Skip to content

commit: warn when a new commit is dated before its parent - #2226

Open
ysai258 wants to merge 1 commit into
gitgitgadget:masterfrom
ysai258:advice-clock-skew
Open

commit: warn when a new commit is dated before its parent#2226
ysai258 wants to merge 1 commit into
gitgitgadget:masterfrom
ysai258:advice-clock-skew

Conversation

@ysai258

@ysai258 ysai258 commented Sep 13, 2026

Copy link
Copy Markdown

RFC. Adds an advice.clockSkew warning when git commit creates a commit dated earlier than one of its parents, which usually means the system clock is wrong and can make git log --since silently skip commits.

Rationale, scope and open questions are in the commit message and this comment.

Git writes whatever the clock says into the commit object and validates
nothing: a commit dated years in the future, or earlier than its own
parent, is accepted silently. "git fsck --strict" does not object either,
since fsck's badDate and badDateOverflow checks are purely syntactic.

That would be harmless if history traversal did not assume commit dates
are non-decreasing, but it does. "git log --since" stops walking at the
first commit older than the cutoff, so a single out-of-order date hides
every commit behind it:

	$ git log --pretty='%cd %s' --date=short
	2026-09-25 C3 - inside the window
	2026-09-01 C2 - outside the window
	2026-09-20 C1 - inside the window

	$ git log --pretty='%cd %s' --date=short --since=2026-09-13
	2026-09-25 C3 - inside the window

C1 is inside the window and silently missing. This is understood --
9669778 (revision: add "--since-as-filter" option, 2022-07-19) added
an opt-in traversal mode for it -- but nothing tells the person whose
clock caused it, at the moment they could still fix it cheaply.

Warn at commit time when the new commit's date precedes a parent's, gated
on a new advice.clockSkew setting. Warning rather than refusing is
deliberate: only the committer can tell whether their clock or the
parent's is the wrong one. Once the commit is published the date is part
of its object name, and correcting it means rewriting every descendant,
so the warning is worth little later and quite a lot now.

The check looks at the commit being created and its parents and nothing
else. Skew between different machines is ordinary in a distributed system
and is not something to complain about; this fires only when one
repository's own history steps backwards. It is limited to git commit --
merges and replayed history go through other paths, where non-monotonic
dates are often legitimate.

A warning along these lines has been suggested more than once without
landing; see for instance the discussion around clock skew in
<CA+55aFw_XjWm+4XwsN6CRJnsrcEu5YEChOHSHN51UUBN6PynWw@mail.gmail.com>.

Signed-off-by: ysai258 <ysaimuppineni789@gmail.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gitgitgadget

gitgitgadget Bot commented Sep 13, 2026

Copy link
Copy Markdown

Welcome to GitGitGadget

Hi @ysai258, and welcome to GitGitGadget, the GitHub App to send patch series to the Git mailing list from GitHub Pull Requests.

Please make sure that either:

  • Your Pull Request has a good description, if it consists of multiple commits, as it will be used as cover letter.
  • Your Pull Request description is empty, if it consists of a single commit, as the commit message should be descriptive enough by itself.

You can CC potential reviewers by adding a footer to the PR description with the following syntax:

CC: Revi Ewer <revi.ewer@example.com>, Ill Takalook <ill.takalook@example.net>

NOTE: DO NOT copy/paste your CC list from a previous GGG PR's description,
because it will result in a malformed CC list on the mailing list. See
example.

Also, it is a good idea to review the commit messages one last time, as the Git project expects them in a quite specific form:

  • the lines should not exceed 76 columns,
  • the first line should be like a header and typically start with a prefix like "tests:" or "revisions:" to state which subsystem the change is about, and
  • the commit messages' body should be describing the "why?" of the change.
  • Finally, the commit messages should end in a Signed-off-by: line matching the commits' author.

It is in general a good idea to await the automated test ("Checks") in this Pull Request before contributing the patches, e.g. to avoid trivial issues such as unportable code.

Contributing the patches

Before you can contribute the patches, your GitHub username needs to be added to the list of permitted users. Any already-permitted user can do that, by adding a comment to your PR of the form /allow. A good way to find other contributors is to locate recent pull requests where someone has been /allowed:

Both the person who commented /allow and the PR author are able to /allow you.

An alternative is the channel #git-devel on the Libera Chat IRC network:

<newcontributor> I've just created my first PR, could someone please /allow me? https://github.com/gitgitgadget/git/pull/12345
<veteran> newcontributor: it is done
<newcontributor> thanks!

Once on the list of permitted usernames, you can contribute the patches to the Git mailing list by adding a PR comment /submit.

If you want to see what email(s) would be sent for a /submit request, add a PR comment /preview to have the email(s) sent to you. You must have a public GitHub email address for this. Note that any reviewers CC'd via the list in the PR description will not actually be sent emails.

After you submit, GitGitGadget will respond with another comment that contains the link to the cover letter mail in the Git mailing list archive. Please make sure to monitor the discussion in that thread and to address comments and suggestions (while the comments and suggestions will be mirrored into the PR by GitGitGadget, you will still want to reply via mail).

