Require git proof before prune deletes a branch
A merged or closed PR no longer authorises a delete on its own: HEAD must be contained in the PR's head commit or in origin/<branch>, otherwise the worktree goes and the branch stays. Branch deletion runs `git branch -d` first and falls back to -D only for a proven branch. Reword the cherry check to say patches reached the default branch's history, print the verdict --keep-branches will actually perform, and warn when a PR listing hits the pagination cap instead of reading it as "no PR".
This commit is contained in:
+58
-24
@@ -29,6 +29,9 @@ type pruneResult struct {
|
||||
wt managedWt
|
||||
verdict string
|
||||
reason string
|
||||
// proven records that git itself confirmed the branch's commits survive
|
||||
// elsewhere; only then may a branch delete override git's own guard.
|
||||
proven bool
|
||||
}
|
||||
|
||||
// repoCtx is the per-repo state classification is decided against.
|
||||
@@ -105,7 +108,7 @@ func runPrune(out io.Writer, prs prLister, apply, keepBranches bool) error {
|
||||
}
|
||||
|
||||
for _, r := range results {
|
||||
_, _ = fmt.Fprintf(out, "%-44s %-34s %-14s %s\n", filepath.Base(r.wt.path), r.wt.branch, r.verdict, r.reason)
|
||||
_, _ = fmt.Fprintf(out, "%-44s %-34s %-14s %s\n", filepath.Base(r.wt.path), r.wt.branch, plannedVerdict(r, keepBranches), r.reason)
|
||||
}
|
||||
if !apply {
|
||||
_, _ = fmt.Fprintln(out, "dry run: nothing removed (pass --yes to apply)")
|
||||
@@ -118,13 +121,22 @@ func runPrune(out io.Writer, prs prLister, apply, keepBranches bool) error {
|
||||
continue
|
||||
}
|
||||
deleteBranch := r.verdict == verdictRemoveBranch && !keepBranches
|
||||
if err := removeWorktree(out, r.wt, deleteBranch); err != nil {
|
||||
if err := removeWorktree(out, r.wt, deleteBranch, r.proven); err != nil {
|
||||
errs = append(errs, fmt.Errorf("%s: %w", r.wt.path, err))
|
||||
}
|
||||
}
|
||||
return errors.Join(errs...)
|
||||
}
|
||||
|
||||
// plannedVerdict is what will actually happen, so --keep-branches does not
|
||||
// print a branch deletion it will not perform.
|
||||
func plannedVerdict(r pruneResult, keepBranches bool) string {
|
||||
if keepBranches && r.verdict == verdictRemoveBranch {
|
||||
return verdictRemove
|
||||
}
|
||||
return r.verdict
|
||||
}
|
||||
|
||||
// newRepoCtx refreshes a source repo and collects the signals prune classifies
|
||||
// against. A failed fetch or an unreachable Gitea is reported and tolerated:
|
||||
// the git-only signals still work offline.
|
||||
@@ -144,12 +156,17 @@ func newRepoCtx(out io.Writer, prs prLister, srcDir string) (repoCtx, error) {
|
||||
return ctx, nil
|
||||
}
|
||||
list, err := prs.ListPRs(repoPath(srcDir, repo), "all")
|
||||
if err != nil {
|
||||
switch {
|
||||
case errors.Is(err, agent.ErrPRListTruncated):
|
||||
// A branch missing from a partial listing must not read as "no PR".
|
||||
_, _ = fmt.Fprintf(out, "warn: list PRs for %s: %v (older PRs unseen)\n", repo, err)
|
||||
ctx.prs = prsByBranch(list)
|
||||
case err != nil:
|
||||
_, _ = fmt.Fprintf(out, "warn: list PRs for %s: %v (git signals only)\n", repo, err)
|
||||
return ctx, nil
|
||||
default:
|
||||
ctx.prs = prsByBranch(list)
|
||||
ctx.prsKnown = true
|
||||
}
|
||||
ctx.prs = prsByBranch(list)
|
||||
ctx.prsKnown = true
|
||||
return ctx, nil
|
||||
}
|
||||
|
||||
@@ -192,9 +209,21 @@ func supersedes(a, b agent.PullRequest) bool {
|
||||
return a.Number > b.Number
|
||||
}
|
||||
|
||||
// headContainedIn reports whether the worktree's HEAD is reachable from ref. A
|
||||
// ref that cannot be resolved proves nothing, so it reads as not contained.
