git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Detecting source of a push in a pre-receive hook

From
Jeff King <peff@peff.net>
Date
Jan 21, 2026, 05:27 UTC
Message-ID
<20260121052705.GA567009@coredump.intra.peff.net>
In-Reply-To
<CAFOYHZDcFJBiZwmposZVGmymmRz1XOaXP8iCRgTDVcsWPTH=6g@mail.gmail.com>
On Wed, Jan 21, 2026 at 09:45:51AM +1300, Chris Packham wrote:
Show 6 quoted lines
> For various reasons we also have a CI system that pushes some things
> (mostly tags but some automated merge commits as well) that runs as
> the same user. We'd really like to be able to have the pre-receive
> hook reject pushes from the CI system but allow them from the Gerrit
> server. Does the pre-receive hook have any way of knowing the source
> of a push operation?

Git doesn't do any authentication or know about the push sources itself; it just sees that stdin/stdout have somehow been hooked up to a client.

But the protocol layer that does that hooking up sometimes leaves information in the environment. If clients are connecting over ssh, for example, then you'll probably have an $SSH_CLIENT variable set. For HTTP, you'd probably get $REMOTE_ADDR, I think.

How do you want to identify the CI system versus the Gerrit system? The suggestions above would look at the source IP. If you're using ssh and have different keys for each incoming entity, you could probably add an "environment=" field to your authorized_keys file, and then check that field in the pre-receive hook (or if you wanted, even use a "command=" field to restrict git-receive-pack to only specific keys).

Over HTTP, you'd have to look at how authentication is done for the two entities. I _think_ you reliably get $REMOTE_USER if there was the usual HTTP auth done, and you could check that. But you could probably also do some server-specific magic to reject receive-pack quests. There are some hints for Apache in the git-http-backend manpage, but you might also be able to copy ideas from the test config we use in t/lib-httpd.

-Peff
Previous: rsbecker@nexbridge.comNext: Jeff King
Message 3 of 4 in “Detecting source of a push in a pre-receive hook”
  1. Chris PackhamJan 20, 2026
  2. rsbecker@nexbridge.comJan 20, 2026
  3. Jeff KingJan 21, 2026
  4. Jeff KingJan 21, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.