blob: 46182fd9d44c2332715fa7974d85f13794ad8365 [file] [log] [blame]
//! This module contains all code sporting `gitoxide` for operations on `git` repositories and it mirrors
//! `utils` closely for now. One day it can be renamed into `utils` once `git2` isn't required anymore.
use crate::util::network::http::HttpTimeout;
use crate::util::{human_readable_bytes, network, MetricsCounter, Progress};
use crate::{CargoResult, GlobalContext};
use cargo_util::paths;
use gix::bstr::{BString, ByteSlice};
use std::cell::RefCell;
use std::path::Path;
use std::sync::atomic::{AtomicBool, Ordering};
use std::sync::{Arc, Weak};
use std::time::{Duration, Instant};
use tracing::debug;
/// For the time being, `repo_path` makes it easy to instantiate a gitoxide repo just for fetching.
/// In future this may change to be the gitoxide repository itself.
pub fn with_retry_and_progress(
repo_path: &std::path::Path,
gctx: &GlobalContext,
cb: &(dyn Fn(
&mut gix::progress::tree::Item,
&mut dyn FnMut(&gix::bstr::BStr),
) -> Result<(), crate::sources::git::fetch::Error>
+ Send
+ Sync),
) -> CargoResult<()> {
std::thread::scope(|s| {
let mut progress_bar = Progress::new("Fetch", gctx);
let is_shallow = gctx.cli_unstable().git.map_or(false, |features| {
features.shallow_deps || features.shallow_index
network::retry::with_retry(gctx, || {
let progress_root: Arc<gix::progress::tree::Root> =
gix::progress::tree::root::Options {
initial_capacity: 10,
message_buffer_capacity: 10,
let root = Arc::downgrade(&progress_root);
let thread = s.spawn(move || {
let mut progress = progress_root.add_child("operation");
let mut urls = RefCell::new(Default::default());
let res = cb(
&mut progress,
&mut |url| {
*urls.borrow_mut() = Some(url.to_owned());
amend_authentication_hints(res, urls.get_mut().take())
translate_progress_to_bar(&mut progress_bar, root, is_shallow)?;
thread.join().expect("no panic in scoped thread")
fn translate_progress_to_bar(
progress_bar: &mut Progress<'_>,
root: Weak<gix::progress::tree::Root>,
is_shallow: bool,
) -> CargoResult<()> {
let remote_progress: gix::progress::Id = gix::remote::fetch::ProgressId::RemoteProgress.into();
let read_pack_bytes: gix::progress::Id =
let delta_index_objects: gix::progress::Id =
let resolve_objects: gix::progress::Id =
// We choose `N=10` here to make a `300ms * 10slots ~= 3000ms`
// sliding window for tracking the data transfer rate (in bytes/s).
let mut last_percentage_update = Instant::now();
let mut last_fast_update = Instant::now();
let mut counter = MetricsCounter::<10>::new(0, last_percentage_update);
let mut tasks = Vec::with_capacity(10);
let slow_check_interval = std::time::Duration::from_millis(300);
let fast_check_interval = Duration::from_millis(50);
let sleep_interval = Duration::from_millis(10);
slow_check_interval.as_millis() % fast_check_interval.as_millis(),
"progress should be smoother by keeping these as multiples of each other"
fast_check_interval.as_millis() % sleep_interval.as_millis(),
"progress should be smoother by keeping these as multiples of each other"
let num_phases = if is_shallow { 3 } else { 2 }; // indexing + delta-resolution, both with same amount of objects to handle
while let Some(root) = root.upgrade() {
let needs_update = last_fast_update.elapsed() >= fast_check_interval;
if !needs_update {
let now = Instant::now();
last_fast_update = now;
root.sorted_snapshot(&mut tasks);
fn progress_by_id(
id: gix::progress::Id,
task: &gix::progress::Task,
) -> Option<(&str, &gix::progress::Value)> {
( == id)
.then(|| task.progress.as_ref())
.map(|value| (, value))
fn find_in<K>(
tasks: &[(K, gix::progress::Task)],
cb: impl Fn(&gix::progress::Task) -> Option<(&str, &gix::progress::Value)>,
) -> Option<(&str, &gix::progress::Value)> {
tasks.iter().find_map(|(_, t)| cb(t))
if let Some((_, objs)) = find_in(&tasks, |t| progress_by_id(resolve_objects, t)) {
// Phase 3: Resolving deltas.
