gh stack init silently recreates an existing branch from trunk (instead of adopting it) when only a remote-tracking ref exists, and submit force-pushes over the real branch, destroying its history and closing its PR
@skarim 已經在處理了。
開始於 2026年9月2日。
評估
這個 Issue 還沒有評估資料。
描述
Environment
- gh-stack v0.1.0
- gh 2.97.0
- git 2.50.1
- macOS
Summary
gh stack init <branch> treats a branch as "new" (and creates it fresh from trunk) if no local branch of that exact name exists — even when a remote-tracking ref for it does exist, with real commits and an open PR behind it. gh stack submit then force-pushes that empty, trunk-tip branch over the real remote branch, silently deleting its commits and causing GitHub to auto-close its PR (empty diff → nothing to merge).
Root cause (traced in source)
internal/git/gitops.goBranchExistscallsclient.HasLocalBranch(...)— it never checksrefs/remotes/<remote>/<name>.cmd/init.go'sresolveArgBranchestreats "not found locally" as "doesn't exist," and runsgit.CreateBranch(name, parent)(parent = trunk for the bottom-most branch) — i.e.git branch <name> <trunk>, discarding any relationship to the real branch/PR of the same name.- The success message still prints "Adopted N branches" regardless of whether a branch was actually adopted or freshly (and destructively) created — no warning is shown.
cmd/submit.go:227then unconditionally force-pushes every branch (git.Push(..., force=true, ...), using--force-with-leaseunder the hood) — the lease only guards against a concurrent change by someone else, not against gh-stack pushing an unrelated commit on purpose.
Repro
feature-xexists onoriginwith real commits and an open PR, based onmain.- Without ever creating a local branch named
feature-x, branch off it under a different name:git checkout -b my-work origin/feature-x. gh stack init feature-x my-work→ prints "Adopted 2 branches" but actually rangit branch feature-x mainforfeature-x.gh stack submit→ force-pushes the emptyfeature-xtoorigin, wiping its real commits. GitHub auto-closesfeature-x's PR since the diff is now empty.
Impact
Silent, unwarned history loss on a shared branch with real, reviewed work behind it. In our case the original commits happened to still be reachable via another local branch built on top before the incident, so we could restore them — anyone without that would have lost the work (short of GitHub's own object retention).
Suggested fix
Before classifying a branch as new in init, also check for a remote-tracking ref (or fetch first); if one exists, create the local branch from it (git branch <name> <remote>/<name> or equivalent) instead of from trunk. Separately, submit/push force-pushing should sanity-check that it isn't collapsing a branch's diff to zero relative to what's currently on the remote, or at minimum surface a loud warning before doing so.
- 主要語言
- Go
- 星號
- 1.5k
- 分支
- 73
- 平均合併
- 13 小時 24 分鐘
- 30 天內合併 PR
- 3
環境準備
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
github/gh-stack 的其他 Issue
-
難度 2/5 1-3 小時 新手友好度 85/100
-
難度 1/5 1 小時以內 新手友好度 92/100
-
feature request topic: cli - general
難度 2/5 1-3 小時 新手友好度 68/100
-
feature request topic: auto-merge
難度 2/5 1-3 小時 新手友好度 68/100
-
bug topic: docs
難度 1/5 1 小時以內 新手友好度 68/100
相似的 Issue
-
security
難度 2/5 1-3 小時 新手友好度 68/100
-
cvss-severity:high devguard l3montree-cybersecurity/...ard-k8s-image-inventory pkg:oci/devguard-k8s-ima...ch=amd64&tag=main-amd64 pkg:oci/devguard-k8s-ima...ch=arm64&tag=main-arm64 risk:low state:open
難度 1/5 1 小時以內 新手友好度 76/100
l3montree-dev/devguard#3094 · 1 則留言 ·
維護者通常 1 天內回覆
-
難度 1/5 1 小時以內 新手友好度 84/100
JuliusBrussee/caveman#1127 · 1 則留言 ·
維護者通常 1 天內回覆
-
enhancement low priority
難度 2/5 1-3 小時 新手友好度 85/100
eugenioenko/ttt#674 ·
維護者通常 1 天內回覆
-
kind/bug
難度 2/5 1-3 小時 新手友好度 86/100
gpustack/gpustack-operator#640 ·
維護者通常 1 天內回覆