git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[RFD] Rewriting safety - warn before/when rewriting published history

From
Jakub Narebski <jnareb@gmail.com>
Date
Feb 4, 2012, 19:45 UTC
Message-ID
<201202042045.54114.jnareb@gmail.com>

Git includes protection against rewriting published history on the receive side with fast-forward check by default (which can be overridden) and various receive.deny* configuration variables, including receive.denyNonFastForwards.

Nevertheless git users requested (among others in Git User's Survey) more help on creation side, namely preventing rewriting parts of history which was already made public (or at least warning that one is about to rewrite published history). The "warn before/when rewriting published history" answer in "17. Which of the following features would you like to see implemented in git?" multiple-choice question in latest Git User's Survey 2011[1] got 24% (1525) responses.

[1]: https://www.survs.com/results/Q5CA9SKQ/P7DE07F0PL

So people would like for git to warn them about rewriting history before they attempt a push and it turns out to not fast-forward.

What prompted this email is the fact that Mercurial includes support for tracking which revisions (changesets) are safe to modify in its 2.1 latest version:

  http://lwn.net/Articles/478795/
  http://mercurial.selenic.com/wiki/WhatsNew
It does that by tracking so called "phase" of a changeset (revision).
  http://mercurial.selenic.com/wiki/Phases
  http://mercurial.selenic.com/wiki/PhasesDevel
  http://www.logilab.org/blogentry/88203
  http://www.logilab.org/blogentry/88219
  http://www.logilab.org/blogentry/88259
  

While we don't have to play catch-up with Mercurial features, I think something similar to what Mercurial has to warn about rewriting published history (amend, rebase, perhaps even filter-branch) would be nice to have. Perhaps even follow UI used by Mercurial, and/or translating its implementation into git terms.

In Mercurial 2.1 there are three available phases: 'public' for published commits, 'draft' for local un-published commits and 'secret' for local un-published commits which are not meant to be published.

The phase of a changeset is always equal to or higher than the phase of it's descendants, according to the following order:

      public < draft < secret
Commits start life as 'draft', and move to 'public' on push.

Mercurial documentation talks about phase of a commit, which might be a good UI, ut also about commits in 'public' phase being "immutable". As commits in Git are immutable, and rewriting history is in fact re-doing commits, this description should probably be changed.

While default "push matching" behavior makes it possible to have "secret" commits, being able to explicitly mark commits as not for publishing might be a good idea also for Git.

What do you think about this?
-- 
Jakub Narebski
Poland
Next: Ben Walton
Message 1 of 34 in “[RFD] Rewriting safety - warn before/when rewriting published history”
  1. Jakub NarebskiFeb 4, 2012
  2. Ben WaltonFeb 5, 2012
  3. Jakub NarebskiFeb 5, 2012
  4. Steven MichalskeFeb 6, 2012
  5. Johan HerlandFeb 6, 2012
  6. Jakub NarebskiFeb 6, 2012
  7. Steven MichalskeApr 7, 2012
  8. Jakub NarebskiFeb 5, 2012
  9. Johan HerlandFeb 5, 2012
  10. Jakub NarebskiFeb 5, 2012
  11. Johan HerlandFeb 5, 2012
  12. Jakub NarebskiFeb 6, 2012
  13. Johan HerlandFeb 6, 2012
  14. Jakub NarebskiFeb 6, 2012
  15. Johan HerlandFeb 6, 2012
  16. Jakub NarebskiFeb 7, 2012
  17. Johan HerlandFeb 7, 2012
  18. Jakub NarebskiFeb 10, 2012
  19. Philip OakleyFeb 10, 2012
  20. Johan HerlandFeb 11, 2012
  21. Jakub NarebskiFeb 11, 2012
  22. [RFC] pre-rebase: Refuse to rewrite commits that are reachable from upstreamJohan Herland, Feb 20, 2012
  23. Johan HerlandFeb 20, 2012
  24. Junio C HamanoFeb 20, 2012
  25. Johan HerlandFeb 21, 2012
  26. Junio C HamanoFeb 21, 2012
  27. Johan HerlandFeb 21, 2012
  28. Junio C HamanoFeb 21, 2012
  29. Dave ZarzyckiFeb 21, 2012
  30. Jeff KingFeb 22, 2012
  31. Dave ZarzyckiFeb 22, 2012
  32. Steven MichalskeApr 7, 2012
  33. Steven MichalskeApr 7, 2012
  34. Ronan KeryellFeb 7, 2012

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.