diff --git a/deploy/git-guard.sh b/deploy/git-guard.sh index ab0f622..0426ce1 100644 --- a/deploy/git-guard.sh +++ b/deploy/git-guard.sh @@ -5,10 +5,20 @@ # Behavior: # - Clean + up to date -> pass silently # - Clean + behind (ff-only) -> auto `git pull --ff-only`, then pass -# - Ahead only (unpushed) -> interactive: offer to push; non-interactive: BLOCK -# - Dirty tracked changes -> offer to commit + push right now -# (auto in non-interactive/CI runs, after a +# - Clean + ahead only -> interactive: offer to push; non-interactive: BLOCK +# (unpushed) +# - Unresolved merge conflict -> REFUSE immediately. Never auto-commits over +# markers present conflict markers. Prints remediation options. +# - Dirty + local in sync -> offer to commit + push right now +# with origin (auto in non-interactive/CI runs, after a # secret-pattern scan of the staged diff) +# - Dirty + local STALE/ -> NEVER commit on top of a stale base. Stash +# diverged vs origin the dirty changes first, resync main with +# origin using the same behind/ahead/diverged +# rules as the clean-tree case, then reapply +# the stash and re-run. On any failure the +# stash is preserved and remediation options +# (with exact commands) are printed. # - Diverged (local AND -> REFUSE. Never auto-resolves. Prints the # remote both moved) backup/stash/reset recovery steps and exits. # @@ -36,12 +46,246 @@ git status --porcelain | grep -q . && DIRTY=1 SECRET_PATTERN='(-----BEGIN [A-Z]+ PRIVATE KEY-----|AKIA[0-9A-Z]{16}|xox[baprs]-[0-9a-zA-Z-]+|password[[:space:]]*[:=][[:space:]]*[^$ ]|api[_-]?key[[:space:]]*[:=][[:space:]]*[^$ ])' +# resync_with_origin +# +# Handles the behind/ahead/diverged cases against a CLEAN working tree. +# Shared by both the "tree was already clean" path and the new +# "dirty tree turned out to be stale, so we stashed first" path, so the +# two paths can never drift out of sync with each other. +# +# Returns 0 if it's now safe to deploy, 1 if it could not safely resolve +# (guidance already printed to stdout in that case). +resync_with_origin() { + local local_sha="$1" remote_sha="$2" base_sha="$3" + + # ---- Case: fully in sync ---- + if [ "$local_sha" = "$remote_sha" ]; then + echo "==> In sync with origin/main ($local_sha). OK to deploy." + return 0 + fi + + # ---- Case: behind only (fast-forwardable) ---- + if [ "$local_sha" = "$base_sha" ]; then + echo "!! Local main is behind origin/main." + if [ "$INTERACTIVE" -eq 1 ]; then + read -rp "Fast-forward pull now? [y/N] " ans + else + ans="y" + echo "(non-interactive session — auto fast-forwarding)" + fi + if [[ "$ans" =~ ^[Yy]$ ]]; then + git pull --ff-only origin main + echo "==> Fast-forwarded to $(git rev-parse --short main). OK to deploy." + return 0 + else + echo "Aborting - pull manually, then retry:" + echo " cd $DIR && git pull --ff-only origin main" + return 1 + fi + fi + + # ---- Case: ahead only (local commits not yet pushed) ---- + if [ "$remote_sha" = "$base_sha" ]; then + echo "!! Local main is AHEAD of origin/main (unpushed commits):" + git log --oneline "origin/main..main" + echo + if [ "$INTERACTIVE" -eq 1 ]; then + read -rp "Push local commits to origin/main now? [y/N] " ans + else + ans="n" + echo "(non-interactive session — will NOT auto-push ahead commits; needs human review)" + fi + if [[ "$ans" =~ ^[Yy]$ ]]; then + git push origin main + echo "==> Pushed. OK to deploy." + return 0 + else + echo "Aborting. Review with:" + echo " cd $DIR && git log origin/main..main" + echo "Then push manually when ready:" + echo " git push origin main" + return 1 + fi + fi + + # ---- Case: true divergence (both ahead and behind) — NEVER auto-fix ---- + echo "!