Repository navigation
feat(cli): add gf ontology module fetch with clone safety rules - #1758
Conversation
Fetch one exact ontology module from Hub discovery (#1746, part of #1732): gf ontology module fetch OWNER/REPO --ontology-id ID --version V \ --digest HEX --output FILE [--hub https://base] - Reuses the gf clone transport: HTTPS-only, credential-free, public-network resolution, bounded metadata and a 64 MiB module object bound, private no-follow staging. - Requests only refs, manifest, and the module package object; checks the object digest and length, verifies through resolve_discovered_ontology_module, and publishes the module document with a no-clobber hard link. - Staging is emptied under the lock and removed on every outcome; filesystems without hard links fail with a stable hub.destination_conflict. - Opens no project; documented next to gf clone. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
There was a problem hiding this comment.
Your trial has ended. Reactivate Greptile to resume code reviews.
|
Important Review skippedAuto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Repository: CurateLabs/graphforge/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Warning Billing warning: we have not been able to collect payment for this subscription for more than 72 hours. Please update the payment method or pay any pending invoices in Billing to avoid service interruption. Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
…o hub publish Main's squash of the lineage discovery work matches the merged lineage tip apart from the ontology module fetch (#1758) and the two binding re-pins. Clone's HTTPS plumbing, including the new parse_input_at, now lives in hub_http.rs and serves module_fetch.rs; clone and publish dispatch share one lib.rs entry to stay within the source-size bound. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Closes #1746. Part of #1732. Builds on #1747, #1754 and #1757.
What
gf clonetransport and safety code. That means HTTPS only, no credentials in URLs, public-network DNS and IP checks on every hop including redirects, and refs/manifest capped at 16 MiB. The module object is capped at 64 MiB (DiscoveryLimits.max_module_package_bytes), and staging is private and no-follow.resolve_discovered_ontology_module.hub.destination_conflict.hub.*codes. It is exempt from the four-surface multi-ontology contract, likegf clone, so there is no Python or Node work.{contract: "graphforge-hub-module-fetch/1", repository, module: {ontology_id, authored_version, canonical_digest}, package_digest, module_sha256, output}.packages/cli/README.mdnext togf clone(usage, safety rules, receipt, error codes, hard-link requirement), the discovery README, andportable-v2-integration.md.Acceptance evidence (#1746)
These tests use the scripted/recording transport over the checked-in openalex fixture bytes.
hub_clone::module_fetch::testsunless noted)module_fetch_requests_only_the_module_package_and_writes_the_verified_documentmodule_fetch_rejects_unsafe_object_locations_before_requesting_the_object,module_fetch_rejects_malformed_inputs_before_any_requestmodule_fetch_of_an_unadvertised_identity_is_a_missing_objectmodule_fetch_enforces_the_module_byte_bound(descriptor over 64 MiB, body longer than declared, short body)module_fetch_rejects_corrupt_bytes_and_publishes_nothingmodule_fetch_refuses_an_existing_output_without_touching_it,module_fetch_refuses_a_dangling_symlink_output,module_fetch_never_replaces_an_output_created_during_the_fetchstaging_release_empties_it_under_the_lock_and_never_clobbers_a_new_lock,a_filesystem_without_hard_links_is_a_stable_conflict_not_a_storage_errorontology_cli::tests::ontology_module_fetch_opens_no_project,ontology_module_fetch_parses_its_flagsgf clonepackages/cli/README.mdEvery failure test asserts that the output directory contains nothing beyond what existed before the fetch.
Verification
Review notes
JobFamilyonly hasClone, the command has no--telemetry-endpoint, and the issue doesn't ask for telemetry. The README says fetch emits none.crates/graphforge-cli/src/lib.rsis at 2999 of 3000 lines, so the next addition there needs a split.🤖 Generated with Claude Code
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.