threads / discuss / 25359

Fetch by SHA missing

Subject: Fetch by SHA missing

## tl;dr

3 messages between Oct 5, 2010 and Oct 6, 2010.

replies: 2people: 3as markdown or json

Jan Engelhardt· Oct 5, 2010, 19:37 UTC · lore
Hi,

it is possible to select single heads/tags for download, but this does not work with SHA IDs as of 1.7.1.

$ git fetch linus 3c06806e690885ce978ef180c8f8b6f8c17fb4b4:x
fatal: Couldn't find remote ref 3c06806e690885ce978ef180c8f8b6f8c17fb4b4
$ git fetch linus refs/heads/master
remote: Counting objects: 1254, done.
remote: Compressing objects: 100% (234/234), done.
remote: Total 709 (delta 562), reused 602 (delta 475)
Receiving objects: 100% (709/709), 112.41 KiB, done.
Resolving deltas: 100% (562/562), completed with 212 local objects.
From git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux-2.6
 * branch            master     -> FETCH_HEAD
Johannes Sixt· Oct 6, 2010, 06:02 UTC · re: Jan Engelhardt · lore

Re: Fetch by SHA missing

Am 10/5/2010 21:37, schrieb Jan Engelhardt:
Show 16 quoted lines
> Hi,
> 
> 
> it is possible to select single heads/tags for download, but this does 
> not work with SHA IDs as of 1.7.1.
> 
> $ git fetch linus 3c06806e690885ce978ef180c8f8b6f8c17fb4b4:x
> fatal: Couldn't find remote ref 3c06806e690885ce978ef180c8f8b6f8c17fb4b4
> $ git fetch linus refs/heads/master
> remote: Counting objects: 1254, done.
> remote: Compressing objects: 100% (234/234), done.
> remote: Total 709 (delta 562), reused 602 (delta 475)
> Receiving objects: 100% (709/709), 112.41 KiB, done.
> Resolving deltas: 100% (562/562), completed with 212 local objects.
> From git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux-2.6
>  * branch            master     -> FETCH_HEAD
That's by design:
http://thread.gmane.org/gmane.comp.version-control.git/73368/focus=73994

That is, when you accidentally push secret data, you can rewind your refs on the server. Even though the objects still live on the server (until they are garbage-collected) nobody will be able to fetch your secret stuff even if they happen to know the SHA1.

Nicolas Pitre· Oct 6, 2010, 20:35 UTC · re: Johannes Sixt · lore

Re: Fetch by SHA missing

On Wed, 6 Oct 2010, Johannes Sixt wrote:
Show 26 quoted lines
> Am 10/5/2010 21:37, schrieb Jan Engelhardt:
> > Hi,
> > 
> > 
> > it is possible to select single heads/tags for download, but this does 
> > not work with SHA IDs as of 1.7.1.
> > 
> > $ git fetch linus 3c06806e690885ce978ef180c8f8b6f8c17fb4b4:x
> > fatal: Couldn't find remote ref 3c06806e690885ce978ef180c8f8b6f8c17fb4b4
> > $ git fetch linus refs/heads/master
> > remote: Counting objects: 1254, done.
> > remote: Compressing objects: 100% (234/234), done.
> > remote: Total 709 (delta 562), reused 602 (delta 475)
> > Receiving objects: 100% (709/709), 112.41 KiB, done.
> > Resolving deltas: 100% (562/562), completed with 212 local objects.
> > From git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux-2.6
> >  * branch            master     -> FETCH_HEAD
> 
> That's by design:
> 
> http://thread.gmane.org/gmane.comp.version-control.git/73368/focus=73994
> 
> That is, when you accidentally push secret data, you can rewind your refs
> on the server. Even though the objects still live on the server (until
> they are garbage-collected) nobody will be able to fetch your secret stuff
> even if they happen to know the SHA1.

One improvement could be for the server to accept serving commits provided a raw SHA1 instead of a branch name if that SHA1 corresponds to a commit that is reachable through the actually exported refs.

Nicolas

← back to recent threads