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!" + echo "!! DIVERGED: local main and origin/main have both moved independently." + echo "!!" + echo "!! Local-only commits:" + git log --oneline "$base_sha..main" | sed 's/^/!! /' + echo "!!" + echo "!! Remote-only commits:" + git log --oneline "$base_sha..origin/main" | sed 's/^/!! /' + echo "!!" + echo "!! This requires a human decision - git-guard will NOT auto-resolve this." + echo "!!" + echo "!! Before stashing anything new, check whether a git-guard safety stash" + echo "!! ALREADY exists from this same run (avoids confusing duplicate stashes):" + echo "!! git stash list" + echo "!!" + echo "!! Recommended recovery:" + echo "!! 1. tar backup: tar czf /volume1/docker/compose-files-backup-\$(date +%Y%m%d-%H%M%S).tar.gz -C /volume1/docker compose-files" + echo "!! 2. name the branch: git branch backup/pre-reset-\$(date +%Y%m%d)" + echo "!! 3. stash any NEW uncommitted state only if 'git stash list' above" + echo "!! didn't already show one for this run:" + echo "!! git stash push -u -m 'pre-reset-snapshot'" + echo "!! 4. reset to origin: git reset --hard origin/main" + echo "!! 5. selectively restore needed files from the stash/backup branch:" + echo "!! git stash list" + echo "!! git stash show -p stash@{N}" + echo "!! git stash apply stash@{N} # 'apply' keeps the stash as a backup; use 'pop' to also drop it" + echo "!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!" + return 1 +} + +# ---- Case: unresolved merge conflict already present ---- +# Can happen if a PRIOR git-guard run's `git stash pop` conflicted and the +# resulting conflict markers were never resolved before the next deploy +# attempt. Must be checked BEFORE the dirty-tree commit flow below, because +# an unmerged path shows up as "dirty" too, and `git add -A` would silently +# stage the literal <<<<<<< / ======= / >>>>>>> markers into a real commit. +if git ls-files -u | grep -q .; then + echo "ERROR: unresolved merge conflict markers present in the working tree." + echo "Refusing to auto-commit over a conflict — this would push literal" + echo "<<<<<<< / ======= / >>>>>>> markers to origin/main." + echo + echo "Conflicted paths:" + git diff --name-only --diff-filter=U | sed 's/^/ /' + echo + echo "Remediation options:" + echo " A) Resolve the conflict by hand, then commit and push:" + echo " cd $DIR" + echo " git status # see conflicted paths" + echo " git diff # inspect the conflict markers" + echo " \$EDITOR # remove markers, keep correct content" + echo " git add " + echo " git commit -m 'resolve git-guard stash-pop conflict'" + echo " git push origin main" + echo " B) Discard the conflicted merge attempt entirely and start clean from" + echo " origin/main, then decide separately whether to re-apply anything" + echo " from a prior safety stash:" + echo " cd $DIR" + echo " git checkout -- ." + echo " git reset --hard origin/main" + echo " git stash list # look for a git-guard-safety-stash-* entry" + echo " git stash show -p stash@{N} # inspect before deciding" + echo " C) Once resolved (via A or B) and no longer needed, clean up the stash:" + echo " git stash drop stash@{N}" + exit 1 +fi + # ---- Case: dirty tracked changes ---- if [ "$DIRTY" -eq 1 ]; then echo "!! WORKING TREE DIRTY — uncommitted changes detected:" git status --short echo + # If local is ALSO stale/diverged from origin, committing right now would + # create a doomed commit on top of a base that's about to be rejected on + # push (this is exactly what caused a real incident: a stray on-disk edit + # sat on a checkout that was 4 commits behind, git-guard auto-committed + # anyway, then the push bounced). Stash first, resync safely using the + # same rules as the clean-tree path, then reapply. + if [ "$LOCAL" != "$REMOTE" ]; then + echo "!! Local main is ALSO stale/diverged from