From: Junio C Hamano Date: Tue, 27 Sep 2005 07:13:43 GMT Subject: Re: shared GIT repos Message-ID: <7vu0g70yqg.fsf_-_@assigned-by-dhcp.cox.net> In-Reply-To: Matthias Urlichs writes: > Speaking of which -- is anybody working on that one? > > I find myself in need of a multiuser shared repository that cannot > be corrupted (i.e. I want to prevent the users from removing objects, > and replacing a ref with something that is not a child of the sha1 that's > already there should also be prevented). Do you want to guard the repository from malicious users? Or is it enough to guard a casual/careless user from making mistakes? If one has commit privileges, then one can already do enough harm to the project without being able to remove objects nor updating a ref with non-fast-forward ref. So let's assume for now that malicious users are not something we worry about. In that case, "working on" might be too scary a word. I think most of the pieces are already there and you only need to assemble them and write a howto ;-). - Place the users that has write access to the repository in the same Unix group, and have the repository owned by that group; - Give the users ssh access, perhaps with authorized_keys set up to only allow running git-receive-pack and nothing else (like normal shell access); - Set up hooks/update to make sure the ref updates are fast forward. Additionally, you could set up a mapping that says which user can/cannot update which refs if you wanted to. -jc