If you do not want to subscribe to the Git mailing list just to be able to respond to a mail, you can download the mbox from the Git mailing list archive (click the (raw) link), then import it into your mail program. If you use GMail, you can do this via:

curl -g --user "<EMailAddress>:<Password>" \
    --url "imaps://imap.gmail.com/INBOX" -T /path/to/raw.txt

To iterate on your change, i.e. send a revised patch or patch series, you will first want to (force-)push to the same branch. You probably also want to modify your Pull Request description (or title). It is a good idea to summarize the revision by adding something like this to the cover letter (read: by editing the first comment on the PR, i.e. the PR description):

Changes since v1:
- Fixed a typo in the commit message (found by ...)
- Added a code comment to ... as suggested by ...
...

To send a new iteration, just add another PR comment with the contents: /submit.

Need help?

New contributors who want advice are encouraged to join git-mentoring@googlegroups.com, where volunteers who regularly contribute to Git are willing to answer newbie questions, give advice, or otherwise provide mentoring to interested contributors. You must join in order to post or view messages, but anyone can join.

You may also be able to find help in real time in the developer IRC channel, #git-devel on Libera Chat. Remember that IRC does not support offline messaging, so if you send someone a private message and log out, they cannot respond to you. The scrollback of #git-devel is archived, though.

@ysai258

ysai258 commented Sep 13, 2026

Copy link
Copy Markdown
Author

This is an RFC. A warning of this shape has been suggested several times over the years without landing, so I would rather hear whether the idea is wanted at all before polishing it.

The problem

Git writes whatever the clock says and validates nothing. A commit dated years in the future, or earlier than its own parent, is accepted silently, and git fsck --strict does not object either — badDate and badDateOverflow are purely syntactic checks.

That would be harmless if history traversal did not assume commit dates are non-decreasing, but it does:

$ git log --pretty='%cd %s' --date=short
2026-09-25 C3 - inside the window
2026-09-01 C2 - outside the window
2026-09-20 C1 - inside the window

$ git log --pretty='%cd %s' --date=short --since=2026-09-13
2026-09-25 C3 - inside the window

C1 is inside the window and silently missing, because --since stops walking at C2. This is understood — 9669778 (revision: add "--since-as-filter" option, 2022-07-19) added an opt-in traversal mode for exactly it — but nothing tells the person whose clock caused the problem, at the point where it is still cheap to fix.

I hit this on a repository of my own after moving the system clock to test date-dependent behaviour. Nothing warned me, and by the time I noticed, the dates were part of the object names.

What this does

Warns at commit time when the new commit's date precedes a parent's, gated on a new advice.clockSkew.

hint: the new commit is dated 2026-09-13 06:00:00 +0530,
hint: which is earlier than its parent, dated 2026-09-25 10:00:00 +0000.
hint: This usually means the system clock is wrong.
hint: Commands that walk history in date order, such as
hint: "git log --since", may skip commits as a result.
hint: Disable this message with "git config set advice.clockSkew false"

Scope, deliberately narrow

  • Warn, never refuse. Only the committer can tell whether their clock or the parent's is wrong.
  • The commit being created and its parents, nothing else. Skew between machines is ordinary in a distributed system. This fires only when one repository's own history steps backwards.
  • git commit only. Merges and replayed history go through other paths, where non-monotonic dates are frequently legitimate. I took this to be the lesson of the objection to checking every incoming commit on the receive side.

Open questions for reviewers

  1. Is this wanted at all? Several people have concluded over the years that it is a good idea, and equally that it may not be worth the effort.
  2. Is hint: the right channel? There is a fair objection that stderr advice gets buried among progress output.
  3. Should fsck grow an INFO-tier check for the "far ahead of now" case as well? That cannot compare against parents — fsck_commit() deliberately never loads parent objects — so it would be a separate, weaker check.

Tests are in t7502; t7502, t7501, t7500 and t0018 all pass.

@dscho

dscho commented Sep 13, 2026

Copy link
Copy Markdown
Member

@ysai258 you will want to move the rationale back into the first comment, which will be sent as a "cover letter" (for single-patch contributions such as yours, the rationale is inserted between the diffstat and the diff). Many of the frequent reviewers like their Git mailing list so much that they will be angry if you try to lead them elsewhere. I am not condoning that behavior, but I want to set you up for success by avoiding that preventable friction.

Also, to mark it as an RFC, simply use GitHub's "Convert to draft" function before /submiting. (And you might want to test first via /preview, which will send the email only to you, even if the email you receive should claim the Git mailing list to be in Cc:.)

@dscho

dscho commented Sep 13, 2026

Copy link
Copy Markdown
Member

/allow

@dscho

dscho commented Sep 13, 2026

Copy link
Copy Markdown
Member

/allow

Hrm. That failed. But interestingly, https://www.githubstatus.com/ says:

GitHub status claims there are no issues... tsk, tsk

@dscho

dscho commented Sep 13, 2026

Copy link
Copy Markdown
Member

I tried to re-run, but...
re-running results in a server error
GitHub Status still says everything's dandy.

@gitgitgadget

gitgitgadget Bot commented Sep 13, 2026

Copy link
Copy Markdown

User ysai258 is now allowed to use GitGitGadget.

WARNING: ysai258 has no public email address set on GitHub; GitGitGadget needs an email address to Cc: you on your contribution, so that you receive any feedback on the Git mailing list. Go to https://github.com/settings/profile to make your preferred email public to let GitGitGadget know which email address to use.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants