Skip to main content

tuff_core/
git.rs

1use std::{
2    path::{Path, PathBuf},
3    process::Command,
4};
5
6use tempfile::TempDir;
7use url::Url;
8
9use crate::error::{Result, TuffError};
10use crate::manifest::CapabilityType;
11
12pub fn is_git_url(s: &str) -> bool {
13    s.starts_with("http://")
14        || s.starts_with("https://")
15        || s.starts_with("git@")
16        || s.starts_with("file://")
17}
18
19fn clean_git_url(raw: &str) -> (String, Option<String>) {
20    let parsed = match Url::parse(raw) {
21        Ok(u) => u,
22        Err(_) => return (raw.to_string(), None),
23    };
24
25    let host = parsed.host_str().unwrap_or("");
26    let path = parsed.path();
27    let segments: Vec<&str> = path.trim_start_matches('/').split('/').collect();
28
29    if (host == "github.com" || host.ends_with(".github.com"))
30        && segments.len() >= 4
31        && (segments[2] == "tree" || segments[2] == "blob")
32    {
33        let clean = format!("https://{}/{}/{}", host, segments[0], segments[1]);
34        return (clean, Some(segments[3].to_string()));
35    }
36
37    if (host == "github.com" || host.ends_with(".github.com")) && segments.len() > 2 {
38        return (
39            format!("https://{}/{}/{}", host, segments[0], segments[1]),
40            None,
41        );
42    }
43
44    if (host == "gitlab.com" || host.ends_with(".gitlab.com"))
45        && segments.len() >= 5
46        && segments[2] == "-"
47        && (segments[3] == "tree" || segments[3] == "blob")
48    {
49        let clean = format!("https://{}/{}/{}", host, segments[0], segments[1]);
50        return (clean, Some(segments[4].to_string()));
51    }
52
53    if (host == "gitlab.com" || host.ends_with(".gitlab.com")) && segments.len() > 2 {
54        return (
55            format!("https://{}/{}/{}", host, segments[0], segments[1]),
56            None,
57        );
58    }
59
60    (raw.to_string(), None)
61}
62
63/// Returns a repository-relative folder selected by a GitHub/GitLab URL.
64///
65/// A repository URL has no subdirectory. Folder URLs may use either the
66/// provider's normal `/tree/<branch>/...` form or a direct `/...` path.
67pub fn source_subdirectory(raw: &str) -> Option<String> {
68    let parsed = Url::parse(raw).ok()?;
69    let host = parsed.host_str()?;
70    let segments: Vec<&str> = parsed.path().trim_start_matches('/').split('/').collect();
71
72    if host == "github.com" || host.ends_with(".github.com") {
73        if segments.len() >= 5 && (segments[2] == "tree" || segments[2] == "blob") {
74            return Some(segments[4..].join("/"));
75        }
76        if segments.len() > 2 && segments[2] != "tree" && segments[2] != "blob" {
77            return Some(segments[2..].join("/"));
78        }
79    }
80
81    if host == "gitlab.com" || host.ends_with(".gitlab.com") {
82        if segments.len() >= 6
83            && segments[2] == "-"
84            && (segments[3] == "tree" || segments[3] == "blob")
85        {
86            return Some(segments[5..].join("/"));
87        }
88        if segments.len() > 2 && segments[2] != "-" {
89            return Some(segments[2..].join("/"));
90        }
91    }
92
93    None
94}
95
96pub fn clone_to_temp(
97    raw_url: &str,
98    resolved_ref: Option<&str>,
99) -> Result<(TempDir, PathBuf, String)> {
100    let (clean_url, branch) = clean_git_url(raw_url);
101    let temp = TempDir::new()?;
102    let checkout = temp.path().join("source");
103    let mut clone = Command::new("git");
104    clone.args(["clone", "--quiet"]);
105    if resolved_ref.is_none() {
106        clone.args(["--depth", "1"]);
107        if let Some(branch) = branch.as_deref() {
108            clone.args(["--branch", branch]);
109        }
110    }
111    clone.arg(&clean_url).arg(&checkout);
112    run_git(
113        &mut clone,
114        &format!("git clone failed for {clean_url}; is the repo accessible?"),
115    )?;
116    if let Some(reference) = resolved_ref {
117        run_git(
118            Command::new("git")
119                .args(["checkout", "--quiet", "--detach", reference])
120                .current_dir(&checkout),
121            &format!("could not check out recorded ref {reference}"),
122        )?;
123    }
124    Ok((temp, checkout, clean_url))
125}
126
127/// Clone a repository at one tag, shallowly. The caller reads the commit
128/// the tag names with [`resolve_ref`]; the lockfile pins that, not the tag.
