Skip to content
internal/oplog
Edit
On this page

Package oplog implements the append-only JSONL operation log that records every mutating operation for undo support and audit trail purposes.

#internal/oplog

#internal/oplog

Package oplog implements the append-only JSONL operation log that records every mutating operation for undo support and audit trail purposes. Each entry appends one JSON line to .git/safegit/log under an exclusive flock, which is what makes a concurrent append atomic; entries have no size limit.

#Entry

Go go
type Entry struct

Entry represents a single operation log entry.

#Path

Go go
func Path(safegitDir string) string

Path returns the path to the log file. It is exported so callers can name the file in an error a human has to go and inspect.

#Append

Go go
func Append(safegitDir string, entry Entry) error

Append writes a single entry to the log file atomically. The entry is serialized as a single JSON line of any length: the exclusive flock held across the whole write is the atomicity mechanism, so the 4096-byte POSIX O_APPEND guarantee is not what this file relies on and no line cap is needed. (Same reasoning as the scrub rewrite-map journal, which holds arbitrarily large commit maps under the same lock.)

#Read

Go go
func Read(safegitDir string) ([]Entry, int, error)

Read returns all parseable entries from the log file, plus the number of non-empty lines it could not parse.

A nonzero skipped count means the log is incomplete: some operation was recorded but cannot be read back. Every caller whose correctness depends on the log being complete (undo arithmetic, bypass detection) must refuse rather than work from a partial history; callers that only summarize the log may report the count instead.

Lines are read with a bufio.Reader rather than a bufio.Scanner: entries have no size cap, and a Scanner would turn an over-long line into a read error for the whole file.

#LastRefUpdate

Go go
func LastRefUpdate(safegitDir, ref string) (*Entry, error)

LastRefUpdate finds the most recent oplog entry for a given ref that records a new tip SHA. It accepts any op type and tries multiple extra keys ("sha", "to", "result") since different ops store the new tip under different names. Returns nil if no matching entry is found. It FAILS CLOSED on an incomplete log: bypass detection asks "is the tip the one safegit last wrote", and a log missing lines cannot answer that.

Two entry shapes are deliberately passed over rather than answered with:

- an entry carrying NO new tip. A guarded operation git refused records the ref it did not move and an empty new tip, so the position safegit really last left the branch at is still the one this returns. - an entry recording a ref DELETION (deleted: true), which stops the walk with no answer at all: safegit removed the ref on purpose, and everything older describes a ref that no longer exists.

#TipSHA

Go go
func TipSHA(extra map[string]interface{}) string

TipSHA extracts the new-tip SHA from an oplog entry's extra map. It checks "sha", "to", and "result" in order. Returns "" if none found.

More tools from this site

  • claudestream Drive Claude Code from Python: run it as a subprocess and read its output as typed events, with async and sync sessions, sandbox policies, and tools you define in Python
  • claudewheel A TUI Claude Code Launcher that lets you have more than one profile, manage sessions lifecycle, pick the exact CC version, model to use (even older unlisted ones), pick which GitHub account to use, etc.
  • dirstat Fast, single-binary directory statistics CLI: every file under a tree grouped by format, with counts, sizes, and lines of code, as a colored terminal table or as JSON
  • fastware A batteries-included ASGI framework: msgspec JSON, a managed Granian server, dependency injection, SSE, WebSockets, auth, and a test client
  • go-toml-edit Zero-dep TOML editing library for Go with comment preservation
  • howmuchleft The fastest Claude Code statusline: context window, 5-hour, and weekly limit usage as three customizable gradient bars, rendering in about 6 ms
  • orxtra
  • pgdesign
  • predraw Declarative rendering pipeline: describe a scene in JSON and get SVG, PNG and WebP out, with light and dark style tokens, reusable components and text converted to path outlines
  • reposummary Turn a git repository's history into a Markdown journal: pick a time window or revision range and get a readable digest of what changed, optionally narrated by an LLM
  • rlsbl Release orchestration and project scaffolding CLI that bumps versions, validates a structured JSONL changelog, tags only the commit CI verified, and publishes to npm, PyPI, Go and more
  • saferm Command-line replacement for rm that archives every deletion with a mandatory reason and the context it ran in, so deleted files can be listed, inspected and restored
  • selfdoc Static Site Generator that builds a project's documentation site directly from its source code, so the docs can never drift from the code they describe, with SEO/AEO, first-class blog, search, and cross-project linking built in
  • strictcli
  • stricttest An always-on test-isolation floor: a pytest plugin and a Go env-hygiene module that make a test suite structurally unable to reach real credentials, the real HOME, the network, or the development repository.
  • wesktop A Python framework that turns an ASGI web app into a desktop application, serving it from a local Granian server and displaying it in a native OS window via pywebview
Search