threads / patch / 63064

v3, 8 partsrefs/files: remove redundant check in split_symref_update()

Subject: [PATCH v3 1/8] refs/files: remove redundant check in split_symref_update()

## tl;dr

59 messages between Mar 5, 2025 and Jun 3, 2025. Diffs are folded; open one to read it.

replies: 58people: 7as markdown or json

Karthik Nayak· Mar 5, 2025, 17:38 UTC · lore

[PATCH v3 0/8] refs: introduce support for partial reference transactions

 Documentation/git-update-ref.adoc |  17 +-
 builtin/fetch.c                   |   2 +-
 builtin/update-ref.c              |  67 ++++-
 refs.c                            | 162 ++++++++++--
 refs.h                            |  76 ++++--
 refs/files-backend.c              | 314 +++++++++++-------------
 refs/packed-backend.c             |  69 +++---
 refs/refs-internal.h              |  51 +++-
 refs/reftable-backend.c           | 502 +++++++++++++++++++-------------------
 t/t1400-update-ref.sh             | 233 ++++++++++++++++++
 10 files changed, 971 insertions(+), 522 deletions(-)
Karthik Nayak (8):
      refs/files: remove redundant check in split_symref_update()
      refs: move duplicate refname update check to generic layer
      refs/files: remove duplicate duplicates check
      refs/reftable: extract code from the transaction preparation
      refs: introduce enum-based transaction error types
      refs: implement partial reference transaction support
      refs: support partial update rejections during F/D checks
      update-ref: add --allow-partial flag for stdin mode

Git's reference updates are traditionally all or nothing - when updating multiple references in a transaction, either all updates succeed or none do. While this behavior is generally desirable, it can be limiting in certain scenarios, particularly with the reftable backend where batching multiple reference updates is more efficient than performing them sequentially.

This series introduces support for partial reference transactions, allowing individual reference updates to fail while letting others proceed. This capability is exposed through git-update-ref's `--allow-partial` flag, which can be used in `--stdin` mode to batch updates and handle failures gracefully.

The changes are structured to carefully build up this functionality:

First, we clean up and consolidate the reference update checking logic. This includes removing duplicate checks in the files backend and moving refname tracking to the generic layer, which simplifies the codebase and prepares it for the new feature.

We then restructure the reftable backend's transaction preparation code, extracting the update validation logic into a dedicated function. This not only improves code organization but sets the stage for implementing partial transaction support.

To ensure we only skip errors which are user-oriented, we introduce typed errors for transactions with 'enum ref_transaction_error'. We extend the existing errors to include other scenarios and use this new errors throughout the refs code.

With this groundwork in place, we implement the core partial transaction support in the refs subsystem. This adds the necessary infrastructure to track and report rejected updates while allowing transactions to proceed. All reference backends are modified to support this behavior when enabled.

Finally, we expose this functionality to users through git-update-ref(1)'s `--allow-partial` flag, complete with test coverage and documentation. The flag is specifically limited to `--stdin` mode where batching multiple updates is most relevant.

This enhancement improves Git's flexibility in handling reference updates while maintaining the safety of atomic transactions by default. It's particularly valuable for tools and workflows that need to handle reference update failures gracefully without abandoning the entire batch of updates.

This series is based on top of b838bf1938 (Merge branch 'master' of https://github.com/j6t/gitk, 2025-02-20) with Patrick's series 'refs: batch refname availability checks' [1] merged in.

[1]: https://lore.kernel.org/all/20250217-pks-update-ref-optimization-v1-0-a2b6d87a24af@pks.im/
---
Changes in v3:
- Changed 'transaction_error' to 'ref_transaction_error' along with the
  error names. Removed 'TRANSACTION_OK' since it can potentially be
  missed instead of simply 'return 0'.
- Rename 'ref_transaction_set_rejected' to
  'ref_transaction_maybe_set_rejected' and move logic around error
  checks to within this function.
- Add a new struct 'ref_transaction_rejections' to track the rejections
  within a transaction. This allows us to only iterate over rejected
  updates.
- Add a new commit to also support partial transactions within the
  batched F/D checks.
- Remove NUL delimited outputs in 'git-update-ref(1)'.
- Remove translations for plumbing outputs.
- Other small cleanups in the commit message and code.
Changes in v2:
- Introduce and use structured errors. This consolidates the errors
  and their handling between the ref backends.
- In the previous version, we skipped over all failures. This include
  system failures such as low memory or IO problems. Let's instead, only
  skip user-oriented failures, such as invalid old OID and so on.
- Change the rejection function name to `ref_transaction_set_rejected()`.
- Modify the commit messages and documentation to be a little more
  verbose.
- Link to v1: https://lore.kernel.org/r/20250207-245-partially-atomic-ref-updates-v1-0-e6a3690ff23a@gmail.com
Range-diff versus v2:
1:  a7a5f8c752 = 1:  1bd0878fd7 refs/files: remove redundant check in split_symref_update()
2:  61ebc1e133 = 2:  92181469bf refs: move duplicate refname update check to generic layer
3:  f54f3d7722 = 3:  6fb0b6b03d refs/files: remove duplicate duplicates check
4:  463e043cd2 = 4:  07788f97e9 refs/reftable: extract code from the transaction preparation
5:  baa94ddfb6 ! 5:  2f872b650f refs: introduce enum-based transaction error types
    @@ Commit message
         refs: introduce enum-based transaction error types
     
         Replace preprocessor-defined transaction errors with a strongly-typed
    -    enum `transaction_error`. This change:
    +    enum `ref_transaction_error`. This change:
     
           - Improves type safety and function signature clarity.
           - Makes error handling more explicit and discoverable.
    @@ Commit message
     
         Signed-off-by: Karthik Nayak <karthik.188@gmail.com>
     
    + ## builtin/fetch.c ##
    +@@ builtin/fetch.c: static int s_update_ref(const char *action,
    + 		switch (ref_transaction_commit(our_transaction, &err)) {
    + 		case 0:
    + 			break;
    +-		case TRANSACTION_NAME_CONFLICT:
    ++		case REF_TRANSACTION_ERROR_NAME_CONFLICT:
    + 			ret = STORE_REF_ERROR_DF_CONFLICT;
    + 			goto out;
    + 		default:
    +
      ## refs.c ##
    +@@ refs.c: int refs_update_symref_extended(struct ref_store *refs, const char *ref,
    + 					   REF_NO_DEREF, logmsg, &err))
    + 			goto error_return;
    + 		prepret = ref_transaction_prepare(transaction, &err);
    +-		if (prepret && prepret != TRANSACTION_CREATE_EXISTS)
    ++		if (prepret && prepret != REF_TRANSACTION_ERROR_CREATE_EXISTS)
    + 			goto error_return;
    + 	} else {
    + 		if (ref_transaction_update(transaction, ref, NULL, NULL,
    +@@ refs.c: int refs_update_symref_extended(struct ref_store *refs, const char *ref,
    + 		}
    + 	}
    + 
    +-	if (prepret == TRANSACTION_CREATE_EXISTS)
    ++	if (prepret == REF_TRANSACTION_ERROR_CREATE_EXISTS)
    + 		goto cleanup;
    + 
    + 	if (ref_transaction_commit(transaction, &err))
    +@@ refs.c: int ref_transaction_prepare(struct ref_transaction *transaction,
    + 
    + 	string_list_sort(&transaction->refnames);
    + 	if (ref_update_reject_duplicates(&transaction->refnames, err))
    +-		return TRANSACTION_GENERIC_ERROR;
    ++		return REF_TRANSACTION_ERROR_GENERIC;
    + 
    + 	ret = refs->be->transaction_prepare(refs, transaction, err);
    + 	if (ret)
     @@ refs.c: int ref_transaction_commit(struct ref_transaction *transaction,
      	return ret;
      }
    @@ refs.c: int ref_transaction_commit(struct ref_transaction *transaction,
     -				   const struct string_list *skip,
     -				   unsigned int initial_transaction,
     -				   struct strbuf *err)
    -+enum transaction_error refs_verify_refnames_available(struct ref_store *refs,
    -+						      const struct string_list *refnames,
    -+						      const struct string_list *extras,
    -+						      const struct string_list *skip,
    -+						      unsigned int initial_transaction,
    -+						      struct strbuf *err)
    ++enum ref_transaction_error refs_verify_refnames_available(struct ref_store *refs,
    ++					  const struct string_list *refnames,
    ++					  const struct string_list *extras,
    ++					  const struct string_list *skip,
    ++					  unsigned int initial_transaction,
    ++					  struct strbuf *err)
      {
      	struct strbuf dirname = STRBUF_INIT;
      	struct strbuf referent = STRBUF_INIT;
      	struct ref_iterator *iter = NULL;
      	struct strset dirnames;
     -	int ret = -1;
    -+	int ret = TRANSACTION_NAME_CONFLICT;
    ++	int ret = REF_TRANSACTION_ERROR_NAME_CONFLICT;
      
      	/*
      	 * For the sake of comments in this function, suppose that
    @@ refs.c: int refs_verify_refnames_available(struct ref_store *refs,
     -				  const struct string_list *skip,
     -				  unsigned int initial_transaction,
     -				  struct strbuf *err)
    -+enum transaction_error refs_verify_refname_available(struct ref_store *refs,
    -+						     const char *refname,
    -+						     const struct string_list *extras,
    -+						     const struct string_list *skip,
    -+						     unsigned int initial_transaction,
    -+						     struct strbuf *err)
    ++enum ref_transaction_error refs_verify_refname_available(
    ++	struct ref_store *refs,
    ++	const char *refname,
    ++	const struct string_list *extras,
    ++	const struct string_list *skip,
    ++	unsigned int initial_transaction,
    ++	struct strbuf *err)
      {
      	struct string_list_item item = { .string = (char *) refname };
      	struct string_list refnames = {
    @@ refs.c: int ref_update_has_null_new_value(struct ref_update *update)
      
     -int ref_update_check_old_target(const char *referent, struct ref_update *update,
     -				struct strbuf *err)
    -+enum transaction_error ref_update_check_old_target(const char *referent,
    -+					      struct ref_update *update,
    -+					      struct strbuf *err)
    ++enum ref_transaction_error ref_update_check_old_target(const char *referent,
    ++						       struct ref_update *update,
    ++						       struct strbuf *err)
      {
      	if (!update->old_target)
      		BUG("called without old_target set");
    - 
    +@@ refs.c: int ref_update_check_old_target(const char *referent, struct ref_update *update,
      	if (!strcmp(referent, update->old_target))
    --		return 0;
    -+		return TRANSACTION_OK;
    + 		return 0;
      
     -	if (!strcmp(referent, ""))
     +	if (!strcmp(referent, "")) {
    @@ refs.c: int ref_update_has_null_new_value(struct ref_update *update)
     -	else
     -		strbuf_addf(err, "verifying symref target: '%s': "
     -			    "is at %s but expected %s",
    -+		return TRANSACTION_NONEXISTENT_REF;
    ++		return REF_TRANSACTION_ERROR_NONEXISTENT_REF;
     +	}
     +
     +	strbuf_addf(err, "verifying symref target: '%s': is at %s but expected %s",
      			    ref_update_original_update_refname(update),
      			    referent, update->old_target);
     -	return -1;
    -+	return TRANSACTION_INCORRECT_OLD_VALUE;
    ++	return REF_TRANSACTION_ERROR_INCORRECT_OLD_VALUE;
      }
      
      struct migration_data {
    @@ refs.h: struct worktree;
      const char *ref_storage_format_to_name(enum ref_storage_format ref_storage_format);
      
     +/*
    -+ * enum transaction_error represents the following return codes:
    -+ * TRANSACTION_OK: success code.
    -+ * TRANSACTION_GENERIC_ERROR error_code: default error code.
    -+ * TRANSACTION_NAME_CONFLICT error_code: ref name conflict like A vs A/B.
    -+ * TRANSACTION_CREATE_EXISTS error_code: ref to be created already exists.
    -+ * TRANSACTION_NONEXISTENT_REF error_code: ref expected but doesn't exist.
    -+ * TRANSACTION_INCORRECT_OLD_VALUE error_code: provided old_oid or old_target of
    ++ * enum ref_transaction_error represents the following return codes:
    ++ * REF_TRANSACTION_ERROR_GENERIC error_code: default error code.
    ++ * REF_TRANSACTION_ERROR_NAME_CONFLICT error_code: ref name conflict like A vs A/B.
    ++ * REF_TRANSACTION_ERROR_CREATE_EXISTS error_code: ref to be created already exists.
    ++ * REF_TRANSACTION_ERROR_NONEXISTENT_REF error_code: ref expected but doesn't exist.
    ++ * REF_TRANSACTION_ERROR_INCORRECT_OLD_VALUE error_code: provided old_oid or old_target of
     + * reference doesn't match actual.
    -+ * TRANSACTION_INVALID_NEW_VALUE error_code: provided new_oid or new_target is
    ++ * REF_TRANSACTION_ERROR_INVALID_NEW_VALUE error_code: provided new_oid or new_target is
     + * invalid.
    -+ * TRANSACTION_EXPECTED_SYMREF error_code: expected ref to be symref, but is a
    ++ * REF_TRANSACTION_ERROR_EXPECTED_SYMREF error_code: expected ref to be symref, but is a
     + * regular ref.
     + */
    -+enum transaction_error {
    -+	TRANSACTION_OK = 0,
    -+	TRANSACTION_GENERIC_ERROR = -1,
    -+	TRANSACTION_NAME_CONFLICT = -2,
    -+	TRANSACTION_CREATE_EXISTS = -3,
    -+	TRANSACTION_NONEXISTENT_REF = -4,
    -+	TRANSACTION_INCORRECT_OLD_VALUE = -5,
    -+	TRANSACTION_INVALID_NEW_VALUE = -6,
    -+	TRANSACTION_EXPECTED_SYMREF = -7,
    ++enum ref_transaction_error {
    ++	REF_TRANSACTION_ERROR_GENERIC = -1,
    ++	REF_TRANSACTION_ERROR_NAME_CONFLICT = -2,
    ++	REF_TRANSACTION_ERROR_CREATE_EXISTS = -3,
    ++	REF_TRANSACTION_ERROR_NONEXISTENT_REF = -4,
    ++	REF_TRANSACTION_ERROR_INCORRECT_OLD_VALUE = -5,
    ++	REF_TRANSACTION_ERROR_INVALID_NEW_VALUE = -6,
    ++	REF_TRANSACTION_ERROR_EXPECTED_SYMREF = -7,
     +};
     +
      /*
    @@ refs.h: int refs_read_symbolic_ref(struct ref_store *ref_store, const char *refn
     -				  const struct string_list *skip,
     -				  unsigned int initial_transaction,
     -				  struct strbuf *err);
    -+enum transaction_error refs_verify_refname_available(struct ref_store *refs,
    -+						     const char *refname,
    -+						     const struct string_list *extras,
    -+						     const struct string_list *skip,
    -+						     unsigned int initial_transaction,
    -+						     struct strbuf *err);
    ++enum ref_transaction_error refs_verify_refname_available(struct ref_store *refs,
    ++						 const char *refname,
    ++						 const struct string_list *extras,
    ++						 const struct string_list *skip,
    ++						 unsigned int initial_transaction,
    ++						 struct strbuf *err);
      
      /*
       * Same as `refs_verify_refname_available()`, but checking for a list of
    @@ refs.h: int refs_read_symbolic_ref(struct ref_store *ref_store, const char *refn
     -				   const struct string_list *skip,
     -				   unsigned int initial_transaction,
     -				   struct strbuf *err);
    -+enum transaction_error refs_verify_refnames_available(struct ref_store *refs,
    -+						      const struct string_list *refnames,
    -+						      const struct string_list *extras,
    -+						      const struct string_list *skip,
    -+						      unsigned int initial_transaction,
    -+						      struct strbuf *err);
    ++enum ref_transaction_error refs_verify_refnames_available(struct ref_store *refs,
    ++					  const struct string_list *refnames,
    ++					  const struct string_list *extras,
    ++					  const struct string_list *skip,
    ++					  unsigned int initial_transaction,
    ++					  struct strbuf *err);
      
      int refs_ref_exists(struct ref_store *refs, const char *refname);
      
    @@ refs.h: int ref_transaction_verify(struct ref_transaction *transaction,
       * any needed locks, check preconditions, etc.; basically, do as much
     
      ## refs/files-backend.c ##
    +@@ refs/files-backend.c: static void unlock_ref(struct ref_lock *lock)
    +  * broken, lock the reference anyway but clear old_oid.
    +  *
    +  * Return 0 on success. On failure, write an error message to err and
    +- * return TRANSACTION_NAME_CONFLICT or TRANSACTION_GENERIC_ERROR.
    ++ * return REF_TRANSACTION_ERROR_NAME_CONFLICT or REF_TRANSACTION_ERROR_GENERIC.
    +  *
    +  * Implementation note: This function is basically
    +  *
     @@ refs/files-backend.c: static void unlock_ref(struct ref_lock *lock)
       *   avoided, namely if we were successfully able to read the ref
       * - Generate informative error messages in the case of failure
    @@ refs/files-backend.c: static void unlock_ref(struct ref_lock *lock)
     -			struct strbuf *referent,
     -			unsigned int *type,
     -			struct strbuf *err)
    -+static enum transaction_error lock_raw_ref(struct files_ref_store *refs,
    -+					   const char *refname, int mustexist,
    -+					   struct string_list *refnames_to_check,
    -+					   const struct string_list *extras,
    -+					   struct ref_lock **lock_p,
    -+					   struct strbuf *referent,
    -+					   unsigned int *type,
    -+					   struct strbuf *err)
    - {
    -+	enum transaction_error ret = TRANSACTION_GENERIC_ERROR;
    +-{
    ++static enum ref_transaction_error lock_raw_ref(struct files_ref_store *refs,
    ++					       const char *refname,
    ++					       int mustexist,
    ++					       struct string_list *refnames_to_check,
    ++					       const struct string_list *extras,
    ++					       struct ref_lock **lock_p,
    ++					       struct strbuf *referent,
    ++					       unsigned int *type,
    ++					       struct strbuf *err)
    ++{
    ++	enum ref_transaction_error ret = REF_TRANSACTION_ERROR_GENERIC;
      	struct ref_lock *lock;
      	struct strbuf ref_file = STRBUF_INIT;
      	int attempts_remaining = 3;
    @@ refs/files-backend.c: static int lock_raw_ref(struct files_ref_store *refs,
      				strbuf_reset(err);
      				strbuf_addf(err, "unable to resolve reference '%s'",
      					    refname);
    -+				ret = TRANSACTION_NONEXISTENT_REF;
    ++				ret = REF_TRANSACTION_ERROR_NONEXISTENT_REF;
      			} else {
      				/*
      				 * The error message set by
    + 				 * refs_verify_refname_available() is
    + 				 * OK.
    + 				 */
    +-				ret = TRANSACTION_NAME_CONFLICT;
    ++				ret = REF_TRANSACTION_ERROR_NAME_CONFLICT;
    + 			}
    + 		} else {
    + 			/*
     @@ refs/files-backend.c: static int lock_raw_ref(struct files_ref_store *refs,
      				/* Garden variety missing reference. */
      				strbuf_addf(err, "unable to resolve reference '%s'",
      					    refname);
    -+				ret = TRANSACTION_NONEXISTENT_REF;
    ++				ret = REF_TRANSACTION_ERROR_NONEXISTENT_REF;
      				goto error_return;
      			} else {
      				/*
    @@ refs/files-backend.c: static int lock_raw_ref(struct files_ref_store *refs,
      				/* Garden variety missing reference. */
      				strbuf_addf(err, "unable to resolve reference '%s'",
      					    refname);
    -+				ret = TRANSACTION_NONEXISTENT_REF;
    ++				ret = REF_TRANSACTION_ERROR_NONEXISTENT_REF;
      				goto error_return;
      			} else if (remove_dir_recursively(&ref_file,
      							  REMOVE_DIR_EMPTY_ONLY)) {
     @@ refs/files-backend.c: static int lock_raw_ref(struct files_ref_store *refs,
    - 		string_list_insert(refnames_to_check, refname);
    - 	}
    - 
    --	ret = 0;
    -+	ret = TRANSACTION_OK;
    - 	goto out;
    - 
    - error_return:
    + 					 * The error message set by
    + 					 * verify_refname_available() is OK.
    + 					 */
    +-					ret = TRANSACTION_NAME_CONFLICT;
    ++					ret = REF_TRANSACTION_ERROR_NAME_CONFLICT;
    + 					goto error_return;
    + 				} else {
    + 					/*
     @@ refs/files-backend.c: static int rename_tmp_log(struct files_ref_store *refs, const char *newrefname)
      	return ret;
      }
    @@ refs/files-backend.c: static int rename_tmp_log(struct files_ref_store *refs, co
     -				 struct ref_lock *lock,
     -				 const struct object_id *oid,
     -				 int skip_oid_verification, struct strbuf *err);
    -+static enum transaction_error write_ref_to_lockfile(struct files_ref_store *refs,
    -+						    struct ref_lock *lock,
    -+						    const struct object_id *oid,
    -+						    int skip_oid_verification, struct strbuf *err);
    ++static enum ref_transaction_error write_ref_to_lockfile(struct files_ref_store *refs,
    ++							struct ref_lock *lock,
    ++							const struct object_id *oid,
    ++							int skip_oid_verification,
    ++							struct strbuf *err);
      static int commit_ref_update(struct files_ref_store *refs,
      			     struct ref_lock *lock,
      			     const struct object_id *oid, const char *logmsg,
    @@ refs/files-backend.c: static int files_log_ref_write(struct files_ref_store *ref
     -				 struct ref_lock *lock,
     -				 const struct object_id *oid,
     -				 int skip_oid_verification, struct strbuf *err)
    -+static enum transaction_error write_ref_to_lockfile(struct files_ref_store *refs,
    -+						    struct ref_lock *lock,
    -+						    const struct object_id *oid,
    -+						    int skip_oid_verification,
    -+						    struct strbuf *err)
    ++static enum ref_transaction_error write_ref_to_lockfile(struct files_ref_store *refs,
    ++							struct ref_lock *lock,
    ++							const struct object_id *oid,
    ++							int skip_oid_verification,
    ++							struct strbuf *err)
      {
      	static char term = '\n';
      	struct object *o;
    @@ refs/files-backend.c: static int write_ref_to_lockfile(struct files_ref_store *r
      				lock->ref_name, oid_to_hex(oid));
      			unlock_ref(lock);
     -			return -1;
    -+			return TRANSACTION_INVALID_NEW_VALUE;
    ++			return REF_TRANSACTION_ERROR_INVALID_NEW_VALUE;
      		}
      		if (o->type != OBJ_COMMIT && is_branch(lock->ref_name)) {
      			strbuf_addf(
    @@ refs/files-backend.c: static int write_ref_to_lockfile(struct files_ref_store *r
      				oid_to_hex(oid), lock->ref_name);
      			unlock_ref(lock);
     -			return -1;
    -+			return TRANSACTION_INVALID_NEW_VALUE;
    ++			return REF_TRANSACTION_ERROR_INVALID_NEW_VALUE;
      		}
      	}
      	fd = get_lock_file_fd(&lock->lk);
    @@ refs/files-backend.c: static int write_ref_to_lockfile(struct files_ref_store *r
      			    "couldn't write '%s'", get_lock_file_path(&lock->lk));
      		unlock_ref(lock);
     -		return -1;
    -+		return TRANSACTION_GENERIC_ERROR;
    ++		return REF_TRANSACTION_ERROR_GENERIC;
      	}
    --	return 0;
    -+	return TRANSACTION_OK;
    + 	return 0;
      }
    - 
    - /*
     @@ refs/files-backend.c: static struct ref_iterator *files_reflog_iterator_begin(struct ref_store *ref_st
       * If update is a direct update of head_ref (the reference pointed to
       * by HEAD), then add an extra REF_LOG_ONLY update for HEAD.
    @@ refs/files-backend.c: static struct ref_iterator *files_reflog_iterator_begin(st
     -static int split_head_update(struct ref_update *update,
     -			     struct ref_transaction *transaction,
     -			     const char *head_ref, struct strbuf *err)
    -+static enum transaction_error split_head_update(struct ref_update *update,
    -+						struct ref_transaction *transaction,
    -+						const char *head_ref,
    -+						struct strbuf *err)
    ++static enum ref_transaction_error split_head_update(struct ref_update *update,
    ++						    struct ref_transaction *transaction,
    ++						    const char *head_ref,
    ++						    struct strbuf *err)
      {
      	struct ref_update *new_update;
      
     @@ refs/files-backend.c: static int split_head_update(struct ref_update *update,
    - 	    (update->flags & REF_SKIP_CREATE_REFLOG) ||
    - 	    (update->flags & REF_IS_PRUNING) ||
    - 	    (update->flags & REF_UPDATE_VIA_HEAD))
    --		return 0;
    -+		return TRANSACTION_OK;
    - 
    - 	if (strcmp(update->refname, head_ref))
    --		return 0;
    -+		return TRANSACTION_OK;
    - 
    - 	/*
    - 	 * First make sure that HEAD is not already in the
    -@@ refs/files-backend.c: static int split_head_update(struct ref_update *update,
    - 	if (strcmp(new_update->refname, "HEAD"))
    - 		BUG("%s unexpectedly not 'HEAD'", new_update->refname);
    - 
    --	return 0;
    -+	return TRANSACTION_OK;
    - }
    + 			    "multiple updates for 'HEAD' (including one "
    + 			    "via its referent '%s') are not allowed",
    + 			    update->refname);
    +-		return TRANSACTION_NAME_CONFLICT;
    ++		return REF_TRANSACTION_ERROR_NAME_CONFLICT;
    + 	}
      
    - /*
    + 	new_update = ref_transaction_add_update(
     @@ refs/files-backend.c: static int split_head_update(struct ref_update *update,
       * Note that the new update will itself be subject to splitting when
       * the iteration gets to it.
    @@ refs/files-backend.c: static int split_head_update(struct ref_update *update,
     -			       const char *referent,
     -			       struct ref_transaction *transaction,
     -			       struct strbuf *err)
    -+static enum transaction_error split_symref_update(struct ref_update *update,
    -+						  const char *referent,
    -+						  struct ref_transaction *transaction,
    -+						  struct strbuf *err)
    ++static enum ref_transaction_error split_symref_update(struct ref_update *update,
    ++						      const char *referent,
    ++						      struct ref_transaction *transaction,
    ++						      struct strbuf *err)
      {
      	struct ref_update *new_update;
      	unsigned int new_flags;
     @@ refs/files-backend.c: static int split_symref_update(struct ref_update *update,
    - 	update->flags |= REF_LOG_ONLY | REF_NO_DEREF;
    - 	update->flags &= ~REF_HAVE_OLD;
    - 
    --	return 0;
    -+	return TRANSACTION_OK;
    - }
    + 			    "multiple updates for '%s' (including one "
    + 			    "via symref '%s') are not allowed",
    + 			    referent, update->refname);
    +-		return TRANSACTION_NAME_CONFLICT;
    ++		return REF_TRANSACTION_ERROR_NAME_CONFLICT;
    + 	}
      
    - /*
    + 	new_flags = update->flags;
     @@ refs/files-backend.c: static int split_symref_update(struct ref_update *update,
       * everything is OK, return 0; otherwise, write an error message to
       * err and return -1.
       */
     -static int check_old_oid(struct ref_update *update, struct object_id *oid,
     -			 struct strbuf *err)
    -+static enum transaction_error check_old_oid(struct ref_update *update,
    -+					    struct object_id *oid,
    -+					    struct strbuf *err)
    ++static enum ref_transaction_error check_old_oid(struct ref_update *update,
    ++						struct object_id *oid,
    ++						struct strbuf *err)
      {
     -	int ret = TRANSACTION_GENERIC_ERROR;
     -
      	if (!(update->flags & REF_HAVE_OLD) ||
      		   oideq(oid, &update->old_oid))
    --		return 0;
    -+		return TRANSACTION_OK;
    - 
    - 	if (is_null_oid(&update->old_oid)) {
    + 		return 0;
    +@@ refs/files-backend.c: static int check_old_oid(struct ref_update *update, struct object_id *oid,
      		strbuf_addf(err, "cannot lock ref '%s': "
      			    "reference already exists",
      			    ref_update_original_update_refname(update));
     -		ret = TRANSACTION_CREATE_EXISTS;
     -	}
     -	else if (is_null_oid(oid))
    -+		return TRANSACTION_CREATE_EXISTS;
    ++		return REF_TRANSACTION_ERROR_CREATE_EXISTS;
     +	} else if (is_null_oid(oid)) {
      		strbuf_addf(err, "cannot lock ref '%s': "
      			    "reference is missing but expected %s",
    @@ refs/files-backend.c: static int split_symref_update(struct ref_update *update,
     -			    ref_update_original_update_refname(update),
     -			    oid_to_hex(oid),
     -			    oid_to_hex(&update->old_oid));
    -+		return TRANSACTION_NONEXISTENT_REF;
    ++		return REF_TRANSACTION_ERROR_NONEXISTENT_REF;
     +	}
      
     -	return ret;
    @@ refs/files-backend.c: static int split_symref_update(struct ref_update *update,
     +		    ref_update_original_update_refname(update), oid_to_hex(oid),
     +		    oid_to_hex(&update->old_oid));
     +
    -+	return TRANSACTION_INCORRECT_OLD_VALUE;
    ++	return REF_TRANSACTION_ERROR_INCORRECT_OLD_VALUE;
      }
      
      struct files_transaction_backend_data {
    @@ refs/files-backend.c: struct files_transaction_backend_data {
     -			       const char *head_ref,
     -			       struct string_list *refnames_to_check,
     -			       struct strbuf *err)
    -+static enum transaction_error lock_ref_for_update(struct files_ref_store *refs,
    -+						  struct ref_update *update,
    -+						  struct ref_transaction *transaction,
    -+						  const char *head_ref,
    -+						  struct string_list *refnames_to_check,
    -+						  struct strbuf *err)
    ++static enum ref_transaction_error lock_ref_for_update(struct files_ref_store *refs,
    ++						      struct ref_update *update,
    ++						      struct ref_transaction *transaction,
    ++						      const char *head_ref,
    ++						      struct string_list *refnames_to_check,
    ++						      struct strbuf *err)
      {
      	struct strbuf referent = STRBUF_INIT;
      	int mustexist = ref_update_expects_existing_old_ref(update);
      	struct files_transaction_backend_data *backend_data;
     -	int ret = 0;
    -+	enum transaction_error ret = TRANSACTION_OK;
    ++	enum ref_transaction_error ret = 0;
      	struct ref_lock *lock;
      
      	files_assert_main_repository(refs, "lock_ref_for_update");
     @@ refs/files-backend.c: static int lock_ref_for_update(struct files_ref_store *refs,
    + 					strbuf_addf(err, "cannot lock ref '%s': "
    + 						    "error reading reference",
    + 						    ref_update_original_update_refname(update));
    +-					ret = TRANSACTION_GENERIC_ERROR;
    ++					ret = REF_TRANSACTION_ERROR_GENERIC;
    + 					goto out;
      				}
      			}
      
    @@ refs/files-backend.c: static int lock_ref_for_update(struct files_ref_store *ref
     -				if  (ret) {
     -					goto out;
     -				}
    -+			if (ret) {
    +-			}
    ++			if (ret)
     +				goto out;
    - 			}
      		} else {
      			/*
    + 			 * Create a new update for the reference this
     @@ refs/files-backend.c: static int lock_ref_for_update(struct files_ref_store *refs,
      					   "but is a regular ref"),
      				    ref_update_original_update_refname(update),
      				    update->old_target);
     -			ret = TRANSACTION_GENERIC_ERROR;
    -+			ret = TRANSACTION_EXPECTED_SYMREF;
    ++			ret = REF_TRANSACTION_ERROR_EXPECTED_SYMREF;
      			goto out;
      		} else {
      			ret = check_old_oid(update, &lock->old_oid, err);
    +@@ refs/files-backend.c: static int lock_ref_for_update(struct files_ref_store *refs,
    + 
    + 	if (update->new_target && !(update->flags & REF_LOG_ONLY)) {
    + 		if (create_symref_lock(lock, update->new_target, err)) {
    +-			ret = TRANSACTION_GENERIC_ERROR;
    ++			ret = REF_TRANSACTION_ERROR_GENERIC;
    + 			goto out;
    + 		}
    + 
    + 		if (close_ref_gently(lock)) {
    + 			strbuf_addf(err, "couldn't close '%s.lock'",
    + 				    update->refname);
    +-			ret = TRANSACTION_GENERIC_ERROR;
    ++			ret = REF_TRANSACTION_ERROR_GENERIC;
    + 			goto out;
    + 		}
    + 
     @@ refs/files-backend.c: static int lock_ref_for_update(struct files_ref_store *refs,
      			 * The reference already has the desired
      			 * value, so we don't need to write it.
    @@ refs/files-backend.c: static int lock_ref_for_update(struct files_ref_store *ref
      		}
      	}
      	if (!(update->flags & REF_NEEDS_COMMIT)) {
    +@@ refs/files-backend.c: static int lock_ref_for_update(struct files_ref_store *refs,
    + 		if (close_ref_gently(lock)) {
    + 			strbuf_addf(err, "couldn't close '%s.lock'",
    + 				    update->refname);
    +-			ret = TRANSACTION_GENERIC_ERROR;
    ++			ret = REF_TRANSACTION_ERROR_GENERIC;
    + 			goto out;
    + 		}
    + 	}
    +@@ refs/files-backend.c: static int files_transaction_prepare(struct ref_store *ref_store,
    + 						refs->packed_ref_store,
    + 						transaction->flags, err);
    + 				if (!packed_transaction) {
    +-					ret = TRANSACTION_GENERIC_ERROR;
    ++					ret = REF_TRANSACTION_ERROR_GENERIC;
    + 					goto cleanup;
    + 				}
    + 
    +@@ refs/files-backend.c: static int files_transaction_prepare(struct ref_store *ref_store,
    + 	 */
    + 	if (refs_verify_refnames_available(refs->packed_ref_store, &refnames_to_check,
    + 					   &transaction->refnames, NULL, 0, err)) {
    +-		ret = TRANSACTION_NAME_CONFLICT;
    ++		ret = REF_TRANSACTION_ERROR_NAME_CONFLICT;
    + 		goto cleanup;
    + 	}
    + 
    + 	if (packed_transaction) {
    + 		if (packed_refs_lock(refs->packed_ref_store, 0, err)) {
    +-			ret = TRANSACTION_GENERIC_ERROR;
    ++			ret = REF_TRANSACTION_ERROR_GENERIC;
    + 			goto cleanup;
    + 		}
    + 		backend_data->packed_refs_locked = 1;
    +@@ refs/files-backend.c: static int files_transaction_prepare(struct ref_store *ref_store,
    + 			 */
    + 			backend_data->packed_transaction = NULL;
    + 			if (ref_transaction_abort(packed_transaction, err)) {
    +-				ret = TRANSACTION_GENERIC_ERROR;
    ++				ret = REF_TRANSACTION_ERROR_GENERIC;
    + 				goto cleanup;
    + 			}
    + 		}
    +@@ refs/files-backend.c: static int files_transaction_finish_initial(struct files_ref_store *refs,
    + 	packed_transaction = ref_store_transaction_begin(refs->packed_ref_store,
    + 							 transaction->flags, err);
    + 	if (!packed_transaction) {
    +-		ret = TRANSACTION_GENERIC_ERROR;
    ++		ret = REF_TRANSACTION_ERROR_GENERIC;
    + 		goto cleanup;
    + 	}
    + 
    +@@ refs/files-backend.c: static int files_transaction_finish_initial(struct files_ref_store *refs,
    + 			if (!loose_transaction) {
    + 				loose_transaction = ref_store_transaction_begin(&refs->base, 0, err);
    + 				if (!loose_transaction) {
    +-					ret = TRANSACTION_GENERIC_ERROR;
    ++					ret = REF_TRANSACTION_ERROR_GENERIC;
    + 					goto cleanup;
    + 				}
    + 			}
    +@@ refs/files-backend.c: static int files_transaction_finish_initial(struct files_ref_store *refs,
    + 	}
    + 
    + 	if (packed_refs_lock(refs->packed_ref_store, 0, err)) {
    +-		ret = TRANSACTION_GENERIC_ERROR;
    ++		ret = REF_TRANSACTION_ERROR_GENERIC;
    + 		goto cleanup;
    + 	}
    + 
    + 	if (refs_verify_refnames_available(&refs->base, &refnames_to_check,
    + 					   &affected_refnames, NULL, 1, err)) {
    + 		packed_refs_unlock(refs->packed_ref_store);
    +-		ret = TRANSACTION_NAME_CONFLICT;
    ++		ret = REF_TRANSACTION_ERROR_NAME_CONFLICT;
    + 		goto cleanup;
    + 	}
    + 
    + 	if (ref_transaction_commit(packed_transaction, err)) {
    +-		ret = TRANSACTION_GENERIC_ERROR;
    ++		ret = REF_TRANSACTION_ERROR_GENERIC;
    + 		goto cleanup;
    + 	}
    + 	packed_refs_unlock(refs->packed_ref_store);
    +@@ refs/files-backend.c: static int files_transaction_finish_initial(struct files_ref_store *refs,
    + 	if (loose_transaction) {
    + 		if (ref_transaction_prepare(loose_transaction, err) ||
    + 		    ref_transaction_commit(loose_transaction, err)) {
    +-			ret = TRANSACTION_GENERIC_ERROR;
    ++			ret = REF_TRANSACTION_ERROR_GENERIC;
    + 			goto cleanup;
    + 		}
    + 	}
    +@@ refs/files-backend.c: static int files_transaction_finish(struct ref_store *ref_store,
    + 		if (update->flags & REF_NEEDS_COMMIT ||
    + 		    update->flags & REF_LOG_ONLY) {
    + 			if (parse_and_write_reflog(refs, update, lock, err)) {
    +-				ret = TRANSACTION_GENERIC_ERROR;
    ++				ret = REF_TRANSACTION_ERROR_GENERIC;
    + 				goto cleanup;
    + 			}
    + 		}
    +@@ refs/files-backend.c: static int files_transaction_finish(struct ref_store *ref_store,
    + 				strbuf_addf(err, "couldn't set '%s'", lock->ref_name);
    + 				unlock_ref(lock);
    + 				update->backend_data = NULL;
    +-				ret = TRANSACTION_GENERIC_ERROR;
    ++				ret = REF_TRANSACTION_ERROR_GENERIC;
    + 				goto cleanup;
    + 			}
    + 		}
    +@@ refs/files-backend.c: static int files_transaction_finish(struct ref_store *ref_store,
    + 				strbuf_reset(&sb);
    + 				files_ref_path(refs, &sb, lock->ref_name);
    + 				if (unlink_or_msg(sb.buf, err)) {
    +-					ret = TRANSACTION_GENERIC_ERROR;
    ++					ret = REF_TRANSACTION_ERROR_GENERIC;
    + 					goto cleanup;
    + 				}
    + 			}
     
