git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Question: What's the best way to implement directory permission control in git?

From
Ævar Arnfjörð Bjarmason <avarab@gmail.com>
Date
Jul 27, 2022, 09:17 UTC
Message-ID
<220727.86mtculxnz.gmgdl@evledraar.gmail.com>
In-Reply-To
<CAOLTT8QusNzdO1mHqQFPz84pznYSpFWJunroRGXQ7qk6sJjeYg@mail.gmail.com>
On Wed, Jul 27 2022, ZheNing Hu wrote:
Show 38 quoted lines
> if there is a monorepo such as
> git@github.com:derrickstolee/sparse-checkout-example.git
>
> There are many files and directories:
>
> client/
>     android/
>     electron/
>     iOS/
> service/
>     common/
>     identity/
>     list/
>     photos/
> web/
>     browser/
>     editor/
>     friends/
> boostrap.sh
> LICENSE.md
> README.md
>
> Now we can use partial-clone + sparse-checkout to reduce
> the network overhead, and reduce disk storage space size, that's good.
>
> But I also need a ACL to control what directory or file people can fetch/push.
> e.g. I don't want a client fetch the code in "service" or "web".
>
> Now if the user client use "git log -p" or "git sparse-checkout add service"...
> or other git command, git which will  download them by
> "git fetch --filter=blob:none --stdin <oid>" automatically.
>
> This means that the git client and server interact with git objects
> (and don't care about path) we cannot simply ban someone download
> a "path" on the server side.
>
> What should I do? You may recommend me to use submodule,
> but due to its complexity, I don't really want to use it :-(
There isn't a way to do this in git.

It's theoretically possible, i.e. a client could be told that the SHA-1 of a directory is XYZ, and construct a commit object with a reference to it.

But currently a *lot* of things in the client code assume that these things will be available in one way or another.

The state-of-the-art in the "sparse" code may differ from the above, I don't know.

Also note that there's a well-known edge case in the git protocol where it's really incompatible with the notion of "secret" data, i.e. even if you hide a ref you'll be able to "guess" it by seeing what delta(s) the server will produce or accept etc.

Previous: ZheNing HuNext: ZheNing Hu
Message 2 of 13 in “Question: What's the best way to implement directory permission control in git?”
  1. ZheNing HuJul 27, 2022
  2. Ævar Arnfjörð BjarmasonJul 27, 2022
  3. ZheNing HuJul 28, 2022
  4. Ævar Arnfjörð BjarmasonJul 28, 2022
  5. Elijah NewrenJul 29, 2022
  6. ZheNing HuJul 29, 2022
  7. rsbecker@nexbridge.comJul 29, 2022
  8. ZheNing HuJul 29, 2022
  9. Thomas GuyotJul 27, 2022
  10. ZheNing HuJul 29, 2022
  11. Emily ShafferJul 29, 2022
  12. ZheNing HuJul 31, 2022
  13. Han-Wen NienhuysAug 1, 2022

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.