{"thread":{"id":"30384","subject":"Is there any way to make hooks part of the repository?","startedAt":"2012-05-01T20:24:28Z","lastAt":"2012-05-04T06:10:57Z","messageCount":18,"participants":["Hilco Wijbenga","Junio C Hamano","Randal L. Schwartz","PJ Weisberg","Nathan Gray","Matthieu Moy","Thomas Rast","Johan Herland"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"190476","messageId":"CAE1pOi2hr7ewjo5WVDoW0ipYxDVTckr5M_sHNoOQ323=_k754Q@mail.gmail.com","threadId":"30384","inReplyTo":null,"subject":"Is there any way to make hooks part of the repository?","fromName":"Hilco Wijbenga","fromEmail":"hilco.wijbenga@gmail.com","sentAt":"2012-05-01T20:24:28Z","receivedAt":"2012-05-01T20:24:28Z","isPatch":false,"sender":{"key":"hilco.wijbenga@gmail.com","avatar":null},"body":"Hi all,\n\nThere are a couple of things that keep going wrong while we are\nworking on our code base. Some of them are very simple to check for in\na Git hook. However, I get the impression that it is not possible to\n\"include\" the hooks with the Git repo itself (so that \"git clone\"\nwould automatically set them up). Normally, this would not be such a\nbig deal: I would simply add the hooks on the server. Unfortunately,\nthis is not an option (we use Unfuddle and they do not support that).\n\nIs there any way to get (some of) the Git hooks to run for everyone\nwithout everyone having to install them separately? If no, is this by\ndesign or simply a feature nobody has asked for (yet)?\n\nCheers,\nHilco\n"},{"id":"190477","messageId":"7vipgf8wve.fsf@alter.siamese.dyndns.org","threadId":"30384","inReplyTo":"CAE1pOi2hr7ewjo5WVDoW0ipYxDVTckr5M_sHNoOQ323=_k754Q@mail.gmail.com","subject":"Re: Is there any way to make hooks part of the repository?","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2012-05-01T20:33:25Z","receivedAt":"2012-05-01T20:33:25Z","isPatch":false,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Hilco Wijbenga <hilco.wijbenga@gmail.com> writes:\n\n> Is there any way to get (some of) the Git hooks to run for everyone\n> without everyone having to install them separately? If no, is this by\n> design or simply a feature nobody has asked for (yet)?\n\nBy design.  Do you want me to include \"rm -fr ~hilco\" in some hook of\ngit.git repository?\n"},{"id":"190482","messageId":"86r4v3mxf7.fsf@red.stonehenge.com","threadId":"30384","inReplyTo":"7vipgf8wve.fsf@alter.siamese.dyndns.org","subject":"Re: Is there any way to make hooks part of the repository?","fromName":"Randal L. Schwartz","fromEmail":"merlyn@stonehenge.com","sentAt":"2012-05-01T20:57:48Z","receivedAt":"2012-05-01T20:57:48Z","isPatch":false,"sender":{"key":"merlyn@stonehenge.com","avatar":"https://gravatar.com/avatar/dc528d210743ff0333e6213f9ee7b33b23f1b7bc1f3c5a8c2d819074ecd7ab19?d=mp&s=160"},"body":">>>>> \"Junio\" == Junio C Hamano <gitster@pobox.com> writes:\n\nJunio> By design.  Do you want me to include \"rm -fr ~hilco\" in some hook of\nJunio> git.git repository?\n\nThis just came up yesterday at $PRIMARY_CLIENT.  One idea we kicked\naround was having a convention for storing the hooks-to-be-populated in\n\".githooks\" in the repository tree, and then having clone notice that\nand offer to install them directly if from a trusted source, or at least\nmove them into a disabled state in .git/hooks otherwise.\n\n-- \nRandal L. Schwartz - Stonehenge Consulting Services, Inc. - +1 503 777 0095\n<merlyn@stonehenge.com> <URL:http://www.stonehenge.com/merlyn/>\nSmalltalk/Perl/Unix consulting, Technical writing, Comedy, etc. etc.