trusty-memory 0.28.2

MCP server (stdio + Unix socket) for trusty-memory
Documentation
//! Per-subcommand handlers for the `trusty-memory` binary.
//!
//! Why: Keep CLI handlers out of `lib.rs` so the library surface stays focused
//! on MCP server code while the binary stays a thin clap-to-handler shim.
//! What: One submodule per subcommand. `serve --stdio` is handled by
//! `serve_stdio_bridge` (pure daemon-bridge, PR #1080); `serve`
//! (HTTP) is wired to `crate::run_http` / `crate::run_http_dynamic` in
//! `main.rs`; `migrate` rewrites Claude settings to point at trusty-memory;
//! `service` manages the macOS launchd LaunchAgent; `setup` orchestrates
//! first-time install (data dir + launchd + Claude settings patch). The
//! former `trusty-memory-mcp-bridge` binary and UDS transport were removed
//! in PR3 of the #914 epic.
//! Test: Each submodule carries its own unit tests.

// #8645: `audit secrets --count-only` — read-only re-screen of stored drawers.
pub mod audit_secrets;
// #4891: ADR-0028 Migration step 3 — the read-only backfill triage report.
pub mod backfill_report;
pub mod daemon_guard;
// #8759: `daemon_lock` is gone — unused since #6286 and racy; the socket's
// singleton bind lock (`trusty_common::uds::bind_singleton_hardened`) is the
// daemon lock.
pub mod doctor;
pub mod inbox_check;
pub mod kg_rebuild;
// #5401: fold pre-#4678 punctuated entity nodes onto their cleaned twins.
pub mod kg_twin_merge;
// #277: `import kuzu` — discover and idempotently import kuzu-memory stores.
pub mod kuzu_import;
// #277: deprecated `migrate kuzu-data`, now a forwarder to `kuzu_import`.
pub mod kuzu_migrate;
pub mod legacy_kg;
pub mod link;
pub(crate) mod maintenance_gate;
pub mod migrate;
pub mod migrations;
pub mod monitor;
pub mod note;
// #6652: `palace stats` / `palace compact` — kg.redb measurement and rewrite.
pub mod palace;
// #8732: `palace deletions` — read the maintenance deletion journal.
pub mod palace_deletions;
pub mod port;
pub mod prompt_context;
pub mod rooms;
pub mod send_message;
pub mod serve_stdio_bridge;
// #8351: the two MCP methods the bridge answers without the daemon.
pub mod serve_stdio_local;
pub mod service;
pub mod setup;
pub mod single_instance;
pub mod start;
pub mod stop;
// #8645: private-copy store reads shared by the read-only reports.
pub(crate) mod store_snapshot;
pub mod upgrade;

/// Process-wide lock for tests that mutate `TRUSTY_DATA_DIR_OVERRIDE` and
/// related env vars.
///
/// Why: Rust's default test runner executes tests in the same process with
/// thread parallelism, but `std::env::set_var` / `remove_var` mutate
/// process-wide state. Tests that pin the data dir override to a tempdir
/// can otherwise observe each other's writes mid-run, with the symptom that
/// the handler resolves the *real* user data dir and the test asserts the
/// wrong directory. Acquiring this lock at the top of each env-touching
/// test forces them to run one-at-a-time without pulling in `serial_test`.
/// What: a `tokio::sync::Mutex<()>` (chosen over `std::sync::Mutex` so the
/// guard can be held across `.await` points without tripping clippy's
/// `await_holding_lock` lint). Tests hold the guard for the duration of
/// the env-sensitive section.
/// Test: indirectly via the integration tests in `prompt_context` and
/// `inbox_check`.
#[cfg(test)]
pub(crate) fn env_test_lock() -> &'static tokio::sync::Mutex<()> {
    use std::sync::OnceLock;
    static LOCK: OnceLock<tokio::sync::Mutex<()>> = OnceLock::new();
    LOCK.get_or_init(|| tokio::sync::Mutex::new(()))
}