contrib: remove "hooks" directory

The "hooks" directory contains a handful of example hooks. Most of these hooks are highly specific and haven't really received any updates over the last couple of years, except for some global cleanups. The multimail hook has also been removed in f74d11471fa (multimail: stop shipping a copy, 2021-06-10) in favor of its upstream project [1]. Remove those hooks. If we want to provide examples for how to use Git hooks we should do that as part of our documentation, for example in githooks(5). [1]: https://github.com/git-multimail/git-multimail Signed-off-by: Patrick Steinhardt <ps@pks.im> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Patrick Steinhardt committed May 12, 2025 at 11:19 UTC 9a19b79e7599432754cab22b29a0ad3291b3d455
5 files changed -1443
contrib/hooks/multimail/README.Git deleted
-7
@@ -1,7 +0,0 @@
1 -git-multimail is developed as an independent project at the following
2 -website:
3 -
4 - https://github.com/git-multimail/git-multimail
5 -
6 -Please refer to that project page for information about how to report
7 -bugs or contribute to git-multimail.
contrib/hooks/post-receive-email deleted
-759
@@ -1,759 +0,0 @@
1 -#!/bin/sh
2 -#
3 -# Copyright (c) 2007 Andy Parkins
4 -#
5 -# An example hook script to mail out commit update information.
6 -#
7 -# NOTE: This script is no longer under active development. There
8 -# is another script, git-multimail, which is more capable and
9 -# configurable and is largely backwards-compatible with this script;
10 -# please see "contrib/hooks/multimail/". For instructions on how to
11 -# migrate from post-receive-email to git-multimail, please see
12 -# "README.migrate-from-post-receive-email" in that directory.
13 -#
14 -# This hook sends emails listing new revisions to the repository
15 -# introduced by the change being reported. The rule is that (for
16 -# branch updates) each commit will appear on one email and one email
17 -# only.
18 -#
19 -# This hook is stored in the contrib/hooks directory. Your distribution
20 -# will have put this somewhere standard. You should make this script
21 -# executable then link to it in the repository you would like to use it in.
22 -# For example, on debian the hook is stored in
23 -# /usr/share/git-core/contrib/hooks/post-receive-email:
24 -#
25 -# cd /path/to/your/repository.git
26 -# ln -sf /usr/share/git-core/contrib/hooks/post-receive-email hooks/post-receive
27 -#
28 -# This hook script assumes it is enabled on the central repository of a
29 -# project, with all users pushing only to it and not between each other. It
30 -# will still work if you don't operate in that style, but it would become
31 -# possible for the email to be from someone other than the person doing the
32 -# push.
33 -#
34 -# To help with debugging and use on pre-v1.5.1 git servers, this script will
35 -# also obey the interface of hooks/update, taking its arguments on the
36 -# command line. Unfortunately, hooks/update is called once for each ref.
37 -# To avoid firing one email per ref, this script just prints its output to
38 -# the screen when used in this mode. The output can then be redirected if
39 -# wanted.
40 -#
41 -# Config
42 -# ------
43 -# hooks.mailinglist
44 -# This is the list that all pushes will go to; leave it blank to not send
45 -# emails for every ref update.
46 -# hooks.announcelist
47 -# This is the list that all pushes of annotated tags will go to. Leave it
48 -# blank to default to the mailinglist field. The announce emails lists
49 -# the short log summary of the changes since the last annotated tag.
50 -# hooks.envelopesender
51 -# If set then the -f option is passed to sendmail to allow the envelope
52 -# sender address to be set
53 -# hooks.emailprefix
54 -# All emails have their subjects prefixed with this prefix, or "[SCM]"
55 -# if emailprefix is unset, to aid filtering
56 -# hooks.showrev
57 -# The shell command used to format each revision in the email, with
58 -# "%s" replaced with the commit id. Defaults to "git rev-list -1
59 -# --pretty %s", displaying the commit id, author, date and log
60 -# message. To list full patches separated by a blank line, you
61 -# could set this to "git show -C %s; echo".
62 -# To list a gitweb/cgit URL *and* a full patch for each change set, use this:
63 -# "t=%s; printf 'http://.../?id=%%s' \$t; echo;echo; git show -C \$t; echo"
64 -# Be careful if "..." contains things that will be expanded by shell "eval"
65 -# or printf.
66 -# hooks.emailmaxlines
67 -# The maximum number of lines that should be included in the generated
68 -# email body. If not specified, there is no limit.
69 -# Lines beyond the limit are suppressed and counted, and a final
70 -# line is added indicating the number of suppressed lines.
71 -# hooks.diffopts
72 -# Alternate options for the git diff-tree invocation that shows changes.
73 -# Default is "--stat --summary --find-copies-harder". Add -p to those
74 -# options to include a unified diff of changes in addition to the usual
75 -# summary output.
76 -#
77 -# Notes
78 -# -----
79 -# All emails include the headers "X-Git-Refname", "X-Git-Oldrev",
80 -# "X-Git-Newrev", and "X-Git-Reftype" to enable fine tuned filtering and
81 -# give information for debugging.
82 -#
83 -
84 -# ---------------------------- Functions
85 -
86 -#
87 -# Function to prepare for email generation. This decides what type
88 -# of update this is and whether an email should even be generated.
89 -#
90 -prep_for_email()
91 -{
92 - # --- Arguments
93 - oldrev=$(git rev-parse $1)
94 - newrev=$(git rev-parse $2)
95 - refname="$3"
96 -
97 - # --- Interpret
98 - # 0000->1234 (create)
99 - # 1234->2345 (update)
100 - # 2345->0000 (delete)
101 - if expr "$oldrev" : '0*$' >/dev/null
102 - then
103 - change_type="create"
104 - else
105 - if expr "$newrev" : '0*$' >/dev/null
106 - then
107 - change_type="delete"
108 - else
109 - change_type="update"
110 - fi
111 - fi
112 -
113 - # --- Get the revision types
114 - newrev_type=$(git cat-file -t $newrev 2> /dev/null)
115 - oldrev_type=$(git cat-file -t "$oldrev" 2> /dev/null)
116 - case "$change_type" in
117 - create|update)
118 - rev="$newrev"
119 - rev_type="$newrev_type"
120 - ;;
121 - delete)
122 - rev="$oldrev"
123 - rev_type="$oldrev_type"
124 - ;;
125 - esac
126 -
127 - # The revision type tells us what type the commit is, combined with
128 - # the location of the ref we can decide between
129 - # - working branch
130 - # - tracking branch
131 - # - unannoted tag
132 - # - annotated tag
133 - case "$refname","$rev_type" in
134 - refs/tags/*,commit)
135 - # un-annotated tag
136 - refname_type="tag"
137 - short_refname=${refname##refs/tags/}
138 - ;;
139 - refs/tags/*,tag)
140 - # annotated tag
141 - refname_type="annotated tag"
142 - short_refname=${refname##refs/tags/}
143 - # change recipients
144 - if [ -n "$announcerecipients" ]; then
145 - recipients="$announcerecipients"
146 - fi
147 - ;;
148 - refs/heads/*,commit)
149 - # branch
150 - refname_type="branch"
151 - short_refname=${refname##refs/heads/}
152 - ;;
153 - refs/remotes/*,commit)
154 - # tracking branch
155 - refname_type="tracking branch"
156 - short_refname=${refname##refs/remotes/}
157 - echo >&2 "*** Push-update of tracking branch, $refname"
158 - echo >&2 "*** - no email generated."
