fork of radicle with Git LFS support, backed by IPFS
Go to file
Maciek "mab122" Bator a9428a9ef9 Fix: rad lfs store/rekey fail with git ref D/F conflict on notes ref
Found live while migrating the blog's food-gallery images into LFS,
diagnosed in NOTES-lfs-store-note-write-bug.md, confirmed and fixed here.

Root cause: store.rs/rekey.rs wrote local notes to the bare
refs/notes/rad-lfs, but the earlier fetch-bug fix (1c65ee62) has the
fetch refspec populate refs/notes/rad-lfs/<peer> siblings locally --
including your own peer's copy, fetched back after your own push. A bare
refs/notes/rad-lfs ref can't coexist with refs/notes/rad-lfs/<peer> in
the same git ref namespace (a leaf ref vs. a directory prefix at the same
path) -- so the very first commit+push+fetch cycle on a repo left it
permanently unable to `rad lfs store` again, failing with "failed to
write LFS note" and no further detail (git itself hits the same conflict
from the fetch direction and just refuses that one ref cleanly; it's
specifically libgit2's ref-write path used here that fails hard instead).

Fix: stop writing to the bare ref locally at all. New
lfs_crypto::LOCAL_NOTES_REF (refs/notes/rad-lfs/local) is what
store.rs/rekey.rs write to now -- living under the same
refs/notes/rad-lfs/ prefix as every fetched peer ref makes it just
another sibling leaf ref, structurally incapable of conflicting with
them ("local" can never collide with an actual peer ID). NOTES_REF
(bare) stays exactly as it was for the remote-side/push-destination
role, unchanged. rad lfs init's push refspec becomes asymmetric
(+refs/notes/rad-lfs/local:refs/notes/rad-lfs) instead of symmetric;
fetch refspec is untouched.

Added a migration step (migrate_local_notes_ref, run by rad lfs init)
for already-affected repos: reads any existing bare-ref notes out,
deletes the bare ref, then re-writes them under the new local ref --
also removes the old symmetric push refspec config entry the same way
the earlier fetch-refspec migration did, so re-running rad lfs init
fully repairs an already-broken repo with no manual git surgery needed.
(First version of the migration itself had the identical bug -- tried to
write the new ref before deleting the old one, hit the same conflict
self-inflicted -- fixed by reading all notes into memory before deleting
the bare ref.)

