# Nushell git module verification matrix Primary scope: `nushell/modules/git.nu`. Secondary verified scope: - `nushell/modules/sy.nu`: dotfiles sync helper; real `run-external git` calls are verified separately. Not command modules for this goal: - `nushell/modules/prompt.nu`: parses `.git` metadata, does not invoke `git`. - `nushell/gen-aliases.nu`: defines alias metadata only (`aka g git`), no concrete git argv to verify. All verification must run in disposable temp repos/remotes via: - `nushell/tests/git-scope-guard.sh`: static guard for Nushell files that launch external `git`; prevents silently ignoring a new module/caller. - `nushell/tests/git-worktree-layout.sh`: `git.nu` behavior/effects smoke. - `nushell/tests/git-command-coverage.sh`: wraps `git` during `git.nu` Nushell calls, logs actual argv, and asserts every command shape below is exercised. - `nushell/tests/git-sync-module.sh`: `sy.nu` behavior/effects smoke with git argv logging. ## Exported command coverage | Export | Class | Covered by smoke | Notes | |---|---:|---:|---| | `co` | network/local mutating | yes | local bare remote fixture only | | `wt` | read-only | yes | alias for `wt ls` | | `wt root` | read-only | yes | layout metadata | | `wt repo` | read-only | yes | layout metadata | | `wt path` | read-only | yes | canonical paths | | `wt ls` | read-only + per-worktree status | yes | checks dirty state | | `wt migrate --dry` | read-only planning | yes | normal checkout fixture | | `wt migrate` | destructive/local mutating | yes | normal + legacy fixtures; source backup verified | | `wt new` | local mutating | yes | with and without `--switch` | | `wt go` | env/local mutating with `--create` | yes | create path verified | | `wt rm` | destructive/local mutating | yes | removes worktree only | | `wt done` | destructive/local mutating | yes | removes worktree + branch | | `wt prune` | destructive metadata cleanup | yes | temp layout only | | `wt repair` | local mutating metadata | yes | forces absolute layout | | `wt add` | local mutating | yes | alias for `wt new` | | `wt list` | read-only | yes | alias for `wt ls` | | `wt lock` | local metadata mutating | yes | locks temp worktree | | `wt unlock` | local metadata mutating | yes | unlocks temp worktree | | `wt move` | local mutating | yes | path move verified | | `wt remove` | destructive/local mutating | yes | alias for `wt rm` | ## `sy.nu` exported command coverage | Export | Git command shape | Class | Covered by smoke | Notes | |---|---|---:|---:|---| | `sy` / `main` | `git -C $DOTFILES status --short --branch` | read-only | yes | disposable `$DOTFILES` clone; fake `macchina` | | `sy up` | `git -C $DOTFILES add --all` | local mutating | yes | clean disposable clone | | `sy up` | `git -C $DOTFILES commit --all` | local mutating | yes | clean clone, failure tolerated by module | | `sy up` | `git -C $DOTFILES push` | remote/network mutating | yes | local bare remote only | | `sy down` | `git -C $DOTFILES pull` | remote/network mutating | yes | local bare remote only; fake `topgrade` | ## `git.nu` invocation inventory | Line | Git command shape | Class | Exercised by | |---:|---|---:|---| | 32 | `git ...$args` | wrapper | all commands | | 34 | `git -C $cwd ...$args` | wrapper | status/diff/apply/stash checks | | 81 | `git --git-dir config --get ` | read-only | layout, migration, config checks | | 86 | `git --git-dir config --bool --get ` | read-only | layout detection/config checks | | 91 | `git --git-dir config ` | local metadata mutating | `co`, `wt migrate`, `wt repair` | | 95 | `git --git-dir config --unset ` | local metadata mutating | `co`, `wt migrate`, `wt repair` | | 99 | `git --git-dir -c worktree.useRelativePaths=false ...