159 - return 1
160 - ;;
161 - *)
162 - # Anything else (is there anything else?)
163 - echo >&2 "*** Unknown type of update to $refname ($rev_type)"
164 - echo >&2 "*** - no email generated"
165 - return 1
166 - ;;
167 - esac
168 -
169 - # Check if we've got anyone to send to
170 - if [ -z "$recipients" ]; then
171 - case "$refname_type" in
172 - "annotated tag")
173 - config_name="hooks.announcelist"
174 - ;;
175 - *)
176 - config_name="hooks.mailinglist"
177 - ;;
178 - esac
179 - echo >&2 "*** $config_name is not set so no email will be sent"
180 - echo >&2 "*** for $refname update $oldrev->$newrev"
181 - return 1
182 - fi
183 -
184 - return 0
185 -}
186 -
187 -#
188 -# Top level email generation function. This calls the appropriate
189 -# body-generation routine after outputting the common header.
190 -#
191 -# Note this function doesn't actually generate any email output, that is
192 -# taken care of by the functions it calls:
193 -# - generate_email_header
194 -# - generate_create_XXXX_email
195 -# - generate_update_XXXX_email
196 -# - generate_delete_XXXX_email
197 -# - generate_email_footer
198 -#
199 -# Note also that this function cannot 'exit' from the script; when this
200 -# function is running (in hook script mode), the send_mail() function
201 -# is already executing in another process, connected via a pipe, and
202 -# if this function exits without, whatever has been generated to that
203 -# point will be sent as an email... even if nothing has been generated.
204 -#
205 -generate_email()
206 -{
207 - # Email parameters
208 - # The email subject will contain the best description of the ref
209 - # that we can build from the parameters
210 - describe=$(git describe $rev 2>/dev/null)
211 - if [ -z "$describe" ]; then
212 - describe=$rev
213 - fi
214 -
215 - generate_email_header
216 -
217 - # Call the correct body generation function
218 - fn_name=general
219 - case "$refname_type" in
220 - "tracking branch"|branch)
221 - fn_name=branch
222 - ;;
223 - "annotated tag")
224 - fn_name=atag
225 - ;;
226 - esac
227 -
228 - if [ -z "$maxlines" ]; then
229 - generate_${change_type}_${fn_name}_email
230 - else
231 - generate_${change_type}_${fn_name}_email | limit_lines $maxlines
232 - fi
233 -
234 - generate_email_footer
235 -}
236 -
237 -generate_email_header()
238 -{
239 - # --- Email (all stdout will be the email)
240 - # Generate header
241 - cat <<-EOF
242 - To: $recipients
243 - Subject: ${emailprefix}$projectdesc $refname_type $short_refname ${change_type}d. $describe
244 - MIME-Version: 1.0
245 - Content-Type: text/plain; charset=utf-8
246 - Content-Transfer-Encoding: 8bit
247 - X-Git-Refname: $refname
248 - X-Git-Reftype: $refname_type
249 - X-Git-Oldrev: $oldrev
250 - X-Git-Newrev: $newrev
251 - Auto-Submitted: auto-generated
252 -
253 - This is an automated email from the git hooks/post-receive script. It was
254 - generated because a ref change was pushed to the repository containing
255 - the project "$projectdesc".
256 -
257 - The $refname_type, $short_refname has been ${change_type}d
258 - EOF
259 -}
260 -
261 -generate_email_footer()
262 -{
263 - SPACE=" "
264 - cat <<-EOF
265 -
266 -
267 - hooks/post-receive
268 - --${SPACE}
269 - $projectdesc
270 - EOF
271 -}
272 -
273 -# --------------- Branches
274 -
275 -#
276 -# Called for the creation of a branch
277 -#
278 -generate_create_branch_email()
279 -{
280 - # This is a new branch and so oldrev is not valid
281 - echo " at $newrev ($newrev_type)"
282 - echo ""
283 -
284 - echo $LOGBEGIN
285 - show_new_revisions
286 - echo $LOGEND
287 -}
288 -
289 -#
290 -# Called for the change of a pre-existing branch
291 -#
292 -generate_update_branch_email()
293 -{
294 - # Consider this:
295 - # 1 --- 2 --- O --- X --- 3 --- 4 --- N
296 - #
297 - # O is $oldrev for $refname
298 - # N is $newrev for $refname
299 - # X is a revision pointed to by some other ref, for which we may
300 - # assume that an email has already been generated.
301 - # In this case we want to issue an email containing only revisions
302 - # 3, 4, and N. Given (almost) by
303 - #
304 - # git rev-list N ^O --not --all
305 - #
306 - # The reason for the "almost", is that the "--not --all" will take
307 - # precedence over the "N", and effectively will translate to
308 - #
309 - # git rev-list N ^O ^X ^N
310 - #
311 - # So, we need to build up the list more carefully. git rev-parse
312 - # will generate a list of revs that may be fed into git rev-list.
313 - # We can get it to make the "--not --all" part and then filter out
314 - # the "^N" with:
315 - #
316 - # git rev-parse --not --all | grep -v N
317 - #
318 - # Then, using the --stdin switch to git rev-list we have effectively
319 - # manufactured
320 - #
321 - # git rev-list N ^O ^X
322 - #
323 - # This leaves a problem when someone else updates the repository
324 - # while this script is running. Their new value of the ref we're
325 - # working on would be included in the "--not --all" output; and as
326 - # our $newrev would be an ancestor of that commit, it would exclude
327 - # all of our commits. What we really want is to exclude the current
328 - # value of $refname from the --not list, rather than N itself. So:
329 - #
330 - # git rev-parse --not --all | grep -v $(git rev-parse $refname)
331 - #
332 - # Gets us to something pretty safe (apart from the small time
333 - # between refname being read, and git rev-parse running - for that,
334 - # I give up)
335 - #
336 - #
337 - # Next problem, consider this:
338 - # * --- B --- * --- O ($oldrev)
339 - # \
340 - # * --- X --- * --- N ($newrev)
341 - #
342 - # That is to say, there is no guarantee that oldrev is a strict
343 - # subset of newrev (it would have required a --force, but that's
344 - # allowed). So, we can't simply say rev-list $oldrev..$newrev.
345 - # Instead we find the common base of the two revs and list from
346 - # there.
347 - #
348 - # As above, we need to take into account the presence of X; if
349 - # another branch is already in the repository and points at some of
350 - # the revisions that we are about to output - we don't want them.
351 - # The solution is as before: git rev-parse output filtered.
352 - #
353 - # Finally, tags: 1 --- 2 --- O --- T --- 3 --- 4 --- N
354 - #
355 - # Tags pushed into the repository generate nice shortlog emails that
356 - # summarise the commits between them and the previous tag. However,
357 - # those emails don't include the full commit messages that we output
358 - # for a branch update. Therefore we still want to output revisions
359 - # that have been output on a tag email.
360 - #
361 - # Luckily, git rev-parse includes just the tool. Instead of using
362 - # "--all" we use "--branches"; this has the added benefit that
363 - # "remotes/" will be ignored as well.
364 -
365 - # List all of the revisions that were removed by this update, in a
366 - # fast-forward update, this list will be empty, because rev-list O
367 - # ^N is empty. For a non-fast-forward, O ^N is the list of removed
368 - # revisions
369 - fast_forward=""
370 - rev=""
371 - for rev in $(git rev-list $newrev..$oldrev)
372 - do
373 - revtype=$(git cat-file -t "$rev")
374 - echo " discards $rev ($revtype)"
375 - done
376 - if [ -z "$rev" ]; then
377 - fast_forward=1
378 - fi
379 -
380 - # List all the revisions from baserev to newrev in a kind of
381 - # "table-of-contents"; note this list can include revisions that
382 - # have already had notification emails and is present to show the
383 - # full detail of the change from rolling back the old revision to
384 - # the base revision and then forward to the new revision
385 - for rev in $(git rev-list $oldrev..$newrev)
386 - do
387 - revtype=$(git cat-file -t "$rev")
388 - echo " via $rev ($revtype)"
389 - done
390 -
391 - if [ "$fast_forward" ]; then
392 - echo " from $oldrev ($oldrev_type)"
393 - else
394 - # 1. Existing revisions were removed. In this case newrev
395 - # is a subset of oldrev - this is the reverse of a
396 - # fast-forward, a rewind
397 - # 2. New revisions were added on top of an old revision,
398 - # this is a rewind and addition.
399 -
400 - # (1) certainly happened, (2) possibly. When (2) hasn't
401 - # happened, we set a flag to indicate that no log printout
402 - # is required.
403 -
404 - echo ""
405 -
406 - # Find the common ancestor of the old and new revisions and
407 - # compare it with newrev
408 - baserev=$(git merge-base $oldrev $newrev)
409 - rewind_only=""
410 - if [ "$baserev" = "$newrev" ]; then
411 - echo "This update discarded existing revisions and left the branch pointing at"
412 - echo "a previous point in the repository history."
413 - echo ""
414 - echo " * -- * -- N ($newrev)"
415 - echo " \\"
416 - echo " O -- O -- O ($oldrev)"
417 - echo ""
418 - echo "The removed revisions are not necessarily gone - if another reference"
419 - echo "still refers to them they will stay in the repository."
420 - rewind_only=1
421 - else
422 - echo "This update added new revisions after undoing existing revisions. That is"
423 - echo "to say, the old revision is not a strict subset of the new revision. This"
424 - echo "situation occurs when you --force push a change and generate a repository"
425 - echo "containing something like this:"
426 - echo ""
427 - echo " * -- * -- B -- O -- O -- O ($oldrev)"
428 - echo " \\"
429 - echo " N -- N -- N ($newrev)"
430 - echo ""
431 - echo "When this happens we assume that you've already had alert emails for all"
432 - echo "of the O revisions, and so we here report only the revisions in the N"
433 - echo "branch from the common base, B."
434 - fi
435 - fi
436 -
437 - echo ""
438 - if [ -z "$rewind_only" ]; then
439 - echo "Those revisions listed above that are new to this repository have"
440 - echo "not appeared on any other notification email; so we list those"
441 - echo "revisions in full, below."
442 -
443 - echo ""
444 - echo $LOGBEGIN
445 - show_new_revisions
446 -
447 - # XXX: Need a way of detecting whether git rev-list actually
448 - # outputted anything, so that we can issue a "no new
449 - # revisions added by this update" message
450 -
451 - echo $LOGEND
452 - else
453 - echo "No new revisions were added by this update."
454 - fi
455 -
456 - # The diffstat is shown from the old revision to the new revision.
457 - # This is to show the truth of what happened in this change.
458 - # There's no point showing the stat from the base to the new
459 - # revision because the base is effectively a random revision at this
460 - # point - the user will be interested in what this revision changed
461 - # - including the undoing of previous revisions in the case of
462 - # non-fast-forward updates.
463 - echo ""
464 - echo "Summary of changes:"
465 - git diff-tree $diffopts $oldrev..$newrev
466 -}
467 -
468 -#
469 -# Called for the deletion of a branch
470 -#
471 -generate_delete_branch_email()
472 -{
473 - echo " was $oldrev"
474 - echo ""
475 - echo $LOGBEGIN
476 - git diff-tree -s --always --encoding=UTF-8 --pretty=oneline $oldrev
477 - echo $LOGEND
478 -}
479 -
480 -# --------------- Annotated tags
481 -
482 -#
483 -# Called for the creation of an annotated tag
484 -#
485 -generate_create_atag_email()
486 -{
487 - echo " at $newrev ($newrev_type)"
488 -
489 - generate_atag_email
490 -}
491 -
492 -#
493 -# Called for the update of an annotated tag (this is probably a rare event
494 -# and may not even be allowed)
495 -#
496 -generate_update_atag_email()
497 -{
498 - echo " to $newrev ($newrev_type)"
499 - echo " from $oldrev (which is now obsolete)"
500 -
501 - generate_atag_email
502 -}
503 -
504 -#
505 -# Called when an annotated tag is created or changed
506 -#
507 -generate_atag_email()
508 -{
509 - # Use git for-each-ref to pull out the individual fields from the
510 - # tag
511 - eval $(git for-each-ref --shell --format='
512 - tagobject=%(*objectname)
513 - tagtype=%(*objecttype)
514 - tagger=%(taggername)
515 - tagged=%(taggerdate)' $refname
516 - )
517 -
518 - echo " tagging $tagobject ($tagtype)"
519 - case "$tagtype" in
520 - commit)
521 -
522 - # If the tagged object is a commit, then we assume this is a
523 - # release, and so we calculate which tag this tag is
524 - # replacing
525 - prevtag=$(git describe --abbrev=0 $newrev^ 2>/dev/null)
526 -
527 - if [ -n "$prevtag" ]; then
528 - echo " replaces $prevtag"
529 - fi
530 - ;;
531 - *)
532 - echo " length $(git cat-file -s $tagobject) bytes"
533 - ;;
534 - esac
535 - echo " tagged by $tagger"
536 - echo " on $tagged"
537 -
538 - echo ""
539 - echo $LOGBEGIN
540 -
541 - # Show the content of the tag message; this might contain a change
542 - # log or release notes so is worth displaying.
543 - git cat-file tag $newrev | sed -e '1,/^$/d'
544 -
545 - echo ""
546 - case "$tagtype" in
547 - commit)
548 - # Only commit tags make sense to have rev-list operations
549 - # performed on them
550 - if [ -n "$prevtag" ]; then
551 - # Show changes since the previous release
552 - git shortlog "$prevtag..$newrev"
553 - else
554 - # No previous tag, show all the changes since time
555 - # began
556 - git shortlog $newrev
557 - fi
558 - ;;
559 - *)
560 - # XXX: Is there anything useful we can do for non-commit
561 - # objects?
562 - ;;
563 - esac
564 -
565 - echo $LOGEND
566 -}
567 -
568 -#
569 -# Called for the deletion of an annotated tag
570 -#
571 -generate_delete_atag_email()
572 -{
573 - echo " was $oldrev"
574 - echo ""
575 - echo $LOGBEGIN
576 - git diff-tree -s --always --encoding=UTF-8 --pretty=oneline $oldrev
577 - echo $LOGEND
578 -}
579 -
580 -# --------------- General references
581 -
582 -#
583 -# Called when any other type of reference is created (most likely a
584 -# non-annotated tag)
585 -#
586 -generate_create_general_email()
587 -{
588 - echo " at $newrev ($newrev_type)"
589 -
590 - generate_general_email
591 -}
592 -
593 -#
594 -# Called when any other type of reference is updated (most likely a
595 -# non-annotated tag)
596 -#
597 -generate_update_general_email()
598 -{
599 - echo " to $newrev ($newrev_type)"
600 - echo " from $oldrev"
601 -
602 - generate_general_email
603 -}
604 -
605 -#
606 -# Called for creation or update of any other type of reference
607 -#
608 -generate_general_email()
609 -{
610 - # Unannotated tags are more about marking a point than releasing a
611 - # version; therefore we don't do the shortlog summary that we do for
612 - # annotated tags above - we simply show that the point has been
613 - # marked, and print the log message for the marked point for
614 - # reference purposes
615 - #
616 - # Note this section also catches any other reference type (although
617 - # there aren't any) and deals with them in the same way.
618 -
619 - echo ""
620 - if [ "$newrev_type" = "commit" ]; then
621 - echo $LOGBEGIN
622 - git diff-tree -s --always --encoding=UTF-8 --pretty=medium $newrev
623 - echo $LOGEND
624 - else
625 - # What can we do here? The tag marks an object that is not
626 - # a commit, so there is no log for us to display. It's
627 - # probably not wise to output git cat-file as it could be a
628 - # binary blob. We'll just say how big it is
629 - echo "$newrev is a $newrev_type, and is $(git cat-file -s $newrev) bytes long."
630 - fi
631 -}
632 -
633 -#
634 -# Called for the deletion of any other type of reference
635 -#
636 -generate_delete_general_email()
637 -{
638 - echo " was $oldrev"
639 - echo ""
640 - echo $LOGBEGIN
641 - git diff-tree -s --always --encoding=UTF-8 --pretty=oneline $oldrev
642 - echo $LOGEND
643 -}
644 -
645 -
646 -# --------------- Miscellaneous utilities
647 -
648 -#
649 -# Show new revisions as the user would like to see them in the email.
650 -#
651 -show_new_revisions()
652 -{
653 - # This shows all log entries that are not already covered by
654 - # another ref - i.e. commits that are now accessible from this
655 - # ref that were previously not accessible
656 - # (see generate_update_branch_email for the explanation of this
657 - # command)
658 -
659 - # Revision range passed to rev-list differs for new vs. updated
660 - # branches.
661 - if [ "$change_type" = create ]
662 - then
663 - # Show all revisions exclusive to this (new) branch.
664 - revspec=$newrev
665 - else
666 - # Branch update; show revisions not part of $oldrev.
667 - revspec=$oldrev..$newrev
668 - fi
669 -
670 - other_branches=$(git for-each-ref --format='%(refname)' refs/heads/ |
671 - grep -F -v $refname)
672 - git rev-parse --not $other_branches |
673 - if [ -z "$custom_showrev" ]
674 - then
675 - git rev-list --pretty --stdin $revspec
676 - else
677 - git rev-list --stdin $revspec |
678 - while read onerev
679 - do
680 - eval $(printf "$custom_showrev" $onerev)
681 - done
682 - fi
683 -}
684 -
685 -
686 -limit_lines()
687 -{
688 - lines=0
689 - skipped=0
690 - while IFS="" read -r line; do
691 - lines=$((lines + 1))
692 - if [ $lines -gt $1 ]; then
693 - skipped=$((skipped + 1))
694 - else
695 - printf "%s\n" "$line"
696 - fi
697 - done
698 - if [ $skipped -ne 0 ]; then
699 - echo "... $skipped lines suppressed ..."
700 - fi
701 -}
702 -
703 -
704 -send_mail()
705 -{
706 - if [ -n "$envelopesender" ]; then
707 - /usr/sbin/sendmail -t -f "$envelopesender"
708 - else
709 - /usr/sbin/sendmail -t
710 - fi
711 -}
712 -
713 -# ---------------------------- main()
714 -
715 -# --- Constants
716 -LOGBEGIN="- Log -----------------------------------------------------------------"
717 -LOGEND="-----------------------------------------------------------------------"
718 -
719 -# --- Config
720 -# Set GIT_DIR either from the working directory, or from the environment
721 -# variable.
722 -GIT_DIR=$(git rev-parse --git-dir 2>/dev/null)
723 -if [ -z "$GIT_DIR" ]; then
724 - echo >&2 "fatal: post-receive: GIT_DIR not set"
725 - exit 1
726 -fi
727 -
728 -projectdesc=$(sed -ne '1p' "$GIT_DIR/description" 2>/dev/null)
729 -# Check if the description is unchanged from it's default, and shorten it to
730 -# a more manageable length if it is
731 -if expr "$projectdesc" : "Unnamed repository.*$" >/dev/null
732 -then
733 - projectdesc="UNNAMED PROJECT"
734 -fi
735 -
736 -recipients=$(git config hooks.mailinglist)
737 -announcerecipients=$(git config hooks.announcelist)
738 -envelopesender=$(git config hooks.envelopesender)
739 -emailprefix=$(git config hooks.emailprefix || echo '[SCM] ')
740 -custom_showrev=$(git config hooks.showrev)
741 -maxlines=$(git config hooks.emailmaxlines)
742 -diffopts=$(git config hooks.diffopts)
743 -: ${diffopts:="--stat --summary --find-copies-harder"}
744 -
745 -# --- Main loop
746 -# Allow dual mode: run from the command line just like the update hook, or
747 -# if no arguments are given then run as a hook script
748 -if [ -n "$1" -a -n "$2" -a -n "$3" ]; then
749 - # Output to the terminal in command line mode - if someone wanted to
750 - # resend an email; they could redirect the output to sendmail
751 - # themselves
752 - prep_for_email $2 $3 $1 && PAGER= generate_email
753 -else
754 - while read oldrev newrev refname
755 - do
756 - prep_for_email $oldrev $newrev $refname || continue
757 - generate_email $maxlines | send_mail
758 - done
759 -fi
contrib/hooks/pre-auto-gc-battery deleted
-42
@@ -1,42 +0,0 @@
1 -#!/bin/sh
2 -#
3 -# An example hook script to verify if you are on battery, in case you
4 -# are running Linux or OS X. Called by git-gc --auto with no arguments.
