set_local_db/set_dot_env diffs can contain secrets (connection
strings), so printing them unconditionally on every up/down leaked
credentials to stdout. Default output is now a line-count summary;
pass -v/--verbose to see the actual before/after lines.
git checkout fires post-checkout even for a single-file checkout
(flag=0), which was tripping an rsync hook in the target repo. Read
the committed blob with git cat-file instead and write it directly -
plumbing, no worktree update, no hooks - with a test that plants a
post-checkout hook and asserts it never runs.
Fix set_local_db/set_dot_env unconditionally stripping (then forcing)
the file's trailing newline: they now detect whether the source file
originally ended in a newline and reproduce that on write, verified
against both the newline and no-newline cases.
Replace the reverse-toggle computation for connections.env on `down`
with a straight `git checkout`, so the file always ends up
byte-for-byte identical to HEAD instead of relying on toggle logic to
get it exactly right. Both git call sites now go through a shared
helper that checks the process exit status and errors out instead of
silently reporting success on a failed checkout/update-index, with
test coverage against real temporary git repos.
Drop the --legacy flag: set_local_db and toggle_index now run
unconditionally instead of only when -l was passed, since that was the
flag's only effect.
Fix set_dot_env writing the connection/RCC_CONNECTION line twice with
opposing polarity (once from the #docker pass, once from the #cidb
pass), which flipped it to the wrong value. Collapsed the three
separate open/read/write passes into one, toggling both sections and
the connection line in a single scan so the connection line is only
ever touched once.
toggle_index ran git checkout on connections.env whenever going
down, discarding whatever set_local_db had just written and
restoring whatever format happens to be committed. This silently
undid the RCC_/legacy dual-format toggle. update-index still marks
the file assume-unchanged/no-assume-unchanged; the checkout is gone.
set_local_db, toggle_after_line and set_dot_env now return a
FileChange (path + before/after line pairs) instead of (), and main
prints it after each toggle so 'up'/'down' shows exactly what the
program rewrote in each env file.
connections.env and local .env are transitioning from dotted keys
(ci.db.master.ip, connection) to upper-cased RCC_-prefixed keys
(RCC_CI_DB_MASTER_IP, RCC_CONNECTION). Both forms are matched and
toggled during the migration, so old branches keep working while
new ones use the new format.