      ## refs/packed-backend.c ##
     @@ refs/packed-backend.c: static int packed_ref_store_remove_on_disk(struct ref_store *ref_store,
    @@ refs/packed-backend.c: static int packed_ref_store_remove_on_disk(struct ref_sto
     -static int write_with_updates(struct packed_ref_store *refs,
     -			      struct string_list *updates,
     -			      struct strbuf *err)
    -+static enum transaction_error write_with_updates(struct packed_ref_store *refs,
    -+						 struct string_list *updates,
    -+						 struct strbuf *err)
    ++static enum ref_transaction_error write_with_updates(struct packed_ref_store *refs,
    ++						     struct string_list *updates,
    ++						     struct strbuf *err)
      {
    -+	enum transaction_error ret = TRANSACTION_GENERIC_ERROR;
    ++	enum ref_transaction_error ret = REF_TRANSACTION_ERROR_GENERIC;
      	struct ref_iterator *iter = NULL;
      	size_t i;
      	int ok;
    @@ refs/packed-backend.c: static int write_with_updates(struct packed_ref_store *re
      			    sb.buf, strerror(errno));
      		strbuf_release(&sb);
     -		return -1;
    -+		return TRANSACTION_GENERIC_ERROR;
    ++		return REF_TRANSACTION_ERROR_GENERIC;
      	}
      	strbuf_release(&sb);
      
    @@ refs/packed-backend.c: static int write_with_updates(struct packed_ref_store *re
      					strbuf_addf(err, "cannot update ref '%s': "
      						    "reference already exists",
      						    update->refname);
    -+					ret = TRANSACTION_CREATE_EXISTS;
    ++					ret = REF_TRANSACTION_ERROR_CREATE_EXISTS;
      					goto error;
      				} else if (!oideq(&update->old_oid, iter->oid)) {
      					strbuf_addf(err, "cannot update ref '%s': "
    @@ refs/packed-backend.c: static int write_with_updates(struct packed_ref_store *re
      						    update->refname,
      						    oid_to_hex(iter->oid),
      						    oid_to_hex(&update->old_oid));
    -+					ret = TRANSACTION_INCORRECT_OLD_VALUE;
    ++					ret = REF_TRANSACTION_ERROR_INCORRECT_OLD_VALUE;
      					goto error;
      				}
      			}
    @@ refs/packed-backend.c: static int write_with_updates(struct packed_ref_store *re
      					    "reference is missing but expected %s",
      					    update->refname,
      					    oid_to_hex(&update->old_oid));
    -+				return TRANSACTION_NONEXISTENT_REF;
    ++				return REF_TRANSACTION_ERROR_NONEXISTENT_REF;
      				goto error;
      			}
      		}
    @@ refs/packed-backend.c: static int write_with_updates(struct packed_ref_store *re
      		strbuf_release(&sb);
      		delete_tempfile(&refs->tempfile);
     -		return -1;
    -+		return TRANSACTION_GENERIC_ERROR;
    ++		return REF_TRANSACTION_ERROR_GENERIC;
      	}
      
    --	return 0;
    -+	return TRANSACTION_OK;
    - 
    - write_error:
    - 	strbuf_addf(err, "error writing to %s: %s",
    + 	return 0;
     @@ refs/packed-backend.c: static int write_with_updates(struct packed_ref_store *refs,
      error:
      	ref_iterator_free(iter);
    @@ refs/packed-backend.c: static int write_with_updates(struct packed_ref_store *re
      }
      
      int is_packed_transaction_needed(struct ref_store *ref_store,
    +@@ refs/packed-backend.c: static int packed_transaction_prepare(struct ref_store *ref_store,
    + 			REF_STORE_READ | REF_STORE_WRITE | REF_STORE_ODB,
    + 			"ref_transaction_prepare");
    + 	struct packed_transaction_backend_data *data;
    +-	int ret = TRANSACTION_GENERIC_ERROR;
    ++	enum ref_transaction_error ret = REF_TRANSACTION_ERROR_GENERIC;
    + 
    + 	/*
    + 	 * Note that we *don't* skip transactions with zero updates,
     @@ refs/packed-backend.c: static int packed_transaction_prepare(struct ref_store *ref_store,
      		data->own_lock = 1;
      	}
    @@ refs/packed-backend.c: static int packed_transaction_prepare(struct ref_store *r
      		goto failure;
      
      	transaction->state = REF_TRANSACTION_PREPARED;
    +@@ refs/packed-backend.c: static int packed_transaction_finish(struct ref_store *ref_store,
    + 			ref_store,
    + 			REF_STORE_READ | REF_STORE_WRITE | REF_STORE_ODB,
    + 			"ref_transaction_finish");
    +-	int ret = TRANSACTION_GENERIC_ERROR;
    ++	int ret = REF_TRANSACTION_ERROR_GENERIC;
    + 	char *packed_refs_path;
    + 
    + 	clear_snapshot(refs);
     
      ## refs/refs-internal.h ##
     @@ refs/refs-internal.h: int ref_update_has_null_new_value(struct ref_update *update);
    @@ refs/refs-internal.h: int ref_update_has_null_new_value(struct ref_update *updat
       */
     -int ref_update_check_old_target(const char *referent, struct ref_update *update,
     -				struct strbuf *err);
    -+enum transaction_error ref_update_check_old_target(const char *referent,
    -+					      struct ref_update *update,
    -+					      struct strbuf *err);
    ++enum ref_transaction_error ref_update_check_old_target(const char *referent,
    ++						       struct ref_update *update,
    ++						       struct strbuf *err);
      
      /*
       * Check if the ref must exist, this means that the old_oid or
    @@ refs/reftable-backend.c: static int queue_transaction_update(struct reftable_ref
     -				 struct strbuf *head_referent,
     -				 struct strbuf *referent,
     -				 struct strbuf *err)
    -+static enum transaction_error prepare_single_update(struct reftable_ref_store *refs,
    -+						    struct reftable_transaction_data *tx_data,
    -+						    struct ref_transaction *transaction,
    -+						    struct reftable_backend *be,
    -+						    struct ref_update *u,
    -+						    struct string_list *refnames_to_check,
    -+						    unsigned int head_type,
    -+						    struct strbuf *head_referent,
    -+						    struct strbuf *referent,
    -+						    struct strbuf *err)
    ++static enum ref_transaction_error prepare_single_update(struct reftable_ref_store *refs,
    ++							struct reftable_transaction_data *tx_data,
    ++							struct ref_transaction *transaction,
    ++							struct reftable_backend *be,
    ++							struct ref_update *u,
    ++							struct string_list *refnames_to_check,
    ++							unsigned int head_type,
    ++							struct strbuf *head_referent,
    ++							struct strbuf *referent,
    ++							struct strbuf *err)
      {
    -+	enum transaction_error ret = TRANSACTION_OK;
    ++	enum ref_transaction_error ret = 0;
      	struct object_id current_oid = {0};
      	const char *rewritten_ref;
     -	int ret = 0;
    @@ refs/reftable-backend.c: static int prepare_single_update(struct reftable_ref_st
      	ret = backend_for(&be, refs, u->refname, &rewritten_ref, 0);
      	if (ret)
     -		return ret;
    -+		return TRANSACTION_GENERIC_ERROR;
    ++		return REF_TRANSACTION_ERROR_GENERIC;
      
      	/* Verify that the new object ID is valid. */
      	if ((u->flags & REF_HAVE_NEW) && !is_null_oid(&u->new_oid) &&
    @@ refs/reftable-backend.c: static int prepare_single_update(struct reftable_ref_st
      				    _("trying to write ref '%s' with nonexistent object %s"),
      				    u->refname, oid_to_hex(&u->new_oid));
     -			return -1;
    -+			return TRANSACTION_INVALID_NEW_VALUE;
    ++			return REF_TRANSACTION_ERROR_INVALID_NEW_VALUE;
      		}
      
      		if (o->type != OBJ_COMMIT && is_branch(u->refname)) {
      			strbuf_addf(err, _("trying to write non-commit object %s to branch '%s'"),
      				    oid_to_hex(&u->new_oid), u->refname);
     -			return -1;
    -+			return TRANSACTION_INVALID_NEW_VALUE;
    ++			return REF_TRANSACTION_ERROR_INVALID_NEW_VALUE;
      		}
      	}
      
    +@@ refs/reftable-backend.c: static int prepare_single_update(struct reftable_ref_store *refs,
    + 				    _("multiple updates for 'HEAD' (including one "
    + 				      "via its referent '%s') are not allowed"),
    + 				    u->refname);
    +-			return TRANSACTION_NAME_CONFLICT;
    ++			return REF_TRANSACTION_ERROR_NAME_CONFLICT;
    + 		}
    + 
    + 		ref_transaction_add_update(
     @@ refs/reftable-backend.c: static int prepare_single_update(struct reftable_ref_store *refs,
      	ret = reftable_backend_read_ref(be, rewritten_ref,
      					&current_oid, referent, &u->type);
      	if (ret < 0)
     -		return ret;
    -+		return TRANSACTION_GENERIC_ERROR;
    ++		return REF_TRANSACTION_ERROR_GENERIC;
      	if (ret > 0 && !ref_update_expects_existing_old_ref(u)) {
      		/*
      		 * The reference does not exist, and we either have no
    @@ refs/reftable-backend.c: static int prepare_single_update(struct reftable_ref_st
      						       &current_oid, err);
      			if (ret)
     -				return ret;
    -+				return TRANSACTION_GENERIC_ERROR;
    ++				return REF_TRANSACTION_ERROR_GENERIC;
      		}
      
      		return 0;
    @@ refs/reftable-backend.c: static int prepare_single_update(struct reftable_ref_st
      				   "unable to resolve reference '%s'"),
      			    ref_update_original_update_refname(u), u->refname);
     -		return -1;
    -+		return TRANSACTION_NONEXISTENT_REF;
    ++		return REF_TRANSACTION_ERROR_NONEXISTENT_REF;
      	}
      
      	if (u->type & REF_ISSYMREF) {
    @@ refs/reftable-backend.c: static int prepare_single_update(struct reftable_ref_st
      				strbuf_addf(err, _("cannot lock ref '%s': "
      						   "error reading reference"), u->refname);
     -				return -1;
    -+				return TRANSACTION_GENERIC_ERROR;
    ++				return REF_TRANSACTION_ERROR_GENERIC;
      			}
      		} else {
      			struct ref_update *new_update;
    +@@ refs/reftable-backend.c: static int prepare_single_update(struct reftable_ref_store *refs,
    + 					    _("multiple updates for '%s' (including one "
    + 					      "via symref '%s') are not allowed"),
    + 					    referent->buf, u->refname);
    +-				return TRANSACTION_NAME_CONFLICT;
    ++				return REF_TRANSACTION_ERROR_NAME_CONFLICT;
    + 			}
    + 
    + 			/*
     @@ refs/reftable-backend.c: static int prepare_single_update(struct reftable_ref_store *refs,
      					   "but is a regular ref"),
      				    ref_update_original_update_refname(u),
      				    u->old_target);
     -			return -1;
    -+			return TRANSACTION_EXPECTED_SYMREF;
    ++			return REF_TRANSACTION_ERROR_EXPECTED_SYMREF;
      		}
      
     -		if (ref_update_check_old_target(referent->buf, u, err)) {
     -			return -1;
    +-		}
     +		ret = ref_update_check_old_target(referent->buf, u, err);
    -+		if (ret) {
    ++		if (ret)
     +			return ret;
    - 		}
      	} else if ((u->flags & REF_HAVE_OLD) && !oideq(&current_oid, &u->old_oid)) {
      		if (is_null_oid(&u->old_oid)) {
    -@@ refs/reftable-backend.c: static int prepare_single_update(struct reftable_ref_store *refs,
    + 			strbuf_addf(err, _("cannot lock ref '%s': "
    + 					   "reference already exists"),
      				    ref_update_original_update_refname(u));
    - 			return TRANSACTION_CREATE_EXISTS;
    - 		}
    +-			return TRANSACTION_CREATE_EXISTS;
    +-		}
     -		else if (is_null_oid(&current_oid))
    -+		else if (is_null_oid(&current_oid)) {
    ++			return REF_TRANSACTION_ERROR_CREATE_EXISTS;
    ++		} else if (is_null_oid(&current_oid)) {
      			strbuf_addf(err, _("cannot lock ref '%s': "
      					   "reference is missing but expected %s"),
      				    ref_update_original_update_refname(u),
      				    oid_to_hex(&u->old_oid));
     -		else
    -+			return TRANSACTION_NONEXISTENT_REF;
    -+
    ++			return REF_TRANSACTION_ERROR_NONEXISTENT_REF;
     +		} else {
      			strbuf_addf(err, _("cannot lock ref '%s': "
      					   "is at %s but expected %s"),
    @@ refs/reftable-backend.c: static int prepare_single_update(struct reftable_ref_st
      				    oid_to_hex(&current_oid),
      				    oid_to_hex(&u->old_oid));
     -		return TRANSACTION_NAME_CONFLICT;
    -+			return TRANSACTION_INCORRECT_OLD_VALUE;
    ++			return REF_TRANSACTION_ERROR_INCORRECT_OLD_VALUE;
     +		}
      	}
      
    @@ refs/reftable-backend.c: static int prepare_single_update(struct reftable_ref_st
     -		return queue_transaction_update(refs, tx_data, u,
     -					       &current_oid, err);
     +		if (queue_transaction_update(refs, tx_data, u, &current_oid, err))
    -+			return TRANSACTION_GENERIC_ERROR;
    ++			return REF_TRANSACTION_ERROR_GENERIC;
      
    --	return 0;
    -+	return TRANSACTION_OK;
    + 	return 0;
      }
    - 
    - static int reftable_be_transaction_prepare(struct ref_store *ref_store,
     @@ refs/reftable-backend.c: static int reftable_be_transaction_prepare(struct ref_store *ref_store,
      	transaction->state = REF_TRANSACTION_PREPARED;
      
6:  49a0e65427 ! 6:  73f8970cb9 refs: implement partial reference transaction support
    @@ Commit message
         'REF_TRANSACTION_ALLOW_PARTIAL'. When enabled, this flag allows
         individual reference updates that would typically cause the entire
         transaction to fail due to non-system-related errors to be marked as
    -    rejected while permitting other updates to proceed. Non-system-related
    -    errors include issues caused by user-provided input values, whereas
    -    system-related errors, such as I/O failures or memory issues, continue
    -    to result in a full transaction failure. This approach enhances
    -    flexibility while preserving transactional integrity where necessary.
    +    rejected while permitting other updates to proceed. System errors
    +    referred by 'REF_TRANSACTION_ERROR_GENERIC' continue to result in the
    +    entire transaction failing. This approach enhances flexibility while
    +    preserving transactional integrity where necessary.
     
         The implementation introduces several key components:
     
           - Add 'rejection_err' field to struct `ref_update` to track failed
             updates with failure reason.
     
    +      - Add a new struct `ref_transaction_rejections` and a field within
    +        `ref_transaction` to this struct to allow quick iteration over
    +        rejected updates.
    +
           - Modify reference backends (files, packed, reftable) to handle
             partial transactions by using `ref_transaction_set_rejected()`
             instead of failing the entire transaction when
    @@ Commit message
             examine which updates were rejected and why.
     
         This foundational change enables partial transaction support throughout
    -    the reference subsystem. The next commit will expose this capability to
    -    users by adding a `--allow-partial` flag to 'git-update-ref(1)',
    +    the reference subsystem. A following commit will expose this capability
    +    to users by adding a `--allow-partial` flag to 'git-update-ref(1)',
         providing both a user-facing feature and a testable implementation.
     
         Signed-off-by: Karthik Nayak <karthik.188@gmail.com>
     
      ## refs.c ##
    +@@ refs.c: struct ref_transaction *ref_store_transaction_begin(struct ref_store *refs,
    + 	tr->ref_store = refs;
    + 	tr->flags = flags;
    + 	string_list_init_dup(&tr->refnames);
    ++
    ++	if (flags & REF_TRANSACTION_ALLOW_PARTIAL)
    ++		CALLOC_ARRAY(tr->rejections, 1);
    ++
    + 	return tr;
    + }
    + 
     @@ refs.c: void ref_transaction_free(struct ref_transaction *transaction)
    + 		free((char *)transaction->updates[i]->old_target);
    + 		free(transaction->updates[i]);
    + 	}
    ++
    ++	if (transaction->rejections)
    ++		free(transaction->rejections->update_indices);
    ++	free(transaction->rejections);
    ++
    + 	string_list_clear(&transaction->refnames, 0);
    + 	free(transaction->updates);
      	free(transaction);
      }
      
    -+void ref_transaction_set_rejected(struct ref_transaction *transaction,
    -+				  size_t update_idx,
    -+				  enum transaction_error err)
    ++int ref_transaction_maybe_set_rejected(struct ref_transaction *transaction,
    ++				       size_t update_idx,
    ++				       enum ref_transaction_error err)
     +{
     +	if (update_idx >= transaction->nr)
     +		BUG("trying to set rejection on invalid update index");
    ++
    ++	if (!(transaction->flags & REF_TRANSACTION_ALLOW_PARTIAL))
    ++		return 0;
    ++
    ++	if (!transaction->rejections)
    ++		BUG("transaction not inititalized with partial support");
    ++
    ++	/*
    ++	 * Don't accept generic errors, since these errors are not user
    ++	 * input related.
    ++	 */
    ++	if (err == REF_TRANSACTION_ERROR_GENERIC)
    ++		return 0;
    ++
     +	transaction->updates[update_idx]->rejection_err = err;
    ++	ALLOC_GROW(transaction->rejections->update_indices,
    ++		   transaction->rejections->nr + 1,
    ++		   transaction->rejections->alloc);
    ++	transaction->rejections->update_indices[transaction->rejections->nr++] = update_idx;
    ++
    ++	return 1;
     +}
     +
      struct ref_update *ref_transaction_add_update(
    @@ refs.c: struct ref_update *ref_transaction_add_update(
      	transaction->updates[transaction->nr++] = update;
      
      	update->flags = flags;
    -+	update->rejection_err = TRANSACTION_OK;
    ++	update->rejection_err = 0;
      
      	update->new_target = xstrdup_or_null(new_target);
      	update->old_target = xstrdup_or_null(old_target);
    @@ refs.c: void ref_transaction_for_each_queued_update(struct ref_transaction *tran
     +					      ref_transaction_for_each_rejected_update_fn cb,
     +					      void *cb_data)
     +{
    -+	if (!(transaction->flags & REF_TRANSACTION_ALLOW_PARTIAL))
    ++	if (!transaction->rejections)
     +		return;
     +
    -+	for (size_t i = 0; i < transaction->nr; i++) {
    -+		struct ref_update *update = transaction->updates[i];
    ++	for (size_t i = 0; i < transaction->rejections->nr; i++) {
    ++		size_t update_index = transaction->rejections->update_indices[i];
    ++		struct ref_update *update = transaction->updates[update_index];
     +
     +		if (!update->rejection_err)
     +			continue;
    @@ refs.h: void ref_transaction_for_each_queued_update(struct ref_transaction *tran
     +							 const struct object_id *new_oid,
     +							 const char *old_target,
     +							 const char *new_target,
    -+							 enum transaction_error err,
    ++							 enum ref_transaction_error err,
     +							 void *cb_data);
     +void ref_transaction_for_each_rejected_update(struct ref_transaction *transaction,
     +					      ref_transaction_for_each_rejected_update_fn cb,
    @@ refs/files-backend.c: static int files_transaction_prepare(struct ref_store *ref
      					  err);
     -		if (ret)
     +		if (ret) {
    -+			if (transaction->flags & REF_TRANSACTION_ALLOW_PARTIAL &&
    -+			    ret != TRANSACTION_GENERIC_ERROR) {
    -+				ref_transaction_set_rejected(transaction, i, ret);
    -+
    ++			if (ref_transaction_maybe_set_rejected(transaction, i, ret)) {
     +				strbuf_setlen(err, 0);
    -+				ret = TRANSACTION_OK;
    ++				ret = 0;
     +
     +				continue;
     +			}
    @@ refs/files-backend.c: static int files_transaction_prepare(struct ref_store *ref
      
      		if (update->flags & REF_DELETING &&
      		    !(update->flags & REF_LOG_ONLY) &&
    +@@ refs/files-backend.c: static int files_transaction_finish(struct ref_store *ref_store,
    + 		struct ref_update *update = transaction->updates[i];
    + 		struct ref_lock *lock = update->backend_data;
    + 
    ++		if (update->rejection_err)
    ++			continue;
    ++
    + 		if (update->flags & REF_NEEDS_COMMIT ||
    + 		    update->flags & REF_LOG_ONLY) {
    + 			if (parse_and_write_reflog(refs, update, lock, err)) {
     
      ## refs/packed-backend.c ##
     @@ refs/packed-backend.c: static int packed_ref_store_remove_on_disk(struct ref_store *ref_store,
       * remain locked when it is done.
       */
    - static enum transaction_error write_with_updates(struct packed_ref_store *refs,
    --						 struct string_list *updates,
    -+						 struct ref_transaction *transaction,
    - 						 struct strbuf *err)
    + static enum ref_transaction_error write_with_updates(struct packed_ref_store *refs,
    +-						     struct string_list *updates,
    ++						     struct ref_transaction *transaction,
    + 						     struct strbuf *err)
      {
    - 	enum transaction_error ret = TRANSACTION_GENERIC_ERROR;
    + 	enum ref_transaction_error ret = REF_TRANSACTION_ERROR_GENERIC;
     +	struct string_list *updates = &transaction->refnames;
      	struct ref_iterator *iter = NULL;
      	size_t i;
      	int ok;
    -@@ refs/packed-backend.c: static enum transaction_error write_with_updates(struct packed_ref_store *refs,
    +@@ refs/packed-backend.c: static enum ref_transaction_error write_with_updates(struct packed_ref_store *re
      						    "reference already exists",
      						    update->refname);
    - 					ret = TRANSACTION_CREATE_EXISTS;
    + 					ret = REF_TRANSACTION_ERROR_CREATE_EXISTS;
     +
    -+					if (transaction->flags & REF_TRANSACTION_ALLOW_PARTIAL) {
    -+						ref_transaction_set_rejected(transaction, i, ret);
    ++					if (ref_transaction_maybe_set_rejected(transaction, i, ret)) {
     +						strbuf_setlen(err, 0);
     +						ret = 0;
     +						continue;
    @@ refs/packed-backend.c: static enum transaction_error write_with_updates(struct p
      					goto error;
      				} else if (!oideq(&update->old_oid, iter->oid)) {
      					strbuf_addf(err, "cannot update ref '%s': "
    -@@ refs/packed-backend.c: static enum transaction_error write_with_updates(struct packed_ref_store *refs,
    +@@ refs/packed-backend.c: static enum ref_transaction_error write_with_updates(struct packed_ref_store *re
      						    oid_to_hex(iter->oid),
      						    oid_to_hex(&update->old_oid));
    - 					ret = TRANSACTION_INCORRECT_OLD_VALUE;
    + 					ret = REF_TRANSACTION_ERROR_INCORRECT_OLD_VALUE;
     +
    -+					if (transaction->flags & REF_TRANSACTION_ALLOW_PARTIAL) {
    -+						ref_transaction_set_rejected(transaction, i, ret);
    ++					if (ref_transaction_maybe_set_rejected(transaction, i, ret)) {
     +						strbuf_setlen(err, 0);
     +						ret = 0;
     +						continue;
    @@ refs/packed-backend.c: static enum transaction_error write_with_updates(struct p
      					goto error;
      				}
      			}
    -@@ refs/packed-backend.c: static enum transaction_error write_with_updates(struct packed_ref_store *refs,
    +@@ refs/packed-backend.c: static enum ref_transaction_error write_with_updates(struct packed_ref_store *re
      					    update->refname,
      					    oid_to_hex(&update->old_oid));
    - 				return TRANSACTION_NONEXISTENT_REF;
    + 				return REF_TRANSACTION_ERROR_NONEXISTENT_REF;
     +
    -+				if (transaction->flags & REF_TRANSACTION_ALLOW_PARTIAL) {
    -+					ref_transaction_set_rejected(transaction, i, ret);
    ++				if (ref_transaction_maybe_set_rejected(transaction, i, ret)) {
     +					strbuf_setlen(err, 0);
     +					ret = 0;
     +					continue;
    @@ refs/packed-backend.c: static enum transaction_error write_with_updates(struct p
      				goto error;
      			}
      		}
    -@@ refs/packed-backend.c: static enum transaction_error write_with_updates(struct packed_ref_store *refs,
    +@@ refs/packed-backend.c: static enum ref_transaction_error write_with_updates(struct packed_ref_store *re
      write_error:
      	strbuf_addf(err, "error writing to %s: %s",
      		    get_tempfile_path(refs->tempfile), strerror(errno));
    -+	ret = TRANSACTION_GENERIC_ERROR;
    ++	ret = REF_TRANSACTION_ERROR_GENERIC;
      
      error:
      	ref_iterator_free(iter);
    @@ refs/refs-internal.h: struct ref_update {
     +	/*
     +	 * Used in partial transactions to mark if a given update was rejected.
     +	 */
    -+	enum transaction_error rejection_err;
    ++	enum ref_transaction_error rejection_err;
     +
      	/*
      	 * If this ref_update was split off of a symref update via
    @@ refs/refs-internal.h: int refs_read_raw_ref(struct ref_store *ref_store, const c
      		      unsigned int *type, int *failure_errno);
      
     +/*
    -+ * Mark a given update as rejected with a given reason. To be used in conjuction
    -+ * with the `REF_TRANSACTION_ALLOW_PARTIAL` flag to allow partial transactions.
    ++ * Mark a given update as rejected with a given reason.
     + */
    -+void ref_transaction_set_rejected(struct ref_transaction *transaction,
    -+				  size_t update_idx,
    -+				  enum transaction_error err);
    ++int ref_transaction_maybe_set_rejected(struct ref_transaction *transaction,
    ++				       size_t update_idx,
    ++				       enum ref_transaction_error err);
     +
      /*
       * Add a ref_update with the specified properties to transaction, and
       * return a pointer to the new object. This function does not verify
    +@@ refs/refs-internal.h: enum ref_transaction_state {
    + 	REF_TRANSACTION_CLOSED   = 2
    + };
    + 
    ++/*
    ++ * Data structure to hold indices of updates which were rejected, when
    ++ * partial transactions where enabled. While the updates themselves hold
    ++ * the rejection error, this structure allows a transaction to iterate
    ++ * only over the rejected updates.
    ++ */
    ++struct ref_transaction_rejections {
    ++	size_t *update_indices;
    ++	size_t alloc;
    ++	size_t nr;
    ++};
    ++
    + /*
    +  * Data structure for holding a reference transaction, which can
    +  * consist of checks and updates to multiple references, carried out
    +@@ refs/refs-internal.h: struct ref_transaction {
    + 	size_t alloc;
    + 	size_t nr;
    + 	enum ref_transaction_state state;
    ++	struct ref_transaction_rejections *rejections;
    + 	void *backend_data;
    + 	unsigned int flags;
    + 	uint64_t max_index;
     
      ## refs/reftable-backend.c ##
     @@ refs/reftable-backend.c: static int reftable_be_transaction_prepare(struct ref_store *ref_store,
    @@ refs/reftable-backend.c: static int reftable_be_transaction_prepare(struct ref_s
      					    &head_referent, &referent, err);
     -		if (ret)
     +		if (ret) {
    -+			if (transaction->flags & REF_TRANSACTION_ALLOW_PARTIAL &&
    -+			    ret != TRANSACTION_GENERIC_ERROR) {
    -+				ref_transaction_set_rejected(transaction, i, ret);
    -+
    ++			if (ref_transaction_maybe_set_rejected(transaction, i, ret)) {
     +				strbuf_setlen(err, 0);
    -+				ret = TRANSACTION_OK;
    ++				ret = 0;
     +
     +				continue;
     +			}
    @@ refs/reftable-backend.c: static int reftable_be_transaction_prepare(struct ref_s
      	}
      
      	string_list_sort(&refnames_to_check);
    +@@ refs/reftable-backend.c: static int write_transaction_table(struct reftable_writer *writer, void *cb_data
    + 		struct reftable_transaction_update *tx_update = &arg->updates[i];
    + 		struct ref_update *u = tx_update->update;
    + 
    ++		if (u->rejection_err)
    ++			continue;
    ++
    + 		/*
    + 		 * Write a reflog entry when updating a ref to point to
    + 		 * something new in either of the following cases:
-:  ---------- > 7:  f0284388ce refs: support partial update rejections during F/D checks
7:  0dc37f87a7 ! 8:  f0e7c44eb7 update-ref: add --allow-partial flag for stdin mode
    @@ Commit message
     
           rejected SP (<old-oid> | <old-target>) SP (<new-oid> | <new-target>) SP <rejection-reason> LF
     
    -    or with `-z`:
    -
    -      rejected NUL (<old-oid> | <old-target>) NUL (<new-oid> | <new-target>) NUL <rejection-reason> NUL
    -
         Update the documentation to reflect this change and also tests to cover
         different scenarios where an update could be rejected.
     
    @@ Documentation/git-update-ref.adoc: performs all modifications together.  Specify
      Quote fields containing whitespace as if they were strings in C source
      code; i.e., surrounded by double-quotes and with backslash escapes.
      Use 40 "0" characters or the empty string to specify a zero value.  To
    -@@ Documentation/git-update-ref.adoc: quoting:
    - In this format, use 40 "0" to specify a zero value, and use the empty
    - string to specify a missing value.
    - 
    -+With `-z`, `--allow-partial` will print rejections in the following form:
    -+
    -+	rejected NUL (<old-oid> | <old-target>) NUL (<new-oid> | <new-target>) NUL <rejection-reason> NUL
    -+
    - In either format, values can be specified in any form that Git
    - recognizes as an object name.  Commands in any other format or a
    - repeated <ref> produce an error.  Command meanings are:
     
      ## builtin/update-ref.c ##
     @@
    @@ builtin/update-ref.c: static void parse_cmd_abort(struct ref_transaction *transa
     +				const struct object_id *new_oid,
     +				const char *old_target,
     +				const char *new_target,
    -+				enum transaction_error err,
    ++				enum ref_transaction_error err,
     +				void *cb_data UNUSED)
     +{
     +	struct strbuf sb = STRBUF_INIT;
    -+	char space = ' ';
     +	const char *reason = "";
     +
     +	switch (err) {
    -+	case TRANSACTION_NAME_CONFLICT:
    -+		reason = _("refname conflict");
    ++	case REF_TRANSACTION_ERROR_NAME_CONFLICT:
    ++		reason = "refname conflict";
     +		break;
    -+	case TRANSACTION_CREATE_EXISTS:
    -+		reason = _("reference already exists");
    ++	case REF_TRANSACTION_ERROR_CREATE_EXISTS:
    ++		reason = "reference already exists";
     +		break;
    -+	case TRANSACTION_NONEXISTENT_REF:
    -+		reason = _("reference does not exist");
    ++	case REF_TRANSACTION_ERROR_NONEXISTENT_REF:
    ++		reason = "reference does not exist";
     +		break;
    -+	case TRANSACTION_INCORRECT_OLD_VALUE:
    -+		reason = _("incorrect old value provided");
    ++	case REF_TRANSACTION_ERROR_INCORRECT_OLD_VALUE:
    ++		reason = "incorrect old value provided";
     +		break;
    -+	case TRANSACTION_INVALID_NEW_VALUE:
    -+		reason = _("invalid new value provided");
    ++	case REF_TRANSACTION_ERROR_INVALID_NEW_VALUE:
    ++		reason = "invalid new value provided";
     +		break;
    -+	case TRANSACTION_EXPECTED_SYMREF:
    -+		reason = _("expected symref but found regular ref");
    ++	case REF_TRANSACTION_ERROR_EXPECTED_SYMREF:
    ++		reason = "expected symref but found regular ref";
     +		break;
     +	default:
    -+		reason = _("unkown failure");
    ++		reason = "unkown failure";
     +	}
     +
    -+	if (!line_termination)
    -+		space = line_termination;
    -+
    -+	strbuf_addf(&sb, "rejected%c%s%c%s%c%c%s%c%s%c", space,
    -+		    refname, space, new_oid ? oid_to_hex(new_oid) : new_target,
    -+		    space, space, old_oid ? oid_to_hex(old_oid) : old_target,
    -+		    space, reason, line_termination);
    ++	strbuf_addf(&sb, "rejected %s %s %s %s\n", refname,
    ++		    new_oid ? oid_to_hex(new_oid) : new_target,
    ++		    old_oid ? oid_to_hex(old_oid) : old_target,
    ++		    reason);
     +
     +	fwrite(sb.buf, sb.len, 1, stdout);
     +	strbuf_release(&sb);
    -+	fflush(stdout);
     +}
     +
      static void parse_cmd_commit(struct ref_transaction *transaction,
    @@ builtin/update-ref.c: static void update_refs_stdin(void)
      		break;
      	case UPDATE_REFS_STARTED:
     @@ builtin/update-ref.c: int cmd_update_ref(int argc,
    - 	const char *refname, *oldval;
      	struct object_id oid, oldoid;
      	int delete = 0, no_deref = 0, read_stdin = 0, end_null = 0;
    --	int create_reflog = 0;
    -+	int create_reflog = 0, allow_partial = 0;
    + 	int create_reflog = 0;
     +	unsigned int flags = 0;
     +
      	struct option options[] = {
    @@ builtin/update-ref.c: int cmd_update_ref(int argc,
     +		update_refs_stdin(flags);
      		return 0;
     -	}
    -+	} else if (allow_partial)
    ++	} else if (flags & REF_TRANSACTION_ALLOW_PARTIAL)
     +		die("--allow-partial can only be used with --stdin");
      
      	if (end_null)
    @@ t/t1400-update-ref.sh: do
     +		)
     +	'
     +
    -+	# F/D conflicts on the files backend are resolved on an individual
    -+	# update level since refs are stored as files. On the reftable backend
    -+	# this check is batched to optimize for performance, so failures cannot
    -+	# be isolated to a single update.
    -+	test_expect_success REFFILES "stdin $type allow-partial refname conflict" '
    ++	test_expect_success "stdin $type allow-partial refname conflict" '
     +		git init repo &&
     +		test_when_finished "rm -fr repo" &&
     +		(
    @@ t/t1400-update-ref.sh: do
     +			test_cmp expect actual &&
     +			test_grep -q "refname conflict" stdout
     +		)
    ++	'
    ++
    ++	test_expect_success "stdin $type allow-partial refname conflict new ref" '
    ++		git init repo &&
    ++		test_when_finished "rm -fr repo" &&
    ++		(
    ++			cd repo &&
    ++			test_commit one &&
    ++			old_head=$(git rev-parse HEAD) &&
    ++			test_commit two &&
    ++			head=$(git rev-parse HEAD) &&
    ++			git update-ref refs/heads/ref/foo $head &&
    ++
    ++			format_command $type "update refs/heads/foo" "$old_head" "" >stdin &&
    ++			format_command $type "update refs/heads/ref" "$old_head" "" >>stdin &&
    ++			git update-ref $type --stdin --allow-partial <stdin >stdout &&
    ++			echo $old_head >expect &&
    ++			git rev-parse refs/heads/foo >actual &&
    ++			test_cmp expect actual &&
    ++			test_grep -q "refname conflict" stdout
    ++		)
     +	'
      done
      

base-commit: f032e4cb6777d229cc1e662e142e99ef71741eb4 change-id: 20241206-245-partially-atomic-ref-updates-9fe8b080345c

Thanks
- Karthik
Karthik Nayak· Mar 5, 2025, 17:38 UTC · re: Karthik Nayak · lore

In `split_symref_update()`, there were two checks for duplicate refnames:

  - At the start, `string_list_has_string()` ensures the refname is not
    already in `affected_refnames`, preventing duplicates from being
    added.
  - After adding the refname, another check verifies whether the newly
    inserted item has a `util` value.

The second check is unnecessary because the first one guarantees that `string_list_insert()` will never encounter a preexisting entry.

Since `item->util` is only used in this context, remove the assignment and simplify the surrounding code.

Signed-off-by: Karthik Nayak <karthik.188@gmail.com>
---
 refs/files-backend.c | 20 +++-----------------
 1 file changed, 3 insertions(+), 17 deletions(-)
Show changes to refs/files-backend.c +3 −17
diff --git a/refs/files-backend.c b/refs/files-backend.c
index 4e1c50fead..6c7df30738 100644
--- a/refs/files-backend.c
+++ b/refs/files-backend.c
@@ -2382,7 +2382,6 @@ static int split_head_update(struct ref_update *update,
 			     struct string_list *affected_refnames,
 			     struct strbuf *err)
 {
-	struct string_list_item *item;
 	struct ref_update *new_update;
 
 	if ((update->flags & REF_LOG_ONLY) ||
@@ -2421,8 +2420,7 @@ static int split_head_update(struct ref_update *update,
 	 */
 	if (strcmp(new_update->refname, "HEAD"))
 		BUG("%s unexpectedly not 'HEAD'", new_update->refname);
-	item = string_list_insert(affected_refnames, new_update->refname);
-	item->util = new_update;
+	string_list_insert(affected_refnames, new_update->refname);
 
 	return 0;
 }
@@ -2441,7 +2439,6 @@ static int split_symref_update(struct ref_update *update,
 			       struct string_list *affected_refnames,
 			       struct strbuf *err)
 {
-	struct string_list_item *item;
 	struct ref_update *new_update;
 	unsigned int new_flags;
 
@@ -2496,11 +2493,7 @@ static int split_symref_update(struct ref_update *update,
 	 * be valid as long as affected_refnames is in use, and NOT
 	 * referent, which might soon be freed by our caller.
 	 */
-	item = string_list_insert(affected_refnames, new_update->refname);
-	if (item->util)
-		BUG("%s unexpectedly found in affected_refnames",
-		    new_update->refname);
-	item->util = new_update;
+	string_list_insert(affected_refnames, new_update->refname);
 
 	return 0;
 }
@@ -2834,7 +2827,6 @@ static int files_transaction_prepare(struct ref_store *ref_store,
 	 */
 	for (i = 0; i < transaction->nr; i++) {
 		struct ref_update *update = transaction->updates[i];
-		struct string_list_item *item;
 
 		if ((update->flags & REF_IS_PRUNING) &&
 		    !(update->flags & REF_NO_DEREF))
@@ -2843,13 +2835,7 @@ static int files_transaction_prepare(struct ref_store *ref_store,
 		if (update->flags & REF_LOG_ONLY)
 			continue;
 
-		item = string_list_append(&affected_refnames, update->refname);
-		/*
-		 * We store a pointer to update in item->util, but at
-		 * the moment we never use the value of this field
-		 * except to check whether it is non-NULL.
-		 */
-		item->util = update;
+		string_list_append(&affected_refnames, update->refname);
 	}
 	string_list_sort(&affected_refnames);
 	if (ref_update_reject_duplicates(&affected_refnames, err)) {
-- 
2.48.1
Junio C Hamano· Mar 5, 2025, 21:20 UTC · re: Karthik Nayak · lore

Re: [PATCH v3 1/8] refs/files: remove redundant check in split_symref_update()

Karthik Nayak <karthik.188@gmail.com> writes:
Show 15 quoted lines
> In `split_symref_update()`, there were two checks for duplicate
> refnames:
>
>   - At the start, `string_list_has_string()` ensures the refname is not
>     already in `affected_refnames`, preventing duplicates from being
>     added.
>
>   - After adding the refname, another check verifies whether the newly
>     inserted item has a `util` value.
>
> The second check is unnecessary because the first one guarantees that
> `string_list_insert()` will never encounter a preexisting entry.
>
> Since `item->util` is only used in this context, remove the assignment and
> simplify the surrounding code.