5 -# The hook should exit with non-zero status after issuing an appropriate
6 -# message if it wants to stop the auto repacking.
7 -#
8 -# This hook is stored in the contrib/hooks directory. Your distribution
9 -# may have put this somewhere else. If you want to use this hook, you
10 -# should make this script executable then link to it in the repository
11 -# you would like to use it in.
12 -#
13 -# For example, if the hook is stored in
14 -# /usr/share/git-core/contrib/hooks/pre-auto-gc-battery:
15 -#
16 -# cd /path/to/your/repository.git
17 -# ln -sf /usr/share/git-core/contrib/hooks/pre-auto-gc-battery \
18 -# hooks/pre-auto-gc
19 -
20 -if test -x /sbin/on_ac_power && (/sbin/on_ac_power;test $? -ne 1)
21 -then
22 - exit 0
23 -elif test "$(cat /sys/class/power_supply/AC/online 2>/dev/null)" = 1
24 -then
25 - exit 0
26 -elif grep -q 'on-line' /proc/acpi/ac_adapter/AC/state 2>/dev/null
27 -then
28 - exit 0
29 -elif grep -q '0x01$' /proc/apm 2>/dev/null
30 -then
31 - exit 0
32 -elif grep -q "AC Power \+: 1" /proc/pmu/info 2>/dev/null
33 -then
34 - exit 0
35 -elif test -x /usr/bin/pmset && /usr/bin/pmset -g batt |
36 - grep -q "drawing from 'AC Power'"
37 -then
38 - exit 0
39 -fi
40 -
41 -echo "Auto packing deferred; not on AC"
42 -exit 1
contrib/hooks/setgitperms.perl deleted
-214
@@ -1,214 +0,0 @@
1 -#!/usr/bin/perl
2 -#
3 -# Copyright (c) 2006 Josh England
4 -#
5 -# This script can be used to save/restore full permissions and ownership data
6 -# within a git working tree.
7 -#
8 -# To save permissions/ownership data, place this script in your .git/hooks
9 -# directory and enable a `pre-commit` hook with the following lines:
10 -# #!/bin/sh
11 -# SUBDIRECTORY_OK=1 . git-sh-setup
12 -# $GIT_DIR/hooks/setgitperms.perl -r
13 -#
14 -# To restore permissions/ownership data, place this script in your .git/hooks
15 -# directory and enable a `post-merge` and `post-checkout` hook with the
16 -# following lines:
17 -# #!/bin/sh
18 -# SUBDIRECTORY_OK=1 . git-sh-setup
19 -# $GIT_DIR/hooks/setgitperms.perl -w
20 -#
21 -use strict;
22 -use Getopt::Long;
23 -use File::Find;
24 -use File::Basename;
25 -
26 -my $usage =
27 -"usage: setgitperms.perl [OPTION]... <--read|--write>
28 -This program uses a file `.gitmeta` to store/restore permissions and uid/gid
29 -info for all files/dirs tracked by git in the repository.
30 -
31 ----------------------------------Read Mode-------------------------------------
32 --r, --read Reads perms/etc from working dir into a .gitmeta file
33 --s, --stdout Output to stdout instead of .gitmeta
34 --d, --diff Show unified diff of perms file (XOR with --stdout)
35 -
36 ----------------------------------Write Mode------------------------------------
37 --w, --write Modify perms/etc in working dir to match the .gitmeta file
38 --v, --verbose Be verbose
39 -
40 -\n";
41 -
42 -my ($stdout, $showdiff, $verbose, $read_mode, $write_mode);
43 -
44 -if ((@ARGV < 0) || !GetOptions(
45 - "stdout", \$stdout,
46 - "diff", \$showdiff,
47 - "read", \$read_mode,
48 - "write", \$write_mode,
49 - "verbose", \$verbose,
50 - )) { die $usage; }
51 -die $usage unless ($read_mode xor $write_mode);
52 -
53 -my $topdir = `git rev-parse --show-cdup` or die "\n"; chomp $topdir;
54 -my $gitdir = $topdir . '.git';
55 -my $gitmeta = $topdir . '.gitmeta';
56 -
57 -if ($write_mode) {
58 - # Update the working dir permissions/ownership based on data from .gitmeta
59 - open (IN, "<$gitmeta") or die "Could not open $gitmeta for reading: $!\n";
60 - while (defined ($_ = <IN>)) {
61 - chomp;
62 - if (/^(.*) mode=(\S+)\s+uid=(\d+)\s+gid=(\d+)/) {
63 - # Compare recorded perms to actual perms in the working dir
64 - my ($path, $mode, $uid, $gid) = ($1, $2, $3, $4);
65 - my $fullpath = $topdir . $path;
66 - my (undef,undef,$wmode,undef,$wuid,$wgid) = lstat($fullpath);
67 - $wmode = sprintf "%04o", $wmode & 07777;
68 - if ($mode ne $wmode) {
69 - $verbose && print "Updating permissions on $path: old=$wmode, new=$mode\n";
70 - chmod oct($mode), $fullpath;
71 - }
72 - if ($uid != $wuid || $gid != $wgid) {
73 - if ($verbose) {
74 - # Print out user/group names instead of uid/gid
75 - my $pwname = getpwuid($uid);
76 - my $grpname = getgrgid($gid);
77 - my $wpwname = getpwuid($wuid);
78 - my $wgrpname = getgrgid($wgid);
79 - $pwname = $uid if !defined $pwname;
80 - $grpname = $gid if !defined $grpname;
81 - $wpwname = $wuid if !defined $wpwname;
82 - $wgrpname = $wgid if !defined $wgrpname;
83 -
84 - print "Updating uid/gid on $path: old=$wpwname/$wgrpname, new=$pwname/$grpname\n";
85 - }
86 - chown $uid, $gid, $fullpath;
87 - }
88 - }
89 - else {
90 - warn "Invalid input format in $gitmeta:\n\t$_\n";
91 - }
92 - }
93 - close IN;
94 -}
95 -elsif ($read_mode) {
96 - # Handle merge conflicts in the .gitperms file
97 - if (-e "$gitdir/MERGE_MSG") {
98 - if (`grep ====== $gitmeta`) {
99 - # Conflict not resolved -- abort the commit
100 - print "PERMISSIONS/OWNERSHIP CONFLICT\n";
101 - print " Resolve the conflict in the $gitmeta file and then run\n";
102 - print " `.git/hooks/setgitperms.perl --write` to reconcile.\n";
103 - exit 1;
104 - }
105 - elsif (`grep $gitmeta $gitdir/MERGE_MSG`) {
106 - # A conflict in .gitmeta has been manually resolved. Verify that
107 - # the working dir perms matches the current .gitmeta perms for
108 - # each file/dir that conflicted.
109 - # This is here because a `setgitperms.perl --write` was not
110 - # performed due to a merge conflict, so permissions/ownership
111 - # may not be consistent with the manually merged .gitmeta file.