origin/main." + echo " Refusing to commit on top of a stale base — stashing the dirty" + echo " changes safely first, then resyncing with origin." + echo + + STASH_MSG="git-guard-safety-stash-$(date -u +%Y%m%dT%H%M%SZ)" + if ! git stash push -u -m "$STASH_MSG"; then + echo "ERROR: 'git stash push' itself failed (disk full, permissions, or" + echo " some other git error). Your changes are still on disk," + echo " uncommitted — nothing has been lost, but git-guard cannot" + echo " proceed safely until this is resolved." + echo + echo "Remediation options:" + echo " A) Check disk space and permissions, then retry the deploy:" + echo " df -h $DIR" + echo " ls -la $DIR" + echo " B) Identify and manually move aside whatever is blocking the stash," + echo " then retry:" + echo " cd $DIR" + echo " git status --short # find the offending path(s)" + echo " mv .bak-\$(date +%s)" + echo " C) Inspect the raw git error above for specifics before proceeding." + exit 1 + fi + echo "==> Stashed as: $STASH_MSG" + + if resync_with_origin "$LOCAL" "$REMOTE" "$BASE"; then + echo "==> Resync succeeded. Reapplying stashed changes..." + if git stash pop; then + echo "==> Stash reapplied cleanly. Re-checking sync state..." + exec "$0" "$@" + else + echo "ERROR: 'git stash pop' did not complete successfully." + echo + if git ls-files -u | grep -q .; then + echo "This is a MERGE CONFLICT — your stashed changes were partially" + echo "applied and conflict markers (<<<<<<< / ======= / >>>>>>>) are now" + echo "in the working tree. The stash itself is still preserved as a backup." + echo + echo "Remediation options:" + echo " A) Resolve the conflict by hand, then commit and push:" + echo " cd $DIR" + echo " git status # see conflicted paths" + echo " git diff # inspect the markers" + echo " \$EDITOR # remove markers, keep correct content" + echo " git add " + echo " git commit -m 'resolve git-guard stash-pop conflict'" + echo " git push origin main" + echo " git stash list # confirm which entry is: $STASH_MSG" + echo " git stash drop stash@{N} # once confirmed no longer needed" + echo " B) Abandon this merge attempt and fall back to a clean, resynced" + echo " tree, then re-apply the change manually with full visibility:" + echo " cd $DIR" + echo " git checkout -- ." + echo " git reset --hard origin/main # now matches origin, no conflict" + echo " git stash list # find: $STASH_MSG" + echo " git stash show -p stash@{N} # review the content" + echo " git stash apply stash@{N} # 'apply' keeps the backup; use 'pop' to also drop it" + else + echo "This looks like an UNTRACKED-FILE COLLISION, not a merge conflict" + echo "(a file added upstream shares a path with an untracked file in your" + echo "stash). No conflict markers were written; the stash was NOT applied" + echo "and remains fully intact." + echo + echo "Remediation options:" + echo " A) Move the colliding upstream file aside, pop, then reconcile:" + echo " cd $DIR" + echo " git status --short # identify the colliding path" + echo " mv .upstream-\$(date +%s)" + echo " git stash pop" + echo " diff .upstream-* # reconcile manually, then remove the .upstream-* backup" + echo " B) Inspect the stash without applying, and hand-merge the needed" + echo " pieces instead:" + echo " git stash list # find N" + echo " git stash show -p stash@{N}" + fi + echo + echo "Your stash reference for this run: $STASH_MSG" + exit 1 + fi + else + echo "ERROR: could not safely resync with origin/main." + echo "Your uncommitted changes are preserved in the stash: $STASH_MSG" + echo + echo "Remediation options:" + echo " A) Follow the manual recovery steps printed above (from the" + echo " behind/ahead/diverged case), THEN reapply your change:" + echo " cd $DIR" + echo " git stash list # find: $STASH_MSG" + echo " git stash apply stash@{N} # or 'pop' to also drop it once resynced" + echo " B) If the stashed change is no longer needed (e.g. it's already" + echo " represented in a since-merged PR), verify then drop it:" + echo " git stash show -p stash@{N}" + echo " git stash drop stash@{N}" + exit 1 + fi + fi + if [ "$INTERACTIVE" -eq 1 ]; then read -rp "Commit and push these changes to origin/main now? [y/N] " ans else @@ -54,7 +298,8 @@ if [ "$DIRTY" -eq 1 ]; then if git diff --cached | grep -Eiq "$SECRET_PATTERN"; then echo "ERROR: possible secret detected in staged changes. Refusing to auto-commit." - echo "Review manually: git diff --cached" + echo "Review manually:" + echo " cd $DIR && git diff --cached" git reset exit 1 fi @@ -66,77 +311,22 @@ if [ "$DIRTY" -eq 1 ]; then exec "$0" "$@" else echo "ERROR: push failed (likely diverged from origin). Aborting deploy." - echo "Run: cd $DIR && git status" + echo "Run:" + echo " cd $DIR && git status" exit 1 fi else - echo "Aborting deploy - commit or stash changes manually, then retry." + echo "Aborting deploy - commit or stash changes manually, then retry:" + echo " cd $DIR" + echo " git add -A && git commit -m 'your message' && git push origin main" + echo " # or: git stash push -u -m 'manual-stash'" exit 1 fi fi -# ---- Case: fully in sync ---- -if [ "$LOCAL" = "$REMOTE" ]; then - echo "==> In sync with origin/main ($LOCAL). OK to deploy." +# ---- Clean tree: resync with origin using the shared logic above ---- +if resync_with_origin "$LOCAL" "$REMOTE" "$BASE"; then exit 0 +else + exit 1 fi - -# ---- Case: behind only (fast-forwardable) ---- -if [ "$LOCAL" = "$BASE" ]; then - echo "!! Local main is behind origin/main." - if [ "$INTERACTIVE" -eq 1 ]; then - read -rp "Fast-forward pull now? [y/N] " ans - else - ans="y" - echo "(non-interactive session — auto fast-forwarding)" - fi - if [[ "$ans" =~ ^[Yy]$ ]]; then - git pull --ff-only origin main - echo "==> Fast-forwarded to $(git rev-parse --short main). OK to deploy." - exit 0 - else - echo "Aborting deploy - pull manually, then retry." - exit 1 - fi -fi - -# ---- Case: ahead only (local commits not yet pushed) ---- -if [ "$REMOTE" = "$BASE" ]; then - echo "!! Local main is AHEAD of origin/main (unpushed commits):" - git log --oneline "origin/main..main" - echo - if [ "$INTERACTIVE" -eq 1 ]; then - read -rp "Push local commits to origin/main now? [y/N] " ans - else - ans="n" - echo "(non-interactive session — will NOT auto-push ahead commits; needs human review)" - fi - if [[ "$ans" =~ ^[Yy]$ ]]; then - git push origin main - echo "==> Pushed. OK to deploy." - exit 0 - else - echo "Aborting deploy. Review with: git log origin/main..main" - exit 1 - fi -fi - -# ---- Case: true divergence (both ahead and behind) — NEVER auto-fix ---- -echo "!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!" -echo "!! DIVERGED: local main and origin/main have both moved independently." -echo "!!" -echo "!! Local-only commits:" -git log --oneline "$BASE..main" | sed 's/^/!! /' -echo "!!" -echo "!! Remote-only commits:" -git log --oneline "$BASE..origin/main" | sed 's/^/!! /' -echo "!!" -echo "!! This requires a human decision - git-guard will NOT auto-resolve this." -echo "!! Recommended recovery:" -echo "!! 1. tar backup: tar czf /volume1/docker/compose-files-backup-\$(date +%Y%m%d-%H%M%S).tar.gz -C /volume1/docker compose-files" -echo "!! 2. name the branch: git branch backup/pre-reset-\$(date +%Y%m%d)" -echo "!! 3. stash all state: git stash push -u -m 'pre-reset-snapshot'" -echo "!! 4. reset to origin: git reset --hard origin/main" -echo "!! 5. selectively restore needed files from the stash/backup branch" -echo "!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!" -exit 1