Rebase Base Detection Mechanism in no-mistakes: How It Prevents Clobbering Changes

The rebase base detection mechanism in no-mistakes uses three synchronized checks—force-push detection, remote default branch advancement detection, and bundled local default commit detection—to block rebases that would silently overwrite upstream work.

The no-mistakes repository (kunchenguid/no-mistakes) implements a robust rebase base detection mechanism that protects Git workflows from accidentally clobbering upstream commits. When preparing to rebase a branch, the system runs three tightly-coupled validation checks in internal/pipeline/steps/rebase.go that analyze the relationship between local work, remote tracking branches, and the repository's default branch.

The Three-Layer Rebase Safety System

Force-Push Detection via isForcePushAgainstRemote

The isForcePushAgainstRemote function determines whether the current push is a non-fast-forward rewrite. It compares the previously observed baseSHA with the current HEAD and, when a branch name is known, verifies the remote branch tip.

If a force-push is detected, the rebase step skips syncing the push-branch tracking ref (lines 60-62) and uses a forcePushRebaseTargets list instead. This keeps the lease anchored to the old remote tip, preventing a stale-remote fast-path from overwriting new upstream commits.

Remote Default Branch Advancement Detection

The remoteDefaultBranchAdvanced function checks whether origin/<default> has moved since the pipeline run started by comparing it against the stored baseSHA. When the remote default has advanced and a force-push is detected on the default branch, the step returns a needs-approval outcome (lines 82-94) with a warning finding.

This forces human review before updating the default branch, ensuring out-of-band upstream changes are not lost.

Bundled Local Default Commit Detection

The detectBundledLocalDefaultCommits function examines the contributor's local default branch (refs/heads/<default>) to see if it is both ahead of origin/<default> and an ancestor of the current branch HEAD. When such commits exist, they would be bundled into the PR during rebase.

The function returns a needs-approval outcome (lines 71-80), prompting the user to push the local default branch or rebase onto the remote default first, preventing accidental inclusion of unrelated work.

How the Mechanism Prevents Clobbering

The rebase base detection mechanism prevents clobbering through lease anchoring and explicit human review gates. By refusing to silently fast-forward a force-push lease and surfacing any divergence as a blocking finding, the system protects both contributor and project history.

  • Force-push scenarios: Skips remote-tracking updates and requires explicit review for default-branch updates.
  • Remote divergence: Blocks rebase and asks for review when upstream changes are detected.
  • Hidden local work: Warns contributors and stops the pipeline when un-pushed local commits would be merged unintentionally.

Implementation in internal/pipeline/steps/rebase.go

The detection logic resides in the rebase step implementation:

// Force-push detection
forcePush := isForcePushAgainstRemote(
    ctx, sctx.WorkDir, pushRemote, branch,
    branchTarget, sctx.Run.BaseSHA,
)
if forcePush {
    // Skip fetching the push-branch tracking ref
    // and use force-push-specific rebase targets.
}

Source: rebase.go:48-66

if forcePush && branch == defaultBranch &&
   remoteDefaultBranchAdvanced(ctx, sctx.WorkDir, defaultBranch, sctx.Run.BaseSHA) {
    // Return a warning finding that requires manual review.
}

Source: rebase.go:82-95

if outcome := detectBundledLocalDefaultCommits(ctx, sctx, branch, defaultBranch); outcome != nil {
    return outcome, nil // abort rebase and request user action
}

Source: rebase.go:74-81

When blocked, the system returns structured findings:

{
  "findings": [
    {
      "severity": "warning",
      "file": "internal/pipeline/steps/rebase.go",
      "description": "origin/main advanced after the force push; manual review required before updating the default branch",
      "action": "ask-user"
    }
  ],
  "summary": "remote main advanced during force push"
}

Summary

  • The rebase base detection mechanism in no-mistakes runs three validation checks before allowing any rebase operation.
  • isForcePushAgainstRemote in internal/pipeline/steps/rebase.go identifies non-fast-forward pushes and adjusts lease anchoring to prevent overwriting remote changes.
  • remoteDefaultBranchAdvanced blocks default branch updates when upstream has moved, requiring manual approval.
  • detectBundledLocalDefaultCommits prevents accidental inclusion of unpushed local default branch work into pull requests.
  • Together, these checks ensure that rebases only proceed when safe, protecting upstream commit history from clobbering.

Frequently Asked Questions

What triggers the rebase base detection mechanism?

The mechanism triggers automatically during the rebase step when preparing to synchronize a branch. According to the no-mistakes source code, it evaluates the relationship between the current HEAD, the stored baseSHA, and remote tracking branches to determine if the rebase would be safe.

How does no-mistakes handle force-pushes differently than standard Git?

Unlike standard Git, no-mistakes detects force-pushes via isForcePushAgainstRemote and skips updating the push-branch tracking ref while using forcePushRebaseTargets. This keeps the lease anchored to the old remote tip, preventing automatic overwrites of new upstream commits that arrived during the force-push window.

What happens when the remote default branch advances during a force-push?

When remoteDefaultBranchAdvanced detects that origin/<default> has moved since the run started, it returns a needs-approval outcome with a warning finding. The pipeline stops and requires human review before proceeding, ensuring that out-of-band upstream changes are not lost during the rebase.

Can local commits on the default branch accidentally be included in a rebase?

The detectBundledLocalDefaultCommits function specifically checks for this scenario. If your local default branch (refs/heads/<default>) is ahead of the remote and an ancestor of your current branch, the pipeline returns a needs-approval outcome, prompting you to push the local default or rebase onto the remote default first, preventing hidden work from being bundled into the PR.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →