# Is there any way to make hooks part of the repository?

18 messages from 2012-05-01 to 2012-05-04. Participants: Hilco Wijbenga, Junio C Hamano, Randal L. Schwartz, PJ Weisberg, Nathan Gray, Matthieu Moy, Thomas Rast, Johan Herland.
Thread: https://gitlist.dev/t/30384

## Hilco Wijbenga, 2012-05-01 20:24

Subject: Is there any way to make hooks part of the repository?
Message-ID: <CAE1pOi2hr7ewjo5WVDoW0ipYxDVTckr5M_sHNoOQ323=_k754Q@mail.gmail.com>
URL: https://gitlist.dev/e/CAE1pOi2hr7ewjo5WVDoW0ipYxDVTckr5M_sHNoOQ323%3D_k754Q%40mail.gmail.com

```
Hi all,

There are a couple of things that keep going wrong while we are
working on our code base. Some of them are very simple to check for in
a Git hook. However, I get the impression that it is not possible to
"include" the hooks with the Git repo itself (so that "git clone"
would automatically set them up). Normally, this would not be such a
big deal: I would simply add the hooks on the server. Unfortunately,
this is not an option (we use Unfuddle and they do not support that).

Is there any way to get (some of) the Git hooks to run for everyone
without everyone having to install them separately? If no, is this by
design or simply a feature nobody has asked for (yet)?

Cheers,
Hilco

```

## Junio C Hamano, 2012-05-01 20:33

Subject: Re: Is there any way to make hooks part of the repository?
Message-ID: <7vipgf8wve.fsf@alter.siamese.dyndns.org>
URL: https://gitlist.dev/e/7vipgf8wve.fsf%40alter.siamese.dyndns.org
In-Reply-To: <CAE1pOi2hr7ewjo5WVDoW0ipYxDVTckr5M_sHNoOQ323=_k754Q@mail.gmail.com>

```
Hilco Wijbenga <hilco.wijbenga@gmail.com> writes:

> Is there any way to get (some of) the Git hooks to run for everyone
> without everyone having to install them separately? If no, is this by
> design or simply a feature nobody has asked for (yet)?

By design.  Do you want me to include "rm -fr ~hilco" in some hook of
git.git repository?

```

## Randal L. Schwartz, 2012-05-01 20:57

Subject: Re: Is there any way to make hooks part of the repository?
Message-ID: <86r4v3mxf7.fsf@red.stonehenge.com>
URL: https://gitlist.dev/e/86r4v3mxf7.fsf%40red.stonehenge.com
In-Reply-To: <7vipgf8wve.fsf@alter.siamese.dyndns.org>

```
>>>>> "Junio" == Junio C Hamano <gitster@pobox.com> writes:

Junio> By design.  Do you want me to include "rm -fr ~hilco" in some hook of
Junio> git.git repository?

This just came up yesterday at $PRIMARY_CLIENT.  One idea we kicked
around was having a convention for storing the hooks-to-be-populated in
".githooks" in the repository tree, and then having clone notice that
and offer to install them directly if from a trusted source, or at least
move them into a disabled state in .git/hooks otherwise.

-- 
Randal L. Schwartz - Stonehenge Consulting Services, Inc. - +1 503 777 0095
<merlyn@stonehenge.com> <URL:http://www.stonehenge.com/merlyn/>
Smalltalk/Perl/Unix consulting, Technical writing, Comedy, etc. etc.
See http://methodsandmessages.posterous.com/ for Smalltalk discussion

```

## Hilco Wijbenga, 2012-05-01 21:00

Subject: Re: Is there any way to make hooks part of the repository?
Message-ID: <CAE1pOi0_ETdSYsuT0Udhbr6rDvmEcuTA157d6aKUosgi7w28jw@mail.gmail.com>
URL: https://gitlist.dev/e/CAE1pOi0_ETdSYsuT0Udhbr6rDvmEcuTA157d6aKUosgi7w28jw%40mail.gmail.com
In-Reply-To: <7vipgf8wve.fsf@alter.siamese.dyndns.org>

```
On 1 May 2012 13:33, Junio C Hamano <gitster@pobox.com> wrote:
> Hilco Wijbenga <hilco.wijbenga@gmail.com> writes:
>
>> Is there any way to get (some of) the Git hooks to run for everyone
>> without everyone having to install them separately? If no, is this by
>> design or simply a feature nobody has asked for (yet)?
>
> By design.  Do you want me to include "rm -fr ~hilco" in some hook of
> git.git repository?

Mmm, well, I might get quite famous if you did... ;-)

But if you wanted to be evil then you could easily find another place
(the build scripts, the code itself, et cetera). So I don't think this
is a good argument. Moreover, I do not work with people that would
ever consider such nastiness. You need to realize that this is all
closed source. Your argument would be more valid in an open source
environment (like git.git).

So let's just say that I'm stubborn or I like living on the edge. :-)
Is there any way to have the hooks run for everyone?

```

## Junio C Hamano, 2012-05-01 21:03

Subject: Re: Is there any way to make hooks part of the repository?
Message-ID: <7vaa1r8vhy.fsf@alter.siamese.dyndns.org>
URL: https://gitlist.dev/e/7vaa1r8vhy.fsf%40alter.siamese.dyndns.org
In-Reply-To: <86r4v3mxf7.fsf@red.stonehenge.com>

```
merlyn@stonehenge.com (Randal L. Schwartz) writes:

>>>>>> "Junio" == Junio C Hamano <gitster@pobox.com> writes:
>
> Junio> By design.  Do you want me to include "rm -fr ~hilco" in some hook of
> Junio> git.git repository?
>
> This just came up yesterday at $PRIMARY_CLIENT.  One idea we kicked
> around was having a convention for storing the hooks-to-be-populated in
> ".githooks" in the repository tree, and then having clone notice that
> and offer to install them directly if from a trusted source, or at least
> move them into a disabled state in .git/hooks otherwise.

We've talked about something like that a few times in the past, but as far
as I (am concerned / remember) the conclusion has always been that is not
worth "standardizing", i.e. nothing a ./setup script in-tree or a Makefile
target cannot offer the same convenience.

```

## Hilco Wijbenga, 2012-05-01 21:07

Subject: Re: Is there any way to make hooks part of the repository?
Message-ID: <CAE1pOi1Dpjow8mkwtPo2o1Zo9rkk6=hhpLqErG1XwTcn=un17A@mail.gmail.com>
URL: https://gitlist.dev/e/CAE1pOi1Dpjow8mkwtPo2o1Zo9rkk6%3DhhpLqErG1XwTcn%3Dun17A%40mail.gmail.com
In-Reply-To: <86r4v3mxf7.fsf@red.stonehenge.com>

```
On 1 May 2012 13:57, Randal L. Schwartz <merlyn@stonehenge.com> wrote:
>>>>>> "Junio" == Junio C Hamano <gitster@pobox.com> writes:
>
> Junio> By design.  Do you want me to include "rm -fr ~hilco" in some hook of
> Junio> git.git repository?
>
> This just came up yesterday at $PRIMARY_CLIENT.  One idea we kicked
> around was having a convention for storing the hooks-to-be-populated in
> ".githooks" in the repository tree, and then having clone notice that
> and offer to install them directly if from a trusted source, or at least
> move them into a disabled state in .git/hooks otherwise.

I guess it would have to be more than just clone. You are quite likely
to update/add hooks later on.

```

## Hilco Wijbenga, 2012-05-01 21:09

Subject: Re: Is there any way to make hooks part of the repository?
Message-ID: <CAE1pOi00Mr4dOj2ChTJU9XWypUAaVUDDa36-M7LA+9BixW0nKw@mail.gmail.com>
URL: https://gitlist.dev/e/CAE1pOi00Mr4dOj2ChTJU9XWypUAaVUDDa36-M7LA%2B9BixW0nKw%40mail.gmail.com
In-Reply-To: <7vaa1r8vhy.fsf@alter.siamese.dyndns.org>

```
On 1 May 2012 14:03, Junio C Hamano <gitster@pobox.com> wrote:
> merlyn@stonehenge.com (Randal L. Schwartz) writes:
>
>>>>>>> "Junio" == Junio C Hamano <gitster@pobox.com> writes:
>>
>> Junio> By design.  Do you want me to include "rm -fr ~hilco" in some hook of
>> Junio> git.git repository?
>>
>> This just came up yesterday at $PRIMARY_CLIENT.  One idea we kicked
>> around was having a convention for storing the hooks-to-be-populated in
>> ".githooks" in the repository tree, and then having clone notice that
>> and offer to install them directly if from a trusted source, or at least
>> move them into a disabled state in .git/hooks otherwise.
>
> We've talked about something like that a few times in the past, but as far
> as I (am concerned / remember) the conclusion has always been that is not
> worth "standardizing", i.e. nothing a ./setup script in-tree or a Makefile
> target cannot offer the same convenience.

This would not keep things up-to-date, though, would it? It seems like
yet another thing developers need to remember and do. I would prefer
something more automatic.

