git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Fetch by SHA missing

From
Nicolas Pitre <nico@fluxnic.net>
Date
Oct 6, 2010, 20:35 UTC
Message-ID
<alpine.LFD.2.00.1010061631420.3107@xanadu.home>
In-Reply-To
<4CAC110C.2000804@viscovery.net>
On Wed, 6 Oct 2010, Johannes Sixt wrote:
Show 26 quoted lines
> Am 10/5/2010 21:37, schrieb Jan Engelhardt:
> > Hi,
> > 
> > 
> > it is possible to select single heads/tags for download, but this does 
> > not work with SHA IDs as of 1.7.1.
> > 
> > $ git fetch linus 3c06806e690885ce978ef180c8f8b6f8c17fb4b4:x
> > fatal: Couldn't find remote ref 3c06806e690885ce978ef180c8f8b6f8c17fb4b4
> > $ git fetch linus refs/heads/master
> > remote: Counting objects: 1254, done.
> > remote: Compressing objects: 100% (234/234), done.
> > remote: Total 709 (delta 562), reused 602 (delta 475)
> > Receiving objects: 100% (709/709), 112.41 KiB, done.
> > Resolving deltas: 100% (562/562), completed with 212 local objects.
> > From git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux-2.6
> >  * branch            master     -> FETCH_HEAD
> 
> That's by design:
> 
> http://thread.gmane.org/gmane.comp.version-control.git/73368/focus=73994
> 
> That is, when you accidentally push secret data, you can rewind your refs
> on the server. Even though the objects still live on the server (until
> they are garbage-collected) nobody will be able to fetch your secret stuff
> even if they happen to know the SHA1.

One improvement could be for the server to accept serving commits provided a raw SHA1 instead of a branch name if that SHA1 corresponds to a commit that is reachable through the actually exported refs.

Nicolas
Previous: Johannes Sixt
Message 3 of 3 in “Fetch by SHA missing”
  1. Jan EngelhardtOct 5, 2010
  2. Johannes SixtOct 6, 2010
  3. Nicolas PitreOct 6, 2010

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.