Verified locally: reproduced the exact failure in the precise order that
triggers it, confirmed the fix resolves that exact same failing call in
the same repo, verified the migration path preserves note content
exactly, and confirmed a full commit->push->fetch->decrypt round trip
plus `rad lfs rekey` all still work correctly afterward.
2026-07-15 19:02:53 +02:00
.cargo fetch: upgrade gix crates 2024-05-17 13:27:18 +02:00
.config nix: switch to use nix flakes 2023-12-13 12:25:12 +01:00
.github treewide: radicle.{xyz → dev,network} 2026-04-27 18:34:30 +02:00
.radicle .radicle/ambient: Add pre-plan action for rustup 2026-05-19 10:46:50 +01:00
build build: Update apline version to 3.22 2026-05-11 12:36:48 +01:00
crates Fix: rad lfs store/rekey fail with git ref D/F conflict on notes ref 2026-07-15 19:02:53 +02:00
debian treewide: radicle.{xyz → dev,network} 2026-04-27 18:34:30 +02:00
radicle-lfs-transfer@ac4a27c098 Bump radicle-lfs-transfer submodule: fix cross-device rename on LFS download 2026-07-14 18:44:06 +02:00
scripts scripts/changelog: Generate links to commits on seed.radicle.dev 2026-05-30 09:12:25 +01:00
simulation just: checking for ellipses 2026-05-28 16:52:02 +01:00
systemd systemd: remove redundant lines from system unit 2026-02-10 11:06:05 +00:00
windows treewide: radicle.{xyz → dev,network} 2026-04-27 18:34:30 +02:00
.codespellrc Revert "codespell: Rule for ... -> …" 2026-05-28 16:50:46 +01:00
.dockerignore build: Add "upload" build step 2024-04-29 10:47:03 +02:00
.env.seed treewide: radicle.{xyz → dev,network} 2026-04-27 18:34:30 +02:00
.envrc.sample .envrc: Replace .envrc with .envrc.sample 2026-04-23 08:56:48 +01:00
.git-blame-ignore-revs git: Ignore parent from blame 2025-10-17 13:00:20 +02:00
.gitignore .envrc: Replace .envrc with .envrc.sample 2026-04-23 08:56:48 +01:00
.gitmodules Add rad lfs init and IPFS-backed pinning for seed/unseed 2026-07-14 12:32:12 +02:00
.gitsigners Add Lorenz Leutgeb to `.gitsigners` 2025-04-17 14:33:36 +02:00
.rustfmt.toml rust/edition/fmt: 2021 → 2024 2026-03-30 16:57:51 +02:00
.typos.toml Revert "typos: Rule for ... -> …" 2026-05-28 16:50:46 +01:00
ARCHITECTURE.md treewide: radicle.{xyz → dev,network} 2026-04-27 18:34:30 +02:00
CHANGELOG.md CHANGELOG: Describe the changes to repository identity evaluation 2026-07-09 11:35:07 +02:00
CONTRIBUTING.md CONTRIBUTING: Add section on issue labels 2026-06-01 11:28:30 +01:00
Cargo.lock Add client-side encryption for private-repo LFS objects 2026-07-14 16:01:49 +02:00
Cargo.toml Exclude radicle-lfs-transfer submodule from the outer cargo workspace 2026-07-14 16:18:55 +02:00
DCO Add licenses and contributor information 2022-11-16 12:26:12 +01:00
HACKING.md CONTRIBUTING/HACKING: Add note on direnv 2026-04-23 08:56:48 +01:00
LFS-IPFS.md Prompt interactively for passphrase instead of requiring RAD_PASSPHRASE 2026-07-14 17:59:04 +02:00
LICENSE-APACHE Add licenses and contributor information 2022-11-16 12:26:12 +01:00
LICENSE-MIT Add licenses and contributor information 2022-11-16 12:26:12 +01:00
NOTES-lfs-notes-fetch-bug.md Fix: rad lfs store/rekey fail with git ref D/F conflict on notes ref 2026-07-15 19:02:53 +02:00
NOTES-lfs-store-note-write-bug.md Fix: rad lfs store/rekey fail with git ref D/F conflict on notes ref 2026-07-15 19:02:53 +02:00
README.md Add client-side encryption for private-repo LFS objects 2026-07-14 16:01:49 +02:00
RELEASE.md treewide: Spelling 2026-04-30 15:50:29 -04:00
VERSIONING.md build: Add "upload" build step 2024-04-29 10:47:03 +02:00
build.rs hooks: Enable typos, fix reported errors 2026-02-17 11:35:28 +00:00
clippy.toml clippy: Configure lint `unwrap_used` 2026-04-15 10:06:05 +02:00
deny.toml cargo(deny): allow Zlib 2025-12-08 16:43:50 +00:00
flake.lock flake: Fix nixpkgs inputs 2026-05-13 17:23:49 +01:00
flake.nix flake: Add NixOS tests to checks 2026-05-13 17:23:54 +01:00
git-remote-rad.1.adoc treewide: radicle.{xyz → dev,network} 2026-04-27 18:34:30 +02:00
justfile just: checking for ellipses 2026-05-28 16:52:02 +01:00
rad-id.1.adoc treewide: radicle.{xyz → dev,network} 2026-04-27 18:34:30 +02:00
rad-patch.1.adoc rad-patch.1.doc: Fix typos and markup errors 2026-05-28 16:28:16 +01:00
rad.1.adoc treewide: radicle.{xyz → dev,network} 2026-04-27 18:34:30 +02:00
radicle-node.1.adoc radicle-node.1.adoc: Fix markup error 2026-05-28 16:28:52 +01:00
rust-toolchain.toml workspace/rust: 1.90 → 1.95 2026-05-11 12:09:04 +01:00

README.md

❤️🪵

Fork: Git LFS support, backed by IPFS

This is a fork of upstream radicle-dev/heartwood adding Git LFS (large file) support, with large file content stored on each contributor's own local IPFS node rather than a central server. Everything below the horizontal rule is upstream's own README, unchanged. See LFS-IPFS.md for the full design, troubleshooting, and background — this section is just the quick start.

