From 79d870d31ef8d39fe0abaa911de757ea35ead998 Mon Sep 17 00:00:00 2001 From: Matt Fisher Date: Wed, 7 Oct 2026 18:19:45 +1100 Subject: [PATCH] Lease the template-update push against the fetched branch A bare --force-with-lease to a URL has no remote-tracking ref to compare against, so the push is refused with "stale info" whenever the update branch already exists. Lease against the ref checkout fetched instead. Co-Authored-By: Claude Opus 5.5 --- .github/workflows/template-update.yml | 9 ++++++++- changelog.d/20261007_000000_template_update_push.md | 3 +++ 2 files changed, 11 insertions(+), 1 deletion(-) create mode 100644 changelog.d/20261007_000000_template_update_push.md diff --git a/.github/workflows/template-update.yml b/.github/workflows/template-update.yml index 3a20929..db8902c 100644 --- a/.github/workflows/template-update.yml +++ b/.github/workflows/template-update.yml @@ -135,7 +135,14 @@ jobs: git checkout -b "$BRANCH" git add -A git commit -m "chore: apply template updates from $REF" - git push --force-with-lease \ + # The push goes to a URL rather than to `origin`, so a bare + # --force-with-lease has no remote-tracking ref to compare against + # and refuses with "stale info" whenever the branch already exists, + # which is every week after a run that pushed but couldn't open its + # PR. Lease against what checkout fetched instead; empty means the + # branch must not exist yet. + expect=$(git rev-parse -q --verify "refs/remotes/origin/$BRANCH" || true) + git push --force-with-lease="$BRANCH:$expect" \ "https://x-access-token:${GH_TOKEN}@github.com/${GITHUB_REPOSITORY}.git" "$BRANCH" BODY="Applied by \`copier update --vcs-ref $REF\`." diff --git a/changelog.d/20261007_000000_template_update_push.md b/changelog.d/20261007_000000_template_update_push.md new file mode 100644 index 0000000..a7ce1fc --- /dev/null +++ b/changelog.d/20261007_000000_template_update_push.md @@ -0,0 +1,3 @@ +### Fixed + +- `template-update.yml` no longer fails every run once its update branch exists. It pushed with a bare `--force-with-lease` to a URL, which gives git no remote-tracking ref to lease against, so the push was refused with `stale info` whenever the branch was already there. A run that pushed the branch but couldn't open its PR (for example, before the Actions pull-request setting was on) left every later run failing. The push now leases against the branch as checkout fetched it, so it still refuses to overwrite a commit pushed during the run.