\nSee http://methodsandmessages.posterous.com/ for Smalltalk discussion\n"},{"id":"190483","messageId":"CAE1pOi0_ETdSYsuT0Udhbr6rDvmEcuTA157d6aKUosgi7w28jw@mail.gmail.com","threadId":"30384","inReplyTo":"7vipgf8wve.fsf@alter.siamese.dyndns.org","subject":"Re: Is there any way to make hooks part of the repository?","fromName":"Hilco Wijbenga","fromEmail":"hilco.wijbenga@gmail.com","sentAt":"2012-05-01T21:00:28Z","receivedAt":"2012-05-01T21:00:28Z","isPatch":false,"sender":{"key":"hilco.wijbenga@gmail.com","avatar":null},"body":"On 1 May 2012 13:33, Junio C Hamano <gitster@pobox.com> wrote:\n> Hilco Wijbenga <hilco.wijbenga@gmail.com> writes:\n>\n>> Is there any way to get (some of) the Git hooks to run for everyone\n>> without everyone having to install them separately? If no, is this by\n>> design or simply a feature nobody has asked for (yet)?\n>\n> By design.  Do you want me to include \"rm -fr ~hilco\" in some hook of\n> git.git repository?\n\nMmm, well, I might get quite famous if you did... ;-)\n\nBut if you wanted to be evil then you could easily find another place\n(the build scripts, the code itself, et cetera). So I don't think this\nis a good argument. Moreover, I do not work with people that would\never consider such nastiness. You need to realize that this is all\nclosed source. Your argument would be more valid in an open source\nenvironment (like git.git).\n\nSo let's just say that I'm stubborn or I like living on the edge. :-)\nIs there any way to have the hooks run for everyone?\n"},{"id":"190485","messageId":"7vaa1r8vhy.fsf@alter.siamese.dyndns.org","threadId":"30384","inReplyTo":"86r4v3mxf7.fsf@red.stonehenge.com","subject":"Re: Is there any way to make hooks part of the repository?","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2012-05-01T21:03:05Z","receivedAt":"2012-05-01T21:03:05Z","isPatch":false,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"merlyn@stonehenge.com (Randal L. Schwartz) writes:\n\n>>>>>> \"Junio\" == Junio C Hamano <gitster@pobox.com> writes:\n>\n> Junio> By design.  Do you want me to include \"rm -fr ~hilco\" in some hook of\n> Junio> git.git repository?\n>\n> This just came up yesterday at $PRIMARY_CLIENT.  One idea we kicked\n> around was having a convention for storing the hooks-to-be-populated in\n> \".githooks\" in the repository tree, and then having clone notice that\n> and offer to install them directly if from a trusted source, or at least\n> move them into a disabled state in .git/hooks otherwise.\n\nWe've talked about something like that a few times in the past, but as far\nas I (am concerned / remember) the conclusion has always been that is not\nworth \"standardizing\", i.e. nothing a ./setup script in-tree or a Makefile\ntarget cannot offer the same convenience.\n"},{"id":"190487","messageId":"CAE1pOi1Dpjow8mkwtPo2o1Zo9rkk6=hhpLqErG1XwTcn=un17A@mail.gmail.com","threadId":"30384","inReplyTo":"86r4v3mxf7.fsf@red.stonehenge.com","subject":"Re: Is there any way to make hooks part of the repository?","fromName":"Hilco Wijbenga","fromEmail":"hilco.wijbenga@gmail.com","sentAt":"2012-05-01T21:07:21Z","receivedAt":"2012-05-01T21:07:21Z","isPatch":false,"sender":{"key":"hilco.wijbenga@gmail.com","avatar":null},"body":"On 1 May 2012 13:57, Randal L. Schwartz <merlyn@stonehenge.com> wrote:\n>>>>>> \"Junio\" == Junio C Hamano <gitster@pobox.com> writes:\n>\n> Junio> By design.  Do you want me to include \"rm -fr ~hilco\" in some hook of\n> Junio> git.git repository?\n>\n> This just came up yesterday at $PRIMARY_CLIENT.  One idea we kicked\n> around was having a convention for storing the hooks-to-be-populated in\n> \".githooks\" in the repository tree, and then having clone notice that\n> and offer to install them directly if from a trusted source, or at least\n> move them into a disabled state in .git/hooks otherwise.