Re: [PATCH 0/2] push: fix --force-if-includes consulting wrong ref
- From
Ben Knoble <ben.knoble@gmail.com>
- Date
- Sep 5, 2026, 18:59 UTC
- Message-ID
- <D798198C-5F97-4701-9050-7868B6482214@gmail.com>
- In-Reply-To
- <20260904210122.431757-1-tyler@tylercipriani.com>
Show 11 quoted lines
> Le 4 sept. 2026 à 17:01, Tyler Cipriani <tyler@tylercipriani.com> a écrit : > > --force-if-includes has been checking the reflog of the local branch named > after the destination branch regardless of what's being pushed. This can cause > false rejections or unintended data loss. > > False rejection has been reported twice that I could find: > > - 2023-07-26 - Stefan Haller reported local branch with a different name > false rejection[0] > - 2025-05-08 - D. Ben Knoble reported detached HEAD false rejection[1]
Aha. I’d nearly forgotten that mail, and have since adjusted to some intuition of when to force-if-includes.
I’d be grateful to not need such potentially-buggy intuition :)
Show 31 quoted lines
> The same root cause can result in data loss: when a same-name local branch > contains the remote tip but you --force-if-includes push an unrelated branch, > clobbering the remote repo. PoCs are in t/t5533-push-cas.sh -- new test cases > fail against maint, but pass with patches applied. > > Existing tests covered refspecs with different names for --force-with-lease, > but missed --force-if-includes. New patches cover: > > - allow forced-update using refspec with different-named local branch > - allow same as above, but with HEAD > - reject force-update using refspec with different-named local branch lacking > branch tip > - reject same as above using HEAD > - reject detached HEAD > > Open question: the detached HEAD case. I opted to reject, since it seems like > it might be surprising to allow in the case where you were just on a branch > without the the tip of a remote ref, removed the last commit with git checkout > HEAD^ and pushed with --force-if-includes and it allowed a destructive push. > I made a separate patch showing different advice for that case (since a > git pull won't help). > > Based on maint since this is a bugfix. Happy to split patches any way > that's helpful. > > [0]: <https://lore.kernel.org/git/f51c73ed-eb03-83ca-fb31-d3e2645c9a63@haller-berlin.de> > [1]: <https://lore.kernel.org/git/CALnO6CCk0SgwObQRnpd5Pt_DvCKF8dBmyVHivU6Nr_O-GusGLA@mail.gmail.com> > > Tyler Cipriani (2): > push: check pushed ref for --force-if-includes > push: fix --force-if-includes detached HEAD advice
Thanks for the advice changes! One small nit on the first patch you can ignore if you choose.
At first I hoped we might be able to stop rejecting detached HEAD pushes, but some further thought begs the question: what reflog would we use? HEAD’s is too broad :)
So this may be all we can do for now.
At least I can replace my intuition with reading the error message again.