commit: warn when a new commit is dated before its parent - #2226
Conversation
Git writes whatever the clock says into the commit object and validates nothing: a commit dated years in the future, or earlier than its own parent, is accepted silently. "git fsck --strict" does not object either, since fsck's badDate and badDateOverflow checks are purely syntactic. That would be harmless if history traversal did not assume commit dates are non-decreasing, but it does. "git log --since" stops walking at the first commit older than the cutoff, so a single out-of-order date hides every commit behind it: $ git log --pretty='%cd %s' --date=short 2026-09-25 C3 - inside the window 2026-09-01 C2 - outside the window 2026-09-20 C1 - inside the window $ git log --pretty='%cd %s' --date=short --since=2026-09-13 2026-09-25 C3 - inside the window C1 is inside the window and silently missing. This is understood -- 9669778 (revision: add "--since-as-filter" option, 2022-07-19) added an opt-in traversal mode for it -- but nothing tells the person whose clock caused it, at the moment they could still fix it cheaply. Warn at commit time when the new commit's date precedes a parent's, gated on a new advice.clockSkew setting. Warning rather than refusing is deliberate: only the committer can tell whether their clock or the parent's is the wrong one. Once the commit is published the date is part of its object name, and correcting it means rewriting every descendant, so the warning is worth little later and quite a lot now. The check looks at the commit being created and its parents and nothing else. Skew between different machines is ordinary in a distributed system and is not something to complain about; this fires only when one repository's own history steps backwards. It is limited to git commit -- merges and replayed history go through other paths, where non-monotonic dates are often legitimate. A warning along these lines has been suggested more than once without landing; see for instance the discussion around clock skew in <CA+55aFw_XjWm+4XwsN6CRJnsrcEu5YEChOHSHN51UUBN6PynWw@mail.gmail.com>. Signed-off-by: ysai258 <ysaimuppineni789@gmail.com> Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Welcome to GitGitGadgetHi @ysai258, and welcome to GitGitGadget, the GitHub App to send patch series to the Git mailing list from GitHub Pull Requests. Please make sure that either:
You can CC potential reviewers by adding a footer to the PR description with the following syntax: NOTE: DO NOT copy/paste your CC list from a previous GGG PR's description, Also, it is a good idea to review the commit messages one last time, as the Git project expects them in a quite specific form:
It is in general a good idea to await the automated test ("Checks") in this Pull Request before contributing the patches, e.g. to avoid trivial issues such as unportable code. Contributing the patchesBefore you can contribute the patches, your GitHub username needs to be added to the list of permitted users. Any already-permitted user can do that, by adding a comment to your PR of the form Both the person who commented An alternative is the channel Once on the list of permitted usernames, you can contribute the patches to the Git mailing list by adding a PR comment If you want to see what email(s) would be sent for a After you submit, GitGitGadget will respond with another comment that contains the link to the cover letter mail in the Git mailing list archive. Please make sure to monitor the discussion in that thread and to address comments and suggestions (while the comments and suggestions will be mirrored into the PR by GitGitGadget, you will still want to reply via mail). If you do not want to subscribe to the Git mailing list just to be able to respond to a mail, you can download the mbox from the Git mailing list archive (click the curl -g --user "<EMailAddress>:<Password>" \
--url "imaps://imap.gmail.com/INBOX" -T /path/to/raw.txtTo iterate on your change, i.e. send a revised patch or patch series, you will first want to (force-)push to the same branch. You probably also want to modify your Pull Request description (or title). It is a good idea to summarize the revision by adding something like this to the cover letter (read: by editing the first comment on the PR, i.e. the PR description): To send a new iteration, just add another PR comment with the contents: Need help?New contributors who want advice are encouraged to join git-mentoring@googlegroups.com, where volunteers who regularly contribute to Git are willing to answer newbie questions, give advice, or otherwise provide mentoring to interested contributors. You must join in order to post or view messages, but anyone can join. You may also be able to find help in real time in the developer IRC channel, |
|
This is an RFC. A warning of this shape has been suggested several times over the years without landing, so I would rather hear whether the idea is wanted at all before polishing it. The problemGit writes whatever the clock says and validates nothing. A commit dated years in the future, or earlier than its own parent, is accepted silently, and That would be harmless if history traversal did not assume commit dates are non-decreasing, but it does: C1 is inside the window and silently missing, because I hit this on a repository of my own after moving the system clock to test date-dependent behaviour. Nothing warned me, and by the time I noticed, the dates were part of the object names. What this doesWarns at commit time when the new commit's date precedes a parent's, gated on a new Scope, deliberately narrow
Open questions for reviewers
Tests are in |
|
@ysai258 you will want to move the rationale back into the first comment, which will be sent as a "cover letter" (for single-patch contributions such as yours, the rationale is inserted between the diffstat and the diff). Many of the frequent reviewers like their Git mailing list so much that they will be angry if you try to lead them elsewhere. I am not condoning that behavior, but I want to set you up for success by avoiding that preventable friction. Also, to mark it as an RFC, simply use GitHub's "Convert to draft" function before |
|
/allow |
Hrm. That failed. But interestingly, https://www.githubstatus.com/ says:
|
|
User ysai258 is now allowed to use GitGitGadget. WARNING: ysai258 has no public email address set on GitHub; GitGitGadget needs an email address to Cc: you on your contribution, so that you receive any feedback on the Git mailing list. Go to https://github.com/settings/profile to make your preferred email public to let GitGitGadget know which email address to use. |


RFC. Adds an
advice.clockSkewwarning whengit commitcreates a commit dated earlier than one of its parents, which usually means the system clock is wrong and can makegit log --sincesilently skip commits.Rationale, scope and open questions are in the commit message and this comment.