` | wrapper | all worktree add/move/repair absolute-path operations | | 123 | `git rev-parse --path-format=absolute --git-common-dir` | read-only | all layout commands | | 201 | `git --git-dir worktree list --porcelain` | read-only | `wt`, `wt ls`, `wt list`, path lookup | | 211 | `git --git-dir show-ref --verify --quiet refs/heads/` | read-only | `wt new`, `wt add`, `wt go --create` | | 223 | `git worktree add [ -b ] ` | local mutating | `wt new`, `wt add`, `wt go --create` | | 241 | `git rev-parse --abbrev-ref HEAD` | read-only | current branch, migrate, default remove | | 247 | `git rev-parse --show-toplevel` | read-only | current repo top/current marker | | 271 | `git --git-dir branch -d/-D ` | destructive local mutating | `wt done` | | 280 | `git --git-dir worktree remove [--force] ` | destructive local mutating | `wt rm`, `wt remove`, `wt done` | | 290 | `git clone --bare ` | network/local mutating | `co` with local bare fixture | | 302 | `git --git-dir symbolic-ref --short HEAD` | read-only | `co` without `--branch` | | 327 | `git worktree add ` | local mutating | `co` | | 338 | `git -C stash list` | read-only | `wt migrate` normal checkout | | 352 | `git rev-parse --path-format=absolute --git-common-dir` | read-only | `wt migrate` layout detection | | 362 | `git rev-parse --show-toplevel` | read-only | `wt migrate` normal checkout | | 405 | `git --git-dir worktree list --porcelain` | read-only | `wt migrate` legacy container | | 421 | `git -C diff --binary --cached` | read-only | dirty migration | | 422 | `git -C diff --binary` | read-only | dirty migration | | 432 | `git -C apply [--index] ` | local mutating | dirty migration | | 449 | `git -C status` | read-only sanity | dirty migration | | 476 | `git worktree add ` | local mutating | normal checkout migration | | 515 | `git worktree repair` | local metadata mutating | migration repair | | 517 | `git worktree repair ` | local metadata mutating | normal checkout migration | | 530 | `git worktree list --porcelain` | read-only | legacy migration | | 536 | `git worktree move ` | local mutating | legacy migration | | 544 | `git worktree repair` | local metadata mutating | `wt migrate` on already-new layout | | 660 | `git worktree prune` | destructive metadata cleanup | `wt prune` | | 666 | `git worktree repair` | local metadata mutating | `wt repair` | | 681 | `git worktree lock [--reason] ` | local metadata mutating | `wt lock` | | 686 | `git worktree unlock ` | local metadata mutating | `wt unlock` | | 690 | `git worktree move ` | local mutating | `wt move` | ## Failure behavior coverage | Scenario | Covered by smoke | Expected behavior | |---|---:|---| | `wt ls` outside co/wt layout | yes | fails | | `co .` | yes | fails; instructs `wt migrate` | | `wt new` to existing path/branch (`trunk`) | yes | fails | | `wt migrate` detached HEAD | yes | fails; original `.git` checkout remains | ## Evidence commands Current verification set: ```bash bash nushell/tests/git-scope-guard.sh bash nushell/tests/git-worktree-layout.sh bash nushell/tests/git-command-coverage.sh bash nushell/tests/git-sync-module.sh nu --commands 'use ./nushell/modules/git.nu *; help co | ignore; help wt migrate | ignore' nu --commands 'use ./nushell/modules/sy.nu; help sy | ignore; help "sy up" | ignore; help "sy down" | ignore' just check ``` `git-scope-guard.sh` records the exact external-git callers in `nushell/`: `nushell/modules/git.nu` and `nushell/modules/sy.nu` are verified; `nushell/gen-aliases.nu` is alias metadata only. `git-command-coverage.sh` logs only git invocations launched from `git.nu` Nushell calls (`DOTFILES_GIT_TEST_PHASE=nu`) and ignores fixture setup git commands. `git-sync-module.sh` logs only git invocations reached through `sy.nu` commands and uses fake `macchina`/`topgrade` plus a local bare remote. ## Remaining verification gaps None known for exported commands and direct git invocation shapes in `nushell/modules/git.nu` or `nushell/modules/sy.nu`.