Skip to main content

devflow_core/
git.rs

1//! Git-flow operations implemented with plain `git` commands.
2
3use crate::config::GitFlowConfig;
4use std::path::{Path, PathBuf};
5use std::process::Command;
6use tracing::{debug, info, warn};
7
8/// Errors produced by git-flow operations.
9#[derive(Debug, thiserror::Error)]
10pub enum GitError {
11    /// Spawning git failed.
12    #[error("failed to execute git: {0}")]
13    Io(#[from] std::io::Error),
14    /// Git returned a non-success status.
15    #[error("git command failed: {0}")]
16    Command(String),
17}
18
19/// Repository helper bound to a project root.
20#[derive(Debug, Clone)]
21pub struct GitFlow {
22    root: PathBuf,
23    config: GitFlowConfig,
24}
25
26/// Summary of a feature branch for the `devflow list` command.
27#[derive(Debug, Clone)]
28pub struct BranchInfo {
29    /// Branch name (e.g. "feature/phase-05").
30    pub name: String,
31    /// Number of commits this branch has that develop doesn't.
32    pub ahead: usize,
33    /// Number of commits develop has that this branch doesn't.
34    pub behind: usize,
35    /// ISO-8601 date of the last commit on this branch.
36    pub last_commit: String,
37}
38
39impl GitFlow {
40    /// Create a git-flow helper for a project root, using the hardcoded
41    /// git-flow constants (`main`, `develop`, `feature/`).
42    pub fn new(root: impl AsRef<Path>) -> Self {
43        Self {
44            root: root.as_ref().to_path_buf(),
45            config: GitFlowConfig::default(),
46        }
47    }
48
49    /// Create a feature branch from the develop branch.
50    ///
51    /// Returns an error if the branch already exists (use
52    /// [`feature_start_force`] to overwrite).
53    pub fn feature_start(&self, phase: u32) -> Result<String, GitError> {
54        let branch = format!("{}phase-{:02}", self.config.feature_prefix, phase);
55        info!("creating feature branch: {branch}");
56        self.git(["checkout", &self.config.develop])?;
57        self.git(["checkout", "-b", &branch])?;
58        Ok(branch)
59    }
60
61    /// Create or reset a feature branch, overwriting it if it already exists.
62    pub fn feature_start_force(&self, phase: u32) -> Result<String, GitError> {
63        let branch = format!("{}phase-{:02}", self.config.feature_prefix, phase);
64        warn!("force-creating feature branch: {branch}");
65        self.git(["checkout", &self.config.develop])?;
66        self.git(["checkout", "-B", &branch])?;
67        Ok(branch)
68    }
69
70    /// Merge a feature branch into develop and delete it.
71    pub fn feature_finish(&self, phase: u32) -> Result<String, GitError> {
72        let branch = self.merge_feature_into_develop(phase)?;
73        self.git(["branch", "-d", &branch])?;
74        Ok(branch)
75    }
76
77    /// Merge a feature branch into develop without deleting it.
78    ///
79    /// Default DevFlow runs keep the feature branch checked out in a linked
80    /// worktree, so deletion belongs to the later best-effort cleanup hook.
81    pub fn merge_feature_into_develop(&self, phase: u32) -> Result<String, GitError> {
82        let branch = format!("{}phase-{:02}", self.config.feature_prefix, phase);
83        info!("merging feature branch: {branch}");
84        self.git(["checkout", &self.config.develop])?;
85        self.git(["merge", "--no-ff", &branch])?;
86        Ok(branch)
87    }
88
89    /// Whether a phase feature branch has nothing left to merge into develop.
90    ///
91    /// An absent branch is not proof of a merge. Callers must fail closed
92    /// rather than treating a deleted or never-created branch as shipped.
93    pub fn is_merged_into_develop(&self, phase: u32) -> bool {
94        let branch = format!("{}phase-{:02}", self.config.feature_prefix, phase);
95        if !self.branch_exists(&branch) {
96            return false;
97        }
98
99        Command::new("git")
100            .args(["merge-base", "--is-ancestor", &branch, &self.config.develop])
101            .current_dir(&self.root)
102            .output()
103            .map(|output| output.status.success())
104            .unwrap_or(false)
105    }
106
107    /// Create or reset a release branch from the current `HEAD`.
108    ///
109    /// The release branch is cut from wherever the caller currently is — the
110    /// branch being shipped — not from `develop`. `devflow ship` writes the
111    /// version bump into the working tree first, so branching from `HEAD`
112    /// keeps any commits unique to the shipped branch in the release.