It was a bit unclear what "this context" refers to. We lost all assignments to the .util member and that is a safe thing to do because ...

Show 11 quoted lines
> @@ -2843,13 +2835,7 @@ static int files_transaction_prepare(struct ref_store *ref_store,
>  		if (update->flags & REF_LOG_ONLY)
>  			continue;
>  
> -		item = string_list_append(&affected_refnames, update->refname);
> -		/*
> -		 * We store a pointer to update in item->util, but at
> -		 * the moment we never use the value of this field
> -		 * except to check whether it is non-NULL.
> -		 */
> -		item->util = update;

... of this comment, and the "except to check whether" used to happen in this code ...

Show 8 quoted lines
>  	 * be valid as long as affected_refnames is in use, and NOT
>  	 * referent, which might soon be freed by our caller.
>  	 */
> -	item = string_list_insert(affected_refnames, new_update->refname);
> -	if (item->util)
> -		BUG("%s unexpectedly found in affected_refnames",
> -		    new_update->refname);
> -	item->util = new_update;
... which the patch removed.
OK.  Makes perfect sense.
Thanks.
Karthik Nayak· Mar 6, 2025, 09:13 UTC · re: Junio C Hamano · lore

Re: [PATCH v3 1/8] refs/files: remove redundant check in split_symref_update()

Junio C Hamano <gitster@pobox.com> writes:
Show 22 quoted lines
> Karthik Nayak <karthik.188@gmail.com> writes:
>
>> In `split_symref_update()`, there were two checks for duplicate
>> refnames:
>>
>>   - At the start, `string_list_has_string()` ensures the refname is not
>>     already in `affected_refnames`, preventing duplicates from being
>>     added.
>>
>>   - After adding the refname, another check verifies whether the newly
>>     inserted item has a `util` value.
>>
>> The second check is unnecessary because the first one guarantees that
>> `string_list_insert()` will never encounter a preexisting entry.
>>
>> Since `item->util` is only used in this context, remove the assignment and
>> simplify the surrounding code.
>
> It was a bit unclear what "this context" refers to.  We lost all
> assignments to the .util member and that is a safe thing to do
> because ...
>
Definitely could use some clarification. Will change to:
  The `item->util` field is assigned to validate that a rename doesn't
  already exist in the list. The validation is done after the first
  check. As this check is removed, clean up the validation and the
  assignment of this field.
Show 29 quoted lines
>> @@ -2843,13 +2835,7 @@ static int files_transaction_prepare(struct ref_store *ref_store,
>>  		if (update->flags & REF_LOG_ONLY)
>>  			continue;
>>
>> -		item = string_list_append(&affected_refnames, update->refname);
>> -		/*
>> -		 * We store a pointer to update in item->util, but at
>> -		 * the moment we never use the value of this field
>> -		 * except to check whether it is non-NULL.
>> -		 */
>> -		item->util = update;
>
> ... of this comment, and the "except to check whether" used to
> happen in this code ...
>
>>  	 * be valid as long as affected_refnames is in use, and NOT
>>  	 * referent, which might soon be freed by our caller.
>>  	 */
>> -	item = string_list_insert(affected_refnames, new_update->refname);
>> -	if (item->util)
>> -		BUG("%s unexpectedly found in affected_refnames",
>> -		    new_update->refname);
>> -	item->util = new_update;
>
> ... which the patch removed.
>
> OK.  Makes perfect sense.
>
> Thanks.
Thanks!
Karthik Nayak· Mar 5, 2025, 17:38 UTC · re: Karthik Nayak · lore

[PATCH v3 3/8] refs/files: remove duplicate duplicates check

Within the files reference backend's transaction's 'finish' phase, a verification step is currently performed wherein the refnames list is sorted and examined for multiple updates targeting the same refname.

It has been observed that this verification is redundant, as an identical check is already executed during the transaction's 'prepare' stage. Since the refnames list remains unmodified following the 'prepare' stage, this secondary verification can be safely eliminated.

The duplicate check has been removed accordingly, and the `ref_update_reject_duplicates()` function has been marked as static, as its usage is now confined to 'refs.c'.

Signed-off-by: Karthik Nayak <karthik.188@gmail.com>
---
 refs.c               | 9 +++++++--
 refs/files-backend.c | 6 ------
 refs/refs-internal.h | 8 --------
 3 files changed, 7 insertions(+), 16 deletions(-)
Show changes to 3 files +7 −16

refs.c, refs/files-backend.c, refs/refs-internal.h

diff --git a/refs.c b/refs.c
index ab69746947..69f385f344 100644
--- a/refs.c
+++ b/refs.c
@@ -2303,8 +2303,13 @@ int refs_update_symref_extended(struct ref_store *refs, const char *ref,
 	return ret;
 }
 
-int ref_update_reject_duplicates(struct string_list *refnames,
-				 struct strbuf *err)
+/*
+ * Write an error to `err` and return a nonzero value iff the same
+ * refname appears multiple times in `refnames`. `refnames` must be
+ * sorted on entry to this function.
+ */
+static int ref_update_reject_duplicates(struct string_list *refnames,
+					struct strbuf *err)
 {
 	size_t i, n = refnames->nr;
 
diff --git a/refs/files-backend.c b/refs/files-backend.c
index 85ed85ad87..7c6a0b3478 100644
--- a/refs/files-backend.c
+++ b/refs/files-backend.c
@@ -3016,12 +3016,6 @@ static int files_transaction_finish_initial(struct files_ref_store *refs,
 	if (transaction->state != REF_TRANSACTION_PREPARED)
 		BUG("commit called for transaction that is not prepared");
 
-	string_list_sort(&transaction->refnames);
-	if (ref_update_reject_duplicates(&transaction->refnames, err)) {
-		ret = TRANSACTION_GENERIC_ERROR;
-		goto cleanup;
-	}
-
 	/*
 	 * It's really undefined to call this function in an active
 	 * repository or when there are existing references: we are
diff --git a/refs/refs-internal.h b/refs/refs-internal.h
index 92db793026..6d3770d0cc 100644
--- a/refs/refs-internal.h
+++ b/refs/refs-internal.h
@@ -142,14 +142,6 @@ int refs_read_raw_ref(struct ref_store *ref_store, const char *refname,
 		      struct object_id *oid, struct strbuf *referent,
 		      unsigned int *type, int *failure_errno);
 
-/*
- * Write an error to `err` and return a nonzero value iff the same
- * refname appears multiple times in `refnames`. `refnames` must be
- * sorted on entry to this function.
- */
-int ref_update_reject_duplicates(struct string_list *refnames,
-				 struct strbuf *err);
-
 /*
  * Add a ref_update with the specified properties to transaction, and
  * return a pointer to the new object. This function does not verify
-- 
2.48.1
Karthik Nayak· Mar 5, 2025, 17:38 UTC · re: Karthik Nayak · lore

[PATCH v3 2/8] refs: move duplicate refname update check to generic layer

Move the tracking of refnames in `affected_refnames` from individual backends into the generic layer in 'refs.c'. This centralizes the duplicate refname detection that was previously handled separately by each backend.

Make some changes to accommodate this move:
  - Add a `string_list` field `refnames` to `ref_transaction` to contain
    all the references in a transaction. This field is updated whenever
    a new update is added via `ref_transaction_add_update`, so manual
    additions in reference backends are dropped.
  - Modify the backends to use this field internally as needed. The
    backends need to check if an update for refname already exists when
    splitting symrefs or adding an update for 'HEAD'.
  - In the reftable backend, within `reftable_be_transaction_prepare()`,
    move the `string_list_has_string()` check above
    `ref_transaction_add_update()`. Since `ref_transaction_add_update()`
    automatically adds the refname to `transaction->refnames`,
    performing the check after will always return true, so we perform
    the check before adding the update.

This helps reduce duplication of functionality between the backends and makes it easier to make changes in a more centralized manner.

Signed-off-by: Karthik Nayak <karthik.188@gmail.com>
---
 refs.c                  | 17 +++++++++++++
 refs/files-backend.c    | 67 +++++++++++--------------------------------------
 refs/packed-backend.c   | 25 +-----------------
 refs/refs-internal.h    |  2 ++
 refs/reftable-backend.c | 54 +++++++++++++--------------------------
 5 files changed, 51 insertions(+), 114 deletions(-)
Show changes to 5 files +51 −114

refs.c, refs/files-backend.c, refs/packed-backend.c, refs/refs-internal.h, refs/reftable-backend.c

diff --git a/refs.c b/refs.c
index 54fd5ce21e..ab69746947 100644
--- a/refs.c
+++ b/refs.c
@@ -1175,6 +1175,7 @@ struct ref_transaction *ref_store_transaction_begin(struct ref_store *refs,
 	CALLOC_ARRAY(tr, 1);
 	tr->ref_store = refs;
 	tr->flags = flags;
+	string_list_init_dup(&tr->refnames);
 	return tr;
 }
 
@@ -1205,6 +1206,7 @@ void ref_transaction_free(struct ref_transaction *transaction)
 		free((char *)transaction->updates[i]->old_target);
 		free(transaction->updates[i]);
 	}
+	string_list_clear(&transaction->refnames, 0);
 	free(transaction->updates);
 	free(transaction);
 }
@@ -1218,6 +1220,7 @@ struct ref_update *ref_transaction_add_update(
 		const char *committer_info,
 		const char *msg)
 {
+	struct string_list_item *item;
 	struct ref_update *update;
 
 	if (transaction->state != REF_TRANSACTION_OPEN)
@@ -1245,6 +1248,16 @@ struct ref_update *ref_transaction_add_update(
 		update->msg = normalize_reflog_message(msg);
 	}
 
+	/*
+	 * This list is generally used by the backends to avoid duplicates.
+	 * But we do support multiple log updates for a given refname within
+	 * a single transaction.
+	 */
+	if (!(update->flags & REF_LOG_ONLY)) {
+		item = string_list_append(&transaction->refnames, refname);
+		item->util = update;
+	}
+
 	return update;
 }
 
@@ -2405,6 +2418,10 @@ int ref_transaction_prepare(struct ref_transaction *transaction,
 		return -1;
 	}
 
+	string_list_sort(&transaction->refnames);
+	if (ref_update_reject_duplicates(&transaction->refnames, err))
+		return TRANSACTION_GENERIC_ERROR;
+
 	ret = refs->be->transaction_prepare(refs, transaction, err);
 	if (ret)
 		return ret;
diff --git a/refs/files-backend.c b/refs/files-backend.c
index 6c7df30738..85ed85ad87 100644
--- a/refs/files-backend.c
+++ b/refs/files-backend.c
@@ -2378,9 +2378,7 @@ static struct ref_iterator *files_reflog_iterator_begin(struct ref_store *ref_st
  */
 static int split_head_update(struct ref_update *update,
 			     struct ref_transaction *transaction,
-			     const char *head_ref,
-			     struct string_list *affected_refnames,
-			     struct strbuf *err)
+			     const char *head_ref, struct strbuf *err)
 {
 	struct ref_update *new_update;
 
@@ -2398,7 +2396,7 @@ static int split_head_update(struct ref_update *update,
 	 * transaction. This check is O(lg N) in the transaction
 	 * size, but it happens at most once per transaction.
 	 */
-	if (string_list_has_string(affected_refnames, "HEAD")) {
+	if (string_list_has_string(&transaction->refnames, "HEAD")) {
 		/* An entry already existed */
 		strbuf_addf(err,
 			    "multiple updates for 'HEAD' (including one "
@@ -2420,7 +2418,6 @@ static int split_head_update(struct ref_update *update,
 	 */
 	if (strcmp(new_update->refname, "HEAD"))
 		BUG("%s unexpectedly not 'HEAD'", new_update->refname);
-	string_list_insert(affected_refnames, new_update->refname);
 
 	return 0;
 }
@@ -2436,7 +2433,6 @@ static int split_head_update(struct ref_update *update,
 static int split_symref_update(struct ref_update *update,
 			       const char *referent,
 			       struct ref_transaction *transaction,
-			       struct string_list *affected_refnames,
 			       struct strbuf *err)
 {
 	struct ref_update *new_update;
@@ -2448,7 +2444,7 @@ static int split_symref_update(struct ref_update *update,
 	 * size, but it happens at most once per symref in a
 	 * transaction.
 	 */
-	if (string_list_has_string(affected_refnames, referent)) {
+	if (string_list_has_string(&transaction->refnames, referent)) {
 		/* An entry already exists */
 		strbuf_addf(err,
 			    "multiple updates for '%s' (including one "
@@ -2486,15 +2482,6 @@ static int split_symref_update(struct ref_update *update,
 	update->flags |= REF_LOG_ONLY | REF_NO_DEREF;
 	update->flags &= ~REF_HAVE_OLD;
 
-	/*
-	 * Add the referent. This insertion is O(N) in the transaction
-	 * size, but it happens at most once per symref in a
-	 * transaction. Make sure to add new_update->refname, which will
-	 * be valid as long as affected_refnames is in use, and NOT
-	 * referent, which might soon be freed by our caller.
-	 */
-	string_list_insert(affected_refnames, new_update->refname);
-
 	return 0;
 }
 
@@ -2558,7 +2545,6 @@ static int lock_ref_for_update(struct files_ref_store *refs,
 			       struct ref_transaction *transaction,
 			       const char *head_ref,
 			       struct string_list *refnames_to_check,
-			       struct string_list *affected_refnames,
 			       struct strbuf *err)
 {
 	struct strbuf referent = STRBUF_INIT;
@@ -2575,8 +2561,7 @@ static int lock_ref_for_update(struct files_ref_store *refs,
 		update->flags |= REF_DELETING;
 
 	if (head_ref) {
-		ret = split_head_update(update, transaction, head_ref,
-					affected_refnames, err);
+		ret = split_head_update(update, transaction, head_ref, err);
 		if (ret)
 			goto out;
 	}
@@ -2586,9 +2571,8 @@ static int lock_ref_for_update(struct files_ref_store *refs,
 		lock->count++;
 	} else {
 		ret = lock_raw_ref(refs, update->refname, mustexist,
-				   refnames_to_check, affected_refnames,
-				   &lock, &referent,
-				   &update->type, err);
+				   refnames_to_check, &transaction->refnames,
+				   &lock, &referent, &update->type, err);
 		if (ret) {
 			char *reason;
 
@@ -2642,9 +2626,8 @@ static int lock_ref_for_update(struct files_ref_store *refs,
 			 * of processing the split-off update, so we
 			 * don't have to do it here.
 			 */
-			ret = split_symref_update(update,
-						  referent.buf, transaction,
-						  affected_refnames, err);
+			ret = split_symref_update(update, referent.buf,
+						  transaction, err);
 			if (ret)
 				goto out;
 		}
@@ -2799,7 +2782,6 @@ static int files_transaction_prepare(struct ref_store *ref_store,
 			       "ref_transaction_prepare");
 	size_t i;
 	int ret = 0;
-	struct string_list affected_refnames = STRING_LIST_INIT_NODUP;
 	struct string_list refnames_to_check = STRING_LIST_INIT_NODUP;
 	char *head_ref = NULL;
 	int head_type;
@@ -2818,12 +2800,7 @@ static int files_transaction_prepare(struct ref_store *ref_store,
 	transaction->backend_data = backend_data;
 
 	/*
-	 * Fail if a refname appears more than once in the
-	 * transaction. (If we end up splitting up any updates using
-	 * split_symref_update() or split_head_update(), those
-	 * functions will check that the new updates don't have the
-	 * same refname as any existing ones.) Also fail if any of the
-	 * updates use REF_IS_PRUNING without REF_NO_DEREF.
+	 * Fail if any of the updates use REF_IS_PRUNING without REF_NO_DEREF.
 	 */
 	for (i = 0; i < transaction->nr; i++) {
 		struct ref_update *update = transaction->updates[i];
@@ -2831,16 +2808,6 @@ static int files_transaction_prepare(struct ref_store *ref_store,
 		if ((update->flags & REF_IS_PRUNING) &&
 		    !(update->flags & REF_NO_DEREF))
 			BUG("REF_IS_PRUNING set without REF_NO_DEREF");
-
-		if (update->flags & REF_LOG_ONLY)
-			continue;
-
-		string_list_append(&affected_refnames, update->refname);
-	}
-	string_list_sort(&affected_refnames);
-	if (ref_update_reject_duplicates(&affected_refnames, err)) {
-		ret = TRANSACTION_GENERIC_ERROR;
-		goto cleanup;
 	}
 
 	/*
@@ -2882,7 +2849,7 @@ static int files_transaction_prepare(struct ref_store *ref_store,
 
 		ret = lock_ref_for_update(refs, update, transaction,
 					  head_ref, &refnames_to_check,
-					  &affected_refnames, err);
+					  err);
 		if (ret)
 			goto cleanup;
 
@@ -2929,7 +2896,7 @@ static int files_transaction_prepare(struct ref_store *ref_store,
 	 * So instead, we accept the race for now.
 	 */
 	if (refs_verify_refnames_available(refs->packed_ref_store, &refnames_to_check,
-					   &affected_refnames, NULL, 0, err)) {
+					   &transaction->refnames, NULL, 0, err)) {
 		ret = TRANSACTION_NAME_CONFLICT;
 		goto cleanup;
 	}
@@ -2975,7 +2942,6 @@ static int files_transaction_prepare(struct ref_store *ref_store,
 
 cleanup:
 	free(head_ref);
-	string_list_clear(&affected_refnames, 0);
 	string_list_clear(&refnames_to_check, 0);
 
 	if (ret)
@@ -3050,13 +3016,8 @@ static int files_transaction_finish_initial(struct files_ref_store *refs,
 	if (transaction->state != REF_TRANSACTION_PREPARED)
 		BUG("commit called for transaction that is not prepared");
 
-	/* Fail if a refname appears more than once in the transaction: */
-	for (i = 0; i < transaction->nr; i++)
-		if (!(transaction->updates[i]->flags & REF_LOG_ONLY))
-			string_list_append(&affected_refnames,
-					   transaction->updates[i]->refname);
-	string_list_sort(&affected_refnames);
-	if (ref_update_reject_duplicates(&affected_refnames, err)) {
+	string_list_sort(&transaction->refnames);
+	if (ref_update_reject_duplicates(&transaction->refnames, err)) {
 		ret = TRANSACTION_GENERIC_ERROR;
 		goto cleanup;
 	}
@@ -3074,7 +3035,7 @@ static int files_transaction_finish_initial(struct files_ref_store *refs,
 	 * that we are creating already exists.
 	 */
 	if (refs_for_each_rawref(&refs->base, ref_present,
-				 &affected_refnames))
+				 &transaction->refnames))
 		BUG("initial ref transaction called with existing refs");
 
 	packed_transaction = ref_store_transaction_begin(refs->packed_ref_store,
diff --git a/refs/packed-backend.c b/refs/packed-backend.c
index f4c82ba2c7..19220d2e99 100644
--- a/refs/packed-backend.c
+++ b/refs/packed-backend.c
@@ -1622,8 +1622,6 @@ int is_packed_transaction_needed(struct ref_store *ref_store,
 struct packed_transaction_backend_data {
 	/* True iff the transaction owns the packed-refs lock. */
 	int own_lock;
-
-	struct string_list updates;
 };
 
 static void packed_transaction_cleanup(struct packed_ref_store *refs,
@@ -1632,8 +1630,6 @@ static void packed_transaction_cleanup(struct packed_ref_store *refs,
 	struct packed_transaction_backend_data *data = transaction->backend_data;
 
 	if (data) {
-		string_list_clear(&data->updates, 0);
-
 		if (is_tempfile_active(refs->tempfile))
 			delete_tempfile(&refs->tempfile);
 
@@ -1658,7 +1654,6 @@ static int packed_transaction_prepare(struct ref_store *ref_store,
 			REF_STORE_READ | REF_STORE_WRITE | REF_STORE_ODB,
 			"ref_transaction_prepare");
 	struct packed_transaction_backend_data *data;
-	size_t i;
 	int ret = TRANSACTION_GENERIC_ERROR;
 
 	/*
@@ -1671,34 +1666,16 @@ static int packed_transaction_prepare(struct ref_store *ref_store,
 	 */
 
 	CALLOC_ARRAY(data, 1);
-	string_list_init_nodup(&data->updates);
 
 	transaction->backend_data = data;
 
-	/*
-	 * Stick the updates in a string list by refname so that we
-	 * can sort them:
-	 */
-	for (i = 0; i < transaction->nr; i++) {
-		struct ref_update *update = transaction->updates[i];
-		struct string_list_item *item =
-			string_list_append(&data->updates, update->refname);
-
-		/* Store a pointer to update in item->util: */
-		item->util = update;
-	}
-	string_list_sort(&data->updates);
-
-	if (ref_update_reject_duplicates(&data->updates, err))
-		goto failure;
-
 	if (!is_lock_file_locked(&refs->lock)) {
 		if (packed_refs_lock(ref_store, 0, err))
 			goto failure;
 		data->own_lock = 1;
 	}
 
-	if (write_with_updates(refs, &data->updates, err))
+	if (write_with_updates(refs, &transaction->refnames, err))
 		goto failure;
 
 	transaction->state = REF_TRANSACTION_PREPARED;
diff --git a/refs/refs-internal.h b/refs/refs-internal.h
index e5862757a7..92db793026 100644
--- a/refs/refs-internal.h
+++ b/refs/refs-internal.h
@@ -3,6 +3,7 @@
 
 #include "refs.h"
 #include "iterator.h"
+#include "string-list.h"
 
 struct fsck_options;
 struct ref_transaction;
@@ -198,6 +199,7 @@ enum ref_transaction_state {
 struct ref_transaction {
 	struct ref_store *ref_store;
 	struct ref_update **updates;
+	struct string_list refnames;
 	size_t alloc;
 	size_t nr;
 	enum ref_transaction_state state;
diff --git a/refs/reftable-backend.c b/refs/reftable-backend.c
index 441b8c69c1..f616d9aabe 100644
--- a/refs/reftable-backend.c
+++ b/refs/reftable-backend.c
@@ -1076,7 +1076,6 @@ static int reftable_be_transaction_prepare(struct ref_store *ref_store,
 	struct reftable_ref_store *refs =
 		reftable_be_downcast(ref_store, REF_STORE_WRITE|REF_STORE_MAIN, "ref_transaction_prepare");
 	struct strbuf referent = STRBUF_INIT, head_referent = STRBUF_INIT;
-	struct string_list affected_refnames = STRING_LIST_INIT_NODUP;
 	struct string_list refnames_to_check = STRING_LIST_INIT_NODUP;
 	struct reftable_transaction_data *tx_data = NULL;
 	struct reftable_backend *be;
@@ -1101,10 +1100,6 @@ static int reftable_be_transaction_prepare(struct ref_store *ref_store,
 						 transaction->updates[i], err);
 		if (ret)
 			goto done;
-
-		if (!(transaction->updates[i]->flags & REF_LOG_ONLY))
-			string_list_append(&affected_refnames,
-					   transaction->updates[i]->refname);
 	}
 
 	/*
@@ -1116,17 +1111,6 @@ static int reftable_be_transaction_prepare(struct ref_store *ref_store,
 		tx_data->args[i].updates_alloc = tx_data->args[i].updates_expected;
 	}
 
-	/*
-	 * Fail if a refname appears more than once in the transaction.
-	 * This code is taken from the files backend and is a good candidate to
-	 * be moved into the generic layer.
-	 */
-	string_list_sort(&affected_refnames);
-	if (ref_update_reject_duplicates(&affected_refnames, err)) {
-		ret = TRANSACTION_GENERIC_ERROR;
-		goto done;
-	}
-
 	/*
 	 * TODO: it's dubious whether we should reload the stack that "HEAD"
 	 * belongs to or not. In theory, it may happen that we only modify
@@ -1194,14 +1178,12 @@ static int reftable_be_transaction_prepare(struct ref_store *ref_store,
 		    !(u->flags & REF_LOG_ONLY) &&
 		    !(u->flags & REF_UPDATE_VIA_HEAD) &&
 		    !strcmp(rewritten_ref, head_referent.buf)) {
-			struct ref_update *new_update;
-
 			/*
 			 * First make sure that HEAD is not already in the
 			 * transaction. This check is O(lg N) in the transaction
 			 * size, but it happens at most once per transaction.
 			 */
-			if (string_list_has_string(&affected_refnames, "HEAD")) {
+			if (string_list_has_string(&transaction->refnames, "HEAD")) {
 				/* An entry already existed */
 				strbuf_addf(err,
 					    _("multiple updates for 'HEAD' (including one "
@@ -1211,12 +1193,11 @@ static int reftable_be_transaction_prepare(struct ref_store *ref_store,
 				goto done;
 			}
 
-			new_update = ref_transaction_add_update(
-					transaction, "HEAD",
-					u->flags | REF_LOG_ONLY | REF_NO_DEREF,
-					&u->new_oid, &u->old_oid, NULL, NULL, NULL,
-					u->msg);
-			string_list_insert(&affected_refnames, new_update->refname);
+			ref_transaction_add_update(
+				transaction, "HEAD",
+				u->flags | REF_LOG_ONLY | REF_NO_DEREF,
+				&u->new_oid, &u->old_oid, NULL, NULL, NULL,
+				u->msg);
 		}
 
 		ret = reftable_backend_read_ref(be, rewritten_ref,
@@ -1281,6 +1262,15 @@ static int reftable_be_transaction_prepare(struct ref_store *ref_store,
 				if (!strcmp(rewritten_ref, "HEAD"))
 					new_flags |= REF_UPDATE_VIA_HEAD;
 
+				if (string_list_has_string(&transaction->refnames, referent.buf)) {
+					strbuf_addf(err,
+						    _("multiple updates for '%s' (including one "
+						    "via symref '%s') are not allowed"),
+						    referent.buf, u->refname);
+					ret = TRANSACTION_NAME_CONFLICT;
+					goto done;
+				}
+
 				/*
 				 * If we are updating a symref (eg. HEAD), we should also
 				 * update the branch that the symref points to.
@@ -1305,16 +1295,6 @@ static int reftable_be_transaction_prepare(struct ref_store *ref_store,
 				 */
 				u->flags |= REF_LOG_ONLY | REF_NO_DEREF;
 				u->flags &= ~REF_HAVE_OLD;
-
-				if (string_list_has_string(&affected_refnames, new_update->refname)) {
-					strbuf_addf(err,
-						    _("multiple updates for '%s' (including one "
-						    "via symref '%s') are not allowed"),
-						    referent.buf, u->refname);
-					ret = TRANSACTION_NAME_CONFLICT;
-					goto done;
-				}
-				string_list_insert(&affected_refnames, new_update->refname);
 			}
 		}
 
@@ -1384,7 +1364,8 @@ static int reftable_be_transaction_prepare(struct ref_store *ref_store,
 	}
 
 	string_list_sort(&refnames_to_check);
-	ret = refs_verify_refnames_available(ref_store, &refnames_to_check, &affected_refnames, NULL,
+	ret = refs_verify_refnames_available(ref_store, &refnames_to_check,
+					     &transaction->refnames, NULL,
 					     transaction->flags & REF_TRANSACTION_FLAG_INITIAL,
 					     err);
 	if (ret < 0)
@@ -1402,7 +1383,6 @@ static int reftable_be_transaction_prepare(struct ref_store *ref_store,
 			strbuf_addf(err, _("reftable: transaction prepare: %s"),
 				    reftable_error_str(ret));
 	}
-	string_list_clear(&affected_refnames, 0);
 	strbuf_release(&referent);
 	strbuf_release(&head_referent);
 	string_list_clear(&refnames_to_check, 0);
-- 
2.48.1
Junio C Hamano· Mar 5, 2025, 21:56 UTC · re: Karthik Nayak · lore

Re: [PATCH v3 2/8] refs: move duplicate refname update check to generic layer

Karthik Nayak <karthik.188@gmail.com> writes:
Show 11 quoted lines
> Move the tracking of refnames in `affected_refnames` from individual
> backends into the generic layer in 'refs.c'. This centralizes the
> duplicate refname detection that was previously handled separately by
> each backend.
>
> Make some changes to accommodate this move:
>
>   - Add a `string_list` field `refnames` to `ref_transaction` to contain
>     all the references in a transaction. This field is updated whenever
>     a new update is added via `ref_transaction_add_update`, so manual
>     additions in reference backends are dropped.

The transaction object is the most logical place to keep track of what is involved in the transaction. Nice.

>   - Modify the backends to use this field internally as needed. The
>     backends need to check if an update for refname already exists when
>     splitting symrefs or adding an update for 'HEAD'.

The above reads to me as if you are saying that the files backend needs to notice that it is updating "HEAD", notice that it is a symbolic ref that points at "refs/heads/main", notice that "HEAD" and "refs/heads/main" are the two things involved in the transaction, and must check if an update is already queued.

But when an update changes a symbolic ref in the sense that the underlying ref gets updated through it, the need to update both the underlying ref and the symbolic ref is common across backends, isn't it? IOW, shouldn't "splitting symrefs" (which I take to mean "ah, we are updating HEAD so we need to update it and at the same time update the underlying refs/heads/main, two updates in total") be done also at the generic layer?

And if that happens at the generic layer, should .refname member even be visible to backends?

Show 6 quoted lines
>   - In the reftable backend, within `reftable_be_transaction_prepare()`,
>     move the `string_list_has_string()` check above
>     `ref_transaction_add_update()`. Since `ref_transaction_add_update()`
>     automatically adds the refname to `transaction->refnames`,
>     performing the check after will always return true, so we perform
>     the check before adding the update.

This change makes perfect tense. It is the most natural to check and modify at the transaction layer the .refnames member, as it belongs at the transaction layer after all.

> This helps reduce duplication of functionality between the backends and
> makes it easier to make changes in a more centralized manner.
Nice.
Karthik Nayak· Mar 6, 2025, 09:46 UTC · re: Junio C Hamano · lore

Re: [PATCH v3 2/8] refs: move duplicate refname update check to generic layer

Junio C Hamano <gitster@pobox.com> writes:
Show 34 quoted lines
> Karthik Nayak <karthik.188@gmail.com> writes:
>
>> Move the tracking of refnames in `affected_refnames` from individual
>> backends into the generic layer in 'refs.c'. This centralizes the
>> duplicate refname detection that was previously handled separately by
>> each backend.
>>
>> Make some changes to accommodate this move:
>>
>>   - Add a `string_list` field `refnames` to `ref_transaction` to contain
>>     all the references in a transaction. This field is updated whenever
>>     a new update is added via `ref_transaction_add_update`, so manual
>>     additions in reference backends are dropped.
>
> The transaction object is the most logical place to keep track of
> what is involved in the transaction.  Nice.
>
>>   - Modify the backends to use this field internally as needed. The
>>     backends need to check if an update for refname already exists when
>>     splitting symrefs or adding an update for 'HEAD'.
>
> The above reads to me as if you are saying that the files backend
> needs to notice that it is updating "HEAD", notice that it is a
> symbolic ref that points at "refs/heads/main", notice that "HEAD"
> and "refs/heads/main" are the two things involved in the
> transaction, and must check if an update is already queued.
>
> But when an update changes a symbolic ref in the sense that the
> underlying ref gets updated through it, the need to update both the
> underlying ref and the symbolic ref is common across backends, isn't
> it?  IOW, shouldn't "splitting symrefs" (which I take to mean "ah,
> we are updating HEAD so we need to update it and at the same time
> update the underlying refs/heads/main, two updates in total") be
> done also at the generic layer?

Yup that is correct, in the files backend, we do this via the 'split_symref_update()' function and in the reftable backend it is directly handled in the 'reftable_be_transaction_prepare()' function.

I don't have a reason for why I didn't undertake that too in this series. Mostly I think I didn't observe it. But it something that can/should be done in the future.

>
> And if that happens at the generic layer, should .refname member
> even be visible to backends?
>

It shouldn't be necessary anymore with that change. I think this is good step in that direction.

Show 15 quoted lines
>>   - In the reftable backend, within `reftable_be_transaction_prepare()`,
>>     move the `string_list_has_string()` check above
>>     `ref_transaction_add_update()`. Since `ref_transaction_add_update()`
>>     automatically adds the refname to `transaction->refnames`,
>>     performing the check after will always return true, so we perform
>>     the check before adding the update.
>
> This change makes perfect tense.  It is the most natural to check
> and modify at the transaction layer the .refnames member, as it
> belongs at the transaction layer after all.
>
>> This helps reduce duplication of functionality between the backends and
>> makes it easier to make changes in a more centralized manner.
>
> Nice.
Karthik Nayak· Mar 5, 2025, 17:38 UTC · re: Karthik Nayak · lore

[PATCH v3 4/8] refs/reftable: extract code from the transaction preparation

Extract the core logic for preparing individual reference updates from `reftable_be_transaction_prepare()` into `prepare_single_update()`. This dedicated function now handles all validation and preparation steps for each reference update in the transaction, including object ID verification, HEAD reference handling, and symref processing.

The refactoring consolidates all reference update validation into a single logical block, which improves code maintainability and readability. More importantly, this restructuring lays the groundwork for implementing partial transaction support in the reftable backend, which will be introduced in the following commit.

No functional changes are included in this commit - it is purely a code reorganization to support future enhancements.