\n\nI guess it would have to be more than just clone. You are quite likely\nto update/add hooks later on.\n"},{"id":"190488","messageId":"CAE1pOi00Mr4dOj2ChTJU9XWypUAaVUDDa36-M7LA+9BixW0nKw@mail.gmail.com","threadId":"30384","inReplyTo":"7vaa1r8vhy.fsf@alter.siamese.dyndns.org","subject":"Re: Is there any way to make hooks part of the repository?","fromName":"Hilco Wijbenga","fromEmail":"hilco.wijbenga@gmail.com","sentAt":"2012-05-01T21:09:36Z","receivedAt":"2012-05-01T21:09:36Z","isPatch":false,"sender":{"key":"hilco.wijbenga@gmail.com","avatar":null},"body":"On 1 May 2012 14:03, Junio C Hamano <gitster@pobox.com> wrote:\n> merlyn@stonehenge.com (Randal L. Schwartz) writes:\n>\n>>>>>>> \"Junio\" == Junio C Hamano <gitster@pobox.com> writes:\n>>\n>> Junio> By design.  Do you want me to include \"rm -fr ~hilco\" in some hook of\n>> Junio> git.git repository?\n>>\n>> This just came up yesterday at $PRIMARY_CLIENT.  One idea we kicked\n>> around was having a convention for storing the hooks-to-be-populated in\n>> \".githooks\" in the repository tree, and then having clone notice that\n>> and offer to install them directly if from a trusted source, or at least\n>> move them into a disabled state in .git/hooks otherwise.\n>\n> We've talked about something like that a few times in the past, but as far\n> as I (am concerned / remember) the conclusion has always been that is not\n> worth \"standardizing\", i.e. nothing a ./setup script in-tree or a Makefile\n> target cannot offer the same convenience.\n\nThis would not keep things up-to-date, though, would it? It seems like\nyet another thing developers need to remember and do. I would prefer\nsomething more automatic.\n"},{"id":"190496","messageId":"CAJsNXT=niP2Ja-pSbvj-OGi5t0x0-Zxm3CdcY0nLs9ROdCG8hg@mail.gmail.com","threadId":"30384","inReplyTo":"CAE1pOi00Mr4dOj2ChTJU9XWypUAaVUDDa36-M7LA+9BixW0nKw@mail.gmail.com","subject":"Re: Is there any way to make hooks part of the repository?","fromName":"PJ Weisberg","fromEmail":"pj@irregularexpressions.net","sentAt":"2012-05-01T21:59:18Z","receivedAt":"2012-05-01T21:59:18Z","isPatch":false,"sender":{"key":"pj@irregularexpressions.net","avatar":"https://gravatar.com/avatar/aa2c1edcc61b536cc5c9f37fbce084e655446e2309f9818d43f13d47304a602b?d=mp&s=160"},"body":"On Tue, May 1, 2012 at 2:09 PM, Hilco Wijbenga <hilco.wijbenga@gmail.com> wrote:\n\n> On 1 May 2012 14:03, Junio C Hamano <gitster@pobox.com> wrote:\n>\n>> We've talked about something like that a few times in the past, but as far\n>> as I (am concerned / remember) the conclusion has always been that is not\n>> worth \"standardizing\", i.e. nothing a ./setup script in-tree or a Makefile\n>> target cannot offer the same convenience.\n>\n> This would not keep things up-to-date, though, would it? It seems like\n> yet another thing developers need to remember and do. I would prefer\n> something more automatic.\n\nOnce your hooks are installed, couldn't your post-checkout and\npost-merge hooks keep all the others up to date?\n\n\n-PJ\n\nGehm's Corollary to Clark's Law: Any technology distinguishable from\nmagic is insufficiently advanced.