113    pub fn release_start(&self, version: &str) -> Result<String, GitError> {
114        let branch = format!("release/{version}");
115        info!("creating release branch: {branch}");
116        self.git(["checkout", "-B", &branch])?;
117        Ok(branch)
118    }
119
120    /// Merge a release branch into main and develop, tag it, and delete it.
121    pub fn release_finish(&self, version: &str) -> Result<String, GitError> {
122        let branch = format!("release/{version}");
123        info!("finishing release branch: {branch}");
124        self.git(["checkout", &self.config.main])?;
125        self.git(["merge", "--no-ff", &branch])?;
126        // `-c tag.gpgSign=false` scopes the override to this invocation only
127        // (never the user's global/repo config) — without it, a global
128        // `tag.gpgsign=true` forces this lightweight tag into an
129        // annotated+signed one requiring a message, which blocks on
130        // `$EDITOR` in what must be a headless, unattended flow (Phase 13
131        // dogfood finding).
132        self.git(["-c", "tag.gpgSign=false", "tag", &format!("v{version}")])?;
133        self.git(["checkout", &self.config.develop])?;
134        self.git(["merge", "--no-ff", &branch])?;
135        self.git(["branch", "-d", &branch])?;
136        Ok(branch)
137    }
138
139    /// Create an annotated-free lightweight tag at the current `HEAD`.
140    ///
141    /// Passes `-c tag.gpgSign=false` scoped to this invocation only — a
142    /// global `tag.gpgsign=true` (common for developers who sign their own
143    /// tags) otherwise forces this lightweight tag into an annotated+signed
144    /// one requiring a message, which blocks on `$EDITOR` in what must be a
145    /// headless, unattended flow (Phase 13 dogfood finding: VersionBump hung
146    /// on a live `devflow start --mode auto` run).
147    pub fn tag(&self, tag: &str) -> Result<(), GitError> {
148        info!("tagging {tag}");
149        self.git(["-c", "tag.gpgSign=false", "tag", tag])
150    }
151
152    /// Delete a single local branch.
153    ///
154    /// With `force`, uses `git branch -D` (deletes even if unmerged); otherwise
155    /// `git branch -d` (refuses to delete unmerged work). Protected branches
156    /// (`main`, `develop`) are never deleted.
157    pub fn delete_branch(&self, branch: &str, force: bool) -> Result<(), GitError> {
158        if branch == self.config.main || branch == self.config.develop {
159            return Err(GitError::Command(format!(
160                "refusing to delete protected branch `{branch}`"
161            )));
162        }
163        let flag = if force { "-D" } else { "-d" };
164        if force {
165            warn!("force-deleting branch: {branch}");
166        } else {
167            info!("deleting branch: {branch}");
168        }
169        self.git(["branch", flag, branch])
170    }
171
172    /// Whether a local branch exists.
173    pub fn branch_exists(&self, branch: &str) -> bool {
174        Command::new("git")
175            .args([
176                "rev-parse",
177                "--verify",
178                "--quiet",
179                &format!("refs/heads/{branch}"),
180            ])
181            .current_dir(&self.root)
182            .output()
183            .map(|o| o.status.success())
184            .unwrap_or(false)
185    }
186
187    /// The commit SHA at the tip of `branch`.
188    pub fn branch_tip(&self, branch: &str) -> Result<String, GitError> {
189        Ok(self.git_output(["rev-parse", branch])?.trim().to_string())
190    }
191
192    /// Create `branch` at `start_point` if it does not already exist, without
193    /// checking it out (leaves the current checkout untouched).
194    pub fn ensure_branch(&self, branch: &str, start_point: &str) -> Result<(), GitError> {
195        if self.branch_exists(branch) {
196            return Ok(());
197        }
198        self.git(["branch", branch, start_point])
199    }
200
201    /// Fast-forward `target`'s ref to `source` (must be a descendant).
202    ///
203    /// `target` must not be checked out in any worktree. Errors if the move
204    /// would not be a fast-forward.
205    pub fn fast_forward_branch(&self, target: &str, source: &str) -> Result<(), GitError> {
206        let is_ancestor = Command::new("git")
207            .args(["merge-base", "--is-ancestor", target, source])
208            .current_dir(&self.root)
209            .output()?
210            .status
211            .success();
212        if !is_ancestor {
213            return Err(GitError::Command(format!(
214                "{target} is not an ancestor of {source}; refusing non-fast-forward update"
215            )));
216        }
217        self.git(["branch", "-f", target, source])
218    }
219
220    /// Rebase the branch checked out at `dir` onto `onto`.
221    ///
222    /// Runs `git rebase` inside the given worktree directory. On conflict the
223    /// rebase is aborted and an error is returned so the caller can surface it.
224    pub fn rebase_in(&self, dir: &Path, onto: &str) -> Result<(), GitError> {
225        debug!("rebasing worktree at {} onto {onto}", dir.display());
226        match git_in(dir, &["rebase", onto]) {
227            Ok(()) => Ok(()),
228            Err(err) => {
229                // Leave the worktree clean for the user to retry.
230                warn!("rebase conflict in {}; aborting", dir.display());
231                let _ = git_in(dir, &["rebase", "--abort"]);
232                Err(err)
233            }
234        }
235    }
236
237    /// Check out an existing branch in the main worktree.
238    pub fn checkout(&self, branch: &str) -> Result<(), GitError> {
239        debug!("checking out branch: {branch}");
240        self.git(["checkout", branch])
241    }
242
243    /// Delete `branch` on `origin` (best-effort; errors if no remote/branch).
244    pub fn delete_remote_branch(&self, branch: &str) -> Result<(), GitError> {
245        info!("deleting remote branch: {branch}");
246        self.git(["push", "origin", "--delete", branch])
247    }
248
249    /// Whether the repository has at least one configured remote.
250    pub fn has_remote(&self) -> bool {
251        self.git_output(["remote"])
252            .map(|s| !s.trim().is_empty())
253            .unwrap_or(false)
254    }
255
256    /// Push `branch` to `origin`, setting upstream.
257    pub fn push(&self, branch: &str) -> Result<(), GitError> {
258        info!("pushing branch: {branch}");
259        self.git(["push", "-u", "origin", branch])
260    }
261
262    /// Delete local branches already merged into `develop`.
263    ///
264    /// WR-04 (13-REVIEW.md): passes `develop` explicitly rather than relying
265    /// on `git branch --merged`'s default of "whatever HEAD currently is" —
266    /// if the main checkout is ever left on a branch other than `develop`
267    /// when this runs, an implicit baseline would silently prune branches
268    /// merged into that other branch instead.
269    ///
270    /// Deletion uses `-D`, not `-d`: `-d` verifies merged-into-HEAD, which
271    /// contradicts the `--merged develop` listing above in exactly the
272    /// checkout-not-on-develop scenario WR-04 targets (every genuinely
273    /// merged branch would be refused as "not fully merged"). The listing IS
274    /// the merge safety check. A branch git still refuses to delete (e.g.
275    /// checked out in a worktree) is logged and skipped so one failure
276    /// doesn't abort the rest of the sweep.
277    pub fn cleanup_merged(&self) -> Result<Vec<String>, GitError> {
278        let output = self.git_output(["branch", "--merged", &self.config.develop])?;
279        let protected = [self.config.main.as_str(), self.config.develop.as_str()];
280        let mut deleted = Vec::new();
281        for line in output.lines() {
282            // git's porcelain marker is an exact two-char prefix ("* " for
283            // the current branch, "+ " for a worktree checkout, "  "
284            // otherwise) — strip it positionally rather than trimming
285            // marker CHARACTERS, which would mangle a branch legitimately
286            // named e.g. "+foo" (WR-03, revised).
287            let branch = line
288                .strip_prefix("* ")
289                .or_else(|| line.strip_prefix("+ "))
290                .unwrap_or(line)
291                .trim();
292            // Skip blanks, protected trunks, and the detached-HEAD line
293            // ("(HEAD detached at ...)"), which is not a branch name.
294            if branch.is_empty() || branch.starts_with('(') || protected.contains(&branch) {
295                continue;
296            }
297            info!("cleaning up merged branch: {branch}");
298            match self.git(["branch", "-D", branch]) {
299                Ok(()) => deleted.push(branch.to_string()),
300                Err(err) => warn!("could not delete merged branch {branch}: {err}"),
301            }
302        }
303        Ok(deleted)
304    }
305
306    /// Stage all changes and commit with the given message.
307    /// Returns Ok(()) whether or not there were changes to commit.
308    pub fn commit_all(&self, message: &str) -> Result<(), GitError> {
309        debug!("committing all changes: {message}");
310        self.git(["add", "."])?;
311        // --allow-empty so we don't fail when there are no changes
312        match self.git_raw(&["commit", "--allow-empty", "-m", message]) {
313            Ok(()) => Ok(()),
314            // If the commit produced no changes and we used --allow-empty,
315            // this should still succeed. But just in case, ignore "nothing to commit".
316            Err(GitError::Command(ref msg)) if msg.contains("nothing to commit") => Ok(()),
317            Err(e) => Err(e),
318        }
319    }
320
321    /// Return divergence from develop: (ahead, behind) commit counts.
322    ///
323    /// If currently on the develop branch, returns (0, 0).
324    /// `ahead` = commits on current branch not yet on develop.
325    /// `behind` = commits on develop not yet on current branch.
326    pub fn divergence_from_develop(&self) -> Result<(usize, usize), GitError> {
327        let current = self
328            .git_output(["rev-parse", "--abbrev-ref", "HEAD"])?
329            .trim()
330            .to_string();
331        if current == self.config.develop {
332            return Ok((0, 0));
333        }
334        let ahead = self
335            .rev_count(&format!("{}..{current}", self.config.develop))
336            .unwrap_or(0);
337        let behind = self
338            .rev_count(&format!("{current}..{}", self.config.develop))
339            .unwrap_or(0);
340        Ok((ahead, behind))
341    }
342
343    /// List all feature branches with divergence from develop.
344    ///
345    /// Returns branches matching `feature/phase-*` with ahead/behind counts
346    /// and last commit dates. Protected branches (main, develop) are excluded.
347    pub fn list_feature_branches(&self) -> Result<Vec<BranchInfo>, GitError> {
348        let prefix = &self.config.feature_prefix;
349        let branches = self.git_output(["branch", "--format=%(refname:short)"])?;
350        let mut result = Vec::new();
351        for name in branches.lines().map(|l| l.trim()) {
352            if name.is_empty()
353                || name == self.config.main
354                || name == self.config.develop
355                || !name.starts_with(prefix)
356            {
357                continue;
358            }
359            let ahead = self
360                .rev_count(&format!("{dev}..{name}", dev = self.config.develop))
361                .unwrap_or(0);
362            let behind = self
363                .rev_count(&format!("{name}..{dev}", dev = self.config.develop))
364                .unwrap_or(0);
365            let last_commit = self
366                .git_output(["log", "-1", "--format=%aI", name])
367                .map(|s| s.trim().to_string())
368                .unwrap_or_default();
369            result.push(BranchInfo {
370                name: name.to_string(),
371                ahead,
372                behind,
373                last_commit,
374            });
375        }
376        // Sort by phase number so phase-01 comes before phase-10.
377        result.sort_by(|a, b| a.name.cmp(&b.name));
378        Ok(result)
379    }
380
381    /// Count revisions in the given range. Returns None if the command fails.
382    fn rev_count(&self, range: &str) -> Option<usize> {
383        self.git_output(["rev-list", "--count", range])
384            .ok()
385            .and_then(|s| s.trim().parse().ok())
386    }
387
388    fn git_raw(&self, args: &[&str]) -> Result<(), GitError> {
389        debug!("git {}", args.join(" "));
390        let output = Command::new("git")
391            .args(args)
392            .current_dir(&self.root)
393            .output()?;
394        if output.status.success() {
395            Ok(())
396        } else {
397            Err(GitError::Command(stderr_or_status(&output)))
398        }
399    }
400
401    fn git<const N: usize>(&self, args: [&str; N]) -> Result<(), GitError> {
402        debug!("git {}", args.iter().copied().collect::<Vec<_>>().join(" "));
403        let output = Command::new("git")
404            .args(args)
405            .current_dir(&self.root)
406            .output()?;
407        if output.status.success() {
408            Ok(())
409        } else {
410            Err(GitError::Command(stderr_or_status(&output)))
411        }
412    }
413
414    fn git_output<const N: usize>(&self, args: [&str; N]) -> Result<String, GitError> {
415        let output = Command::new("git")
416            .args(args)
417            .current_dir(&self.root)
418            .output()?;
419        if output.status.success() {
420            Ok(String::from_utf8_lossy(&output.stdout).to_string())
421        } else {
422            Err(GitError::Command(stderr_or_status(&output)))
423        }
424    }
425}
426
427/// Run a git command in an arbitrary directory (e.g. a worktree).
428fn git_in(dir: &Path, args: &[&str]) -> Result<(), GitError> {
429    debug!("git (in {}) {}", dir.display(), args.join(" "));
430    let output = Command::new("git").args(args).current_dir(dir).output()?;
431    if output.status.success() {
432        Ok(())
433    } else {
434        Err(GitError::Command(stderr_or_status(&output)))
435    }
436}
437
438fn stderr_or_status(output: &std::process::Output) -> String {
439    let stderr = String::from_utf8_lossy(&output.stderr).trim().to_string();
440    if stderr.is_empty() {
441        format!("exited with {}", output.status)
442    } else {
443        stderr
444    }
445}
446
447#[cfg(test)]
448mod tests {
449    use super::*;
450    use std::process::Command;
451    use tempfile::TempDir;
452
453    /// Run a git command in `root`, asserting success.
