# Rebase Base Detection Mechanism in no-mistakes: How It Prevents Clobbering Changes

> Discover how the rebase base detection mechanism in no-mistakes prevents clobbering changes with three synchronized checks. Protect your work from accidental overwrites.

- Repository: [Kun Chen/no-mistakes](https://github.com/kunchenguid/no-mistakes)
- Tags: internals
- Published: 2026-07-13

---

**The rebase base detection mechanism in `no-mistakes` uses three synchronized checks—force-push detection, remote default branch advancement detection, and bundled local default commit detection—to block rebases that would silently overwrite upstream work.**

The `no-mistakes` repository (kunchenguid/no-mistakes) implements a robust rebase base detection mechanism that protects Git workflows from accidentally clobbering upstream commits. When preparing to rebase a branch, the system runs three tightly-coupled validation checks in [`internal/pipeline/steps/rebase.go`](https://github.com/kunchenguid/no-mistakes/blob/main/internal/pipeline/steps/rebase.go) that analyze the relationship between local work, remote tracking branches, and the repository's default branch.

## The Three-Layer Rebase Safety System

### Force-Push Detection via `isForcePushAgainstRemote`

The `isForcePushAgainstRemote` function determines whether the current push is a non-fast-forward rewrite. It compares the previously observed `baseSHA` with the current `HEAD` and, when a branch name is known, verifies the remote branch tip.

If a force-push is detected, the rebase step **skips syncing the push-branch tracking ref** (lines 60-62) and uses a `forcePushRebaseTargets` list instead. This keeps the lease anchored to the old remote tip, preventing a stale-remote fast-path from overwriting new upstream commits.

### Remote Default Branch Advancement Detection

The `remoteDefaultBranchAdvanced` function checks whether `origin/<default>` has moved since the pipeline run started by comparing it against the stored `baseSHA`. When the remote default has advanced and a force-push is detected on the default branch, the step returns a *needs-approval* outcome (lines 82-94) with a warning finding.

This forces human review before updating the default branch, ensuring out-of-band upstream changes are not lost.

### Bundled Local Default Commit Detection

The `detectBundledLocalDefaultCommits` function examines the contributor's local default branch (`refs/heads/<default>`) to see if it is both ahead of `origin/<default>` and an ancestor of the current branch HEAD. When such commits exist, they would be bundled into the PR during rebase.

The function returns a *needs-approval* outcome (lines 71-80), prompting the user to push the local default branch or rebase onto the remote default first, preventing accidental inclusion of unrelated work.

## How the Mechanism Prevents Clobbering

The rebase base detection mechanism prevents clobbering through **lease anchoring** and explicit human review gates. By refusing to silently fast-forward a force-push lease and surfacing any divergence as a blocking finding, the system protects both contributor and project history.

- **Force-push scenarios**: Skips remote-tracking updates and requires explicit review for default-branch updates.
- **Remote divergence**: Blocks rebase and asks for review when upstream changes are detected.
- **Hidden local work**: Warns contributors and stops the pipeline when un-pushed local commits would be merged unintentionally.

## Implementation in [`internal/pipeline/steps/rebase.go`](https://github.com/kunchenguid/no-mistakes/blob/main/internal/pipeline/steps/rebase.go)

The detection logic resides in the rebase step implementation:

```go
// Force-push detection
forcePush := isForcePushAgainstRemote(
    ctx, sctx.WorkDir, pushRemote, branch,
    branchTarget, sctx.Run.BaseSHA,
)
if forcePush {
    // Skip fetching the push-branch tracking ref
    // and use force-push-specific rebase targets.
}

```

*Source*: [`rebase.go:48-66`](https://github.com/kunchenguid/no-mistakes/blob/main/internal/pipeline/steps/rebase.go#L48-L66)

```go
if forcePush && branch == defaultBranch &&
   remoteDefaultBranchAdvanced(ctx, sctx.WorkDir, defaultBranch, sctx.Run.BaseSHA) {
    // Return a warning finding that requires manual review.
}

```

*Source*: [`rebase.go:82-95`](https://github.com/kunchenguid/no-mistakes/blob/main/internal/pipeline/steps/rebase.go#L82-L95)

```go
if outcome := detectBundledLocalDefaultCommits(ctx, sctx, branch, defaultBranch); outcome != nil {
    return outcome, nil // abort rebase and request user action
}

```

*Source*: [`rebase.go:74-81`](https://github.com/kunchenguid/no-mistakes/blob/main/internal/pipeline/steps/rebase.go#L74-L81)

When blocked, the system returns structured findings:

```json
{
  "findings": [
    {
      "severity": "warning",
      "file": "internal/pipeline/steps/rebase.go",
      "description": "origin/main advanced after the force push; manual review required before updating the default branch",
      "action": "ask-user"
    }
  ],
  "summary": "remote main advanced during force push"
}

```

## Summary

- The rebase base detection mechanism in `no-mistakes` runs three validation checks before allowing any rebase operation.
- `isForcePushAgainstRemote` in [`internal/pipeline/steps/rebase.go`](https://github.com/kunchenguid/no-mistakes/blob/main/internal/pipeline/steps/rebase.go) identifies non-fast-forward pushes and adjusts lease anchoring to prevent overwriting remote changes.
- `remoteDefaultBranchAdvanced` blocks default branch updates when upstream has moved, requiring manual approval.
- `detectBundledLocalDefaultCommits` prevents accidental inclusion of unpushed local default branch work into pull requests.
- Together, these checks ensure that rebases only proceed when safe, protecting upstream commit history from clobbering.

## Frequently Asked Questions

### What triggers the rebase base detection mechanism?

The mechanism triggers automatically during the rebase step when preparing to synchronize a branch. According to the `no-mistakes` source code, it evaluates the relationship between the current `HEAD`, the stored `baseSHA`, and remote tracking branches to determine if the rebase would be safe.

### How does `no-mistakes` handle force-pushes differently than standard Git?

Unlike standard Git, `no-mistakes` detects force-pushes via `isForcePushAgainstRemote` and skips updating the push-branch tracking ref while using `forcePushRebaseTargets`. This keeps the lease anchored to the old remote tip, preventing automatic overwrites of new upstream commits that arrived during the force-push window.

### What happens when the remote default branch advances during a force-push?

When `remoteDefaultBranchAdvanced` detects that `origin/<default>` has moved since the run started, it returns a *needs-approval* outcome with a warning finding. The pipeline stops and requires human review before proceeding, ensuring that out-of-band upstream changes are not lost during the rebase.

### Can local commits on the default branch accidentally be included in a rebase?

The `detectBundledLocalDefaultCommits` function specifically checks for this scenario. If your local default branch (`refs/heads/<default>`) is ahead of the remote and an ancestor of your current branch, the pipeline returns a *needs-approval* outcome, prompting you to push the local default or rebase onto the remote default first, preventing hidden work from being bundled into the PR.