```

## PJ Weisberg, 2012-05-01 21:59

Subject: Re: Is there any way to make hooks part of the repository?
Message-ID: <CAJsNXT=niP2Ja-pSbvj-OGi5t0x0-Zxm3CdcY0nLs9ROdCG8hg@mail.gmail.com>
URL: https://gitlist.dev/e/CAJsNXT%3DniP2Ja-pSbvj-OGi5t0x0-Zxm3CdcY0nLs9ROdCG8hg%40mail.gmail.com
In-Reply-To: <CAE1pOi00Mr4dOj2ChTJU9XWypUAaVUDDa36-M7LA+9BixW0nKw@mail.gmail.com>

```
On Tue, May 1, 2012 at 2:09 PM, Hilco Wijbenga <hilco.wijbenga@gmail.com> wrote:

> On 1 May 2012 14:03, Junio C Hamano <gitster@pobox.com> wrote:
>
>> We've talked about something like that a few times in the past, but as far
>> as I (am concerned / remember) the conclusion has always been that is not
>> worth "standardizing", i.e. nothing a ./setup script in-tree or a Makefile
>> target cannot offer the same convenience.
>
> This would not keep things up-to-date, though, would it? It seems like
> yet another thing developers need to remember and do. I would prefer
> something more automatic.

Once your hooks are installed, couldn't your post-checkout and
post-merge hooks keep all the others up to date?


-PJ

Gehm's Corollary to Clark's Law: Any technology distinguishable from
magic is insufficiently advanced.

```

## Hilco Wijbenga, 2012-05-01 22:21

Subject: Re: Is there any way to make hooks part of the repository?
Message-ID: <CAE1pOi02_u9j2oHy-RJ-XbrCmDiUWd4-=50f-v+iaK1GLaLQZw@mail.gmail.com>
URL: https://gitlist.dev/e/CAE1pOi02_u9j2oHy-RJ-XbrCmDiUWd4-%3D50f-v%2BiaK1GLaLQZw%40mail.gmail.com
In-Reply-To: <CAJsNXT=niP2Ja-pSbvj-OGi5t0x0-Zxm3CdcY0nLs9ROdCG8hg@mail.gmail.com>

```
On 1 May 2012 14:59, PJ Weisberg <pj@irregularexpressions.net> wrote:
> On Tue, May 1, 2012 at 2:09 PM, Hilco Wijbenga <hilco.wijbenga@gmail.com> wrote:
>
>> On 1 May 2012 14:03, Junio C Hamano <gitster@pobox.com> wrote:
>>
>>> We've talked about something like that a few times in the past, but as far
>>> as I (am concerned / remember) the conclusion has always been that is not
>>> worth "standardizing", i.e. nothing a ./setup script in-tree or a Makefile
>>> target cannot offer the same convenience.
>>
>> This would not keep things up-to-date, though, would it? It seems like
>> yet another thing developers need to remember and do. I would prefer
>> something more automatic.
>
> Once your hooks are installed, couldn't your post-checkout and
> post-merge hooks keep all the others up to date?

Excellent point. Yes, that would certainly work.

