Skip to content

fix(#403): finish the streaming-hash repair — snapshot.rs imports Sha256 but hash_records is unchanged #411

Description

@2233admin

Follow-up to #403, found while recovering the 2026-09-03 dirty tree
(PR #409).

The recovery brought back a partially applied version of the #403 fix.
crates/code-intel-cli/src/snapshot.rs now carries:

use crate::capability::{sha256_hex, Sha256};

Sha256 is imported and never used anywhere in the file. The conversion it
was imported for was never written: hash_records (line 1610) still
concatenates every record into a second canonical buffer before hashing.

fn hash_records(records: &[Vec<u8>]) -> String {
    let mut canonical = Vec::new();
    for record in records {
        canonical.extend_from_slice(&(record.len() as u64).to_be_bytes());
        canonical.extend_from_slice(record);
    }
    sha256_hex(&canonical)
}

So peak allocation still scales with whole-tree content times two, and the
defect #403 describes is unfixed. The incremental API it needs already
exists — Sha256::new(), update(), finish() in
content_contract.rs:245-387, and sha256_hex is documented as "the
one-shot form of this and must keep producing identical output".

Why this was not caught

The unused import would normally be a warning. It is one of the ~100
dead-code warnings AGENTS.md describes, and this crate has no
lib.rs — modules are shared by #[path] re-inclusion, so most warnings
are expected. One real regression hides inside the expected noise.

The fix

Stream the framed bytes into the hasher instead of materialising them:

fn hash_records(records: &[Vec<u8>]) -> String {
    let mut hasher = Sha256::new();
    for record in records {
        hasher.update(&(record.len() as u64).to_be_bytes());
        hasher.update(record);
    }
    hasher.finish()
}

This produces byte-identical digests, so snapshot identity does not change.
It can be verified without the LAN host too, because a test that pins a
known digest over a known record set would catch a framing error.

Note on host isolation

DR-0013 excludes the host that owns the original checkout from compiling.
A second host (DESKTOP-AL7MNNO, an Orca-paired runtime on the LAN) is now
configured with Rust 1.95.0, MSVC 14.44.35207, ripgrep 14.1.0, and
ast-grep 0.42.3, and runs the full suite to exit 0. This issue can be
implemented and verified there.

hash_records has 6 call sites, all in this one file. Scope: one function,
plus removing the now-unused import if the fix does not consume it.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingclaimedIssue claimed by an active session (DR-0004): read the claim comment before touching it

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions