# Restricting access to a branch

5 messages from 2008-05-21 to 2008-05-22. Participants: Stephen Hemminger, Junio C Hamano, Linus Torvalds, Jakub Narebski.
Thread: https://gitlist.dev/t/13607

## Stephen Hemminger, 2008-05-21 23:36

Subject: Restricting access to a branch
Message-ID: <20080521163616.31fad56f@extreme>
URL: https://gitlist.dev/e/20080521163616.31fad56f%40extreme

```
Is there some standard way to freeze a branch and not allow anymore changes to
be pushed?

Yes, I know it is possible by playing with hook files, but that doesn't seem
very admin friendly.

```

## Junio C Hamano, 2008-05-22 00:17

Subject: Re: Restricting access to a branch
Message-ID: <7vhccrxkdm.fsf@gitster.siamese.dyndns.org>
URL: https://gitlist.dev/e/7vhccrxkdm.fsf%40gitster.siamese.dyndns.org
In-Reply-To: <20080521163616.31fad56f@extreme>

```
Stephen Hemminger <shemminger@vyatta.com> writes:

> Is there some standard way to freeze a branch and not allow anymore changes to
> be pushed?
>
> Yes, I know it is possible by playing with hook files, but that doesn't seem
> very admin friendly.

If you do not want to use hooks, then the answer is no.  Sorry.

```

## Linus Torvalds, 2008-05-22 00:37

Subject: Re: Restricting access to a branch
Message-ID: <alpine.LFD.1.10.0805211732520.3081@woody.linux-foundation.org>
URL: https://gitlist.dev/e/alpine.LFD.1.10.0805211732520.3081%40woody.linux-foundation.org
In-Reply-To: <7vhccrxkdm.fsf@gitster.siamese.dyndns.org>

```


On Wed, 21 May 2008, Junio C Hamano wrote:

> Stephen Hemminger <shemminger@vyatta.com> writes:
> 
> > Is there some standard way to freeze a branch and not allow anymore changes to
> > be pushed?
> >
> > Yes, I know it is possible by playing with hook files, but that doesn't seem
> > very admin friendly.
> 
> If you do not want to use hooks, then the answer is no.  Sorry.

Hmm. I don't think that's strictly true.

What you *can* do is:

 - rename the branch to something that includes a slash (aka 
   subdirectory). Let's call it "frozen/mybranch" as an example.

 - do a 'git gc' to make sure that branch is in the packed refs file.

 - make the subdirectory of that branch is unwritable (ie just do 
   something like "chmod -w refs/heads/frozen")

and now the filesystem permissions should mean that you can't actually 
update that branch any more, even though you can read it.

Of course, if the person has full shell access, then they can still just 
undo those file permissions, but at least it should be protected from 
accidentally being overwritten.

This is all totally untested, of course.

		Linus

```

## Junio C Hamano, 2008-05-22 01:43

Subject: Re: Restricting access to a branch
Message-ID: <7v63t7xgdg.fsf@gitster.siamese.dyndns.org>
URL: https://gitlist.dev/e/7v63t7xgdg.fsf%40gitster.siamese.dyndns.org
In-Reply-To: <alpine.LFD.1.10.0805211732520.3081@woody.linux-foundation.org>

```
Linus Torvalds <torvalds@linux-foundation.org> writes:

> What you *can* do is:
>
>  - rename the branch to something that includes a slash (aka 
>    subdirectory). Let's call it "frozen/mybranch" as an example.
>
>  - do a 'git gc' to make sure that branch is in the packed refs file.
>
>  - make the subdirectory of that branch is unwritable (ie just do 
>    something like "chmod -w refs/heads/frozen")
>
> and now the filesystem permissions should mean that you can't actually 
> update that branch any more, even though you can read it.

Hmmmmm... and deleting of the branch would take the same lock used for
updating, which is under frozen/ directory, so that is also safe.

That's sneaky.

I'd however throw that into "happens to work, unsure if we would want to
promise supporting it as a _feature_ forever" category.

```

## Jakub Narebski, 2008-05-22 08:16

Subject: Re: Restricting access to a branch
Message-ID: <m3d4ne4uts.fsf@localhost.localdomain>
URL: https://gitlist.dev/e/m3d4ne4uts.fsf%40localhost.localdomain
In-Reply-To: <7v63t7xgdg.fsf@gitster.siamese.dyndns.org>

```
Junio C Hamano <gitster@pobox.com> writes:

> Linus Torvalds <torvalds@linux-foundation.org> writes:
> 
> > What you *can* do is:
> >
> >  - rename the branch to something that includes a slash (aka 
> >    subdirectory). Let's call it "frozen/mybranch" as an example.
> >
> >  - do a 'git gc' to make sure that branch is in the packed refs file.
> >
> >  - make the subdirectory of that branch is unwritable (ie just do 
> >    something like "chmod -w refs/heads/frozen")
> >
> > and now the filesystem permissions should mean that you can't actually 
> > update that branch any more, even though you can read it.
> 
> Hmmmmm... and deleting of the branch would take the same lock used for
> updating, which is under frozen/ directory, so that is also safe.
> 
> That's sneaky.
> 
> I'd however throw that into "happens to work, unsure if we would want to
> promise supporting it as a _feature_ forever" category.

Another solution would be to make it lightweight tag, i.e. change if
from refs/heads/somebranch to refs/tags/somebranch (by tagging, for
example).

-- 
Jakub Narebski
Poland
ShadeHawk on #git

```
