{"thread":{"id":"28828","subject":"Folder level Acces in git","startedAt":"2011-11-03T06:10:55Z","lastAt":"2011-11-04T15:59:28Z","messageCount":7,"participants":["redhat1981","Magnus Bäck","Jens Lehmann","Eugene Sajine","Joshua Jensen"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"178758","messageId":"1320300655224-6958047.post@n2.nabble.com","threadId":"28828","inReplyTo":null,"subject":"Folder level Acces in git","fromName":"redhat1981","fromEmail":"redhat1981@gmail.com","sentAt":"2011-11-03T06:10:55Z","receivedAt":"2011-11-03T06:10:55Z","isPatch":false,"sender":{"key":"redhat1981@gmail.com","avatar":null},"body":"Hi,\n\nI am using Gitosis, Adding the gitosis conf file\n\n[group testabc]\nwritable = testabc\nmembers =   shrii Abhijeet premkumar\nadd cgit = yes\ngitweb = yes\n\n\n[group testabc-readonly]\nreadonly = testabc\nmembers =  Ganesh Shweta\nadd cgit = yes\ngitweb = yes\n\nInside the repository, testabc let us say there are folders folder1, folder\n2 etc, I want some users to have read/write, read or no access to the\nfolder1 or folder2, Is this possible in Git, I have done it in SVN, Please\nhelp!!\n\nredhat1981@gmail.com\n\n\n--\nView this message in context: http://git.661346.n2.nabble.com/Folder-level-Acces-in-git-tp6958047p6958047.html\nSent from the git mailing list archive at Nabble.com.\n"},{"id":"178760","messageId":"20111103071701.GA22412@jpl.local","threadId":"28828","inReplyTo":"1320300655224-6958047.post@n2.nabble.com","subject":"Re: Folder level Acces in git","fromName":"Magnus Bäck","fromEmail":"magnus.back@sonyericsson.com","sentAt":"2011-11-03T07:17:01Z","receivedAt":"2011-11-03T07:17:01Z","isPatch":false,"sender":{"key":"magnus.back@sonyericsson.com","avatar":null},"body":"On Thursday, November 03, 2011 at 07:10 CET,\n     redhat1981 <redhat1981@gmail.com> wrote:\n\n> I am using Gitosis, Adding the gitosis conf file\n> \n> [group testabc]\n> writable = testabc\n> members =   shrii Abhijeet premkumar\n> add cgit = yes\n> gitweb = yes\n> \n> \n> [group testabc-readonly]\n> readonly = testabc\n> members =  Ganesh Shweta\n> add cgit = yes\n> gitweb = yes\n> \n> Inside the repository, testabc let us say there are folders folder1,\n> folder 2 etc, I want some users to have read/write, read or no access\n> to the folder1 or folder2, Is this possible in Git, I have done it in\n> SVN, Please help!!\n\nGiven Git's nature, you can't have read access restrictions on a sub-git\nlevel (i.e. file/directory level). For basically the same reason, you\ncan never prevent users from making (local) commits that modify certain\npaths (but you can encourage people to have local hooks to enforce such\npolicies). What you *can* do is install a server-side update hook that\nrejects attempts to push commits that modify certain paths. If you're\nwilling to trade Gitosis for Gitolite, you get that feature for free.\n\nhttp://book.git-scm.com/5_git_hooks.html\nhttp://progit.org/book/ch4-8.html\n\n-- \nMagnus Bäck                   Opinions are my own and do not necessarily\nSW Configuration Manager      represent the ones of my employer, etc.\nSony Ericsson\n"},{"id":"178783","messageId":"4EB2D9BD.6020801@web.de","threadId":"28828","inReplyTo":"20111103071701.GA22412@jpl.local","subject":"Re: Folder level Acces in git","fromName":"Jens Lehmann","fromEmail":"jens.lehmann@web.de","sentAt":"2011-11-03T18:13:17Z","receivedAt":"2011-11-03T18:13:17Z","isPatch":false,"sender":{"key":"jens.lehmann@web.de","avatar":"https://avatars.githubusercontent.com/u/135220?v=4"},"body":"Am 03.11.2011 08:17, schrieb Magnus Bäck:\n> On Thursday, November 03, 2011 at 07:10 CET,\n>      redhat1981 <redhat1981@gmail.com> wrote:\n>> Inside the repository, testabc let us say there are folders folder1,\n>> folder 2 etc, I want some users to have read/write, read or no access\n>> to the folder1 or folder2, Is this possible in Git, I have done it in\n>> SVN, Please help!!\n> \n> Given Git's nature, you can't have read access restrictions on a sub-git\n> level (i.e. file/directory level). For basically the same reason, you\n> can never prevent users from making (local) commits that modify certain\n> paths (but you can encourage people to have local hooks to enforce such\n> policies). What you *can* do is install a server-side update hook that\n> rejects attempts to push commits that modify certain paths. If you're\n> willing to trade Gitosis for Gitolite, you get that feature for free.\n\nDirectory read access control can be achieved by putting the directory\ncontent into a submodule. You can then control who is allowed to clone\nfrom the repo for that submodule separately from the superproject,\nthereby disallowing a group of people to see (let alone modify) what is\nin there.\n\nhttp://progit.org/book/ch6-6.html\n"},{"id":"178793","messageId":"CAPZPVFY15AqCpWcRbv0tjXBz4G2kQTm+nMGpsYzCKe0niHV_dA@mail.gmail.com","threadId":"28828","inReplyTo":"1320300655224-6958047.post@n2.nabble.com","subject":"Re: Folder level Acces in git","fromName":"Eugene Sajine","fromEmail":"euguess@gmail.com","sentAt":"2011-11-03T19:28:53Z","receivedAt":"2011-11-03T19:28:53Z","isPatch":false,"sender":{"key":"euguess@gmail.com","avatar":null},"body":"On Thu, Nov 3, 2011 at 2:10 AM, redhat1981 <redhat1981@gmail.com> wrote:\n> Hi,\n>\n> I am using Gitosis, Adding the gitosis conf file\n>\n> [group testabc]\n> writable = testabc\n> members =   shrii Abhijeet premkumar\n> add cgit = yes\n> gitweb = yes\n>\n>\n> [group testabc-readonly]\n> readonly = testabc\n> members =  Ganesh Shweta\n> add cgit = yes\n> gitweb = yes\n>\n> Inside the repository, testabc let us say there are folders folder1, folder\n> 2 etc, I want some users to have read/write, read or no access to the\n> folder1 or folder2, Is this possible in Git, I have done it in SVN, Please\n> help!!\n>\n> redhat1981@gmail.com\n>\n\n\nAre you sure that the way your have organized the repository is\nactually correct? If you need to manage the access on folder level why\ndon't you simply split up the project into several\nrepositories/projects which each team is going to work with\nindependently?\n\nThis seems to me to be much simpler and cleaner solution then any\nother alternative.\n\nThanks,\nEugene\n"},{"id":"178810","messageId":"4EB36855.8000802@workspacewhiz.com","threadId":"28828","inReplyTo":"CAPZPVFY15AqCpWcRbv0tjXBz4G2kQTm+nMGpsYzCKe0niHV_dA@mail.gmail.com","subject":"Re: Folder level Acces in git","fromName":"Joshua Jensen","fromEmail":"jjensen@workspacewhiz.com","sentAt":"2011-11-04T04:21:41Z","receivedAt":"2011-11-04T04:21:41Z","isPatch":false,"sender":{"key":"jjensen@workspacewhiz.com","avatar":"https://avatars.githubusercontent.com/u/111687?v=4"},"body":"----- Original Message -----\nFrom: Eugene Sajine\nDate: 11/3/2011 1:28 PM\n> Are you sure that the way your have organized the repository is\n> actually correct? If you need to manage the access on folder level why\n> don't you simply split up the project into several\n> repositories/projects which each team is going to work with\n> independently?\n>\n> This seems to me to be much simpler and cleaner solution then any\n> other alternative.\n>\nSubmodules are _not_ simple at all.  Our organization of nearly 100 \ndevelopers using Git pretty much let out a collective cheer when we \nfinally removed the submodules.  Submodules are an absolute pain to \ndevelop within; there are a number of Git mailing list exchanges about \nthat, but I'd be happy to go into great detail if anybody cares.  Even \nsubmodules that are read-only are a pain as it takes two steps (git pull \n+ git submodule update) to actually get them up to date.\n\nIck.\n\nIn short, if it is an absolute requirement to manage access to a \nrepository on a folder level, get Subversion or Perforce.  DVCS is not \nfor you...