git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] push: disable lazy --force-with-lease by default

From
Ævar Arnfjörð Bjarmason <avarab@gmail.com>
Date
Jul 7, 2017, 09:54 UTC
Message-ID
<8760f4bmig.fsf@gmail.com>
In-Reply-To
<1n8sh3u.1lsabkd1pislrwM%lists@haller-berlin.de>
On Fri, Jul 07 2017, Stefan Haller jotted:
Show 19 quoted lines
> Junio C Hamano <gitster@pobox.com> wrote:
>
>> It turns out that some people use third-party tools that fetch from
>> remote and update the remote-tracking branches behind users' back,
>> defeating the safety relying on the stability of the remote-tracking
>> branches.
>
> Third-party tools are not the only problem. They may make the problem
> more likely to occur, but it can also happen without them. (See below.)
>
>> Let's disable the form that relies on the stability of remote-tracking
>> branches by default, and allow users who _know_ their remote-tracking
>> branches are stable to enable it with a configuration variable.
>
> I'm wondering if people who claim they know they are safe really do.
> Elsewhere in the other thread somebody said "I only ever explicitly
> fetch, so I know I'm safe". Are you sure?
>
> Consider this example:

Both of your examples explicitly fetch. Yes this could be confusing to someone who doesn't understand that "git fetch" doesn't just fetch the current remote branch, but all branches.

> What I'm getting at is that there's a lot of things that you have to
> remember to not do in order to make --force-with-lease without parameter
> a useful tool.
Fully agreed, it's confusing, but it's less shitty than --force.

The concern I have with Junio's patch above (but I like Francesco Mazzoli's approach better) is that the safety of the various --force options, from least safe to most safe, is:

 1. --force: You blow away the remote history, no idea what's there, or
    if your local ref mirrors what you just wiped.
 2. --force-with-lease: Even if you have a `git fetch` in the
     background, at least if you wipe a remote ref you have a copy in a
     local reflog to restore it.
 3. --force-with-lease=master:origin/master: More explicit, but still
     subject to the caveat with background fetching.
 4. --force-with-lease=master:<manually copied sha1>: You know exactly
     what you're wiping, and have likely reviewed that exact commit.

Yes, #4 is the safest, #2 & #3 are similar but subject to various caveats with background fetching / users not realizing "git pull" fetches everything etc.

But I think we have to keep our eye on the ball here. Which is to enact a net increase in user safety.

Right now most users who want to force a remote branch just use --force. E.g. Stack Overflow shows >100k results for git + --force, but just 500 for git + --force-with-lease.

You and others are rightly pointing out that --force-with-lease has lots of caveats, but that as an argument-less flag is something we could (with Francesco patch) turn on by default as a --force replacement.

This would leave users better off than they were before, because now when they accidentally wipe something they at least have a local copy if they did the wrong thing.

Moving everyone from #1 to #2 would be a net increase in user safety without more complex UX. Not having #2 would, for a lot of users who'd otherwise be happy to use #2, mean they'll just use #1 (the least safe option!) instead of the more ideal #4.

Which is why I think we should take Francesco's patch (with fixes from feedback), instead of Junio's.

Previous: Jeff KingNext: Junio C Hamano
Message 29 of 49 in “Tools that do an automatic fetch defeat "git push --force-with-lease"”
  1. Matt McCutchenApr 8, 2017
  2. Stefan HallerApr 8, 2017
  3. Ævar Arnfjörð BjarmasonApr 8, 2017
  4. Jeff KingApr 8, 2017
  5. Jakub NarębskiApr 8, 2017
  6. push: document & test --force-with-lease with multiple remotesÆvar Arnfjörð Bjarmason, Apr 8, 2017
  7. Simon RuderichApr 9, 2017
  8. Ævar Arnfjörð BjarmasonApr 9, 2017
  9. Junio C HamanoApr 17, 2017
  10. push: document & test --force-with-lease with multiple remotesÆvar Arnfjörð Bjarmason, Apr 19, 2017
  11. Jacob KellerApr 8, 2017
  12. Jeff KingApr 8, 2017
  13. Jacob KellerApr 8, 2017
  14. Stefan HallerApr 9, 2017
  15. Jacob KellerApr 9, 2017
  16. Stefan HallerApr 9, 2017
  17. Jacob KellerApr 10, 2017
  18. Ævar Arnfjörð BjarmasonApr 10, 2017
  19. Jacob KellerApr 10, 2017
  20. Junio C HamanoApr 11, 2017
  21. Stefan HallerApr 12, 2017
  22. push: disable lazy --force-with-lease by defaultJunio C Hamano, Jul 6, 2017
  23. Stefan BellerJul 6, 2017
  24. Junio C HamanoJul 6, 2017
  25. Stefan BellerJul 6, 2017
  26. Stefan BellerJul 10, 2017
  27. Stefan HallerJul 7, 2017
  28. Jeff KingJul 7, 2017
  29. Ævar Arnfjörð BjarmasonJul 7, 2017
  30. Junio C HamanoJul 7, 2017
  31. Ævar Arnfjörð BjarmasonJul 15, 2017
  32. Junio C HamanoJul 17, 2017
  33. Ævar Arnfjörð BjarmasonJul 7, 2017
  34. Stefan HallerApr 11, 2017
  35. Stefan HallerApr 11, 2017
  36. Jeff KingApr 10, 2017
  37. Stefan HallerApr 11, 2017
  38. Jeff KingApr 11, 2017
  39. Stefan HallerApr 12, 2017
  40. Stefan HallerApr 9, 2017
  41. Jacob KellerApr 9, 2017
  42. Jacob KellerApr 8, 2017
  43. Jeff KingApr 8, 2017
  44. Stefan HallerApr 8, 2017
  45. Jeff KingApr 8, 2017
  46. Stefan HallerApr 8, 2017
  47. Ævar Arnfjörð BjarmasonApr 8, 2017
  48. Stefan HallerApr 8, 2017
  49. Stefan HallerApr 12, 2017

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.