git: git_create_branch is marked non-destructive but silently resets an existing packed branch
I maintainer di solito rispondono entro 1 giorno
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 2/5
- Tempo stimato
- 1-3 ore
- Idoneità per principianti
- 85/100
Direzione di ricerca
Parti da src/git/src/mcp_server_git/server.py: l'handler git_create_branch (intorno a L183-L195) e il suo blocco di annotazione (L396-L404). Riproduci il problema con il repo temporaneo pack-refs dell'issue, quindi aggiungi un controllo del branch esistente prima di repo.create_head in modo che i ref packati vengano rifiutati (o autorizzati tramite un argomento force esplicito), e regola di conseguenza destructiveHint. L'issue è risolta quando un branch packato non viene più spostato silenziosamente e i test del server git passano.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Summary
git_create_branch is annotated destructiveHint: false, but if a branch with the requested name already exists as a packed ref (as after git gc, git pack-refs, or in a fresh clone), the call silently moves that branch to the new base. The previous tip becomes unreachable from every ref, and no reflog entry records the reset. git branch <name> on the CLI would refuse.
Where
- Annotation:
src/git/src/mcp_server_git/server.py#L396-L404. - Handler calls
repo.create_head(branch_name, base)without checking whether the branch exists:server.py#L183-L195. - GitPython only refuses to overwrite an existing loose ref file, so a packed ref is overwritten.
Reproduce
- In a scratch repo: create
main, then a branchfeaturewith one extra commit, and rungit pack-refs --all. - Start the git server on that repo.
- Call
git_create_branchwith{"repo_path": "<repo>", "branch_name": "feature", "base_branch": "main"}. - The call reports
Created branch 'feature' from 'main';featurenow points atmain, its previous commit is unreachable, andgit reflog show featurehas no entry for the move.
Why it matters
MCP clients relax confirmation for tools that declare destructiveHint: false, so this call can be auto-approved, and it can discard commits.
Possible fix
Check for an existing branch (loose or packed) and return an error, or require an explicit force argument, matching the git CLI. While a force path exists, destructiveHint: true would be accurate.
Found during an audit of MCP tool annotations (AI-assisted source review, then reproduced locally). Happy to send a PR.
- Lingua principale
- TypeScript
- Stelle
- 91k
- Fork
- 11.8k
- Merge medio
- 6h 33m
- PR unite (30g)
- 79
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Ha un modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di modelcontextprotocol/servers
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
modelcontextprotocol/servers#5071 ·
I maintainer di solito rispondono entro 1 giorno
-
mcp-server-fetch: `fetch` prompt returns JSON-RPC error code 0 with the raw exception text for an invalid URLForse di nuovo libera Una pull request per questa issue è stata chiusa senza essere unita. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
modelcontextprotocol/servers#4914 ·
I maintainer di solito rispondono entro 1 giorno
-
CLAUDE.md: tool-naming rule (kebab-case) disagrees with filesystem and memory serversForse già presa @liang0417 l’ha presa 9 giorni fa. Aperta
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 92/100
modelcontextprotocol/servers#4892 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
Filesystem README recommends deprecated MCP Roots protocol for restricting directory accessForse già presa @its-amann l’ha presa 14 giorni fa. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
modelcontextprotocol/servers#4844 ·
I maintainer di solito rispondono entro 1 giorno
-
Docs: `fetch` installs npm packages during a tool call, which is worth stating for deploymentsForse già presa @teddiesloco l’ha presa 18 giorni fa. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
modelcontextprotocol/servers#4830 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di modelcontextprotocol/servers
Issue simili
-
[bug] diagnostics.dumpBody:Buffer 形态请求(透传 lane)跳过 dumps/ 落盘,仅留 raw/-unknown-Forse già presa @ranxianglei l’ha presa oggi. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 62/100
ranxianglei/billion-context#2421 · 2 commenti ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
platformatic/mcp#216 ·
I maintainer di solito rispondono entro 1 giorno
-
pending triage
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
nuxt/test-utils#1842 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
MoonshotAI/kimi-code#4146 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
farbenmeer/tapi#531 ·