112 - my @conflict_diff = `git show \$(cat $gitdir/MERGE_HEAD)`;
113 - my @conflict_files;
114 - my $metadiff = 0;
115 -
116 - # Build a list of files that conflicted from the .gitmeta diff
117 - foreach my $line (@conflict_diff) {
118 - if ($line =~ m|^diff --git a/$gitmeta b/$gitmeta|) {
119 - $metadiff = 1;
120 - }
121 - elsif ($line =~ /^diff --git/) {
122 - $metadiff = 0;
123 - }
124 - elsif ($metadiff && $line =~ /^\+(.*) mode=/) {
125 - push @conflict_files, $1;
126 - }
127 - }
128 -
129 - # Verify that each conflict file now has permissions consistent
130 - # with the .gitmeta file
131 - foreach my $file (@conflict_files) {
132 - my $absfile = $topdir . $file;
133 - my $gm_entry = `grep "^$file mode=" $gitmeta`;
134 - if ($gm_entry =~ /mode=(\d+) uid=(\d+) gid=(\d+)/) {
135 - my ($gm_mode, $gm_uid, $gm_gid) = ($1, $2, $3);
136 - my (undef,undef,$mode,undef,$uid,$gid) = lstat("$absfile");
137 - $mode = sprintf("%04o", $mode & 07777);
138 - if (($gm_mode ne $mode) || ($gm_uid != $uid)
139 - || ($gm_gid != $gid)) {
140 - print "PERMISSIONS/OWNERSHIP CONFLICT\n";
141 - print " Mismatch found for file: $file\n";
142 - print " Run `.git/hooks/setgitperms.perl --write` to reconcile.\n";
143 - exit 1;
144 - }
145 - }
146 - else {
147 - print "Warning! Permissions/ownership no longer being tracked for file: $file\n";
148 - }
149 - }
150 - }
151 - }
152 -
153 - # No merge conflicts -- write out perms/ownership data to .gitmeta file
154 - unless ($stdout) {
155 - open (OUT, ">$gitmeta.tmp") or die "Could not open $gitmeta.tmp for writing: $!\n";
156 - }
157 -
158 - my @files = `git ls-files`;
159 - my %dirs;
160 -
161 - foreach my $path (@files) {
162 - chomp $path;
163 - # We have to manually add stats for parent directories
164 - my $parent = dirname($path);
165 - while (!exists $dirs{$parent}) {
166 - $dirs{$parent} = 1;
167 - next if $parent eq '.';
168 - printstats($parent);
169 - $parent = dirname($parent);
170 - }
171 - # Now the git-tracked file
172 - printstats($path);
173 - }
174 -
175 - # diff the temporary metadata file to see if anything has changed
176 - # If no metadata has changed, don't overwrite the real file
177 - # This is just so `git commit -a` doesn't try to commit a bogus update
178 - unless ($stdout) {
179 - if (! -e $gitmeta) {
180 - rename "$gitmeta.tmp", $gitmeta;
181 - }
182 - else {
183 - my $diff = `diff -U 0 $gitmeta $gitmeta.tmp`;
184 - if ($diff ne '') {
185 - rename "$gitmeta.tmp", $gitmeta;
186 - }
187 - else {
188 - unlink "$gitmeta.tmp";
189 - }
190 - if ($showdiff) {
191 - print $diff;
192 - }
193 - }
194 - close OUT;
195 - }
196 - # Make sure the .gitmeta file is tracked
197 - system("git add $gitmeta");
198 -}
199 -
200 -
201 -sub printstats {
202 - my $path = $_[0];
203 - $path =~ s/@/\@/g;
204 - my (undef,undef,$mode,undef,$uid,$gid) = lstat($path);
205 - $path =~ s/%/\%/g;
206 - if ($stdout) {
207 - print $path;
208 - printf " mode=%04o uid=$uid gid=$gid\n", $mode & 07777;
209 - }
210 - else {
211 - print OUT $path;
212 - printf OUT " mode=%04o uid=$uid gid=$gid\n", $mode & 07777;
213 - }
214 -}
contrib/hooks/update-paranoid deleted
-421
@@ -1,421 +0,0 @@
1 -#!/usr/bin/perl
2 -
3 -use strict;
4 -use File::Spec;
5 -
6 -$ENV{PATH} = '/opt/git/bin';
7 -my $acl_git = '/vcs/acls.git';
8 -my $acl_branch = 'refs/heads/master';
9 -my $debug = 0;
10 -
11 -=doc
12 -Invoked as: update refname old-sha1 new-sha1
13 -
14 -This script is run by git-receive-pack once for each ref that the
15 -client is trying to modify. If we exit with a non-zero exit value
16 -then the update for that particular ref is denied, but updates for
17 -other refs in the same run of receive-pack may still be allowed.
18 -
19 -We are run after the objects have been uploaded, but before the
20 -ref is actually modified. We take advantage of that fact when we
21 -look for "new" commits and tags (the new objects won't show up in
22 -`rev-list --all`).
23 -
24 -This script loads and parses the content of the config file
25 -"users/$this_user.acl" from the $acl_branch commit of $acl_git ODB.
26 -The acl file is a git-config style file, but uses a slightly more
27 -restricted syntax as the Perl parser contained within this script
28 -is not nearly as permissive as git-config.
29 -
30 -Example:
31 -
32 - [user]
33 - committer = John Doe <john.doe@example.com>
34 - committer = John R. Doe <john.doe@example.com>
35 -
36 - [repository "acls"]
37 - allow = heads/master
38 - allow = CDUR for heads/jd/
39 - allow = C for ^tags/v\\d+$
40 -
41 -For all new commit or tag objects the committer (or tagger) line
42 -within the object must exactly match one of the user.committer
43 -values listed in the acl file ("HEAD:users/$this_user.acl").
44 -
45 -For a branch to be modified an allow line within the matching
46 -repository section must be matched for both the refname and the
47 -opcode.
48 -
49 -Repository sections are matched on the basename of the repository
50 -(after removing the .git suffix).
51 -
52 -The opcode abbreviations are:
53 -
54 - C: create new ref
55 - D: delete existing ref
56 - U: fast-forward existing ref (no commit loss)
57 - R: rewind/rebase existing ref (commit loss)
58 -
59 -if no opcodes are listed before the "for" keyword then "U" (for
60 -fast-forward update only) is assumed as this is the most common
61 -usage.
62 -
63 -Refnames are matched by always assuming a prefix of "refs/".
64 -This hook forbids pushing or deleting anything not under "refs/".
65 -
66 -Refnames that start with ^ are Perl regular expressions, and the ^
67 -is kept as part of the regexp. \\ is needed to get just one \, so
68 -\\d expands to \d in Perl. The 3rd allow line above is an example.
69 -
70 -Refnames that don't start with ^ but that end with / are prefix
71 -matches (2nd allow line above); all other refnames are strict
72 -equality matches (1st allow line).
73 -
74 -Anything pushed to "heads/" (ok, really "refs/heads/") must be
75 -a commit. Tags are not permitted here.
