Skip to content

Accept a source commit a branch or tag contains - #140

Merged
shiny-code-app[bot] merged 2 commits into
mainfrom
work/reachable-source-commit
Sep 30, 2026
Merged

shiny-code-app[bot] merged 2 commits into
mainfrom
work/reachable-source-commit

Conversation

@shiny-code-app

Copy link
Copy Markdown
Contributor

Every merge to devkit main broke the next artifact build of every site pinned to the previous main tip. The publish check required each source commit to be a ref tip (git ls-remote). After #137 moved main, cm-website's pin 74f4cf7, still an ancestor of main, was refused, and cm-website#108's build failed.

What changed

  • The ref-tip check stays. When the commit is not a tip, remote_branch_or_tag_contains_commit does the following:
    • fetches only commit history (--filter=tree:0) for the origin's branches and tags into a temporary bare repository, created with an empty template and with lazy fetching disabled;
    • accepts the commit only if a branch or tag contains it.
  • The commit is never fetched by id. GitHub serves any commit in a fork network that way, so a fork-only commit still fails. PR refs are not in the history fetch; PR tips stay accepted by the existing tip rule.
  • docs/tooling/artifact-inputs.md says what "published in its origin" now means.

Review

OpenAI gpt-6.1-sol found the reachability rule sound under the fork threat model. Two findings are applied:

  • an inherited git template could seed a tag into the verification repository, so it now uses --template=;
  • a missing-object probe could lazily fetch the commit by id, so the probe is gone and GIT_NO_LAZY_FETCH=1 is set.

Declined: a Git version check for --filter=tree:0. Every supported Git has had it since 2.20, and a failed fetch already stops with Git's error.

Verification

  • A new real-git test accepts an ancestor of main and refuses a commit whose branch was deleted.
  • The full suite passes (320 tests), as does ruff.
  • Live: 74f4cf7 is accepted against cbusillo/odoo-devkit, and an unknown commit is refused.

Fixes #139

Publish required each source commit to be a ref tip, so every merge to
devkit main broke the next artifact build of every tenant pinned to the
previous tip. A commit that is not a tip now passes when a branch or tag
of its origin contains it, found by fetching only commit history. The
commit itself is never fetched by id, so a fork-network commit still
fails.

Fixes #139
Initialize the verification repository with an empty template and disable
lazy fetching, so neither an inherited template nor a missing-object lookup
can supply a commit. for-each-ref --contains already rejects an unknown
commit, so the separate existence probe is gone. From an OpenAI
gpt-6.1-sol review.
@shiny-code-app shiny-code-app Bot added the ready-to-merge Every Code PR is ready for repository owner merge review label Sep 30, 2026
shiny-code-app Bot added a commit that referenced this pull request Sep 30, 2026
shiny-code-app Bot added a commit that referenced this pull request Sep 30, 2026
@shiny-code-app
shiny-code-app Bot merged commit d3f0e70 into main Sep 30, 2026
5 checks passed
@shiny-code-app
shiny-code-app Bot deleted the work/reachable-source-commit branch September 30, 2026 03:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ready-to-merge Every Code PR is ready for repository owner merge review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Artifact publish rejects a pinned devkit commit once it stops being a ref tip

1 participant