git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH 01/15] remote: validate --force-with-lease <refname> argument

From
Jon Simons <jon@jonsimons.org>
Date
Oct 9, 2026, 19:29 UTC
Message-ID
<20261009192953.81794-2-jon@jonsimons.org>
In-Reply-To
<20261009192953.81794-1-jon@jonsimons.org>

Use check_refname_format() to validate the <refname> component of 'git push --force-with-lease=<refname>[:<expect>]'.

apply_push_cas() will silently ignore a lease entry that does not match any remote ref. And today "./refs/heads/main" will happen to be matched with "refs/heads/main" due to refname_match() usage of mkpath(), whose cleanup_path() strips leading "./".

An upcoming commit removes mkpath() from refname_match(), after which there is no unintentional match in this situation, so that the lease is ignored instead of applied. Reject an invalid refname now to make this situation fail fast both before and after that change.

Signed-off-by: Jon Simons <jon@jonsimons.org>
---
 remote.c            | 2 ++
 t/t5533-push-cas.sh | 9 +++++++++
 2 files changed, 11 insertions(+)
diff --git a/remote.c b/remote.c
index 71170f36a9..114d4d983c 100644
--- a/remote.c
+++ b/remote.c
@@ -2740,6 +2740,8 @@ static int parse_push_cas_option(struct push_cas_option *cas, const char *arg, i
 	/* "--<option>=refname" or "--<option>=refname:value" */
 	colon = strchrnul(arg, ':');
 	entry = add_cas_entry(cas, arg, colon - arg);
+	if (check_refname_format(entry->refname, REFNAME_ALLOW_ONELEVEL))
+		return error(_("'%s' is not a valid refname"), entry->refname);
 	if (!*colon)
 		entry->use_tracking = 1;
 	else if (!colon[1])
diff --git a/t/t5533-push-cas.sh b/t/t5533-push-cas.sh
index e6e1360a42..f6eafee7ad 100755
--- a/t/t5533-push-cas.sh
+++ b/t/t5533-push-cas.sh
@@ -63,6 +63,15 @@ test_expect_success setup '
 	test_commit C
 '
 
+test_expect_success 'push --force-with-lease rejects invalid refname' '
+	setup_srcdst_basic &&
+	(
+		cd dst &&
+		test_must_fail git push --force-with-lease=./refs/heads/main origin main 2>err &&
+		test_grep "is not a valid refname" err
+	)
+'
+
 test_expect_success 'push to update (protected)' '
 	setup_srcdst_basic &&
 	(
-- 
2.55.0
Previous: Jon SimonsNext: Jon Simons
Message 2 of 18 in “push: speed up client-side refspec matching”
  1. 00/15 push: speed up client-side refspec matchingJon Simons, Oct 9, 2026
  2. 01/15 remote: validate --force-with-lease <refname> argumentJon Simons, Oct 9, 2026
  3. 02/15 t5516: demonstrate push with "./"-prefixed sourceJon Simons, Oct 9, 2026
  4. 03/15 t5510: document fetch with "./"-prefixed branch.<name>.mergeJon Simons, Oct 9, 2026
  5. 04/15 t/perf: add explicit delete refspec matching testJon Simons, Oct 9, 2026
  6. 05/15 refs: stop using mkpath() in refname_match()Jon Simons, Oct 9, 2026
  7. 06/15 remote: use strmap for check_push_refs()Jon Simons, Oct 9, 2026
  8. 07/15 t5516: test pushing two refspecs creating the same new branchJon Simons, Oct 9, 2026
  9. 08/15 t5408, t5410: test duplicate updates without relying on the clientJon Simons, Oct 9, 2026
  10. 09/15 t5408: check refspec order with distinct destinationsJon Simons, Oct 9, 2026
  11. 10/15 t5408: expect client-side error for duplicate destinationsJon Simons, Oct 9, 2026
  12. 11/15 remote: reject duplicate destinations on an empty remoteJon Simons, Oct 9, 2026
  13. 12/15 remote: use strmap for match_explicit_refs()Jon Simons, Oct 9, 2026
  14. 13/15 t/perf: measure --force-with-lease in p5516Jon Simons, Oct 9, 2026
  15. 14/15 remote: restructure apply_push_cas() loopsJon Simons, Oct 9, 2026
  16. 15/15 remote: use strmap for apply_push_cas()Jon Simons, Oct 9, 2026
  17. Kristoffer HaugsbakkOct 9, 2026
  18. Jon SimonsOct 11, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.