git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Gnome chose Git

From
Shawn O. Pearce <spearce@spearce.org>
Date
Mar 19, 2009, 15:16 UTC
Message-ID
<20090319151610.GO23521@spearce.org>
In-Reply-To
<1cd1989b0903190701uac4602dl1d2c3cace45a9938@mail.gmail.com>
Pat Notz <patnotz@gmail.com> wrote:
Show 20 quoted lines
> On Thu, Mar 19, 2009 at 7:50 AM, Michael J Gruber
> <git@drmicha.warpmail.net> wrote:
> > Pat Notz venit, vidit, dixit 19.03.2009 14:43:
> >> On Thu, Mar 19, 2009 at 7:33 AM, Michael J Gruber
> >> <git@drmicha.warpmail.net> wrote:
> >>>
> >>> Also, they need push tracking for pushing through ssh, which is a common
> >>> requirement for many large projects. Do we have something to support
> >>> that? git-notes comes to my mind.
> >>>
> >>> Their current approach is writing to a single log file (receive-hook).
> >>> That may support a linear push history best, but looking up who pushed
> >>> what, given "what"?
> >>
> >> That's also something we do. ?Since the post-receive hook gives you
> >> the refname and the old and new refs you should have everything you
> >> need. ?We basically record the user name, UTC timestamp and the ref
> >> info. ?With a little bit more scripting you should be able to figure
> >> everything else out (though post-receive isn't called for local
> >> commits).
Why are people reinventing the reflog, and core.logallrefupdates ?
Show 5 quoted lines
> > I know the info is there. It might just make more sense to have it in
> > the git repo the way notes are/will be: It's public, it's connected to
> > the commits, it's tamper proof (anyone would notice rewrites).
> 
> Ahh, yes.  We'd like that too.
Eclipse is also talking about Git, and has a similar problem.

Anytime you start talking about "who put what" though, you get into a "where, and why does it matter?"

Imagine you are Eclipse Foundation or GNOME, you need to know which authorized developer put the code on your servers.

But imagine you are an ISV like Oracle or IBM and you consume code from the upstream project (Eclipse), put it on your servers, add some "extra sauce", and distribute the result in some form. Who put what on the Eclipse server isn't relevant, but what employee your clone to use 3.4.1 instead of 3.4.0 matters a whole lot more. For the most part, you just trust the upstream to do their own IP tracking and diligence, as they have the contributor license agreements, and you don't.

Its a thorny problem. We've talked about trying to add some sort of GnuPG signature into a push stream (for example) to allow the server to store a record of who-did-what-when and later distribute that back.

  http://thread.gmane.org/gmane.comp.version-control.git/71849
-- 
Shawn.
Previous: Pat NotzNext: Pat Notz
Message 7 of 21 in “Gnome chose Git”
  1. Teemu LikonenMar 19, 2009
  2. Sverre RabbelierMar 19, 2009
  3. Mike RalphsonMar 19, 2009
  4. Andreas EricssonMar 19, 2009
  5. Michael J GruberMar 19, 2009
  6. Pat NotzMar 19, 2009
  7. Shawn O. PearceMar 19, 2009
  8. Pat NotzMar 19, 2009
  9. Jeff KingMar 19, 2009
  10. demerphqMar 19, 2009
  11. Shawn O. PearceMar 19, 2009
  12. Shawn O. PearceMar 19, 2009
  13. demerphqMar 19, 2009
  14. Shawn O. PearceMar 19, 2009
  15. demerphqMar 19, 2009
  16. Johannes SchindelinMar 19, 2009
  17. demerphqMar 19, 2009
  18. Jeff KingMar 20, 2009
  19. make oneline reflog dates more consistent with multiline formatJeff King, Mar 20, 2009
  20. Michael J GruberMar 20, 2009
  21. Jeff KingMar 20, 2009

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.