A local Git merge queue with content-bound gate verdicts
OCaml 86%
Perl 11%
Shell 2%
<1%
Python <1%
Raku <1%
Dune <1%
C <1%
Standard ML <1%

README.md

merge-queue #

mq is a merge queue that runs where the developer works. mq land replays a branch on its target, runs the target's checks on the replayed tree, and fast-forwards the target to the tree that passed, on a laptop with no network. A change across several repositories lands as one.

State is kept where Git keeps it: the base of a branch is its upstream, its description is branch.NAME.description, the rules are the branch mq/config, a check result is a Git note on the tree it is about, and a stopped conflict is a git rebase in progress. Git's own tools therefore show what mq status shows.

Packages #

  • merge-queue is the model: every decision of the queue, as total state machines that read no clock, no file and no process. Time, identity and every fact read from Git enter as events, and the machines answer with actions.
  • merge-queue-eio is the shell and the mq command line. The shell interprets the model's actions (it reads and writes Git, runs checks, takes the run lock, prints) and holds no decision.

Security #

Queueing a change runs its code with your rights. A land runs the checks of the tree under check, and that tree supplies their scripts and its build, which run with the rights of the process that runs them, as Git runs a hook with the rights of whoever runs Git. On a machine whose scheduler starts the runs, that is outside the sandbox of whoever queued the change. The checks catch mistakes, not malice, and a result is as trustworthy as whoever can write the remote (What mq trusts). A machine may opt in to running its checks confined, with mq.confine set to auto (How a check is confined).

Documentation #

The manual is in doc/: the specification of the command line, page by page, and doc/design.md, the implementation's own page.

Licence #

ISC. See LICENSE.md.