{"thread":{"id":"13607","subject":"Restricting access to a branch","startedAt":"2008-05-21T23:36:16Z","lastAt":"2008-05-22T08:16:50Z","messageCount":5,"participants":["Stephen Hemminger","Junio C Hamano","Linus Torvalds","Jakub Narebski"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"77428","messageId":"20080521163616.31fad56f@extreme","threadId":"13607","inReplyTo":null,"subject":"Restricting access to a branch","fromName":"Stephen Hemminger","fromEmail":"shemminger@vyatta.com","sentAt":"2008-05-21T23:36:16Z","receivedAt":"2008-05-21T23:36:16Z","isPatch":false,"sender":{"key":"shemminger@vyatta.com","avatar":null},"body":"Is there some standard way to freeze a branch and not allow anymore changes to\nbe pushed?\n\nYes, I know it is possible by playing with hook files, but that doesn't seem\nvery admin friendly.\n"},{"id":"77431","messageId":"7vhccrxkdm.fsf@gitster.siamese.dyndns.org","threadId":"13607","inReplyTo":"20080521163616.31fad56f@extreme","subject":"Re: Restricting access to a branch","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2008-05-22T00:17:25Z","receivedAt":"2008-05-22T00:17:25Z","isPatch":false,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Stephen Hemminger <shemminger@vyatta.com> writes:\n\n> Is there some standard way to freeze a branch and not allow anymore changes to\n> be pushed?\n>\n> Yes, I know it is possible by playing with hook files, but that doesn't seem\n> very admin friendly.\n\nIf you do not want to use hooks, then the answer is no.  Sorry.\n"},{"id":"77432","messageId":"alpine.LFD.1.10.0805211732520.3081@woody.linux-foundation.org","threadId":"13607","inReplyTo":"7vhccrxkdm.fsf@gitster.siamese.dyndns.org","subject":"Re: Restricting access to a branch","fromName":"Linus Torvalds","fromEmail":"torvalds@linux-foundation.org","sentAt":"2008-05-22T00:37:20Z","receivedAt":"2008-05-22T00:37:20Z","isPatch":false,"sender":{"key":"torvalds@linux-foundation.org","avatar":"https://avatars.githubusercontent.com/u/1024025?v=4"},"body":"\n\nOn Wed, 21 May 2008, Junio C Hamano wrote:\n\n> Stephen Hemminger <shemminger@vyatta.com> writes:\n> \n> > Is there some standard way to freeze a branch and not allow anymore changes to\n> > be pushed?\n> >\n> > Yes, I know it is possible by playing with hook files, but that doesn't seem\n> > very admin friendly.\n> \n> If you do not want to use hooks, then the answer is no.  Sorry.\n\nHmm. I don't think that's strictly true.\n\nWhat you *can* do is:\n\n - rename the branch to something that includes a slash (aka \n   subdirectory). Let's call it \"frozen/mybranch\" as an example.\n\n - do a 'git gc' to make sure that branch is in the packed refs file.\n\n - make the subdirectory of that branch is unwritable (ie just do \n   something like \"chmod -w refs/heads/frozen\")\n\nand now the filesystem permissions should mean that you can't actually \nupdate that branch any more, even though you can read it.\n\nOf course, if the person has full shell access, then they can still just \nundo those file permissions, but at least it should be protected from \naccidentally being overwritten.\n\nThis is all totally untested, of course.\n\n\t\tLinus\n"},{"id":"77441","messageId":"7v63t7xgdg.fsf@gitster.siamese.dyndns.org","threadId":"13607","inReplyTo":"alpine.LFD.1.10.0805211732520.3081@woody.linux-foundation.org","subject":"Re: Restricting access to a branch","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2008-05-22T01:43:55Z","receivedAt":"2008-05-22T01:43:55Z","isPatch":false,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Linus Torvalds <torvalds@linux-foundation.org> writes:\n\n> What you *can* do is:\n>\n>  - rename the branch to something that includes a slash (aka \n>    subdirectory). Let's call it \"frozen/mybranch\" as an example.\n>\n>  - do a 'git gc' to make sure that branch is in the packed refs file.\n>\n>  - make the subdirectory of that branch is unwritable (ie just do \n>    something like \"chmod -w refs/heads/frozen\")\n>\n> and now the filesystem permissions should mean that you can't actually \n> update that branch any more, even though you can read it.\n\nHmmmmm... and deleting of the branch would take the same lock used for\nupdating, which is under frozen/ directory, so that is also safe.\n\nThat's sneaky.\n\nI'd however throw that into \"happens to work, unsure if we would want to\npromise supporting it as a _feature_ forever\" category.\n"},{"id":"77446","messageId":"m3d4ne4uts.fsf@localhost.localdomain","threadId":"13607","inReplyTo":"7v63t7xgdg.fsf@gitster.siamese.dyndns.org","subject":"Re: Restricting access to a branch","fromName":"Jakub Narebski","fromEmail":"jnareb@gmail.com","sentAt":"2008-05-22T08:16:50Z","receivedAt":"2008-05-22T08:16:50Z","isPatch":false,"sender":{"key":"jnareb@gmail.com","avatar":"https://avatars.githubusercontent.com/u/2706?v=4"},"body":"Junio C Hamano <gitster@pobox.com> writes:\n\n> Linus Torvalds <torvalds@linux-foundation.org> writes:\n> \n> > What you *can* do is:\n> >\n> >  - rename the branch to something that includes a slash (aka \n> >    subdirectory). Let's call it \"frozen/mybranch\" as an example.\n> >\n> >  - do a 'git gc' to make sure that branch is in the packed refs file.\n> >\n> >  - make the subdirectory of that branch is unwritable (ie just do \n> >    something like \"chmod -w refs/heads/frozen\")\n> >\n> > and now the filesystem permissions should mean that you can't actually \n> > update that branch any more, even though you can read it.\n> \n> Hmmmmm... and deleting of the branch would take the same lock used for\n> updating, which is under frozen/ directory, so that is also safe.\n> \n> That's sneaky.\n> \n> I'd however throw that into \"happens to work, unsure if we would want to\n> promise supporting it as a _feature_ forever\" category.\n\nAnother solution would be to make it lightweight tag, i.e. change if\nfrom refs/heads/somebranch to refs/tags/somebranch (by tagging, for\nexample).\n\n-- \nJakub Narebski\nPoland\nShadeHawk on #git\n"}]}