Repository navigation
mismatched-author checks a merge commit's identity at pre-merge-commit - #304
Conversation
|
Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 21 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configuration
📒 Files selected for processing (5)
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (5)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe ChangesAuthor identity checks
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Bug fix · Severity of issue fixed: Medium Merge Risk: ⚪ Minimal · up to The merge-commit identity check has no identified merge-blocking issue. Run the reported tests as part of normal validation before merging. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #304 +/- ##
=======================================
Coverage 94.10% 94.10%
=======================================
Files 46 46
Lines 21025 21025
=======================================
Hits 19786 19786
Misses 1239 1239 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
A non-fast-forward `git merge`, and a `git pull` that merges, records a commit without running `pre-commit`; git runs `pre-merge-commit` instead. With the set at one stage, a merge under a bot identity passed in `-c user.*` or `GIT_AUTHOR_*` / `GIT_COMMITTER_*` was recorded and nothing looked. The set's ceiling and the rule's hooks are now `pre-commit` and `pre-merge-commit`, and the comment names both moments. A conflicted merge is concluded by `git commit` and was already covered at `pre-commit`. No engine change: the guard already parses the stage and dispatches the rule there, and `git var` in the merge hook resolves the identity the merge commit records. The set lock is regenerated and REFERENCE.md names the new stage. guard_cli holds that `uphold guard --stage pre-merge-commit` refuses a bot identity in the environment and passes the global one. base_sets_cli runs a real `git merge --no-ff` through a `pre-merge-commit` hook in a repository inheriting the set: under a bot `-c user.*` and under bot `GIT_*` variables it is refused and HEAD does not move, and as the global identity it records a two-parent commit. The two refusals fail against the one-stage set. A consumer that already lists `uphold-guard-merge` needs no policy change. Closes #305
e738762 to
09a667b
Compare
No engine change since 1.25.1; one bundled set widens. mismatched-author now runs at `pre-merge-commit` as well as `pre-commit`. A non-fast-forward `git merge`, or a `git pull` that merges, records a commit without running `pre-commit`, so a merge under a bot identity passed in `-c user.*` or `GIT_AUTHOR_*` / `GIT_COMMITTER_*` was recorded with nothing looking. The set's ceiling and the rule's hooks are now both stages, and the set lock is regenerated (#304). A consumer taking the pin to v1.26.0 that inherits mismatched-author and runs the `pre-merge-commit` guard (the `uphold-guard-merge` hook, or the lefthook manifest) is now refused a merge commit recorded under an identity the rule rejects, where it passed. Such a consumer needs no policy change; record the merge as the global identity.
A non-fast-forward
git merge, and agit pullthat merges, records a commit without runningpre-commit; git runspre-merge-commitinstead. Withmismatched-authorat one stage, a merge under an identity passed in-c user.*orGIT_AUTHOR_*/GIT_COMMITTER_*was recorded unchecked.policy/base/mismatched-author.toml:[set] stagesand the rule'sgit.hooksare["pre-commit", "pre-merge-commit"]; the comment names both moments, and notes that a conflicted merge is concluded bygit commitand was already covered.policy/base/sets.lock.jsonregenerated withcargo run --quiet -- rules --sets --json.docs/REFERENCE.md: the set's row says it installspre-commitandpre-merge-commit.Tests:
tests/guard_cli.rs:uphold guard --stage pre-merge-commitrefuses a bot identity inGIT_AUTHOR_*/GIT_COMMITTER_*, and passes the global one (and says the guard ran).tests/base_sets_cli.rs: a realgit merge --no-ffthrough apre-merge-commithook in a repository inheriting the set is refused under a bot-c user.*and under botGIT_*variables, with HEAD unchanged, and as the global identity records a two-parent commit. Both refusals fail against the one-stage set.every_guard_set_declares_the_stages_its_rules_installandtests/base_set_lock.rspass.A consumer that already lists
uphold-guard-mergeneeds no policy change.Closes #305
Summary by CodeRabbit