{"thread":{"id":"25605","subject":"[PATCH] Add support in sample hook script for denying annotated tags.","startedAt":"2010-10-31T19:57:09Z","lastAt":"2010-11-01T07:29:37Z","messageCount":3,"participants":["Boyd Stephen Smith Jr.","Jonathan Nieder"],"isPatch":true,"patchVersion":1,"patchTotal":null},"messages":[{"id":"154899","messageId":"201010311457.17817.bss@iguanasuicide.net","threadId":"25605","inReplyTo":null,"subject":"[PATCH] Add support in sample hook script for denying annotated tags.","fromName":"Boyd Stephen Smith Jr.","fromEmail":"bss@iguanasuicide.net","sentAt":"2010-10-31T19:57:09Z","receivedAt":"2010-10-31T19:57:09Z","isPatch":true,"sender":{"key":"bss@iguanasuicide.net","avatar":"https://gravatar.com/avatar/84b95eeff194b816c1568b1339e63e4b229825298664a9037b9f1ec713ead1e3?d=mp&s=160"},"body":"Signed-off-by: \"Boyd Stephen Smith Jr.\" <bss@iguanasuicide.net>\n---\n templates/hooks--update.sample |    9 +++++++++\n 1 files changed, 9 insertions(+), 0 deletions(-)\n\nIn one project I'm in we are using a centralized Git repository that many \ndevelopers have access to.  As such, we want to prevent tags from being \ncreated by push operations and have them created by the administrators.\n\nThis is a modification to the sample update hook to allow this to simply be \na configuration option.\n\nreceive.denyCreate actually seems to be what my project wants, but I can see \nmore fine-grained support being nice-to-have.  For example, we might want \nto allow developers to create branches in a developer-specific namespace \nbut still disallow pushing annotated tags.\n\ndiff --git a/templates/hooks--update.sample b/templates/hooks--update.sample\nindex fd63b2d..c783973 100755\n--- a/templates/hooks--update.sample\n+++ b/templates/hooks--update.sample\n@@ -7,6 +7,9 @@\n #\n # Config\n # ------\n+# hooks.allowannotated\n+#   This boolean sets whether annotated tags will be allowed into the\n+#   repository.  By default they won't be.\n # hooks.allowunannotated\n #   This boolean sets whether unannotated tags will be allowed into the\n #   repository.  By default they won't be.\n@@ -43,6 +46,7 @@ if [ -z \"$refname\" -o -z \"$oldrev\" -o -z \"$newrev\" ]; then\n fi\n \n # --- Config\n+allowannotated=$(git config --bool hooks.allowannotated)\n allowunannotated=$(git config --bool hooks.allowunannotated)\n allowdeletebranch=$(git config --bool hooks.allowdeletebranch)\n denycreatebranch=$(git config --bool hooks.denycreatebranch)\n@@ -86,6 +90,11 @@ case \"$refname\",\"$newrev_type\" in\n \t\t;;\n \trefs/tags/*,tag)\n \t\t# annotated tag\n+\t\tif [ \"$oldrev\" = \"$zero\" -a \"$allowannotated\" != \"true\" ]; then\n+\t\t\techo \"*** Creating a tag is not allowed in this repository\" >&2\n+\t\t\texit 1\n+\t\tfi\n+\n \t\tif [ \"$allowmodifytag\" != \"true\" ] && git rev-parse $refname > /dev/null 2>&1\n \t\tthen\n \t\t\techo \"*** Tag '$refname' already exists.\" >&2\n-- \n1.7.1\n-- \nBoyd Stephen Smith Jr.                   ,= ,-_-. =.\nbss@iguanasuicide.net                   ((_/)o o(\\_))\nICQ: 514984 YM/AIM: DaTwinkDaddy         `-'(. .)`-'\nhttp://iguanasuicide.net/                    \\_/\n"},{"id":"154900","messageId":"20101031202433.GB21240@burratino","threadId":"25605","inReplyTo":"201010311457.17817.bss@iguanasuicide.net","subject":"Re: [PATCH] Add support in sample hook script for denying annotated tags.","fromName":"Jonathan Nieder","fromEmail":"jrnieder@gmail.com","sentAt":"2010-10-31T20:24:33Z","receivedAt":"2010-10-31T20:24:33Z","isPatch":true,"sender":{"key":"jrnieder@gmail.com","avatar":"https://avatars.githubusercontent.com/u/281595?v=4"},"body":"Hi,\n\nBoyd Stephen Smith Jr. wrote:\n\n> Signed-off-by: \"Boyd Stephen Smith Jr.\" <bss@iguanasuicide.net>\n> ---\n>  templates/hooks--update.sample |    9 +++++++++\n>  1 files changed, 9 insertions(+), 0 deletions(-)\n> \n> In one project I'm in we are using a centralized Git repository that many \n> developers have access to.  