```

## Nathan Gray, 2012-05-02 00:10

Subject: Re: Is there any way to make hooks part of the repository?
Message-ID: <CA+7g9JzvN+5RsSF+bRFtaMafZeY+TyFkXeq-6OSAW3qJ99JqKg@mail.gmail.com>
URL: https://gitlist.dev/e/CA%2B7g9JzvN%2B5RsSF%2BbRFtaMafZeY%2BTyFkXeq-6OSAW3qJ99JqKg%40mail.gmail.com
In-Reply-To: <CAE1pOi02_u9j2oHy-RJ-XbrCmDiUWd4-=50f-v+iaK1GLaLQZw@mail.gmail.com>

```
On Tue, May 1, 2012 at 3:21 PM, Hilco Wijbenga <hilco.wijbenga@gmail.com> wrote:
> On 1 May 2012 14:59, PJ Weisberg <pj@irregularexpressions.net> wrote:
>> On Tue, May 1, 2012 at 2:09 PM, Hilco Wijbenga <hilco.wijbenga@gmail.com> wrote:
>>
>>> On 1 May 2012 14:03, Junio C Hamano <gitster@pobox.com> wrote:
>>>
>>>> We've talked about something like that a few times in the past, but as far
>>>> as I (am concerned / remember) the conclusion has always been that is not
>>>> worth "standardizing", i.e. nothing a ./setup script in-tree or a Makefile
>>>> target cannot offer the same convenience.
>>>
>>> This would not keep things up-to-date, though, would it? It seems like
>>> yet another thing developers need to remember and do. I would prefer
>>> something more automatic.
>>
>> Once your hooks are installed, couldn't your post-checkout and
>> post-merge hooks keep all the others up to date?
>
> Excellent point. Yes, that would certainly work.

But beware, this has the effect of making your hooks
version-dependent.  Check out a different branch and you can
potentially end up with a different hook.

IMHO things like this belong in a separate "admin" repo -- policy may
change over time, but going back to an old version of your code
shouldn't take you back to a correspondingly old version of your
policy.

Cheers,
-n8

-- 
HexaLex: A New Angle on Crossword Games for iPhone and iPod Touch
http://hexalex.com
On The App Store: http://bit.ly/8Mj1CU
On Facebook: http://bit.ly/9MIJiV
On Twitter: http://twitter.com/hexalexgame
http://n8gray.org

```

## Hilco Wijbenga, 2012-05-02 00:18

Subject: Re: Is there any way to make hooks part of the repository?
Message-ID: <CAE1pOi2Gj-8fRhaUMmwhCDTLp27ETKeaExvm7iHz8HpObY8O+A@mail.gmail.com>
URL: https://gitlist.dev/e/CAE1pOi2Gj-8fRhaUMmwhCDTLp27ETKeaExvm7iHz8HpObY8O%2BA%40mail.gmail.com
In-Reply-To: <CA+7g9JzvN+5RsSF+bRFtaMafZeY+TyFkXeq-6OSAW3qJ99JqKg@mail.gmail.com>

```
On 1 May 2012 17:10, Nathan Gray <n8gray@n8gray.org> wrote:
> On Tue, May 1, 2012 at 3:21 PM, Hilco Wijbenga <hilco.wijbenga@gmail.com> wrote:
>> On 1 May 2012 14:59, PJ Weisberg <pj@irregularexpressions.net> wrote:
>>> On Tue, May 1, 2012 at 2:09 PM, Hilco Wijbenga <hilco.wijbenga@gmail.com> wrote:
>>>
>>>> On 1 May 2012 14:03, Junio C Hamano <gitster@pobox.com> wrote:
>>>>
>>>>> We've talked about something like that a few times in the past, but as far
>>>>> as I (am concerned / remember) the conclusion has always been that is not
>>>>> worth "standardizing", i.e. nothing a ./setup script in-tree or a Makefile
>>>>> target cannot offer the same convenience.
>>>>
>>>> This would not keep things up-to-date, though, would it? It seems like
>>>> yet another thing developers need to remember and do. I would prefer
>>>> something more automatic.
>>>
>>> Once your hooks are installed, couldn't your post-checkout and
>>> post-merge hooks keep all the others up to date?
>>
>> Excellent point. Yes, that would certainly work.
>
> But beware, this has the effect of making your hooks
> version-dependent.  Check out a different branch and you can
> potentially end up with a different hook.
>
> IMHO things like this belong in a separate "admin" repo -- policy may
> change over time, but going back to an old version of your code
> shouldn't take you back to a correspondingly old version of your
> policy.

You have a point, of course, however, checking out an older version
(that does not comply with current policy) should not break (when
interacting with Git) just because of that. So I think there is at
least some justification to version the policy as well.

This is something we will simply have to experience to see what works best.

```

## Matthieu Moy, 2012-05-02 06:38

Subject: Re: Is there any way to make hooks part of the repository?
Message-ID: <vpqfwbjnl4a.fsf@bauges.imag.fr>
URL: https://gitlist.dev/e/vpqfwbjnl4a.fsf%40bauges.imag.fr
In-Reply-To: <CAE1pOi0_ETdSYsuT0Udhbr6rDvmEcuTA157d6aKUosgi7w28jw@mail.gmail.com>

```
Hilco Wijbenga <hilco.wijbenga@gmail.com> writes:

> On 1 May 2012 13:33, Junio C Hamano <gitster@pobox.com> wrote:
>> Hilco Wijbenga <hilco.wijbenga@gmail.com> writes:
>>
>>> Is there any way to get (some of) the Git hooks to run for everyone
>>> without everyone having to install them separately? If no, is this by
>>> design or simply a feature nobody has asked for (yet)?
>>
>> By design.  Do you want me to include "rm -fr ~hilco" in some hook of
>> git.git repository?
>
> Mmm, well, I might get quite famous if you did... ;-)
>
> But if you wanted to be evil then you could easily find another place
> (the build scripts, the code itself, et cetera).

Yes, but at least, you have the opportunity to examine the other places
before they are ran. Hooks would be really, really nasty security-wise.
For example, "git clone" does a checkout, so should probably run the
checkout hooks.

> So I don't think this is a good argument. Moreover, I do not work with
> people that would ever consider such nastiness. You need to realize
> that this is all closed source. Your argument would be more valid in
> an open source environment (like git.git).

That may be acceptable for you, but you can't ask for such feature to be
included in Git itself. At best, a standardized way to setup hooks (but
something that would require a user-action to be set up) would be
acceptable.

-- 
Matthieu Moy
http://www-verimag.imag.fr/~moy/

```

## Hilco Wijbenga, 2012-05-02 19:10

Subject: Re: Is there any way to make hooks part of the repository?
Message-ID: <CAE1pOi3RZ+x7YcVZ-dLt70=wwRsvY9D6GQR-T+JZ9S7x8CFjPw@mail.gmail.com>
URL: https://gitlist.dev/e/CAE1pOi3RZ%2Bx7YcVZ-dLt70%3DwwRsvY9D6GQR-T%2BJZ9S7x8CFjPw%40mail.gmail.com
In-Reply-To: <vpqfwbjnl4a.fsf@bauges.imag.fr>

```
On 1 May 2012 23:38, Matthieu Moy <Matthieu.Moy@grenoble-inp.fr> wrote:
> Hilco Wijbenga <hilco.wijbenga@gmail.com> writes:
>
>> On 1 May 2012 13:33, Junio C Hamano <gitster@pobox.com> wrote:
>>> Hilco Wijbenga <hilco.wijbenga@gmail.com> writes:
>>>
>>>> Is there any way to get (some of) the Git hooks to run for everyone
>>>> without everyone having to install them separately? If no, is this by
>>>> design or simply a feature nobody has asked for (yet)?
>>>
>>> By design.  Do you want me to include "rm -fr ~hilco" in some hook of
>>> git.git repository?
>>
>> Mmm, well, I might get quite famous if you did... ;-)
>>
>> But if you wanted to be evil then you could easily find another place
>> (the build scripts, the code itself, et cetera).
>
> Yes, but at least, you have the opportunity to examine the other places
> before they are ran. Hooks would be really, really nasty security-wise.
> For example, "git clone" does a checkout, so should probably run the
> checkout hooks.

There is (or, rather, should be) absolutely no difference between code
changes and hook changes. Both would go through the same review
process. If it's possible to put in nasty hooks then it's possible to
put in nasty code.

>> So I don't think this is a good argument. Moreover, I do not work with
>> people that would ever consider such nastiness. You need to realize
>> that this is all closed source. Your argument would be more valid in
>> an open source environment (like git.git).
>
> That may be acceptable for you, but you can't ask for such feature to be
> included in Git itself. At best, a standardized way to setup hooks (but
> something that would require a user-action to be set up) would be
> acceptable.

Given ${PROJECT}/.git, I would think that a simple config setting
(hooks.run-automatically-this-is-a-security-risk [defaulting to false,
of course]) and an extra directory like ${PROJECT}/.hooks (this should
probably be configurable as well: hooks.directory) would work
perfectly. Then it's up to the project to decide if they want to use
that feature. Moreover, you could then still have "personal" hooks in
${PROJECT}/.git/hooks.

Would such a setup be acceptable?

