git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Restricting access to a branch

From
Linus Torvalds <torvalds@linux-foundation.org>
Date
May 22, 2008, 00:37 UTC
Message-ID
<alpine.LFD.1.10.0805211732520.3081@woody.linux-foundation.org>
In-Reply-To
<7vhccrxkdm.fsf@gitster.siamese.dyndns.org>
On Wed, 21 May 2008, Junio C Hamano wrote:
Show 9 quoted lines
> Stephen Hemminger <shemminger@vyatta.com> writes:
> 
> > Is there some standard way to freeze a branch and not allow anymore changes to
> > be pushed?
> >
> > Yes, I know it is possible by playing with hook files, but that doesn't seem
> > very admin friendly.
> 
> If you do not want to use hooks, then the answer is no.  Sorry.
Hmm. I don't think that's strictly true.
What you *can* do is:
 - rename the branch to something that includes a slash (aka 
   subdirectory). Let's call it "frozen/mybranch" as an example.
 - do a 'git gc' to make sure that branch is in the packed refs file.
 - make the subdirectory of that branch is unwritable (ie just do 
   something like "chmod -w refs/heads/frozen")

and now the filesystem permissions should mean that you can't actually update that branch any more, even though you can read it.

Of course, if the person has full shell access, then they can still just undo those file permissions, but at least it should be protected from accidentally being overwritten.

This is all totally untested, of course.
		Linus
Previous: Junio C HamanoNext: Junio C Hamano
Message 3 of 5 in “Restricting access to a branch”
  1. Stephen HemmingerMay 21, 2008
  2. Junio C HamanoMay 22, 2008
  3. Linus TorvaldsMay 22, 2008
  4. Junio C HamanoMay 22, 2008
  5. Jakub NarebskiMay 22, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.