git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: preventing destructive operations to central repository

From
Shawn O. Pearce <spearce@spearce.org>
Date
Apr 16, 2010, 01:03 UTC
Message-ID
<20100416010344.GB6181@spearce.org>
In-Reply-To
<t2q76718491004151758p8862970bua5e7d60ccda8cdae@mail.gmail.com>
Jay Soffian <jaysoffian@gmail.com> wrote:
Show 21 quoted lines
> On Thu, Apr 15, 2010 at 8:39 PM, Brendan Miller <catphive@catphive.net> wrote:
> > Let's say you have a bare git repository writeable by a number of
> > different people. How do you prevent them from borking the central
> > repository?
> 
> Depends what you mean by borking, but you might consider starting with
> reading the "git config" man page for the following entries:
> 
> - receive.denyDeletes
> - receive.denyNonFastForwards
> 
> > Also, is there an automated mechanism to ensure that the timeline
> > stays clean? Say, force people to rebase their repositories before
> > merging into the shared repository?
> 
> In order to prevent merges, you will need to use a a receive-pack hook such as:
> 
> http://lists.gnu.org/archive/html/bug-gnulib/2008-10/msg00221.html
> 
> You might also consider something like gitosis/gitolite/gerrit
> depending upon how formal you want to be.

I think his only choice is to install a gitosis/gitolite/gerrit solution. Basically he needs to completely remove write access to the repository, so developers can't muck with it directly. That requires one of those 3 tools to provide secured proxy access.

On top of those, yea, you would then also want to configure the receive.denyDeletes and denyNonFastForwards you mentioned above, as well as maybe also write a custom update or pre-receive hook to prevent merges from entering the repository.

Though preventing merges is a bit pedantic. Eventually you'll want to use a merge rather than a rebase (e.g. merge in a maintenance branch to pick up its bug fixes into the main development trunk).

-- 
Shawn.
Previous: Jay Soffian
Message 3 of 3 in “preventing destructive operations to central repository”
  1. Brendan MillerApr 16, 2010
  2. Jay SoffianApr 16, 2010
  3. Shawn O. PearceApr 16, 2010

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.