let objects = objs.step.load(Ordering::Relaxed);
let total_objects = objs.done_at.expect("known amount of objects");
let msg = format!(", ({objects}/{total_objects}) resolving deltas");
(total_objects * (num_phases - 1)) + objects,
total_objects * num_phases,
} else if let Some((objs, read_pack)) =
find_in(&tasks, |t| progress_by_id(read_pack_bytes, t)).and_then(|read| {
find_in(&tasks, |t| progress_by_id(delta_index_objects, t))
.map(|delta| (delta.1, read.1))
// Phase 2: Receiving objects.
let objects = objs.step.load(Ordering::Relaxed);
let total_objects = objs.done_at.expect("known amount of objects");
let received_bytes = read_pack.step.load(Ordering::Relaxed);
let needs_percentage_update = last_percentage_update.elapsed() >= slow_check_interval;
if needs_percentage_update {
counter.add(received_bytes, now);
last_percentage_update = now;
let (rate, unit) = human_readable_bytes(counter.rate() as u64);
let msg = format!(", {rate:.2}{unit}/s");
(total_objects * (num_phases - 2)) + objects,
total_objects * num_phases,
} else if let Some((action, remote)) =
find_in(&tasks, |t| progress_by_id(remote_progress, t))
if !is_shallow {
// phase 1: work on the remote side
// Resolving deltas.
let objects = remote.step.load(Ordering::Relaxed);
if let Some(total_objects) = remote.done_at {
let msg = format!(", ({objects}/{total_objects}) {action}");
progress_bar.tick(objects, total_objects * num_phases, &msg)?;
fn amend_authentication_hints(
res: Result<(), crate::sources::git::fetch::Error>,
last_url_for_authentication: Option<gix::bstr::BString>,
) -> CargoResult<()> {
let Err(err) = res else { return Ok(()) };
let e = match &err {
) => Some(err),
_ => None,
if let Some(e) = e {
use anyhow::Context;
let auth_message = match e {
gix::protocol::handshake::Error::Credentials(_) => {
"\n* attempted to find username/password via \
git's `credential.helper` support, but failed"
gix::protocol::handshake::Error::InvalidCredentials { .. } => {
"\n* attempted to find username/password via \
`credential.helper`, but maybe the found \
credentials were incorrect"
gix::protocol::handshake::Error::Transport(_) => {
let msg = concat!(
"network failure seems to have happened\n",
"if a proxy or similar is necessary `net.git-fetch-with-cli` may help here\n",
return Err(anyhow::Error::from(err)).context(msg);
_ => None,
if let Some(auth_message) = auth_message {
let mut msg = "failed to authenticate when downloading \
if let Some(url) = last_url_for_authentication {
msg.push_str(": ");
msg.push_str("if the git CLI succeeds then `net.git-fetch-with-cli` may help here\n");
return Err(anyhow::Error::from(err)).context(msg);
/// The reason we are opening a git repository.
/// This can affect the way we open it and the cost associated with it.
pub enum OpenMode {
/// We need `git_binary` configuration as well for being able to see credential helpers
/// that are configured with the `git` installation itself.
/// However, this is slow on windows (~150ms) and most people won't need it as they use the
/// standard index which won't ever need authentication, so we only enable this when needed.
impl OpenMode {
/// Sometimes we don't need to pay for figuring out the system's git installation, and this tells
/// us if that is the case.
pub fn needs_git_binary_config(&self) -> bool {
match self {
OpenMode::ForFetch => true,
/// Produce a repository with everything pre-configured according to `config`. Most notably this includes
/// transport configuration. Knowing its `purpose` helps to optimize the way we open the repository.
