host>`), any named user opens one (gitoria's own API token; the text says who), the first ticket creates the project there.
  106. `tickets.hl`, `components/home.hl`, `git.hl parseView`, `tests/ticketskit.mjs`. Gate `node tests/browser.mjs`: 99 checks green (own tickets
  107. copy: 404 → first ticket creates the project, text as text, live to another viewer, ticket made in tickets shows on reload, forged
  108. session refused, tickets down message, 390/1280px). Not deployed: needs `GITORIA_TICKETS_TOKEN` in `.env` (README "Tickets").
  109. Not built: ticket text/comments inside gitoria, real author in tickets (tickets has no act-on-behalf).
  110. - **Browse code** (gitoria#9, 2026-09-24): `/code`, `/branch/<name>`, `/commit/<id>` (+ a path), `git.hl` `browse`, `components/home.hl`, `host.js`,
  111. `repos.hl` (`branch` field, `setMainBranch`), routes in `project.hl`. Gate `node tests/browser.mjs`: 79 checks green (main branch tree,
  112. folder/file/crumbs, old commit incl. short id, branch with a slash, binary file, unknown branch/commit/path messages, empty repo,
  113. "Make main" for the owner only, homepage follows the setting, 390/1280px). Not deployed. Not built: API / Markdown read view of code,
  114. commit diff, syntax highlighting. Found: hl:proc lines cannot carry non-UTF-8 bytes (breaks the socket) — files are checked with
  115. `git grep` first; a non-UTF-8 author name / branch name is not handled.
  116. - **Repo homepage from README and $docs** (gitoria#8, 2026-09-24): `git.hl`, `markdown.hl`, `components/markdown.hl`, `components/home.hl`;
  117. repo creation makes a bare git repo. Gate `node tests/browser.mjs`: 54 checks green (README as HTML incl. table/quote/rule/code,
  118. unsafe HTML and `javascript:` links stay text, `$docs` replaces README, empty repo message, 390/1280px). Not deployed:
  119. the Dockerfile now installs `git`; repos created before this have no bare repo yet (they show "no README.md yet").
  120. Not built: Markdown read view of the homepage in the API, images in Markdown, per-repo branch setting (#9).
  121. - **Repos with their own address** (gitoria#6, 2026-09-24): the app (`project.hl`, `components/`, `repos.hl`, `users.hl`),
  122. README "How a repo gets its address". Gate `node tests/browser.mjs`: 46 checks green (create, refusals, unique slug, live
  123. list, `<slug>.gitoria.test` pages, login from a repo address, shared cookie, restart, 390/1280px). Not deployed.
  124. Not built: git data (#7), homepage (#8), code browsing (#9), tickets (#10), pulls (#11), releases (#12), API creation, settings.
  125. ## Research done
  126. - [`docs/differ-from-custom-ide.md`](docs/differ-from-custom-ide.md) — gitoria#2: whether to reuse
  127. custom-ide's diff/editor (CodeJar-based) as a Hybriel component. Verdict: the diff **algorithm**
  128. (`lineDiff.js`, pure, no DOM) is directly reusable as a native Hybriel module; the CodeJar-based
  129. editing **surface** is real engineering (~3,400 LOC total, not "simple") and a native rewrite is blocked on
  130. open webex tickets (hybriel#31/#32/#33/#17/#41). Final plan (see Decision below): native Hybriel only,
  131. no JS-asset interim.
  132. - [`docs/git-backend.md`](docs/git-backend.md) — gitoria#5: how to use git from Hybriel. Verdict: the `git`
  133. binary, no `hl:git` library plugin (libgit2 has no server side). Reads via `hl:proc`; HTTPS clone/push
  134. served by Hybriel itself (`git upload-pack|receive-pack --stateless-rpc` through hl:proc stdin/binary, after
  135. hybriel#42); only SSH needs a small sshd container. Tested: byte-exact blobs, upload-pack over stdin, hl:http1
  136. byte-safe bodies. Full endpoint (#7) and SSH not run.
  137. ## Decision (gitoria#4, rejected 2026-09-24)
  138. Embedding custom-ide's JS bundle is **not** wanted. Editor and differ are built natively in Hybriel as
  139. shared components in layouts.worldapi.org (as ticket #2 said). Not started: the native port; the editing
  140. surface is blocked on hybriel#31/#32/#33/#17.
  141. Note: `DECISIONS.md` is generated by the librarian and still says "no decisions recorded yet"; it does not yet hold this decision.
  142. - **How to get code in, said where the creator looks** (gitoria#8 sent back 2026-09-25: "no description how i get a repo in at the /code page"): the "Add code to this repository" box (gitoria#7, `repohead.hl`, open while the repo is empty) was built but not yet deployed when the creator tested. The empty messages of the Readme and Code views now point to it (`components/readme.hl`, `git.hl`). Gate `node tests/browser.mjs`: 149 green. Needs the gitoria#7 deploy.
  143. ## 2026-09-26 mission 037 rolled back
  144. The re-vendor to hybriel master e6720b1f was ROLLED BACK (bin/ plugins/ tests/browser.mjs from .scratch/pre-037): the new client pulls Firefox users back during a navigation (hybriel#107). gitoria stays on 13ef4f9b until #107 is fixed; then re-vendor and use the stricter code-browser check (#crumbs a) from mission 037.
  145. **Done in mission 038** (see Built): master 317d4754 with the #107 fix, stricter check applied, all gates green.

Branches

Latest commits

  • fd981932State of 2026-09-27; bin/ no longer tracked (Hybriel commit is in README)mre
  • 4a2d7125initial commitmre