Yuxuan 'fishy' Wang | 61698b1 | 2013-12-20 12:55:51 -0800 | [diff] [blame] | 1 | = Gerrit Code Review - Uploading Changes |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 2 | |
Shawn O. Pearce | 518fe3f | 2009-08-22 15:40:58 -0700 | [diff] [blame] | 3 | Gerrit supports three methods of uploading changes: |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 4 | |
| 5 | * Use `repo upload`, to create changes for review |
| 6 | * Use `git push`, to create changes for review |
| 7 | * Use `git push`, and bypass code review |
| 8 | |
David Pursehouse | baac425 | 2013-01-25 17:42:19 +0900 | [diff] [blame] | 9 | All three methods rely on authentication, which must first be configured |
| 10 | by the uploading user. |
| 11 | |
| 12 | Gerrit supports two methods of authenticating the uploading user. SSH |
| 13 | public key, and HTTP/HTTPS. |
| 14 | |
Edwin Kempin | 60ab853 | 2013-03-27 14:33:46 +0100 | [diff] [blame] | 15 | [[http]] |
Yuxuan 'fishy' Wang | 61698b1 | 2013-12-20 12:55:51 -0800 | [diff] [blame] | 16 | == HTTP/HTTPS |
David Pursehouse | baac425 | 2013-01-25 17:42:19 +0900 | [diff] [blame] | 17 | |
| 18 | On Gerrit installations that do not support SSH authentication, the |
| 19 | user must authenticate via HTTP/HTTPS. |
| 20 | |
Han-Wen Nienhuys | 84d830b | 2017-02-15 16:36:04 +0100 | [diff] [blame] | 21 | The user is authenticated using standard BasicAuth. Depending on the |
| 22 | value of link:#auth.gitBasicAuthPolicy[auth.gitBasicAuthPolicy], |
| 23 | credentials are validated using: |
David Pursehouse | baac425 | 2013-01-25 17:42:19 +0900 | [diff] [blame] | 24 | |
Hector Oswaldo Caballero | 2a9ad1f | 2016-09-15 18:24:42 -0400 | [diff] [blame] | 25 | * The randomly generated HTTP password on the `HTTP Password` tab |
| 26 | in the user settings page if `gitBasicAuthPolicy` is `HTTP`. |
| 27 | * The LDAP password if `gitBasicAuthPolicy` is `LDAP` |
| 28 | * Both, the HTTP and the LDAP passwords (in this order) if `gitBasicAuthPolicy` |
| 29 | is `HTTP_LDAP`. |
| 30 | |
Han-Wen Nienhuys | 84d830b | 2017-02-15 16:36:04 +0100 | [diff] [blame] | 31 | When gitBasicAuthPolicy is not `LDAP`, the user's HTTP credentials can |
| 32 | be regenerated by going to `Settings`, and then accessing the `HTTP |
| 33 | Password` tab. Revocation can effectively be done by regenerating the |
| 34 | password and then forgetting it. |
David Pursehouse | baac425 | 2013-01-25 17:42:19 +0900 | [diff] [blame] | 35 | |
| 36 | For Gerrit installations where an link:config-gerrit.html#auth.httpPasswordUrl[HTTP password URL] |
| 37 | is configured, the password can be obtained by clicking on `Obtain Password` |
| 38 | and then following the site-specific instructions. On sites where this URL is |
| 39 | not configured, the password can be obtained by clicking on `Generate Password`. |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 40 | |
Edwin Kempin | 1f55622 | 2015-04-22 13:24:39 +0200 | [diff] [blame] | 41 | [[ssh]] |
Yuxuan 'fishy' Wang | 61698b1 | 2013-12-20 12:55:51 -0800 | [diff] [blame] | 42 | == SSH |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 43 | |
Shawn O. Pearce | 518fe3f | 2009-08-22 15:40:58 -0700 | [diff] [blame] | 44 | Each user uploading changes to Gerrit must configure one or more SSH |
| 45 | public keys. The per-user SSH key list can be accessed over the web |
Edwin Kempin | b5df3b8 | 2011-10-10 11:31:14 +0200 | [diff] [blame] | 46 | within Gerrit by `Settings`, and then accessing the `SSH Public Keys` |
| 47 | tab. |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 48 | |
Shawn O. Pearce | 518fe3f | 2009-08-22 15:40:58 -0700 | [diff] [blame] | 49 | [[configure_ssh]] |