/// Use `config_overrides` to configure the new repository.
pub fn open_repo(
repo_path: &std::path::Path,
config_overrides: Vec<BString>,
purpose: OpenMode,
) -> Result<gix::Repository, gix::open::Error> {
gix::open_opts(repo_path, {
let mut opts = gix::open::Options::default();
opts.permissions.config = gix::open::permissions::Config::all();
opts.permissions.config.git_binary = purpose.needs_git_binary_config();
/// Convert `git` related cargo configuration into the respective `git` configuration which can be
/// used when opening new repositories.
pub fn cargo_config_to_gitoxide_overrides(gctx: &GlobalContext) -> CargoResult<Vec<BString>> {
use gix::config::tree::{gitoxide, Core, Http, Key};
let timeout = HttpTimeout::new(gctx)?;
let http = gctx.http_config()?;
let mut values = vec![
// Assure we are not depending on committer information when updating refs after cloning.
if let Some(proxy) = &http.proxy {
if let Some(check_revoke) = http.check_revoke {
if let Some(cainfo) = &http.cainfo {
values.push(if let Some(user_agent) = &http.user_agent {
} else {
Http::USER_AGENT.validated_assignment_fmt(&format!("cargo {}", crate::version()))
if let Some(ssl_version) = &http.ssl_version {
use crate::util::context::SslVersionConfig;
match ssl_version {
SslVersionConfig::Single(version) => {
SslVersionConfig::Range(range) => {
} else if cfg!(windows) {
// This text is copied from .
// This is a temporary workaround for some bugs with libcurl and
// schannel and TLS 1.3.
// Our libcurl on Windows is usually built with schannel.
// On Windows 11 (or Windows Server 2022), libcurl recently (late
// 2022) gained support for TLS 1.3 with schannel, and it now defaults
// to 1.3. Unfortunately there have been some bugs with this.
// is the most recent. Once
// that has been fixed, and some time has passed where we can be more
// confident that the 1.3 support won't cause issues, this can be
// removed.
// Windows 10 is unaffected. libcurl does not support TLS 1.3 on
// Windows 10. (Windows 10 sorta had support, but it required enabling
// an advanced option in the registry which was buggy, and libcurl
// does runtime checks to prevent it.)
if let Some(debug) = http.debug {
if let Some(multiplexing) = http.multiplexing {
let http_version = multiplexing.then(|| "HTTP/2").unwrap_or("HTTP/1.1");
// Note that failing to set the HTTP version in `gix-transport` isn't fatal,
// which is why we don't have to try to figure out if HTTP V2 is supported in the
// currently linked version (see `try_old_curl!()`)
/// Reinitializes a given Git repository. This is useful when a Git repository
/// seems corrupted and we want to start over.
pub fn reinitialize(git_dir: &Path) -> CargoResult<()> {
fn init(path: &Path, bare: bool) -> CargoResult<()> {
let mut opts = git2::RepositoryInitOptions::new();
// Skip anything related to templates, they just call all sorts of issues as
// we really don't want to use them yet they insist on being used. See #6240
// for an example issue that comes up.
git2::Repository::init_opts(&path, &opts)?;
// Here we want to drop the current repository object pointed to by `repo`,
// so we initialize temporary repository in a sub-folder, blow away the
// existing git folder, and then recreate the git repo. Finally we blow away
// the `tmp` folder we allocated.
debug!("reinitializing git repo at {:?}", git_dir);
let tmp = git_dir.join("tmp");
let bare = !git_dir.ends_with(".git");
init(&tmp, false)?;
for entry in git_dir.read_dir()? {
let entry = entry?;
if entry.file_name().to_str() == Some("tmp") {
let path = entry.path();
drop(paths::remove_file(&path).or_else(|_| paths::remove_dir_all(&path)));
init(git_dir, bare)?;