git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: ACLs for GIT

From
Phil Hord <hordp@cisco.com>
Date
May 16, 2011, 15:33 UTC
Message-ID
<4DD143CA.3000700@cisco.com>
In-Reply-To
<4DD1250D.50005@bbn.com>
On 05/16/2011 09:22 AM, Martin L Resnick wrote:
Show 11 quoted lines
> Thanks Mangus.
>
> You pointed out some hurdles I'll have to think about
> (blocked files not matching the SHA and so can't be committed).
>
> As to why I want to do this consider NSA non-export rules.
> Our application would be built with NSA encryption
> but we have foreign nationals working on the code
> and so they are not permitted to see that part.
> The makefiles look to see if the NSA encryption code file
> is there and link it in. If not a stub is used.

We use submodules for this same need here. If the submodule is loaded, the code is used from that. If not, pre-built binaries are used instead. These could be stubs.

When we share code with outside partners, we give them access only to the modules they need.

We further guard the code in the submodule by PGP-encrypting the source files and storing them in the repository (as binaries). This practice lets us be more free with the repository and not worry so much that it may be cloned well out of our control. Storing code as shrouded binaries negates much of git's power, but only for this one submodule. Our other submodules are still quite git-friendly.

Phil
Previous: Richard PetersonNext: Martin L Resnick
Message 5 of 15 in “ACLs for GIT”
  1. Martin L ResnickMay 15, 2011
  2. Magnus BäckMay 15, 2011
  3. Martin L ResnickMay 16, 2011
  4. Richard PetersonMay 16, 2011
  5. Phil HordMay 16, 2011
  6. Martin L ResnickMay 16, 2011
  7. Jakub NarebskiMay 16, 2011
  8. R. Tyler CroyMay 15, 2011
  9. Martin L ResnickMay 16, 2011
  10. Sitaram ChamartyMay 17, 2011
  11. Shawn PearceMay 17, 2011
  12. Sitaram ChamartyMay 17, 2011
  13. Shawn PearceMay 17, 2011
  14. Sitaram ChamartyMay 17, 2011
  15. Marc WeberMay 15, 2011

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.