454    fn git(root: &Path, args: &[&str]) {
455        let output = Command::new("git")
456            .args(args)
457            .current_dir(root)
458            .output()
459            .expect("spawn git");
460        assert!(
461            output.status.success(),
462            "git {args:?} failed: {}",
463            String::from_utf8_lossy(&output.stderr)
464        );
465    }
466
467    fn current_branch(root: &Path) -> String {
468        let output = Command::new("git")
469            .args(["rev-parse", "--abbrev-ref", "HEAD"])
470            .current_dir(root)
471            .output()
472            .expect("rev-parse");
473        String::from_utf8_lossy(&output.stdout).trim().to_string()
474    }
475
476    fn commit_file(root: &Path, name: &str) {
477        std::fs::write(root.join(name), name).unwrap();
478        git(root, &["add", "."]);
479        git(root, &["commit", "-q", "-m", &format!("add {name}")]);
480    }
481
482    /// Initialize a repo with `main` and `develop` branches and one commit.
483    fn init_repo() -> TempDir {
484        let dir = tempfile::tempdir().unwrap();
485        let root = dir.path();
486        git(root, &["init", "-q"]);
487        git(root, &["config", "user.email", "test@example.com"]);
488        git(root, &["config", "user.name", "Test"]);
489        git(root, &["config", "commit.gpgsign", "false"]);
490        git(root, &["config", "tag.gpgsign", "false"]);
491        // Disable any globally-configured hooks (e.g. gitleaks) for isolation.
492        git(root, &["config", "core.hooksPath", "/dev/null"]);
493        commit_file(root, "README.md");
494        git(root, &["branch", "-M", "main"]);
495        git(root, &["checkout", "-q", "-b", "develop"]);
496        dir
497    }
498
499    fn flow(root: &Path) -> GitFlow {
500        GitFlow::new(root)
501    }
502
503    #[test]
504    fn feature_start_branches_from_develop() {
505        let repo = init_repo();
506        let root = repo.path();
507        let branch = flow(root).feature_start(3).expect("feature_start");
508        assert_eq!(branch, "feature/phase-03");
509        assert_eq!(current_branch(root), "feature/phase-03");
510    }
511
512    #[test]
513    fn list_feature_branches_reports_ahead_and_behind_semantics() {
514        let repo = init_repo();
515        let root = repo.path();
516        let gf = flow(root);
517
518        gf.feature_start(12).expect("feature_start");
519        commit_file(root, "feature-one.txt");
520        commit_file(root, "feature-two.txt");
521        git(root, &["checkout", "-q", "develop"]);
522        commit_file(root, "develop-only.txt");
523
524        let branches = gf.list_feature_branches().unwrap();
525        let branch = branches
526            .iter()
527            .find(|branch| branch.name == "feature/phase-12")
528            .unwrap();
529
530        assert_eq!(branch.ahead, 2);
531        assert_eq!(branch.behind, 1);
532    }
533
534    #[test]
535    fn feature_finish_merges_into_develop_and_deletes() {
536        let repo = init_repo();
537        let root = repo.path();
538        let gf = flow(root);
539
540        gf.feature_start(1).expect("start");
541        commit_file(root, "feature.txt");
542
543        let branch = gf.feature_finish(1).expect("finish");
544        assert_eq!(branch, "feature/phase-01");
545        assert_eq!(current_branch(root), "develop");
546
547        // Branch is deleted and its work is now on develop.
548        let branches = Command::new("git")
549            .args(["branch"])
550            .current_dir(root)
551            .output()
552            .unwrap();
553        let listing = String::from_utf8_lossy(&branches.stdout);
554        assert!(!listing.contains("feature/phase-01"));
555        assert!(root.join("feature.txt").exists());
556    }
557
558    #[test]
559    fn release_start_and_finish_tags_main_and_merges_both() {
560        let repo = init_repo();
561        let root = repo.path();
562        let gf = flow(root);
563
564        // Add work on develop so the release has content.
565        commit_file(root, "work.txt");
566        let branch = gf.release_start("1.2.0").expect("release_start");
567        assert_eq!(branch, "release/1.2.0");
568
569        gf.release_finish("1.2.0").expect("release_finish");
570        assert_eq!(current_branch(root), "develop");
571
572        // Tag exists.
573        let tags = Command::new("git")
574            .args(["tag"])
575            .current_dir(root)
576            .output()
577            .unwrap();
578        assert!(String::from_utf8_lossy(&tags.stdout).contains("v1.2.0"));
579
580        // Release branch deleted.
581        let branches = Command::new("git")
582            .args(["branch"])
583            .current_dir(root)
584            .output()
585            .unwrap();
586        assert!(!String::from_utf8_lossy(&branches.stdout).contains("release/1.2.0"));
587    }
588
589    /// A global/repo `tag.gpgsign=true` must not turn `tag()`'s lightweight
590    /// tag into an annotated+signed one — that would require a tag message
591    /// and block on `$EDITOR`, silently hanging a headless, unattended run
592    /// (Phase 13 dogfood finding: VersionBump hung on a live
593    /// `devflow start --mode auto` run because the operator's global
594    /// gitconfig sets `tag.gpgsign=true`).
595    #[test]
596    fn tag_stays_lightweight_when_gpgsign_is_forced_on() {
597        let repo = init_repo();
598        let root = repo.path();
599        // Simulate an operator whose global config signs tags by default —
600        // override the test harness's own `tag.gpgsign false` to prove
601        // `tag()`'s per-invocation `-c` override wins regardless.
602        git(root, &["config", "tag.gpgsign", "true"]);
603
604        flow(root)
605            .tag("v9.9.9")
606            .expect("tag must not block on $EDITOR");
607
608        let tags = Command::new("git")
609            .args(["tag", "-l"])
610            .current_dir(root)
611            .output()
612            .unwrap();
613        assert!(String::from_utf8_lossy(&tags.stdout).contains("v9.9.9"));
614
615        // Confirm it's a lightweight tag (points directly at the commit),
616        // not an annotated tag object (which `cat-file -t` would report as
617        // "tag" rather than "commit").
618        let obj_type = Command::new("git")
619            .args(["cat-file", "-t", "v9.9.9"])
620            .current_dir(root)
621            .output()
622            .unwrap();
623        assert_eq!(
624            String::from_utf8_lossy(&obj_type.stdout).trim(),
625            "commit",
626            "tag() must stay lightweight even when tag.gpgsign=true"
627        );
628    }
629
630    #[test]
631    fn release_start_branches_from_current_head_not_develop() {
632        let repo = init_repo();
633        let root = repo.path();
634        let gf = flow(root);
635
636        // Ship from a feature branch carrying a commit that is NOT on develop.
637        gf.feature_start(5).expect("feature_start");
638        commit_file(root, "feature-only.txt");
639        let feature_tip = gf.branch_tip("feature/phase-05").expect("feature tip");
640
641        let branch = gf.release_start("2.0.0").expect("release_start");
642        assert_eq!(branch, "release/2.0.0");
643        assert_eq!(current_branch(root), "release/2.0.0");
644
645        // The release branch tip must descend from the feature commit — i.e.
646        // the feature-only work is present, not dropped to develop's HEAD.
647        let release_tip = gf.branch_tip("release/2.0.0").expect("release tip");
648        let is_ancestor = Command::new("git")
649            .args(["merge-base", "--is-ancestor", &feature_tip, &release_tip])
650            .current_dir(root)
651            .output()
652            .unwrap()
653            .status
654            .success();
655        assert!(
656            is_ancestor,
657            "release branch must descend from the shipped feature commit"
658        );
659        assert!(root.join("feature-only.txt").exists());
660    }
661
662    #[test]
663    fn cleanup_merged_removes_merged_but_keeps_protected() {
664        let repo = init_repo();
665        let root = repo.path();
666        let gf = flow(root);
667
668        // Create and merge a feature branch into develop.
669        gf.feature_start(2).expect("start");
670        commit_file(root, "f.txt");
671        gf.feature_finish(2).expect("finish");
672
673        // Create an already-merged stray branch off develop.
674        git(root, &["branch", "stale-merged"]);
675
676        let deleted = gf.cleanup_merged().expect("cleanup");
677        assert!(deleted.contains(&"stale-merged".to_string()));
678        // Protected branches survive.
679        assert!(!deleted.contains(&"develop".to_string()));
680        assert!(!deleted.contains(&"main".to_string()));
681    }
682
683    /// WR-04 (13-REVIEW.md): `cleanup_merged` must compute "merged" relative
684    /// to `develop` explicitly, not whatever the main checkout's current
685    /// HEAD happens to be. If the main checkout is left on a divergent
686    /// branch, an implicit-HEAD baseline would wrongly identify (and
687    /// delete) a branch that's merged into that other branch but was never
688    /// actually merged into `develop`.
689    #[test]
690    fn cleanup_merged_is_relative_to_develop_not_current_head() {
691        let repo = init_repo();
692        let root = repo.path();
693        let gf = flow(root);
694
695        // `topic` diverges from develop with a unique commit develop never
696        // sees, then `premature` branches off `topic`'s tip — so
697        // `premature` is merged into `topic` but NOT into `develop`.