Signed-off-by: Karthik Nayak <karthik.188@gmail.com>
---
 refs/reftable-backend.c | 463 +++++++++++++++++++++++++-----------------------
 1 file changed, 237 insertions(+), 226 deletions(-)
Show changes to refs/reftable-backend.c +237 −226
diff --git a/refs/reftable-backend.c b/refs/reftable-backend.c
index f616d9aabe..2c1e2995de 100644
--- a/refs/reftable-backend.c
+++ b/refs/reftable-backend.c
@@ -1069,6 +1069,239 @@ static int queue_transaction_update(struct reftable_ref_store *refs,
 	return 0;
 }
 
+static int prepare_single_update(struct reftable_ref_store *refs,
+				 struct reftable_transaction_data *tx_data,
+				 struct ref_transaction *transaction,
+				 struct reftable_backend *be,
+				 struct ref_update *u,
+				 struct string_list *refnames_to_check,
+				 unsigned int head_type,
+				 struct strbuf *head_referent,
+				 struct strbuf *referent,
+				 struct strbuf *err)
+{
+	struct object_id current_oid = {0};
+	const char *rewritten_ref;
+	int ret = 0;
+
+	/*
+	 * There is no need to reload the respective backends here as
+	 * we have already reloaded them when preparing the transaction
+	 * update. And given that the stacks have been locked there
+	 * shouldn't have been any concurrent modifications of the
+	 * stack.
+	 */
+	ret = backend_for(&be, refs, u->refname, &rewritten_ref, 0);
+	if (ret)
+		return ret;
+
+	/* Verify that the new object ID is valid. */
+	if ((u->flags & REF_HAVE_NEW) && !is_null_oid(&u->new_oid) &&
+	    !(u->flags & REF_SKIP_OID_VERIFICATION) &&
+	    !(u->flags & REF_LOG_ONLY)) {
+		struct object *o = parse_object(refs->base.repo, &u->new_oid);
+		if (!o) {
+			strbuf_addf(err,
+				    _("trying to write ref '%s' with nonexistent object %s"),
+				    u->refname, oid_to_hex(&u->new_oid));
+			return -1;
+		}
+
+		if (o->type != OBJ_COMMIT && is_branch(u->refname)) {
+			strbuf_addf(err, _("trying to write non-commit object %s to branch '%s'"),
+				    oid_to_hex(&u->new_oid), u->refname);
+			return -1;
+		}
+	}
+
+	/*
+	 * When we update the reference that HEAD points to we enqueue
+	 * a second log-only update for HEAD so that its reflog is
+	 * updated accordingly.
+	 */
+	if (head_type == REF_ISSYMREF &&
+	    !(u->flags & REF_LOG_ONLY) &&
+	    !(u->flags & REF_UPDATE_VIA_HEAD) &&
+	    !strcmp(rewritten_ref, head_referent->buf)) {
+		/*
+		 * First make sure that HEAD is not already in the
+		 * transaction. This check is O(lg N) in the transaction
+		 * size, but it happens at most once per transaction.
+		 */
+		if (string_list_has_string(&transaction->refnames, "HEAD")) {
+			/* An entry already existed */
+			strbuf_addf(err,
+				    _("multiple updates for 'HEAD' (including one "
+				      "via its referent '%s') are not allowed"),
+				    u->refname);
+			return TRANSACTION_NAME_CONFLICT;
+		}
+
+		ref_transaction_add_update(
+			transaction, "HEAD",
+			u->flags | REF_LOG_ONLY | REF_NO_DEREF,
+			&u->new_oid, &u->old_oid, NULL, NULL, NULL,
+			u->msg);
+	}
+
+	ret = reftable_backend_read_ref(be, rewritten_ref,
+					&current_oid, referent, &u->type);
+	if (ret < 0)
+		return ret;
+	if (ret > 0 && !ref_update_expects_existing_old_ref(u)) {
+		/*
+		 * The reference does not exist, and we either have no
+		 * old object ID or expect the reference to not exist.
+		 * We can thus skip below safety checks as well as the
+		 * symref splitting. But we do want to verify that
+		 * there is no conflicting reference here so that we
+		 * can output a proper error message instead of failing
+		 * at a later point.
+		 */
+		string_list_append(refnames_to_check, u->refname);
+
+		/*
+		 * There is no need to write the reference deletion
+		 * when the reference in question doesn't exist.
+		 */
+		if ((u->flags & REF_HAVE_NEW) && !ref_update_has_null_new_value(u)) {
+			ret = queue_transaction_update(refs, tx_data, u,
+						       &current_oid, err);
+			if (ret)
+				return ret;
+		}
+
+		return 0;
+	}
+	if (ret > 0) {
+		/* The reference does not exist, but we expected it to. */
+		strbuf_addf(err, _("cannot lock ref '%s': "
+
+
+				   "unable to resolve reference '%s'"),
+			    ref_update_original_update_refname(u), u->refname);
+		return -1;
+	}
+
+	if (u->type & REF_ISSYMREF) {
+		/*
+		 * The reftable stack is locked at this point already,
+		 * so it is safe to call `refs_resolve_ref_unsafe()`
+		 * here without causing races.
+		 */
+		const char *resolved = refs_resolve_ref_unsafe(&refs->base, u->refname, 0,
+							       &current_oid, NULL);
+
+		if (u->flags & REF_NO_DEREF) {
+			if (u->flags & REF_HAVE_OLD && !resolved) {
+				strbuf_addf(err, _("cannot lock ref '%s': "
+						   "error reading reference"), u->refname);
+				return -1;
+			}
+		} else {
+			struct ref_update *new_update;
+			int new_flags;
+
+			new_flags = u->flags;
+			if (!strcmp(rewritten_ref, "HEAD"))
+				new_flags |= REF_UPDATE_VIA_HEAD;
+
+			if (string_list_has_string(&transaction->refnames, referent->buf)) {
+				strbuf_addf(err,
+					    _("multiple updates for '%s' (including one "
+					      "via symref '%s') are not allowed"),
+					    referent->buf, u->refname);
+				return TRANSACTION_NAME_CONFLICT;
+			}
+
+			/*
+			 * If we are updating a symref (eg. HEAD), we should also
+			 * update the branch that the symref points to.
+			 *
+			 * This is generic functionality, and would be better
+			 * done in refs.c, but the current implementation is
+			 * intertwined with the locking in files-backend.c.
+			 */
+			new_update = ref_transaction_add_update(
+				transaction, referent->buf, new_flags,
+				u->new_target ? NULL : &u->new_oid,
+				u->old_target ? NULL : &u->old_oid,
+				u->new_target, u->old_target,
+				u->committer_info, u->msg);
+
+			new_update->parent_update = u;
+
+			/*
+			 * Change the symbolic ref update to log only. Also, it
+			 * doesn't need to check its old OID value, as that will be
+			 * done when new_update is processed.
+			 */
+			u->flags |= REF_LOG_ONLY | REF_NO_DEREF;
+			u->flags &= ~REF_HAVE_OLD;
+		}
+	}
+
+	/*
+	 * Verify that the old object matches our expectations. Note
+	 * that the error messages here do not make a lot of sense in
+	 * the context of the reftable backend as we never lock
+	 * individual refs. But the error messages match what the files
+	 * backend returns, which keeps our tests happy.
+	 */
+	if (u->old_target) {
+		if (!(u->type & REF_ISSYMREF)) {
+			strbuf_addf(err, _("cannot lock ref '%s': "
+					   "expected symref with target '%s': "
+					   "but is a regular ref"),
+				    ref_update_original_update_refname(u),
+				    u->old_target);
+			return -1;
+		}
+
+		if (ref_update_check_old_target(referent->buf, u, err)) {
+			return -1;
+		}
+	} else if ((u->flags & REF_HAVE_OLD) && !oideq(&current_oid, &u->old_oid)) {
+		if (is_null_oid(&u->old_oid)) {
+			strbuf_addf(err, _("cannot lock ref '%s': "
+					   "reference already exists"),
+				    ref_update_original_update_refname(u));
+			return TRANSACTION_CREATE_EXISTS;
+		}
+		else if (is_null_oid(&current_oid))
+			strbuf_addf(err, _("cannot lock ref '%s': "
+					   "reference is missing but expected %s"),
+				    ref_update_original_update_refname(u),
+				    oid_to_hex(&u->old_oid));
+		else
+			strbuf_addf(err, _("cannot lock ref '%s': "
+					   "is at %s but expected %s"),
+				    ref_update_original_update_refname(u),
+				    oid_to_hex(&current_oid),
+				    oid_to_hex(&u->old_oid));
+		return TRANSACTION_NAME_CONFLICT;
+	}
+
+	/*
+	 * If all of the following conditions are true:
+	 *
+	 *   - We're not about to write a symref.
+	 *   - We're not about to write a log-only entry.
+	 *   - Old and new object ID are different.
+	 *
+	 * Then we're essentially doing a no-op update that can be
+	 * skipped. This is not only for the sake of efficiency, but
+	 * also skips writing unneeded reflog entries.
+	 */
+	if ((u->type & REF_ISSYMREF) ||
+	    (u->flags & REF_LOG_ONLY) ||
+	    (u->flags & REF_HAVE_NEW && !oideq(&current_oid, &u->new_oid)))
+		return queue_transaction_update(refs, tx_data, u,
+					       &current_oid, err);
+
+	return 0;
+}
+
 static int reftable_be_transaction_prepare(struct ref_store *ref_store,
 					   struct ref_transaction *transaction,
 					   struct strbuf *err)
@@ -1133,234 +1366,12 @@ static int reftable_be_transaction_prepare(struct ref_store *ref_store,
 	ret = 0;
 
 	for (i = 0; i < transaction->nr; i++) {
-		struct ref_update *u = transaction->updates[i];
-		struct object_id current_oid = {0};
-		const char *rewritten_ref;
-
-		/*
-		 * There is no need to reload the respective backends here as
-		 * we have already reloaded them when preparing the transaction
-		 * update. And given that the stacks have been locked there
-		 * shouldn't have been any concurrent modifications of the
-		 * stack.
-		 */
-		ret = backend_for(&be, refs, u->refname, &rewritten_ref, 0);
+		ret = prepare_single_update(refs, tx_data, transaction, be,
+					    transaction->updates[i],
+					    &refnames_to_check, head_type,
+					    &head_referent, &referent, err);
 		if (ret)
 			goto done;
-
-		/* Verify that the new object ID is valid. */
-		if ((u->flags & REF_HAVE_NEW) && !is_null_oid(&u->new_oid) &&
-		    !(u->flags & REF_SKIP_OID_VERIFICATION) &&
-		    !(u->flags & REF_LOG_ONLY)) {
-			struct object *o = parse_object(refs->base.repo, &u->new_oid);
-			if (!o) {
-				strbuf_addf(err,
-					    _("trying to write ref '%s' with nonexistent object %s"),
-					    u->refname, oid_to_hex(&u->new_oid));
-				ret = -1;
-				goto done;
-			}
-
-			if (o->type != OBJ_COMMIT && is_branch(u->refname)) {
-				strbuf_addf(err, _("trying to write non-commit object %s to branch '%s'"),
-					    oid_to_hex(&u->new_oid), u->refname);
-				ret = -1;
-				goto done;
-			}
-		}
-
-		/*
-		 * When we update the reference that HEAD points to we enqueue
-		 * a second log-only update for HEAD so that its reflog is
-		 * updated accordingly.
-		 */
-		if (head_type == REF_ISSYMREF &&
-		    !(u->flags & REF_LOG_ONLY) &&
-		    !(u->flags & REF_UPDATE_VIA_HEAD) &&
-		    !strcmp(rewritten_ref, head_referent.buf)) {
-			/*
-			 * First make sure that HEAD is not already in the
-			 * transaction. This check is O(lg N) in the transaction
-			 * size, but it happens at most once per transaction.
-			 */
-			if (string_list_has_string(&transaction->refnames, "HEAD")) {
-				/* An entry already existed */
-				strbuf_addf(err,
-					    _("multiple updates for 'HEAD' (including one "
-					    "via its referent '%s') are not allowed"),
-					    u->refname);
-				ret = TRANSACTION_NAME_CONFLICT;
-				goto done;
-			}
-
-			ref_transaction_add_update(
-				transaction, "HEAD",
-				u->flags | REF_LOG_ONLY | REF_NO_DEREF,
-				&u->new_oid, &u->old_oid, NULL, NULL, NULL,
-				u->msg);
-		}
-
-		ret = reftable_backend_read_ref(be, rewritten_ref,
-						&current_oid, &referent, &u->type);
-		if (ret < 0)
-			goto done;
-		if (ret > 0 && !ref_update_expects_existing_old_ref(u)) {
-			/*
-			 * The reference does not exist, and we either have no
-			 * old object ID or expect the reference to not exist.
-			 * We can thus skip below safety checks as well as the
-			 * symref splitting. But we do want to verify that
-			 * there is no conflicting reference here so that we
-			 * can output a proper error message instead of failing
-			 * at a later point.
-			 */
-			string_list_append(&refnames_to_check, u->refname);
-
-			/*
-			 * There is no need to write the reference deletion
-			 * when the reference in question doesn't exist.
-			 */
-			 if ((u->flags & REF_HAVE_NEW) && !ref_update_has_null_new_value(u)) {
-				 ret = queue_transaction_update(refs, tx_data, u,
-								&current_oid, err);
-				 if (ret)
-					 goto done;
-			 }
-
-			continue;
-		}
-		if (ret > 0) {
-			/* The reference does not exist, but we expected it to. */
-			strbuf_addf(err, _("cannot lock ref '%s': "
-				    "unable to resolve reference '%s'"),
-				    ref_update_original_update_refname(u), u->refname);
-			ret = -1;
-			goto done;
-		}
-
-		if (u->type & REF_ISSYMREF) {
-			/*
-			 * The reftable stack is locked at this point already,
-			 * so it is safe to call `refs_resolve_ref_unsafe()`
-			 * here without causing races.
-			 */
-			const char *resolved = refs_resolve_ref_unsafe(&refs->base, u->refname, 0,
-								       &current_oid, NULL);
-
-			if (u->flags & REF_NO_DEREF) {
-				if (u->flags & REF_HAVE_OLD && !resolved) {
-					strbuf_addf(err, _("cannot lock ref '%s': "
-						    "error reading reference"), u->refname);
-					ret = -1;
-					goto done;
-				}
-			} else {
-				struct ref_update *new_update;
-				int new_flags;
-
-				new_flags = u->flags;
-				if (!strcmp(rewritten_ref, "HEAD"))
-					new_flags |= REF_UPDATE_VIA_HEAD;
-
-				if (string_list_has_string(&transaction->refnames, referent.buf)) {
-					strbuf_addf(err,
-						    _("multiple updates for '%s' (including one "
-						    "via symref '%s') are not allowed"),
-						    referent.buf, u->refname);
-					ret = TRANSACTION_NAME_CONFLICT;
-					goto done;
-				}
-
-				/*
-				 * If we are updating a symref (eg. HEAD), we should also
-				 * update the branch that the symref points to.
-				 *
-				 * This is generic functionality, and would be better
-				 * done in refs.c, but the current implementation is
-				 * intertwined with the locking in files-backend.c.
-				 */
-				new_update = ref_transaction_add_update(
-					transaction, referent.buf, new_flags,
-					u->new_target ? NULL : &u->new_oid,
-					u->old_target ? NULL : &u->old_oid,
-					u->new_target, u->old_target,
-					u->committer_info, u->msg);
-
-				new_update->parent_update = u;
-
-				/*
-				 * Change the symbolic ref update to log only. Also, it
-				 * doesn't need to check its old OID value, as that will be
-				 * done when new_update is processed.
-				 */
-				u->flags |= REF_LOG_ONLY | REF_NO_DEREF;
-				u->flags &= ~REF_HAVE_OLD;
-			}
-		}
-
-		/*
-		 * Verify that the old object matches our expectations. Note
-		 * that the error messages here do not make a lot of sense in
-		 * the context of the reftable backend as we never lock
-		 * individual refs. But the error messages match what the files
-		 * backend returns, which keeps our tests happy.
-		 */
-		if (u->old_target) {
-			if (!(u->type & REF_ISSYMREF)) {
-				strbuf_addf(err, _("cannot lock ref '%s': "
-					   "expected symref with target '%s': "
-					   "but is a regular ref"),
-					    ref_update_original_update_refname(u),
-					    u->old_target);
-				ret = -1;
-				goto done;
-			}
-
-			if (ref_update_check_old_target(referent.buf, u, err)) {
-				ret = -1;
-				goto done;
-			}
-		} else if ((u->flags & REF_HAVE_OLD) && !oideq(&current_oid, &u->old_oid)) {
-			ret = TRANSACTION_NAME_CONFLICT;
-			if (is_null_oid(&u->old_oid)) {
-				strbuf_addf(err, _("cannot lock ref '%s': "
-						   "reference already exists"),
-					    ref_update_original_update_refname(u));
-				ret = TRANSACTION_CREATE_EXISTS;
-			}
-			else if (is_null_oid(&current_oid))
-				strbuf_addf(err, _("cannot lock ref '%s': "
-						   "reference is missing but expected %s"),
-					    ref_update_original_update_refname(u),
-					    oid_to_hex(&u->old_oid));
-			else
-				strbuf_addf(err, _("cannot lock ref '%s': "
-						   "is at %s but expected %s"),
-					    ref_update_original_update_refname(u),
-					    oid_to_hex(&current_oid),
-					    oid_to_hex(&u->old_oid));
-			goto done;
-		}
-
-		/*
-		 * If all of the following conditions are true:
-		 *
-		 *   - We're not about to write a symref.
-		 *   - We're not about to write a log-only entry.
-		 *   - Old and new object ID are different.
-		 *
-		 * Then we're essentially doing a no-op update that can be
-		 * skipped. This is not only for the sake of efficiency, but
-		 * also skips writing unneeded reflog entries.
-		 */
-		if ((u->type & REF_ISSYMREF) ||
-		    (u->flags & REF_LOG_ONLY) ||
-		    (u->flags & REF_HAVE_NEW && !oideq(&current_oid, &u->new_oid))) {
-			ret = queue_transaction_update(refs, tx_data, u,
-						       &current_oid, err);
-			if (ret)
-				goto done;
-		}
 	}
 
 	string_list_sort(&refnames_to_check);
-- 
2.48.1
Karthik Nayak· Mar 5, 2025, 17:39 UTC · re: Karthik Nayak · lore

[PATCH v3 5/8] refs: introduce enum-based transaction error types

Replace preprocessor-defined transaction errors with a strongly-typed enum `ref_transaction_error`. This change:

  - Improves type safety and function signature clarity.
  - Makes error handling more explicit and discoverable.
  - Maintains existing error cases, while adding new error cases for
    common scenarios.

This refactoring paves the way for more comprehensive error handling which we will utilize in the upcoming commits to add partial transaction support.

Signed-off-by: Karthik Nayak <karthik.188@gmail.com>
---
 builtin/fetch.c         |   2 +-
 refs.c                  |  49 ++++++------
 refs.h                  |  54 ++++++++-----
 refs/files-backend.c    | 202 ++++++++++++++++++++++++------------------------
 refs/packed-backend.c   |  23 +++---
 refs/refs-internal.h    |   5 +-
 refs/reftable-backend.c |  64 +++++++--------
 7 files changed, 213 insertions(+), 186 deletions(-)
Show changes to 7 files +213 −186

builtin/fetch.c, refs.c, refs.h, refs/files-backend.c, refs/packed-backend.c, refs/refs-internal.h, refs/reftable-backend.c

diff --git a/builtin/fetch.c b/builtin/fetch.c
index 1c740d5aac..52c913d28a 100644
--- a/builtin/fetch.c
+++ b/builtin/fetch.c
@@ -687,7 +687,7 @@ static int s_update_ref(const char *action,
 		switch (ref_transaction_commit(our_transaction, &err)) {
 		case 0:
 			break;
-		case TRANSACTION_NAME_CONFLICT:
+		case REF_TRANSACTION_ERROR_NAME_CONFLICT:
 			ret = STORE_REF_ERROR_DF_CONFLICT;
 			goto out;
 		default:
diff --git a/refs.c b/refs.c
index 69f385f344..63b8050ce2 100644
--- a/refs.c
+++ b/refs.c
@@ -2271,7 +2271,7 @@ int refs_update_symref_extended(struct ref_store *refs, const char *ref,
 					   REF_NO_DEREF, logmsg, &err))
 			goto error_return;
 		prepret = ref_transaction_prepare(transaction, &err);
-		if (prepret && prepret != TRANSACTION_CREATE_EXISTS)
+		if (prepret && prepret != REF_TRANSACTION_ERROR_CREATE_EXISTS)
 			goto error_return;
 	} else {
 		if (ref_transaction_update(transaction, ref, NULL, NULL,
@@ -2289,7 +2289,7 @@ int refs_update_symref_extended(struct ref_store *refs, const char *ref,
 		}
 	}
 
-	if (prepret == TRANSACTION_CREATE_EXISTS)
+	if (prepret == REF_TRANSACTION_ERROR_CREATE_EXISTS)
 		goto cleanup;
 
 	if (ref_transaction_commit(transaction, &err))
@@ -2425,7 +2425,7 @@ int ref_transaction_prepare(struct ref_transaction *transaction,
 
 	string_list_sort(&transaction->refnames);
 	if (ref_update_reject_duplicates(&transaction->refnames, err))
-		return TRANSACTION_GENERIC_ERROR;
+		return REF_TRANSACTION_ERROR_GENERIC;
 
 	ret = refs->be->transaction_prepare(refs, transaction, err);
 	if (ret)
@@ -2497,18 +2497,18 @@ int ref_transaction_commit(struct ref_transaction *transaction,
 	return ret;
 }
 
-int refs_verify_refnames_available(struct ref_store *refs,
-				   const struct string_list *refnames,
-				   const struct string_list *extras,
-				   const struct string_list *skip,
-				   unsigned int initial_transaction,
-				   struct strbuf *err)
+enum ref_transaction_error refs_verify_refnames_available(struct ref_store *refs,
+					  const struct string_list *refnames,
+					  const struct string_list *extras,
+					  const struct string_list *skip,
+					  unsigned int initial_transaction,
+					  struct strbuf *err)
 {
 	struct strbuf dirname = STRBUF_INIT;
 	struct strbuf referent = STRBUF_INIT;
 	struct ref_iterator *iter = NULL;
 	struct strset dirnames;
-	int ret = -1;
+	int ret = REF_TRANSACTION_ERROR_NAME_CONFLICT;
 
 	/*
 	 * For the sake of comments in this function, suppose that
@@ -2624,12 +2624,13 @@ int refs_verify_refnames_available(struct ref_store *refs,
 	return ret;
 }
 
-int refs_verify_refname_available(struct ref_store *refs,
-				  const char *refname,
-				  const struct string_list *extras,
-				  const struct string_list *skip,
-				  unsigned int initial_transaction,
-				  struct strbuf *err)
+enum ref_transaction_error refs_verify_refname_available(
+	struct ref_store *refs,
+	const char *refname,
+	const struct string_list *extras,
+	const struct string_list *skip,
+	unsigned int initial_transaction,
+	struct strbuf *err)
 {
 	struct string_list_item item = { .string = (char *) refname };
 	struct string_list refnames = {
@@ -2817,8 +2818,9 @@ int ref_update_has_null_new_value(struct ref_update *update)
 	return !update->new_target && is_null_oid(&update->new_oid);
 }
 
-int ref_update_check_old_target(const char *referent, struct ref_update *update,
-				struct strbuf *err)
+enum ref_transaction_error ref_update_check_old_target(const char *referent,
+						       struct ref_update *update,
+						       struct strbuf *err)
 {
 	if (!update->old_target)
 		BUG("called without old_target set");
@@ -2826,17 +2828,18 @@ int ref_update_check_old_target(const char *referent, struct ref_update *update,
 	if (!strcmp(referent, update->old_target))
 		return 0;
 
-	if (!strcmp(referent, ""))
+	if (!strcmp(referent, "")) {
 		strbuf_addf(err, "verifying symref target: '%s': "
 			    "reference is missing but expected %s",
 			    ref_update_original_update_refname(update),
 			    update->old_target);
-	else
-		strbuf_addf(err, "verifying symref target: '%s': "
-			    "is at %s but expected %s",
+		return REF_TRANSACTION_ERROR_NONEXISTENT_REF;
+	}
+
+	strbuf_addf(err, "verifying symref target: '%s': is at %s but expected %s",
 			    ref_update_original_update_refname(update),
 			    referent, update->old_target);
-	return -1;
+	return REF_TRANSACTION_ERROR_INCORRECT_OLD_VALUE;
 }
 
 struct migration_data {
diff --git a/refs.h b/refs.h
index b14ba1f9ff..1b9213f9ce 100644
--- a/refs.h
+++ b/refs.h
@@ -16,6 +16,29 @@ struct worktree;
 enum ref_storage_format ref_storage_format_by_name(const char *name);
 const char *ref_storage_format_to_name(enum ref_storage_format ref_storage_format);
 
+/*
+ * enum ref_transaction_error represents the following return codes:
+ * REF_TRANSACTION_ERROR_GENERIC error_code: default error code.
+ * REF_TRANSACTION_ERROR_NAME_CONFLICT error_code: ref name conflict like A vs A/B.
+ * REF_TRANSACTION_ERROR_CREATE_EXISTS error_code: ref to be created already exists.
+ * REF_TRANSACTION_ERROR_NONEXISTENT_REF error_code: ref expected but doesn't exist.
+ * REF_TRANSACTION_ERROR_INCORRECT_OLD_VALUE error_code: provided old_oid or old_target of
+ * reference doesn't match actual.
+ * REF_TRANSACTION_ERROR_INVALID_NEW_VALUE error_code: provided new_oid or new_target is
+ * invalid.
+ * REF_TRANSACTION_ERROR_EXPECTED_SYMREF error_code: expected ref to be symref, but is a
+ * regular ref.
+ */
+enum ref_transaction_error {
+	REF_TRANSACTION_ERROR_GENERIC = -1,
+	REF_TRANSACTION_ERROR_NAME_CONFLICT = -2,
+	REF_TRANSACTION_ERROR_CREATE_EXISTS = -3,
+	REF_TRANSACTION_ERROR_NONEXISTENT_REF = -4,
+	REF_TRANSACTION_ERROR_INCORRECT_OLD_VALUE = -5,
+	REF_TRANSACTION_ERROR_INVALID_NEW_VALUE = -6,
+	REF_TRANSACTION_ERROR_EXPECTED_SYMREF = -7,
+};
+
 /*
  * Resolve a reference, recursively following symbolic references.
  *
@@ -117,24 +140,24 @@ int refs_read_symbolic_ref(struct ref_store *ref_store, const char *refname,
  *
  * extras and skip must be sorted.
  */
-int refs_verify_refname_available(struct ref_store *refs,
-				  const char *refname,
-				  const struct string_list *extras,
-				  const struct string_list *skip,
-				  unsigned int initial_transaction,
-				  struct strbuf *err);
+enum ref_transaction_error refs_verify_refname_available(struct ref_store *refs,
+						 const char *refname,
+						 const struct string_list *extras,
+						 const struct string_list *skip,
+						 unsigned int initial_transaction,
+						 struct strbuf *err);
 
 /*
  * Same as `refs_verify_refname_available()`, but checking for a list of
  * refnames instead of only a single item. This is more efficient in the case
  * where one needs to check multiple refnames.
  */
-int refs_verify_refnames_available(struct ref_store *refs,
-				   const struct string_list *refnames,
-				   const struct string_list *extras,
-				   const struct string_list *skip,
-				   unsigned int initial_transaction,
-				   struct strbuf *err);
+enum ref_transaction_error refs_verify_refnames_available(struct ref_store *refs,
+					  const struct string_list *refnames,
+					  const struct string_list *extras,
+					  const struct string_list *skip,
+					  unsigned int initial_transaction,
+					  struct strbuf *err);
 
 int refs_ref_exists(struct ref_store *refs, const char *refname);
 
@@ -830,13 +853,6 @@ int ref_transaction_verify(struct ref_transaction *transaction,
 			   unsigned int flags,
 			   struct strbuf *err);
 
-/* Naming conflict (for example, the ref names A and A/B conflict). */
-#define TRANSACTION_NAME_CONFLICT -1
-/* When only creation was requested, but the ref already exists. */
-#define TRANSACTION_CREATE_EXISTS -2
-/* All other errors. */
-#define TRANSACTION_GENERIC_ERROR -3
-
 /*
  * Perform the preparatory stages of committing `transaction`. Acquire
  * any needed locks, check preconditions, etc.; basically, do as much
diff --git a/refs/files-backend.c b/refs/files-backend.c
index 7c6a0b3478..1e1663f44b 100644
--- a/refs/files-backend.c
+++ b/refs/files-backend.c
@@ -663,7 +663,7 @@ static void unlock_ref(struct ref_lock *lock)
  * broken, lock the reference anyway but clear old_oid.
  *
  * Return 0 on success. On failure, write an error message to err and
- * return TRANSACTION_NAME_CONFLICT or TRANSACTION_GENERIC_ERROR.
+ * return REF_TRANSACTION_ERROR_NAME_CONFLICT or REF_TRANSACTION_ERROR_GENERIC.
  *
  * Implementation note: This function is basically
  *
@@ -676,19 +676,20 @@ static void unlock_ref(struct ref_lock *lock)
  *   avoided, namely if we were successfully able to read the ref
  * - Generate informative error messages in the case of failure
  */
-static int lock_raw_ref(struct files_ref_store *refs,
-			const char *refname, int mustexist,
-			struct string_list *refnames_to_check,
-			const struct string_list *extras,
-			struct ref_lock **lock_p,
-			struct strbuf *referent,
-			unsigned int *type,
-			struct strbuf *err)
-{
+static enum ref_transaction_error lock_raw_ref(struct files_ref_store *refs,
+					       const char *refname,
+					       int mustexist,
+					       struct string_list *refnames_to_check,
+					       const struct string_list *extras,
+					       struct ref_lock **lock_p,
+					       struct strbuf *referent,
+					       unsigned int *type,
+					       struct strbuf *err)
+{
+	enum ref_transaction_error ret = REF_TRANSACTION_ERROR_GENERIC;
 	struct ref_lock *lock;
 	struct strbuf ref_file = STRBUF_INIT;
 	int attempts_remaining = 3;
-	int ret = TRANSACTION_GENERIC_ERROR;
 	int failure_errno;
 
 	assert(err);
@@ -728,13 +729,14 @@ static int lock_raw_ref(struct files_ref_store *refs,
 				strbuf_reset(err);
 				strbuf_addf(err, "unable to resolve reference '%s'",
 					    refname);
+				ret = REF_TRANSACTION_ERROR_NONEXISTENT_REF;
 			} else {
 				/*
 				 * The error message set by
 				 * refs_verify_refname_available() is
 				 * OK.
 				 */
-				ret = TRANSACTION_NAME_CONFLICT;
+				ret = REF_TRANSACTION_ERROR_NAME_CONFLICT;
 			}
 		} else {
 			/*
@@ -788,6 +790,7 @@ static int lock_raw_ref(struct files_ref_store *refs,
 				/* Garden variety missing reference. */
 				strbuf_addf(err, "unable to resolve reference '%s'",
 					    refname);
+				ret = REF_TRANSACTION_ERROR_NONEXISTENT_REF;
 				goto error_return;
 			} else {
 				/*
@@ -820,6 +823,7 @@ static int lock_raw_ref(struct files_ref_store *refs,
 				/* Garden variety missing reference. */
 				strbuf_addf(err, "unable to resolve reference '%s'",
 					    refname);
+				ret = REF_TRANSACTION_ERROR_NONEXISTENT_REF;
 				goto error_return;
 			} else if (remove_dir_recursively(&ref_file,
 							  REMOVE_DIR_EMPTY_ONLY)) {
@@ -830,7 +834,7 @@ static int lock_raw_ref(struct files_ref_store *refs,
 					 * The error message set by
 					 * verify_refname_available() is OK.
 					 */
-					ret = TRANSACTION_NAME_CONFLICT;
+					ret = REF_TRANSACTION_ERROR_NAME_CONFLICT;
 					goto error_return;
 				} else {
 					/*
@@ -1517,10 +1521,11 @@ static int rename_tmp_log(struct files_ref_store *refs, const char *newrefname)
 	return ret;
 }
 
-static int write_ref_to_lockfile(struct files_ref_store *refs,
-				 struct ref_lock *lock,
-				 const struct object_id *oid,
-				 int skip_oid_verification, struct strbuf *err);
+static enum ref_transaction_error write_ref_to_lockfile(struct files_ref_store *refs,
+							struct ref_lock *lock,
+							const struct object_id *oid,
+							int skip_oid_verification,
+							struct strbuf *err);
 static int commit_ref_update(struct files_ref_store *refs,
 			     struct ref_lock *lock,
 			     const struct object_id *oid, const char *logmsg,
@@ -1926,10 +1931,11 @@ static int files_log_ref_write(struct files_ref_store *refs,
  * Write oid into the open lockfile, then close the lockfile. On
  * errors, rollback the lockfile, fill in *err and return -1.
  */
-static int write_ref_to_lockfile(struct files_ref_store *refs,
-				 struct ref_lock *lock,
-				 const struct object_id *oid,
-				 int skip_oid_verification, struct strbuf *err)
+static enum ref_transaction_error write_ref_to_lockfile(struct files_ref_store *refs,
+							struct ref_lock *lock,
+							const struct object_id *oid,
+							int skip_oid_verification,
+							struct strbuf *err)
 {
 	static char term = '\n';
 	struct object *o;
@@ -1943,7 +1949,7 @@ static int write_ref_to_lockfile(struct files_ref_store *refs,
 				"trying to write ref '%s' with nonexistent object %s",
 				lock->ref_name, oid_to_hex(oid));
 			unlock_ref(lock);
-			return -1;
+			return REF_TRANSACTION_ERROR_INVALID_NEW_VALUE;
 		}
 		if (o->type != OBJ_COMMIT && is_branch(lock->ref_name)) {
 			strbuf_addf(
@@ -1951,7 +1957,7 @@ static int write_ref_to_lockfile(struct files_ref_store *refs,
 				"trying to write non-commit object %s to branch '%s'",
 				oid_to_hex(oid), lock->ref_name);
 			unlock_ref(lock);
-			return -1;
+			return REF_TRANSACTION_ERROR_INVALID_NEW_VALUE;
 		}
 	}
 	fd = get_lock_file_fd(&lock->lk);
@@ -1962,7 +1968,7 @@ static int write_ref_to_lockfile(struct files_ref_store *refs,
 		strbuf_addf(err,
 			    "couldn't write '%s'", get_lock_file_path(&lock->lk));
 		unlock_ref(lock);
-		return -1;
+		return REF_TRANSACTION_ERROR_GENERIC;
 	}
 	return 0;
 }
@@ -2376,9 +2382,10 @@ static struct ref_iterator *files_reflog_iterator_begin(struct ref_store *ref_st
  * If update is a direct update of head_ref (the reference pointed to
  * by HEAD), then add an extra REF_LOG_ONLY update for HEAD.
  */
-static int split_head_update(struct ref_update *update,
-			     struct ref_transaction *transaction,
-			     const char *head_ref, struct strbuf *err)
+static enum ref_transaction_error split_head_update(struct ref_update *update,
+						    struct ref_transaction *transaction,
+						    const char *head_ref,
+						    struct strbuf *err)
 {
 	struct ref_update *new_update;
 
@@ -2402,7 +2409,7 @@ static int split_head_update(struct ref_update *update,
 			    "multiple updates for 'HEAD' (including one "
 			    "via its referent '%s') are not allowed",
 			    update->refname);
-		return TRANSACTION_NAME_CONFLICT;
+		return REF_TRANSACTION_ERROR_NAME_CONFLICT;
 	}
 
 	new_update = ref_transaction_add_update(
@@ -2430,10 +2437,10 @@ static int split_head_update(struct ref_update *update,
  * Note that the new update will itself be subject to splitting when
  * the iteration gets to it.
  */
-static int split_symref_update(struct ref_update *update,
-			       const char *referent,
-			       struct ref_transaction *transaction,
-			       struct strbuf *err)
+static enum ref_transaction_error split_symref_update(struct ref_update *update,
+						      const char *referent,
+						      struct ref_transaction *transaction,
+						      struct strbuf *err)
 {
 	struct ref_update *new_update;
 	unsigned int new_flags;
@@ -2450,7 +2457,7 @@ static int split_symref_update(struct ref_update *update,
 			    "multiple updates for '%s' (including one "
 			    "via symref '%s') are not allowed",
 			    referent, update->refname);
-		return TRANSACTION_NAME_CONFLICT;
+		return REF_TRANSACTION_ERROR_NAME_CONFLICT;
 	}
 
 	new_flags = update->flags;
@@ -2491,11 +2498,10 @@ static int split_symref_update(struct ref_update *update,
  * everything is OK, return 0; otherwise, write an error message to
  * err and return -1.
  */
-static int check_old_oid(struct ref_update *update, struct object_id *oid,
-			 struct strbuf *err)
+static enum ref_transaction_error check_old_oid(struct ref_update *update,
+						struct object_id *oid,
+						struct strbuf *err)
 {
-	int ret = TRANSACTION_GENERIC_ERROR;
-
 	if (!(update->flags & REF_HAVE_OLD) ||
 		   oideq(oid, &update->old_oid))
 		return 0;
@@ -2504,21 +2510,20 @@ static int check_old_oid(struct ref_update *update, struct object_id *oid,
 		strbuf_addf(err, "cannot lock ref '%s': "
 			    "reference already exists",
 			    ref_update_original_update_refname(update));
-		ret = TRANSACTION_CREATE_EXISTS;
-	}
-	else if (is_null_oid(oid))
+		return REF_TRANSACTION_ERROR_CREATE_EXISTS;
+	} else if (is_null_oid(oid)) {
 		strbuf_addf(err, "cannot lock ref '%s': "
 			    "reference is missing but expected %s",
 			    ref_update_original_update_refname(update),
 			    oid_to_hex(&update->old_oid));
-	else
-		strbuf_addf(err, "cannot lock ref '%s': "
-			    "is at %s but expected %s",
-			    ref_update_original_update_refname(update),
-			    oid_to_hex(oid),
-			    oid_to_hex(&update->old_oid));
+		return REF_TRANSACTION_ERROR_NONEXISTENT_REF;
+	}
 
-	return ret;
+	strbuf_addf(err, "cannot lock ref '%s': is at %s but expected %s",
+		    ref_update_original_update_refname(update), oid_to_hex(oid),
+		    oid_to_hex(&update->old_oid));
+
+	return REF_TRANSACTION_ERROR_INCORRECT_OLD_VALUE;
 }
 
 struct files_transaction_backend_data {
@@ -2540,17 +2545,17 @@ struct files_transaction_backend_data {
  * - If it is an update of head_ref, add a corresponding REF_LOG_ONLY
  *   update of HEAD.
  */
-static int lock_ref_for_update(struct files_ref_store *refs,
-			       struct ref_update *update,
-			       struct ref_transaction *transaction,
-			       const char *head_ref,
-			       struct string_list *refnames_to_check,
-			       struct strbuf *err)
+static enum ref_transaction_error lock_ref_for_update(struct files_ref_store *refs,
+						      struct ref_update *update,
+						      struct ref_transaction *transaction,
+						      const char *head_ref,
+						      struct string_list *refnames_to_check,
+						      struct strbuf *err)
 {
 	struct strbuf referent = STRBUF_INIT;
 	int mustexist = ref_update_expects_existing_old_ref(update);
 	struct files_transaction_backend_data *backend_data;
-	int ret = 0;
+	enum ref_transaction_error ret = 0;
 	struct ref_lock *lock;
 
 	files_assert_main_repository(refs, "lock_ref_for_update");
@@ -2602,22 +2607,17 @@ static int lock_ref_for_update(struct files_ref_store *refs,
 					strbuf_addf(err, "cannot lock ref '%s': "
 						    "error reading reference",
 						    ref_update_original_update_refname(update));
-					ret = TRANSACTION_GENERIC_ERROR;
+					ret = REF_TRANSACTION_ERROR_GENERIC;
 					goto out;
 				}
 			}
 
-			if (update->old_target) {
-				if (ref_update_check_old_target(referent.buf, update, err)) {
-					ret = TRANSACTION_GENERIC_ERROR;
-					goto out;
-				}
-			} else {
+			if (update->old_target)
+				ret = ref_update_check_old_target(referent.buf, update, err);
+			else
 				ret = check_old_oid(update, &lock->old_oid, err);
-				if  (ret) {
-					goto out;
-				}
-			}
+			if (ret)
+				goto out;
 		} else {
 			/*
 			 * Create a new update for the reference this
@@ -2644,7 +2644,7 @@ static int lock_ref_for_update(struct files_ref_store *refs,
 					   "but is a regular ref"),
 				    ref_update_original_update_refname(update),
 				    update->old_target);
-			ret = TRANSACTION_GENERIC_ERROR;
+			ret = REF_TRANSACTION_ERROR_EXPECTED_SYMREF;
 			goto out;
 		} else {
 			ret = check_old_oid(update, &lock->old_oid, err);
@@ -2668,14 +2668,14 @@ static int lock_ref_for_update(struct files_ref_store *refs,
 
 	if (update->new_target && !(update->flags & REF_LOG_ONLY)) {
 		if (create_symref_lock(lock, update->new_target, err)) {
-			ret = TRANSACTION_GENERIC_ERROR;
+			ret = REF_TRANSACTION_ERROR_GENERIC;
 			goto out;
 		}
 
 		if (close_ref_gently(lock)) {
 			strbuf_addf(err, "couldn't close '%s.lock'",
 				    update->refname);
-			ret = TRANSACTION_GENERIC_ERROR;
+			ret = REF_TRANSACTION_ERROR_GENERIC;
 			goto out;
 		}
 
@@ -2693,25 +2693,27 @@ static int lock_ref_for_update(struct files_ref_store *refs,
 			 * The reference already has the desired
 			 * value, so we don't need to write it.
 			 */
-		} else if (write_ref_to_lockfile(
-				   refs, lock, &update->new_oid,
-				   update->flags & REF_SKIP_OID_VERIFICATION,
-				   err)) {
-			char *write_err = strbuf_detach(err, NULL);
-
-			/*
-			 * The lock was freed upon failure of
-			 * write_ref_to_lockfile():
-			 */
-			update->backend_data = NULL;
-			strbuf_addf(err,
-				    "cannot update ref '%s': %s",
-				    update->refname, write_err);
-			free(write_err);
-			ret = TRANSACTION_GENERIC_ERROR;
-			goto out;
 		} else {
-			update->flags |= REF_NEEDS_COMMIT;
+			ret = write_ref_to_lockfile(
+				refs, lock, &update->new_oid,
+				update->flags & REF_SKIP_OID_VERIFICATION,
+				err);
+			if (ret) {
+				char *write_err = strbuf_detach(err, NULL);
+
+				/*
+				 * The lock was freed upon failure of
+				 * write_ref_to_lockfile():
+				 */
+				update->backend_data = NULL;
+				strbuf_addf(err,
+					    "cannot update ref '%s': %s",
+					    update->refname, write_err);
+				free(write_err);
+				goto out;
+			} else {
+				update->flags |= REF_NEEDS_COMMIT;
+			}
 		}
 	}
 	if (!(update->flags & REF_NEEDS_COMMIT)) {
@@ -2723,7 +2725,7 @@ static int lock_ref_for_update(struct files_ref_store *refs,
 		if (close_ref_gently(lock)) {
 			strbuf_addf(err, "couldn't close '%s.lock'",
 				    update->refname);
-			ret = TRANSACTION_GENERIC_ERROR;
+			ret = REF_TRANSACTION_ERROR_GENERIC;
 			goto out;
 		}
 	}
@@ -2865,7 +2867,7 @@ static int files_transaction_prepare(struct ref_store *ref_store,
 						refs->packed_ref_store,
 						transaction->flags, err);
 				if (!packed_transaction) {
-					ret = TRANSACTION_GENERIC_ERROR;
+					ret = REF_TRANSACTION_ERROR_GENERIC;
 					goto cleanup;
 				}
 
