patchreceive-pack: fix updateInstead with core.worktree
5 messages between May 22, 2026 and May 25, 2026, from Alyssa Ross, Kristoffer Haugsbakk, Junio C Hamano.
Plain Markdown or JSON for tools and agents. Diffs are folded; open one to read it.
Alyssa RossMay 22, 2026, 15:44 UTC on loreThis used to work, but when push_to_checkout() started being called before push_to_deploy(), push_to_checkout()'s side effect of adding GIT_WORK_TREE to the same environment that would be used by push_to_deploy() wasn't taken into account. Fix by only mutating the environment for push_to_commit(), rather than the shared environment.
Fixes: a8cc594333 ("hooks: fix an obscure TOCTOU "did we just run a hook?" race")
Signed-off-by: Alyssa Ross <hi@alyssa.is>
---
builtin/receive-pack.c | 2 +-
t/t5516-fetch-push.sh | 11 +++++++++++
2 files changed, 12 insertions(+), 1 deletion(-)Show changes to 2 files +12 −1
builtin/receive-pack.c, t/t5516-fetch-push.sh
diff --git a/builtin/receive-pack.c b/builtin/receive-pack.c
index c7b2818f20..7ee157532d 100644
--- a/builtin/receive-pack.c
+++ b/builtin/receive-pack.c
@@ -1460,8 +1460,8 @@ static const char *push_to_checkout(unsigned char *hash,
opt.invoked_hook = invoked_hook;
- strvec_pushf(env, "GIT_WORK_TREE=%s", absolute_path(work_tree));
strvec_pushv(&opt.env, env->v);
+ strvec_pushf(&opt.env, "GIT_WORK_TREE=%s", absolute_path(work_tree));
strvec_push(&opt.args, hash_to_hex(hash));
if (run_hooks_opt(the_repository, push_to_checkout_hook, &opt))
return "push-to-checkout hook declined";
diff --git a/t/t5516-fetch-push.sh b/t/t5516-fetch-push.sh
index 117cfa051f..f51fb11a6d 100755
--- a/t/t5516-fetch-push.sh
+++ b/t/t5516-fetch-push.sh
@@ -1791,6 +1791,17 @@ test_expect_success 'updateInstead with push-to-checkout hook' '
)
'
+test_expect_success 'denyCurrentBranch and core.worktree' '
+ test_when_finished "rm -fr cloned cloned.git" &&
+ git clone --separate-git-dir cloned.git . cloned &&
+ git --git-dir cloned.git config receive.denyCurrentBranch updateInstead &&
+ git --git-dir cloned.git config core.worktree "$PWD/cloned" &&
+ test_commit raspberry &&
+ git push cloned.git HEAD:main &&
+ test_path_exists cloned/raspberry.t &&
+ test_must_fail git push --delete cloned.git main
+'
+
test_expect_success 'denyCurrentBranch and worktrees' '
test_when_finished "rm -fr cloned && git worktree remove --force new-wt" &&
git worktree add new-wt &&
base-commit: aec3f587505a472db67e9462d0702e7d463a449d
--
2.53.0
Re: [PATCH] receive-pack: fix updateInstead with core.worktree
On Fri, May 22, 2026, at 17:44, Alyssa Ross wrote:
Show 7 quoted lines
> This used to work, but when push_to_checkout() started being called
> before push_to_deploy(), push_to_checkout()'s side effect of adding
> GIT_WORK_TREE to the same environment that would be used by
> push_to_deploy() wasn't taken into account. Fix by only mutating the
> environment for push_to_commit(), rather than the shared environment.
>
> Fixes: a8cc594333 ("hooks: fix an obscure TOCTOU "did we just run a hook?" race")This project doesn’t use `Fixes` trailers.[1] Mentions of commits go in the commit message body (outside the trailers) using `git log -1 --format-reference <cmt>`.
The Linux project has uses for this structured information since there is a lot of backporting of bugfixes. But I haven’t heard of a need for that in this project.
🔗 1: https://lore.kernel.org/git/72839071-153f-4306-a705-3be0dc203109@app.fastmail.com/
> Signed-off-by: Alyssa Ross <hi@alyssa.is>
> ---
>[snip]
Re: [PATCH] receive-pack: fix updateInstead with core.worktree
Alyssa Ross <hi@alyssa.is> writes:
> This used to work, but when push_to_checkout() started being called
> before push_to_deploy(), ...