76 -
77 -Anything pushed to "tags/" (err, really "refs/tags/") must be an
78 -annotated tag. Commits, blobs, trees, etc. are not permitted here.
79 -Annotated tag signatures aren't checked, nor are they required.
80 -
81 -The special subrepository of 'info/new-commit-check' can
82 -be created and used to allow users to push new commits and
83 -tags from another local repository to this one, even if they
84 -aren't the committer/tagger of those objects. In a nut shell
85 -the info/new-commit-check directory is a Git repository whose
86 -objects/info/alternates file lists this repository and all other
87 -possible sources, and whose refs subdirectory contains symlinks
88 -to this repository's refs subdirectory, and to all other possible
89 -sources refs subdirectories. Yes, this means that you cannot
90 -use packed-refs in those repositories as they won't be resolved
91 -correctly.
92 -
93 -=cut
94 -
95 -my $git_dir = $ENV{GIT_DIR};
96 -my $new_commit_check = "$git_dir/info/new-commit-check";
97 -my $ref = $ARGV[0];
98 -my $old = $ARGV[1];
99 -my $new = $ARGV[2];
100 -my $new_type;
101 -my ($this_user) = getpwuid $<; # REAL_USER_ID
102 -my $repository_name;
103 -my %user_committer;
104 -my @allow_rules;
105 -my @path_rules;
106 -my %diff_cache;
107 -
108 -sub deny ($) {
109 - print STDERR "-Deny- $_[0]\n" if $debug;
110 - print STDERR "\ndenied: $_[0]\n\n";
111 - exit 1;
112 -}
113 -
114 -sub grant ($) {
115 - print STDERR "-Grant- $_[0]\n" if $debug;
116 - exit 0;
117 -}
118 -
119 -sub info ($) {
120 - print STDERR "-Info- $_[0]\n" if $debug;
121 -}
122 -
123 -sub git_value (@) {
124 - open(T,'-|','git',@_); local $_ = <T>; chop; close T; $_;
125 -}
126 -
127 -sub match_string ($$) {
128 - my ($acl_n, $ref) = @_;
129 - ($acl_n eq $ref)
130 - || ($acl_n =~ m,/$, && substr($ref,0,length $acl_n) eq $acl_n)
131 - || ($acl_n =~ m,^\^, && $ref =~ m:$acl_n:);
132 -}
133 -
134 -sub parse_config ($$$$) {
135 - my $data = shift;
136 - local $ENV{GIT_DIR} = shift;
137 - my $br = shift;
138 - my $fn = shift;
139 - return unless git_value('rev-list','--max-count=1',$br,'--',$fn);
140 - info "Loading $br:$fn";
141 - open(I,'-|','git','cat-file','blob',"$br:$fn");
142 - my $section = '';
143 - while (<I>) {
144 - chomp;
145 - if (/^\s*$/ || /^\s*#/) {
146 - } elsif (/^\[([a-z]+)\]$/i) {
147 - $section = lc $1;
148 - } elsif (/^\[([a-z]+)\s+"(.*)"\]$/i) {
149 - $section = join('.',lc $1,$2);
150 - } elsif (/^\s*([a-z][a-z0-9]+)\s*=\s*(.*?)\s*$/i) {
151 - push @{$data->{join('.',$section,lc $1)}}, $2;
152 - } else {
153 - deny "bad config file line $. in $br:$fn";
154 - }
155 - }
156 - close I;
157 -}
158 -
159 -sub all_new_committers () {
160 - local $ENV{GIT_DIR} = $git_dir;
161 - $ENV{GIT_DIR} = $new_commit_check if -d $new_commit_check;
162 -
163 - info "Getting committers of new commits.";
164 - my %used;
165 - open(T,'-|','git','rev-list','--pretty=raw',$new,'--not','--all');
166 - while (<T>) {
167 - next unless s/^committer //;
168 - chop;
169 - s/>.*$/>/;
170 - info "Found $_." unless $used{$_}++;
171 - }
172 - close T;
173 - info "No new commits." unless %used;
174 - keys %used;
175 -}
176 -
177 -sub all_new_taggers () {
178 - my %exists;
179 - open(T,'-|','git','for-each-ref','--format=%(objectname)','refs/tags');
180 - while (<T>) {
181 - chop;
182 - $exists{$_} = 1;
183 - }
184 - close T;
185 -
186 - info "Getting taggers of new tags.";
187 - my %used;
188 - my $obj = $new;
189 - my $obj_type = $new_type;
190 - while ($obj_type eq 'tag') {
191 - last if $exists{$obj};
192 - $obj_type = '';
193 - open(T,'-|','git','cat-file','tag',$obj);
194 - while (<T>) {
195 - chop;
196 - if (/^object ([a-z0-9]{40})$/) {
197 - $obj = $1;
198 - } elsif (/^type (.+)$/) {
199 - $obj_type = $1;
200 - } elsif (s/^tagger //) {
201 - s/>.*$/>/;
202 - info "Found $_." unless $used{$_}++;
203 - last;
204 - }
205 - }
206 - close T;
207 - }
208 - info "No new tags." unless %used;
209 - keys %used;
210 -}
211 -
212 -sub check_committers (@) {
213 - my @bad;
214 - foreach (@_) { push @bad, $_ unless $user_committer{$_}; }
215 - if (@bad) {
216 - print STDERR "\n";
217 - print STDERR "You are not $_.\n" foreach (sort @bad);
218 - deny "You cannot push changes not committed by you.";
219 - }
220 -}
221 -
222 -sub load_diff ($) {
223 - my $base = shift;
224 - my $d = $diff_cache{$base};
225 - unless ($d) {
226 - local $/ = "\0";
227 - my %this_diff;
228 - if ($base =~ /^0{40}$/) {
229 - # Don't load the diff at all; we are making the
230 - # branch and have no base to compare to in this
231 - # case. A file level ACL makes no sense in this
232 - # context. Having an empty diff will allow the
233 - # branch creation.
234 - #
235 - } else {
236 - open(T,'-|','git','diff-tree',
237 - '-r','--name-status','-z',
238 - $base,$new) or return undef;
239 - while (<T>) {
240 - my $op = $_;
241 - chop $op;
242 -
243 - my $path = <T>;
244 - chop $path;
245 -
246 - $this_diff{$path} = $op;
247 - }
248 - close T or return undef;
249 - }
250 - $d = \%this_diff;
251 - $diff_cache{$base} = $d;
252 - }
253 - return $d;
254 -}
255 -
256 -deny "No GIT_DIR inherited from caller" unless $git_dir;
257 -deny "Need a ref name" unless $ref;
258 -deny "Refusing funny ref $ref" unless $ref =~ s,^refs/,,;
259 -deny "Bad old value $old" unless $old =~ /^[a-z0-9]{40}$/;
260 -deny "Bad new value $new" unless $new =~ /^[a-z0-9]{40}$/;
261 -deny "Cannot determine who you are." unless $this_user;
262 -grant "No change requested." if $old eq $new;
263 -
264 -$repository_name = File::Spec->rel2abs($git_dir);
265 -$repository_name =~ m,/([^/]+)(?:\.git|/\.git)$,;
266 -$repository_name = $1;
267 -info "Updating in '$repository_name'.";
268 -
269 -my $op;
270 -if ($old =~ /^0{40}$/) { $op = 'C'; }
271 -elsif ($new =~ /^0{40}$/) { $op = 'D'; }
272 -else { $op = 'R'; }
273 -
274 -# This is really an update (fast-forward) if the
275 -# merge base of $old and $new is $old.