As such, we want to prevent tags from being \n> created by push operations and have them created by the administrators.\n> \n> This is a modification to the sample update hook to allow this to simply be \n> a configuration option.\n\nThis kind of justification belongs above the \"---\", I think.\n\nNo opinion on the functionality itself.  Just:\n\n> --- a/templates/hooks--update.sample\n> +++ b/templates/hooks--update.sample\n> @@ -7,6 +7,9 @@\n>  #\n>  # Config\n>  # ------\n> +# hooks.allowannotated\n> +#   This boolean sets whether annotated tags will be allowed into the\n> +#   repository.  By default they won't be.\n\nhooks.denyannotated (defaulting to false) would be more consistent\nwith hooks.denycreatebranch, no?\n\nOr maybe hooks.denycreatetag --- a situation in which unannotated\ntags should be allowed but annotated denied seems hard to imagine.\n\nHope that helps,\nJonathan\n"},{"id":"154917","messageId":"201011010229.45218.bss@iguanasuicide.net","threadId":"25605","inReplyTo":"20101031202433.GB21240@burratino","subject":"Re: [PATCH] Add support in sample hook script for denying annotated tags.","fromName":"Boyd Stephen Smith Jr.","fromEmail":"bss@iguanasuicide.net","sentAt":"2010-11-01T07:29:37Z","receivedAt":"2010-11-01T07:29:37Z","isPatch":true,"sender":{"key":"bss@iguanasuicide.net","avatar":"https://gravatar.com/avatar/84b95eeff194b816c1568b1339e63e4b229825298664a9037b9f1ec713ead1e3?d=mp&s=160"},"body":"In <20101031202433.GB21240@burratino>, Jonathan Nieder wrote:\n>Boyd Stephen Smith Jr. wrote:\n>> Signed-off-by: \"Boyd Stephen Smith Jr.\" <bss@iguanasuicide.net>\n>> ---\n>> \n>>  templates/hooks--update.sample |    9 +++++++++\n>>  1 files changed, 9 insertions(+), 0 deletions(-)\n>> \n>> In one project I'm in we are using a centralized Git repository that many\n>> developers have access to.  As such, we want to prevent tags from being\n>> created by push operations and have them created by the administrators.\n>> \n>> This is a modification to the sample update hook to allow this to simply\n>> be a configuration option.\n>\n>This kind of justification belongs above the \"---\", I think.\n\nEh, poop.  I wasn't sure were it went since it's been so long since I sent a \npatch in.  I thought only the \"commit message\" went above the \"---\" and my \nexplanation seemed a bit over-long for a commit message.\n\nI'll STFW next time and get it correct; I'd like to make it easy to use git am \nor git apply on the mail so that it is easier to review.\n\n>No opinion on the functionality itself.  Just:\n>> --- a/templates/hooks--update.sample\n>> +++ b/templates/hooks--update.sample\n>> @@ -7,6 +7,9 @@\n>> \n>>  #\n>>  # Config\n>>  # ------\n>> \n>> +# hooks.allowannotated\n>> +#   This boolean sets whether annotated tags will be allowed into the\n>> +#   repository.  By default they won't be.\n>\n>hooks.denyannotated (defaulting to false) would be more consistent\n>with hooks.denycreatebranch, no?\n\nMost of the flags were allow* and that seems to be a better way to approach \naccess restrictions like this.  denycreatebranch is the odd one out, and I was \nconsidering a patch that would change it to an allow* as well.\n\nStill, I'm happy to change the new flag to a deny* if there's consensus that \nit is better implemented that way.\n\n>Or maybe hooks.denycreatetag --- \n\nThat's probably better if you think of this as being analogous to \ndenycreatebranch.  When I wrote the patch I was thinking of this flag as being \nanalogous to allowunannotated.\n\n>a situation in which unannotated\n>tags should be allowed but annotated denied seems hard to imagine.\n\nAgreed.\n-- \nBoyd Stephen Smith Jr.                   ,= ,-_-. =.\nbss@iguanasuicide.net                   ((_/)o o(\\_))\nICQ: 514984 YM/AIM: DaTwinkDaddy         `-'(. .)`-'\nhttp://iguanasuicide.net/                    \\_/\n"}]}