Yuxuan 'fishy' Wang | 61698b1 | 2013-12-20 12:55:51 -0800 | [diff] [blame] | 50 | === Configuration |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 51 | |
Shawn O. Pearce | 518fe3f | 2009-08-22 15:40:58 -0700 | [diff] [blame] | 52 | To register a new SSH key for use with Gerrit, paste the contents of |
| 53 | your `id_rsa.pub` or `id_dsa.pub` file into the text box and click |
| 54 | the add button. Gerrit only understands SSH version 2 public keys. |
| 55 | Keys may be supplied in either the OpenSSH format (key starts with |
| 56 | `ssh-rsa` or `ssh-dss`) or the RFC 4716 format (file starts with |
| 57 | `---- BEGIN SSH2 PUBLIC KEY ----`). |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 58 | |
Shawn O. Pearce | 518fe3f | 2009-08-22 15:40:58 -0700 | [diff] [blame] | 59 | Typically SSH keys are stored in your home directory, under `~/.ssh`. |
| 60 | If you don't have any keys yet, you can create a new one and protect |
| 61 | it with a passphrase: |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 62 | |
Michael Ochmann | b99feab | 2016-07-06 14:10:22 +0200 | [diff] [blame] | 63 | ---- |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 64 | ssh-keygen -t rsa |
Michael Ochmann | b99feab | 2016-07-06 14:10:22 +0200 | [diff] [blame] | 65 | ---- |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 66 | |
| 67 | Then copy the content of the public key file onto your clipboard, |
| 68 | and paste it into Gerrit's web interface: |
| 69 | |
Michael Ochmann | b99feab | 2016-07-06 14:10:22 +0200 | [diff] [blame] | 70 | ---- |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 71 | cat ~/.ssh/id_rsa.pub |
Michael Ochmann | b99feab | 2016-07-06 14:10:22 +0200 | [diff] [blame] | 72 | ---- |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 73 | |
| 74 | [TIP] |
Shawn O. Pearce | 518fe3f | 2009-08-22 15:40:58 -0700 | [diff] [blame] | 75 | Users who frequently upload changes will also want to consider |
David Pursehouse | 221d4f6 | 2012-06-08 17:38:08 +0900 | [diff] [blame] | 76 | starting an `ssh-agent`, and adding their private key to the list |
Shawn O. Pearce | 518fe3f | 2009-08-22 15:40:58 -0700 | [diff] [blame] | 77 | managed by the agent, to reduce the frequency of entering the |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 78 | key's passphrase. Consult `man ssh-agent`, or your SSH client's |
| 79 | documentation, for more details on configuration of the agent |
| 80 | process and how to add the private key. |
| 81 | |
Shawn O. Pearce | 518fe3f | 2009-08-22 15:40:58 -0700 | [diff] [blame] | 82 | [[test_ssh]] |
Yuxuan 'fishy' Wang | 61698b1 | 2013-12-20 12:55:51 -0800 | [diff] [blame] | 83 | === Testing Connections |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 84 | |
| 85 | To verify your SSH key is working correctly, try using an SSH client |
David Pursehouse | 221d4f6 | 2012-06-08 17:38:08 +0900 | [diff] [blame] | 86 | to connect to Gerrit's SSHD port. By default Gerrit runs on |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 87 | port 29418, using the same hostname as the web server: |
| 88 | |
Michael Ochmann | b99feab | 2016-07-06 14:10:22 +0200 | [diff] [blame] | 89 | ---- |
Hugo Arès | 93ef427 | 2016-03-01 21:50:41 -0500 | [diff] [blame] | 90 | $ ssh -p 29418 sshusername@hostname |
Edwin Kempin | fb95a1b | 2011-10-05 10:08:00 +0200 | [diff] [blame] | 91 | |
| 92 | **** Welcome to Gerrit Code Review **** |
| 93 | |
| 94 | Hi John Doe, you have successfully connected over SSH. |
| 95 | |
| 96 | Unfortunately, interactive shells are disabled. |
| 97 | To clone a hosted Git repository, use: |
