git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: why is git destructive by default? (i suggest it not be!)

From
DJDavid Jeske <jeske@google.com>
Date
Aug 14, 2016, 00:45 UTC
Message-ID
<willow-jeske-01l5cKsCFEDjC=91MX>
In-Reply-To
<jeske@willow=01l5V7waFEDjChmh>

As a new user, I'm finding git difficult to trust, because there are operations which are destructive by default and capable of inadvertently throwing hours or days of work into the bit bucket.

More problematic, those commands have no discernible pattern that shows their danger, and they need to be used to do typical everyday things. I'm starting to feel like I need to use another source control system on top of the git repository in case I make a mistake. My philosophy is simple, I never never never want to throw away changes, you shouldn't either. Disks are cheaper than programmer hours. I can understand wanting to keep things tidy, so I can understand ways to correct the 'easily visible changes', and also avoid pushing them to other trees, but I don't understand why git needs to delete things.

For example, the following commands seem capable of totally destroying hours or days of work. Some of them need to be used regularly to do everyday things, and there is no pattern among them spelling out danger.

git reset --hard : if another branch name hasn't been created git rebase git branch -D <branch> : if branch hasn't been merged git branch -f <new> : if new exists and hasn't been merged git branch -m <old> <new> : if new exists and hasn't been merged

I've heard from a couple users that the solution to these problems is to "go dig what you need out of the log, it's still in there". However, it's only in there until the log is garbage collected. This either means they are destructive operations, or we expect "running without ever collecting the log" to be a valid mode of operation... which I doubt is the case.

Question: How about assuring ALL operations can be done non-destructivly by
default? Then make destructive things require an explicit action that follows a
common pattern.

Suggestion Illustration -----------------------

Below is one illustration of how these commands could be changed to be entirely non-destructive, while retaining the current functionality. It also allows you to destroy stuff if you have lawyers breathing down your neck, or really really can't afford the hard drive space for a couple lines of text (though I'll personally make a donation to anyone in this state!) :)

1) Require the "--destroy" flag for ANY git operation which is capable of
destroying data such that it is unrecoverable. A narrow view of this is to only
consider checked-in repository data, and not metadata, such as the location of
a branchname. However, the broad view would be to include all/most metadata.
2) Make a pattern for branch names which are kept in the local tree, not
included in push/pull, not modifiable without first renaming, and not shown by
default when viewing all branch history. For example, "local-<date>-*"
3) make 'git reset --hard <commit>' safe

Automatically commit working set and make a branch name (if necessary) to avoid changes being thrown away. The branch name could be of the form "local-<date>-reset-<user>-<date>". If the user really wants to destroy it, they could use the dangerous version "git reset --hard --destroy", or they could just "git branch -d --destroy <branchname>" afterwords. Most users would do neither.

4) make 'git rebase' safe

'rebase' would make a branch name before performing its operation, assuring it was easy to get back to the previous state. Currently, "git rebase" turns this:

A---B---C topic / D---E---F---G master

Into this:

A'--B'--C' topic / D---E---F---G master

.. and in turn destroys the original changes. It would instead create this:

A--B--C (x) A'--B'--C' (y) / / D---E------F-------G master

(x) - local-<date>-rebase-topic-<commit for G> (y) - topic

5) make 'git branch' follow rule 1 above (safe without --destroy)

Using any of the following commands without --destroy would cause them to create a branch "local-<date>-rename-<old branch name>", to prevet the destruction of the old branch location:

git branch -d <branchname> git branch -M <old> <new> git branch -f <branchname>

Previous: Junio C HamanoNext: Boaz Harrosh
Message 38 of 100 in “Re: why is git destructive by default? (i suggest it not be!)”
  1. David JeskeJun 24, 2008
  2. Nicolas PitreJun 24, 2008
  3. David JeskeJun 24, 2008
  4. David JeskeAug 14, 2016
  5. Lea WiemannJun 24, 2008
  6. Nicolas PitreJun 24, 2008
  7. David JeskeJun 24, 2008
  8. David JeskeAug 14, 2016
  9. Jan KrügerJun 24, 2008
  10. Avery PennarunJun 24, 2008
  11. David JeskeJun 24, 2008
  12. Jakub NarebskiJun 24, 2008
  13. David JeskeJun 24, 2008
  14. David JeskeAug 14, 2016
  15. Jakub NarebskiJun 24, 2008
  16. David JeskeJun 24, 2008
  17. Rogan DawesJun 24, 2008
  18. Johannes GilgerJun 24, 2008
  19. Rogan DawesJun 24, 2008
  20. Jakub NarebskiJun 24, 2008
  21. David JeskeAug 14, 2016
  22. Jakub NarebskiJun 24, 2008
  23. David JeskeAug 14, 2016
  24. Jeff KingJun 24, 2008
  25. David JeskeJun 24, 2008
  26. David JeskeAug 14, 2016
  27. Jeff KingJun 24, 2008
  28. David JeskeJun 24, 2008
  29. Jakub NarebskiJun 24, 2008
  30. David JeskeAug 14, 2016
  31. Fedor SergeevJun 24, 2008
  32. David JeskeJun 24, 2008
  33. Theodore TsoJun 24, 2008
  34. Junio C HamanoJun 27, 2008
  35. しらいしななこJun 28, 2008
  36. しらいしななこJun 28, 2008
  37. Junio C HamanoJun 29, 2008
  38. David JeskeAug 14, 2016
  39. Boaz HarroshJun 24, 2008
  40. Boaz HarroshJun 24, 2008
  41. Jakub NarebskiJun 24, 2008
  42. David JeskeJun 24, 2008
  43. Boaz HarroshJun 25, 2008
  44. David JeskeAug 14, 2016
  45. Brandon CaseyJun 24, 2008
  46. David JeskeJun 24, 2008
  47. Theodore TsoJun 24, 2008
  48. Junio C HamanoJun 24, 2008
  49. Theodore TsoJun 25, 2008
  50. Jakub NarebskiJun 25, 2008
  51. Junio C HamanoJun 25, 2008
  52. Brandon CaseyJun 26, 2008
  53. David JeskeAug 14, 2016
  54. Steven WalterJun 24, 2008
  55. cmd_reset: don't trash uncommitted changes unless told toSteven Walter, Jun 24, 2008
  56. Junio C HamanoJun 24, 2008
  57. Boaz HarroshJun 25, 2008
  58. Junio C HamanoJun 25, 2008
  59. Boaz HarroshJun 25, 2008
  60. Johannes SchindelinJun 25, 2008
  61. Matthias KestenholzJun 25, 2008
  62. Anton GladkovJun 25, 2008
  63. Johannes SchindelinJun 25, 2008
  64. Craig L. ChingJun 25, 2008
  65. Anton GladkovJun 25, 2008
  66. Johannes SixtJun 25, 2008
  67. Johannes SchindelinJun 25, 2008
  68. Theodore TsoJun 25, 2008
  69. Junio C HamanoJun 25, 2008
  70. Theodore TsoJun 25, 2008
  71. Avery PennarunJun 25, 2008
  72. Junio C HamanoJun 25, 2008
  73. Avery PennarunJun 25, 2008
  74. Junio C HamanoJun 25, 2008
  75. Avery PennarunJun 25, 2008
  76. Re* [PATCH] cmd_reset: don't trash uncommitted changes unless told toJunio C Hamano, Jun 25, 2008
  77. Junio C HamanoJun 25, 2008
  78. Junio C HamanoJun 26, 2008
  79. Steven WalterJun 25, 2008
  80. Theodore TsoJun 25, 2008
  81. Junio C HamanoJun 25, 2008
  82. Theodore TsoJun 25, 2008
  83. Junio C HamanoJun 25, 2008
  84. Junio C HamanoJun 26, 2008
  85. Petr BaudisJun 25, 2008
  86. Johannes SchindelinJun 26, 2008
  87. Junio C HamanoJun 25, 2008
  88. Björn SteinbrinkJun 26, 2008
  89. Johannes SchindelinJun 26, 2008
  90. Björn SteinbrinkJun 26, 2008
  91. Avery PennarunJun 26, 2008
  92. Johannes SchindelinJun 26, 2008
  93. Matthieu MoyJun 26, 2008
  94. Johannes SchindelinJun 26, 2008
  95. David KastrupJun 26, 2008
  96. Ian HiltJun 25, 2008
  97. Andreas EricssonJun 26, 2008
  98. Jon LoeligerJun 26, 2008
  99. Johannes GilgerJun 25, 2008
  100. Brandon CaseyJun 24, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.