fix(strategy): defer checkpoint push until a normal remote branch exists (#1743) · Entire

fix(strategy): defer checkpoint push until a normal remote branch exists (#1743)

d5d8ac6→main· ?
Karthik Rameshkumar·3d ago·6 files·+253 added/-10 removed

When Entire is enabled before a repository has any branch on its remote, the pre-push hook could independently publish entire/checkpoints/v1 ahead of the user's first normal branch. On an empty GitHub repo that metadata branch can become the repository default branch.

Route the Git pre-push hook through a new PrePushFromGitHook that, for the user's push remote, inspects the actual push target(s) (including a distinct pushurl via git remote get-url --push --all) and defers automatic checkpoint publication until a non-metadata branch exists there. A configured, separate checkpoint_remote is intentionally exempt. The OPF rewrite still runs before deferral so a user push that explicitly includes v1 stays redacted. Deferral fails closed: the user's push proceeds and a later push publishes the queued metadata.

Adds integration coverage on both checkpoint backends (empty remote and empty pushurl target) plus a unit test asserting OPF runs during deferral.

Sessions

01KXFTRJE032AGXJKYGV4HQ4PQView transcript

Changes

6

240 unmodified lines

241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277

240 unmodified lines

return lsRemote(ctx, dir, remote, patterns...)

// PushTargetsInDir resolves the endpoint or endpoints Git will use for a push.
// A named remote may configure pushurl, which differs from its fetch URL and
// can contain more than one destination. URLs and local paths are already
// concrete push targets and are returned unchanged.
func PushTargetsInDir(ctx context.Context, dir, target string) ([]string, error) {
    if target == "" || IsURL(target) || isLocalPath(target) {
        return []string{target}, nil
    }

cmd := newCommand(ctx, "remote", "get-url", "--push", "--all", target)
    if dir != "" {
        cmd.Dir = dir
    }
    disableTerminalPrompt(cmd)
    out, err := cmd.Output()
    if err != nil {
        return nil, fmt.Errorf("git remote get-url --push: %w", err)
    }

var targets []string
    for _, line := range strings.Split(string(out), "\n") {
        if target := strings.TrimSpace(line); target != "" {
            targets = append(targets, target)
        }
    }
    if len(targets) == 0 {
        return nil, fmt.Errorf("git remote get-url --push: no push target for %q", target)
    }
    return targets, nil
}

func lsRemote(ctx context.Context, dir, remote string, patterns ...string) ([]byte, error) {
    args := append([]string{"ls-remote", remote}, patterns...)
    cmd := newCommand(ctx, args...)
    // multiple remotes.
func (env *TestEnv) SetupNamedBareRemote(remoteName string) string {
    env.T.Helper()
    bareDir := env.SetupEmptyNamedBareRemote(remoteName)

// Push HEAD to the remote.
    cmd := exec.CommandContext(env.T.Context(), "git", "push", "--no-verify", "-u", remoteName, "HEAD")
    cmd.Dir = env.RepoDir
    cmd.Env = testutil.GitIsolatedEnv()
    if output, err := cmd.CombinedOutput(); err != nil {
        env.T.Fatalf("failed to push to %s: %v\n%s", remoteName, err, output)
    }

env.setGitConfigBaseline()

return bareDir
}

// SetupEmptyNamedBareRemote creates a bare git repository and adds it as a
// remote without pushing a branch. Use this to exercise first-push behavior.
func (env *TestEnv) SetupEmptyNamedBareRemote(remoteName string) string {
    env.T.Helper()

ctx := env.T.Context();

_ = env.SetupBareRemote()
    pushTarget := env.SetupEmptyNamedBareRemote("push-target")
    cmd := exec.CommandContext(t.Context(), "git", "remote", "set-url", "--push", "origin", pushTarget)
    cmd.Dir = env.RepoDir
    cmd.Env = env.cliEnv()
    if output, err := cmd.CombinedOutput(); err != nil {
        env.T.Fatalf("set origin pushurl: %v\n%s", err, output)
    }
    env.setGitConfigBaseline()

checkpointID := createCheckpointedCommit(t, env, "Add auth module", "auth.go", "package auth", "Add auth module")
    env.GitPushWithHooks("origin", "HEAD")
    if env.CheckpointsPresentOnRemote(pushTarget) {
        t.Fatalf("[%s] checkpoints must be deferred on the empty pushurl target", backend)
    }

env.WriteFile("later.go", "package later")
    env.GitAdd("later.go")
    env.GitCommit("Later user commit")
    env.GitPushWithHooks("origin", "HEAD")
    if !env.CheckpointExistsOnRemote(pushTarget, checkpointID) {
        t.Fatalf("[%s] deferred checkpoint %s should be published to pushurl on a later push", backend, checkpointID)
    }
}