The hotfix that is running nowhere in Git INC-2391

Open2 versionsGit · Hard · Incident · about 50 min ·Linux

Lab machine

A private Linux machine with the problem already set up. Sessions last up to 60 minutes.
Priya Raman opened INC-2391 at 10:00SEV-3

Production runs the 2.5.1 hotfix. Git has no record of it: a force-push yesterday wiped the commit from main, and v2.5.1 was never tagged.

An auditor asks a simple question: which source code is production running? Today nobody can answer it from Git.

"And please, no more force-pushes. Ivo's runbook commit is on main now, and it stays." (Priya)

The running image is the only thing that still knows what it was built from.

Your task

Recover the hotfix commit, tag it with an annotated v2.5.1, bring it into main without losing later work, push normally, and record commit and digest in RELEASES.md. Do not redeploy anything.

On the machine

  • deploy/fleet.json and the image's revision label
  • ci/runner-17/ (the runner that built the hotfix)
  • origin.git (git fsck --unreachable)
  • RELEASES.md

Timeline

Tue 22:10Ivo builds hotfix 2.5.1 on CI runner 17 and deploys it.
Wed 09:12Teo force-pushes main to undo a broken merge. The hotfix commit goes with it.
Wed 09:30Ivo pushes a runbook commit on top.
10:00Audit: "Which commit is production running?"

Done when

  1. An annotated v2.5.1 tag on the remote names the hotfix commit.
  2. RELEASES.md links v2.5.1 to its commit and the running image's digest.
  3. Main on the remote keeps Ivo's runbook commit and gains the hotfix, with no force-push and no moved tags.

Hints

Hint 1

Start from what runs: `bin/deployctl status`, then `bin/registry inspect` the digest and read the revision label.

Hint 2

That commit is not in `work/`. Did another clone check it out recently? If not, a bare repository keeps objects nobody points to for a while.

Hint 3

`git fsck --unreachable` in `origin.git` lists commits no ref points to. A branch on one of them makes it fetchable.

Hint 4

Tag with `git tag -a`, merge into main without rewriting it, then `git push origin main v2.5.1`.

Show the solution

Read the running digest's revision label to get the hotfix commit. Find a copy of it: in the CI runner's checkout (`ci/runner-17/workspace`) if it still exists, or as an unreachable object in `origin.git` (`git -C origin.git fsck --unreachable`), where a temporary branch makes it fetchable. Bring it into `work/`, create an annotated `v2.5.1` tag on it, merge it into `main` so Ivo's runbook commit stays, and push `main` and the tag normally. Record the commit and digest under v2.5.1 in RELEASES.md. A force-push in either direction loses someone's work again.