129pub fn clone_tag_to_temp(raw_url: &str, tag: &str) -> Result<(TempDir, PathBuf, String)> {
130    let (clean_url, _) = clean_git_url(raw_url);
131    let temp = TempDir::new()?;
132    let checkout = temp.path().join("source");
133    run_git(
134        Command::new("git")
135            .args(["clone", "--quiet", "--depth", "1", "--branch", tag])
136            .arg(&clean_url)
137            .arg(&checkout),
138        &format!("git clone failed for {clean_url} at tag {tag}; is the repo accessible?"),
139    )?;
140    Ok((temp, checkout, clean_url))
141}
142
143/// One tag a remote publishes and the commit it names right now.
144#[derive(Debug, Clone, PartialEq, Eq)]
145pub struct RemoteTag {
146    pub name: String,
147    /// The commit, not the tag object: an annotated tag is peeled.
148    pub commit: String,
149}
150
151/// The tags a repository publishes, without cloning it, each with the
152/// commit it currently names. That commit is what a repointed tag changes.
153pub fn list_remote_tags(raw_url: &str) -> Result<Vec<RemoteTag>> {
154    let (clean_url, _) = clean_git_url(raw_url);
155    let output = Command::new("git")
156        .args(["ls-remote", "--tags", &clean_url])
157        .output()?;
158    if !output.status.success() {
159        let stderr = String::from_utf8_lossy(&output.stderr).trim().to_string();
160        let context = format!("git ls-remote failed for {clean_url}; is the repo accessible?");
161        return Err(TuffError::source_failed(if stderr.is_empty() {
162            context
163        } else {
164            format!("{context}: {stderr}")
165        }));
166    }
167    Ok(parse_ls_remote_tags(&String::from_utf8_lossy(
168        &output.stdout,
169    )))
170}
171
172/// Read `git ls-remote --tags` output. A lightweight tag is one row naming
173/// the commit. An annotated tag is two: the tag object, then a `^{}` row
174/// naming the commit it points at, which is the one that matters.
175fn parse_ls_remote_tags(output: &str) -> Vec<RemoteTag> {
176    let mut tags: Vec<RemoteTag> = Vec::new();
177    for line in output.lines() {
178        let Some((sha, reference)) = line.split_once('\t') else {
179            continue;
180        };
181        let Some(name) = reference.strip_prefix("refs/tags/") else {
182            continue;
183        };
184        match name.strip_suffix("^{}") {
185            Some(peeled) => {
186                if let Some(tag) = tags.iter_mut().find(|tag| tag.name == peeled) {
187                    tag.commit = sha.to_string();
188                }
189            }
190            None => tags.push(RemoteTag {
191                name: name.to_string(),
192                commit: sha.to_string(),
193            }),
194        }
195    }
196    tags
197}
198
199fn run_git(cmd: &mut Command, context: &str) -> Result<()> {
200    let output = cmd.output()?;
201    if output.status.success() {
202        return Ok(());
203    }
204
205    let stderr = String::from_utf8_lossy(&output.stderr).trim().to_string();
206    if stderr.is_empty() {
207        Err(TuffError::source_failed(context.to_string()))
208    } else {
209        Err(TuffError::source_failed(format!("{context}: {stderr}")))
210    }
211}
212
213pub fn resolve_ref(repo: &Path) -> Result<String> {
214    let output = Command::new("git")
215        .args(["rev-parse", "HEAD"])
216        .current_dir(repo)
217        .output()?;
218
219    if !output.status.success() {
220        return Err(TuffError::source_failed("failed to resolve git ref"));
221    }
222
223    let sha = String::from_utf8_lossy(&output.stdout).trim().to_string();
224    if sha.is_empty() {
225        return Err(TuffError::source_failed("empty git ref"));
226    }
227    Ok(sha)
228}
229
230pub fn discover_capability(
231    repo: &Path,
232    name: &str,
233    capability_type: CapabilityType,
234) -> Result<PathBuf> {
235    let dir_plural = capability_type.plural_dir(); // "skills", "tools", "hooks", "workflows"
236    let dir_singular = capability_type.as_str(); // "skill", "tool", "hook", "workflow"
237
238    let mut matches = Vec::new();
239
240    // A URL-selected path can be nested arbitrarily deep, so try the exact
241    // repository-relative path before the conventional capability layouts.