\n"},{"id":"190501","messageId":"CAE1pOi02_u9j2oHy-RJ-XbrCmDiUWd4-=50f-v+iaK1GLaLQZw@mail.gmail.com","threadId":"30384","inReplyTo":"CAJsNXT=niP2Ja-pSbvj-OGi5t0x0-Zxm3CdcY0nLs9ROdCG8hg@mail.gmail.com","subject":"Re: Is there any way to make hooks part of the repository?","fromName":"Hilco Wijbenga","fromEmail":"hilco.wijbenga@gmail.com","sentAt":"2012-05-01T22:21:04Z","receivedAt":"2012-05-01T22:21:04Z","isPatch":false,"sender":{"key":"hilco.wijbenga@gmail.com","avatar":null},"body":"On 1 May 2012 14:59, PJ Weisberg <pj@irregularexpressions.net> wrote:\n> On Tue, May 1, 2012 at 2:09 PM, Hilco Wijbenga <hilco.wijbenga@gmail.com> wrote:\n>\n>> On 1 May 2012 14:03, Junio C Hamano <gitster@pobox.com> wrote:\n>>\n>>> We've talked about something like that a few times in the past, but as far\n>>> as I (am concerned / remember) the conclusion has always been that is not\n>>> worth \"standardizing\", i.e. nothing a ./setup script in-tree or a Makefile\n>>> target cannot offer the same convenience.\n>>\n>> This would not keep things up-to-date, though, would it? It seems like\n>> yet another thing developers need to remember and do. I would prefer\n>> something more automatic.\n>\n> Once your hooks are installed, couldn't your post-checkout and\n> post-merge hooks keep all the others up to date?\n\nExcellent point. Yes, that would certainly work.\n"},{"id":"190508","messageId":"CA+7g9JzvN+5RsSF+bRFtaMafZeY+TyFkXeq-6OSAW3qJ99JqKg@mail.gmail.com","threadId":"30384","inReplyTo":"CAE1pOi02_u9j2oHy-RJ-XbrCmDiUWd4-=50f-v+iaK1GLaLQZw@mail.gmail.com","subject":"Re: Is there any way to make hooks part of the repository?","fromName":"Nathan Gray","fromEmail":"n8gray@n8gray.org","sentAt":"2012-05-02T00:10:02Z","receivedAt":"2012-05-02T00:10:02Z","isPatch":false,"sender":{"key":"n8gray@n8gray.org","avatar":"https://avatars.githubusercontent.com/u/82794?v=4"},"body":"On Tue, May 1, 2012 at 3:21 PM, Hilco Wijbenga <hilco.wijbenga@gmail.com> wrote:\n> On 1 May 2012 14:59, PJ Weisberg <pj@irregularexpressions.net> wrote:\n>> On Tue, May 1, 2012 at 2:09 PM, Hilco Wijbenga <hilco.wijbenga@gmail.com> wrote:\n>>\n>>> On 1 May 2012 14:03, Junio C Hamano <gitster@pobox.com> wrote:\n>>>\n>>>> We've talked about something like that a few times in the past, but as far\n>>>> as I (am concerned / remember) the conclusion has always been that is not\n>>>> worth \"standardizing\", i.e. nothing a ./setup script in-tree or a Makefile\n>>>> target cannot offer the same convenience.\n>>>\n>>> This would not keep things up-to-date, though, would it? It seems like\n>>> yet another thing developers need to remember and do. I would prefer\n>>> something more automatic.\n>>\n>> Once your hooks are installed, couldn't your post-checkout and\n>> post-merge hooks keep all the others up to date?\n>\n> Excellent point. Yes, that would certainly work.\n\nBut beware, this has the effect of making your hooks\nversion-dependent.  Check out a different branch and you can\npotentially end up with a different hook.\n\nIMHO things like this belong in a separate \"admin\" repo -- policy may\nchange over time, but going back to an old version of your code\nshouldn't take you back to a correspondingly old version of your\npolicy.\n\nCheers,\n-n8\n\n-- \nHexaLex: A New Angle on Crossword Games for iPhone and iPod Touch\nhttp://hexalex.com\nOn The App Store: http://bit.ly/8Mj1CU\nOn Facebook: http://bit.ly/9MIJiV\nOn Twitter: http://twitter.com/hexalexgame\nhttp://n8gray.org\n"},{"id":"190509","messageId":"CAE1pOi2Gj-8fRhaUMmwhCDTLp27ETKeaExvm7iHz8HpObY8O+A@mail.gmail.com","threadId":"30384","inReplyTo":"CA+7g9JzvN+5RsSF+bRFtaMafZeY+TyFkXeq-6OSAW3qJ99JqKg@mail.gmail.com","subject":"Re: Is there any way to make hooks part of the repository?","fromName":"Hilco Wijbenga","fromEmail":"hilco.wijbenga@gmail.com","sentAt":"2012-05-02T00:18:46Z","receivedAt":"2012-05-02T00:18:46Z","isPatch":false,"sender":{"key":"hilco.wijbenga@gmail.com","avatar":null},"body":"On 1 May 2012 17:10, Nathan Gray <n8gray@n8gray.org> wrote:\n> On Tue, May 1, 2012 at 3:21 PM, Hilco Wijbenga <hilco.wijbenga@gmail.com> wrote:\n>> On 1 May 2012 14:59, PJ Weisberg <pj@irregularexpressions.net> wrote:\n>>> On Tue, May 1, 2012 at 2:09 PM, Hilco Wijbenga <hilco.wijbenga@gmail.com> wrote:\n>>>\n>>>> On 1 May 2012 14:03, Junio C Hamano <gitster@pobox.com> wrote:\n>>>>\n>>>>> We've talked about something like that a few times in the past, but as far\n>>>>> as I (am concerned / remember) the conclusion has always been that is not\n>>>>> worth \"standardizing\", i.e. nothing a ./setup script in-tree or a Makefile\n>>>>> target cannot offer the same convenience.\n>>>>\n>>>> This would not keep things up-to-date, though, would it? It seems like\n>>>> yet another thing developers need to remember and do. I would prefer\n>>>> something more automatic.\n>>>\n>>> Once your hooks are installed, couldn't your post-checkout and\n>>> post-merge hooks keep all the others up to date?\n>>\n>> Excellent point. Yes, that would certainly work.\n>\n> But beware, this has the effect of making your hooks\n> version-dependent.  Check out a different branch and you can\n> potentially end up with a different hook.\n>\n> IMHO things like this belong in a separate \"admin\" repo -- policy may\n> change over time, but going back to an old version of your code\n> shouldn't take you back to a correspondingly old version of your\n> policy.\n\nYou have a point, of course, however, checking out an older version\n(that does not comply with current policy) should not break (when\ninteracting with Git) just because of that. So I think there is at\nleast some justification to version the policy as well.\n\nThis is something we will simply have to experience to see what works best.\n"},{"id":"190524","messageId":"vpqfwbjnl4a.fsf@bauges.imag.fr","threadId":"30384","inReplyTo":"CAE1pOi0_ETdSYsuT0Udhbr6rDvmEcuTA157d6aKUosgi7w28jw@mail.gmail.com","subject":"Re: Is there any way to make hooks part of the repository?","fromName":"Matthieu Moy","fromEmail":"matthieu.moy@grenoble-inp.fr","sentAt":"2012-05-02T06:38:13Z","receivedAt":"2012-05-02T06:38:13Z","isPatch":false,"sender":{"key":"matthieu.moy@grenoble-inp.fr","avatar":"https://gravatar.com/avatar/72c8a2705971a25dfaff23cece15130d405685845d911aedd5667ace277f3fc5?d=mp&s=160"},"body":"Hilco Wijbenga <hilco.wijbenga@gmail.com> writes:\n\n> On 1 May 2012 13:33, Junio C Hamano <gitster@pobox.com> wrote:\n>> Hilco Wijbenga <hilco.wijbenga@gmail.com> writes:\n>>\n>>> Is there any way to get (some of) the Git hooks to run for everyone\n>>> without everyone having to install them separately? If no, is this by\n>>> design or simply a feature nobody has asked for (yet)?\n>>\n>> By design.  Do you want me to include \"rm -fr ~hilco\" in some hook of\n>> git.git repository?\n>\n> Mmm, well, I might get quite famous if you did... ;-)\n>\n> But if you wanted to be evil then you could easily find another place\n> (the build scripts, the code itself, et cetera).\n\nYes, but at least, you have the opportunity to examine the other places\nbefore they are ran. Hooks would be really, really nasty security-wise.\nFor example, \"git clone\" does a checkout, so should probably run the\ncheckout hooks.\n\n> So I don't think this is a good argument. Moreover, I do not work with\n> people that would ever consider such nastiness. You need to realize\n> that this is all closed source. Your argument would be more valid in\n> an open source environment (like git.git).\n\nThat may be acceptable for you, but you can't ask for such feature to be\nincluded in Git itself. At best, a standardized way to setup hooks (but\nsomething that would require a user-action to be set up) would be\nacceptable.