git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Git and securing a repository

From
Junio C Hamano <gitster@pobox.com>
Date
Jan 3, 2008, 09:36 UTC
Message-ID
<7vzlvns11r.fsf@gitster.siamese.dyndns.org>
In-Reply-To
<200801031011.29050.jnareb@gmail.com>
Jakub Narebski <jnareb@gmail.com> writes:
Show 12 quoted lines
> Shawn O. Pearce wrote:
>> Jakub Narebski <jnareb@gmail.com> wrote:
>   
>> > AFAIK both update and pre-receive hooks are invoked also on fetch...
>> > but I might be mistaken.
>> 
>> No, they are *not* invoked on fetch.  Currently no hooks execute
>> during fetch; either on the server *or* on the client side of
>> the connection.
>
> Errr... I think at least post-update hook (the one with 
> git-update-server-info by default) is invoked on fetch.

Please don't think then. Instead check your facts before posting to avoid wasting bandwidth and people's time. The post-update hook is run on the remote end when you push into it.

I do not particularly like hooks that act after an operation is initiated locally and act solely on local data. This is maybe because I still consider git tools building blocks suitable for higher level scripting more than other people do.

There are five valid reasons you might want a hook to a git operation:

 (1) A hook that countermands the normal decision made by the
     underlying command.  Examples of this class are the update
     hook and the pre-commit hook.
 (2) A hook that operates on data generated after the command
     starts to run.  The ability to munge the commit log message
     by the commit-msg hook is an example.
 (3) A hook that operates on the remote end of the connection
     that you may not otherwise have access to other than over
     the git protocol.  An example is the post-update hook.
 (4) A hook that runs under a lock that is acquired by the
     command for mutual exclusion.  Currently there is no
     example, but if we allowed the update hook to modify the
     commit that was pushed through send-pack => receive-pack
     pair, which was discussed on the list a while ago, it would
     be a good example of this.
 (5) A hook that is run differently depending on the outcome of
     the command.  The post-merge hook conditionally run by
     git-pull is an example of this (it is not even run if no
     merge takes place).  Another example is the post-checkout
     hook that gets information that is otherwise harder to get
     (namely, if it was a branch checkout or file checkout --
     you can figure it out by examining the command line but
     that already is part of the processing git-checkout does
     anyway, so no need to force duplicating that code in the
     userland).

You cannot do an equivalent operation from outside the git command for the above classes of operations. You need hooks for them.

On the other hand, if you want to always cause an action after running a git opeation locally, you do not have to have a hook. You can just run them yourself, or have "git myfetch" wrapper that does whatever you want after running "git fetch". Only when the combination of the underlying command and something else is widely useful, _and_ that something else needs flexibility, a hook is warranted (if that something else is always the same thing, it is better to fold that into the underlying command).

Previous: Jakub NarebskiNext: Jan Hudec
Message 14 of 18 in “Git and securing a repository”
  1. Gonzalo GarramuñoJan 2, 2008
  2. Felipe BalbiJan 2, 2008
  3. Gonzalo GarramuñoJan 2, 2008
  4. David SymondsJan 2, 2008
  5. Gonzalo GarramuñoJan 2, 2008
  6. Jakub NarebskiJan 2, 2008
  7. Shawn O. PearceJan 3, 2008
  8. Bruno Cesar RibasJan 3, 2008
  9. Gonzalo GarramuñoJan 3, 2008
  10. Shawn O. PearceJan 3, 2008
  11. Gonzalo GarramuñoJan 3, 2008
  12. Shawn O. PearceJan 3, 2008
  13. Jakub NarebskiJan 3, 2008
  14. Junio C HamanoJan 3, 2008
  15. Jan HudecJan 2, 2008
  16. Gregory JefferisJan 2, 2008
  17. Linus TorvaldsJan 2, 2008
  18. Daniel BarkalowJan 2, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.