698        git(root, &["checkout", "-q", "-b", "topic", "develop"]);
699        commit_file(root, "topic-only.txt");
700        git(root, &["checkout", "-q", "-b", "premature", "topic"]);
701
702        // Leave the main checkout on `topic` — NOT `develop` — before
703        // calling cleanup_merged, mirroring an operator who forgot to
704        // check out develop first. (`topic` itself is also technically
705        // "merged into HEAD" under an implicit baseline since it IS HEAD,
706        // which git's own `-d` correctly refuses as the checked-out branch
707        // — so the call's overall Ok/Err is not itself decisive here; check
708        // the actual side effect on `premature` instead.)
709        git(root, &["checkout", "-q", "topic"]);
710
711        let _ = gf.cleanup_merged();
712        assert!(
713            gf.branch_exists("premature"),
714            "premature is merged into topic (current HEAD) but not into \
715             develop — it must survive cleanup_merged when the baseline is develop"
716        );
717    }
718
719    /// WR-03 (13-REVIEW.md), revised: `git branch --merged` prefixes a
720    /// branch checked out in a linked worktree with `+ `. The prefix must be
721    /// stripped positionally (not by trimming marker characters, which would
722    /// mangle a branch legitimately named "+foo"), and a branch git refuses
723    /// to delete — a worktree checkout can never be deleted, by design —
724    /// must be skipped with a warning rather than aborting the sweep before
725    /// the remaining merged branches.
726    #[test]
727    fn cleanup_merged_skips_worktree_branch_and_continues_sweep() {
728        let repo = init_repo();
729        let root = repo.path();
730        let gf = flow(root);
731
732        // Merge a branch into develop WITHOUT deleting it (feature_finish
733        // deletes on merge, which would leave nothing to check out).
734        git(
735            root,
736            &["checkout", "-q", "-b", "worktree-merged", "develop"],
737        );
738        commit_file(root, "g.txt");
739        git(root, &["checkout", "-q", "develop"]);
740        git(root, &["merge", "-q", "--no-ff", "worktree-merged"]);
741
742        // Check the merged branch out in a linked worktree so
743        // `git branch --merged` reports it with a `+ ` prefix.
744        let wt_dir = tempfile::tempdir().unwrap();
745        git(
746            root,
747            &[
748                "worktree",
749                "add",
750                wt_dir.path().to_str().unwrap(),
751                "worktree-merged",
752            ],
753        );
754
755        // A second merged branch that sorts after "worktree-merged" would be
756        // reached only if the sweep survives the worktree refusal; "zz-" also
757        // guards against luck in iteration order via the branch before it.
758        git(root, &["branch", "aa-stale"]);
759        git(root, &["branch", "zz-stale"]);
760
761        let deleted = gf
762            .cleanup_merged()
763            .expect("a skipped worktree branch must not abort the sweep");
764        assert!(deleted.contains(&"aa-stale".to_string()));
765        assert!(deleted.contains(&"zz-stale".to_string()));
766        assert!(
767            !deleted.contains(&"worktree-merged".to_string()),
768            "worktree checkout cannot be deleted"
769        );
770        assert!(gf.branch_exists("worktree-merged"));
771    }
772
773    /// The delete side must agree with the `--merged develop` listing: `-d`
774    /// verifies merged-into-HEAD, so with the main checkout parked on a
775    /// stale branch every genuinely-merged branch was refused as "not fully
776    /// merged" — in exactly the scenario WR-04 exists for.
777    #[test]
778    fn cleanup_merged_deletes_when_head_is_not_on_develop() {
779        let repo = init_repo();
780        let root = repo.path();
781        let gf = flow(root);
782
783        // `old` is parked before the merge below, so nothing merged later is
784        // reachable from HEAD while it's checked out.
785        git(root, &["checkout", "-q", "-b", "old", "develop"]);
786        git(root, &["checkout", "-q", "develop"]);
787        git(root, &["checkout", "-q", "-b", "merged-feature", "develop"]);
788        commit_file(root, "h.txt");
789        git(root, &["checkout", "-q", "develop"]);
790        git(root, &["merge", "-q", "--no-ff", "merged-feature"]);
791        git(root, &["checkout", "-q", "old"]);
792
793        let deleted = gf.cleanup_merged().expect("cleanup");
794        assert!(
795            deleted.contains(&"merged-feature".to_string()),
796            "merged-into-develop branch must be deleted even when HEAD is elsewhere: {deleted:?}"
797        );
798        assert!(!gf.branch_exists("merged-feature"));
799    }
800
801    #[test]
802    fn delete_branch_removes_unmerged_with_force_and_protects_trunk() {
803        let repo = init_repo();
804        let root = repo.path();
805        let gf = flow(root);
806
807        // Create a feature branch with an unmerged commit.
808        gf.feature_start(8).expect("start");
809        commit_file(root, "unmerged.txt");
810        // Switch back to develop so the branch isn't checked out.
811        git(root, &["checkout", "-q", "develop"]);
812
813        // -d would refuse (unmerged); force deletes it.