242    let direct = repo.join(name);
243    if direct.is_dir() {
244        matches.push(direct);
245    }
246
247    // Pattern 1: <plural>/<name>/ (e.g. skills/security-review/)
248    let p1 = repo.join(dir_plural).join(name);
249    if p1.is_dir() {
250        matches.push(p1);
251    }
252
253    // Pattern 2: <singular>/<name>/ (e.g. skill/security-review/)
254    let p2 = repo.join(dir_singular).join(name);
255    if p2.is_dir() {
256        matches.push(p2);
257    }
258
259    // Pattern 3: <name>/ at root level
260    let p3 = repo.join(name);
261    if p3.is_dir() {
262        matches.push(p3);
263    }
264
265    // Pattern 4: Walk <plural>/ subdirs for <category>/<name>/
266    let plural_dir = repo.join(dir_plural);
267    if plural_dir.is_dir() {
268        for entry in std::fs::read_dir(&plural_dir)? {
269            let entry = entry?;
270            if entry.file_type()?.is_dir() {
271                let candidate = entry.path().join(name);
272                if candidate.is_dir() {
273                    matches.push(candidate);
274                }
275            }
276        }
277    }
278
279    matches.sort();
280    matches.dedup();
281    match matches.len() {
282        0 => {
283            let nearby = list_nearby_capabilities(repo, capability_type)?;
284            let hint = if nearby.is_empty() {
285                String::new()
286            } else {
287                format!("\nAvailable {dir_plural}: {}", nearby.join(", "))
288            };
289            Err(TuffError::not_found(format!(
290                "{} '{}' not found in repository{hint}",
291                capability_type, name
292            )))
293        }
294        1 => Ok(matches[0].clone()),
295        _ => {
296            let paths: Vec<_> = matches
297                .iter()
298                .map(|p| p.strip_prefix(repo).unwrap_or(p).display().to_string())
299                .collect();
300            Err(TuffError::usage(format!(
301                "ambiguous capability name '{}' matches multiple paths: {}",
302                name,
303                paths.join(", ")
304            )))
305        }
306    }
307}
308
309fn list_nearby_capabilities(repo: &Path, capability_type: CapabilityType) -> Result<Vec<String>> {
310    let dir_plural = capability_type.plural_dir();
311    let capabilities_dir = repo.join(dir_plural);
312    if !capabilities_dir.is_dir() {
313        return Ok(Vec::new());
314    }
315
316    let mut names = Vec::new();
317    for entry in std::fs::read_dir(&capabilities_dir)? {
318        let entry = entry?;
319        if entry.file_type()?.is_dir() {
320            let name = entry.file_name().to_string_lossy().to_string();
321            if !name.starts_with('.') {
322                names.push(name);
323            }
324        }
325    }
326    names.sort();
327    Ok(names)
328}
329
330#[cfg(test)]
331mod tests {
332    use super::*;
333
334    #[test]
335    fn ls_remote_tags_peel_annotated_tags_to_their_commit() {
336        let output = "aaaa\trefs/tags/v1.0.0\n\
337                      bbbb\trefs/tags/v1.2.0\n\
338                      cccc\trefs/tags/v1.2.0^{}\n\
339                      dddd\trefs/heads/main\n";
340        let tags = parse_ls_remote_tags(output);
341        assert_eq!(
342            tags,
343            vec![
344                RemoteTag {
345                    name: "v1.0.0".into(),
