git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: On undoing a forced push

From
Stefan Beller <sbeller@google.com>
Date
Jun 9, 2015, 16:55 UTC
Message-ID
<CAGZ79kYLGV0mp2JzT8p4ZK2_zsbMiYD_yjp4boTMx=bygAYrMw@mail.gmail.com>
In-Reply-To
<012a980b0b9f1aa394e2b3701e4e6f97@www.dscho.org>

On Tue, Jun 9, 2015 at 9:29 AM, Johannes Schindelin <johannes.schindelin@gmx.de> wrote:

Show 30 quoted lines
> Hi,
>
> On 2015-06-09 16:06, Sitaram Chamarty wrote:
>> On 06/09/2015 05:42 PM, Duy Nguyen wrote:
>>> From a thread on Hacker News. It seems that if a user does not have
>>> access to the remote's reflog and accidentally forces a push to a ref,
>>> how does he recover it? In order to force push again to revert it
>>> back, he would need to know the remote's old SHA-1. Local reflog does
>>> not help because remote refs are not updated during a push.
>>>
>>> This patch prints the latest SHA-1 before the forced push in full. He
>>> then can do
>>>
>>>     git push <remote> +<old-sha1>:<ref>
>>>
>>> He does not even need to have the objects that <old-sha1> refers
>>> to. We could simply push an empty pack and the the remote will happily
>>> accept the force, assuming garbage collection has not happened. But
>>> that's another and a little more complex patch.
>>
>> If I am not mistaken, we actively prevent people from downloading an
>> unreferenced SHA (such as would happen if you overwrote refs that
>> contained sensitive information like passwords).
>>
>> Wouldn't allowing the kind of push you just described, require negating
>> that protection?
>
> I believe that to be the case.
>
> Sorry to chime in so late in the discussion, but I think that the `--force-with-lease` option is what you are looking for. It allows you to force-push *but only* if the forced push would overwrite the ref we expect, i.e. (simplified, but you get the idea) `git push --force-with-lease <remote> <ref>` will *only* succeed if the remote's <ref> agrees with the local `refs/remotes/<remote>/<ref>`.

Yeah that was my first thought as well. It's unfortunate that --force-with-lease is not as well known though (it wasn't there first, so many people picked it up and "it's good enough" to not pickup other --force-with-foo options).

Maybe we should add the option receive.denyNonFastForwards = onlyWithLease instead?

Thanks, Stefan

Show 9 quoted lines
>
> If you use `--force-with-lease`, you simply cannot force-forget anything on the remote side that you cannot undo (because you have everything locally you need to undo it).
>
> Ciao,
> Johannes
> --
> To unsubscribe from this list: send the line "unsubscribe git" in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at  http://vger.kernel.org/majordomo-info.html
Previous: Johannes SchindelinNext: Duy Nguyen
Message 7 of 11 in “On undoing a forced push”
  1. Duy NguyenJun 9, 2015
  2. Matthieu MoyJun 9, 2015
  3. Sitaram ChamartyJun 9, 2015
  4. Jeff KingJun 9, 2015
  5. Sitaram ChamartyJun 9, 2015
  6. Johannes SchindelinJun 9, 2015
  7. Stefan BellerJun 9, 2015
  8. Duy NguyenJun 9, 2015
  9. brian m. carlsonJun 9, 2015
  10. Duy NguyenJun 10, 2015
  11. brian m. carlsonJun 10, 2015

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.