@@ -2897,13 +2899,13 @@ static int files_transaction_prepare(struct ref_store *ref_store,
 	 */
 	if (refs_verify_refnames_available(refs->packed_ref_store, &refnames_to_check,
 					   &transaction->refnames, NULL, 0, err)) {
-		ret = TRANSACTION_NAME_CONFLICT;
+		ret = REF_TRANSACTION_ERROR_NAME_CONFLICT;
 		goto cleanup;
 	}
 
 	if (packed_transaction) {
 		if (packed_refs_lock(refs->packed_ref_store, 0, err)) {
-			ret = TRANSACTION_GENERIC_ERROR;
+			ret = REF_TRANSACTION_ERROR_GENERIC;
 			goto cleanup;
 		}
 		backend_data->packed_refs_locked = 1;
@@ -2934,7 +2936,7 @@ static int files_transaction_prepare(struct ref_store *ref_store,
 			 */
 			backend_data->packed_transaction = NULL;
 			if (ref_transaction_abort(packed_transaction, err)) {
-				ret = TRANSACTION_GENERIC_ERROR;
+				ret = REF_TRANSACTION_ERROR_GENERIC;
 				goto cleanup;
 			}
 		}
@@ -3035,7 +3037,7 @@ static int files_transaction_finish_initial(struct files_ref_store *refs,
 	packed_transaction = ref_store_transaction_begin(refs->packed_ref_store,
 							 transaction->flags, err);
 	if (!packed_transaction) {
-		ret = TRANSACTION_GENERIC_ERROR;
+		ret = REF_TRANSACTION_ERROR_GENERIC;
 		goto cleanup;
 	}
 
@@ -3058,7 +3060,7 @@ static int files_transaction_finish_initial(struct files_ref_store *refs,
 			if (!loose_transaction) {
 				loose_transaction = ref_store_transaction_begin(&refs->base, 0, err);
 				if (!loose_transaction) {
-					ret = TRANSACTION_GENERIC_ERROR;
+					ret = REF_TRANSACTION_ERROR_GENERIC;
 					goto cleanup;
 				}
 			}
@@ -3083,19 +3085,19 @@ static int files_transaction_finish_initial(struct files_ref_store *refs,
 	}
 
 	if (packed_refs_lock(refs->packed_ref_store, 0, err)) {
-		ret = TRANSACTION_GENERIC_ERROR;
+		ret = REF_TRANSACTION_ERROR_GENERIC;
 		goto cleanup;
 	}
 
 	if (refs_verify_refnames_available(&refs->base, &refnames_to_check,
 					   &affected_refnames, NULL, 1, err)) {
 		packed_refs_unlock(refs->packed_ref_store);
-		ret = TRANSACTION_NAME_CONFLICT;
+		ret = REF_TRANSACTION_ERROR_NAME_CONFLICT;
 		goto cleanup;
 	}
 
 	if (ref_transaction_commit(packed_transaction, err)) {
-		ret = TRANSACTION_GENERIC_ERROR;
+		ret = REF_TRANSACTION_ERROR_GENERIC;
 		goto cleanup;
 	}
 	packed_refs_unlock(refs->packed_ref_store);
@@ -3103,7 +3105,7 @@ static int files_transaction_finish_initial(struct files_ref_store *refs,
 	if (loose_transaction) {
 		if (ref_transaction_prepare(loose_transaction, err) ||
 		    ref_transaction_commit(loose_transaction, err)) {
-			ret = TRANSACTION_GENERIC_ERROR;
+			ret = REF_TRANSACTION_ERROR_GENERIC;
 			goto cleanup;
 		}
 	}
@@ -3152,7 +3154,7 @@ static int files_transaction_finish(struct ref_store *ref_store,
 		if (update->flags & REF_NEEDS_COMMIT ||
 		    update->flags & REF_LOG_ONLY) {
 			if (parse_and_write_reflog(refs, update, lock, err)) {
-				ret = TRANSACTION_GENERIC_ERROR;
+				ret = REF_TRANSACTION_ERROR_GENERIC;
 				goto cleanup;
 			}
 		}
@@ -3171,7 +3173,7 @@ static int files_transaction_finish(struct ref_store *ref_store,
 				strbuf_addf(err, "couldn't set '%s'", lock->ref_name);
 				unlock_ref(lock);
 				update->backend_data = NULL;
-				ret = TRANSACTION_GENERIC_ERROR;
+				ret = REF_TRANSACTION_ERROR_GENERIC;
 				goto cleanup;
 			}
 		}
@@ -3227,7 +3229,7 @@ static int files_transaction_finish(struct ref_store *ref_store,
 				strbuf_reset(&sb);
 				files_ref_path(refs, &sb, lock->ref_name);
 				if (unlink_or_msg(sb.buf, err)) {
-					ret = TRANSACTION_GENERIC_ERROR;
+					ret = REF_TRANSACTION_ERROR_GENERIC;
 					goto cleanup;
 				}
 			}
diff --git a/refs/packed-backend.c b/refs/packed-backend.c
index 19220d2e99..5458952624 100644
--- a/refs/packed-backend.c
+++ b/refs/packed-backend.c
@@ -1326,10 +1326,11 @@ static int packed_ref_store_remove_on_disk(struct ref_store *ref_store,
  * The packfile must be locked before calling this function and will
  * remain locked when it is done.
  */
-static int write_with_updates(struct packed_ref_store *refs,
-			      struct string_list *updates,
-			      struct strbuf *err)
+static enum ref_transaction_error write_with_updates(struct packed_ref_store *refs,
+						     struct string_list *updates,
+						     struct strbuf *err)
 {
+	enum ref_transaction_error ret = REF_TRANSACTION_ERROR_GENERIC;
 	struct ref_iterator *iter = NULL;
 	size_t i;
 	int ok;
@@ -1353,7 +1354,7 @@ static int write_with_updates(struct packed_ref_store *refs,
 		strbuf_addf(err, "unable to create file %s: %s",
 			    sb.buf, strerror(errno));
 		strbuf_release(&sb);
-		return -1;
+		return REF_TRANSACTION_ERROR_GENERIC;
 	}
 	strbuf_release(&sb);
 
@@ -1409,6 +1410,7 @@ static int write_with_updates(struct packed_ref_store *refs,
 					strbuf_addf(err, "cannot update ref '%s': "
 						    "reference already exists",
 						    update->refname);
+					ret = REF_TRANSACTION_ERROR_CREATE_EXISTS;
 					goto error;
 				} else if (!oideq(&update->old_oid, iter->oid)) {
 					strbuf_addf(err, "cannot update ref '%s': "
@@ -1416,6 +1418,7 @@ static int write_with_updates(struct packed_ref_store *refs,
 						    update->refname,
 						    oid_to_hex(iter->oid),
 						    oid_to_hex(&update->old_oid));
+					ret = REF_TRANSACTION_ERROR_INCORRECT_OLD_VALUE;
 					goto error;
 				}
 			}
@@ -1452,6 +1455,7 @@ static int write_with_updates(struct packed_ref_store *refs,
 					    "reference is missing but expected %s",
 					    update->refname,
 					    oid_to_hex(&update->old_oid));
+				return REF_TRANSACTION_ERROR_NONEXISTENT_REF;
 				goto error;
 			}
 		}
@@ -1509,7 +1513,7 @@ static int write_with_updates(struct packed_ref_store *refs,
 			    strerror(errno));
 		strbuf_release(&sb);
 		delete_tempfile(&refs->tempfile);
-		return -1;
+		return REF_TRANSACTION_ERROR_GENERIC;
 	}
 
 	return 0;
@@ -1521,7 +1525,7 @@ static int write_with_updates(struct packed_ref_store *refs,
 error:
 	ref_iterator_free(iter);
 	delete_tempfile(&refs->tempfile);
-	return -1;
+	return ret;
 }
 
 int is_packed_transaction_needed(struct ref_store *ref_store,
@@ -1654,7 +1658,7 @@ static int packed_transaction_prepare(struct ref_store *ref_store,
 			REF_STORE_READ | REF_STORE_WRITE | REF_STORE_ODB,
 			"ref_transaction_prepare");
 	struct packed_transaction_backend_data *data;
-	int ret = TRANSACTION_GENERIC_ERROR;
+	enum ref_transaction_error ret = REF_TRANSACTION_ERROR_GENERIC;
 
 	/*
 	 * Note that we *don't* skip transactions with zero updates,
@@ -1675,7 +1679,8 @@ static int packed_transaction_prepare(struct ref_store *ref_store,
 		data->own_lock = 1;
 	}
 
-	if (write_with_updates(refs, &transaction->refnames, err))
+	ret = write_with_updates(refs, &transaction->refnames, err);
+	if (ret)
 		goto failure;
 
 	transaction->state = REF_TRANSACTION_PREPARED;
@@ -1707,7 +1712,7 @@ static int packed_transaction_finish(struct ref_store *ref_store,
 			ref_store,
 			REF_STORE_READ | REF_STORE_WRITE | REF_STORE_ODB,
 			"ref_transaction_finish");
-	int ret = TRANSACTION_GENERIC_ERROR;
+	int ret = REF_TRANSACTION_ERROR_GENERIC;
 	char *packed_refs_path;
 
 	clear_snapshot(refs);
diff --git a/refs/refs-internal.h b/refs/refs-internal.h
index 6d3770d0cc..3f1d19abd9 100644
--- a/refs/refs-internal.h
+++ b/refs/refs-internal.h
@@ -770,8 +770,9 @@ int ref_update_has_null_new_value(struct ref_update *update);
  * If everything is OK, return 0; otherwise, write an error message to
  * err and return -1.
  */
-int ref_update_check_old_target(const char *referent, struct ref_update *update,
-				struct strbuf *err);
+enum ref_transaction_error ref_update_check_old_target(const char *referent,
+						       struct ref_update *update,
+						       struct strbuf *err);
 
 /*
  * Check if the ref must exist, this means that the old_oid or
diff --git a/refs/reftable-backend.c b/refs/reftable-backend.c
index 2c1e2995de..0132b8b06a 100644
--- a/refs/reftable-backend.c
+++ b/refs/reftable-backend.c
@@ -1069,20 +1069,20 @@ static int queue_transaction_update(struct reftable_ref_store *refs,
 	return 0;
 }
 
-static int prepare_single_update(struct reftable_ref_store *refs,
-				 struct reftable_transaction_data *tx_data,
-				 struct ref_transaction *transaction,
-				 struct reftable_backend *be,
-				 struct ref_update *u,
-				 struct string_list *refnames_to_check,
-				 unsigned int head_type,
-				 struct strbuf *head_referent,
-				 struct strbuf *referent,
-				 struct strbuf *err)
+static enum ref_transaction_error prepare_single_update(struct reftable_ref_store *refs,
+							struct reftable_transaction_data *tx_data,
+							struct ref_transaction *transaction,
+							struct reftable_backend *be,
+							struct ref_update *u,
+							struct string_list *refnames_to_check,
+							unsigned int head_type,
+							struct strbuf *head_referent,
+							struct strbuf *referent,
+							struct strbuf *err)
 {
+	enum ref_transaction_error ret = 0;
 	struct object_id current_oid = {0};
 	const char *rewritten_ref;
-	int ret = 0;
 
 	/*
 	 * There is no need to reload the respective backends here as
@@ -1093,7 +1093,7 @@ static int prepare_single_update(struct reftable_ref_store *refs,
 	 */
 	ret = backend_for(&be, refs, u->refname, &rewritten_ref, 0);
 	if (ret)
-		return ret;
+		return REF_TRANSACTION_ERROR_GENERIC;
 
 	/* Verify that the new object ID is valid. */
 	if ((u->flags & REF_HAVE_NEW) && !is_null_oid(&u->new_oid) &&
@@ -1104,13 +1104,13 @@ static int prepare_single_update(struct reftable_ref_store *refs,
 			strbuf_addf(err,
 				    _("trying to write ref '%s' with nonexistent object %s"),
 				    u->refname, oid_to_hex(&u->new_oid));
-			return -1;
+			return REF_TRANSACTION_ERROR_INVALID_NEW_VALUE;
 		}
 
 		if (o->type != OBJ_COMMIT && is_branch(u->refname)) {
 			strbuf_addf(err, _("trying to write non-commit object %s to branch '%s'"),
 				    oid_to_hex(&u->new_oid), u->refname);
-			return -1;
+			return REF_TRANSACTION_ERROR_INVALID_NEW_VALUE;
 		}
 	}
 
@@ -1134,7 +1134,7 @@ static int prepare_single_update(struct reftable_ref_store *refs,
 				    _("multiple updates for 'HEAD' (including one "
 				      "via its referent '%s') are not allowed"),
 				    u->refname);
-			return TRANSACTION_NAME_CONFLICT;
+			return REF_TRANSACTION_ERROR_NAME_CONFLICT;
 		}
 
 		ref_transaction_add_update(
@@ -1147,7 +1147,7 @@ static int prepare_single_update(struct reftable_ref_store *refs,
 	ret = reftable_backend_read_ref(be, rewritten_ref,
 					&current_oid, referent, &u->type);
 	if (ret < 0)
-		return ret;
+		return REF_TRANSACTION_ERROR_GENERIC;
 	if (ret > 0 && !ref_update_expects_existing_old_ref(u)) {
 		/*
 		 * The reference does not exist, and we either have no
@@ -1168,7 +1168,7 @@ static int prepare_single_update(struct reftable_ref_store *refs,
 			ret = queue_transaction_update(refs, tx_data, u,
 						       &current_oid, err);
 			if (ret)
-				return ret;
+				return REF_TRANSACTION_ERROR_GENERIC;
 		}
 
 		return 0;
@@ -1180,7 +1180,7 @@ static int prepare_single_update(struct reftable_ref_store *refs,
 
 				   "unable to resolve reference '%s'"),
 			    ref_update_original_update_refname(u), u->refname);
-		return -1;
+		return REF_TRANSACTION_ERROR_NONEXISTENT_REF;
 	}
 
 	if (u->type & REF_ISSYMREF) {
@@ -1196,7 +1196,7 @@ static int prepare_single_update(struct reftable_ref_store *refs,
 			if (u->flags & REF_HAVE_OLD && !resolved) {
 				strbuf_addf(err, _("cannot lock ref '%s': "
 						   "error reading reference"), u->refname);
-				return -1;
+				return REF_TRANSACTION_ERROR_GENERIC;
 			}
 		} else {
 			struct ref_update *new_update;
@@ -1211,7 +1211,7 @@ static int prepare_single_update(struct reftable_ref_store *refs,
 					    _("multiple updates for '%s' (including one "
 					      "via symref '%s') are not allowed"),
 					    referent->buf, u->refname);
-				return TRANSACTION_NAME_CONFLICT;
+				return REF_TRANSACTION_ERROR_NAME_CONFLICT;
 			}
 
 			/*
@@ -1255,31 +1255,32 @@ static int prepare_single_update(struct reftable_ref_store *refs,
 					   "but is a regular ref"),
 				    ref_update_original_update_refname(u),
 				    u->old_target);
-			return -1;
+			return REF_TRANSACTION_ERROR_EXPECTED_SYMREF;
 		}
 
-		if (ref_update_check_old_target(referent->buf, u, err)) {
-			return -1;
-		}
+		ret = ref_update_check_old_target(referent->buf, u, err);
+		if (ret)
+			return ret;
 	} else if ((u->flags & REF_HAVE_OLD) && !oideq(&current_oid, &u->old_oid)) {
 		if (is_null_oid(&u->old_oid)) {
 			strbuf_addf(err, _("cannot lock ref '%s': "
 					   "reference already exists"),
 				    ref_update_original_update_refname(u));
-			return TRANSACTION_CREATE_EXISTS;
-		}
-		else if (is_null_oid(&current_oid))
+			return REF_TRANSACTION_ERROR_CREATE_EXISTS;
+		} else if (is_null_oid(&current_oid)) {
 			strbuf_addf(err, _("cannot lock ref '%s': "
 					   "reference is missing but expected %s"),
 				    ref_update_original_update_refname(u),
 				    oid_to_hex(&u->old_oid));
-		else
+			return REF_TRANSACTION_ERROR_NONEXISTENT_REF;
+		} else {
 			strbuf_addf(err, _("cannot lock ref '%s': "
 					   "is at %s but expected %s"),
 				    ref_update_original_update_refname(u),
 				    oid_to_hex(&current_oid),
 				    oid_to_hex(&u->old_oid));
-		return TRANSACTION_NAME_CONFLICT;
+			return REF_TRANSACTION_ERROR_INCORRECT_OLD_VALUE;
+		}
 	}
 
 	/*
@@ -1296,8 +1297,8 @@ static int prepare_single_update(struct reftable_ref_store *refs,
 	if ((u->type & REF_ISSYMREF) ||
 	    (u->flags & REF_LOG_ONLY) ||
 	    (u->flags & REF_HAVE_NEW && !oideq(&current_oid, &u->new_oid)))
-		return queue_transaction_update(refs, tx_data, u,
-					       &current_oid, err);
+		if (queue_transaction_update(refs, tx_data, u, &current_oid, err))
+			return REF_TRANSACTION_ERROR_GENERIC;
 
 	return 0;
 }
@@ -1386,7 +1387,6 @@ static int reftable_be_transaction_prepare(struct ref_store *ref_store,
 	transaction->state = REF_TRANSACTION_PREPARED;
 
 done:
-	assert(ret != REFTABLE_API_ERROR);
 	if (ret < 0) {
 		free_transaction_data(tx_data);
 		transaction->state = REF_TRANSACTION_CLOSED;
-- 
2.48.1
Karthik Nayak· Mar 5, 2025, 17:39 UTC · re: Karthik Nayak · lore

[PATCH v3 6/8] refs: implement partial reference transaction support

Git's reference transactions are all-or-nothing: either all updates succeed, or none do. While this atomic behavior is generally desirable, it can be suboptimal especially when using the reftable backend, where batching multiple reference updates into a single transaction is more efficient than performing them sequentially.

Introduce partial transaction support with a new flag, 'REF_TRANSACTION_ALLOW_PARTIAL'. When enabled, this flag allows individual reference updates that would typically cause the entire transaction to fail due to non-system-related errors to be marked as rejected while permitting other updates to proceed. System errors referred by 'REF_TRANSACTION_ERROR_GENERIC' continue to result in the entire transaction failing. This approach enhances flexibility while preserving transactional integrity where necessary.

The implementation introduces several key components:
  - Add 'rejection_err' field to struct `ref_update` to track failed
    updates with failure reason.
  - Add a new struct `ref_transaction_rejections` and a field within
    `ref_transaction` to this struct to allow quick iteration over
    rejected updates.
  - Modify reference backends (files, packed, reftable) to handle
    partial transactions by using `ref_transaction_set_rejected()`
    instead of failing the entire transaction when
    `REF_TRANSACTION_ALLOW_PARTIAL` is set.
  - Add `ref_transaction_for_each_rejected_update()` to let callers
    examine which updates were rejected and why.

This foundational change enables partial transaction support throughout the reference subsystem. A following commit will expose this capability to users by adding a `--allow-partial` flag to 'git-update-ref(1)', providing both a user-facing feature and a testable implementation.

Signed-off-by: Karthik Nayak <karthik.188@gmail.com>
---
 refs.c                  | 61 +++++++++++++++++++++++++++++++++++++++++++++++++
 refs.h                  | 22 ++++++++++++++++++
 refs/files-backend.c    | 12 +++++++++-
 refs/packed-backend.c   | 27 ++++++++++++++++++++--
 refs/refs-internal.h    | 25 ++++++++++++++++++++
 refs/reftable-backend.c | 12 +++++++++-
 6 files changed, 155 insertions(+), 4 deletions(-)
Show changes to 6 files +155 −4

refs.c, refs.h, refs/files-backend.c, refs/packed-backend.c, refs/refs-internal.h, refs/reftable-backend.c

diff --git a/refs.c b/refs.c
index 63b8050ce2..b735510c3b 100644
--- a/refs.c
+++ b/refs.c
@@ -1176,6 +1176,10 @@ struct ref_transaction *ref_store_transaction_begin(struct ref_store *refs,
 	tr->ref_store = refs;
 	tr->flags = flags;
 	string_list_init_dup(&tr->refnames);
+
+	if (flags & REF_TRANSACTION_ALLOW_PARTIAL)
+		CALLOC_ARRAY(tr->rejections, 1);
+
 	return tr;
 }
 
@@ -1206,11 +1210,45 @@ void ref_transaction_free(struct ref_transaction *transaction)
 		free((char *)transaction->updates[i]->old_target);
 		free(transaction->updates[i]);
 	}
+
+	if (transaction->rejections)
+		free(transaction->rejections->update_indices);
+	free(transaction->rejections);
+
 	string_list_clear(&transaction->refnames, 0);
 	free(transaction->updates);
 	free(transaction);
 }
 
+int ref_transaction_maybe_set_rejected(struct ref_transaction *transaction,
+				       size_t update_idx,
+				       enum ref_transaction_error err)
+{
+	if (update_idx >= transaction->nr)
+		BUG("trying to set rejection on invalid update index");
+
+	if (!(transaction->flags & REF_TRANSACTION_ALLOW_PARTIAL))
+		return 0;
+
+	if (!transaction->rejections)
+		BUG("transaction not inititalized with partial support");
+
+	/*
+	 * Don't accept generic errors, since these errors are not user
+	 * input related.
+	 */
+	if (err == REF_TRANSACTION_ERROR_GENERIC)
+		return 0;
+
+	transaction->updates[update_idx]->rejection_err = err;
+	ALLOC_GROW(transaction->rejections->update_indices,
+		   transaction->rejections->nr + 1,
+		   transaction->rejections->alloc);
+	transaction->rejections->update_indices[transaction->rejections->nr++] = update_idx;
+
+	return 1;
+}
+
 struct ref_update *ref_transaction_add_update(
 		struct ref_transaction *transaction,
 		const char *refname, unsigned int flags,
@@ -1236,6 +1274,7 @@ struct ref_update *ref_transaction_add_update(
 	transaction->updates[transaction->nr++] = update;
 
 	update->flags = flags;
+	update->rejection_err = 0;
 
 	update->new_target = xstrdup_or_null(new_target);
 	update->old_target = xstrdup_or_null(old_target);
@@ -2727,6 +2766,28 @@ void ref_transaction_for_each_queued_update(struct ref_transaction *transaction,
 	}
 }
 
+void ref_transaction_for_each_rejected_update(struct ref_transaction *transaction,
+					      ref_transaction_for_each_rejected_update_fn cb,
+					      void *cb_data)
+{
+	if (!transaction->rejections)
+		return;
+
+	for (size_t i = 0; i < transaction->rejections->nr; i++) {
+		size_t update_index = transaction->rejections->update_indices[i];
+		struct ref_update *update = transaction->updates[update_index];
+
+		if (!update->rejection_err)
+			continue;
+
+		cb(update->refname,
+		   (update->flags & REF_HAVE_OLD) ? &update->old_oid : NULL,
+		   (update->flags & REF_HAVE_NEW) ? &update->new_oid : NULL,
+		   update->old_target, update->new_target,
+		   update->rejection_err, cb_data);
+	}
+}
+
 int refs_delete_refs(struct ref_store *refs, const char *logmsg,
 		     struct string_list *refnames, unsigned int flags)
 {
diff --git a/refs.h b/refs.h
index 1b9213f9ce..5e5ff9e57d 100644
--- a/refs.h
+++ b/refs.h
@@ -673,6 +673,13 @@ enum ref_transaction_flag {
 	 * either be absent or null_oid.
 	 */
 	REF_TRANSACTION_FLAG_INITIAL = (1 << 0),
+
+	/*
+	 * The transaction mechanism by default fails all updates if any conflict
+	 * is detected. This flag allows transactions to partially apply updates
+	 * while rejecting updates which do not match the expected state.
+	 */
+	REF_TRANSACTION_ALLOW_PARTIAL = (1 << 1),
 };
 
 /*
@@ -903,6 +910,21 @@ void ref_transaction_for_each_queued_update(struct ref_transaction *transaction,
 					    ref_transaction_for_each_queued_update_fn cb,
 					    void *cb_data);
 
+/*
+ * Execute the given callback function for each of the reference updates which
+ * have been rejected in the given transaction.
+ */
+typedef void ref_transaction_for_each_rejected_update_fn(const char *refname,
+							 const struct object_id *old_oid,
+							 const struct object_id *new_oid,
+							 const char *old_target,
+							 const char *new_target,
+							 enum ref_transaction_error err,
+							 void *cb_data);
+void ref_transaction_for_each_rejected_update(struct ref_transaction *transaction,
+					      ref_transaction_for_each_rejected_update_fn cb,
+					      void *cb_data);
+
 /*
  * Free `*transaction` and all associated data.
  */
diff --git a/refs/files-backend.c b/refs/files-backend.c
index 1e1663f44b..c2fdee6013 100644
--- a/refs/files-backend.c
+++ b/refs/files-backend.c
@@ -2852,8 +2852,15 @@ static int files_transaction_prepare(struct ref_store *ref_store,
 		ret = lock_ref_for_update(refs, update, transaction,
 					  head_ref, &refnames_to_check,
 					  err);
-		if (ret)
+		if (ret) {
+			if (ref_transaction_maybe_set_rejected(transaction, i, ret)) {
+				strbuf_setlen(err, 0);
+				ret = 0;
+
+				continue;
+			}
 			goto cleanup;
+		}
 
 		if (update->flags & REF_DELETING &&
 		    !(update->flags & REF_LOG_ONLY) &&
@@ -3151,6 +3158,9 @@ static int files_transaction_finish(struct ref_store *ref_store,
 		struct ref_update *update = transaction->updates[i];
 		struct ref_lock *lock = update->backend_data;
 
+		if (update->rejection_err)
+			continue;
+
 		if (update->flags & REF_NEEDS_COMMIT ||
 		    update->flags & REF_LOG_ONLY) {
 			if (parse_and_write_reflog(refs, update, lock, err)) {
diff --git a/refs/packed-backend.c b/refs/packed-backend.c
index 5458952624..bfc6135743 100644
--- a/refs/packed-backend.c
+++ b/refs/packed-backend.c
@@ -1327,10 +1327,11 @@ static int packed_ref_store_remove_on_disk(struct ref_store *ref_store,
  * remain locked when it is done.
  */
 static enum ref_transaction_error write_with_updates(struct packed_ref_store *refs,
-						     struct string_list *updates,
+						     struct ref_transaction *transaction,
 						     struct strbuf *err)
 {
 	enum ref_transaction_error ret = REF_TRANSACTION_ERROR_GENERIC;
+	struct string_list *updates = &transaction->refnames;
 	struct ref_iterator *iter = NULL;
 	size_t i;
 	int ok;
@@ -1411,6 +1412,13 @@ static enum ref_transaction_error write_with_updates(struct packed_ref_store *re
 						    "reference already exists",
 						    update->refname);
 					ret = REF_TRANSACTION_ERROR_CREATE_EXISTS;
+
+					if (ref_transaction_maybe_set_rejected(transaction, i, ret)) {
+						strbuf_setlen(err, 0);
+						ret = 0;
+						continue;
+					}
+
 					goto error;
 				} else if (!oideq(&update->old_oid, iter->oid)) {
 					strbuf_addf(err, "cannot update ref '%s': "
@@ -1419,6 +1427,13 @@ static enum ref_transaction_error write_with_updates(struct packed_ref_store *re
 						    oid_to_hex(iter->oid),
 						    oid_to_hex(&update->old_oid));
 					ret = REF_TRANSACTION_ERROR_INCORRECT_OLD_VALUE;
+
+					if (ref_transaction_maybe_set_rejected(transaction, i, ret)) {
+						strbuf_setlen(err, 0);
+						ret = 0;
+						continue;
+					}
+
 					goto error;
 				}
 			}
@@ -1456,6 +1471,13 @@ static enum ref_transaction_error write_with_updates(struct packed_ref_store *re
 					    update->refname,
 					    oid_to_hex(&update->old_oid));
 				return REF_TRANSACTION_ERROR_NONEXISTENT_REF;
+
+				if (ref_transaction_maybe_set_rejected(transaction, i, ret)) {
+					strbuf_setlen(err, 0);
+					ret = 0;
+					continue;
+				}
+
 				goto error;
 			}
 		}
@@ -1521,6 +1543,7 @@ static enum ref_transaction_error write_with_updates(struct packed_ref_store *re
 write_error:
 	strbuf_addf(err, "error writing to %s: %s",
 		    get_tempfile_path(refs->tempfile), strerror(errno));
+	ret = REF_TRANSACTION_ERROR_GENERIC;
 
 error:
 	ref_iterator_free(iter);
@@ -1679,7 +1702,7 @@ static int packed_transaction_prepare(struct ref_store *ref_store,
 		data->own_lock = 1;
 	}
 
-	ret = write_with_updates(refs, &transaction->refnames, err);
+	ret = write_with_updates(refs, transaction, err);
 	if (ret)
 		goto failure;
 
diff --git a/refs/refs-internal.h b/refs/refs-internal.h
index 3f1d19abd9..c417aec217 100644
--- a/refs/refs-internal.h
+++ b/refs/refs-internal.h
@@ -123,6 +123,11 @@ struct ref_update {
 	 */
 	uint64_t index;
 
+	/*
+	 * Used in partial transactions to mark if a given update was rejected.
+	 */
+	enum ref_transaction_error rejection_err;
+
 	/*
 	 * If this ref_update was split off of a symref update via
 	 * split_symref_update(), then this member points at that
@@ -142,6 +147,13 @@ int refs_read_raw_ref(struct ref_store *ref_store, const char *refname,
 		      struct object_id *oid, struct strbuf *referent,
 		      unsigned int *type, int *failure_errno);
 
+/*
+ * Mark a given update as rejected with a given reason.
+ */
+int ref_transaction_maybe_set_rejected(struct ref_transaction *transaction,
+				       size_t update_idx,
+				       enum ref_transaction_error err);
+
 /*
  * Add a ref_update with the specified properties to transaction, and
  * return a pointer to the new object. This function does not verify
@@ -183,6 +195,18 @@ enum ref_transaction_state {
 	REF_TRANSACTION_CLOSED   = 2
 };
 
+/*
+ * Data structure to hold indices of updates which were rejected, when
+ * partial transactions where enabled. While the updates themselves hold
+ * the rejection error, this structure allows a transaction to iterate
+ * only over the rejected updates.
+ */
+struct ref_transaction_rejections {
+	size_t *update_indices;
+	size_t alloc;
+	size_t nr;
+};
+
 /*
  * Data structure for holding a reference transaction, which can
  * consist of checks and updates to multiple references, carried out
@@ -195,6 +219,7 @@ struct ref_transaction {
 	size_t alloc;
 	size_t nr;
 	enum ref_transaction_state state;
+	struct ref_transaction_rejections *rejections;
 	void *backend_data;
 	unsigned int flags;
 	uint64_t max_index;
diff --git a/refs/reftable-backend.c b/refs/reftable-backend.c
index 0132b8b06a..dd9912d637 100644
--- a/refs/reftable-backend.c
+++ b/refs/reftable-backend.c
@@ -1371,8 +1371,15 @@ static int reftable_be_transaction_prepare(struct ref_store *ref_store,
 					    transaction->updates[i],
 					    &refnames_to_check, head_type,
 					    &head_referent, &referent, err);
-		if (ret)
+		if (ret) {
+			if (ref_transaction_maybe_set_rejected(transaction, i, ret)) {
+				strbuf_setlen(err, 0);
+				ret = 0;
+
+				continue;
+			}
 			goto done;
+		}
 	}
 
 	string_list_sort(&refnames_to_check);
@@ -1455,6 +1462,9 @@ static int write_transaction_table(struct reftable_writer *writer, void *cb_data
 		struct reftable_transaction_update *tx_update = &arg->updates[i];
 		struct ref_update *u = tx_update->update;
 
+		if (u->rejection_err)
+			continue;
+
 		/*
 		 * Write a reflog entry when updating a ref to point to
 		 * something new in either of the following cases:
-- 
2.48.1
Jeff King· Mar 7, 2025, 19:50 UTC · re: Karthik Nayak · lore

Re: [PATCH v3 6/8] refs: implement partial reference transaction support

On Wed, Mar 05, 2025 at 06:39:01PM +0100, Karthik Nayak wrote:
Show 14 quoted lines
> @@ -1456,6 +1471,13 @@ static enum ref_transaction_error write_with_updates(struct packed_ref_store *re
>  					    update->refname,
>  					    oid_to_hex(&update->old_oid));
>  				return REF_TRANSACTION_ERROR_NONEXISTENT_REF;
> +
> +				if (ref_transaction_maybe_set_rejected(transaction, i, ret)) {
> +					strbuf_setlen(err, 0);
> +					ret = 0;
> +					continue;
> +				}
> +
>  				goto error;
>  			}
>  		}

This new code isn't reachable, since we return in the lines shown in the diff context.

Should it have been "ret = REF_TRANSACTION_ERROR"... in the first place? I think the "goto error" was already unreachable, so possibly the error is in an earlier patch. (I didn't look; Coverity flagged this in the final state in 'jch').

-Peff
Junio C Hamano· Mar 7, 2025, 20:46 UTC · re: Jeff King · lore

Re: [PATCH v3 6/8] refs: implement partial reference transaction support

Jeff King <peff@peff.net> writes:
Show 24 quoted lines
> On Wed, Mar 05, 2025 at 06:39:01PM +0100, Karthik Nayak wrote:
>
>> @@ -1456,6 +1471,13 @@ static enum ref_transaction_error write_with_updates(struct packed_ref_store *re
>>  					    update->refname,
>>  					    oid_to_hex(&update->old_oid));
>>  				return REF_TRANSACTION_ERROR_NONEXISTENT_REF;
>> +
>> +				if (ref_transaction_maybe_set_rejected(transaction, i, ret)) {
>> +					strbuf_setlen(err, 0);
>> +					ret = 0;
>> +					continue;
>> +				}
>> +
>>  				goto error;
>>  			}
>>  		}
>
> This new code isn't reachable, since we return in the lines shown in the
> diff context.
>
> Should it have been "ret = REF_TRANSACTION_ERROR"... in the first place?
> I think the "goto error" was already unreachable, so possibly the error
> is in an earlier patch. (I didn't look; Coverity flagged this in the
> final state in 'jch').

Sorry about that. It shows that I lack the bandwidth necessary to go through fine toothed comb on all the topics I queue. Perhaps I should be more selective and queue only the ones I personally had enough bandwidth to look over (or have seen clear "I looked each and every line of this series with fine toothed comb, put reviewed-by: me" messages sent by trusted reviewers) while ignoring others?

I dunno.
Thanks.
Junio C Hamano· Mar 7, 2025, 20:48 UTC · re: Junio C Hamano · lore

Re: [PATCH v3 6/8] refs: implement partial reference transaction support

Junio C Hamano <gitster@pobox.com> writes:
Show 6 quoted lines
> Sorry about that.  It shows that I lack the bandwidth necessary to
> go through fine toothed comb on all the topics I queue.  Perhaps I
> should be more selective and queue only the ones I personally had
> enough bandwidth to look over (or have seen clear "I looked each and
> every line of this series with fine toothed comb, put reviewed-by:
> me" messages sent by trusted reviewers) while ignoring others?

I forgot a third category. I should be able to queue series by those who have track record of being meticulous and not have made silly mistakes without reading each and every line.

Karthik Nayak· Mar 7, 2025, 21:05 UTC · re: Junio C Hamano · lore

Re: [PATCH v3 6/8] refs: implement partial reference transaction support

Junio C Hamano <gitster@pobox.com> writes:
Show 37 quoted lines
> Jeff King <peff@peff.net> writes:
>
>> On Wed, Mar 05, 2025 at 06:39:01PM +0100, Karthik Nayak wrote:
>>
>>> @@ -1456,6 +1471,13 @@ static enum ref_transaction_error write_with_updates(struct packed_ref_store *re
>>>  					    update->refname,
>>>  					    oid_to_hex(&update->old_oid));
>>>  				return REF_TRANSACTION_ERROR_NONEXISTENT_REF;
>>> +
>>> +				if (ref_transaction_maybe_set_rejected(transaction, i, ret)) {
>>> +					strbuf_setlen(err, 0);
>>> +					ret = 0;
>>> +					continue;
>>> +				}
>>> +
>>>  				goto error;
>>>  			}
>>>  		}
>>
>> This new code isn't reachable, since we return in the lines shown in the
>> diff context.
>>
>> Should it have been "ret = REF_TRANSACTION_ERROR"... in the first place?
>> I think the "goto error" was already unreachable, so possibly the error
>> is in an earlier patch. (I didn't look; Coverity flagged this in the
>> final state in 'jch').
>
> Sorry about that.  It shows that I lack the bandwidth necessary to
> go through fine toothed comb on all the topics I queue.  Perhaps I
> should be more selective and queue only the ones I personally had
> enough bandwidth to look over (or have seen clear "I looked each and
> every line of this series with fine toothed comb, put reviewed-by:
> me" messages sent by trusted reviewers) while ignoring others?
>
> I dunno.
>
> Thanks.

Apologies, I see that this was also present in the previous version. Definitely a miss on my side. I'll see how it was missed in the tests and add one if necessary!

Thanks!
Jeff King· Mar 7, 2025, 22:54 UTC · re: Junio C Hamano · lore

[PATCH] config.mak.dev: enable -Wunreachable-code

On Fri, Mar 07, 2025 at 12:46:27PM -0800, Junio C Hamano wrote:
Show 33 quoted lines
> Jeff King <peff@peff.net> writes:
> 
> > On Wed, Mar 05, 2025 at 06:39:01PM +0100, Karthik Nayak wrote:
> >
> >> @@ -1456,6 +1471,13 @@ static enum ref_transaction_error write_with_updates(struct packed_ref_store *re
> >>  					    update->refname,
> >>  					    oid_to_hex(&update->old_oid));
> >>  				return REF_TRANSACTION_ERROR_NONEXISTENT_REF;
> >> +
> >> +				if (ref_transaction_maybe_set_rejected(transaction, i, ret)) {
> >> +					strbuf_setlen(err, 0);
> >> +					ret = 0;
> >> +					continue;
> >> +				}
> >> +
> >>  				goto error;
> >>  			}
> >>  		}
> >
> > This new code isn't reachable, since we return in the lines shown in the
> > diff context.
> >
> > Should it have been "ret = REF_TRANSACTION_ERROR"... in the first place?
> > I think the "goto error" was already unreachable, so possibly the error
> > is in an earlier patch. (I didn't look; Coverity flagged this in the
> > final state in 'jch').
> 
> Sorry about that.  It shows that I lack the bandwidth necessary to
> go through fine toothed comb on all the topics I queue.  Perhaps I
> should be more selective and queue only the ones I personally had
> enough bandwidth to look over (or have seen clear "I looked each and
> every line of this series with fine toothed comb, put reviewed-by:
> me" messages sent by trusted reviewers) while ignoring others?

