git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: why is git destructive by default? (i suggest it not be!)

From
DJDavid Jeske <jeske@google.com>
Date
Aug 14, 2016, 00:43 UTC
Message-ID
<willow-jeske-01l61=64jMFEDjCiBE>
In-Reply-To
<m31w2mlki4.fsf@localhost.localdomain>
Show 7 quoted lines
> -- David Jeske wrote:
>> - improve the man page description of "reset --hard"
>> - standardize all the potentially destructive operations
>> (after gc) on "-f/--force" to override
>
> The thing is 'force' is not always the most descriptive word
> for the behavior that you propose enabling with --force.

I'm not talking about switching "git reset --hard" to "git reset -f". I'm talking about requiring a "-f" option to "git reset --hard" when it would destroy or dangle information.

(a) If you have a clean working directory which is fully checked in and has another branch tag other than the current branch tag, then "git reset --hard <commitish>" is non-destructive, and would complete happily.

(b) If you have local modifications to working files it would complain "hey, your working files are dirty, 'reset --hard' will blow them away, either revert them or use -f". This is what Boaz asked for, and I doubt it would change along would alter workflow much for people who are using "git reset --hard" to toss attempted patches (since they were fully committed anyhow), or even undo a clone or pull operation. If people use it as a combo "revert and reset", they would notice.

(c) If the current location is only pointed to by the current branch (which you are going to move with 'reset --hard') tell the user that those changes will be dangling and will be eligible for garbage collection if they move the branch. What to do in this case seems more controversial. I would prefer for this to error with "either label these changes with 'branch', or use 'reset --hard -f' to force us to leave these in the reflog unnamed". --- Some here say that being in the reflog is enough, and the -f is overkill here. If we define destructive as dropping code-commits, then that's true. If we define destructive as leaving code-commits unreferenced, then -f is warranted. Personally, I'd rather git help me avoid dropping the NAMES to tips, because even with GC-never, I don't really want to find myself crawling through SHA1 hashes and visualization trees to find them later, when git could have reminded me to name a branch that would conveniently show up in 'git branch'. It's easy enough to avoid dropping the names, or force git to not care with '-f'. I personally would like to avoid dealing with reflog or SHA1 hashes 99% of the time.

> 'gc' is another command that has been mentioned along
> with its '--aggressive' option.

This was an accident. When I made my "mv --aggressive" joke I was NOT intending to reference "gc --aggressive", that is just a coincidence. I was trying to make up another 'semi-dangerous sounding name that might or not might be destructive". It's comical that it's in use for gc. I don't see any relationship between "gc --aggressive" and destructive behavior.

However, there IS a situation to require a "-f" on a, because again, "-f" would be required for operations which destroy commits. If we think commits being in the reflog is good enough to hold onto them, and users are thinking that items being in the reflog are 'safe', then a GC where reflog entry expiration is going to cause DAG entries to be removed could print an error like:

error: the following entries are beyond the expiration time, ...<base branchname>/<commit-ish>: 17 commits, 78 lines, 3 authors ...use diff <commit-ish> , to see the changes ...use gc -f, to cause them to be deleted

This wouldn't happen very often, and would make "gc" a safe operation even on trees with shorter expiration time. In fact, if this were the way it worked, I might set my GC back from never to "30 days", because this would not only allow me to safely cleanup junk, but it would also allow me to catch unnamed and dangling references before they became so old I didn't remember what to name them.

This would make a "non forced gc" safe from throwing away commits, but still make it really easy to do so for people who want to. Likewise, we could make any "auto-gc" that happens not forced by default.

