Re: Reason for objects still being written with a failing pre-receive hook?
- From
Shawn O. Pearce <spearce@spearce.org>
- Date
- Jun 24, 2009, 13:57 UTC
- Message-ID
- <20090624135713.GE11191@spearce.org>
- In-Reply-To
- <9e0f31700906240621k314b4bbehc283c8a1c673a2f1@mail.gmail.com>
Johan S?rensen <johan@johansorensen.com> wrote:
> I'm wondering what the reason is that objects are still being stored, > despite a non-zero exit code from the pre-receive hook?
The pre-receive hook is allowed to inspect the objects that have been uploaded in order to make its access decision. Thus those objects must have been unpacked (or indexed into a new pack) so git commands in the pre-receive hook can read them.
> If it's expected and accepted behaviour, what other options do I have > to prevent a scenario like the above?
There currently isn't a way to stop this, other than to use something in front of git-receive-pack, e.g. Gitosis, to deny even forking the receive-pack binary for the user.
-- Shawn.