| 98 | |
| 99 | git clone ssh://sshusername@hostname:29418/REPOSITORY_NAME.git |
| 100 | |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 101 | Connection to hostname closed. |
Michael Ochmann | b99feab | 2016-07-06 14:10:22 +0200 | [diff] [blame] | 102 | ---- |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 103 | |
Edwin Kempin | fb95a1b | 2011-10-05 10:08:00 +0200 | [diff] [blame] | 104 | In the command above, `sshusername` was configured as `Username` on |
| 105 | the `Profile` tab of the `Settings` screen. If it is not set, |
| 106 | propose a name and use `Select Username` to select the name. |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 107 | |
| 108 | To determine the port number Gerrit is running on, visit the special |
| 109 | information URL `http://'hostname'/ssh_info`, and copy the port |
| 110 | number from the second field: |
| 111 | |
Michael Ochmann | b99feab | 2016-07-06 14:10:22 +0200 | [diff] [blame] | 112 | ---- |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 113 | $ curl http://hostname/ssh_info |
| 114 | hostname 29418 |
Michael Ochmann | b99feab | 2016-07-06 14:10:22 +0200 | [diff] [blame] | 115 | ---- |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 116 | |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 117 | If you are developing an automated tool to perform uploads to Gerrit, |
| 118 | let the user supply the hostname or the web address for Gerrit, |
| 119 | and obtain the port number on the fly from the `/ssh_info` URL. |
| 120 | The returned output from this URL is always `'hostname' SP 'port'`, |
Shawn O. Pearce | 518fe3f | 2009-08-22 15:40:58 -0700 | [diff] [blame] | 121 | or `NOT_AVAILABLE` if the SSHD server is not currently running. |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 122 | |
| 123 | |
Yuxuan 'fishy' Wang | 61698b1 | 2013-12-20 12:55:51 -0800 | [diff] [blame] | 124 | == git push |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 125 | |
Shawn O. Pearce | 518fe3f | 2009-08-22 15:40:58 -0700 | [diff] [blame] | 126 | [[push_create]] |
Yuxuan 'fishy' Wang | 61698b1 | 2013-12-20 12:55:51 -0800 | [diff] [blame] | 127 | === Create Changes |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 128 | |
David Pursehouse | 221d4f6 | 2012-06-08 17:38:08 +0900 | [diff] [blame] | 129 | To create new changes for review, simply push to the project's |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 130 | magical `refs/for/'branch'` ref using any Git client tool: |
| 131 | |
Michael Ochmann | b99feab | 2016-07-06 14:10:22 +0200 | [diff] [blame] | 132 | ---- |
Shawn Pearce | 69928a6 | 2013-02-24 18:01:27 -0800 | [diff] [blame] | 133 | git push ssh://sshusername@hostname:29418/projectname HEAD:refs/for/branch |
Michael Ochmann | b99feab | 2016-07-06 14:10:22 +0200 | [diff] [blame] | 134 | ---- |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 135 | |
| 136 | E.g. `john.doe` can use git push to upload new changes for the |
| 137 | `experimental` branch of project `kernel/common`, hosted at the |
| 138 | `git.example.com` Gerrit server: |
| 139 | |
Michael Ochmann | b99feab | 2016-07-06 14:10:22 +0200 | [diff] [blame] | 140 | ---- |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 141 | git push ssh://john.doe@git.example.com:29418/kernel/common HEAD:refs/for/experimental |
Michael Ochmann | b99feab | 2016-07-06 14:10:22 +0200 | [diff] [blame] | 142 | ---- |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 143 | |
| 144 | Each new commit uploaded by the `git push` client will be |
| 145 | converted into a change record on the server. The remote ref |
