git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: receive.denyNonNonFastForwards not denying force update

From
JAJohn Arthorne <arthorne.eclipse@gmail.com>
Date
Sep 10, 2012, 13:24 UTC
Message-ID
<CAHgXSoqZMPC8uawL7f+7iq-L=Ns+G2w4kh3_oV3DB=WXnTg+Ug@mail.gmail.com>
In-Reply-To
<CAHgXSop42qWcAEGn6=og8Pistv_Jrwhgcnv3B_ORVtSMi1fCHA@mail.gmail.com>

Just to close the loop on this thread, it did turn out to be a permission problem in our case. It was difficult to track down because it was only a problem on one server in the cluster. Each server had a system git config file at /usr/local/etc/gitconfig. This was a symlink pointing to a single common config file at /etc/gitconfig. This real file had correct content and permissions, and all the machines where eclipse.org allows shell access had correct symlinks. So any tests on the command line always showed that the system config looked fine. However on git.eclipse.org, which is the machine with the central repositories we are pushing to, the symlink was missing o+rx. For security reasons this machine doesn't allow shell access, but our pushes to this machine were failing to honour the system configuration. I gather the patch prepared earlier in this thread will cause an error to be reported when the system config could not be read, which sounds like a good fix to help others track down problems like this.

John Arthorne

On Fri, Aug 17, 2012 at 12:26 PM, John Arthorne <arthorne.eclipse@gmail.com> wrote:

Show 21 quoted lines
> At eclipse.org we wanted all git repositories to disallow non-fastforward
> commits by default. So, we set receive.denyNonFastForwards=true as a system
> configuration setting. However, this does not prevent a non-fastforward
> force push. If we set the same configuration setting in the local repository
> configuration then it does prevent non-fastforward pushes.
>
> For all the details see this bugzilla, particularly comment #59 where we
> finally narrowed this down:
>
> https://bugs.eclipse.org/bugs/show_bug.cgi?id=343150
>
> This is on git version 1.7.4.1.
>
> The Git book recommends setting this property at the system level:
>
> http://git-scm.com/book/ch7-1.html (near the bottom)
>
> Can someone confirm if this is intended behaviour or not.
>
> Thanks,
> John Arthorne
Previous: Sitaram Chamarty
Message 20 of 20 in “receive.denyNonNonFastForwards not denying force update”
  1. John ArthorneAug 20, 2012
  2. Junio C HamanoAug 20, 2012
  3. Sitaram ChamartyAug 21, 2012
  4. Junio C HamanoAug 21, 2012
  5. Brandon CaseyAug 21, 2012
  6. Jay SoffianAug 21, 2012
  7. Junio C HamanoAug 21, 2012
  8. Jeff KingAug 21, 2012
  9. Junio C HamanoAug 21, 2012
  10. Jeff KingAug 21, 2012
  11. Jeff KingAug 21, 2012
  12. Jeff KingAug 21, 2012
  13. Jeff KingAug 21, 2012
  14. Junio C HamanoAug 21, 2012
  15. Jeff KingAug 21, 2012
  16. Junio C HamanoAug 21, 2012
  17. Junio C HamanoAug 21, 2012
  18. Jeff KingAug 21, 2012
  19. Sitaram ChamartyAug 21, 2012
  20. John ArthorneSep 10, 2012

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.