refs: refuse to write pseudorefs

Pseudorefs are not stored in the ref database as by definition, they carry additional metadata that essentially makes them not a ref. As such, writing pseudorefs via the ref backend does not make any sense whatsoever as the ref backend wouldn't know how exactly to store the data. Restrict writing pseudorefs via the ref backend. Signed-off-by: Patrick Steinhardt <ps@pks.im> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Patrick Steinhardt committed May 15, 2024 at 08:51 UTC 8e4f5c2dc26e8e88c8c4784f133d2b35a771d2ac
2 files changed +10 -3
refs.c
+7
@@ -1263,6 +1263,13 @@ int ref_transaction_update(struct ref_transaction *transaction,
1263 return -1;
1264 }
1265
1266 + if (!(flags & REF_SKIP_REFNAME_VERIFICATION) &&
1267 + is_pseudo_ref(refname)) {
1268 + strbuf_addf(err, _("refusing to update pseudoref '%s'"),
1269 + refname);
1270 + return -1;
1271 + }
1272 +
1273 if (flags & ~REF_TRANSACTION_UPDATE_ALLOWED_FLAGS)
1274 BUG("illegal flags 0x%x passed to ref_transaction_update()", flags);
1275
t/t5510-fetch.sh
+3 -3
@@ -518,7 +518,7 @@ test_expect_success 'fetch with a non-applying branch.<name>.merge' '
518 test_expect_success 'fetch from GIT URL with a non-applying branch.<name>.merge [1]' '
519 one_head=$(cd one && git rev-parse HEAD) &&
520 this_head=$(git rev-parse HEAD) &&
521 - git update-ref -d FETCH_HEAD &&
521 + rm .git/FETCH_HEAD &&
522 git fetch one &&
523 test $one_head = "$(git rev-parse --verify FETCH_HEAD)" &&
524 test $this_head = "$(git rev-parse --verify HEAD)"
@@ -530,7 +530,7 @@ test_expect_success 'fetch from GIT URL with a non-applying branch.<name>.merge
530 one_ref=$(cd one && git symbolic-ref HEAD) &&
531 git config branch.main.remote blub &&
532 git config branch.main.merge "$one_ref" &&
533 - git update-ref -d FETCH_HEAD &&
533 + rm .git/FETCH_HEAD &&
534 git fetch one &&
535 test $one_head = "$(git rev-parse --verify FETCH_HEAD)" &&
536 test $this_head = "$(git rev-parse --verify HEAD)"
@@ -540,7 +540,7 @@ test_expect_success 'fetch from GIT URL with a non-applying branch.<name>.merge
540 # the merge spec does not match the branch the remote HEAD points to
541 test_expect_success 'fetch from GIT URL with a non-applying branch.<name>.merge [3]' '
542 git config branch.main.merge "${one_ref}_not" &&
543 - git update-ref -d FETCH_HEAD &&
543 + rm .git/FETCH_HEAD &&
544 git fetch one &&
545 test $one_head = "$(git rev-parse --verify FETCH_HEAD)" &&
546 test $this_head = "$(git rev-parse --verify HEAD)"