On this page
Package oplog implements the append-only JSONL operation log that records every mutating operation for undo support and audit trail purposes.
#internal/oplog
#internal/oplog
Package oplog implements the append-only JSONL operation log that records every mutating operation for undo support and audit trail purposes. Each entry appends one JSON line to .git/safegit/log under an exclusive flock, which is what makes a concurrent append atomic; entries have no size limit.
#Entry
type Entry structEntry represents a single operation log entry.
#Path
func Path(safegitDir string) stringPath returns the path to the log file. It is exported so callers can name the file in an error a human has to go and inspect.
#Append
func Append(safegitDir string, entry Entry) errorAppend writes a single entry to the log file atomically. The entry is serialized as a single JSON line of any length: the exclusive flock held across the whole write is the atomicity mechanism, so the 4096-byte POSIX O_APPEND guarantee is not what this file relies on and no line cap is needed. (Same reasoning as the scrub rewrite-map journal, which holds arbitrarily large commit maps under the same lock.)
#Read
func Read(safegitDir string) ([]Entry, int, error)Read returns all parseable entries from the log file, plus the number of non-empty lines it could not parse.
A nonzero skipped count means the log is incomplete: some operation was recorded but cannot be read back. Every caller whose correctness depends on the log being complete (undo arithmetic, bypass detection) must refuse rather than work from a partial history; callers that only summarize the log may report the count instead.
Lines are read with a bufio.Reader rather than a bufio.Scanner: entries have no size cap, and a Scanner would turn an over-long line into a read error for the whole file.
#LastRefUpdate
func LastRefUpdate(safegitDir, ref string) (*Entry, error)LastRefUpdate finds the most recent oplog entry for a given ref that records a new tip SHA. It accepts any op type and tries multiple extra keys ("sha", "to", "result") since different ops store the new tip under different names. Returns nil if no matching entry is found. It FAILS CLOSED on an incomplete log: bypass detection asks "is the tip the one safegit last wrote", and a log missing lines cannot answer that.
Two entry shapes are deliberately passed over rather than answered with:
- an entry carrying NO new tip. A guarded operation git refused records the ref it did not move and an empty new tip, so the position safegit really last left the branch at is still the one this returns. - an entry recording a ref DELETION (deleted: true), which stops the walk with no answer at all: safegit removed the ref on purpose, and everything older describes a ref that no longer exists.
#TipSHA
func TipSHA(extra map[string]interface{}) stringTipSHA extracts the new-tip SHA from an oplog entry's extra map. It checks "sha", "to", and "result" in order. Returns "" if none found.