346                    commit: "aaaa".into()
347                },
348                RemoteTag {
349                    name: "v1.2.0".into(),
350                    commit: "cccc".into()
351                },
352            ]
353        );
354    }
355
356    #[test]
357    fn detect_github_clean_url() {
358        assert!(is_git_url("https://github.com/owner/repo"));
359        assert!(is_git_url("http://github.com/owner/repo"));
360    }
361
362    #[test]
363    fn detect_github_tree_url() {
364        assert!(is_git_url("https://github.com/owner/repo/tree/main/skills"));
365    }
366
367    #[test]
368    fn detect_ssh_url() {
369        assert!(is_git_url("git@github.com:owner/repo.git"));
370    }
371
372    #[test]
373    fn detect_file_url() {
374        assert!(is_git_url("file:///path/to/repo"));
375    }
376
377    #[test]
378    fn reject_local_path() {
379        assert!(!is_git_url("./my-skill"));
380        assert!(!is_git_url("/absolute/path"));
381    }
382
383    #[test]
384    fn clean_github_tree_extracts_repo_and_branch() {
385        let (url, branch) = clean_git_url("https://github.com/owner/repo/tree/main/skills");
386        assert_eq!(url, "https://github.com/owner/repo");
387        assert_eq!(branch, Some("main".to_string()));
388    }
389
390    #[test]
391    fn clean_github_blob_extracts_repo_and_branch() {
392        let (url, branch) = clean_git_url("https://github.com/owner/repo/blob/main/README.md");
393        assert_eq!(url, "https://github.com/owner/repo");
394        assert_eq!(branch, Some("main".to_string()));
395    }
396
397    #[test]
398    fn clean_plain_url_passes_through() {
399        let (url, branch) = clean_git_url("https://github.com/vercel-labs/skills");
400        assert_eq!(url, "https://github.com/vercel-labs/skills");
401        assert_eq!(branch, None);
402    }
403
404    #[test]
405    fn github_folder_url_is_normalized_and_preserves_subdirectory() {
406        let (url, branch) = clean_git_url(
407            "https://github.com/am-will/codex-skills/hooks/aitmpl-codex/automation/change-logger",
408        );
409        assert_eq!(url, "https://github.com/am-will/codex-skills");
410        assert_eq!(branch, None);
411        assert_eq!(
412            source_subdirectory(
413                "https://github.com/am-will/codex-skills/hooks/aitmpl-codex/automation/change-logger"
414            ),
415            Some("hooks/aitmpl-codex/automation/change-logger".to_string())
416        );
417    }
418
419    #[test]
420    fn github_tree_url_preserves_branch_and_subdirectory() {
421        assert_eq!(
422            source_subdirectory(
423                "https://github.com/am-will/codex-skills/tree/main/hooks/aitmpl-codex/automation/change-logger"
424            ),
425            Some("hooks/aitmpl-codex/automation/change-logger".to_string())
426        );
427    }
428
429    #[test]
430    fn clean_gitlab_tree_extracts_repo_and_branch() {
431        let (url, branch) = clean_git_url("https://gitlab.com/owner/repo/-/tree/main/src");
432        assert_eq!(url, "https://gitlab.com/owner/repo");
433        assert_eq!(branch, Some("main".to_string()));
434    }
435
436    #[test]
437    fn clean_file_url_passes_through() {
438        let (url, branch) = clean_git_url("file:///path/to/repo");
439        assert_eq!(url, "file:///path/to/repo");
440        assert_eq!(branch, None);
441    }
442}