\n\n-- \nMatthieu Moy\nhttp://www-verimag.imag.fr/~moy/\n"},{"id":"190585","messageId":"CAE1pOi3RZ+x7YcVZ-dLt70=wwRsvY9D6GQR-T+JZ9S7x8CFjPw@mail.gmail.com","threadId":"30384","inReplyTo":"vpqfwbjnl4a.fsf@bauges.imag.fr","subject":"Re: Is there any way to make hooks part of the repository?","fromName":"Hilco Wijbenga","fromEmail":"hilco.wijbenga@gmail.com","sentAt":"2012-05-02T19:10:41Z","receivedAt":"2012-05-02T19:10:41Z","isPatch":false,"sender":{"key":"hilco.wijbenga@gmail.com","avatar":null},"body":"On 1 May 2012 23:38, Matthieu Moy <Matthieu.Moy@grenoble-inp.fr> wrote:\n> Hilco Wijbenga <hilco.wijbenga@gmail.com> writes:\n>\n>> On 1 May 2012 13:33, Junio C Hamano <gitster@pobox.com> wrote:\n>>> Hilco Wijbenga <hilco.wijbenga@gmail.com> writes:\n>>>\n>>>> Is there any way to get (some of) the Git hooks to run for everyone\n>>>> without everyone having to install them separately? If no, is this by\n>>>> design or simply a feature nobody has asked for (yet)?\n>>>\n>>> By design.  Do you want me to include \"rm -fr ~hilco\" in some hook of\n>>> git.git repository?\n>>\n>> Mmm, well, I might get quite famous if you did... ;-)\n>>\n>> But if you wanted to be evil then you could easily find another place\n>> (the build scripts, the code itself, et cetera).\n>\n> Yes, but at least, you have the opportunity to examine the other places\n> before they are ran. Hooks would be really, really nasty security-wise.\n> For example, \"git clone\" does a checkout, so should probably run the\n> checkout hooks.\n\nThere is (or, rather, should be) absolutely no difference between code\nchanges and hook changes. Both would go through the same review\nprocess. If it's possible to put in nasty hooks then it's possible to\nput in nasty code.\n\n>> So I don't think this is a good argument. Moreover, I do not work with\n>> people that would ever consider such nastiness. You need to realize\n>> that this is all closed source. Your argument would be more valid in\n>> an open source environment (like git.git).\n>\n> That may be acceptable for you, but you can't ask for such feature to be\n> included in Git itself. At best, a standardized way to setup hooks (but\n> something that would require a user-action to be set up) would be\n> acceptable.\n\nGiven ${PROJECT}/.git, I would think that a simple config setting\n(hooks.run-automatically-this-is-a-security-risk [defaulting to false,\nof course]) and an extra directory like ${PROJECT}/.hooks (this should\nprobably be configurable as well: hooks.directory) would work\nperfectly. Then it's up to the project to decide if they want to use\nthat feature. Moreover, you could then still have \"personal\" hooks in\n${PROJECT}/.git/hooks.\n\nWould such a setup be acceptable?\n"},{"id":"190588","messageId":"7v1un2idt0.fsf@alter.siamese.dyndns.org","threadId":"30384","inReplyTo":"CAE1pOi3RZ+x7YcVZ-dLt70=wwRsvY9D6GQR-T+JZ9S7x8CFjPw@mail.gmail.com","subject":"Re: Is there any way to make hooks part of the repository?","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2012-05-02T19:27:23Z","receivedAt":"2012-05-02T19:27:23Z","isPatch":false,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Hilco Wijbenga <hilco.wijbenga@gmail.com> writes:\n\n> On 1 May 2012 23:38, Matthieu Moy <Matthieu.Moy@grenoble-inp.fr> wrote:\n> ...\n>> Yes, but at least, you have the opportunity to examine the other places\n>> before they are ran. Hooks would be really, really nasty security-wise.\n>> For example, \"git clone\" does a checkout, so should probably run the\n>> checkout hooks.\n>\n> There is (or, rather, should be) absolutely no difference between code\n> changes and hook changes. Both would go through the same review\n> process.\n\nMatthieu is *not* talking about auditing nastiness going into the\nproject's repository; he is talking is about a chance to audit whatever\ncomes from the project's repository that *could* potentially contain some\nnastiness before it causes harm to your working environment. In other\nwords, not *having* to trust what is in the project's repository, but\nhaving a way to verify.\n\nRead what he wrote again with that in mind, and you will understand his\npoint.\n"},{"id":"190590","messageId":"CAE1pOi1SLU5_eLr3ahiUjzQqPUnVPX70CPq=OW-o-85Lk43GwA@mail.gmail.com","threadId":"30384","inReplyTo":"7v1un2idt0.fsf@alter.siamese.dyndns.org","subject":"Re: Is there any way to make hooks part of the repository?","fromName":"Hilco Wijbenga","fromEmail":"hilco.wijbenga@gmail.com","sentAt":"2012-05-02T19:42:17Z","receivedAt":"2012-05-02T19:42:17Z","isPatch":false,"sender":{"key":"hilco.wijbenga@gmail.com","avatar":null},"body":"On 2 May 2012 12:27, Junio C Hamano <gitster@pobox.com> wrote:\n> Hilco Wijbenga <hilco.wijbenga@gmail.com> writes:\n>\n>> On 1 May 2012 23:38, Matthieu Moy <Matthieu.Moy@grenoble-inp.fr> wrote:\n>> ...\n>>> Yes, but at least, you have the opportunity to examine the other places\n>>> before they are ran. Hooks would be really, really nasty security-wise.\n>>> For example, \"git clone\" does a checkout, so should probably run the\n>>> checkout hooks.\n>>\n>> There is (or, rather, should be) absolutely no difference between code\n>> changes and hook changes. Both would go through the same review\n>> process.\n>\n> Matthieu is *not* talking about auditing nastiness going into the\n> project's repository; he is talking is about a chance to audit whatever\n> comes from the project's repository that *could* potentially contain some\n> nastiness before it causes harm to your working environment. In other\n> words, not *having* to trust what is in the project's repository, but\n> having a way to verify.\n>\n> Read what he wrote again with that in mind, and you will understand his\n> point.\n\nYes, I understand.\n\nPerhaps these automatic hooks should only be applicable for \"outgoing\"\nchanges like commit and push? That way you can review the hooks before\nthey run but you still have a chance to prevent developer errors from\ngetting to the server/other people (which is really all I care about,\nI am looking for a way to protect developers from making silly\nmistakes).\n"},{"id":"190628","messageId":"87ipgdskpx.fsf@thomas.inf.ethz.ch","threadId":"30384","inReplyTo":"CAE1pOi1SLU5_eLr3ahiUjzQqPUnVPX70CPq=OW-o-85Lk43GwA@mail.gmail.com","subject":"Re: Is there any way to make hooks part of the repository?","fromName":"Thomas Rast","fromEmail":"trast@student.ethz.ch","sentAt":"2012-05-03T09:00:10Z","receivedAt":"2012-05-03T09:00:10Z","isPatch":false,"sender":{"key":"tr@thomasrast.ch","avatar":"https://avatars.githubusercontent.com/u/153510?v=4"},"body":"Hilco Wijbenga <hilco.wijbenga@gmail.com> writes:\n\n>> Matthieu is *not* talking about auditing nastiness going into the\n>> project's repository; he is talking is about a chance to audit whatever\n>> comes from the project's repository that *could* potentially contain some\n>> nastiness before it causes harm to your working environment. In other\n>> words, not *having* to trust what is in the project's repository, but\n>> having a way to verify.\n>\n> Perhaps these automatic hooks should only be applicable for \"outgoing\"\n> changes like commit and push? That way you can review the hooks before\n> they run but you still have a chance to prevent developer errors from\n> getting to the server/other people (which is really all I care about,\n> I am looking for a way to protect developers from making silly\n> mistakes).\n\nShouldn't those checks be made server-side with a pre-receive hook?\n\n-- \nThomas Rast\ntrast@{inf,student}.ethz.ch\n"},{"id":"190656","messageId":"CAE1pOi39i4hg_bTuigq15ifuKtXVW7F-NukMP57E_4e=s0fMdQ@mail.gmail.com","threadId":"30384","inReplyTo":"87ipgdskpx.fsf@thomas.inf.ethz.ch","subject":"Re: Is there any way to make hooks part of the repository?","fromName":"Hilco Wijbenga","fromEmail":"hilco.wijbenga@gmail.com","sentAt":"2012-05-03T17:05:11Z","receivedAt":"2012-05-03T17:05:11Z","isPatch":false,"sender":{"key":"hilco.wijbenga@gmail.com","avatar":null},"body":"On 3 May 2012 02:00, Thomas Rast <trast@student.ethz.ch> wrote:\n> Hilco Wijbenga <hilco.wijbenga@gmail.com> writes:\n>\n>>> Matthieu is *not* talking about auditing nastiness going into the\n>>> project's repository; he is talking is about a chance to audit whatever\n>>> comes from the project's repository that *could* potentially contain some\n>>> nastiness before it causes harm to your working environment. In other\n>>> words, not *having* to trust what is in the project's repository, but\n>>> having a way to verify.\n>>\n>> Perhaps these automatic hooks should only be applicable for \"outgoing\"\n>> changes like commit and push? That way you can review the hooks before\n>> they run but you still have a chance to prevent developer errors from\n>> getting to the server/other people (which is really all I care about,\n>> I am looking for a way to protect developers from making silly\n>> mistakes).\n>\n> Shouldn't those checks be made server-side with a pre-receive hook?\n\nFirstly, see my original email: we have no such access to the server.\nSecondly, (now that I've thought about it a bit more), it makes more\nsense to do it on the \"client\" instead of having the server do all the\nwork for everybody. (Fail early, fail fast.)\n"},{"id":"190724","messageId":"CALKQrgcTtjQtS34EZhay8nMKxFO2iCHv+YCZjXefB6oZsa93kw@mail.gmail.com","threadId":"30384","inReplyTo":"CAE1pOi39i4hg_bTuigq15ifuKtXVW7F-NukMP57E_4e=s0fMdQ@mail.gmail.com","subject":"Re: Is there any way to make hooks part of the repository?","fromName":"Johan Herland","fromEmail":"johan@herland.net","sentAt":"2012-05-04T06:10:57Z","receivedAt":"2012-05-04T06:10:57Z","isPatch":false,"sender":{"key":"johan@herland.net","avatar":"https://avatars.githubusercontent.com/u/547031?v=4"},"body":"On Thu, May 3, 2012 at 7:05 PM, Hilco Wijbenga <hilco.wijbenga@gmail.com> wrote:\n> On 3 May 2012 02:00, Thomas Rast <trast@student.ethz.ch> wrote:\n>> Shouldn't those checks be made server-side with a pre-receive hook?\n>\n> Firstly, see my original email: we have no such access to the server.\n> Secondly, (now that I've thought about it a bit more), it makes more\n> sense to do it on the \"client\" instead of having the server do all the\n> work for everybody. (Fail early, fail fast.)\n\nNo matter how you go about this, there is no way to _guarantee_ that a\ngiven hook is run in all user repos (after all, the users have the\nultimate control over their own repos), so if you really _need_ the\nhook to be run, then you have no other choice but to put it on the\nserver. Such is the nature of distributed version control.\n\nIf you still want a hook to run in user repos, you can only ask that\nusers enable the hook by including a script which copies the hook into\nplace, and then tell your users to run that script (e.g. in your\nREADME).\n\n\n...Johan\n\n-- \nJohan Herland, <johan@herland.net>\nwww.herland.net\n"}]}