```

## Junio C Hamano, 2012-05-02 19:27

Subject: Re: Is there any way to make hooks part of the repository?
Message-ID: <7v1un2idt0.fsf@alter.siamese.dyndns.org>
URL: https://gitlist.dev/e/7v1un2idt0.fsf%40alter.siamese.dyndns.org
In-Reply-To: <CAE1pOi3RZ+x7YcVZ-dLt70=wwRsvY9D6GQR-T+JZ9S7x8CFjPw@mail.gmail.com>

```
Hilco Wijbenga <hilco.wijbenga@gmail.com> writes:

> On 1 May 2012 23:38, Matthieu Moy <Matthieu.Moy@grenoble-inp.fr> wrote:
> ...
>> Yes, but at least, you have the opportunity to examine the other places
>> before they are ran. Hooks would be really, really nasty security-wise.
>> For example, "git clone" does a checkout, so should probably run the
>> checkout hooks.
>
> There is (or, rather, should be) absolutely no difference between code
> changes and hook changes. Both would go through the same review
> process.

Matthieu is *not* talking about auditing nastiness going into the
project's repository; he is talking is about a chance to audit whatever
comes from the project's repository that *could* potentially contain some
nastiness before it causes harm to your working environment. In other
words, not *having* to trust what is in the project's repository, but
having a way to verify.

Read what he wrote again with that in mind, and you will understand his
point.

```

## Hilco Wijbenga, 2012-05-02 19:42

Subject: Re: Is there any way to make hooks part of the repository?
Message-ID: <CAE1pOi1SLU5_eLr3ahiUjzQqPUnVPX70CPq=OW-o-85Lk43GwA@mail.gmail.com>
URL: https://gitlist.dev/e/CAE1pOi1SLU5_eLr3ahiUjzQqPUnVPX70CPq%3DOW-o-85Lk43GwA%40mail.gmail.com
In-Reply-To: <7v1un2idt0.fsf@alter.siamese.dyndns.org>

```
On 2 May 2012 12:27, Junio C Hamano <gitster@pobox.com> wrote:
> Hilco Wijbenga <hilco.wijbenga@gmail.com> writes:
>
>> On 1 May 2012 23:38, Matthieu Moy <Matthieu.Moy@grenoble-inp.fr> wrote:
>> ...
>>> Yes, but at least, you have the opportunity to examine the other places
>>> before they are ran. Hooks would be really, really nasty security-wise.
>>> For example, "git clone" does a checkout, so should probably run the
>>> checkout hooks.
>>
>> There is (or, rather, should be) absolutely no difference between code
>> changes and hook changes. Both would go through the same review
>> process.
>
> Matthieu is *not* talking about auditing nastiness going into the
> project's repository; he is talking is about a chance to audit whatever
> comes from the project's repository that *could* potentially contain some
> nastiness before it causes harm to your working environment. In other
> words, not *having* to trust what is in the project's repository, but
> having a way to verify.
>
> Read what he wrote again with that in mind, and you will understand his
> point.

Yes, I understand.

Perhaps these automatic hooks should only be applicable for "outgoing"
changes like commit and push? That way you can review the hooks before
they run but you still have a chance to prevent developer errors from
getting to the server/other people (which is really all I care about,
I am looking for a way to protect developers from making silly
mistakes).

```

## Thomas Rast, 2012-05-03 09:00

Subject: Re: Is there any way to make hooks part of the repository?
Message-ID: <87ipgdskpx.fsf@thomas.inf.ethz.ch>
URL: https://gitlist.dev/e/87ipgdskpx.fsf%40thomas.inf.ethz.ch
In-Reply-To: <CAE1pOi1SLU5_eLr3ahiUjzQqPUnVPX70CPq=OW-o-85Lk43GwA@mail.gmail.com>

```
Hilco Wijbenga <hilco.wijbenga@gmail.com> writes:

>> Matthieu is *not* talking about auditing nastiness going into the
>> project's repository; he is talking is about a chance to audit whatever
>> comes from the project's repository that *could* potentially contain some
>> nastiness before it causes harm to your working environment. In other
>> words, not *having* to trust what is in the project's repository, but
>> having a way to verify.
>
> Perhaps these automatic hooks should only be applicable for "outgoing"
> changes like commit and push? That way you can review the hooks before
> they run but you still have a chance to prevent developer errors from
> getting to the server/other people (which is really all I care about,
> I am looking for a way to protect developers from making silly
> mistakes).

Shouldn't those checks be made server-side with a pre-receive hook?

-- 
Thomas Rast
trast@{inf,student}.ethz.ch

```

## Hilco Wijbenga, 2012-05-03 17:05

Subject: Re: Is there any way to make hooks part of the repository?
Message-ID: <CAE1pOi39i4hg_bTuigq15ifuKtXVW7F-NukMP57E_4e=s0fMdQ@mail.gmail.com>
URL: https://gitlist.dev/e/CAE1pOi39i4hg_bTuigq15ifuKtXVW7F-NukMP57E_4e%3Ds0fMdQ%40mail.gmail.com
In-Reply-To: <87ipgdskpx.fsf@thomas.inf.ethz.ch>

```
On 3 May 2012 02:00, Thomas Rast <trast@student.ethz.ch> wrote:
> Hilco Wijbenga <hilco.wijbenga@gmail.com> writes:
>
>>> Matthieu is *not* talking about auditing nastiness going into the
>>> project's repository; he is talking is about a chance to audit whatever
>>> comes from the project's repository that *could* potentially contain some
>>> nastiness before it causes harm to your working environment. In other
>>> words, not *having* to trust what is in the project's repository, but
>>> having a way to verify.
>>
>> Perhaps these automatic hooks should only be applicable for "outgoing"
>> changes like commit and push? That way you can review the hooks before
>> they run but you still have a chance to prevent developer errors from
>> getting to the server/other people (which is really all I care about,
>> I am looking for a way to protect developers from making silly
>> mistakes).
>
> Shouldn't those checks be made server-side with a pre-receive hook?

Firstly, see my original email: we have no such access to the server.
Secondly, (now that I've thought about it a bit more), it makes more
sense to do it on the "client" instead of having the server do all the
work for everybody. (Fail early, fail fast.)

```

## Johan Herland, 2012-05-04 06:10

Subject: Re: Is there any way to make hooks part of the repository?
Message-ID: <CALKQrgcTtjQtS34EZhay8nMKxFO2iCHv+YCZjXefB6oZsa93kw@mail.gmail.com>
URL: https://gitlist.dev/e/CALKQrgcTtjQtS34EZhay8nMKxFO2iCHv%2BYCZjXefB6oZsa93kw%40mail.gmail.com
In-Reply-To: <CAE1pOi39i4hg_bTuigq15ifuKtXVW7F-NukMP57E_4e=s0fMdQ@mail.gmail.com>

```
On Thu, May 3, 2012 at 7:05 PM, Hilco Wijbenga <hilco.wijbenga@gmail.com> wrote:
> On 3 May 2012 02:00, Thomas Rast <trast@student.ethz.ch> wrote:
>> Shouldn't those checks be made server-side with a pre-receive hook?
>
> Firstly, see my original email: we have no such access to the server.
> Secondly, (now that I've thought about it a bit more), it makes more
> sense to do it on the "client" instead of having the server do all the
> work for everybody. (Fail early, fail fast.)

No matter how you go about this, there is no way to _guarantee_ that a
given hook is run in all user repos (after all, the users have the
ultimate control over their own repos), so if you really _need_ the
hook to be run, then you have no other choice but to put it on the
server. Such is the nature of distributed version control.

If you still want a hook to run in user repos, you can only ask that
users enable the hook by including a script which copies the hook into
place, and then tell your users to run that script (e.g. in your
README).


...Johan

-- 
Johan Herland, <johan@herland.net>
www.herland.net

```