Previous: Boaz HarroshNext: Brandon Casey
Message 44 of 100 in “Re: why is git destructive by default? (i suggest it not be!)”
  1. David JeskeJun 24, 2008
  2. Nicolas PitreJun 24, 2008
  3. David JeskeJun 24, 2008
  4. David JeskeAug 14, 2016
  5. Lea WiemannJun 24, 2008
  6. Nicolas PitreJun 24, 2008
  7. David JeskeJun 24, 2008
  8. David JeskeAug 14, 2016
  9. Jan KrügerJun 24, 2008
  10. Avery PennarunJun 24, 2008
  11. David JeskeJun 24, 2008
  12. Jakub NarebskiJun 24, 2008
  13. David JeskeJun 24, 2008
  14. David JeskeAug 14, 2016
  15. Jakub NarebskiJun 24, 2008
  16. David JeskeJun 24, 2008
  17. Rogan DawesJun 24, 2008
  18. Johannes GilgerJun 24, 2008
  19. Rogan DawesJun 24, 2008
  20. Jakub NarebskiJun 24, 2008
  21. David JeskeAug 14, 2016
  22. Jakub NarebskiJun 24, 2008
  23. David JeskeAug 14, 2016
  24. Jeff KingJun 24, 2008
  25. David JeskeJun 24, 2008
  26. David JeskeAug 14, 2016
  27. Jeff KingJun 24, 2008
  28. David JeskeJun 24, 2008
  29. Jakub NarebskiJun 24, 2008
  30. David JeskeAug 14, 2016
  31. Fedor SergeevJun 24, 2008
  32. David JeskeJun 24, 2008
  33. Theodore TsoJun 24, 2008
  34. Junio C HamanoJun 27, 2008
  35. しらいしななこJun 28, 2008
  36. しらいしななこJun 28, 2008
  37. Junio C HamanoJun 29, 2008
  38. David JeskeAug 14, 2016
  39. Boaz HarroshJun 24, 2008
  40. Boaz HarroshJun 24, 2008
  41. Jakub NarebskiJun 24, 2008
  42. David JeskeJun 24, 2008
  43. Boaz HarroshJun 25, 2008
  44. David JeskeAug 14, 2016
  45. Brandon CaseyJun 24, 2008
  46. David JeskeJun 24, 2008
  47. Theodore TsoJun 24, 2008
  48. Junio C HamanoJun 24, 2008
  49. Theodore TsoJun 25, 2008
  50. Jakub NarebskiJun 25, 2008
  51. Junio C HamanoJun 25, 2008
  52. Brandon CaseyJun 26, 2008
  53. David JeskeAug 14, 2016
  54. Steven WalterJun 24, 2008
  55. cmd_reset: don't trash uncommitted changes unless told toSteven Walter, Jun 24, 2008
  56. Junio C HamanoJun 24, 2008
  57. Boaz HarroshJun 25, 2008
  58. Junio C HamanoJun 25, 2008
  59. Boaz HarroshJun 25, 2008
  60. Johannes SchindelinJun 25, 2008
  61. Matthias KestenholzJun 25, 2008
  62. Anton GladkovJun 25, 2008
  63. Johannes SchindelinJun 25, 2008
  64. Craig L. ChingJun 25, 2008
  65. Anton GladkovJun 25, 2008
  66. Johannes SixtJun 25, 2008
  67. Johannes SchindelinJun 25, 2008
  68. Theodore TsoJun 25, 2008
  69. Junio C HamanoJun 25, 2008
  70. Theodore TsoJun 25, 2008
  71. Avery PennarunJun 25, 2008
  72. Junio C HamanoJun 25, 2008
  73. Avery PennarunJun 25, 2008
  74. Junio C HamanoJun 25, 2008
  75. Avery PennarunJun 25, 2008
  76. Re* [PATCH] cmd_reset: don't trash uncommitted changes unless told toJunio C Hamano, Jun 25, 2008
  77. Junio C HamanoJun 25, 2008
  78. Junio C HamanoJun 26, 2008
  79. Steven WalterJun 25, 2008
  80. Theodore TsoJun 25, 2008
  81. Junio C HamanoJun 25, 2008
  82. Theodore TsoJun 25, 2008
  83. Junio C HamanoJun 25, 2008
  84. Junio C HamanoJun 26, 2008
  85. Petr BaudisJun 25, 2008
  86. Johannes SchindelinJun 26, 2008
  87. Junio C HamanoJun 25, 2008
  88. Björn SteinbrinkJun 26, 2008
  89. Johannes SchindelinJun 26, 2008
  90. Björn SteinbrinkJun 26, 2008
  91. Avery PennarunJun 26, 2008
  92. Johannes SchindelinJun 26, 2008
  93. Matthieu MoyJun 26, 2008
  94. Johannes SchindelinJun 26, 2008
  95. David KastrupJun 26, 2008
  96. Ian HiltJun 25, 2008
  97. Andreas EricssonJun 26, 2008
  98. Jon LoeligerJun 26, 2008
  99. Johannes GilgerJun 25, 2008
  100. Brandon CaseyJun 24, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.