Repository navigation
fix(git): serve want-by-sha for unadvertised refs (PR merge commits) - #27
Conversation
Codecov Report❌ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## main #27 +/- ##
==========================================
+ Coverage 96.69% 96.80% +0.10%
==========================================
Files 6 6
Lines 1846 2065 +219
==========================================
+ Hits 1785 1999 +214
- Misses 61 66 +5 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
|
Thanks for your contribution @DanielHabenicht ! I left a few comments. You also need to fixup the commit msg/body. |
14a02b8 to
6e36d14
Compare
|
@DanielHabenicht do you think you'll have the time to address the comments? |
I'd be happy to pick this up and wrap it up if you're too busy. |
|
Sorry, so much todo. You can take it from here. |
1329ac2 to
238dbde
Compare
actions/checkout fetches a PR merge commit by bare SHA, but that commit lives only under GitHub's unadvertised refs/pull/<n>/merge, so the mirror never captured it and upload-pack rejected the want. ensure_fresh now fetches any missing wanted SHA from upstream and pins it under refs/proxy-wants/<sha> so it stays serveable; --max-wants bounds how many pins a mirror retains. Assisted-by: Claude:claude-opus-4-8
5a1eeb0 to
996762c
Compare
Thanks for your contributions. No worries. I've taken over and will get this merged in a bit. |
Before serving an upload-pack RPC, parse the client's
wantlines and, for any SHA missing from the mirror, fetch it from upstream on demand and pin it under a reservedrefs/proxy-wants/<sha>ref. Pinning makes the object a valid want tip (so upload-pack serves it) and keeps it fromgit gc. The namespace is hidden from the ref advertisement (uploadpack.hideRefs) yet still honored as a want tip, and excluded fromfetch --pruneso pins survive periodic refreshes.Relies on the upstream serving arbitrary SHAs (GitHub's allowAnySHA1InWant); an upstream that refuses leaves the request to fail as before - no regression. Ordinary branch/tag clones pay only a single cheap cat-file check, never an extra upstream call.
What kind of change does this PR introduce?
Summary
actions/checkout on a pull_request event fetches the synthetic merge commit by bare SHA. That commit lives only under GitHub's unadvertised refs/pull//merge, so
clone --mirrornever captured it and the mirror's upload-pack rejected the want with "fatal: not our ref ", breaking CI behind the proxy.Tests
Checklist
cargo fmt --all --check,cargo clippy --all-targets --all-features --locked -- -D warnings,cargo test --all-featuresAssisted-by:trailer (see CONTRIBUTING.md / AGENTS.md)Breaking change?
If yes, describe the impact and the migration path (flags / env, on-disk cache layout).