fix(run): refuse an auto-detected branch that is not on the remote - #266
Merged
Merged
Conversation
`rafter run` scans the remote repository, but when it auto-detected the current local branch it never checked that the branch had been pushed. The scan was queued and then failed on the backend minutes later. When both repo and branch come from the local checkout, ask origin with `git ls-remote --exit-code --heads`. If the remote answers without the branch, exit 1 with a message to push it or pass --branch. If origin cannot be reached, proceed as before. If the pushed commit differs from local HEAD, note that the scan covers the pushed commit. Explicit --branch and CI-provided branches are unchanged. Same behavior in the Node and Python CLIs, each with a test against a real local bare remote.
This was referenced Oct 2, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
rafter runscans the remote repository.When it auto-detects the current local branch, it never checked that the branch had been pushed, so a scan of an unpushed branch was queued and then failed on the backend with branch-not-found.
This is common for coding agents that run rafter on a task branch before pushing it.
When both repo and branch come from the local checkout (origin remote + current
HEAD), both CLIs now rungit ls-remote --exit-code --heads origin refs/heads/<branch>(15 s timeout, no credential prompt):1with "push the branch first, or pass --branch"HEAD: a one-line note that the scan covers the pushed commitAn explicit
--repo/--branchand CI-provided branches (GITHUB_REF_NAME,CI_COMMIT_BRANCH,CI_BRANCH) are unchanged.Exit code
1(general error) is used rather than2, which the remote-command exit-code contract reserves for "scan not found".CLI_SPEC documents the check.
Tests
node/tests/remote-branch.test.tsandpython/tests/test_git_utils.py::test_remote_branch_sha_tells_unpushed_from_pushed_and_unreachable: real git against a local bare origin, checking pushed (SHA), unpushed (absent) and unreachable origin (unknown)._do_remote_scantests that mock an auto-detected repo now also stub the lookup so they stay off the network.Manual check from an unpushed branch of this repo: the published 0.10.5 CLIs (Node and Python) submit the scan; this branch exits 1 with the message before any API call.
From a local branch whose name exists on the remote, the build notes the pushed commit and submits.
tscclean. Python suite: 1754 passed, 1 skipped. Node suite: 2275 passed; the 3 Cursor hook tests that fail also fail onmainin a local checkout and are unrelated.