The LFS byte-transfer logic lives in a separate, small companion repository: radicle-lfs-transfer, included here as a git submodule.

Dependencies (Arch Linux)

# To build and install rad/radicle-node/radicle-lfs-transfer
sudo pacman -S --needed rust git openssh base-devel

# To actually use Git LFS (not needed to build/install anything)
sudo pacman -S --needed git-lfs kubo

On other distributions: a Rust toolchain (e.g. via rustup), Git, OpenSSH, a C toolchain — and, only for using rad lfs, Git LFS and Kubo.

Zero to usable

# Clone with the submodule
git clone --branch rad-lfs-ipfs --recurse-submodules \
  ssh://git@git.hswro.org:9022/mab122/radicle-heartwood-lfs.git
cd radicle-heartwood-lfs

# Build & install rad, radicle-node, git-remote-rad, and rad-lfs-transfer to one place
cargo install --path crates/radicle-cli --force --locked --root ~/.radicle
cargo install --path crates/radicle-node --force --locked --root ~/.radicle
cargo install --path crates/radicle-remote-helper --force --locked --root ~/.radicle
cargo install --path radicle-lfs-transfer --force --locked --root ~/.radicle

# Add the install root to your PATH (e.g. in ~/.bashrc / ~/.zshrc)
export PATH="$HOME/.radicle/bin:$PATH"

# Verify
rad --version

From here, use rad exactly as upstream describes below (rad auth, rad init, etc). The only new commands are rad lfs init (run once per repository you want large-file support in) and rad lfs rekey (run after granting a new collaborator access to a private repository, so they can decrypt previously-committed LFS objects too) — see LFS-IPFS.md for that workflow and how private-repo content gets encrypted before it reaches IPFS. Nothing above requires IPFS; Git LFS support specifically needs a running ipfs daemon, and rad lfs init will tell you plainly if one isn't reachable rather than failing confusingly later.


Radicle Heartwood Protocol & Stack

Heartwood is the third iteration of the Radicle Protocol, a powerful peer-to-peer code collaboration and publishing stack. The repository contains a full implementation of Heartwood, complete with a user-friendly command-line interface (rad) and network daemon (radicle-node).

Radicle was designed to be a secure, decentralized and powerful alternative to code forges such as GitHub and GitLab that preserves user sovereignty and freedom.

See the Radicle home page for general information, and the Zulip chat to talk to the project.

See the Protocol Guide for an in-depth description of how Radicle works.

Installation

Requirements

  • Linux or Unix based operating system.
  • Git 2.34 or later
  • OpenSSH 9.1 or later with ssh-agent

📀 From binaries

Requires curl and tar.

Run the following command to install the latest binary release:

curl -sSf https://radicle.dev/install | sh

Or visit our download page.

📦 From source

Requires the Rust toolchain.

You can install the Radicle stack from source, by running the following commands from inside this repository:

cargo install --path crates/radicle-cli --force --locked --root ~/.radicle
cargo install --path crates/radicle-node --force --locked --root ~/.radicle
cargo install --path crates/radicle-remote-helper --force --locked --root ~/.radicle

Or directly from our seed node:

cargo install --force --locked --root ~/.radicle \
    --git https://seed.radicle.dev/z3gqcJUoA1n9HaHKufZs5FCSGazv5.git \
    crates/radicle-cli crates/radicle-node crates/radicle-remote-helper

Running

Systemd unit files are provided for the node under the /systemd folder. They can be used as a starting point for further customization.

For running in debug mode, see HACKING.md.

Feedback

If you have feedback, feel free to create issues using rad issue, join our Zulip, or email feedback@radicle.dev. Emails sent to this address are automatically posted to our public #feedback channel on Zulip, revealing the From header (which usually contains your name and email address). This allows us to discuss your feedback on Zulip, and, if necessary, respond to you via email.

Contributing

See CONTRIBUTING.md and HACKING.md for an introduction to contributing to Radicle.

License

Radicle is distributed under the terms of both the MIT license and the Apache License (Version 2.0).

See LICENSE-APACHE and LICENSE-MIT for details.