git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Git - Pushing to a production website

From
Boyd Stephen Smith Jr. <bss@iguanasuicide.net>
Date
Jan 10, 2009, 05:04 UTC
Message-ID
<200901092304.51986.bss@iguanasuicide.net>
In-Reply-To
<20090109224618.5d8c461c@family.dyweni.com>
On Friday 2009 January 09 22:46:18 4jxDQ6FQee2H@dyweni.com wrote:
Show 9 quoted lines
>> You could simply commit after running the perl script.  You could
>> even commit to a branch so that it's (a little) less likely those
>> changes get integrated into master.
>
>How about this, ran by the post-update hook:
>
>For the first update:
>
> - Do a git pull
I'm not enitirely sure you want post-update doing the pull.
> - Then create a new branch 'working' and checkout
> - Apply the patches to 'working' and commit
>
>This leaves 'working' == 'master^'
Actually, it leaves HEAD == working and master == working^.
Show 5 quoted lines
>For subsequent updates:
> - Compare the SHA1 hashes for 'working' and 'master^'.
>   - If they don't match, throw an error and exit
> - Assuming they match, checkout 'master' and delete 'working'
> - Do a git pull
(See above)
Show 8 quoted lines
> - Then create a new branch 'working' and checkout
> - Apply the patches to 'working' and commit
>
>
>This would keep the working directory clean and allow future updates to
>occur, if no one commits anything to git 'working'.  If they did, the
>script would exit and prevent the update requiring the developer to
>review the commit logs and cherry-pick where necessary.

It wouldn't *completely* prevent changes to working as one could "git commit --amend" and still have working^ == master. That said, if developers get creative enough they can probably bypass most measures, at least those based on a hook.

A privileged process for updates could stash the expected SHA for master and working somewhere developers can't write. That should prevent even dedicated developers from making unauthorized changes, modulo security/cryptographic exploits.

-- 
Boyd Stephen Smith Jr.                     ,= ,-_-. =. 
bss@iguanasuicide.net                     ((_/)o o(\_))
ICQ: 514984 YM/AIM: DaTwinkDaddy           `-'(. .)`-' 
http://iguanasuicide.net/                      \_/     
Previous: 4jxdq6fqee2h@dyweni.comNext: 4jxdq6fqee2h@dyweni.com
Message 4 of 10 in “Git - Pushing to a production website”
  1. 4jxdq6fqee2h@dyweni.comJan 10, 2009
  2. Boyd Stephen Smith Jr.Jan 10, 2009
  3. 4jxdq6fqee2h@dyweni.comJan 10, 2009
  4. Boyd Stephen Smith Jr.Jan 10, 2009
  5. 4jxdq6fqee2h@dyweni.comJan 10, 2009
  6. Boyd Stephen Smith Jr.Jan 10, 2009
  7. david@lang.hmJan 10, 2009
  8. Jacob HelwigJan 10, 2009
  9. David AguilarJan 10, 2009
  10. Sitaram ChamartyJan 10, 2009

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.