[PATCH v5 0/3] push: check pushed ref for --force-if-includes
- From
Tyler Cipriani <tyler@tylercipriani.com>
- Date
- Sep 15, 2026, 23:33 UTC
- Message-ID
- <20260915233305.334115-1-tyler@tylercipriani.com>
- In-Reply-To
- <20260904210122.431757-1-tyler@tylercipriani.com>
Changes since v4:
- Add patch to series: Fix case where fast-forward pushes are being rejected by --force-if-includes: an existing bug that I made worse with the previous changes in my series. - Add tests to cover allowed fast-forward merges when using --force-if-includes
Changes since v3:
- check_if_includes_upstream unconditionally resolves peer_ref with RESOLVE_REF_READING, now all non-branch ref pushes will be rejected when using --force-if-includes - add test for --force-if-includes tag push 1/3 - clarify log message problem example 1/3 - clarify deletion in log message 1/3 - add missing blank line between test cases - shorten long line in builtin/push.c - reword advice-message wording 2/3 - rename 2/2 from "detached HEAD" to "non-branch"
Changes since v2:
- Correct patch threading of 1/3 and 2/3 to reply to cover letter of current patchset vs. cover letter of the initial iteration.
Changes since v1:
- Clarify in log message 1/3 that --force-if-includes will reject a detached HEAD today (when the same-named local branch lacks the remote tip). And note that this change makes it explicit to always reject the detached HEAD case.
--force-if-includes has been checking the reflog of the local branch named after the destination branch regardless of what's being pushed. This can cause false rejections or unintended data loss.
False rejection has been reported twice that I could find:
- 2023-07-26 - Stefan Haller reported local branch with a different name
false rejection[0]
- 2025-05-08 - D. Ben Knoble reported detached HEAD false rejection[1]The same root cause can result in data loss: when a same-name local branch contains the remote tip but you --force-if-includes push an unrelated branch, clobbering the remote repo. PoCs are in t/t5533-push-cas.sh -- new test cases fail against maint, but pass with patches applied.
Existing tests covered refspecs with different names for --force-with-lease, but missed --force-if-includes. New patches cover:
- allow fast-forward push using --force-if-includes with an expired reflog - allow fast-forward push of a tag on a different-named local branch - allow forced-update using refspec with different-named local branch - allow same as above, but with HEAD - reject force-update using refspec with different-named local branch lacking branch tip - reject same as above using HEAD - reject detached HEAD
Resolved question: the detached HEAD case; HEAD's reflog was considered and rejected as too broad for purpose in the original review. cf. [2]
[0]: <https://lore.kernel.org/git/f51c73ed-eb03-83ca-fb31-d3e2645c9a63@haller-berlin.de> [1]: <https://lore.kernel.org/git/CALnO6CCk0SgwObQRnpd5Pt_DvCKF8dBmyVHivU6Nr_O-GusGLA@mail.gmail.com> [2]: <https://lore.kernel.org/git/CAHLx=O=tVhtiZpaRP9TpfiBfOMS2xPe3c3=mC3VNEdBrLOioFg@mail.gmail.com>
Tyler Cipriani (3): push: check pushed ref for --force-if-includes push: fix --force-if-includes non-branch advice push: --force-if-includes should allow fast-forward
Documentation/config/advice.adoc | 4 ++ advice.c | 1 + advice.h | 1 + builtin/push.c | 17 +++++ builtin/send-pack.c | 5 ++ remote.c | 43 ++++++++++-- remote.h | 10 ++- send-pack.c | 1 + t/t5533-push-cas.sh | 115 ++++++++++++++++++++++++++++++- transport-helper.c | 5 ++ transport.c | 8 +++ transport.h | 1 + 12 files changed, 203 insertions(+), 8 deletions(-)
Range-diff against v4: 1: e7912c3fd0 = 1: e7912c3fd0 push: check pushed ref for --force-if-includes 2: 2a455d8a76 = 2: 2a455d8a76 push: fix --force-if-includes non-branch advice -: ---------- > 3: 1776f8d572 push: --force-if-includes should allow fast-forward
-- 2.47.3