1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
//! §12 `prime` — the tracker's two readiness handlers under the sync loop, one
//! per axis of "make this checkout ready" (bl-0a23).
//!
//! - **`prime/pre` settles the NAME + clones the store in** ([`prime`]). With no
//! remote it is STEALTH: touch no remote, persist nothing, say nothing (the
//! expected first-run shape, bl-2013) — the
//! opt-out is structural (no remote, nothing to leave on `origin`) and the
//! DECLARED opt-out is a config fact core re-derives every op (the landing
//! `task_remote` sentinel, bl-9df0), so there is no tracker-side state.
//! With a remote it (a) WARNS when the configured store sits elsewhere (a
//! default-named clone of a repo whose canonical store is a non-default branch —
//! diagnostic only; config crosses into a landing solely by `install`, §0/§12),
//! and (b) CLONES IN: when the remote already carries the store branch and this
//! clone has no local ref by that name yet, fetch it straight into a local
//! branch so core's `materialize` CHECKS IT OUT (an established history adopts
//! with no divergent orphan to reset — the bl-fa00 reset is gone). A local
//! branch that already exists is left for `sync` to fast-forward; an absent
//! remote branch is the bootstrap, left for core to found + `prime/post` to push.
//! - **`prime/post` settles the CONTENT** ([`prime_post`]). Established remote →
//! fetch-ff (bring current) then push (publish); a rejected push to an
//! ESTABLISHED store is split-brain and ERRORS (E5), never degrades. Absent
//! remote branch → the founding push CREATES it; a rejection there (no create
//! perm) falls back to stealth-local SILENTLY — nothing existed to land on, so
//! the founding-miss is harmless and once-per-clone (§12) — and persists
//! NOTHING: the miss is an outcome, re-derived per op, so re-running prime
//! re-attempts by construction (bl-9df0). Established-vs-absent
//! is read from the remote, never declared.
use git;
use Binding;
use ;
use Env;
use io;
use Path;
/// `prime/pre`: settle the store NAME and clone an established store in (§12).
/// Stealth (no remote) is SILENT and stops — persisting nothing; it is the
/// expected first-run shape and the declared opt-out already lives in config,
/// re-derivable via `bl conf` (bl-9df0/bl-2013). Otherwise warn on a
/// store-elsewhere mismatch and on an ephemeral remote (both diagnostic, never
/// fatal), then [`clone_in`] the
/// remote store branch if it is established and absent locally. Idempotent: a
/// re-prime finds the local branch present and clones nothing.
/// The §12 ephemeral-remote gap (W2, bl-c2de): prime is acting on `remote`, but
/// the DURABLE ladder (landing `task_remote` > per-clone `binding` remote > legacy
/// XDG remote > `origin`) resolves to something else
/// — so it arrived via a per-op `--remote` and plain commands will
/// not reproduce it (the bl-d234 silent-stealth failure). A landing stealth
/// sentinel is the strongest durable answer: plain commands run DECLARED
/// stealth, named as such (bl-9df0). The binding tier mirrors core's
/// [`crate::config::remote_ladder`] (bl-d081) so a per-clone remote read by core
/// is not misreported here as ephemeral. Returns what durable
/// resolution yields, rendered for the warning; `None` = no gap (the remote in
/// use IS the durable one, however it was spelled).
/// `prime/post`: settle the store CONTENT (§12). An ESTABLISHED remote branch is
/// brought current ([`super::remote_ops::sync`] — fetch + ff-only) then published
/// ([`super::remote_ops::push`] — a rejection is E5, the op aborts). An ABSENT
/// branch is FOUNDED by this push; a rejection there is the once-per-clone
/// founding-miss (no create perm) and degrades to stealth-local SILENTLY, the
/// fallback that is founding's ALONE (nothing existed to land on). Stealth (no
/// remote) no-ops, like every handler.
/// Clone an established remote store branch into a LOCAL ref so core's
/// `materialize` checks it out — adopting an established history with no divergent
/// orphan to reconcile (bl-0a23, supersedes the bl-fa00 reset). Three cases, all
/// no-ops or one fetch: a local branch already here (a prior clone) is left for
/// `sync` to ff; an absent remote branch is the bootstrap, left for core to found;
/// only an established-remote-and-locally-absent branch is fetched, straight into
/// `refs/heads/<branch>` (the branch is checked out nowhere yet, so the refspec
/// just creates the ref). "Established" means an established STORE (bl-868d): a
/// remote tip with no `tasks/` — a hub still carrying the PRE-greenfield legacy
/// store on the colliding branch name (§16) — is QUARANTINED, not adopted
/// ([`not_yet_cut_over`] warns), so core founds a fresh greenfield orphan and the
/// runbook's "prime founds, import fills, cutover rewrites" holds on a fresh
/// clone. Runs against the LANDING — on a first prime the store is
/// not materialized yet, and landing + store share one object store and refs (§2).
/// Does `repo` carry a local branch ref named `branch`? `show-ref --verify
/// --quiet` exits zero iff the ref resolves — the "already cloned in" signal.
/// The store this repo really uses, if it is NOT the one we are bound to — the
/// silent-empty diagnostic (§12). Returns `Some(branch)` only when our
/// `tasks_branch` is still the SEEDED DEFAULT (an un-`install`ed clone): it fetches
/// the standard `balls/config` landing branch from `remote` into `repo` (reading is
/// free, no authority) and reads its `tasks_branch`; a value DIFFERENT from ours is
/// the gap to warn about. Any failure to read it — remote unreachable, no
/// `balls/config` branch, malformed config — is UNCATCHABLE, silent by design:
/// `None`. A non-default name is a deliberate fork, never the gap.