runMRMerge:UpdateRefCAS(mr.go:1099) thenMarkMerged(:1102). If the second fails the branch has moved and the MR stays open; a retry refuses at:897because the target already contains the head.runRepoFork:CreateRepothenSetForkOf(mr.go:103-109); a failure leaves a repo row without a directory.runRepoTransfer: the revert atrepo.go:388, :393ignores its own error.checkRepoQuota(repo.go:191) thenCreateRepois check-then-act with no lock.
Remedy: make MarkMerged idempotent when the head is already an ancestor of the target; put SetForkOf inside CreateRepo's transaction.
closed by commit 84e1f08f23 by cmc: control: no write sequence leaves a half state
2026-09-04 01:17 UTC