mirror of
https://relay.ngit.dev/npub15qydau2hjma6ngxkl2cyar74wzyjshvl65za5k5rl69264ar2exs5cyejr/ngit-grasp.git
synced 2026-10-06 07:28:23 +00:00
A stale deletion still required a pending state after background promotion had already removed the ref. Rewriting its old OID to zero is unsafe: receive-pack can interpret that command as an unconditional deletion of a recreated ref. For fully satisfied unsigned pushes containing ordinary-ref deletions, retain normal repository and PR authorization, then verify all requested targets in one Git ref transaction. Verification checks absent refs and existing targets without issuing updates or deletes. Report success at that transaction point, respecting report-status/v2 and sideband framing, without unpacking redundant objects. Recreated or changed refs fail verification and remain untouched. Only fully satisfied requests take this path. Pushes making changes still use receive-pack; certificates, malformed and duplicate commands do not take the shortcut. This does not authorize new targets from stored state or objects. Validation: the deletion reproduction previously failed with missing purgatory authorization and now passes in ordinary and sideband status-v2 modes. The 949-test library suite and 202 selected Git integration tests passed; all four final completed-push tests pass, including ref recreation and companion-ref changes between inspection and verification. Strict all-target Clippy passed. Assisted-by: GPT-6