git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH] Fix "commit-msg" hook unexpectedly called for "git pull --no-verify"

From
Alex Riesen <alexander.riesen@cetitec.com>
Date
Oct 26, 2021, 12:11 UTC
Message-ID
<YXfwanz3MynCLDmn@pflmari>

The option is incorrectly translated to "--no-verify-signatures", which causes the unexpected effect of the hook being called. And an even more unexpected effect of disabling verification of signatures.

The manual page describes the option to behave same as the similarly named option of "git merge", which seems to be the original intention of this option in the "pull" command.

Signed-off-by: Alexander Riesen <raa.lkml@gmail.com>
---
 builtin/pull.c          |  6 ++++++
 t/t5521-pull-options.sh | 11 +++++++++++
 2 files changed, 17 insertions(+)
diff --git a/builtin/pull.c b/builtin/pull.c
index 425950f469..428baea95b 100644
--- a/builtin/pull.c
+++ b/builtin/pull.c
@@ -84,6 +84,7 @@ static char *opt_edit;
 static char *cleanup_arg;
 static char *opt_ff;
 static char *opt_verify_signatures;
+static char *opt_no_verify;
 static int opt_autostash = -1;
 static int config_autostash;
 static int check_trust_level = 1;
@@ -160,6 +161,9 @@ static struct option pull_options[] = {
 	OPT_PASSTHRU(0, "ff-only", &opt_ff, NULL,
 		N_("abort if fast-forward is not possible"),
 		PARSE_OPT_NOARG | PARSE_OPT_NONEG),
+	OPT_PASSTHRU(0, "no-verify", &opt_no_verify, NULL,
+		N_("bypass pre-merge-commit and commit-msg hooks"),
+		PARSE_OPT_NOARG | PARSE_OPT_NONEG),
 	OPT_PASSTHRU(0, "verify-signatures", &opt_verify_signatures, NULL,
 		N_("verify that the named commit has a valid GPG signature"),
 		PARSE_OPT_NOARG),
@@ -688,6 +692,8 @@ static int run_merge(void)
 		strvec_pushf(&args, "--cleanup=%s", cleanup_arg);
 	if (opt_ff)
 		strvec_push(&args, opt_ff);
+	if (opt_no_verify)
+		strvec_push(&args, opt_no_verify);
 	if (opt_verify_signatures)
 		strvec_push(&args, opt_verify_signatures);
 	strvec_pushv(&args, opt_strategies.v);
diff --git a/t/t5521-pull-options.sh b/t/t5521-pull-options.sh
index db1a381cd9..0eb1916175 100755
--- a/t/t5521-pull-options.sh
+++ b/t/t5521-pull-options.sh
@@ -225,4 +225,15 @@ test_expect_success 'git pull --no-signoff flag cancels --signoff flag' '
 	test_must_be_empty actual
 '
 
+test_expect_success 'git pull --no-verify flag passed to merge' '
+	test_when_finished "rm -fr src dst actual" &&
+	git init src &&
+	test_commit -C src one &&
+	git clone src dst &&
+	echo false >dst/.git/hooks/commit-msg &&
+	chmod +x dst/.git/hooks/commit-msg &&
+	test_commit -C src two &&
+	git -C dst pull --no-ff --no-verify
+'
+
 test_done
-- 
2.31.0.30.g60a470ee5c
Next: Jeff King
Message 1 of 22 in “Fix "commit-msg" hook unexpectedly called for "git pull --no-verify"”
  1. Fix "commit-msg" hook unexpectedly called for "git pull --no-verify"Alex Riesen, Oct 26, 2021
  2. Jeff KingOct 26, 2021
  3. Fix "commit-msg" hook unexpectedly called for "git pull --no-verify"Alex Riesen, Oct 27, 2021
  4. Jeff KingOct 27, 2021
  5. Alex RiesenOct 27, 2021
  6. Jeff KingOct 27, 2021
  7. Remove negation from the merge option "--no-verify"Alex Riesen, Oct 27, 2021
  8. Junio C HamanoOct 27, 2021
  9. Alex RiesenOct 28, 2021
  10. Remove negation from the commit and merge option "--no-verify"Alex Riesen, Oct 28, 2021
  11. Phillip WoodOct 28, 2021
  12. Alex RiesenOct 28, 2021
  13. 2/2 Fix "commit-msg" hook unexpectedly called for "git pull --no-verify"Alex Riesen, Oct 28, 2021
  14. Junio C HamanoOct 28, 2021
  15. Alex RiesenOct 28, 2021
  16. Junio C HamanoOct 28, 2021
  17. Alex RiesenOct 29, 2021
  18. Alex RiesenOct 28, 2021
  19. Phillip WoodOct 29, 2021
  20. Document positive variant of commit and merge option "--no-verify"Alex Riesen, Oct 29, 2021
  21. Phillip WoodNov 1, 2021
  22. Junio C HamanoOct 27, 2021

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.