|
||||
func headContainedIn(dir, ref string) bool {
|
||||
if ref == "" {
|
||||
return false
|
||||
}
|
||||
ok, err := agent.GitIsAncestor(dir, "HEAD", ref)
|
||||
return err == nil && ok
|
||||
}
|
||||
|
||||
// classify applies the prune precedence: dirty and open-PR worktrees are kept,
|
||||
// provably-upstream work loses its branch too, and anything unproven keeps its
|
||||
// branch so no commits become unreachable.
|
||||
// branch so no commits become unreachable. A PR's state alone never authorises
|
||||
// deleting a branch — git must confirm HEAD is contained in what merged or in
|
||||
// what origin still holds.
|
||||
func classify(wt managedWt, ctx repoCtx) (pruneResult, error) {
|
||||
res := pruneResult{wt: wt}
|
||||
dirty, err := agent.GitIsDirty(wt.path)
|
||||
@@ -218,7 +247,7 @@ func classify(wt managedWt, ctx repoCtx) (pruneResult, error) {
|
||||
return res, err
|
||||
}
|
||||
if contained {
|
||||
res.verdict, res.reason = verdictRemoveBranch, "contained in "+upstream
|
||||
res.verdict, res.reason, res.proven = verdictRemoveBranch, "contained in "+upstream, true
|
||||
return res, nil
|
||||
}
|
||||
unmerged, err := agent.GitUnmergedCommits(wt.path, upstream, "HEAD")
|
||||
@@ -226,25 +255,30 @@ func classify(wt managedWt, ctx repoCtx) (pruneResult, error) {
|
||||
return res, err
|
||||
}
|
||||
if unmerged == 0 {
|
||||
res.verdict, res.reason = verdictRemoveBranch, "cherry-clean against "+upstream
|
||||
// git cherry proves the patches reached that history, not that they stand at its tip.
|
||||
res.verdict, res.reason, res.proven = verdictRemoveBranch, "patch-equivalent commits in "+upstream+" history", true
|
||||
return res, nil
|
||||
}
|
||||
if hasPR && pr.Merged {
|
||||
res.verdict, res.reason = verdictRemoveBranch, fmt.Sprintf("PR merged #%d", pr.Number)
|
||||
return res, nil
|
||||
}
|
||||
if hasPR {
|
||||
if agent.GitRemoteBranchExists(ctx.srcDir, "origin", wt.branch) {
|
||||
res.verdict, res.reason = verdictRemoveBranch, fmt.Sprintf("PR closed #%d, branch on origin", pr.Number)
|
||||
return res, nil
|
||||
}
|
||||
|
||||
remote := "origin/" + wt.branch
|
||||
onOrigin := hasPR && agent.GitRemoteBranchExists(ctx.srcDir, "origin", wt.branch)
|
||||
switch {
|
||||
case hasPR && pr.Merged && headContainedIn(wt.path, pr.Head.Sha):
|
||||
res.verdict, res.reason, res.proven = verdictRemoveBranch, fmt.Sprintf("PR merged #%d, HEAD contained in the merged head", pr.Number), true
|
||||
case hasPR && pr.Merged && onOrigin && headContainedIn(wt.path, remote):
|
||||
res.verdict, res.reason, res.proven = verdictRemoveBranch, fmt.Sprintf("PR merged #%d, HEAD contained in %s", pr.Number, remote), true
|
||||
case hasPR && pr.Merged:
|
||||
res.verdict, res.reason = verdictRemove, fmt.Sprintf("PR merged #%d, local commits not in the merged head", pr.Number)
|
||||
case hasPR && onOrigin && headContainedIn(wt.path, remote):
|
||||
res.verdict, res.reason, res.proven = verdictRemoveBranch, fmt.Sprintf("PR closed #%d, HEAD contained in %s", pr.Number, remote), true
|
||||
case hasPR && onOrigin:
|
||||
res.verdict, res.reason = verdictRemove, fmt.Sprintf("PR closed #%d, local commits not on %s", pr.Number, remote)
|
||||
case hasPR:
|
||||
res.verdict, res.reason = verdictRemove, fmt.Sprintf("PR closed #%d, branch gone", pr.Number)
|
||||
return res, nil
|
||||
}
|
||||
res.verdict = verdictRemove
|
||||
res.reason = "no PR"
|
||||
if !ctx.prsKnown {
|
||||
res.reason = "PR state unknown"
|
||||
case ctx.prsKnown:
|
||||
res.verdict, res.reason = verdictRemove, "no PR"
|
||||
default:
|
||||
res.verdict, res.reason = verdictRemove, "PR state unknown"
|
||||
}
|
||||
return res, nil
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user