Repository navigation
fix(git): fail closed on ref discovery checks - #411
Conversation
When upstream ref freshness cannot be verified, serving the local mirror can advertise stale commits. Proxy info/refs upstream on check errors while preserving stale fetches and successful-check caching.
An in-progress or failed freshness check is not evidence that local refs are current. Keep the cache invalid until both ref reads and comparison succeed so concurrent info/refs requests also fail closed.
|
🤖 The agent review exported a concurrency finding, but no GitHub review thread was published. I updated |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 68a760ef1b
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Protocol v2 ls-refs and overlapping checks could still advertise stale refs after a freshness failure or stale result. Treat ls-refs as discovery, invalidate stale check results, and keep clone integration coverage independent of GitHub availability.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 6ddfb58ae8
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Serve the fetch fixture from a local smart-HTTP repository so CI does not depend on external GitHub TLS trust or availability.
The assignment is self-explanatory, and removing its annotation keeps comments aligned with the repository convention.
Cachew could advertise stale refs from a local mirror when the upstream
ls-remotefreshness check failed. The same gap existed for protocol-v2ls-refs, and overlapping checks could leave a stale result cached as fresh. This matches the failure class observed in squareup/blox#3879, where GitHub had a newer commit while Cachew served an older one, without assuming multi-pod skew caused it.This change treats GET
info/refsand protocol-v2ls-refsas discovery requests. A freshness error proxies the request upstream. A stale result still proxies and schedules a background fetch. Only a completed successful check populates the 10-second cache, and a later stale result invalidates an overlapping success.Tests: