{"thread":{"id":"17154","subject":"Removing options from build","startedAt":"2009-01-13T21:43:22Z","lastAt":"2009-01-13T22:47:29Z","messageCount":12,"participants":["R. Tyler Ballance","Thomas Rast","Björn Steinbrink","Jakub Narebski","Boyd Stephen Smith Jr.","Daniel Barkalow"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"100320","messageId":"1231883002.14181.27.camel@starfruit","threadId":"17154","inReplyTo":null,"subject":"Removing options from build","fromName":"R. Tyler Ballance","fromEmail":"tyler@slide.com","sentAt":"2009-01-13T21:43:22Z","receivedAt":"2009-01-13T21:43:22Z","isPatch":false,"sender":{"key":"tyler@slide.com","avatar":null},"body":"One of our developers \"discovered\" the --force option on `git push` and\nused it without taking the appropriate care and hosed one of the project\nbranches we have running around in our central repository.\n\nBesides a vigorous flogging, we're looking at other ways to prevent this\nsort of thing from happening again; the option we've settled on is to\nremove the \"--force\" flag from our internal build of v1.6.1\n\nI'm wondering if somebody could point me in the right direction to\nremove \"--force\" (safely) from the builtin-push.c and removing the\n\"rebase\" command (we've got no use for it, and would prefer it gone).\n\nCheers\n-- \n-R. Tyler Ballance\nSlide, Inc.\n"},{"id":"100322","messageId":"200901132253.15370.trast@student.ethz.ch","threadId":"17154","inReplyTo":"1231883002.14181.27.camel@starfruit","subject":"Re: Removing options from build","fromName":"Thomas Rast","fromEmail":"trast@student.ethz.ch","sentAt":"2009-01-13T21:53:12Z","receivedAt":"2009-01-13T21:53:12Z","isPatch":false,"sender":{"key":"tr@thomasrast.ch","avatar":"https://avatars.githubusercontent.com/u/153510?v=4"},"body":"R. Tyler Ballance wrote:\n> Besides a vigorous flogging, we're looking at other ways to prevent this\n> sort of thing from happening again; the option we've settled on is to\n> remove the \"--force\" flag from our internal build of v1.6.1\n>\n> I'm wondering if somebody could point me in the right direction to\n> remove \"--force\" (safely) from the builtin-push.c and removing the\n> \"rebase\" command (we've got no use for it, and would prefer it gone).\n\nIMHO your update (or pre-receive) hook should just disallow\nnon-fast-forward updates.\n\nThis doesn't really address git-rebase, but it will disallow pushing a\n\"harmfully\" rebased branch since those are by definition non-ff.  Why\ntake away the option to correct a mistake in the last commit with 'git\nrebase -i'?\n\n-- \nThomas Rast\ntrast@{inf,student}.ethz.ch\n\n"},{"id":"100323","messageId":"20090113215550.GE30404@atjola.homenet","threadId":"17154","inReplyTo":"1231883002.14181.27.camel@starfruit","subject":"Re: Removing options from build","fromName":"Björn Steinbrink","fromEmail":"b.steinbrink@gmx.de","sentAt":"2009-01-13T21:55:50Z","receivedAt":"2009-01-13T21:55:50Z","isPatch":false,"sender":{"key":"b.steinbrink@gmx.de","avatar":"https://avatars.githubusercontent.com/u/230962?v=4"},"body":"On 2009.01.13 13:43:22 -0800, R. Tyler Ballance wrote:\n> One of our developers \"discovered\" the --force option on `git push` and\n> used it without taking the appropriate care and hosed one of the project\n> branches we have running around in our central repository.\n> \n> Besides a vigorous flogging, we're looking at other ways to prevent this\n> sort of thing from happening again; the option we've settled on is to\n> remove the \"--force\" flag from our internal build of v1.6.1\n> \n> I'm wondering if somebody could point me in the right direction to\n> remove \"--force\" (safely) from the builtin-push.c and removing the\n> \"rebase\" command (we've got no use for it, and would prefer it gone).\n\ngit help config\n\nreceive.denyNonFastForwards (to refuse non-fast-forwards, even with -f)\nreceive.denyDeletes (to stop users from working around the non-ff using\n                     a delete + recreate operation)\n\nBjörn\n"},{"id":"100324","messageId":"200901132256.40313.trast@student.ethz.ch","threadId":"17154","inReplyTo":"200901132253.15370.trast@student.ethz.ch","subject":"Re: Removing options from build","fromName":"Thomas Rast","fromEmail":"trast@student.ethz.ch","sentAt":"2009-01-13T21:56:36Z","receivedAt":"2009-01-13T21:56:36Z","isPatch":false,"sender":{"key":"tr@thomasrast.ch","avatar":"https://avatars.githubusercontent.com/u/153510?v=4"},"body":"Thomas Rast wrote:\n> R. Tyler Ballance wrote:\n> > I'm wondering if somebody could point me in the right direction to\n> > remove \"--force\" (safely) from the builtin-push.c\n> \n> IMHO your update (or pre-receive) hook should just disallow\n> non-fast-forward updates.\n\nActually there's even this config option:\n\n       receive.denyNonFastForwards\n           If set to true, git-receive-pack will deny a ref update\n           which is not a fast forward.  Use this to prevent such an\n           update via a push, even if that push is forced. This\n           configuration variable is set when initializing a shared\n           repository.\n\n-- \nThomas Rast\ntrast@{inf,student}.ethz.ch\n\n"},{"id":"100325","messageId":"1231884045.14181.36.camel@starfruit","threadId":"17154","inReplyTo":"200901132253.15370.trast@student.ethz.ch","subject":"Re: Removing options from build","fromName":"R. Tyler Ballance","fromEmail":"tyler@slide.com","sentAt":"2009-01-13T22:00:45Z","receivedAt":"2009-01-13T22:00:45Z","isPatch":false,"sender":{"key":"tyler@slide.com","avatar":null},"body":"On Tue, 2009-01-13 at 22:53 +0100, Thomas Rast wrote:\n> R. Tyler Ballance wrote:\n> > Besides a vigorous flogging, we're looking at other ways to prevent this\n> > sort of thing from happening again; the option we've settled on is to\n> > remove the \"--force\" flag from our internal build of v1.6.1\n> >\n> > I'm wondering if somebody could point me in the right direction to\n> > remove \"--force\" (safely) from the builtin-push.c and removing the\n> > \"rebase\" command (we've got no use for it, and would prefer it gone).\n> \n> IMHO your update (or pre-receive) hook should just disallow\n> non-fast-forward updates.\n\nDon't merges count as non-fast-forward updates? We generate merge\ncommits with almost every merge, rarely do we actually have\nfast-forwards anymore (highly active repository)\n\n> \n> This doesn't really address git-rebase, but it will disallow pushing a\n> \"harmfully\" rebased branch since those are by definition non-ff.  Why\n> take away the option to correct a mistake in the last commit with 'git\n> rebase -i'?\n\nI'm a strong proponent of revision history only moving forward, I would\nmuch rather see a series of revert commits than having somebody who is\ninexperienced with the tools they're using muck about an jeopardize the\nstability of our central repository. \n\n\nUsed correctly, both --force and `rebase` have good reason to exist in\nthe Git codebase; they just haven't been used correctly, and proper\nbamboo to flog developers with will take a couple days to ship from\nAsia, so removing the options from our internal build is a lot easier\nand faster ;)\n\nCheers :D\n-- \n-R. Tyler Ballance\nSlide, Inc.\n"},{"id":"100326","messageId":"m3d4eqzwuc.fsf@localhost.localdomain","threadId":"17154","inReplyTo":"1231883002.14181.27.camel@starfruit","subject":"Re: Removing options from build","fromName":"Jakub Narebski","fromEmail":"jnareb@gmail.com","sentAt":"2009-01-13T22:05:36Z","receivedAt":"2009-01-13T22:05:36Z","isPatch":false,"sender":{"key":"jnareb@gmail.com","avatar":"https://avatars.githubusercontent.com/u/2706?v=4"},"body":"\"R. Tyler Ballance\" <tyler@slide.com> writes:\n\n> One of our developers \"discovered\" the --force option on `git push` and\n> used it without taking the appropriate care and hosed one of the project\n> branches we have running around in our central repository.\n> \n> Besides a vigorous flogging, we're looking at other ways to prevent this\n> sort of thing from happening again; the option we've settled on is to\n> remove the \"--force\" flag from our internal build of v1.6.1\n> \n> I'm wondering if somebody could point me in the right direction to\n> remove \"--force\" (safely) from the builtin-push.c and removing the\n> \"rebase\" command (we've got no use for it, and would prefer it gone).\n\nFirst, the title (subject) of this email is misleading: it is about\nyour solution, and not about the problem you have (protecting against\n\"git push --force\").\n\nSecond, there are two possible solutions: use receive.denyNonFastForwards\nand perhaps also receive.denyDeletes (see git-config(1)) to forbid forced\npushes on server (target of push); removing '--force' is a client solution.\nOr, better, use update or post-receive hook on server, forbidding \nnon-fastforward updates to selected set of 'stable' branches; you can\nuse contrib/hooks/update-paranoid for that.\n\n-- \nJakub Narebski\nPoland\nShadeHawk on #git\n"},{"id":"100327","messageId":"200901131606.04634.bss@iguanasuicide.net","threadId":"17154","inReplyTo":"1231883002.14181.27.camel@starfruit","subject":"Re: Removing options from build","fromName":"Boyd Stephen Smith Jr.","fromEmail":"bss@iguanasuicide.net","sentAt":"2009-01-13T22:06:00Z","receivedAt":"2009-01-13T22:06:00Z","isPatch":false,"sender":{"key":"bss@iguanasuicide.net","avatar":"https://gravatar.com/avatar/84b95eeff194b816c1568b1339e63e4b229825298664a9037b9f1ec713ead1e3?d=mp&s=160"},"body":"On Tuesday 2009 January 13 15:43:22 R. Tyler Ballance wrote:\n>One of our developers \"discovered\" the --force option on `git push` and\n>used it without taking the appropriate care and hosed one of the project\n>branches we have running around in our central repository.\n\nReflogs should let you recover from this.\n\n>Besides a vigorous flogging, we're looking at other ways to prevent this\n>sort of thing from happening again;\n\nreceive.denyNonFastForwards\n        If set to true, git-receive-pack will deny a ref update which\n        is not a fast forward. Use this to prevent such an update via a\n        push, even if that push is forced. This configuration variable\n        is set when initializing a shared repository.\n-- \nBoyd Stephen Smith Jr.                     ,= ,-_-. =. \nbss@iguanasuicide.net                     ((_/)o o(\\_))\nICQ: 514984 YM/AIM: DaTwinkDaddy           `-'(. .)`-' \nhttp://iguanasuicide.net/                      \\_/     \n"},{"id":"100329","messageId":"20090113220730.GF30404@atjola.homenet","threadId":"17154","inReplyTo":"1231884045.14181.36.camel@starfruit","subject":"Re: Removing options from build","fromName":"Björn Steinbrink","fromEmail":"b.steinbrink@gmx.de","sentAt":"2009-01-13T22:07:30Z","receivedAt":"2009-01-13T22:07:30Z","isPatch":false,"sender":{"key":"b.steinbrink@gmx.de","avatar":"https://avatars.githubusercontent.com/u/230962?v=4"},"body":"On 2009.01.13 14:00:45 -0800, R. Tyler Ballance wrote:\n> On Tue, 2009-01-13 at 22:53 +0100, Thomas Rast wrote:\n> > R. Tyler Ballance wrote:\n> > > Besides a vigorous flogging, we're looking at other ways to prevent this\n> > > sort of thing from happening again; the option we've settled on is to\n> > > remove the \"--force\" flag from our internal build of v1.6.1\n> > >\n> > > I'm wondering if somebody could point me in the right direction to\n> > > remove \"--force\" (safely) from the builtin-push.c and removing the\n> > > \"rebase\" command (we've got no use for it, and would prefer it gone).\n> > \n> > IMHO your update (or pre-receive) hook should just disallow\n> > non-fast-forward updates.\n> \n> Don't merges count as non-fast-forward updates? We generate merge\n> commits with almost every merge, rarely do we actually have\n> fast-forwards anymore (highly active repository)\n\nNo, merges are \"fast-forward\". In rev-list terms:\n\ngit rev-list new_head..old_head ==> Empty\n\nIOW: No commits are lost by the push.\n\nMerges only add commits to the history, they don't remove anything.\n\nBjörn\n"},{"id":"100330","messageId":"200901131610.22732.bss@iguanasuicide.net","threadId":"17154","inReplyTo":"1231884045.14181.36.camel@starfruit","subject":"Re: Removing options from build","fromName":"Boyd Stephen Smith Jr.","fromEmail":"bss@iguanasuicide.net","sentAt":"2009-01-13T22:10:22Z","receivedAt":"2009-01-13T22:10:22Z","isPatch":false,"sender":{"key":"bss@iguanasuicide.net","avatar":"https://gravatar.com/avatar/84b95eeff194b816c1568b1339e63e4b229825298664a9037b9f1ec713ead1e3?d=mp&s=160"},"body":"On Tuesday 2009 January 13 16:00:45 R. Tyler Ballance wrote:\n>On Tue, 2009-01-13 at 22:53 +0100, Thomas Rast wrote:\n>> IMHO your update (or pre-receive) hook should just disallow\n>> non-fast-forward updates.\n>\n>Don't merges count as non-fast-forward updates?\n\nNo.  If there is a chain of parent links X ~> Y then updating a ref Y -> X is \na fast-forward.\n-- \nBoyd Stephen Smith Jr.                     ,= ,-_-. =. \nbss@iguanasuicide.net                     ((_/)o o(\\_))\nICQ: 514984 YM/AIM: DaTwinkDaddy           `-'(. .)`-' \nhttp://iguanasuicide.net/                      \\_/     \n"},{"id":"100331","messageId":"1231885132.14181.38.camel@starfruit","threadId":"17154","inReplyTo":"200901131606.04634.bss@iguanasuicide.net","subject":"Re: Removing options from build","fromName":"R. Tyler Ballance","fromEmail":"tyler@slide.com","sentAt":"2009-01-13T22:18:52Z","receivedAt":"2009-01-13T22:18:52Z","isPatch":false,"sender":{"key":"tyler@slide.com","avatar":null},"body":"On Tue, 2009-01-13 at 16:06 -0600, Boyd Stephen Smith Jr. wrote:\n> On Tuesday 2009 January 13 15:43:22 R. Tyler Ballance wrote:\n> >One of our developers \"discovered\" the --force option on `git push` and\n> >used it without taking the appropriate care and hosed one of the project\n> >branches we have running around in our central repository.\n> \n> Reflogs should let you recover from this.\n> \n> >Besides a vigorous flogging, we're looking at other ways to prevent this\n> >sort of thing from happening again;\n> \n> receive.denyNonFastForwards\n>         If set to true, git-receive-pack will deny a ref update which\n>         is not a fast forward. Use this to prevent such an update via a\n>         push, even if that push is forced. This configuration variable\n>         is set when initializing a shared repository.\n\nLooks good, thanks; sorry I missed it, didn't even think to look at the\ngit-config(1) page for such an option. \n\nI'm assuming this will actually cover the rebase -i case as well?\n\n\nCheers\n\n-- \n-R. Tyler Ballance\nSlide, Inc.\n"},{"id":"100332","messageId":"200901131634.31389.bss@iguanasuicide.net","threadId":"17154","inReplyTo":"1231885132.14181.38.camel@starfruit","subject":"Re: Removing options from build","fromName":"Boyd Stephen Smith Jr.","fromEmail":"bss@iguanasuicide.net","sentAt":"2009-01-13T22:34:31Z","receivedAt":"2009-01-13T22:34:31Z","isPatch":false,"sender":{"key":"bss@iguanasuicide.net","avatar":"https://gravatar.com/avatar/84b95eeff194b816c1568b1339e63e4b229825298664a9037b9f1ec713ead1e3?d=mp&s=160"},"body":"On Tuesday 2009 January 13 16:18:52 R. Tyler Ballance wrote:\n>On Tue, 2009-01-13 at 16:06 -0600, Boyd Stephen Smith Jr. wrote:\n>> receive.denyNonFastForwards\n>>         If set to true, git-receive-pack will deny a ref update which\n>>         is not a fast forward. Use this to prevent such an update via a\n>>         push, even if that push is forced.\n>\n>Looks good, thanks; sorry I missed it, didn't even think to look at the\n>git-config(1) page for such an option.\n\nI didn't really know about it until earlier this week.  I was expecting to be \nable to do a non-ff push to one of my repositories and it didn't work because \nthis was set \"behind my back\".  (I'm not sure when it got added, but I don't \nthink the shared repositories I set up with git 1.4.4.4 had it, so I wasn't \nexpecting it.)\n\n>I'm assuming this will actually cover the rebase -i case as well?\n\nI don't know exactly what you mean.  It prevents fast-forwards, so once a \ncommit is \"visible\" on one of your central branches, it won't ever go away.  \n(You can, of course, use git revert to undo it's changes.)\n\nAs others mentioned, now would be a good time to look at receive.denyDeletes \nand/or a custom hook as well.\n-- \nBoyd Stephen Smith Jr.                     ,= ,-_-. =. \nbss@iguanasuicide.net                     ((_/)o o(\\_))\nICQ: 514984 YM/AIM: DaTwinkDaddy           `-'(. .)`-' \nhttp://iguanasuicide.net/                      \\_/     \n"},{"id":"100336","messageId":"alpine.LNX.1.00.0901131729520.19665@iabervon.org","threadId":"17154","inReplyTo":"1231884045.14181.36.camel@starfruit","subject":"Re: Removing options from build","fromName":"Daniel Barkalow","fromEmail":"barkalow@iabervon.org","sentAt":"2009-01-13T22:47:29Z","receivedAt":"2009-01-13T22:47:29Z","isPatch":false,"sender":{"key":"barkalow@iabervon.org","avatar":"https://avatars.githubusercontent.com/u/55364219?v=4"},"body":"On Tue, 13 Jan 2009, R. Tyler Ballance wrote:\n\n> On Tue, 2009-01-13 at 22:53 +0100, Thomas Rast wrote:\n> > R. Tyler Ballance wrote:\n> > > Besides a vigorous flogging, we're looking at other ways to prevent this\n> > > sort of thing from happening again; the option we've settled on is to\n> > > remove the \"--force\" flag from our internal build of v1.6.1\n> > >\n> > > I'm wondering if somebody could point me in the right direction to\n> > > remove \"--force\" (safely) from the builtin-push.c and removing the\n> > > \"rebase\" command (we've got no use for it, and would prefer it gone).\n> > \n> > IMHO your update (or pre-receive) hook should just disallow\n> > non-fast-forward updates.\n> \n> Don't merges count as non-fast-forward updates? We generate merge\n> commits with almost every merge, rarely do we actually have\n> fast-forwards anymore (highly active repository)\n\nCreating a merge is a non-fast-forward update, but sending the merge to a \nrepository that is currently at one of the parents is a fast-forward.\n\nHopefully, you're generating merge commits with merge, not with push. :)\n\n> > This doesn't really address git-rebase, but it will disallow pushing a\n> > \"harmfully\" rebased branch since those are by definition non-ff.  Why\n> > take away the option to correct a mistake in the last commit with 'git\n> > rebase -i'?\n> \n> I'm a strong proponent of revision history only moving forward, I would\n> much rather see a series of revert commits than having somebody who is\n> inexperienced with the tools they're using muck about an jeopardize the\n> stability of our central repository. \n> \n> \n> Used correctly, both --force and `rebase` have good reason to exist in\n> the Git codebase; they just haven't been used correctly, and proper\n> bamboo to flog developers with will take a couple days to ship from\n> Asia, so removing the options from our internal build is a lot easier\n> and faster ;)\n\nDenying non-fast-forward updates means that people can rebase, but if they \nrebase anything that they've pushed (or anyone else has pushed), they \ncan't push.\n\nYou can't really disallow rebasing of private commits while still using \ngit; a user can always clone the upstream repository again, get diffs from \nthe repository where they don't like the history, apply them to the new \nclone, and throw away the repository with the bad history. Or they can \ncall up a coworker, tell them what changes to make, commit, and push, and \nthen lose their work in a hard drive crash. People can always make the \nexcuse \"My identical twin did stuff wrong, but I knocked him out before \nhe could push and did everything right.\" As long as they can't say \"My \nevil twin pushed the changes to the repository's evil twin, but I knocked \nhim out and destoryed the evil repository, and now we've got the good \nrepository.\"\n\n\t-Daniel\n*This .sig left intentionally blank*\n"}]}