test: prove the rebased force-push shape is scanned correctly (#2573)

#2573: after `git rebase origin/main`, the feature branch's remote tip
still exists locally (the pre-rebase tip) but is no longer an ancestor of
HEAD, so the old `remoteSha..localSha` range swept in every upstream
commit rebased onto — 1.14 MiB scanned instead of 0.27 MiB on the
reported repo, tripping the engine's 1 MiB cap and blocking the push
with engine.input_too_large (a HIGH that meant "the engine never ran",
not a finding).

The catch-up-merge narrowing (`rev-list localSha --not remoteSha
--remotes`) covers this shape too: the upstream commits are reachable
from origin/main's remote-tracking ref, which exists by construction —
you cannot have rebased onto origin/main without it. No residual gap
found; this lands the proof alone, end-to-end through the actual hook
binary with the real pre-push stdin protocol:

- fixture sanity: the pre-rebase tip exists locally, is NOT an ancestor,
  and the OLD two-dot range would have swept in the upstream credential
- a clean rebased force-push passes — someone else's already-published
  HIGH-shaped fixture no longer blocks it
- coverage is not narrowed: a HIGH in a rebased commit of our own still
  blocks
- the scanned commit set is exactly the rebased own commits, so scan
  size is proportional to OUR work, not to how busy main was

Analyzed non-gap, recorded in the test header: upstream commits in NO
remote-tracking ref cannot arise from the standard flow — rebasing onto
origin/<branch> requires the tracking ref, and rebasing onto a purely
local branch means the "upstream" content was never published, so
scanning it is correct.

Fixes #2573

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Garry Tan
2026-08-16 10:02:33 -07:00
co-authored by Claude Fable 5
parent 4cc19e4712
commit 45fd8e2e3d
@@ -0,0 +1,154 @@
/**
* gstack-redact-prepush — the REBASED FORCE-PUSH shape (#2573).
*
* After `git rebase origin/main`, the remote tip of the feature branch still
* exists locally (it is the pre-rebase tip) but is no longer an ancestor of
* HEAD. The old `remoteSha..localSha` range therefore swept in every upstream
* commit rebased onto — content already published and already scanned when it
* reached the remote. Reported as #2573: a 23-commit branch rebased onto a
* main that advanced 23 commits scanned 1.14 MiB instead of 0.27 MiB, tripped
* the engine's 1 MiB cap, and blocked the push with engine.input_too_large —
* a HIGH that was the engine saying it never ran, not a finding.
*
* The catch-up-merge narrowing (`rev-list localSha --not remoteSha --remotes`)
* covers this shape too: the upstream commits are reachable from origin/main's
* remote-tracking ref, which exists by construction — you cannot have rebased
* onto origin/main without it. These tests PROVE that, end-to-end through the
* actual hook binary with the real pre-push stdin protocol, in both
* directions: upstream content is not re-scanned (a HIGH-shaped credential
* someone else already published does not block a clean rebased push), and
* narrowing does not narrow coverage (a HIGH in a rebased commit of our own
* still blocks).
*
* Analyzed non-gap, recorded for the next reader: a rebased force-push where
* the upstream commits sit in NO remote-tracking ref cannot arise from the
* standard flow — rebasing onto origin/<branch> requires the tracking ref,
* and rebasing onto a purely local branch means the "upstream" commits were
* never published, so scanning them is correct, not a false positive.
*/
import { describe, test, expect, beforeEach, afterEach } from "bun:test";
import * as fs from "fs";
import * as os from "os";
import * as path from "path";
import { spawnSync } from "child_process";
const PREPUSH = path.resolve(import.meta.dir, "..", "bin", "gstack-redact-prepush");
let repo: string;
let remote: string;
function git(args: string[], cwd = repo): string {
const r = spawnSync("git", args, { cwd, encoding: "utf8" });
if (r.status !== 0) throw new Error(`git ${args.join(" ")}\n${r.stderr}`);
return r.stdout?.trim() ?? "";
}
function commit(file: string, content: string, msg: string): string {
fs.mkdirSync(path.dirname(path.join(repo, file)), { recursive: true });
fs.writeFileSync(path.join(repo, file), content);
git(["add", file]);
git(["commit", "-q", "-m", msg]);
return git(["rev-parse", "HEAD"]);
}
function runHook(stdinLines: string): { code: number; stderr: string } {
const r = spawnSync("bun", [PREPUSH], {
cwd: repo,
input: Buffer.from(stdinLines),
encoding: "utf8",
env: { ...process.env },
});
return { code: r.status ?? 0, stderr: r.stderr ?? "" };
}
// Assembled at runtime so the LITERAL never appears in a pushed diff — the
// repo's own pre-push scanner (correctly) blocks live-format AWS key shapes.
const FAKE_AWS_KEY = ["AKIA", "1234567890ABCDEF"].join("");
/**
* Build the #2573 shape:
* 1. feature branch pushed → remote + tracking ref hold the pre-rebase tip
* 2. main advances with someone else's already-published HIGH-shaped
* fixture, pushed and fetched
* 3. feature rebases onto origin/main
* Returns the pre-rebase tip (what git hands the hook as remoteSha on the
* force-push) — it still EXISTS locally but is no longer an ancestor of HEAD.
*/
function buildRebasedForcePush(): { preRebaseTip: string } {
git(["checkout", "-q", "-b", "feature"]);
commit("mine.ts", "export const mine = 1;\n", "my clean work");
git(["push", "-q", "-u", "origin", "feature"]);
const preRebaseTip = git(["rev-parse", "HEAD"]);
// Someone else lands a HIGH-shaped placeholder on main. It is published:
// pushed to the remote, fetched into origin/main.
git(["checkout", "-q", "main"]);
commit("fixtures/foreign.txt", `key ${FAKE_AWS_KEY}\n`, "someone else's fixture");
git(["push", "-q", "origin", "main"]);
git(["fetch", "-q", "origin"]);
git(["checkout", "-q", "feature"]);
git(["rebase", "-q", "origin/main"]);
return { preRebaseTip };
}
beforeEach(() => {
repo = fs.mkdtempSync(path.join(os.tmpdir(), "prepush-rebase-"));
remote = fs.mkdtempSync(path.join(os.tmpdir(), "prepush-rebase-remote-"));
git(["init", "-q", "--bare", "-b", "main"], remote);
git(["init", "-q", "-b", "main"]);
git(["config", "user.email", "t@example.com"]);
git(["config", "user.name", "T"]);
commit("README.md", "seed\n", "seed");
git(["remote", "add", "origin", remote]);
git(["push", "-q", "-u", "origin", "main"]);
});
afterEach(() => {
fs.rmSync(repo, { recursive: true, force: true });
fs.rmSync(remote, { recursive: true, force: true });
});
describe("rebased force-push does not re-scan upstream commits (#2573)", () => {
test("fixture sanity: the old two-dot range WOULD have swept in the upstream credential", () => {
const { preRebaseTip } = buildRebasedForcePush();
// The rebased tip exists locally and is NOT an ancestor of HEAD — the
// exact condition #2573 identified as the untested third branch.
expect(git(["cat-file", "-t", preRebaseTip])).toBe("commit");
const isAncestor = spawnSync("git", ["merge-base", "--is-ancestor", preRebaseTip, "HEAD"], { cwd: repo });
expect(isAncestor.status).not.toBe(0);
// What the OLD range would scan: upstream's published fixture included.
const oldDiff = git(["diff", "--unified=0", `${preRebaseTip}..HEAD`]);
expect(oldDiff).toContain(FAKE_AWS_KEY);
});
test("a clean rebased force-push passes: the published upstream credential does not block", () => {
const { preRebaseTip } = buildRebasedForcePush();
const head = git(["rev-parse", "HEAD"]);
const { code, stderr } = runHook(`refs/heads/feature ${head} refs/heads/feature ${preRebaseTip}\n`);
expect(stderr).not.toContain("BLOCKED");
expect(code).toBe(0);
});
test("narrowing does not narrow coverage: a HIGH in a REBASED commit of our own still blocks", () => {
const { preRebaseTip } = buildRebasedForcePush();
commit("leak.txt", `key ${FAKE_AWS_KEY}\n`, "oops, my own leak");
const head = git(["rev-parse", "HEAD"]);
const { code, stderr } = runHook(`refs/heads/feature ${head} refs/heads/feature ${preRebaseTip}\n`);
expect(code).toBe(1);
expect(stderr).toContain("BLOCKED");
});
test("the scanned commit set is exactly the rebased own commits, none of upstream's", () => {
// Pin the range arithmetic itself (the #2573 measurement, in miniature):
// the narrowed set excludes every commit reachable from a remote-tracking
// ref, so the 1.14 MiB-vs-0.27 MiB pathology cannot recur — scan size is
// proportional to OUR commits, not to how busy main was.
const { preRebaseTip } = buildRebasedForcePush();
const narrowed = git(["rev-list", "HEAD", "--not", preRebaseTip, "--remotes"])
.split("\n").filter(Boolean);
expect(narrowed).toHaveLength(1); // the rebased copy of "my clean work"
const subject = git(["log", "-1", "--format=%s", narrowed[0]]);
expect(subject).toBe("my clean work");
});
});