276 -#
277 -$op = 'U' if ($op eq 'R'
278 - && $ref =~ m,^heads/,
279 - && $old eq git_value('merge-base',$old,$new));
280 -
281 -# Load the user's ACL file. Expand groups (user.memberof) one level.
282 -{
283 - my %data = ('user.committer' => []);
284 - parse_config(\%data,$acl_git,$acl_branch,"external/$repository_name.acl");
285 -
286 - %data = (
287 - 'user.committer' => $data{'user.committer'},
288 - 'user.memberof' => [],
289 - );
290 - parse_config(\%data,$acl_git,$acl_branch,"users/$this_user.acl");
291 -
292 - %user_committer = map {$_ => $_} @{$data{'user.committer'}};
293 - my $rule_key = "repository.$repository_name.allow";
294 - my $rules = $data{$rule_key} || [];
295 -
296 - foreach my $group (@{$data{'user.memberof'}}) {
297 - my %g;
298 - parse_config(\%g,$acl_git,$acl_branch,"groups/$group.acl");
299 - my $group_rules = $g{$rule_key};
300 - push @$rules, @$group_rules if $group_rules;
301 - }
302 -
303 -RULE:
304 - foreach (@$rules) {
305 - while (/\${user\.([a-z][a-zA-Z0-9]+)}/) {
306 - my $k = lc $1;
307 - my $v = $data{"user.$k"};
308 - next RULE unless defined $v;
309 - next RULE if @$v != 1;
310 - next RULE unless defined $v->[0];
311 - s/\${user\.$k}/$v->[0]/g;
312 - }
313 -
314 - if (/^([AMD ]+)\s+of\s+([^\s]+)\s+for\s+([^\s]+)\s+diff\s+([^\s]+)$/) {
315 - my ($ops, $pth, $ref, $bst) = ($1, $2, $3, $4);
316 - $ops =~ s/ //g;
317 - $pth =~ s/\\\\/\\/g;
318 - $ref =~ s/\\\\/\\/g;
319 - push @path_rules, [$ops, $pth, $ref, $bst];
320 - } elsif (/^([AMD ]+)\s+of\s+([^\s]+)\s+for\s+([^\s]+)$/) {
321 - my ($ops, $pth, $ref) = ($1, $2, $3);
322 - $ops =~ s/ //g;
323 - $pth =~ s/\\\\/\\/g;
324 - $ref =~ s/\\\\/\\/g;
325 - push @path_rules, [$ops, $pth, $ref, $old];
326 - } elsif (/^([CDRU ]+)\s+for\s+([^\s]+)$/) {
327 - my $ops = $1;
328 - my $ref = $2;
329 - $ops =~ s/ //g;
330 - $ref =~ s/\\\\/\\/g;
331 - push @allow_rules, [$ops, $ref];
332 - } elsif (/^for\s+([^\s]+)$/) {
333 - # Mentioned, but nothing granted?
334 - } elsif (/^[^\s]+$/) {
335 - s/\\\\/\\/g;
336 - push @allow_rules, ['U', $_];
337 - }
338 - }
339 -}
340 -
341 -if ($op ne 'D') {
342 - $new_type = git_value('cat-file','-t',$new);
343 -
344 - if ($ref =~ m,^heads/,) {
345 - deny "$ref must be a commit." unless $new_type eq 'commit';
346 - } elsif ($ref =~ m,^tags/,) {
347 - deny "$ref must be an annotated tag." unless $new_type eq 'tag';
348 - }
349 -
350 - check_committers (all_new_committers);
351 - check_committers (all_new_taggers) if $new_type eq 'tag';
352 -}
353 -
354 -info "$this_user wants $op for $ref";
355 -foreach my $acl_entry (@allow_rules) {
356 - my ($acl_ops, $acl_n) = @$acl_entry;
357 - next unless $acl_ops =~ /^[CDRU]+$/; # Uhh.... shouldn't happen.
358 - next unless $acl_n;
359 - next unless $op =~ /^[$acl_ops]$/;
360 - next unless match_string $acl_n, $ref;
361 -
362 - # Don't test path rules on branch deletes.
363 - #
364 - grant "Allowed by: $acl_ops for $acl_n" if $op eq 'D';
365 -
366 - # Aggregate matching path rules; allow if there aren't
367 - # any matching this ref.
368 - #
369 - my %pr;
370 - foreach my $p_entry (@path_rules) {
371 - my ($p_ops, $p_n, $p_ref, $p_bst) = @$p_entry;
372 - next unless $p_ref;
373 - push @{$pr{$p_bst}}, $p_entry if match_string $p_ref, $ref;
374 - }
375 - grant "Allowed by: $acl_ops for $acl_n" unless %pr;
376 -
377 - # Allow only if all changes against a single base are
378 - # allowed by file path rules.
379 - #
380 - my @bad;
381 - foreach my $p_bst (keys %pr) {
382 - my $diff_ref = load_diff $p_bst;
383 - deny "Cannot difference trees." unless ref $diff_ref;
384 -
385 - my %fd = %$diff_ref;
386 - foreach my $p_entry (@{$pr{$p_bst}}) {
387 - my ($p_ops, $p_n, $p_ref, $p_bst) = @$p_entry;
388 - next unless $p_ops =~ /^[AMD]+$/;
389 - next unless $p_n;
390 -
391 - foreach my $f_n (keys %fd) {
392 - my $f_op = $fd{$f_n};
393 - next unless $f_op;
394 - next unless $f_op =~ /^[$p_ops]$/;
395 - delete $fd{$f_n} if match_string $p_n, $f_n;
396 - }
397 - last unless %fd;
398 - }
399 -
400 - if (%fd) {
401 - push @bad, [$p_bst, \%fd];
402 - } else {
403 - # All changes relative to $p_bst were allowed.
404 - #
405 - grant "Allowed by: $acl_ops for $acl_n diff $p_bst";
406 - }
407 - }
408 -
409 - foreach my $bad_ref (@bad) {
410 - my ($p_bst, $fd) = @$bad_ref;
411 - print STDERR "\n";
412 - print STDERR "Not allowed to make the following changes:\n";
413 - print STDERR "(base: $p_bst)\n";
414 - foreach my $f_n (sort keys %$fd) {
415 - print STDERR " $fd->{$f_n} $f_n\n";
416 - }
417 - }
418 - deny "You are not permitted to $op $ref";
419 -}
420 -close A;
421 -deny "You are not permitted to $op $ref";