1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
//! §12 substrate — `prime`'s bootstrap-on-miss, the retired `init`.
//!
//! Founding is not a separate verb: it is the local-miss branch of idempotent
//! `prime` (§12). The two-branch substrate (§2) is founded in TWO steps, on two
//! different schedules:
//! - [`found_landing`] lays the **landing** (`balls/config`, holding `config/`)
//! as the repo's first worktree EAGERLY — `prime` needs its `config/` to know
//! the plugin chain and the configured `tasks_branch` before it can do anything.
//! - [`materialize`] lays the **store** (`tasks_branch`, holding `tasks/`)
//! LAZILY, between `prime`'s pre and post phases (bl-0a23): it checks out the branch if
//! a ref already exists — a remote one the `prime/pre` tracker just cloned in
//! (§12) — and founds a fresh orphan ONLY when no such ref exists (the genuine
//! no-remote bootstrap). Founding eagerly would create a divergent orphan that
//! an established remote could not fast-forward onto, the unrelated-histories
//! bug bl-fa00 had to reset away; materializing after the tracker's clone-in
//! means that divergence is never CREATED.
//!
//! One repo, two branches, two real checkouts — no symlink indirection, no chain
//! to resolve (§1). Core knows nothing of remotes here (§0); it only ensures the
//! two checkouts exist and seeds the landing's `config/` from the app
//! default-config ([`crate::seed`]). Re-running `prime` skips both steps (the
//! landing is already a landing, the store checkout already sits on the
//! configured `tasks_branch` — the §12 predicate, not "a store dir exists",
//! bl-eb52), so the whole verb converges to a no-op — there is no `--reinit`.
use crategit;
use crateXdg;
use crateMessage;
use crateseed;
use crateVerb;
use crateLANDING_BRANCH;
use fs;
use io;
use Path;
/// Is the landing already founded? A founded landing has a COMMIT on the
/// `balls/config` branch (§12) — founding's ONE commit point, not the `config/`
/// folder [`found_landing`] creates on its way there (bl-ffbf).
///
/// The directory this once tested is created BEFORE that commit, so a crash in
/// between left debris a directory test called "founded" forever: every later op
/// then opened its change worktree on an unborn HEAD and failed, with no act
/// that could ever converge it. Keyed on the commit, the same debris is simply
/// "not founded yet" — and founding runs again straight over it (idempotent by
/// construction: `git init`, the seed and the `.gitignore` all overwrite what a
/// crashed founding left), so the general path IS the recovery and there is no
/// bootstrap special case to write.
/// Found the landing half of the substrate (§2 bootstrap-on-miss): the
/// `balls/config` branch at `landing`, its `config/` SEEDED from the app
/// default-config (the `balls.toml` + the `plugins.toml` hook schedule, with each
/// named plugin found beside `bl` in `exe_dir` bound and every absent-binary entry
/// pruned, §12). Returns the seed's rendered prune notes (a pruned name with a
/// `[source]` hint, bl-5b09) for `prime` to emit through the op log once it has
/// one — founding necessarily precedes the log's threshold read. The caller
/// guarantees [`is_landing`] is false, so this never clobbers an established
/// checkout.
///
/// Founding is a TRANSACTION whose one commit point is the seal at the end
/// (bl-ffbf): every step before it OVERWRITES rather than creates — `git init`
/// re-inits, the `.gitignore` and the seeded `config/` rewrite — so a re-run
/// straight over the debris of a crashed founding converges. That is the
/// ordinary path with the seed already on disk, not a bootstrap special case;
/// there is nothing to detect and nothing to repair. The STORE is NOT founded
/// here — that is
/// [`materialize`]'s lazy job, run after the tracker's `prime/pre` has
/// had its chance to clone an established remote branch in (bl-0a23).
///
/// The ONE piece of crash debris that transaction cannot overwrite is git's own
/// `.git/index.lock` (bl-3e89): `git init` re-inits and the seed rewrites, but the
/// `git add -A` below fails on a leftover lock with git's raw error, and prime's
/// debris report — which runs only AFTER founding — never gets to speak. So the
/// same report line refuses here, up front, before any half-founding work:
/// founding cannot delete the lock (it may be LIVE, and prime never deletes what
/// may hold work), so it names it and the removal in the debris-report voice.
/// Ensure the configured `tasks_branch` `name` IS the store checkout at `store`
/// — the lazy "a branch is a disk path" primitive `prime` drives between its
/// phases (bl-0a23). Two invariants, each established only when missing, so a
/// re-prime converges to a no-op:
/// - the branch ref `name` exists — a prior clone, or the remote branch the
/// `prime/pre` tracker just fetched into a local ref (clone-in, §12); absent
/// (no remote, or the remote had no such branch — the genuine bootstrap)
/// ⇒ FOUND a fresh orphan root with a tracked `tasks/.gitkeep`;
/// - the store checkout sits on `name` — absent ⇒ add the worktree; present on
/// a DIFFERENT branch (the §12 predicate is "the CONFIGURED branch is the
/// current checkout", not "a store dir exists" — a repointed `tasks_branch`
/// on a once-primed checkout, bl-eb52) ⇒ SWITCH it onto `name`.
///
/// Keyed on `name` (the configured `tasks_branch`) — and `prime/pre` may not
/// move that name: a moved dial aborts the op (bl-698d), so one materialize
/// per prime is the whole story.
/// The branch the `store` checkout currently has — the datum convergence is
/// keyed on (bl-eb52), read from the checkout itself.
/// Does `landing` carry a local branch ref named `name`? `show-ref --verify
/// --quiet` exits zero iff the ref resolves — the adopt-vs-found signal, read
/// from LOCAL refs only (core touches no remote, §0): an established branch is
/// either a prior clone or one the tracker's clone-in just created.
/// Found a fresh orphan store branch `name` (§2): no ref anywhere offered this
/// history, so this clone bootstraps it. Plumbing builds an orphan root (no
/// parent — the two single-job branches stay independent) carrying a tracked
/// `tasks/.gitkeep`, which keeps `tasks/` present on every checkout (empty dirs
/// are untracked) — one commit, no working-tree round-trip. The REF only:
/// putting it on disk is [`materialize`]'s second invariant.
/// Pin a deterministic commit identity on the new repo so the founding commits
/// (and every later seal here) work headlessly, independent of global git
/// config. Authorship of a ball rides the §5 trailers, not this identity. Set on
/// the landing repo; its linked store worktree inherits the same config.
/// The bl-b915 founding advisory: report-only scrutiny, zero mechanism added to
/// resolution — never a refusal, never a redirect. Call only on the miss branch
/// of `prime`, right before [`found_landing`]: the caller is ABOUT to found a
/// brand-new store at `invocation_path`, so if a founded store already sits at
/// some ANCESTOR directory (balls' own record — [`Xdg::nearest_founded_ancestor`]
/// stats the ancestor's own clone dir, git never consulted), that is almost
/// always the bl-0bd8 invisible-sibling-substrate footgun rather than a
/// deliberate nested/sibling store: warn on stderr, naming the `-C` escape
/// hatch (bl-c620), and let founding proceed regardless.
/// Found a COMPLETE bootstrapped substrate in one call — the landing plus an
/// orphan-founded default store — for callers and tests that want the whole shape
/// eager founding used to make, with no remote in play (bl-0a23). Founds as the
/// fixture actor `tester` (the test edges' `default_actor`).