git: git_create_branch is marked non-destructive but silently resets an existing packed branch
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 2/5
- 見積もり時間
- 1〜3時間
- 初心者へのやさしさ
- 85/100
調査の方向性
src/git/src/mcp_server_git/server.py を起点にする:git_create_branch ハンドラー(L183-L195 あたり)とそのアノテーションブロック(L396-L404)。issue の pack-refs 用スクラッチリポジトリで問題を再現し、その後 repo.create_head の前に既存ブランチのチェックを追加して、packed refs が拒否されるようにする(または明示的な force 引数の背後でガードする)。そして destructiveHint をそれに合わせて調整する。packed ブランチが黙って移動されなくなり、git サーバーのテストが通ることで完了。
索引モデルが issue の本文から書いたものです。
説明
Summary
git_create_branch is annotated destructiveHint: false, but if a branch with the requested name already exists as a packed ref (as after git gc, git pack-refs, or in a fresh clone), the call silently moves that branch to the new base. The previous tip becomes unreachable from every ref, and no reflog entry records the reset. git branch <name> on the CLI would refuse.
Where
- Annotation:
src/git/src/mcp_server_git/server.py#L396-L404. - Handler calls
repo.create_head(branch_name, base)without checking whether the branch exists:server.py#L183-L195. - GitPython only refuses to overwrite an existing loose ref file, so a packed ref is overwritten.
Reproduce
- In a scratch repo: create
main, then a branchfeaturewith one extra commit, and rungit pack-refs --all. - Start the git server on that repo.
- Call
git_create_branchwith{"repo_path": "<repo>", "branch_name": "feature", "base_branch": "main"}. - The call reports
Created branch 'feature' from 'main';featurenow points atmain, its previous commit is unreachable, andgit reflog show featurehas no entry for the move.
Why it matters
MCP clients relax confirmation for tools that declare destructiveHint: false, so this call can be auto-approved, and it can discard commits.
Possible fix
Check for an existing branch (loose or packed) and return an error, or require an explicit force argument, matching the git CLI. While a force path exists, destructiveHint: true would be accurate.
Found during an audit of MCP tool annotations (AI-assisted source review, then reproduced locally). Happy to send a PR.
- 主要言語
- TypeScript
- スター
- 91k
- フォーク
- 11.8k
- 平均マージ
- 6時間 33分
- マージ済み PR(30日)
- 79
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートあり
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
modelcontextprotocol/servers のほかの issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
modelcontextprotocol/servers#5071 · コメント 2 件 ·
メンテナーはふだん 1 日以内に返信
-
mcp-server-fetch: `fetch` prompt returns JSON-RPC error code 0 with the raw exception text for an invalid URL再び着手できるかも このイシューのプルリクエストはマージされずにクローズされました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
modelcontextprotocol/servers#4914 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
CLAUDE.md: tool-naming rule (kebab-case) disagrees with filesystem and memory servers対応中かも @liang0417 が 9 日前に担当しました。 オープン
難易度 1/5 1時間未満 初心者へのやさしさ 92/100
modelcontextprotocol/servers#4892 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
Filesystem README recommends deprecated MCP Roots protocol for restricting directory access対応中かも @its-amann が 14 日前に担当しました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 76/100
modelcontextprotocol/servers#4844 ·
メンテナーはふだん 1 日以内に返信
-
Docs: `fetch` installs npm packages during a tool call, which is worth stating for deployments対応中かも @teddiesloco が 18 日前に担当しました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
modelcontextprotocol/servers#4830 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
modelcontextprotocol/servers の issue をすべて見る
似ている issue
-
area: backend bug priority: low
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
snapotter-hq/SnapOtter#2254 ·
メンテナーはふだん 1 日以内に返信
-
bug ticket
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
cratestack/cratestack#1154 ·
メンテナーはふだん 1 日以内に返信
-
server 消息处理器 cmd 分支补显式错误回报——竞态非法命令现走未处理拒绝対応中かも @openaddr が今日担当しました。 オープンready-for-agent refactor wayfinder:task
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
openaddr/dafung-web#428 ·
メンテナーはふだん 1 日以内に返信
-
Flaky: mongodb-memory-server 'Port already in use' when another process starts a mongod concurrentlyオープンarea:testing bug effort:S priority:P2
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
メンテナーはふだん 1 日以内に返信
-
lens:agent lens:process process
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
thebristolsound/birdbrain#1772 ·
メンテナーはふだん 1 日以内に返信