misc/git_hook: reject pushes that add large files

Add a large blob check to the pre-push hook, using the same git tree
diff logic as corp's check-file-size CI workflow (the
check-git-accidental-large-file GitHub Action): diff the pushed tree
against the remote's old tree (or the merge base with the remote's
default branch for new refs) and reject any new or changed blob over
1.5 MB. Unlike the CI check, which only guards PRs into main, the hook
runs before pushing to any branch, catching mistakes before they
permanently bloat the remote repo.

Set TS_SKIP_LARGE_FILE_CHECK=1 to push a large file intentionally,
mirroring the skip-large-file-check commit message tag honored by CI.

This folds the go.mod replace check and the new check into a single
CheckPrePush entry point so both share one read of the hook's stdin;
corp's git-hook.go needs the matching call site update when it next
bumps its tailscale.com dependency.

Updates tailscale/corp#9863

Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>
Change-Id: I1c8cf2a277ce854d45c0ea809bed7c06b3295374
This commit is contained in:
Brad Fitzpatrick
2026-07-24 08:22:19 -07:00
committed by Brad Fitzpatrick
parent b062abb1ea
commit 8c98d2a417
5 changed files with 238 additions and 17 deletions
+9 -1
View File
@@ -22,6 +22,11 @@ import (
"tailscale.com/misc/git_hook/githook"
)
// maxPushBlobSize is the largest new or changed blob allowed in a
// push. It matches the 1.5 MB limit enforced by the check-file-size CI
// workflow. Set TS_SKIP_LARGE_FILE_CHECK=1 to override.
const maxPushBlobSize = 1_500_000
var pushRemotes = []string{
"git@github.com:tailscale/tailscale",
"git@github.com:tailscale/tailscale.git",
@@ -51,7 +56,10 @@ func main() {
case "commit-msg":
err = githook.AddChangeID(args)
case "pre-push":
err = githook.CheckGoModReplaces(args, pushRemotes, nil)
err = githook.CheckPrePush(args, githook.PrePushConfig{
WatchedRemotes: pushRemotes,
MaxBlobSize: maxPushBlobSize,
})
}
if err != nil {
log.Fatalf("git-hook: %v: %v", cmd, err)