git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: thoughts on a possible "pre-upload" hook

From
Sitaram Chamarty <sitaramc@gmail.com>
Date
Sep 25, 2009, 13:43 UTC
Message-ID
<2e24e5b90909250643s5fb469f8x6974fed96aba4db4@mail.gmail.com>
In-Reply-To
<vpqab0j1a2s.fsf@bauges.imag.fr>

On Fri, Sep 25, 2009 at 5:59 PM, Matthieu Moy <Matthieu.Moy@grenoble-inp.fr> wrote:

Show 13 quoted lines
> Sitaram Chamarty <sitaramc@gmail.com> writes:
>
>> yes indeed -- if someone were to foolishly merge a "secret" branch
>> into a "normal" branch, so that it is now reachable from a "normal"
>> branch, that's his problem -- that cannot be within the scope of this
>> check.
>
> Merging is not the only scenario. Adding a tag could make secret
> things become visible too. I'm not saying the approach isn't viable,
> but if it gets implemented, it should be done with care to make sure
> there's no easy mis-use that would lead to reveal a secret (typically,
> I'd do that with a whitelist and not a black-list, so that new
> references are secret by default).

A whitelist may be better, but I'd be quite happy with a blacklist, if that's easier to implement, and take on myself/my team the onus of ensuring that code remains unreachable from any of the non-blacklisted tags.

In other words, I don't expect this to be idiot-proof and I'll take what I can get and work with it :-)

-- 
Sitaram
Previous: Matthieu MoyNext: Adam Brewster
Message 7 of 9 in “thoughts on a possible "pre-upload" hook”
  1. Sitaram ChamartySep 22, 2009
  2. Randal L. SchwartzSep 22, 2009
  3. Matthieu MoySep 22, 2009
  4. Shawn O. PearceSep 22, 2009
  5. Sitaram ChamartySep 25, 2009
  6. Matthieu MoySep 25, 2009
  7. Sitaram ChamartySep 25, 2009
  8. Adam BrewsterSep 28, 2009
  9. Sitaram ChamartySep 28, 2009

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.