We tend to try describing where things started breaking a bit more precisely. The above seems to say that you know that in the past push_to__checkout() was not called before push_to_deploy(), and it no longer is the case these days? Can you spell out in what commit that change happened (refer to the commit using the "git show -s --pretty=reference" format)? I.e.
... but when X started doing Y at a8cc5943 (hooks: fix an
obscure TOCTOU "did we just run a hook?" race, 2022-03-07),
<<this bad thing>> started to happen.
It isn't really we are exercising "checkout" and "deploy" both at the same time, but an old commit started to always call _checkout only to see if that actually invokes the hook, and if it didn't, then call _deploy. The intent still is to use either one of these, but as you exactly identified what is wrong in the current code, the call to _checkout that is only done to probe if it is used at all started to contaminate the environment with that commit.
So this change ...
> - strvec_pushf(env, "GIT_WORK_TREE=%s", absolute_path(work_tree));
> strvec_pushv(&opt.env, env->v);
> + strvec_pushf(&opt.env, "GIT_WORK_TREE=%s", absolute_path(work_tree));
> strvec_push(&opt.args, hash_to_hex(hash));
... looks like absolutely the right thing to do. And ...
Show 20 quoted lines
> if (run_hooks_opt(the_repository, push_to_checkout_hook, &opt))
> return "push-to-checkout hook declined";
> diff --git a/t/t5516-fetch-push.sh b/t/t5516-fetch-push.sh
> index 117cfa051f..f51fb11a6d 100755
> --- a/t/t5516-fetch-push.sh
> +++ b/t/t5516-fetch-push.sh
> @@ -1791,6 +1791,17 @@ test_expect_success 'updateInstead with push-to-checkout hook' '
> )
> '
>
> +test_expect_success 'denyCurrentBranch and core.worktree' '
> + test_when_finished "rm -fr cloned cloned.git" &&
> + git clone --separate-git-dir cloned.git . cloned &&
> + git --git-dir cloned.git config receive.denyCurrentBranch updateInstead &&
> + git --git-dir cloned.git config core.worktree "$PWD/cloned" &&
> + test_commit raspberry &&
> + git push cloned.git HEAD:main &&
> + test_path_exists cloned/raspberry.t &&
> + test_must_fail git push --delete cloned.git main
> +'
... a test that protects similar breakage in the future is also excellent.
Show 5 quoted lines
> test_expect_success 'denyCurrentBranch and worktrees' '
> test_when_finished "rm -fr cloned && git worktree remove --force new-wt" &&
> git worktree add new-wt &&
>
> base-commit: aec3f587505a472db67e9462d0702e7d463a449d
[PATCH v2] receive-pack: fix updateInstead with core.worktree
Previously, only one of push_to_checkout() or push_to_deploy() was called. In a8cc594333 (hooks: fix an obscure TOCTOU "did we just run a hook?" race, 2022-03-07), this was changed to always call push_to_checkout(), and then to call push_to_deploy() if push_to_checkout() didn't run anything. This change didn't take into account that push_to_checkout() had a side effect of modifying env, and that modified env broke updating the worktree in push_to_deploy() if core.worktree was configured. To fix this, only mutate the environment used inside push_to_commit(), rather than the environment that might later be passed to push_to_deploy().
