git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: why is git destructive by default? (i suggest it not be!)

From
Jakub Narebski <jnareb@gmail.com>
Date
Jun 24, 2008, 09:39 UTC
Message-ID
<m3ej6nkw2u.fsf@localhost.localdomain>
In-Reply-To
<15381.9593288519$1214297235@news.gmane.org>
"David Jeske" <jeske@google.com> writes:
> This is mostly moot since I've understood that it's easy to set git
> to never GC. I guess I'm curious about why those GC fields would
> ever be set to anything other than never?

Because not everybody has unlimited quota / unlimited disk space? Besides growing repository, reflogs also grow even if you shitch between some limited set of commits.

Note however that IIRC reflogs are not enabled by default for bare repositories, and public repositories should be bare (without working directory). But see receive.denyNonFastForwards below.

Show 22 quoted lines
> -- Jeff King wrote:
> >
> > No. Git keeps the reachable DAG. So if the DAG is part of development
> > that is merged into one of your long running branches, or if you keep
> > around the branch that points to it, it will never go away.
> 
> Right, that's what I thought.
> 
> I'm not primarily concerned with what developers can do to their
> local git repositories. I'm concerned with what the default sync
> operations can let them do to the crown-jewels in the 'central
> organization repositories' which everyone is periodically pushing
> to.
> 
> I like that deleting a branch in your repo does not cause it to be
> deleted in other repos. Presumably in an organization we could
> prevent the central repo from ever accepting branch deletes from
> developers. (without some kind of authorization)
> 
> Does it have the same protection for all operations that can cause
> DAGs to be dangling? For example, if they branch -f" and push the
> branch?
git-config(1)
  receive.denyNonFastForwards::
        If set to true, git-receive-pack will deny a ref update which is
        not a fast forward. Use this to prevent such an update via a push,
        even if that push is forced. This configuration variable is
        set when initializing a shared repository.

That is even more than protection against leaving some commits dangling. This makes working on top of published branches safe.

If such all-or-nothing policy is not for you, you can always set-up hooks, like shown for example in contrib/hooks/update-paranoid

Or you can use different workflow, where maintainer _pulls_ from other developers or groups of developers, or apply (git-am) patches from email. This way if you screw up, it would be your fault for not having backups ;-)

[...]
> Quite a bit of my fear of losing data came from some issues in the
> git-gui. I'm trying out git on a windows project, and windows-shells
> just don't work right, so I'm using the "Git Gui". It turns out
> right-clicking on a history entry in the gui has no checkout option,

This might be result of the fact that in older versions of git you could not checkout arbitrary commit. You now can use so called "detached HEAD" (when current branch pointer points directly to the commit, instead of pointing to current branch [name]); note however that comitting on top of detached HEAD is discouraged.

Show 6 quoted lines
> and the only option it does have which will let you move the tree to
> that place is "reset --hard".. since this was the easiest thing to
> find in the GUI, I assumed it was the right way to do it, and then
> all my more recent changes disappeared. It doesn't seem to have
> reflog functionality, so I couldn't find any way to get back all my
> changes.

There is always ORIG_HEAD, which predates reflog introduction, and contains only old "version", as in

  $ git reset --hard ORIG_HEAD
That said, it would be nice if git-gui had some reflog interface.
> [...] The docs clearly explained that it
> will garbage collect dangling refs, and frankly the information
> about how often this happens is buried so deep I had no idea what
> the frequency was.
git-gc(1), section called (suprise, suprise) "Configuration".
-- 
Jakub Narebski
Poland
ShadeHawk on #git
Previous: David JeskeNext: David Jeske
Message 29 of 100 in “Re: why is git destructive by default? (i suggest it not be!)”
  1. David JeskeJun 24, 2008
  2. Nicolas PitreJun 24, 2008
  3. David JeskeJun 24, 2008
  4. David JeskeAug 14, 2016
  5. Lea WiemannJun 24, 2008
  6. Nicolas PitreJun 24, 2008
  7. David JeskeJun 24, 2008
  8. David JeskeAug 14, 2016
  9. Jan KrügerJun 24, 2008
  10. Avery PennarunJun 24, 2008
  11. David JeskeJun 24, 2008
  12. Jakub NarebskiJun 24, 2008
  13. David JeskeJun 24, 2008
  14. David JeskeAug 14, 2016
  15. Jakub NarebskiJun 24, 2008
  16. David JeskeJun 24, 2008
  17. Rogan DawesJun 24, 2008
  18. Johannes GilgerJun 24, 2008
  19. Rogan DawesJun 24, 2008
  20. Jakub NarebskiJun 24, 2008
  21. David JeskeAug 14, 2016
  22. Jakub NarebskiJun 24, 2008
  23. David JeskeAug 14, 2016
  24. Jeff KingJun 24, 2008
  25. David JeskeJun 24, 2008
  26. David JeskeAug 14, 2016
  27. Jeff KingJun 24, 2008
  28. David JeskeJun 24, 2008
  29. Jakub NarebskiJun 24, 2008
  30. David JeskeAug 14, 2016
  31. Fedor SergeevJun 24, 2008
  32. David JeskeJun 24, 2008
  33. Theodore TsoJun 24, 2008
  34. Junio C HamanoJun 27, 2008
  35. しらいしななこJun 28, 2008
  36. しらいしななこJun 28, 2008
  37. Junio C HamanoJun 29, 2008
  38. David JeskeAug 14, 2016
  39. Boaz HarroshJun 24, 2008
  40. Boaz HarroshJun 24, 2008
  41. Jakub NarebskiJun 24, 2008
  42. David JeskeJun 24, 2008
  43. Boaz HarroshJun 25, 2008
  44. David JeskeAug 14, 2016
  45. Brandon CaseyJun 24, 2008
  46. David JeskeJun 24, 2008
  47. Theodore TsoJun 24, 2008
  48. Junio C HamanoJun 24, 2008
  49. Theodore TsoJun 25, 2008
  50. Jakub NarebskiJun 25, 2008
  51. Junio C HamanoJun 25, 2008
  52. Brandon CaseyJun 26, 2008
  53. David JeskeAug 14, 2016
  54. Steven WalterJun 24, 2008
  55. cmd_reset: don't trash uncommitted changes unless told toSteven Walter, Jun 24, 2008
  56. Junio C HamanoJun 24, 2008
  57. Boaz HarroshJun 25, 2008
  58. Junio C HamanoJun 25, 2008
  59. Boaz HarroshJun 25, 2008
  60. Johannes SchindelinJun 25, 2008
  61. Matthias KestenholzJun 25, 2008
  62. Anton GladkovJun 25, 2008
  63. Johannes SchindelinJun 25, 2008
  64. Craig L. ChingJun 25, 2008
  65. Anton GladkovJun 25, 2008
  66. Johannes SixtJun 25, 2008
  67. Johannes SchindelinJun 25, 2008
  68. Theodore TsoJun 25, 2008
  69. Junio C HamanoJun 25, 2008
  70. Theodore TsoJun 25, 2008
  71. Avery PennarunJun 25, 2008
  72. Junio C HamanoJun 25, 2008
  73. Avery PennarunJun 25, 2008
  74. Junio C HamanoJun 25, 2008
  75. Avery PennarunJun 25, 2008
  76. Re* [PATCH] cmd_reset: don't trash uncommitted changes unless told toJunio C Hamano, Jun 25, 2008
  77. Junio C HamanoJun 25, 2008
  78. Junio C HamanoJun 26, 2008
  79. Steven WalterJun 25, 2008
  80. Theodore TsoJun 25, 2008
  81. Junio C HamanoJun 25, 2008
  82. Theodore TsoJun 25, 2008
  83. Junio C HamanoJun 25, 2008
  84. Junio C HamanoJun 26, 2008
  85. Petr BaudisJun 25, 2008
  86. Johannes SchindelinJun 26, 2008
  87. Junio C HamanoJun 25, 2008
  88. Björn SteinbrinkJun 26, 2008
  89. Johannes SchindelinJun 26, 2008
  90. Björn SteinbrinkJun 26, 2008
  91. Avery PennarunJun 26, 2008
  92. Johannes SchindelinJun 26, 2008
  93. Matthieu MoyJun 26, 2008
  94. Johannes SchindelinJun 26, 2008
  95. David KastrupJun 26, 2008
  96. Ian HiltJun 25, 2008
  97. Andreas EricssonJun 26, 2008
  98. Jon LoeligerJun 26, 2008
  99. Johannes GilgerJun 25, 2008
  100. Brandon CaseyJun 24, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.