Eh, I would not worry about it too much. Things get missed, and that is why we have many layers of reviews, static analysis, and ultimately users to help us find bugs. ;)

I was disappointed that the compiler didn't complain, though. Maybe we should do this:

-- >8 --
Subject: [PATCH] config.mak.dev: enable -Wunreachable-code

Having the compiler point out unreachable code can help avoid bugs, like the one discussed in:

  https://lore.kernel.org/git/20250307195057.GA3675279@coredump.intra.peff.net/

In that case it was found by Coverity, but finding it earlier saves everybody time and effort.

We can use -Wunreachable-code to get some help from the compiler here. Interestingly, this is a noop in gcc. It was a real warning up until gcc 4.x, when it was removed for being too flaky, but they left the command-line option to avoid breaking users. See:

  https://stackoverflow.com/questions/17249934/why-does-gcc-not-warn-for-unreachable-code

However, clang does implement this option, and it finds the case mentioned above (and no other cases within the code base). And since we run clang in several of our CI jobs, that's enough to get an early warning of breakage.

We could enable it only for clang, but since gcc is happy to ignore it, it's simpler to just turn it on for all developer builds.

Signed-off-by: Jeff King <peff@peff.net>
---
You can see it in action (merged into 'jch') here:
  https://github.com/peff/git/actions/runs/13729842188
where all of the clang jobs fail.
 config.mak.dev | 1 +
 1 file changed, 1 insertion(+)
Show changes to config.mak.dev +1 −0
diff --git a/config.mak.dev b/config.mak.dev
index 0fd8cc4d35..95b7bc46ae 100644
--- a/config.mak.dev
+++ b/config.mak.dev
@@ -39,6 +39,7 @@ DEVELOPER_CFLAGS += -Wunused
 DEVELOPER_CFLAGS += -Wvla
 DEVELOPER_CFLAGS += -Wwrite-strings
 DEVELOPER_CFLAGS += -fno-common
+DEVELOPER_CFLAGS += -Wunreachable-code
 
 ifneq ($(filter clang4,$(COMPILER_FEATURES)),)
 DEVELOPER_CFLAGS += -Wtautological-constant-out-of-range-compare
-- 
2.49.0.rc1.380.g53e738dd21
Junio C Hamano· Mar 7, 2025, 23:28 UTC · re: Jeff King · lore

Re: [PATCH] config.mak.dev: enable -Wunreachable-code

Jeff King <peff@peff.net> writes:
> I was disappointed that the compiler didn't complain, though. Maybe we
> should do this:
Indeed.  It would have helped us if it were already there in place.
Show 17 quoted lines
> -- >8 --
> Subject: [PATCH] config.mak.dev: enable -Wunreachable-code
>
> Having the compiler point out unreachable code can help avoid bugs, like
> the one discussed in:
>
>   https://lore.kernel.org/git/20250307195057.GA3675279@coredump.intra.peff.net/
>
> In that case it was found by Coverity, but finding it earlier saves
> everybody time and effort.
>
> We can use -Wunreachable-code to get some help from the compiler here.
> Interestingly, this is a noop in gcc. It was a real warning up until gcc
> 4.x, when it was removed for being too flaky, but they left the
> command-line option to avoid breaking users. See:
>
>   https://stackoverflow.com/questions/17249934/why-does-gcc-not-warn-for-unreachable-code

Wow, now they leave their users confused, making them wondering why their command line option does not do anything useful ;-)

> However, clang does implement this option, and it finds the case
> mentioned above (and no other cases within the code base). And since we
> run clang in several of our CI jobs, that's enough to get an early
> warning of breakage.
Yes, this is great.
Thanks.
Jeff King· Mar 8, 2025, 03:23 UTC · re: Jeff King · lore

Re: [PATCH] config.mak.dev: enable -Wunreachable-code

On Fri, Mar 07, 2025 at 05:54:45PM -0500, Jeff King wrote:
> However, clang does implement this option, and it finds the case
> mentioned above (and no other cases within the code base). And since we
> run clang in several of our CI jobs, that's enough to get an early
> warning of breakage.
Hmph, this might be more trouble than it is worth.

After correcting the problem in the refs code, the osx CI builds (and only those) now fail with:

  run-command.c:519:3: error: code will never be executed [-Werror,-Wunreachable-code]
                  die_errno("sigfillset");
                  ^~~~~~~~~
The code in question is just:
  if (sigfillset(&all))
	die_errno("sigfillset");

So I have to imagine that the issue is that sigfillset() on that platform is an inline or macro that will never return an error, and the compiler can see that. But since POSIX says this can fail (though I'd imagine it's unlikely on most platforms), we should check in the general case.

So I don't see how to solve it short of:
#ifdef SIGFILLSET_CANNOT_FAIL
	sigfillset(&all);
#else
	if (sigfillset(&all))
		die_errno("sigfillset");
#endif

which is rather ugly. It's only used in one spot, so the damage doesn't go too far, but I don't love the idea of getting surprised by the compiler over-analyzing system functions (and having to add Makefile knobs to support it).

I guess a knob-less version is:
  errno = 0;
  sigfillset(&all); /* don't check return value! only errno */
  if (errno)
	die_errno("sigfillset");
which is subtle, to say the least.
-Peff
Junio C Hamano· Mar 10, 2025, 15:40 UTC · re: Jeff King · lore

Re: [PATCH] config.mak.dev: enable -Wunreachable-code

Jeff King <peff@peff.net> writes:
Show 24 quoted lines
> On Fri, Mar 07, 2025 at 05:54:45PM -0500, Jeff King wrote:
>
>> However, clang does implement this option, and it finds the case
>> mentioned above (and no other cases within the code base). And since we
>> run clang in several of our CI jobs, that's enough to get an early
>> warning of breakage.
>
> Hmph, this might be more trouble than it is worth.
>
> After correcting the problem in the refs code, the osx CI builds (and
> only those) now fail with:
>
>   run-command.c:519:3: error: code will never be executed [-Werror,-Wunreachable-code]
>                   die_errno("sigfillset");
>                   ^~~~~~~~~
> ...
> I guess a knob-less version is:
>
>   errno = 0;
>   sigfillset(&all); /* don't check return value! only errno */
>   if (errno)
> 	die_errno("sigfillset");
>
> which is subtle, to say the least.

Bah. This is just as horrible as some other warnings that are not enabled by default. I guess we should just be more vigilant X-<.

Thanks.
Jeff King· Mar 10, 2025, 16:04 UTC · re: Junio C Hamano · lore

Re: [PATCH] config.mak.dev: enable -Wunreachable-code

On Mon, Mar 10, 2025 at 08:40:46AM -0700, Junio C Hamano wrote:
Show 29 quoted lines
> Jeff King <peff@peff.net> writes:
> 
> > On Fri, Mar 07, 2025 at 05:54:45PM -0500, Jeff King wrote:
> >
> >> However, clang does implement this option, and it finds the case
> >> mentioned above (and no other cases within the code base). And since we
> >> run clang in several of our CI jobs, that's enough to get an early
> >> warning of breakage.
> >
> > Hmph, this might be more trouble than it is worth.
> >
> > After correcting the problem in the refs code, the osx CI builds (and
> > only those) now fail with:
> >
> >   run-command.c:519:3: error: code will never be executed [-Werror,-Wunreachable-code]
> >                   die_errno("sigfillset");
> >                   ^~~~~~~~~
> > ...
> > I guess a knob-less version is:
> >
> >   errno = 0;
> >   sigfillset(&all); /* don't check return value! only errno */
> >   if (errno)
> > 	die_errno("sigfillset");
> >
> > which is subtle, to say the least.
> 
> Bah.  This is just as horrible as some other warnings that are not
> enabled by default.  I guess we should just be more vigilant X-<.

Yeah. We could perhaps live with hacking around this one specific spot. But there's an open question of how often these kinds of false positives will come up.

Maybe not often, if there is only one instance in the current code base. Or maybe a lot, but we wouldn't know because we haven't had the warning enabled.

I guess another option is to enable it in _one_ CI job that uses clang on Linux (maybe linux-sha256?) and see how often it is helpful or harmful.

-Peff
Junio C Hamano· Mar 10, 2025, 18:50 UTC · re: Jeff King · lore

Re: [PATCH] config.mak.dev: enable -Wunreachable-code

Jeff King <peff@peff.net> writes:
Show 7 quoted lines
> Maybe not often, if there is only one instance in the current code base.
> Or maybe a lot, but we wouldn't know because we haven't had the warning
> enabled.
>
> I guess another option is to enable it in _one_ CI job that uses clang
> on Linux (maybe linux-sha256?) and see how often it is helpful or
> harmful.

The reason why you said Linux rather than macOS is because the single instance we know about would not have to be worked around if we did it that way?

I am OK with that.  
Thanks.
Jeff King· Mar 14, 2025, 16:10 UTC · re: Junio C Hamano · lore

Re: [PATCH] config.mak.dev: enable -Wunreachable-code

On Mon, Mar 10, 2025 at 11:50:20AM -0700, Junio C Hamano wrote:
Show 15 quoted lines
> Jeff King <peff@peff.net> writes:
> 
> > Maybe not often, if there is only one instance in the current code base.
> > Or maybe a lot, but we wouldn't know because we haven't had the warning
> > enabled.
> >
> > I guess another option is to enable it in _one_ CI job that uses clang
> > on Linux (maybe linux-sha256?) and see how often it is helpful or
> > harmful.
> 
> The reason why you said Linux rather than macOS is because the
> single instance we know about would not have to be worked around if
> we did it that way?
> 
> I am OK with that.

Yes, exactly. I started to prepare a patch for that, but then I realized I'd probably be adding support in config.mak.dev. So we could also just handle it automatically there, skipping the flag on macOS.

That would use the flag in more situations (blocking the known-bad case, rather than enabling it in a known-good one). It might hit more false positives, but I'd rather experiment in that direction and see if anybody setting DEVELOPER=1 complains. After all, in either case it is still a big question of whether this is the only false positive we'll see, or if this is opening up a can of worms. So I consider it all kind-of exploratory.

So that patch could look like this (on top of what you've queued already in jk/use-wunreachable-code-for-devs).

-- >8 --
Subject: [PATCH] config.mak.dev: disable -Wunreachable-code on macOS

We've seen false positives here related to calling sigfillset(); even though POSIX specifies that it may return an error, it transparently (to the compiler) always returns success on macOS. As a result, the compiler flags the error path in something like:

  if (sigfillset(&set))
	die(...);

as unreachable (which it is on this platform, but not in the general case). We could work around it, but let's just disable the warning on this platform. There are plenty of CI jobs that will still trigger it (e.g., all of the linux+clang jobs).

Signed-off-by: Jeff King <peff@peff.net>
---
It's possible FreeBSD might share the same problem, but their manpage
does not seem to have the same "it always returns 0" language. But we
might need to expand this list if people report more problems.
 config.mak.dev | 5 +++++
 1 file changed, 5 insertions(+)
Show changes to config.mak.dev +5 −0
diff --git a/config.mak.dev b/config.mak.dev
index 95b7bc46ae..30dcd0c175 100644
--- a/config.mak.dev
+++ b/config.mak.dev
@@ -39,7 +39,12 @@ DEVELOPER_CFLAGS += -Wunused
 DEVELOPER_CFLAGS += -Wvla
 DEVELOPER_CFLAGS += -Wwrite-strings
 DEVELOPER_CFLAGS += -fno-common
+
+# There are false positives for unreachable code related to system
+# functions on macOS.
+ifneq ($(uname_S),Darwin)
 DEVELOPER_CFLAGS += -Wunreachable-code
+endif
 
 ifneq ($(filter clang4,$(COMPILER_FEATURES)),)
 DEVELOPER_CFLAGS += -Wtautological-constant-out-of-range-compare
-- 
2.49.0.rc2.384.gf2d6285ccb
Jeff King· Mar 14, 2025, 16:13 UTC · re: Jeff King · lore

Re: [PATCH] config.mak.dev: enable -Wunreachable-code

On Fri, Mar 14, 2025 at 12:10:10PM -0400, Jeff King wrote:
Show 10 quoted lines
> So that patch could look like this (on top of what you've queued already
> in jk/use-wunreachable-code-for-devs).
> 
> -- >8 --
> Subject: [PATCH] config.mak.dev: disable -Wunreachable-code on macOS
> [...]
> ---
> It's possible FreeBSD might share the same problem, but their manpage
> does not seem to have the same "it always returns 0" language. But we
> might need to expand this list if people report more problems.

And I'm still a bit tempted to instead actually silence this one false positive, and keep the warning enabled everywhere. That would help FreeBSD (if it indeed does have the same issue) and let macOS benefit from the warning (most code paths would be covered on Linux anyway, but there could be platform-specific ones).

And that patch would look like this (again, on top of what you've already queued, and replacing the patch I'm replying to):

-- >8 --
Subject: [PATCH] run-command: use errno to check for sigfillset() error

Since enabling -Wunreachable-code, builds with clang on macOS now fail, complaining that the die_errno() call in:

  if (sigfillset(&all))
	die_errno("sigfillset");

is unreachable. On that platform the manpage documents that sigfillset() always returns success, and presumably the implementation is a macro or inline function that does so in a way that is transparent to the compiler.

But we should continue to check on other platforms, since POSIX says it may return an error.

We could solve this with a compile-time knob to split the two cases (assuming success on macOS and checking for the error elsewhere). But we can also work around it more directly by relying on errno to check the outcome (since POSIX dictates that errno will be set on error). And that works around the compiler's cleverness, since it doesn't know the semantics of errno (though I suppose if sigfillset() is simple enough, it could perhaps realize that no writes to errno are possible; however this does seem to work in practice).

Signed-off-by: Jeff King <peff@peff.net>
---
 run-command.c | 10 +++++++++-
 1 file changed, 9 insertions(+), 1 deletion(-)
Show changes to run-command.c +9 −1
diff --git a/run-command.c b/run-command.c
index 402138b8b5..d527c46175 100644
--- a/run-command.c
+++ b/run-command.c
@@ -515,7 +515,15 @@ static void atfork_prepare(struct atfork_state *as)
 {
 	sigset_t all;
 
-	if (sigfillset(&all))
+	/*
+	 * Do not use the return value of sigfillset(). It is transparently 0
+	 * on some platforms, meaning a clever compiler may complain that
+	 * the conditional body is dead code. Instead, check for error via
+	 * errno, which outsmarts the compiler.
+	 */
+	errno = 0;
+	sigfillset(&all);
+	if (errno)
 		die_errno("sigfillset");
 #ifdef NO_PTHREADS
 	if (sigprocmask(SIG_SETMASK, &all, &as->old))
-- 
2.49.0.rc2.384.gf2d6285ccb
Junio C Hamano· Mar 14, 2025, 17:27 UTC · re: Jeff King · lore

Re: [PATCH] config.mak.dev: enable -Wunreachable-code

Jeff King <peff@peff.net> writes:
Show 13 quoted lines
> -- >8 --
> Subject: [PATCH] run-command: use errno to check for sigfillset() error
>
> Since enabling -Wunreachable-code, builds with clang on macOS now fail,
> complaining that the die_errno() call in:
>
>   if (sigfillset(&all))
> 	die_errno("sigfillset");
>
> is unreachable. On that platform the manpage documents that sigfillset()
> always returns success, and presumably the implementation is a macro or
> inline function that does so in a way that is transparent to the
> compiler.
Would it work to instead do this here
	if (sigfillset(&all) || false_but_compiler_does_not_know_it)
		die_error("sigfillset");
with
	extern int false_but_compiler_does_not_know_it;

in <git-compat-util.h>? And a standalone .c file with its definition

	#include <git-compat-util.h>
	int false_but_compiler_does_not_know_it;
and nothing else, linked into libgit.a?

I am hoping that such a false-positive would come from conditionals that are known to be compiler to be always taken (or never taken), so eventually we can mark such an expression with a macro, e.g.

	if (CAN_BE_TAKEN(sigfilllset(&all))
		die_error("sigfillset");

Because in this particular case we _can_ rely on errno, so the patch we see here is perfectly fine by me, but a more generic approach like the above would make it unnecessary to

 - have a 4-line comment
 - come up with workaround

suitable for each such places we need to work around compiler smarta^hness.

Show 38 quoted lines
> But we should continue to check on other platforms, since POSIX says it
> may return an error.
>
> We could solve this with a compile-time knob to split the two cases
> (assuming success on macOS and checking for the error elsewhere). But we
> can also work around it more directly by relying on errno to check the
> outcome (since POSIX dictates that errno will be set on error). And that
> works around the compiler's cleverness, since it doesn't know the
> semantics of errno (though I suppose if sigfillset() is simple enough,
> it could perhaps realize that no writes to errno are possible; however
> this does seem to work in practice).
>
> Signed-off-by: Jeff King <peff@peff.net>
> ---
>  run-command.c | 10 +++++++++-
>  1 file changed, 9 insertions(+), 1 deletion(-)
>
> diff --git a/run-command.c b/run-command.c
> index 402138b8b5..d527c46175 100644
> --- a/run-command.c
> +++ b/run-command.c
> @@ -515,7 +515,15 @@ static void atfork_prepare(struct atfork_state *as)
>  {
>  	sigset_t all;
>  
> -	if (sigfillset(&all))
> +	/*
> +	 * Do not use the return value of sigfillset(). It is transparently 0
> +	 * on some platforms, meaning a clever compiler may complain that
> +	 * the conditional body is dead code. Instead, check for error via
> +	 * errno, which outsmarts the compiler.
> +	 */
> +	errno = 0;
> +	sigfillset(&all);
> +	if (errno)
>  		die_errno("sigfillset");
>  #ifdef NO_PTHREADS
>  	if (sigprocmask(SIG_SETMASK, &all, &as->old))
Junio C Hamano· Mar 14, 2025, 17:40 UTC · re: Junio C Hamano · lore

Re: [PATCH] config.mak.dev: enable -Wunreachable-code

Junio C Hamano <gitster@pobox.com> writes:
Show 18 quoted lines
> Jeff King <peff@peff.net> writes:
>
>> -- >8 --
>> Subject: [PATCH] run-command: use errno to check for sigfillset() error
>>
>> Since enabling -Wunreachable-code, builds with clang on macOS now fail,
>> complaining that the die_errno() call in:
>>
>>   if (sigfillset(&all))
>> 	die_errno("sigfillset");
>>
>> is unreachable. On that platform the manpage documents that sigfillset()
>> always returns success, and presumably the implementation is a macro or
>> inline function that does so in a way that is transparent to the
>> compiler.
>
> Would it work to instead do this here
> ...

I forgot to say a more important thing. Between the "let's excempt developers on macOS" and the "let's see how far we can go with the warning turned on everywhere and wack-a-mole this particular one with errno check" patches, I prefer the latter at least for a short term.

Thanks.
Patrick Steinhardt· Mar 14, 2025, 17:43 UTC · re: Junio C Hamano · lore

Re: [PATCH] config.mak.dev: enable -Wunreachable-code

On Fri, Mar 14, 2025 at 10:40:24AM -0700, Junio C Hamano wrote:
Show 26 quoted lines
> Junio C Hamano <gitster@pobox.com> writes:
> 
> > Jeff King <peff@peff.net> writes:
> >
> >> -- >8 --
> >> Subject: [PATCH] run-command: use errno to check for sigfillset() error
> >>
> >> Since enabling -Wunreachable-code, builds with clang on macOS now fail,
> >> complaining that the die_errno() call in:
> >>
> >>   if (sigfillset(&all))
> >> 	die_errno("sigfillset");
> >>
> >> is unreachable. On that platform the manpage documents that sigfillset()
> >> always returns success, and presumably the implementation is a macro or
> >> inline function that does so in a way that is transparent to the
> >> compiler.
> >
> > Would it work to instead do this here
> > ...
> 
> I forgot to say a more important thing.  Between the "let's excempt
> developers on macOS" and the "let's see how far we can go with the
> warning turned on everywhere and wack-a-mole this particular one
> with errno check" patches, I prefer the latter at least for a short
> term.

Yeah, I'm also in favor of generally enabling the warning and seeing whether it will end up being a pain or not. This particular edge case here is ugly, but it's manageable and may protect us from mistakes in other places going forward.

If we do so, could we please also include the following patch for Meson?
Thanks!
Patrick
Show changes to meson.build +1 −0
diff --git a/meson.build b/meson.build
index efe2871c9d..a0a602864a 100644
--- a/meson.build
+++ b/meson.build
@@ -721,6 +721,7 @@ if get_option('warning_level') in ['2','3', 'everything'] and compiler.get_argum
     '-Woverflow',
     '-Wpointer-arith',
     '-Wstrict-prototypes',
+    '-Wunreachable-code',
     '-Wunused',
     '-Wvla',
     '-Wwrite-strings',
Jeff King· Mar 14, 2025, 18:53 UTC · re: Junio C Hamano · lore

Re: [PATCH] config.mak.dev: enable -Wunreachable-code

On Fri, Mar 14, 2025 at 10:40:24AM -0700, Junio C Hamano wrote:
Show 22 quoted lines
> >> -- >8 --
> >> Subject: [PATCH] run-command: use errno to check for sigfillset() error
> >>
> >> Since enabling -Wunreachable-code, builds with clang on macOS now fail,
> >> complaining that the die_errno() call in:
> >>
> >>   if (sigfillset(&all))
> >> 	die_errno("sigfillset");
> >>
> >> is unreachable. On that platform the manpage documents that sigfillset()
> >> always returns success, and presumably the implementation is a macro or
> >> inline function that does so in a way that is transparent to the
> >> compiler.
> >
> > Would it work to instead do this here
> > ...
> 
> I forgot to say a more important thing.  Between the "let's excempt
> developers on macOS" and the "let's see how far we can go with the
> warning turned on everywhere and wack-a-mole this particular one
> with errno check" patches, I prefer the latter at least for a short
> term.

That's my gut feeling, too. I wasn't sure how people would feel about actually touching the code (whereas the other patches were purely turning compiler knobs). It may turn into wack-a-mole, but finding out is part of the experiment.

Your CAN_BE_TAKEN() approach is certainly less subtle, and can be applied in a more general way. If this is the only spot needed it may be overkill, but the readability improvement alone probably makes it worthwhile.

Do you want to turn that into a patch?
-Peff
Junio C Hamano· Mar 14, 2025, 19:50 UTC · re: Jeff King · lore

Re: [PATCH] config.mak.dev: enable -Wunreachable-code

Jeff King <peff@peff.net> writes:
Show 6 quoted lines
> Your CAN_BE_TAKEN() approach is certainly less subtle, and can be
> applied in a more general way. If this is the only spot needed it may be
> overkill, but the readability improvement alone probably makes it
> worthwhile.
>
> Do you want to turn that into a patch?

Yes, but after I come up with a better name. CAN_BE_TAKEN may be OK for if/while but not good enough for switch() for example. "Do not opmimize out because, despite your beliefs, this expression is ..." is what we want to convey.

 Makefile          |  1 +
 git-compat-util.h |  9 +++++++++
 meson.build       |  1 +
 run-command.c     | 12 +++++-------
 4 files changed, 16 insertions(+), 7 deletions(-)
Show changes to diff +16 −7
diff --git c/Makefile w/Makefile
index 97e8385b66..2158bf6916 100644
--- c/Makefile
+++ w/Makefile
@@ -1018,6 +1018,7 @@ LIB_OBJS += ewah/ewah_bitmap.o
 LIB_OBJS += ewah/ewah_io.o
 LIB_OBJS += ewah/ewah_rlw.o
 LIB_OBJS += exec-cmd.o
+LIB_OBJS += fbtcdnki.o
 LIB_OBJS += fetch-negotiator.o
 LIB_OBJS += fetch-pack.o
 LIB_OBJS += fmt-merge-msg.o
diff --git c/git-compat-util.h w/git-compat-util.h
index e283c46c6f..63a3ef6b70 100644
--- c/git-compat-util.h
+++ w/git-compat-util.h
@@ -1593,4 +1593,13 @@ static inline void *container_of_or_null_offset(void *ptr, size_t offset)
 	((uintptr_t)&(ptr)->member - (uintptr_t)(ptr))
 #endif /* !__GNUC__ */
 
+/*
+ * Prevent an overly clever compiler from optimizing an expression
+ * out, triggering a false positive when building with the
+ * -Wunreachable-code option. false_but_the_compiler_does_not_know_it_
+ * is defined in a compilation unit separate from where the macro is
+ * used, initialized to 0, and never modified.
+ */
+#define NOT_A_CONST(expr) ((expr) || false_but_the_compiler_does_not_know_it_)
+extern int false_but_the_compiler_does_not_know_it_;
 #endif
diff --git c/meson.build w/meson.build
index f60f3f49e4..ce642dcf65 100644
--- c/meson.build
+++ w/meson.build
@@ -282,6 +282,7 @@ libgit_sources = [
   'ewah/ewah_io.c',
   'ewah/ewah_rlw.c',
   'exec-cmd.c',
+  'fbtcdnki.c',
   'fetch-negotiator.c',
   'fetch-pack.c',
   'fmt-merge-msg.c',
diff --git c/run-command.c w/run-command.c
index d527c46175..535c73a059 100644
--- c/run-command.c
+++ w/run-command.c
@@ -516,14 +516,12 @@ static void atfork_prepare(struct atfork_state *as)
 	sigset_t all;
 
 	/*
-	 * Do not use the return value of sigfillset(). It is transparently 0
-	 * on some platforms, meaning a clever compiler may complain that
-	 * the conditional body is dead code. Instead, check for error via
-	 * errno, which outsmarts the compiler.
+	 * POSIX says sitfillset() can fail, but an overly clever
+	 * compiler can see through the header files and decide
+	 * it cannot fail on a particular platform it is compiling for,
+	 * triggering -Wunreachable-code false positive.
 	 */
-	errno = 0;
-	sigfillset(&all);
-	if (errno)
+	if (NOT_A_CONST(sigfillset(&all)))
 		die_errno("sigfillset");
 #ifdef NO_PTHREADS
 	if (sigprocmask(SIG_SETMASK, &all, &as->old))
Junio C Hamano· Mar 14, 2025, 17:15 UTC · re: Jeff King · lore

Re: [PATCH] config.mak.dev: enable -Wunreachable-code

Jeff King <peff@peff.net> writes:
> That would use the flag in more situations (blocking the known-bad case,
> rather than enabling it in a known-good one). It might hit more false
> positives, but I'd rather experiment in that direction and see if
> anybody setting DEVELOPER=1 complains.
Good.
> After all, in either case it is
> still a big question of whether this is the only false positive we'll
> see, or if this is opening up a can of worms. So I consider it all
> kind-of exploratory.
Again, good.
> So that patch could look like this (on top of what you've queued already
> in jk/use-wunreachable-code-for-devs).
Show 6 quoted lines
> +
> +# There are false positives for unreachable code related to system
> +# functions on macOS.
> +ifneq ($(uname_S),Darwin)
>  DEVELOPER_CFLAGS += -Wunreachable-code
> +endif

One possible downside of this is that we would not know when their compiler stops giving the "false positive" and becomes as usuable as other platforms (oh, it came out unintendedly harsh---it could be that the situation is that their compiler is doing the right thing, and the right thing is a bit inconvenient for this codebase).

Unless diligent volunteers with macOS step up to do trial builds with the option when they notice that their toolchain or OS header files got upgraded, that is.

But other than that, I am fine with this. Let's have this for some time to see how much problems (false positives) our newly added code would get to judge if it is worth our time to deal with them.

Thanks.
Mike Hommey· Jun 3, 2025, 21:29 UTC · re: Jeff King · lore

Re: [PATCH] config.mak.dev: enable -Wunreachable-code

On Fri, Mar 07, 2025 at 10:23:09PM -0500, Jeff King wrote:
Show 35 quoted lines
> On Fri, Mar 07, 2025 at 05:54:45PM -0500, Jeff King wrote:
> 
> > However, clang does implement this option, and it finds the case
> > mentioned above (and no other cases within the code base). And since we
> > run clang in several of our CI jobs, that's enough to get an early
> > warning of breakage.
> 
> Hmph, this might be more trouble than it is worth.
> 
> After correcting the problem in the refs code, the osx CI builds (and
> only those) now fail with:
> 
>   run-command.c:519:3: error: code will never be executed [-Werror,-Wunreachable-code]
>                   die_errno("sigfillset");
>                   ^~~~~~~~~
> 
> The code in question is just:
> 
>   if (sigfillset(&all))
> 	die_errno("sigfillset");
> 
> So I have to imagine that the issue is that sigfillset() on that
> platform is an inline or macro that will never return an error, and the
> compiler can see that. But since POSIX says this can fail (though I'd
> imagine it's unlikely on most platforms), we should check in the general
> case.
> 
> So I don't see how to solve it short of:
> 
> #ifdef SIGFILLSET_CANNOT_FAIL
> 	sigfillset(&all);
> #else
> 	if (sigfillset(&all))
> 		die_errno("sigfillset");
> #endif
There is a similar problem with this code in refs/files-backend.c:
			if (!create_ref_symlink(lock, update->new_target))
				continue;
Where create_ref_symlink is defined as such:

#ifdef NO_SYMLINK_HEAD #define create_ref_symlink(a, b) (-1) #else static int create_ref_symlink(struct ref_lock *lock, const char *target) { ... #endif

And NO_SYMLINK_HEAD is defined on Windows.
Mike
Junio C Hamano· Jun 3, 2025, 22:07 UTC · re: Mike Hommey · lore

Re: [PATCH] config.mak.dev: enable -Wunreachable-code

Mike Hommey <mh@glandium.org> writes:
Show 16 quoted lines
> There is a similar problem with this code in refs/files-backend.c:
>
> 			if (!create_ref_symlink(lock, update->new_target))
> 				continue;
>
> Where create_ref_symlink is defined as such:
>
> #ifdef NO_SYMLINK_HEAD
> #define create_ref_symlink(a, b) (-1)
> #else
> static int create_ref_symlink(struct ref_lock *lock, const char *target)
> {
> ...
> #endif
>
> And NO_SYMLINK_HEAD is defined on Windows.

Would the NOT_CONSTANT() trick we ended up using for the original "sigfillset" thing solve your issue as well?

Mike Hommey· Jun 3, 2025, 22:37 UTC · re: Junio C Hamano · lore

Re: [PATCH] config.mak.dev: enable -Wunreachable-code

On Tue, Jun 03, 2025 at 03:07:36PM -0700, Junio C Hamano wrote:
Show 21 quoted lines
> Mike Hommey <mh@glandium.org> writes:
> 
> > There is a similar problem with this code in refs/files-backend.c:
> >
> > 			if (!create_ref_symlink(lock, update->new_target))
> > 				continue;
> >
> > Where create_ref_symlink is defined as such:
> >
> > #ifdef NO_SYMLINK_HEAD
> > #define create_ref_symlink(a, b) (-1)
> > #else
> > static int create_ref_symlink(struct ref_lock *lock, const char *target)
> > {
> > ...
> > #endif
> >
> > And NO_SYMLINK_HEAD is defined on Windows.
> 
> Would the NOT_CONSTANT() trick we ended up using for the original
> "sigfillset" thing solve your issue as well?
   if (NOT_CONSTANT(!create_ref_symlink(lock, update->new_target)))
indeed works around it.
Mike
Mike Hommey· Jun 3, 2025, 23:08 UTC · re: Mike Hommey · lore

Re: [PATCH] config.mak.dev: enable -Wunreachable-code

On Wed, Jun 04, 2025 at 07:37:50AM +0900, Mike Hommey wrote:
Show 26 quoted lines
> On Tue, Jun 03, 2025 at 03:07:36PM -0700, Junio C Hamano wrote:
> > Mike Hommey <mh@glandium.org> writes:
> > 
> > > There is a similar problem with this code in refs/files-backend.c:
> > >
> > > 			if (!create_ref_symlink(lock, update->new_target))
> > > 				continue;
> > >
> > > Where create_ref_symlink is defined as such:
> > >
> > > #ifdef NO_SYMLINK_HEAD
> > > #define create_ref_symlink(a, b) (-1)
> > > #else
> > > static int create_ref_symlink(struct ref_lock *lock, const char *target)
> > > {
> > > ...
> > > #endif
> > >
> > > And NO_SYMLINK_HEAD is defined on Windows.
> > 
> > Would the NOT_CONSTANT() trick we ended up using for the original
> > "sigfillset" thing solve your issue as well?
> 
>    if (NOT_CONSTANT(!create_ref_symlink(lock, update->new_target)))
> 
> indeed works around it.
I sent it as a patch along with other warning fixes.
Mike
Junio C Hamano· Mar 14, 2025, 21:09 UTC · re: Jeff King · lore

[PATCH v2 0/3] -Wunreachable-code

So here is a recap. The first one has meson.build change from Patrick squashed in, the second "errno" based one was what made me write the last one, and is kept as-is. The third one introduces NOT_A_CONST() marking to an expression to tell the compiler not to be overly aggressive to optimize it out.

Jeff King (2):
  config.mak.dev: enable -Wunreachable-code
  run-command: use errno to check for sigfillset() error
Junio C Hamano (1):
  git-compat-util: add NOT_A_CONST macro and use it in atfork_prepare()
 Makefile          | 1 +
 config.mak.dev    | 1 +
 git-compat-util.h | 9 +++++++++
 meson.build       | 2 ++
 run-command.c     | 8 +++++++-
 5 files changed, 20 insertions(+), 1 deletion(-)
-- 
2.49.0-188-g35fcca2323
Junio C Hamano· Mar 14, 2025, 21:09 UTC · re: Junio C Hamano · lore

[PATCH v2 1/3] config.mak.dev: enable -Wunreachable-code

From: Jeff King <peff@peff.net>

Having the compiler point out unreachable code can help avoid bugs, like the one discussed in:

  https://lore.kernel.org/git/20250307195057.GA3675279@coredump.intra.peff.net/

In that case it was found by Coverity, but finding it earlier saves everybody time and effort.

We can use -Wunreachable-code to get some help from the compiler here. Interestingly, this is a noop in gcc. It was a real warning up until gcc 4.x, when it was removed for being too flaky, but they left the command-line option to avoid breaking users. See:

  https://stackoverflow.com/questions/17249934/why-does-gcc-not-warn-for-unreachable-code

However, clang does implement this option, and it finds the case mentioned above (and no other cases within the code base). And since we run clang in several of our CI jobs, that's enough to get an early warning of breakage.

We could enable it only for clang, but since gcc is happy to ignore it, it's simpler to just turn it on for all developer builds.

Signed-off-by: Jeff King <peff@peff.net>
[jc: squashed meson.build change sent by Patrick]
Signed-off-by: Junio C Hamano <gitster@pobox.com>
---
 config.mak.dev | 1 +
 meson.build    | 1 +
 2 files changed, 2 insertions(+)
Show changes to 2 files +2 −0

config.mak.dev, meson.build

diff --git a/config.mak.dev b/config.mak.dev
index 0fd8cc4d35..95b7bc46ae 100644
--- a/config.mak.dev
+++ b/config.mak.dev
@@ -39,6 +39,7 @@ DEVELOPER_CFLAGS += -Wunused
 DEVELOPER_CFLAGS += -Wvla
 DEVELOPER_CFLAGS += -Wwrite-strings
 DEVELOPER_CFLAGS += -fno-common
+DEVELOPER_CFLAGS += -Wunreachable-code
 
 ifneq ($(filter clang4,$(COMPILER_FEATURES)),)
 DEVELOPER_CFLAGS += -Wtautological-constant-out-of-range-compare
diff --git a/meson.build b/meson.build
index 0064eb64f5..f60f3f49e4 100644
--- a/meson.build
+++ b/meson.build
@@ -697,6 +697,7 @@ if get_option('warning_level') in ['2','3', 'everything'] and compiler.get_argum
     '-Woverflow',
     '-Wpointer-arith',
     '-Wstrict-prototypes',
+    '-Wunreachable-code',
     '-Wunused',
     '-Wvla',
     '-Wwrite-strings',
-- 
2.49.0-188-g35fcca2323
Junio C Hamano· Mar 14, 2025, 21:09 UTC · re: Junio C Hamano · lore

[PATCH v2 2/3] run-command: use errno to check for sigfillset() error

From: Jeff King <peff@peff.net>

Since enabling -Wunreachable-code, builds with clang on macOS now fail, complaining that the die_errno() call in:

  if (sigfillset(&all))
	die_errno("sigfillset");

is unreachable. On that platform the manpage documents that sigfillset() always returns success, and presumably the implementation is a macro or inline function that does so in a way that is transparent to the compiler.

But we should continue to check on other platforms, since POSIX says it may return an error.

We could solve this with a compile-time knob to split the two cases (assuming success on macOS and checking for the error elsewhere). But we can also work around it more directly by relying on errno to check the outcome (since POSIX dictates that errno will be set on error). And that works around the compiler's cleverness, since it doesn't know the semantics of errno (though I suppose if sigfillset() is simple enough, it could perhaps realize that no writes to errno are possible; however this does seem to work in practice).

Signed-off-by: Jeff King <peff@peff.net>
Signed-off-by: Junio C Hamano <gitster@pobox.com>
---
 run-command.c | 10 +++++++++-
 1 file changed, 9 insertions(+), 1 deletion(-)
Show changes to run-command.c +9 −1
diff --git a/run-command.c b/run-command.c
index 402138b8b5..d527c46175 100644
--- a/run-command.c
+++ b/run-command.c
@@ -515,7 +515,15 @@ static void atfork_prepare(struct atfork_state *as)
 {
 	sigset_t all;
 
-	if (sigfillset(&all))
+	/*
+	 * Do not use the return value of sigfillset(). It is transparently 0
+	 * on some platforms, meaning a clever compiler may complain that
+	 * the conditional body is dead code. Instead, check for error via
+	 * errno, which outsmarts the compiler.
+	 */
+	errno = 0;
+	sigfillset(&all);
+	if (errno)
 		die_errno("sigfillset");
 #ifdef NO_PTHREADS
 	if (sigprocmask(SIG_SETMASK, &all, &as->old))
-- 
2.49.0-188-g35fcca2323
Taylor Blau· Mar 17, 2025, 21:30 UTC · re: Junio C Hamano · lore

Re: [PATCH v2 2/3] run-command: use errno to check for sigfillset() error

On Fri, Mar 14, 2025 at 02:09:08PM -0700, Junio C Hamano wrote:
Show 7 quoted lines
> From: Jeff King <peff@peff.net>
>
> Since enabling -Wunreachable-code, builds with clang on macOS now fail,
> complaining that the die_errno() call in:
>
>   if (sigfillset(&all))
> 	die_errno("sigfillset");

Hmm. Would it have made sense to swap the order of this and the first patch so we don't have a DEVELOPER=1 breakage (for macOS with Clang) in history?