814        assert!(gf.delete_branch("feature/phase-08", false).is_err());
815        gf.delete_branch("feature/phase-08", true)
816            .expect("force delete");
817        let branches = Command::new("git")
818            .args(["branch"])
819            .current_dir(root)
820            .output()
821            .unwrap();
822        assert!(!String::from_utf8_lossy(&branches.stdout).contains("feature/phase-08"));
823
824        // Protected branches are never deleted.
825        assert!(gf.delete_branch("develop", true).is_err());
826        assert!(gf.delete_branch("main", true).is_err());
827    }
828
829    #[test]
830    fn sequentagent_helpers_integrate_and_rebase_cleanly() {
831        let repo = init_repo();
832        let root = repo.path();
833        let gf = flow(root);
834
835        // Base branch off develop, not checked out anywhere.
836        gf.ensure_branch("feature/phase-07", "develop")
837            .expect("ensure base");
838        assert!(gf.branch_exists("feature/phase-07"));
839        assert!(!gf.branch_tip("feature/phase-07").unwrap().is_empty());
840        // ensure_branch is idempotent.
841        gf.ensure_branch("feature/phase-07", "develop")
842            .expect("ensure again");
843
844        // Two agent worktrees off the same base tip.
845        let wt_a = root.join(".worktrees/a");
846        let wt_b = root.join(".worktrees/b");
847        crate::worktree::add(root, &wt_a, "feat-a", "feature/phase-07", true).expect("add A");
848        crate::worktree::add(root, &wt_b, "feat-b", "feature/phase-07", true).expect("add B");
849
850        // Agent A commits a new file, then we integrate A into the base (ff).
851        std::fs::write(wt_a.join("a.txt"), "from-a\n").unwrap();
852        git(&wt_a, &["add", "."]);
853        git(&wt_a, &["commit", "-q", "-m", "a work"]);
854        gf.fast_forward_branch("feature/phase-07", "feat-a")
855            .expect("ff base to A");
856        assert_eq!(
857            gf.branch_tip("feature/phase-07").unwrap(),
858            gf.branch_tip("feat-a").unwrap()
859        );
860
861        // Agent B (no overlapping changes) rebases onto the updated base cleanly.
862        gf.rebase_in(&wt_b, "feature/phase-07")
863            .expect("clean rebase");
864        // B now contains A's file.
865        assert!(wt_b.join("a.txt").exists());
866    }
867
868    #[test]
869    fn rebase_in_aborts_and_errors_on_conflict() {
870        let repo = init_repo();
871        let root = repo.path();
872        let gf = flow(root);
873
874        gf.ensure_branch("feature/phase-07", "develop")
875            .expect("ensure base");
876
877        // Worktree B is created off the ORIGINAL base, then edits a.txt.
878        let wt_b = root.join(".worktrees/b");
879        crate::worktree::add(root, &wt_b, "feat-b", "feature/phase-07", true).expect("add B");
880        std::fs::write(wt_b.join("a.txt"), "from-b\n").unwrap();
881        git(&wt_b, &["add", "."]);
882        git(&wt_b, &["commit", "-q", "-m", "b edits a"]);
883
884        // Meanwhile the base advances with a conflicting a.txt (via worktree A).
885        let wt_a = root.join(".worktrees/a");
886        crate::worktree::add(root, &wt_a, "feat-a", "feature/phase-07", true).expect("add A");
887        std::fs::write(wt_a.join("a.txt"), "from-base\n").unwrap();
888        git(&wt_a, &["add", "."]);
889        git(&wt_a, &["commit", "-q", "-m", "base edits a"]);
890        gf.fast_forward_branch("feature/phase-07", "feat-a")
891            .expect("ff base to A");
892
893        // Rebasing B onto the updated base conflicts on a.txt → error + abort.
894        let err = gf.rebase_in(&wt_b, "feature/phase-07").unwrap_err();
895        assert!(matches!(err, GitError::Command(_)));
896        // The abort left no rebase-in-progress state behind.
897        assert!(!root.join(".git/worktrees/b/rebase-merge").exists());
898        // B is still usable: its own commit is intact.
899        assert_eq!(
900            std::fs::read_to_string(wt_b.join("a.txt")).unwrap(),
901            "from-b\n"
902        );
903    }
904
905    #[test]
906    fn merge_of_missing_branch_is_an_error() {
907        let repo = init_repo();
908        let root = repo.path();
909        // feature_finish for a phase that was never started: checkout develop
910        // succeeds, but merging the nonexistent feature branch fails.
911        let err = flow(root).feature_finish(99).unwrap_err();
912        assert!(matches!(err, GitError::Command(_)));
913    }
914}