Follow-up to #403, found while recovering the 2026-09-03 dirty tree
(PR #409).
The recovery brought back a partially applied version of the #403 fix.
crates/code-intel-cli/src/snapshot.rs now carries:
use crate::capability::{sha256_hex, Sha256};
Sha256 is imported and never used anywhere in the file. The conversion it
was imported for was never written: hash_records (line 1610) still
concatenates every record into a second canonical buffer before hashing.
fn hash_records(records: &[Vec<u8>]) -> String {
let mut canonical = Vec::new();
for record in records {
canonical.extend_from_slice(&(record.len() as u64).to_be_bytes());
canonical.extend_from_slice(record);
}
sha256_hex(&canonical)
}
So peak allocation still scales with whole-tree content times two, and the
defect #403 describes is unfixed. The incremental API it needs already
exists — Sha256::new(), update(), finish() in
content_contract.rs:245-387, and sha256_hex is documented as "the
one-shot form of this and must keep producing identical output".
Why this was not caught
The unused import would normally be a warning. It is one of the ~100
dead-code warnings AGENTS.md describes, and this crate has no
lib.rs — modules are shared by #[path] re-inclusion, so most warnings
are expected. One real regression hides inside the expected noise.
The fix
Stream the framed bytes into the hasher instead of materialising them:
fn hash_records(records: &[Vec<u8>]) -> String {
let mut hasher = Sha256::new();
for record in records {
hasher.update(&(record.len() as u64).to_be_bytes());
hasher.update(record);
}
hasher.finish()
}
This produces byte-identical digests, so snapshot identity does not change.
It can be verified without the LAN host too, because a test that pins a
known digest over a known record set would catch a framing error.
Note on host isolation
DR-0013 excludes the host that owns the original checkout from compiling.
A second host (DESKTOP-AL7MNNO, an Orca-paired runtime on the LAN) is now
configured with Rust 1.95.0, MSVC 14.44.35207, ripgrep 14.1.0, and
ast-grep 0.42.3, and runs the full suite to exit 0. This issue can be
implemented and verified there.
hash_records has 6 call sites, all in this one file. Scope: one function,
plus removing the now-unused import if the fix does not consume it.
Follow-up to #403, found while recovering the 2026-09-03 dirty tree
(PR #409).
The recovery brought back a partially applied version of the #403 fix.
crates/code-intel-cli/src/snapshot.rsnow carries:Sha256is imported and never used anywhere in the file. The conversion itwas imported for was never written:
hash_records(line 1610) stillconcatenates every record into a second
canonicalbuffer before hashing.So peak allocation still scales with whole-tree content times two, and the
defect #403 describes is unfixed. The incremental API it needs already
exists —
Sha256::new(),update(),finish()incontent_contract.rs:245-387, andsha256_hexis documented as "theone-shot form of this and must keep producing identical output".
Why this was not caught
The unused import would normally be a warning. It is one of the ~100
dead-code warnings
AGENTS.mddescribes, and this crate has nolib.rs— modules are shared by#[path]re-inclusion, so most warningsare expected. One real regression hides inside the expected noise.
The fix
Stream the framed bytes into the hasher instead of materialising them:
This produces byte-identical digests, so snapshot identity does not change.
It can be verified without the LAN host too, because a test that pins a
known digest over a known record set would catch a framing error.
Note on host isolation
DR-0013 excludes the host that owns the original checkout from compiling.
A second host (
DESKTOP-AL7MNNO, an Orca-paired runtime on the LAN) is nowconfigured with Rust 1.95.0, MSVC 14.44.35207, ripgrep 14.1.0, and
ast-grep 0.42.3, and runs the full suite to exit 0. This issue can be
implemented and verified there.
hash_recordshas 6 call sites, all in this one file. Scope: one function,plus removing the now-unused import if the fix does not consume it.