[Bug] CI accepts obsolete PR targets after retargeting or force-push
Maintainers usually reply within 1 day
Nobody has claimed this yet.
- #3297 by @contrueCT — closed without merging
Assessment
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Newbie friendliness
- 25/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Active
- Tech stack
- git, github
- Domain
- ci-cd
Research direction
Start with require_current_pr(), which checks the target repository but not the target branch name or whether the tested base is still in the target's history, and with create_plan() and the all, memory and advisory gates that accept the stale snapshot. Build the Git fixture from the reproduction (base commit, PR head, two-parent synthetic merge) and check that a retargeted base or force-pushed unrelated history is rejected while a normal advance and a changed-head control behave as described. Done when those cases pass and the Memory metadata-outage policy is unchanged. PR #3297 is already open against this issue, so coordinate with it first.
Written by the indexing model from the issue text.
Description
Problem
On Apache master 68855199031d5801edb4fe41b2bacbacffe8fe68, CI accepts an old synthetic merge after a PR is retargeted within the same repository or the target branch is force-pushed to unrelated history. require_current_pr() checks the target repository, but omits the target branch name and whether the tested base remains in the target's history.
Reproduction
Create a local Git fixture with a base commit, a PR head and a two-parent synthetic merge. Build a plan against master, then supply live PR metadata with either a different base ref or an unrelated commit at the same base ref. With unchanged head identity and successful selected results, create_plan() and the all, memory and advisory gates accept the obsolete snapshot. A changed-head control is correctly rejected.
Expected behavior
Bind the plan to its target ref and reject rewritten target history. Continue to allow normal target-branch advancement, consistent with non-strict protection, and preserve the documented metadata-outage policy for completed Memory tests.
Scope and existing work
This concerns CI planning and reporting; the fixture does not establish that GitHub branch protection can be bypassed. Existing issues and PRs were searched for retargeting, force-push and plan freshness. Merged CI changes #3271 and #3277 retain the gap; no active fix was found. The earlier report is in the Topling review.
- Dominant language
- Java
- Stars
- 3.2k
- Forks
- 641
- Avg merge
- 1d 16h
- Merged PRs (30d)
- 38
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from apache/hugegraph
-
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
apache/hugegraph#3231 · 1 comment ·
Maintainers usually reply within 1 day
-
[Bug] Prometheus metrics format bugMay be free again @cui2022 claimed this 61 days ago, and no pull request is open. Openbug
Difficulty 2/5 1-3 hours Newbie friendliness 64/100
apache/hugegraph#3142 · 7 comments ·
Maintainers usually reply within 1 day
-
Difficulty 4/5 3-5 days Newbie friendliness 48/100
Maintainers usually reply within 1 day
-
Difficulty 5/5 Over a week Newbie friendliness 45/100
Maintainers usually reply within 1 day
-
[Bug] Basic auth decodes the credential as ASCII and splits on every colon: a non-ASCII password answers 401, a password with ':' answers 400Possibly taken @arshilkxwork claimed this 3 days ago. Open
Difficulty 1/5 Under an hour Newbie friendliness 35/100
apache/hugegraph#3284 · 1 comment ·
Maintainers usually reply within 1 day
All issues in apache/hugegraph
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 64/100
utopia-rise/godot-jvm#1004 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
resilience4j/resilience4j#2547 ·
Maintainers usually reply within 9 days
-
Clock.MakeDate continues execution and returns a rolled-over instant after dispatching error on invalid datePossibly taken A pull request linked to this issue is open or already merged. Open
Difficulty 1/5 Under an hour Newbie friendliness 82/100
mit-cml/appinventor-sources#4155 ·
Maintainers usually reply within 1 day
-
Difficulty 1/5 1-3 hours Newbie friendliness 62/100
Hira-shi/PW1-DAI-Carrel-Egal-Eyer#28 ·
Maintainers usually reply within 1 day
-
`GET /v1/event/token/{uuid}` can report a BOM upload as done before policy evaluation and metrics have finishedPossibly taken @Zargath claimed this today. Opendefect in triage
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
DependencyTrack/dependency-track#7646 ·
Maintainers usually reply within 1 day