I think it's too late now since this topic is already on 'next', but it occurred to me idly while reading this patch.

Thanks, Taylor

Junio C Hamano· Mar 17, 2025, 23:12 UTC · re: Taylor Blau · lore

Re: [PATCH v2 2/3] run-command: use errno to check for sigfillset() error

Taylor Blau <me@ttaylorr.com> writes:
Show 15 quoted lines
> On Fri, Mar 14, 2025 at 02:09:08PM -0700, Junio C Hamano wrote:
>> From: Jeff King <peff@peff.net>
>>
>> Since enabling -Wunreachable-code, builds with clang on macOS now fail,
>> complaining that the die_errno() call in:
>>
>>   if (sigfillset(&all))
>> 	die_errno("sigfillset");
>
> Hmm. Would it have made sense to swap the order of this and the first
> patch so we don't have a DEVELOPER=1 breakage (for macOS with Clang) in
> history?
>
> I think it's too late now since this topic is already on 'next', but it
> occurred to me idly while reading this patch.

I thought db1d1f5d (config.mak.dev: enable -Wunreachable-code, 2025-03-14) aka jk/use-wunreachable-code-for-devs~2 is still out of 'next'?

Junio C Hamano· Mar 18, 2025, 00:36 UTC · re: Junio C Hamano · lore

Re: [PATCH v2 2/3] run-command: use errno to check for sigfillset() error

Junio C Hamano <gitster@pobox.com> writes:
Show 21 quoted lines
> Taylor Blau <me@ttaylorr.com> writes:
>
>> On Fri, Mar 14, 2025 at 02:09:08PM -0700, Junio C Hamano wrote:
>>> From: Jeff King <peff@peff.net>
>>>
>>> Since enabling -Wunreachable-code, builds with clang on macOS now fail,
>>> complaining that the die_errno() call in:
>>>
>>>   if (sigfillset(&all))
>>> 	die_errno("sigfillset");
>>
>> Hmm. Would it have made sense to swap the order of this and the first
>> patch so we don't have a DEVELOPER=1 breakage (for macOS with Clang) in
>> history?
>>
>> I think it's too late now since this topic is already on 'next', but it
>> occurred to me idly while reading this patch.
>
> I thought db1d1f5d (config.mak.dev: enable -Wunreachable-code,
> 2025-03-14) aka jk/use-wunreachable-code-for-devs~2 is still out of
> 'next'?

Ah, I did revert an earlier one-commit topic out of 'next'. Perhaps I didn't tell What's cooking about it.

Junio C Hamano· Mar 14, 2025, 21:09 UTC · re: Junio C Hamano · lore

[PATCH v2 3/3] git-compat-util: add NOT_A_CONST macro and use it in atfork_prepare()

Our hope is that the number of code paths that falsely trigger warnings with the -Wunreachable-code compilation option are small, and they can be worked around case-by-case basis, like we just did in the previous commit. If we need such a workaround a bit more often, however, we may benefit from a more generic and descriptive facility that helps document the cases we need such workarounds.

    Side note: if we need the workaround all over the place, it
    simply means -Wunreachable-code is not a good tool for us to
    save engineering effort to catch mistakes.  We are still
    exploring if it helps us, so let's assume that it is not the
    case.

Introduce NOT_A_CONST() macro, with which, the developer can tell the compiler:

    Do not optimize this expression out, because, despite whatever
    you are told by the system headers, this expression should *not*
    be treated as a constant.

and use it as a replacement for the workaround we used that was somewhat specific to the sigfillset case. If the compiler already knows that the call to sigfillset() cannot fail on a particular platform it is compiling for and declares that the if() condition would not hold, it is plausible that the next version of the compiler may learn that sigfillset() that never fails would not touch errno and decide that in this sequence:

	errno = 0;
	sigfillset(&all)
	if (errno)
		die_errno("sigfillset");

the if() statement will never trigger. Marking that the value returned by sigfillset() cannot be a constant would document our intention better and would not break with such a new version of compiler that is even more "clever". With the marco, the above sequence can be rewritten:

	if (NOT_A_CONST(sigfillset(&all)))
		die_errno("sigfillset");

which looks almost like other innocuous annotations we have, e.g. UNUSED.

Signed-off-by: Junio C Hamano <gitster@pobox.com>
---
 Makefile          |  1 +
 git-compat-util.h |  9 +++++++++
 meson.build       |  1 +
 run-command.c     | 12 +++++-------
 4 files changed, 16 insertions(+), 7 deletions(-)
Show changes to 4 files +16 −7

Makefile, git-compat-util.h, meson.build, run-command.c

diff --git a/Makefile b/Makefile
index 97e8385b66..2158bf6916 100644
--- a/Makefile
+++ b/Makefile
@@ -1018,6 +1018,7 @@ LIB_OBJS += ewah/ewah_bitmap.o
 LIB_OBJS += ewah/ewah_io.o
 LIB_OBJS += ewah/ewah_rlw.o
 LIB_OBJS += exec-cmd.o
+LIB_OBJS += fbtcdnki.o
 LIB_OBJS += fetch-negotiator.o
 LIB_OBJS += fetch-pack.o
 LIB_OBJS += fmt-merge-msg.o
diff --git a/git-compat-util.h b/git-compat-util.h
index e283c46c6f..63a3ef6b70 100644
--- a/git-compat-util.h
+++ b/git-compat-util.h
@@ -1593,4 +1593,13 @@ static inline void *container_of_or_null_offset(void *ptr, size_t offset)
 	((uintptr_t)&(ptr)->member - (uintptr_t)(ptr))
 #endif /* !__GNUC__ */
 
+/*
+ * Prevent an overly clever compiler from optimizing an expression
+ * out, triggering a false positive when building with the
+ * -Wunreachable-code option. false_but_the_compiler_does_not_know_it_
+ * is defined in a compilation unit separate from where the macro is
+ * used, initialized to 0, and never modified.
+ */
+#define NOT_A_CONST(expr) ((expr) || false_but_the_compiler_does_not_know_it_)
+extern int false_but_the_compiler_does_not_know_it_;
 #endif
diff --git a/meson.build b/meson.build
index f60f3f49e4..ce642dcf65 100644
--- a/meson.build
+++ b/meson.build
@@ -282,6 +282,7 @@ libgit_sources = [
   'ewah/ewah_io.c',
   'ewah/ewah_rlw.c',
   'exec-cmd.c',
+  'fbtcdnki.c',
   'fetch-negotiator.c',
   'fetch-pack.c',
   'fmt-merge-msg.c',
diff --git a/run-command.c b/run-command.c
index d527c46175..535c73a059 100644
--- a/run-command.c
+++ b/run-command.c
@@ -516,14 +516,12 @@ static void atfork_prepare(struct atfork_state *as)
 	sigset_t all;
 
 	/*
-	 * Do not use the return value of sigfillset(). It is transparently 0
-	 * on some platforms, meaning a clever compiler may complain that
-	 * the conditional body is dead code. Instead, check for error via
-	 * errno, which outsmarts the compiler.
+	 * POSIX says sitfillset() can fail, but an overly clever
+	 * compiler can see through the header files and decide
+	 * it cannot fail on a particular platform it is compiling for,
+	 * triggering -Wunreachable-code false positive.
 	 */
-	errno = 0;
-	sigfillset(&all);
-	if (errno)
+	if (NOT_A_CONST(sigfillset(&all)))
 		die_errno("sigfillset");
 #ifdef NO_PTHREADS
 	if (sigprocmask(SIG_SETMASK, &all, &as->old))
-- 
2.49.0-188-g35fcca2323
Junio C Hamano· Mar 14, 2025, 22:29 UTC · re: Junio C Hamano · lore

Re: [PATCH v2 3/3] git-compat-util: add NOT_A_CONST macro and use it in atfork_prepare()

Sorry, one new file was left out of the patch. Here is a quick fix (I am not rerolling the earlier 2 steps).

---- >8 ---- Our hope is that the number of code paths that falsely trigger warnings with the -Wunreachable-code compilation option are small, and they can be worked around case-by-case basis, like we just did in the previous commit. If we need such a workaround a bit more often, however, we may benefit from a more generic and descriptive facility that helps document the cases we need such workarounds.

    Side note: if we need the workaround all over the place, it
    simply means -Wunreachable-code is not a good tool for us to
    save engineering effort to catch mistakes.  We are still
    exploring if it helps us, so let's assume that it is not the
    case.

Introduce NOT_A_CONST() macro, with which, the developer can tell the compiler:

    Do not optimize this expression out, because, despite whatever
    you are told by the system headers, this expression should *not*
    be treated as a constant.

and use it as a replacement for the workaround we used that was somewhat specific to the sigfillset case. If the compiler already knows that the call to sigfillset() cannot fail on a particular platform it is compiling for and declares that the if() condition would not hold, it is plausible that the next version of the compiler may learn that sigfillset() that never fails would not touch errno and decide that in this sequence:

	errno = 0;
	sigfillset(&all)
	if (errno)
		die_errno("sigfillset");

the if() statement will never trigger. Marking that the value returned by sigfillset() cannot be a constant would document our intention better and would not break with such a new version of compiler that is even more "clever". With the marco, the above sequence can be rewritten:

	if (NOT_A_CONST(sigfillset(&all)))
		die_errno("sigfillset");

which looks almost like other innocuous annotations we have, e.g. UNUSED.

Signed-off-by: Junio C Hamano <gitster@pobox.com>
---
 Makefile          |  1 +
 fbtcdnki.c        |  2 ++
 git-compat-util.h |  9 +++++++++
 meson.build       |  1 +
 run-command.c     | 12 +++++-------
 5 files changed, 18 insertions(+), 7 deletions(-)
 create mode 100644 fbtcdnki.c
Show changes to 5 files +18 −7

Makefile, fbtcdnki.c, git-compat-util.h, meson.build, run-command.c

diff --git a/Makefile b/Makefile
index 97e8385b66..2158bf6916 100644
--- a/Makefile
+++ b/Makefile
@@ -1018,6 +1018,7 @@ LIB_OBJS += ewah/ewah_bitmap.o
 LIB_OBJS += ewah/ewah_io.o
 LIB_OBJS += ewah/ewah_rlw.o
 LIB_OBJS += exec-cmd.o
+LIB_OBJS += fbtcdnki.o
 LIB_OBJS += fetch-negotiator.o
 LIB_OBJS += fetch-pack.o
 LIB_OBJS += fmt-merge-msg.o
diff --git a/fbtcdnki.c b/fbtcdnki.c
new file mode 100644
index 0000000000..1da3ffc2f5
--- /dev/null
+++ b/fbtcdnki.c
@@ -0,0 +1,2 @@
+#include <git-compat-util.h>
+int false_but_the_compiler_does_not_know_it_;
diff --git a/git-compat-util.h b/git-compat-util.h
index e283c46c6f..63a3ef6b70 100644
--- a/git-compat-util.h
+++ b/git-compat-util.h
@@ -1593,4 +1593,13 @@ static inline void *container_of_or_null_offset(void *ptr, size_t offset)
 	((uintptr_t)&(ptr)->member - (uintptr_t)(ptr))
 #endif /* !__GNUC__ */
 
+/*
+ * Prevent an overly clever compiler from optimizing an expression
+ * out, triggering a false positive when building with the
+ * -Wunreachable-code option. false_but_the_compiler_does_not_know_it_
+ * is defined in a compilation unit separate from where the macro is
+ * used, initialized to 0, and never modified.
+ */
+#define NOT_A_CONST(expr) ((expr) || false_but_the_compiler_does_not_know_it_)
+extern int false_but_the_compiler_does_not_know_it_;
 #endif
diff --git a/meson.build b/meson.build
index f60f3f49e4..ce642dcf65 100644
--- a/meson.build
+++ b/meson.build
@@ -282,6 +282,7 @@ libgit_sources = [
   'ewah/ewah_io.c',
   'ewah/ewah_rlw.c',
   'exec-cmd.c',
+  'fbtcdnki.c',
   'fetch-negotiator.c',
   'fetch-pack.c',
   'fmt-merge-msg.c',
diff --git a/run-command.c b/run-command.c
index d527c46175..535c73a059 100644
--- a/run-command.c
+++ b/run-command.c
@@ -516,14 +516,12 @@ static void atfork_prepare(struct atfork_state *as)
 	sigset_t all;
 
 	/*
-	 * Do not use the return value of sigfillset(). It is transparently 0
-	 * on some platforms, meaning a clever compiler may complain that
-	 * the conditional body is dead code. Instead, check for error via
-	 * errno, which outsmarts the compiler.
+	 * POSIX says sitfillset() can fail, but an overly clever
+	 * compiler can see through the header files and decide
+	 * it cannot fail on a particular platform it is compiling for,
+	 * triggering -Wunreachable-code false positive.
 	 */
-	errno = 0;
-	sigfillset(&all);
-	if (errno)
+	if (NOT_A_CONST(sigfillset(&all)))
 		die_errno("sigfillset");
 #ifdef NO_PTHREADS
 	if (sigprocmask(SIG_SETMASK, &all, &as->old))
-- 
2.49.0-188-g35fcca2323
Jeff King· Mar 17, 2025, 18:00 UTC · re: Junio C Hamano · lore

Re: [PATCH v2 3/3] git-compat-util: add NOT_A_CONST macro and use it in atfork_prepare()

On Fri, Mar 14, 2025 at 03:29:54PM -0700, Junio C Hamano wrote:
Show 13 quoted lines
> ---- >8 ----
> Our hope is that the number of code paths that falsely trigger
> warnings with the -Wunreachable-code compilation option are small,
> and they can be worked around case-by-case basis, like we just did
> in the previous commit.  If we need such a workaround a bit more
> often, however, we may benefit from a more generic and descriptive
> facility that helps document the cases we need such workarounds.
> 
>     Side note: if we need the workaround all over the place, it
>     simply means -Wunreachable-code is not a good tool for us to
>     save engineering effort to catch mistakes.  We are still
>     exploring if it helps us, so let's assume that it is not the
>     case.

Yup, I very much agree with this, especially the side note. (I'd probably have just dropped patch 2 and gone straight here, but I don't mind leaving it in as documentation of that other direction).

Show 6 quoted lines
> Introduce NOT_A_CONST() macro, with which, the developer can tell
> the compiler:
> 
>     Do not optimize this expression out, because, despite whatever
>     you are told by the system headers, this expression should *not*
>     be treated as a constant.

This is definitely better than the other name. I might spell it out as "NOT_A_CONSTANT", just because "const" to me is a variable annotation (for something that _could_ change, but we are not allowed to). Whereas "constant" is something defined to a single value in the program. Maybe splitting hairs, but as somebody who read NOT_A_CONST(foo) I might expect it to be casting away "const" or something.

Show 7 quoted lines
> --- a/Makefile
> +++ b/Makefile
> @@ -1018,6 +1018,7 @@ LIB_OBJS += ewah/ewah_bitmap.o
>  LIB_OBJS += ewah/ewah_io.o
>  LIB_OBJS += ewah/ewah_rlw.o
>  LIB_OBJS += exec-cmd.o
> +LIB_OBJS += fbtcdnki.o

That name is a mouthful, for sure. The long name is really an implementation detail. Would calling it not-constant.c or something be more descriptive? (Yes, the macro itself does not appear in the file, but hopefully it links the two semantically in the reader's head).

I almost want to suggest a name like "compiler-tricks.c", but part of the point of this particular trick is that there's nothing else in its translation unit. So later when somebody adds another trick, it cannot use this macro. ;)

Show 9 quoted lines
> +/*
> + * Prevent an overly clever compiler from optimizing an expression
> + * out, triggering a false positive when building with the
> + * -Wunreachable-code option. false_but_the_compiler_does_not_know_it_
> + * is defined in a compilation unit separate from where the macro is
> + * used, initialized to 0, and never modified.
> + */
> +#define NOT_A_CONST(expr) ((expr) || false_but_the_compiler_does_not_know_it_)
> +extern int false_but_the_compiler_does_not_know_it_;

Good explanation. I do wonder if we'd eventually see a compiler that reaches across translation units to optimize, but I'd hope we probably bought ourselves a decade or two.

Show 22 quoted lines
> diff --git a/run-command.c b/run-command.c
> index d527c46175..535c73a059 100644
> --- a/run-command.c
> +++ b/run-command.c
> @@ -516,14 +516,12 @@ static void atfork_prepare(struct atfork_state *as)
>  	sigset_t all;
>  
>  	/*
> -	 * Do not use the return value of sigfillset(). It is transparently 0
> -	 * on some platforms, meaning a clever compiler may complain that
> -	 * the conditional body is dead code. Instead, check for error via
> -	 * errno, which outsmarts the compiler.
> +	 * POSIX says sitfillset() can fail, but an overly clever
> +	 * compiler can see through the header files and decide
> +	 * it cannot fail on a particular platform it is compiling for,
> +	 * triggering -Wunreachable-code false positive.
>  	 */
> -	errno = 0;
> -	sigfillset(&all);
> -	if (errno)
> +	if (NOT_A_CONST(sigfillset(&all)))
>  		die_errno("sigfillset");

And this looks much nicer and more descriptive. You could probably even get away without the comment, but I certainly do not mind it.

s/sitfillset/sigfillset/ in your comment text, though.
-Peff
Junio C Hamano· Mar 17, 2025, 23:53 UTC · re: Junio C Hamano · lore

[PATCH v3 0/3] -Wunreachable-code

As Taylor noticed, we can still help macOS users by first dealing with the false positive in the code, and then flip the warning option for developers on.

 [1/3] run-command: use errno to check for sigfillset() error
 This was our first "workaround" that is very specific to the code
 that gets falsely flagged by the compiler.
 [2/3] git-compat-util: add NOT_CONSTANT macro and use it in atfork_prepare()
 This adds a more generic way to work around a false positive from
 -Wunreachable-code to prevent compilers from optimize away
 expressions that are used in conditionals, and rewrite the earlier
 workaround with it.
 [3/3] config.mak.dev: enable -Wunreachable-code
 Now we worked around known false positive of -Wunreachable-code,
 we force it upon our developers, including macOS ones.

This is totally offtopic, but I often find the short-log (list of commits, grouped by author) in the cover letter very awkward to work with. Between v2 and v3, aside from the NOT_CONSTANT() improvements in the patch [2/3] that used to be [3/3], one large change is the reordering of the patches but that is not seen in the shortlog (I ran "git log --oneline -reverse" to prepare the list of commits in the order they are applied to describe them in the above list).

Jeff King (2):
  run-command: use errno to check for sigfillset() error
  config.mak.dev: enable -Wunreachable-code
Junio C Hamano (1):
  git-compat-util: add NOT_CONSTANT macro and use it in atfork_prepare()
 Makefile                         | 1 +
 compiler-tricks/not-a-constant.c | 2 ++
 config.mak.dev                   | 1 +
 git-compat-util.h                | 9 +++++++++
 meson.build                      | 2 ++
 run-command.c                    | 8 +++++++-
 6 files changed, 22 insertions(+), 1 deletion(-)
 create mode 100644 compiler-tricks/not-a-constant.c
-- 
2.49.0-207-gc8924421c3
Junio C Hamano· Mar 17, 2025, 23:53 UTC · re: Junio C Hamano · lore

[PATCH v3 1/3] run-command: use errno to check for sigfillset() error

From: Jeff King <peff@peff.net>

Since enabling -Wunreachable-code, builds with clang on macOS now fail, complaining that the die_errno() call in:

  if (sigfillset(&all))
	die_errno("sigfillset");

is unreachable. On that platform the manpage documents that sigfillset() always returns success, and presumably the implementation is a macro or inline function that does so in a way that is transparent to the compiler.

But we should continue to check on other platforms, since POSIX says it may return an error.

We could solve this with a compile-time knob to split the two cases (assuming success on macOS and checking for the error elsewhere). But we can also work around it more directly by relying on errno to check the outcome (since POSIX dictates that errno will be set on error). And that works around the compiler's cleverness, since it doesn't know the semantics of errno (though I suppose if sigfillset() is simple enough, it could perhaps realize that no writes to errno are possible; however this does seem to work in practice).

Signed-off-by: Jeff King <peff@peff.net>
Signed-off-by: Junio C Hamano <gitster@pobox.com>
---
 run-command.c | 10 +++++++++-
 1 file changed, 9 insertions(+), 1 deletion(-)
Show changes to run-command.c +9 −1
diff --git a/run-command.c b/run-command.c
index 402138b8b5..d527c46175 100644
--- a/run-command.c
+++ b/run-command.c
@@ -515,7 +515,15 @@ static void atfork_prepare(struct atfork_state *as)
 {
 	sigset_t all;
 
-	if (sigfillset(&all))
+	/*
+	 * Do not use the return value of sigfillset(). It is transparently 0
+	 * on some platforms, meaning a clever compiler may complain that
+	 * the conditional body is dead code. Instead, check for error via
+	 * errno, which outsmarts the compiler.
+	 */
+	errno = 0;
+	sigfillset(&all);
+	if (errno)
 		die_errno("sigfillset");
 #ifdef NO_PTHREADS
 	if (sigprocmask(SIG_SETMASK, &all, &as->old))
-- 
2.49.0-207-gc8924421c3
Junio C Hamano· Mar 17, 2025, 23:53 UTC · re: Junio C Hamano · lore

[PATCH v3 2/3] git-compat-util: add NOT_CONSTANT macro and use it in atfork_prepare()

Our hope is that the number of code paths that falsely trigger warnings with the -Wunreachable-code compilation option are small, and they can be worked around case-by-case basis, like we just did in the previous commit. If we need such a workaround a bit more often, however, we may benefit from a more generic and descriptive facility that helps document the cases we need such workarounds.

    Side note: if we need the workaround all over the place, it
    simply means -Wunreachable-code is not a good tool for us to
    save engineering effort to catch mistakes.  We are still
    exploring if it helps us, so let's assume that it is not the
    case.

Introduce NOT_CONSTANT() macro, with which, the developer can tell the compiler:

    Do not optimize this expression out, because, despite whatever
    you are told by the system headers, this expression should *not*
    be treated as a constant.

and use it as a replacement for the workaround we used that was somewhat specific to the sigfillset case. If the compiler already knows that the call to sigfillset() cannot fail on a particular platform it is compiling for and declares that the if() condition would not hold, it is plausible that the next version of the compiler may learn that sigfillset() that never fails would not touch errno and decide that in this sequence:

	errno = 0;
	sigfillset(&all)
	if (errno)
		die_errno("sigfillset");

the if() statement will never trigger. Marking that the value returned by sigfillset() cannot be a constant would document our intention better and would not break with such a new version of compiler that is even more "clever". With the marco, the above sequence can be rewritten:

	if (NOT_CONSTANT(sigfillset(&all)))
		die_errno("sigfillset");

which looks almost like other innocuous annotations we have, e.g. UNUSED.

Signed-off-by: Junio C Hamano <gitster@pobox.com>
---
 Makefile                         |  1 +
 compiler-tricks/not-a-constant.c |  2 ++
 git-compat-util.h                |  9 +++++++++
 meson.build                      |  1 +
 run-command.c                    | 12 +++++-------
 5 files changed, 18 insertions(+), 7 deletions(-)
 create mode 100644 compiler-tricks/not-a-constant.c
Show changes to 5 files +18 −7

Makefile, compiler-tricks/not-a-constant.c, git-compat-util.h, meson.build, run-command.c

diff --git a/Makefile b/Makefile
index 97e8385b66..605e2d7f61 100644
--- a/Makefile
+++ b/Makefile
@@ -985,6 +985,7 @@ LIB_OBJS += compat/nonblock.o
 LIB_OBJS += compat/obstack.o
 LIB_OBJS += compat/terminal.o
 LIB_OBJS += compat/zlib-uncompress2.o
+LIB_OBJS += compiler-tricks/not-a-constant.o
 LIB_OBJS += config.o
 LIB_OBJS += connect.o
 LIB_OBJS += connected.o
diff --git a/compiler-tricks/not-a-constant.c b/compiler-tricks/not-a-constant.c
new file mode 100644
index 0000000000..1da3ffc2f5
--- /dev/null
+++ b/compiler-tricks/not-a-constant.c
@@ -0,0 +1,2 @@
+#include <git-compat-util.h>
+int false_but_the_compiler_does_not_know_it_;
diff --git a/git-compat-util.h b/git-compat-util.h
index e283c46c6f..f6a149827b 100644
--- a/git-compat-util.h
+++ b/git-compat-util.h
@@ -1593,4 +1593,13 @@ static inline void *container_of_or_null_offset(void *ptr, size_t offset)
 	((uintptr_t)&(ptr)->member - (uintptr_t)(ptr))
 #endif /* !__GNUC__ */
 
+/*
+ * Prevent an overly clever compiler from optimizing an expression
+ * out, triggering a false positive when building with the
+ * -Wunreachable-code option. false_but_the_compiler_does_not_know_it_
+ * is defined in a compilation unit separate from where the macro is
+ * used, initialized to 0, and never modified.
+ */
+#define NOT_CONSTANT(expr) ((expr) || false_but_the_compiler_does_not_know_it_)
+extern int false_but_the_compiler_does_not_know_it_;
 #endif
diff --git a/meson.build b/meson.build
index 0064eb64f5..373524dad2 100644
--- a/meson.build
+++ b/meson.build
@@ -249,6 +249,7 @@ libgit_sources = [
   'compat/obstack.c',
   'compat/terminal.c',
   'compat/zlib-uncompress2.c',
+  'compiler-tricks/not-a-constant.c',
   'config.c',
   'connect.c',
   'connected.c',
diff --git a/run-command.c b/run-command.c
index d527c46175..b74fd08056 100644
--- a/run-command.c
+++ b/run-command.c
@@ -516,14 +516,12 @@ static void atfork_prepare(struct atfork_state *as)
 	sigset_t all;
 
 	/*
-	 * Do not use the return value of sigfillset(). It is transparently 0
-	 * on some platforms, meaning a clever compiler may complain that
-	 * the conditional body is dead code. Instead, check for error via
-	 * errno, which outsmarts the compiler.
+	 * POSIX says sigfillset() can fail, but an overly clever
+	 * compiler can see through the header files and decide
+	 * it cannot fail on a particular platform it is compiling for,
+	 * triggering -Wunreachable-code false positive.
 	 */
-	errno = 0;
-	sigfillset(&all);
-	if (errno)
+	if (NOT_CONSTANT(sigfillset(&all)))
 		die_errno("sigfillset");
 #ifdef NO_PTHREADS
 	if (sigprocmask(SIG_SETMASK, &all, &as->old))
-- 
2.49.0-207-gc8924421c3
Jeff King· Mar 18, 2025, 00:20 UTC · re: Junio C Hamano · lore

Re: [PATCH v3 2/3] git-compat-util: add NOT_CONSTANT macro and use it in atfork_prepare()

On Mon, Mar 17, 2025 at 04:53:28PM -0700, Junio C Hamano wrote:
> Introduce NOT_CONSTANT() macro, with which, the developer can tell
> the compiler:
This name looks great to me.
>  compiler-tricks/not-a-constant.c |  2 ++

And this is much better, too. ;) I see you dropped the "a" in the macro name; I don't know if it matters much to do it here, too.

-Peff
Junio C Hamano· Mar 18, 2025, 00:28 UTC · re: Jeff King · lore

Re: [PATCH v3 2/3] git-compat-util: add NOT_CONSTANT macro and use it in atfork_prepare()

Jeff King <peff@peff.net> writes:
Show 11 quoted lines
> On Mon, Mar 17, 2025 at 04:53:28PM -0700, Junio C Hamano wrote:
>
>> Introduce NOT_CONSTANT() macro, with which, the developer can tell
>> the compiler:
>
> This name looks great to me.
>
>>  compiler-tricks/not-a-constant.c |  2 ++
>
> And this is much better, too. ;) I see you dropped the "a" in the macro
> name; I don't know if it matters much to do it here, too.
Good eyes.
Calvin Wan· Mar 18, 2025, 22:04 UTC · re: Junio C Hamano · lore

Re: [PATCH v3 2/3] git-compat-util: add NOT_CONSTANT macro and use it in atfork_prepare()

Junio C Hamano <gitster@pobox.com> writes:
Show 64 quoted lines
> Our hope is that the number of code paths that falsely trigger
> warnings with the -Wunreachable-code compilation option are small,
> and they can be worked around case-by-case basis, like we just did
> in the previous commit.  If we need such a workaround a bit more
> often, however, we may benefit from a more generic and descriptive
> facility that helps document the cases we need such workarounds.
> 
>     Side note: if we need the workaround all over the place, it
>     simply means -Wunreachable-code is not a good tool for us to
>     save engineering effort to catch mistakes.  We are still
>     exploring if it helps us, so let's assume that it is not the
>     case.
> 
> Introduce NOT_CONSTANT() macro, with which, the developer can tell
> the compiler:
> 
>     Do not optimize this expression out, because, despite whatever
>     you are told by the system headers, this expression should *not*
>     be treated as a constant.
> 
> and use it as a replacement for the workaround we used that was
> somewhat specific to the sigfillset case.  If the compiler already
> knows that the call to sigfillset() cannot fail on a particular
> platform it is compiling for and declares that the if() condition
> would not hold, it is plausible that the next version of the
> compiler may learn that sigfillset() that never fails would not
> touch errno and decide that in this sequence:
> 
> 	errno = 0;
> 	sigfillset(&all)
> 	if (errno)
> 		die_errno("sigfillset");
> 
> the if() statement will never trigger.  Marking that the value
> returned by sigfillset() cannot be a constant would document our
> intention better and would not break with such a new version of
> compiler that is even more "clever".  With the marco, the above
> sequence can be rewritten:
> 
> 	if (NOT_CONSTANT(sigfillset(&all)))
> 		die_errno("sigfillset");
> 
> which looks almost like other innocuous annotations we have,
> e.g. UNUSED.
> 
> Signed-off-by: Junio C Hamano <gitster@pobox.com>
> ---
>  Makefile                         |  1 +
>  compiler-tricks/not-a-constant.c |  2 ++
>  git-compat-util.h                |  9 +++++++++
>  meson.build                      |  1 +
>  run-command.c                    | 12 +++++-------
>  5 files changed, 18 insertions(+), 7 deletions(-)
>  create mode 100644 compiler-tricks/not-a-constant.c
> 
> diff --git a/Makefile b/Makefile
> index 97e8385b66..605e2d7f61 100644
> --- a/Makefile
> +++ b/Makefile
> @@ -985,6 +985,7 @@ LIB_OBJS += compat/nonblock.o
>  LIB_OBJS += compat/obstack.o
>  LIB_OBJS += compat/terminal.o
>  LIB_OBJS += compat/zlib-uncompress2.o
> +LIB_OBJS += compiler-tricks/not-a-constant.o

The name is correctly added here, but in `next,` this name is set to `compiler-tricks/not-constant.o`.

Calvin Wan· Mar 18, 2025, 22:26 UTC · re: Calvin Wan · lore

Re: [PATCH v3 2/3] git-compat-util: add NOT_CONSTANT macro and use it in atfork_prepare()

On Tue, Mar 18, 2025 at 3:05 PM Calvin Wan <calvinwan@google.com> wrote:
Show 11 quoted lines
>
> Junio C Hamano <gitster@pobox.com> writes:
> > Our hope is that the number of code paths that falsely trigger
> > @@ -985,6 +985,7 @@ LIB_OBJS += compat/nonblock.o
> >  LIB_OBJS += compat/obstack.o
> >  LIB_OBJS += compat/terminal.o
> >  LIB_OBJS += compat/zlib-uncompress2.o
> > +LIB_OBJS += compiler-tricks/not-a-constant.o
>
> The name is correctly added here, but in `next,` this name is set to
> `compiler-tricks/not-constant.o`.

Apologies you can ignore this -- we needed to add a reference to the new folder internally so this was a red herring for our broken build.

Junio C Hamano· Mar 18, 2025, 23:55 UTC · re: Calvin Wan · lore

Re: [PATCH v3 2/3] git-compat-util: add NOT_CONSTANT macro and use it in atfork_prepare()

Calvin Wan <calvinwan@google.com> writes:
Show 15 quoted lines
> On Tue, Mar 18, 2025 at 3:05 PM Calvin Wan <calvinwan@google.com> wrote:
>>
>> Junio C Hamano <gitster@pobox.com> writes:
>> > Our hope is that the number of code paths that falsely trigger
>> > @@ -985,6 +985,7 @@ LIB_OBJS += compat/nonblock.o
>> >  LIB_OBJS += compat/obstack.o
>> >  LIB_OBJS += compat/terminal.o
>> >  LIB_OBJS += compat/zlib-uncompress2.o
>> > +LIB_OBJS += compiler-tricks/not-a-constant.o
>>
>> The name is correctly added here, but in `next,` this name is set to
>> `compiler-tricks/not-constant.o`.
>
> Apologies you can ignore this -- we needed to add a reference to the new folder
> internally so this was a red herring for our broken build.

Sorry, I may not have sent a reroll to the list for the version that went into 'next'. It should have lost "a" from not-constant consistently everywhere.

Thanks for being eagle-eyed.
Junio C Hamano· Mar 17, 2025, 23:53 UTC · re: Junio C Hamano · lore

[PATCH v3 3/3] config.mak.dev: enable -Wunreachable-code

From: Jeff King <peff@peff.net>

Having the compiler point out unreachable code can help avoid bugs, like the one discussed in:

  https://lore.kernel.org/git/20250307195057.GA3675279@coredump.intra.peff.net/

In that case it was found by Coverity, but finding it earlier saves everybody time and effort.

We can use -Wunreachable-code to get some help from the compiler here. Interestingly, this is a noop in gcc. It was a real warning up until gcc 4.x, when it was removed for being too flaky, but they left the command-line option to avoid breaking users. See:

  https://stackoverflow.com/questions/17249934/why-does-gcc-not-warn-for-unreachable-code

However, clang does implement this option, and it finds the case mentioned above (and no other cases within the code base). And since we run clang in several of our CI jobs, that's enough to get an early warning of breakage.

We could enable it only for clang, but since gcc is happy to ignore it, it's simpler to just turn it on for all developer builds.

Signed-off-by: Jeff King <peff@peff.net>
[jc: squashed meson.build change sent by Patrick]
Signed-off-by: Junio C Hamano <gitster@pobox.com>
---
 config.mak.dev | 1 +
 meson.build    | 1 +
 2 files changed, 2 insertions(+)
Show changes to 2 files +2 −0

config.mak.dev, meson.build

diff --git a/config.mak.dev b/config.mak.dev
index 0fd8cc4d35..95b7bc46ae 100644
--- a/config.mak.dev
+++ b/config.mak.dev
@@ -39,6 +39,7 @@ DEVELOPER_CFLAGS += -Wunused
 DEVELOPER_CFLAGS += -Wvla
 DEVELOPER_CFLAGS += -Wwrite-strings
 DEVELOPER_CFLAGS += -fno-common
+DEVELOPER_CFLAGS += -Wunreachable-code
 
 ifneq ($(filter clang4,$(COMPILER_FEATURES)),)
 DEVELOPER_CFLAGS += -Wtautological-constant-out-of-range-compare
diff --git a/meson.build b/meson.build
index 373524dad2..fdccc59945 100644
--- a/meson.build
+++ b/meson.build
@@ -698,6 +698,7 @@ if get_option('warning_level') in ['2','3', 'everything'] and compiler.get_argum
     '-Woverflow',
     '-Wpointer-arith',
     '-Wstrict-prototypes',
+    '-Wunreachable-code',
     '-Wunused',
     '-Wvla',
     '-Wwrite-strings',
-- 
2.49.0-207-gc8924421c3
Jeff King· Mar 18, 2025, 00:18 UTC · re: Junio C Hamano · lore

Re: [PATCH v3 0/3] -Wunreachable-code

On Mon, Mar 17, 2025 at 04:53:26PM -0700, Junio C Hamano wrote:
> As Taylor noticed, we can still help macOS users by first dealing
> with the false positive in the code, and then flip the warning
> option for developers on.
Yeah, this is worth doing.
Show 14 quoted lines
> This is totally offtopic, but I often find the short-log (list of
> commits, grouped by author) in the cover letter very awkward to work
> with.  Between v2 and v3, aside from the NOT_CONSTANT() improvements
> in the patch [2/3] that used to be [3/3], one large change is the
> reordering of the patches but that is not seen in the shortlog (I
> ran "git log --oneline -reverse" to prepare the list of commits in
> the order they are applied to describe them in the above list).
> 
> Jeff King (2):
>   run-command: use errno to check for sigfillset() error
>   config.mak.dev: enable -Wunreachable-code
> 
> Junio C Hamano (1):
>   git-compat-util: add NOT_CONSTANT macro and use it in atfork_prepare()

The re-ordering does appear in the range-diff, if you provide one. But I agree that the organized-by-name shortlog does not make much sense for most series. As a reviewer, I care most about the patches, not the authors.

I make my cover letters with something like this (part of a larger script):

    git format-patch --stdout origin..$topic |
    perl -lne '
      if (/^Subject: (.*)/) {
        $subject = $1;
      }
      elsif ($subject && /^\s+(.*)/) {
        $subject .= " $1";
      }
      elsif ($subject) {
        print $subject;
        $subject = undef;
      }
    ' |
    sed -e 's/\[PATCH /[/' \
        -e 's/]/]:/' \
        -e 's/^/  /'
which yields something like (for the older version of this series):
  [1/3]: config.mak.dev: enable -Wunreachable-code
  [2/3]: run-command: use errno to check for sigfillset() error
  [3/3]: git-compat-util: add NOT_A_CONST macro and use it in atfork_prepare()

Having the correct order and the matching numbering next to each one makes it much easier if you're going to comment on them inline.

The perl in the script above is required to handle rfc822 wrapping / line continuation. I never bothered to implement rfc2047 unquoting. I don't tend to use non-ascii chars in my subject lines. ;)

It would be nice if we had a format-patch option to avoid quoting and wrapping in order to make text processing like this easier.

-Peff
Karthik Nayak· Mar 7, 2025, 21:02 UTC · re: Jeff King · lore

Re: [PATCH v3 6/8] refs: implement partial reference transaction support

Jeff King <peff@peff.net> writes:
Show 26 quoted lines
> On Wed, Mar 05, 2025 at 06:39:01PM +0100, Karthik Nayak wrote:
>
>> @@ -1456,6 +1471,13 @@ static enum ref_transaction_error write_with_updates(struct packed_ref_store *re
>>  					    update->refname,
>>  					    oid_to_hex(&update->old_oid));
>>  				return REF_TRANSACTION_ERROR_NONEXISTENT_REF;
>> +
>> +				if (ref_transaction_maybe_set_rejected(transaction, i, ret)) {
>> +					strbuf_setlen(err, 0);
>> +					ret = 0;
>> +					continue;
>> +				}
>> +
>>  				goto error;
>>  			}
>>  		}
>
> This new code isn't reachable, since we return in the lines shown in the
> diff context.
>
> Should it have been "ret = REF_TRANSACTION_ERROR"... in the first place?
> I think the "goto error" was already unreachable, so possibly the error
> is in an earlier patch. (I didn't look; Coverity flagged this in the
> final state in 'jch').
>
> -Peff

It should have bee `ret = REF_TRANSACTION_ERROR_NONEXISTENT_REF` and it should have been in the previous commit!