\n\nJosh\n"},{"id":"178814","messageId":"4EB3A565.2040408@web.de","threadId":"28828","inReplyTo":"4EB36855.8000802@workspacewhiz.com","subject":"Re: Folder level Acces in git","fromName":"Jens Lehmann","fromEmail":"jens.lehmann@web.de","sentAt":"2011-11-04T08:42:13Z","receivedAt":"2011-11-04T08:42:13Z","isPatch":false,"sender":{"key":"jens.lehmann@web.de","avatar":"https://avatars.githubusercontent.com/u/135220?v=4"},"body":"Am 04.11.2011 05:21, schrieb Joshua Jensen:\n> ----- Original Message -----\n> From: Eugene Sajine\n> Date: 11/3/2011 1:28 PM\n>> Are you sure that the way your have organized the repository is\n>> actually correct? If you need to manage the access on folder level why\n>> don't you simply split up the project into several\n>> repositories/projects which each team is going to work with\n>> independently?\n>>\n>> This seems to me to be much simpler and cleaner solution then any\n>> other alternative.\n>>\n> Submodules are _not_ simple at all.  Our organization of nearly 100 developers using Git pretty much let out a collective cheer when we finally removed the submodules.  Submodules are an absolute pain to develop within; there are a number of Git mailing list exchanges about that, but I'd be happy to go into great detail if anybody cares.\n\nI do care and would appreciate if you could share your problems.\n\n> Even submodules that are read-only are a pain as it takes two steps (git pull + git submodule update) to actually get them up to date.\n\nFull Ack. I'm working on teaching git to update update the whole\nwork tree - including the submodules - after each checkout, merge,\npull, bisect, etc. (which also includes proper support for deletion\nand re-creation of submodules).\n\nWhat else made using submodules hard for you?\n"},{"id":"178835","messageId":"CAPZPVFZwW1VF2qb8YVQjBixRzZgz+HSz6NjJBUimuC-nx7LwZQ@mail.gmail.com","threadId":"28828","inReplyTo":"4EB36855.8000802@workspacewhiz.com","subject":"Re: Folder level Acces in git","fromName":"Eugene Sajine","fromEmail":"euguess@gmail.com","sentAt":"2011-11-04T15:59:28Z","receivedAt":"2011-11-04T15:59:28Z","isPatch":false,"sender":{"key":"euguess@gmail.com","avatar":null},"body":"On Fri, Nov 4, 2011 at 12:21 AM, Joshua Jensen\n<jjensen@workspacewhiz.com> wrote:\n> ----- Original Message -----\n> From: Eugene Sajine\n> Date: 11/3/2011 1:28 PM\n>>\n>> Are you sure that the way your have organized the repository is\n>> actually correct? If you need to manage the access on folder level why\n>> don't you simply split up the project into several\n>> repositories/projects which each team is going to work with\n>> independently?\n>>\n>> This seems to me to be much simpler and cleaner solution then any\n>> other alternative.\n>>\n> Submodules are _not_ simple at all.  Our organization of nearly 100\n> developers using Git pretty much let out a collective cheer when we finally\n> removed the submodules.  Submodules are an absolute pain to develop within;\n> there are a number of Git mailing list exchanges about that, but I'd be\n> happy to go into great detail if anybody cares.  Even submodules that are\n> read-only are a pain as it takes two steps (git pull + git submodule update)\n> to actually get them up to date.\n>\n> Ick.\n>\n> In short, if it is an absolute requirement to manage access to a repository\n> on a folder level, get Subversion or Perforce.  DVCS is not for you...\n>\n> Josh\n>\n\nThat is exactly what i wanted to say. I suggest OP not to go into\nsubmodules, but just have separate repositories. I think if they need\nthis kind of granularity in permissions it means that their repository\nis too big and incorrectly organized. I think they are trying to\nmigrate to better VCS (as git is superior by definition;) ), but they\nstill think in central VCS terms and that's what causing this folder\nlevel management requirement to appear. We  at $work have hundreds of\nrepositories and never had any need of submodules or folder level\npermissions. (One repo = one project = one artifact) + Ivy as\ndependency manager works just fine and if we will need to fine tune\nthe permissions it will be always pretty easy to do.\n\n\nThanks,\nEugene\n"}]}