Signed-off-by: Alyssa Ross <hi@alyssa.is>
---
v2: reword commit message in response to feedback
builtin/receive-pack.c | 2 +-
t/t5516-fetch-push.sh | 11 +++++++++++
2 files changed, 12 insertions(+), 1 deletion(-)
Show changes to 2 files +12 −1
builtin/receive-pack.c, t/t5516-fetch-push.sh
diff --git a/builtin/receive-pack.c b/builtin/receive-pack.c
index c7b2818f20..7ee157532d 100644
--- a/builtin/receive-pack.c
+++ b/builtin/receive-pack.c
@@ -1460,8 +1460,8 @@ static const char *push_to_checkout(unsigned char *hash,
opt.invoked_hook = invoked_hook;
- strvec_pushf(env, "GIT_WORK_TREE=%s", absolute_path(work_tree));
strvec_pushv(&opt.env, env->v);
+ strvec_pushf(&opt.env, "GIT_WORK_TREE=%s", absolute_path(work_tree));
strvec_push(&opt.args, hash_to_hex(hash));
if (run_hooks_opt(the_repository, push_to_checkout_hook, &opt))
return "push-to-checkout hook declined";
diff --git a/t/t5516-fetch-push.sh b/t/t5516-fetch-push.sh
index 117cfa051f..db6cc18673 100755
--- a/t/t5516-fetch-push.sh
+++ b/t/t5516-fetch-push.sh
@@ -1791,6 +1791,17 @@ test_expect_success 'updateInstead with push-to-checkout hook' '
)
'
+test_expect_success 'denyCurrentBranch and core.worktree' '
+ test_when_finished "rm -fr cloned cloned.git" &&
+ git clone --separate-git-dir cloned.git . cloned &&
+ git --git-dir cloned.git config receive.denyCurrentBranch updateInstead &&
+ git --git-dir cloned.git config core.worktree "$PWD/cloned" &&
+ test_commit raspberry &&
+ git push cloned.git HEAD:main &&
+ test_path_exists cloned/raspberry.t &&
+ test_must_fail git push --delete cloned.git main
+'
+
test_expect_success 'denyCurrentBranch and worktrees' '
test_when_finished "rm -fr cloned && git worktree remove --force new-wt" &&
git worktree add new-wt &&
base-commit: aec3f587505a472db67e9462d0702e7d463a449d
--
2.53.0
Re: [PATCH v2] receive-pack: fix updateInstead with core.worktree
Alyssa Ross <hi@alyssa.is> writes:
Show 14 quoted lines
> Previously, only one of push_to_checkout() or push_to_deploy() was
> called. In a8cc594333 (hooks: fix an obscure TOCTOU "did we just run a
> hook?" race, 2022-03-07), this was changed to always call
> push_to_checkout(), and then to call push_to_deploy() if
> push_to_checkout() didn't run anything. This change didn't take into
> account that push_to_checkout() had a side effect of modifying env, and
> that modified env broke updating the worktree in push_to_deploy() if
> core.worktree was configured. To fix this, only mutate the environment
> used inside push_to_commit(), rather than the environment that might
> later be passed to push_to_deploy().
>
> Signed-off-by: Alyssa Ross <hi@alyssa.is>
> ---
> v2: reword commit message in response to feedback
You also fixed an incorrectly indentated line in the new test, which is very much appreciated.
Will queue. Thanks.
Show 43 quoted lines
>
> builtin/receive-pack.c | 2 +-
> t/t5516-fetch-push.sh | 11 +++++++++++
> 2 files changed, 12 insertions(+), 1 deletion(-)
>
> diff --git a/builtin/receive-pack.c b/builtin/receive-pack.c
> index c7b2818f20..7ee157532d 100644
> --- a/builtin/receive-pack.c
> +++ b/builtin/receive-pack.c
> @@ -1460,8 +1460,8 @@ static const char *push_to_checkout(unsigned char *hash,
>
> opt.invoked_hook = invoked_hook;
>
> - strvec_pushf(env, "GIT_WORK_TREE=%s", absolute_path(work_tree));
> strvec_pushv(&opt.env, env->v);
> + strvec_pushf(&opt.env, "GIT_WORK_TREE=%s", absolute_path(work_tree));
> strvec_push(&opt.args, hash_to_hex(hash));
> if (run_hooks_opt(the_repository, push_to_checkout_hook, &opt))
> return "push-to-checkout hook declined";
> diff --git a/t/t5516-fetch-push.sh b/t/t5516-fetch-push.sh
> index 117cfa051f..db6cc18673 100755
> --- a/t/t5516-fetch-push.sh
> +++ b/t/t5516-fetch-push.sh
> @@ -1791,6 +1791,17 @@ test_expect_success 'updateInstead with push-to-checkout hook' '
> )
> '
>
> +test_expect_success 'denyCurrentBranch and core.worktree' '
> + test_when_finished "rm -fr cloned cloned.git" &&
> + git clone --separate-git-dir cloned.git . cloned &&
> + git --git-dir cloned.git config receive.denyCurrentBranch updateInstead &&
> + git --git-dir cloned.git config core.worktree "$PWD/cloned" &&
> + test_commit raspberry &&
> + git push cloned.git HEAD:main &&
> + test_path_exists cloned/raspberry.t &&
> + test_must_fail git push --delete cloned.git main
> +'
> +
> test_expect_success 'denyCurrentBranch and worktrees' '
> test_when_finished "rm -fr cloned && git worktree remove --force new-wt" &&
> git worktree add new-wt &&
>
> base-commit: aec3f587505a472db67e9462d0702e7d463a449d