Thanks for reporting!
Jeff King· Mar 7, 2025, 19:57 UTC · re: Karthik Nayak · lore

Re: [PATCH v3 6/8] refs: implement partial reference transaction support

On Wed, Mar 05, 2025 at 06:39:01PM +0100, Karthik Nayak wrote:
Show 21 quoted lines
> diff --git a/refs/reftable-backend.c b/refs/reftable-backend.c
> index 0132b8b06a..dd9912d637 100644
> --- a/refs/reftable-backend.c
> +++ b/refs/reftable-backend.c
> @@ -1371,8 +1371,15 @@ static int reftable_be_transaction_prepare(struct ref_store *ref_store,
>  					    transaction->updates[i],
>  					    &refnames_to_check, head_type,
>  					    &head_referent, &referent, err);
> -		if (ret)
> +		if (ret) {
> +			if (ref_transaction_maybe_set_rejected(transaction, i, ret)) {
> +				strbuf_setlen(err, 0);
> +				ret = 0;
> +
> +				continue;
> +			}
>  			goto done;
> +		}
>  	}
>  
>  	string_list_sort(&refnames_to_check);

Coverity complains that this "ret = 0" is a dead store. I think it's right, because either:

  1. Our continue loops again, and we overwrite "ret" with the next call
     to prepare_single_update().
  2. We leave the loop (because this is the final entry in the
     transaction update array), and then we overwrite "ret" with the
     result of refs_verify_refnames_available().

But it may be better to leave it in place as a defensive measure against the rest of the function changing.

-Peff
Karthik Nayak· Mar 7, 2025, 21:07 UTC · re: Jeff King · lore

Re: [PATCH v3 6/8] refs: implement partial reference transaction support

Jeff King <peff@peff.net> writes:
Show 37 quoted lines
> On Wed, Mar 05, 2025 at 06:39:01PM +0100, Karthik Nayak wrote:
>
>> diff --git a/refs/reftable-backend.c b/refs/reftable-backend.c
>> index 0132b8b06a..dd9912d637 100644
>> --- a/refs/reftable-backend.c
>> +++ b/refs/reftable-backend.c
>> @@ -1371,8 +1371,15 @@ static int reftable_be_transaction_prepare(struct ref_store *ref_store,
>>  					    transaction->updates[i],
>>  					    &refnames_to_check, head_type,
>>  					    &head_referent, &referent, err);
>> -		if (ret)
>> +		if (ret) {
>> +			if (ref_transaction_maybe_set_rejected(transaction, i, ret)) {
>> +				strbuf_setlen(err, 0);
>> +				ret = 0;
>> +
>> +				continue;
>> +			}
>>  			goto done;
>> +		}
>>  	}
>>
>>  	string_list_sort(&refnames_to_check);
>
> Coverity complains that this "ret = 0" is a dead store. I think it's
> right, because either:
>
>   1. Our continue loops again, and we overwrite "ret" with the next call
>      to prepare_single_update().
>
>   2. We leave the loop (because this is the final entry in the
>      transaction update array), and then we overwrite "ret" with the
>      result of refs_verify_refnames_available().
>
> But it may be better to leave it in place as a defensive measure against
> the rest of the function changing.
>

Yes agreed with your analysis, and also your inference. So I'll let this stay. Thanks for reporting!

> -Peff
Karthik Nayak· Mar 5, 2025, 17:39 UTC · re: Karthik Nayak · lore

[PATCH v3 7/8] refs: support partial update rejections during F/D checks

The `refs_verify_refnames_available()` is used to batch check refnames for F/D conflicts. While this is the more performant alternative than its individual version, it does not provide rejection capabilities on a single update level. For partial transactions, this would mean a rejection of the entire transaction whenever one reference has a F/D conflict.

Modify the function to call `ref_transaction_maybe_set_rejected()` to check if a single update can be rejected. Since this function is only internally used within 'refs/' and we want to pass in a `struct ref_transaction *` as a variable. We also move and mark `refs_verify_refnames_available()` to 'refs-internal.h' to be an internal function.

Signed-off-by: Karthik Nayak <karthik.188@gmail.com>
---
 refs.c                  | 28 +++++++++++++++++++++++++++-
 refs.h                  | 12 ------------
 refs/files-backend.c    | 27 ++++++++++++++++++---------
 refs/refs-internal.h    | 17 +++++++++++++++++
 refs/reftable-backend.c | 11 ++++++++---
 5 files changed, 70 insertions(+), 25 deletions(-)
Show changes to 5 files +70 −25

refs.c, refs.h, refs/files-backend.c, refs/refs-internal.h, refs/reftable-backend.c

diff --git a/refs.c b/refs.c
index b735510c3b..c4dccf9d8b 100644
--- a/refs.c
+++ b/refs.c
@@ -2540,6 +2540,7 @@ enum ref_transaction_error refs_verify_refnames_available(struct ref_store *refs
 					  const struct string_list *refnames,
 					  const struct string_list *extras,
 					  const struct string_list *skip,
+					  struct ref_transaction *transaction,
 					  unsigned int initial_transaction,
 					  struct strbuf *err)
 {
@@ -2559,6 +2560,7 @@ enum ref_transaction_error refs_verify_refnames_available(struct ref_store *refs
 	strset_init(&dirnames);
 
 	for (size_t i = 0; i < refnames->nr; i++) {
+		const size_t *update_idx = (size_t *)refnames->items[i].util;
 		const char *refname = refnames->items[i].string;
 		const char *extra_refname;
 		struct object_id oid;
@@ -2598,12 +2600,26 @@ enum ref_transaction_error refs_verify_refnames_available(struct ref_store *refs
 			if (!initial_transaction &&
 			    !refs_read_raw_ref(refs, dirname.buf, &oid, &referent,
 					       &type, &ignore_errno)) {
+				if (transaction && ref_transaction_maybe_set_rejected(
+					    transaction, *update_idx,
+					    REF_TRANSACTION_ERROR_NAME_CONFLICT)) {
+					strset_remove(&dirnames, dirname.buf);
+					continue;
+				}
+
 				strbuf_addf(err, _("'%s' exists; cannot create '%s'"),
 					    dirname.buf, refname);
 				goto cleanup;
 			}
 
 			if (extras && string_list_has_string(extras, dirname.buf)) {
+				if (transaction && ref_transaction_maybe_set_rejected(
+					    transaction, *update_idx,
+					    REF_TRANSACTION_ERROR_NAME_CONFLICT)) {
+					strset_remove(&dirnames, dirname.buf);
+					continue;
+				}
+
 				strbuf_addf(err, _("cannot process '%s' and '%s' at the same time"),
 					    refname, dirname.buf);
 				goto cleanup;
@@ -2636,6 +2652,11 @@ enum ref_transaction_error refs_verify_refnames_available(struct ref_store *refs
 				    string_list_has_string(skip, iter->refname))
 					continue;
 
+				if (transaction && ref_transaction_maybe_set_rejected(
+					    transaction, *update_idx,
+					    REF_TRANSACTION_ERROR_NAME_CONFLICT))
+					continue;
+
 				strbuf_addf(err, _("'%s' exists; cannot create '%s'"),
 					    iter->refname, refname);
 				goto cleanup;
@@ -2647,6 +2668,11 @@ enum ref_transaction_error refs_verify_refnames_available(struct ref_store *refs
 
 		extra_refname = find_descendant_ref(dirname.buf, extras, skip);
 		if (extra_refname) {
+			if (transaction && ref_transaction_maybe_set_rejected(
+				    transaction, *update_idx,
+				    REF_TRANSACTION_ERROR_NAME_CONFLICT))
+				continue;
+
 			strbuf_addf(err, _("cannot process '%s' and '%s' at the same time"),
 				    refname, extra_refname);
 			goto cleanup;
@@ -2678,7 +2704,7 @@ enum ref_transaction_error refs_verify_refname_available(
 	};
 
 	return refs_verify_refnames_available(refs, &refnames, extras, skip,
-					      initial_transaction, err);
+					      NULL, initial_transaction, err);
 }
 
 struct do_for_each_reflog_help {
diff --git a/refs.h b/refs.h
index 5e5ff9e57d..938420bec4 100644
--- a/refs.h
+++ b/refs.h
@@ -147,18 +147,6 @@ enum ref_transaction_error refs_verify_refname_available(struct ref_store *refs,
 						 unsigned int initial_transaction,
 						 struct strbuf *err);
 
-/*
- * Same as `refs_verify_refname_available()`, but checking for a list of
- * refnames instead of only a single item. This is more efficient in the case
- * where one needs to check multiple refnames.
- */
-enum ref_transaction_error refs_verify_refnames_available(struct ref_store *refs,
-					  const struct string_list *refnames,
-					  const struct string_list *extras,
-					  const struct string_list *skip,
-					  unsigned int initial_transaction,
-					  struct strbuf *err);
-
 int refs_ref_exists(struct ref_store *refs, const char *refname);
 
 int should_autocreate_reflog(enum log_refs_config log_all_ref_updates,
diff --git a/refs/files-backend.c b/refs/files-backend.c
index c2fdee6013..7525bf75ab 100644
--- a/refs/files-backend.c
+++ b/refs/files-backend.c
@@ -677,16 +677,18 @@ static void unlock_ref(struct ref_lock *lock)
  * - Generate informative error messages in the case of failure
  */
 static enum ref_transaction_error lock_raw_ref(struct files_ref_store *refs,
-					       const char *refname,
+					       struct ref_update *update,
+					       size_t update_idx,
 					       int mustexist,
 					       struct string_list *refnames_to_check,
 					       const struct string_list *extras,
 					       struct ref_lock **lock_p,
 					       struct strbuf *referent,
-					       unsigned int *type,
 					       struct strbuf *err)
 {
 	enum ref_transaction_error ret = REF_TRANSACTION_ERROR_GENERIC;
+	const char *refname = update->refname;
+	unsigned int *type = &update->type;
 	struct ref_lock *lock;
 	struct strbuf ref_file = STRBUF_INIT;
 	int attempts_remaining = 3;
@@ -785,6 +787,8 @@ static enum ref_transaction_error lock_raw_ref(struct files_ref_store *refs,
 
 	if (files_read_raw_ref(&refs->base, refname, &lock->old_oid, referent,
 			       type, &failure_errno)) {
+		struct string_list_item *item;
+
 		if (failure_errno == ENOENT) {
 			if (mustexist) {
 				/* Garden variety missing reference. */
@@ -864,7 +868,9 @@ static enum ref_transaction_error lock_raw_ref(struct files_ref_store *refs,
 		 * make sure there is no existing packed ref that conflicts
 		 * with refname. This check is deferred so that we can batch it.
 		 */
-		string_list_insert(refnames_to_check, refname);
+		item = string_list_insert(refnames_to_check, refname);
+		item->util = xmalloc(sizeof(update_idx));
+		memcpy(item->util, &update_idx, sizeof(update_idx));
 	}
 
 	ret = 0;
@@ -2547,6 +2553,7 @@ struct files_transaction_backend_data {
  */
 static enum ref_transaction_error lock_ref_for_update(struct files_ref_store *refs,
 						      struct ref_update *update,
+						      size_t update_idx,
 						      struct ref_transaction *transaction,
 						      const char *head_ref,
 						      struct string_list *refnames_to_check,
@@ -2575,9 +2582,9 @@ static enum ref_transaction_error lock_ref_for_update(struct files_ref_store *re
 	if (lock) {
 		lock->count++;
 	} else {
-		ret = lock_raw_ref(refs, update->refname, mustexist,
+		ret = lock_raw_ref(refs, update, update_idx, mustexist,
 				   refnames_to_check, &transaction->refnames,
-				   &lock, &referent, &update->type, err);
+				   &lock, &referent, err);
 		if (ret) {
 			char *reason;
 
@@ -2849,7 +2856,7 @@ static int files_transaction_prepare(struct ref_store *ref_store,
 	for (i = 0; i < transaction->nr; i++) {
 		struct ref_update *update = transaction->updates[i];
 
-		ret = lock_ref_for_update(refs, update, transaction,
+		ret = lock_ref_for_update(refs, update, i, transaction,
 					  head_ref, &refnames_to_check,
 					  err);
 		if (ret) {
@@ -2905,7 +2912,8 @@ static int files_transaction_prepare(struct ref_store *ref_store,
 	 * So instead, we accept the race for now.
 	 */
 	if (refs_verify_refnames_available(refs->packed_ref_store, &refnames_to_check,
-					   &transaction->refnames, NULL, 0, err)) {
+					   &transaction->refnames, NULL, transaction,
+					   0, err)) {
 		ret = REF_TRANSACTION_ERROR_NAME_CONFLICT;
 		goto cleanup;
 	}
@@ -2951,7 +2959,7 @@ static int files_transaction_prepare(struct ref_store *ref_store,
 
 cleanup:
 	free(head_ref);
-	string_list_clear(&refnames_to_check, 0);
+	string_list_clear(&refnames_to_check, 1);
 
 	if (ret)
 		files_transaction_cleanup(refs, transaction);
@@ -3097,7 +3105,8 @@ static int files_transaction_finish_initial(struct files_ref_store *refs,
 	}
 
 	if (refs_verify_refnames_available(&refs->base, &refnames_to_check,
-					   &affected_refnames, NULL, 1, err)) {
+					   &affected_refnames, NULL, transaction,
+					   1, err)) {
 		packed_refs_unlock(refs->packed_ref_store);
 		ret = REF_TRANSACTION_ERROR_NAME_CONFLICT;
 		goto cleanup;
diff --git a/refs/refs-internal.h b/refs/refs-internal.h
index c417aec217..f0e958dc83 100644
--- a/refs/refs-internal.h
+++ b/refs/refs-internal.h
@@ -805,4 +805,21 @@ enum ref_transaction_error ref_update_check_old_target(const char *referent,
  */
 int ref_update_expects_existing_old_ref(struct ref_update *update);
 
+/*
+ * Same as `refs_verify_refname_available()`, but checking for a list of
+ * refnames instead of only a single item. This is more efficient in the case
+ * where one needs to check multiple refnames.
+ *
+ * If a transaction is provided with partial support, then individual updates
+ * are marked rejected, reference backends are then in charge of not committing
+ * those updates.
+ */
+enum ref_transaction_error refs_verify_refnames_available(struct ref_store *refs,
+					  const struct string_list *refnames,
+					  const struct string_list *extras,
+					  const struct string_list *skip,
+					  struct ref_transaction *transaction,
+					  unsigned int initial_transaction,
+					  struct strbuf *err);
+
 #endif /* REFS_REFS_INTERNAL_H */
diff --git a/refs/reftable-backend.c b/refs/reftable-backend.c
index dd9912d637..a50e004d96 100644
--- a/refs/reftable-backend.c
+++ b/refs/reftable-backend.c
@@ -1074,6 +1074,7 @@ static enum ref_transaction_error prepare_single_update(struct reftable_ref_stor
 							struct ref_transaction *transaction,
 							struct reftable_backend *be,
 							struct ref_update *u,
+							size_t update_idx,
 							struct string_list *refnames_to_check,
 							unsigned int head_type,
 							struct strbuf *head_referent,
@@ -1149,6 +1150,7 @@ static enum ref_transaction_error prepare_single_update(struct reftable_ref_stor
 	if (ret < 0)
 		return REF_TRANSACTION_ERROR_GENERIC;
 	if (ret > 0 && !ref_update_expects_existing_old_ref(u)) {
+		struct string_list_item *item;
 		/*
 		 * The reference does not exist, and we either have no
 		 * old object ID or expect the reference to not exist.
@@ -1158,7 +1160,9 @@ static enum ref_transaction_error prepare_single_update(struct reftable_ref_stor
 		 * can output a proper error message instead of failing
 		 * at a later point.
 		 */
-		string_list_append(refnames_to_check, u->refname);
+		item = string_list_append(refnames_to_check, u->refname);
+		item->util = xmalloc(sizeof(update_idx));
+		memcpy(item->util, &update_idx, sizeof(update_idx));
 
 		/*
 		 * There is no need to write the reference deletion
@@ -1368,7 +1372,7 @@ static int reftable_be_transaction_prepare(struct ref_store *ref_store,
 
 	for (i = 0; i < transaction->nr; i++) {
 		ret = prepare_single_update(refs, tx_data, transaction, be,
-					    transaction->updates[i],
+					    transaction->updates[i], i,
 					    &refnames_to_check, head_type,
 					    &head_referent, &referent, err);
 		if (ret) {
@@ -1385,6 +1389,7 @@ static int reftable_be_transaction_prepare(struct ref_store *ref_store,
 	string_list_sort(&refnames_to_check);
 	ret = refs_verify_refnames_available(ref_store, &refnames_to_check,
 					     &transaction->refnames, NULL,
+					     transaction,
 					     transaction->flags & REF_TRANSACTION_FLAG_INITIAL,
 					     err);
 	if (ret < 0)
@@ -1403,7 +1408,7 @@ static int reftable_be_transaction_prepare(struct ref_store *ref_store,
 	}
 	strbuf_release(&referent);
 	strbuf_release(&head_referent);
-	string_list_clear(&refnames_to_check, 0);
+	string_list_clear(&refnames_to_check, 1);
 
 	return ret;
 }
-- 
2.48.1
Karthik Nayak· Mar 5, 2025, 17:39 UTC · re: Karthik Nayak · lore

[PATCH v3 8/8] update-ref: add --allow-partial flag for stdin mode

When updating multiple references through stdin, Git's update-ref command normally aborts the entire transaction if any single update fails. While this atomic behavior prevents partial updates by default, there are cases where applying successful updates while reporting failures is desirable.

Add a new `--allow-partial` flag that allows the transaction to continue even when individual reference updates fail. This flag can only be used in `--stdin` mode and builds upon the partial transaction support added to the refs subsystem. When enabled, failed updates are reported in the following format:

  rejected SP (<old-oid> | <old-target>) SP (<new-oid> | <new-target>) SP <rejection-reason> LF

Update the documentation to reflect this change and also tests to cover different scenarios where an update could be rejected.

Signed-off-by: Karthik Nayak <karthik.188@gmail.com>
---
 Documentation/git-update-ref.adoc |  17 ++-
 builtin/update-ref.c              |  67 ++++++++++-
 t/t1400-update-ref.sh             | 233 ++++++++++++++++++++++++++++++++++++++
 3 files changed, 309 insertions(+), 8 deletions(-)
Show changes to 3 files +309 −8

Documentation/git-update-ref.adoc, builtin/update-ref.c, t/t1400-update-ref.sh

diff --git a/Documentation/git-update-ref.adoc b/Documentation/git-update-ref.adoc
index 9e6935d38d..bcf38850a4 100644
--- a/Documentation/git-update-ref.adoc
+++ b/Documentation/git-update-ref.adoc
@@ -7,8 +7,10 @@ git-update-ref - Update the object name stored in a ref safely
 
 SYNOPSIS
 --------
-[verse]
-'git update-ref' [-m <reason>] [--no-deref] (-d <ref> [<old-oid>] | [--create-reflog] <ref> <new-oid> [<old-oid>] | --stdin [-z])
+[synopsis]
+git update-ref [-m <reason>] [--no-deref] -d <ref> [<old-oid>]
+	       [-m <reason>] [--no-deref] [--create-reflog] <ref> <new-oid> [<old-oid>]
+               [-m <reason>] [--no-deref] --stdin [-z] [--allow-partial]
 
 DESCRIPTION
 -----------
@@ -57,6 +59,17 @@ performs all modifications together.  Specify commands of the form:
 With `--create-reflog`, update-ref will create a reflog for each ref
 even if one would not ordinarily be created.
 
+With `--allow-partial`, update-ref continues executing the transaction even if
+some updates fail due to invalid or incorrect user input, applying only the
+successful updates. Errors resulting from user-provided input are treated as
+non-system-related and do not cause the entire transaction to be aborted.
+However, system-related errors—such as I/O failures or memory issues—will still
+result in a full failure. Additionally, errors like F/D conflicts are batched
+for performance optimization and will also cause a full failure. Any failed
+updates will be reported in the following format:
+
+	rejected SP (<old-oid> | <old-target>) SP (<new-oid> | <new-target>) SP <rejection-reason> LF
+
 Quote fields containing whitespace as if they were strings in C source
 code; i.e., surrounded by double-quotes and with backslash escapes.
 Use 40 "0" characters or the empty string to specify a zero value.  To
diff --git a/builtin/update-ref.c b/builtin/update-ref.c
index 1d541e13ad..66bd3cb44f 100644
--- a/builtin/update-ref.c
+++ b/builtin/update-ref.c
@@ -5,6 +5,7 @@
 #include "config.h"
 #include "gettext.h"
 #include "hash.h"
+#include "hex.h"
 #include "refs.h"
 #include "object-name.h"
 #include "parse-options.h"
@@ -13,7 +14,7 @@
 static const char * const git_update_ref_usage[] = {
 	N_("git update-ref [<options>] -d <refname> [<old-oid>]"),
 	N_("git update-ref [<options>]    <refname> <new-oid> [<old-oid>]"),
-	N_("git update-ref [<options>] --stdin [-z]"),
+	N_("git update-ref [<options>] --stdin [-z] [--allow-partial]"),
 	NULL
 };
 
@@ -565,6 +566,49 @@ static void parse_cmd_abort(struct ref_transaction *transaction,
 	report_ok("abort");
 }
 
+static void print_rejected_refs(const char *refname,
+				const struct object_id *old_oid,
+				const struct object_id *new_oid,
+				const char *old_target,
+				const char *new_target,
+				enum ref_transaction_error err,
+				void *cb_data UNUSED)
+{
+	struct strbuf sb = STRBUF_INIT;
+	const char *reason = "";
+
+	switch (err) {
+	case REF_TRANSACTION_ERROR_NAME_CONFLICT:
+		reason = "refname conflict";
+		break;
+	case REF_TRANSACTION_ERROR_CREATE_EXISTS:
+		reason = "reference already exists";
+		break;
+	case REF_TRANSACTION_ERROR_NONEXISTENT_REF:
+		reason = "reference does not exist";
+		break;
+	case REF_TRANSACTION_ERROR_INCORRECT_OLD_VALUE:
+		reason = "incorrect old value provided";
+		break;
+	case REF_TRANSACTION_ERROR_INVALID_NEW_VALUE:
+		reason = "invalid new value provided";
+		break;
+	case REF_TRANSACTION_ERROR_EXPECTED_SYMREF:
+		reason = "expected symref but found regular ref";
+		break;
+	default:
+		reason = "unkown failure";
+	}
+
+	strbuf_addf(&sb, "rejected %s %s %s %s\n", refname,
+		    new_oid ? oid_to_hex(new_oid) : new_target,
+		    old_oid ? oid_to_hex(old_oid) : old_target,
+		    reason);
+
+	fwrite(sb.buf, sb.len, 1, stdout);
+	strbuf_release(&sb);
+}
+
 static void parse_cmd_commit(struct ref_transaction *transaction,
 			     const char *next, const char *end UNUSED)
 {
@@ -573,6 +617,10 @@ static void parse_cmd_commit(struct ref_transaction *transaction,
 		die("commit: extra input: %s", next);
 	if (ref_transaction_commit(transaction, &error))
 		die("commit: %s", error.buf);
+
+	ref_transaction_for_each_rejected_update(transaction,
+						 print_rejected_refs, NULL);
+
 	report_ok("commit");
 	ref_transaction_free(transaction);
 }
@@ -609,7 +657,7 @@ static const struct parse_cmd {
 	{ "commit",        parse_cmd_commit,        0, UPDATE_REFS_CLOSED },
 };
 
-static void update_refs_stdin(void)
+static void update_refs_stdin(unsigned int flags)
 {
 	struct strbuf input = STRBUF_INIT, err = STRBUF_INIT;
 	enum update_refs_state state = UPDATE_REFS_OPEN;
@@ -617,7 +665,7 @@ static void update_refs_stdin(void)
 	int i, j;
 
 	transaction = ref_store_transaction_begin(get_main_ref_store(the_repository),
-						  0, &err);
+						  flags, &err);
 	if (!transaction)
 		die("%s", err.buf);
 
@@ -685,7 +733,7 @@ static void update_refs_stdin(void)
 			 */
 			state = cmd->state;
 			transaction = ref_store_transaction_begin(get_main_ref_store(the_repository),
-								  0, &err);
+								  flags, &err);
 			if (!transaction)
 				die("%s", err.buf);
 
@@ -701,6 +749,8 @@ static void update_refs_stdin(void)
 		/* Commit by default if no transaction was requested. */
 		if (ref_transaction_commit(transaction, &err))
 			die("%s", err.buf);
+		ref_transaction_for_each_rejected_update(transaction,
+						 print_rejected_refs, NULL);
 		ref_transaction_free(transaction);
 		break;
 	case UPDATE_REFS_STARTED:
@@ -727,6 +777,8 @@ int cmd_update_ref(int argc,
 	struct object_id oid, oldoid;
 	int delete = 0, no_deref = 0, read_stdin = 0, end_null = 0;
 	int create_reflog = 0;
+	unsigned int flags = 0;
+
 	struct option options[] = {
 		OPT_STRING( 'm', NULL, &msg, N_("reason"), N_("reason of the update")),
 		OPT_BOOL('d', NULL, &delete, N_("delete the reference")),
@@ -735,6 +787,8 @@ int cmd_update_ref(int argc,
 		OPT_BOOL('z', NULL, &end_null, N_("stdin has NUL-terminated arguments")),
 		OPT_BOOL( 0 , "stdin", &read_stdin, N_("read updates from stdin")),
 		OPT_BOOL( 0 , "create-reflog", &create_reflog, N_("create a reflog")),
+		OPT_BIT('0', "allow-partial", &flags, N_("allow partial transactions"),
+			REF_TRANSACTION_ALLOW_PARTIAL),
 		OPT_END(),
 	};
 
@@ -756,9 +810,10 @@ int cmd_update_ref(int argc,
 			usage_with_options(git_update_ref_usage, options);
 		if (end_null)
 			line_termination = '\0';
-		update_refs_stdin();
+		update_refs_stdin(flags);
 		return 0;
-	}
+	} else if (flags & REF_TRANSACTION_ALLOW_PARTIAL)
+		die("--allow-partial can only be used with --stdin");
 
 	if (end_null)
 		usage_with_options(git_update_ref_usage, options);
diff --git a/t/t1400-update-ref.sh b/t/t1400-update-ref.sh
index 29045aad43..62a82f4af6 100755
--- a/t/t1400-update-ref.sh
+++ b/t/t1400-update-ref.sh
@@ -2066,6 +2066,239 @@ do
 		grep "$(git rev-parse $a) $(git rev-parse $a)" actual
 	'
 
+	test_expect_success "stdin $type allow-partial" '
+		git init repo &&
+		test_when_finished "rm -fr repo" &&
+		(
+			cd repo &&
+			test_commit commit &&
+			head=$(git rev-parse HEAD) &&
+
+			format_command $type "update refs/heads/ref1" "$head" "$Z" >stdin &&
+			format_command $type "update refs/heads/ref2" "$head" "$Z" >>stdin &&
+			git update-ref $type --stdin --allow-partial <stdin &&
+			echo $head >expect &&
+			git rev-parse refs/heads/ref1 >actual &&
+			test_cmp expect actual &&
+			git rev-parse refs/heads/ref2 >actual &&
+			test_cmp expect actual
+		)
+	'
+
+	test_expect_success "stdin $type allow-partial with invalid new_oid" '
+		git init repo &&
+		test_when_finished "rm -fr repo" &&
+		(
+			cd repo &&
+			test_commit one &&
+			old_head=$(git rev-parse HEAD) &&
+			test_commit two &&
+			head=$(git rev-parse HEAD) &&
+			git update-ref refs/heads/ref1 $head &&
+			git update-ref refs/heads/ref2 $head &&
+
+			format_command $type "update refs/heads/ref1" "$old_head" "$head" >stdin &&
+			format_command $type "update refs/heads/ref2" "$(test_oid 001)" "$head" >>stdin &&
+			git update-ref $type --stdin --allow-partial <stdin >stdout &&
+			echo $old_head >expect &&
+			git rev-parse refs/heads/ref1 >actual &&
+			test_cmp expect actual &&
+			echo $head >expect &&
+			git rev-parse refs/heads/ref2 >actual &&
+			test_cmp expect actual &&
+			test_grep -q "invalid new value provided" stdout
+		)
+	'
+
+	test_expect_success "stdin $type allow-partial with non-commit new_oid" '
+		git init repo &&
+		test_when_finished "rm -fr repo" &&
+		(
+			cd repo &&
+			test_commit one &&
+			old_head=$(git rev-parse HEAD) &&
+			test_commit two &&
+			head=$(git rev-parse HEAD) &&
+			head_tree=$(git rev-parse HEAD^{tree}) &&
+			git update-ref refs/heads/ref1 $head &&
+			git update-ref refs/heads/ref2 $head &&
+
+			format_command $type "update refs/heads/ref1" "$old_head" "$head" >stdin &&
+			format_command $type "update refs/heads/ref2" "$head_tree" "$head" >>stdin &&
+			git update-ref $type --stdin --allow-partial <stdin >stdout &&
+			echo $old_head >expect &&
+			git rev-parse refs/heads/ref1 >actual &&
+			test_cmp expect actual &&
+			echo $head >expect &&
+			git rev-parse refs/heads/ref2 >actual &&
+			test_cmp expect actual &&
+			test_grep -q "invalid new value provided" stdout
+		)
+	'
+
+	test_expect_success "stdin $type allow-partial with non-existent ref" '
+		git init repo &&
+		test_when_finished "rm -fr repo" &&
+		(
+			cd repo &&
+			test_commit one &&
+			old_head=$(git rev-parse HEAD) &&
+			test_commit two &&
+			head=$(git rev-parse HEAD) &&
+			git update-ref refs/heads/ref1 $head &&
+
+			format_command $type "update refs/heads/ref1" "$old_head" "$head" >stdin &&
+			format_command $type "update refs/heads/ref2" "$old_head" "$head" >>stdin &&
+			git update-ref $type --stdin --allow-partial <stdin >stdout &&
+			echo $old_head >expect &&
+			git rev-parse refs/heads/ref1 >actual &&
+			test_cmp expect actual &&
+			test_must_fail git rev-parse refs/heads/ref2 &&
+			test_grep -q "reference does not exist" stdout
+		)
+	'
+
+	test_expect_success "stdin $type allow-partial with dangling symref" '
+		git init repo &&
+		test_when_finished "rm -fr repo" &&
+		(
+			cd repo &&
+			test_commit one &&
+			old_head=$(git rev-parse HEAD) &&
+			test_commit two &&
+			head=$(git rev-parse HEAD) &&
+			git update-ref refs/heads/ref1 $head &&
+			git symbolic-ref refs/heads/ref2 refs/heads/nonexistent &&
+
+			format_command $type "update refs/heads/ref1" "$old_head" "$head" >stdin &&
+			format_command $type "update refs/heads/ref2" "$old_head" "$head" >>stdin &&
+			git update-ref $type --no-deref --stdin --allow-partial <stdin >stdout &&
+			echo $old_head >expect &&
+			git rev-parse refs/heads/ref1 >actual &&
+			test_cmp expect actual &&
+			echo $head >expect &&
+			test_must_fail git rev-parse refs/heads/ref2 &&
+			test_grep -q "reference does not exist" stdout
+		)
+	'
+
+	test_expect_success "stdin $type allow-partial with regular ref as symref" '
+		git init repo &&
+		test_when_finished "rm -fr repo" &&
+		(
+			cd repo &&
+			test_commit one &&
+			old_head=$(git rev-parse HEAD) &&
+			test_commit two &&
+			head=$(git rev-parse HEAD) &&
+			git update-ref refs/heads/ref1 $head &&
+			git update-ref refs/heads/ref2 $head &&
+
+			format_command $type "update refs/heads/ref1" "$old_head" "$head" >stdin &&
+			format_command $type "symref-update refs/heads/ref2" "$old_head" "ref" "refs/heads/nonexistent" >>stdin &&
+			git update-ref $type --no-deref --stdin --allow-partial <stdin >stdout &&
+			echo $old_head >expect &&
+			git rev-parse refs/heads/ref1 >actual &&
+			test_cmp expect actual &&
+			echo $head >expect &&
+			echo $head >expect &&
+			git rev-parse refs/heads/ref2 >actual &&
+			test_cmp expect actual &&
+			test_grep -q "expected symref but found regular ref" stdout
+		)
+	'
+
+	test_expect_success "stdin $type allow-partial with invalid old_oid" '
+		git init repo &&
+		test_when_finished "rm -fr repo" &&
+		(
+			cd repo &&
+			test_commit one &&
+			old_head=$(git rev-parse HEAD) &&
+			test_commit two &&
+			head=$(git rev-parse HEAD) &&
+			git update-ref refs/heads/ref1 $head &&
+			git update-ref refs/heads/ref2 $head &&
+
+			format_command $type "update refs/heads/ref1" "$old_head" "$head" >stdin &&
+			format_command $type "update refs/heads/ref2" "$old_head" "$Z" >>stdin &&
+			git update-ref $type --stdin --allow-partial <stdin >stdout &&
+			echo $old_head >expect &&
+			git rev-parse refs/heads/ref1 >actual &&
+			test_cmp expect actual &&
+			echo $head >expect &&
+			git rev-parse refs/heads/ref2 >actual &&
+			test_cmp expect actual &&
+			test_grep -q "reference already exists" stdout
+		)
+	'
+
+	test_expect_success "stdin $type allow-partial with incorrect old oid" '
+		git init repo &&
+		test_when_finished "rm -fr repo" &&
+		(
+			cd repo &&
+			test_commit one &&
+			old_head=$(git rev-parse HEAD) &&
+			test_commit two &&
+			head=$(git rev-parse HEAD) &&
+			git update-ref refs/heads/ref1 $head &&
+			git update-ref refs/heads/ref2 $head &&
+
+			format_command $type "update refs/heads/ref1" "$old_head" "$head" >stdin &&
+			format_command $type "update refs/heads/ref2" "$head" "$old_head" >>stdin &&
+			git update-ref $type --stdin --allow-partial <stdin >stdout &&
+			echo $old_head >expect &&
+			git rev-parse refs/heads/ref1 >actual &&
+			test_cmp expect actual &&
+			echo $head >expect &&
+			git rev-parse refs/heads/ref2 >actual &&
+			test_cmp expect actual &&
+			test_grep -q "incorrect old value provided" stdout
+		)
+	'
+
+	test_expect_success "stdin $type allow-partial refname conflict" '
+		git init repo &&
+		test_when_finished "rm -fr repo" &&
+		(
+			cd repo &&
+			test_commit one &&
+			old_head=$(git rev-parse HEAD) &&
+			test_commit two &&
+			head=$(git rev-parse HEAD) &&
+			git update-ref refs/heads/ref/foo $head &&
+
+			format_command $type "update refs/heads/ref/foo" "$old_head" "$head" >stdin &&
+			format_command $type "update refs/heads/ref" "$old_head" "" >>stdin &&
+			git update-ref $type --stdin --allow-partial <stdin >stdout &&
+			echo $old_head >expect &&
+			git rev-parse refs/heads/ref/foo >actual &&
+			test_cmp expect actual &&
+			test_grep -q "refname conflict" stdout
+		)
+	'
+
+	test_expect_success "stdin $type allow-partial refname conflict new ref" '
+		git init repo &&
+		test_when_finished "rm -fr repo" &&
+		(
+			cd repo &&
+			test_commit one &&
+			old_head=$(git rev-parse HEAD) &&
+			test_commit two &&
+			head=$(git rev-parse HEAD) &&
+			git update-ref refs/heads/ref/foo $head &&
+
+			format_command $type "update refs/heads/foo" "$old_head" "" >stdin &&
+			format_command $type "update refs/heads/ref" "$old_head" "" >>stdin &&
+			git update-ref $type --stdin --allow-partial <stdin >stdout &&
+			echo $old_head >expect &&
+			git rev-parse refs/heads/foo >actual &&
+			test_cmp expect actual &&
+			test_grep -q "refname conflict" stdout
+		)
+	'
 done
 
 test_expect_success 'update-ref should also create reflog for HEAD' '
-- 
2.48.1
Junio C Hamano· Mar 5, 2025, 19:28 UTC · re: Karthik Nayak · lore

Re: [PATCH v3 0/8] refs: introduce support for partial reference transactions

Karthik Nayak <karthik.188@gmail.com> writes:
> Git's reference updates are traditionally all or nothing - when
> updating multiple references in a transaction, either all updates
> succeed or none do.

I am quite confused. In the beginning (traditionally), there was no transaction to speak of. You try to update two refs at the same time, we did best effort but that was never atomic. Later we introduced transactions to optionally make the changes all-or-none.

So, if you want "I have these N updates, but I do not care if some of them have to fail---just make your best effort to update as many of them as you can", why are you still doing a transaction?

Perhaps it is merely the phrasing that makes this proposal confusing. If presented as "non-transactional batched updates", perhaps it may have been more palatable. I dunno, but "partial transaction" does not quite sound like a transaction, at least to me.

Karthik Nayak· Mar 6, 2025, 09:06 UTC · re: Junio C Hamano · lore

Re: [PATCH v3 0/8] refs: introduce support for partial reference transactions

Junio C Hamano <gitster@pobox.com> writes:
Show 20 quoted lines
> Karthik Nayak <karthik.188@gmail.com> writes:
>
>> Git's reference updates are traditionally all or nothing - when
>> updating multiple references in a transaction, either all updates
>> succeed or none do.
>
> I am quite confused.  In the beginning (traditionally), there was no
> transaction to speak of.  You try to update two refs at the same
> time, we did best effort but that was never atomic.  Later we
> introduced transactions to optionally make the changes all-or-none.
>
> So, if you want "I have these N updates, but I do not care if some
> of them have to fail---just make your best effort to update as many
> of them as you can", why are you still doing a transaction?
>
> Perhaps it is merely the phrasing that makes this proposal
> confusing.  If presented as "non-transactional batched updates",
> perhaps it may have been more palatable.  I dunno, but "partial
> transaction" does not quite sound like a transaction, at least to
> me.

That's fair. There was also some discussion earlier around this [1]. It is in indeed batched updates which can allow failures, but it is built on top of the transaction infrastructure in the refs subsystem.

Perhaps the best way would be to use the transaction interface under the hood, but present this feature as 'batched updates' to users, so there is no confusion between the two.

[1]: 4beb0359-763d-425d-b416-ac40bda59e2e@gmail.com

← back to recent threads