| 146 | `refs/for/experimental` is not actually created by Gerrit, even |
| 147 | though the client's status messages may say otherwise. |
| 148 | |
| 149 | Other users (e.g. project owners) who have configured Gerrit to |
| 150 | notify them of new changes will be automatically sent an email |
| 151 | message when the push is completed. |
| 152 | |
David Pursehouse | 06eb3eb | 2016-09-01 11:04:03 +0900 | [diff] [blame] | 153 | [[push_options]] |
| 154 | === Push Options |
| 155 | |
| 156 | Additional options may be specified when pushing changes. |
| 157 | |
Edwin Kempin | 9e078d8 | 2016-01-29 10:56:07 +0100 | [diff] [blame] | 158 | [[notify]] |
David Pursehouse | 06eb3eb | 2016-09-01 11:04:03 +0900 | [diff] [blame] | 159 | ==== Email Notifications |
Edwin Kempin | 9e078d8 | 2016-01-29 10:56:07 +0100 | [diff] [blame] | 160 | |
| 161 | Uploaders can control to whom email notifications are sent by setting |
| 162 | the `notify` option: |
| 163 | |
| 164 | * `NONE`: No email notification will be sent to anyone. |
| 165 | * `OWNER`: Only the change owner is notified. |
| 166 | * `OWNER_REVIEWERS`: Only owners and reviewers will be notified. This |
| 167 | includes all reviewers, existing reviewers of the change and new |
| 168 | reviewers that are added by the `reviewer` option or by mentioning |
| 169 | in the commit message. |
| 170 | * `ALL`: All email notifications will be sent. This includes |
| 171 | notifications to watchers, users that have starred the change, CCs |
| 172 | and the committer and author of the uploaded commit. |
| 173 | |
| 174 | By default all email notifications are sent. |
| 175 | |
Michael Ochmann | b99feab | 2016-07-06 14:10:22 +0200 | [diff] [blame] | 176 | ---- |
Edwin Kempin | 9e078d8 | 2016-01-29 10:56:07 +0100 | [diff] [blame] | 177 | git push ssh://bot@git.example.com:29418/kernel/common HEAD:refs/for/master%notify=NONE |
Michael Ochmann | b99feab | 2016-07-06 14:10:22 +0200 | [diff] [blame] | 178 | ---- |
Edwin Kempin | 9e078d8 | 2016-01-29 10:56:07 +0100 | [diff] [blame] | 179 | |
Edwin Kempin | cd07df4 | 2016-12-01 09:10:09 +0100 | [diff] [blame] | 180 | In addition uploaders can explicitly specify accounts that should be |
| 181 | notified, regardless of the value that is given for the `notify` |
| 182 | option. To notify a specific account specify it by an |
| 183 | `notify-to='email'`, `notify-cc='email'` or `notify-bcc='email'` |
| 184 | option. These options can be specified as many times as necessary to |
| 185 | cover all interested parties. Gerrit will automatically avoid sending |
| 186 | duplicate email notifications, such as if one of the specified accounts |
| 187 | had also requested to receive all new change notifications. The |
| 188 | accounts that are specified by `notify-to='email'`, `notify-cc='email'` |
| 189 | and `notify-bcc='email'` will only be notified about this one push. |
| 190 | They are not added as link:#reviewers[reviewers or CCs], hence they are |
| 191 | not automatically signed up to be notified on further updates of the |
| 192 | change. |
| 193 | |
| 194 | ---- |
| 195 | git push ssh://bot@git.example.com:29418/kernel/common HEAD:refs/for/master%notify=NONE,notify-to=a@a.com |
| 196 | ---- |
| 197 | |
Edwin Kempin | 1f55622 | 2015-04-22 13:24:39 +0200 | [diff] [blame] | 198 | [[topic]] |
David Pursehouse | 06eb3eb | 2016-09-01 11:04:03 +0900 | [diff] [blame] | 199 | ==== Topic |
| 200 | |
Shawn O. Pearce | d50c94e | 2010-07-15 12:24:11 -0700 | [diff] [blame] | 201 | To include a short tag associated with all of the changes in the |
| 202 | same group, such as the local topic branch name, append it after |
Dan Wang | 17ced40 | 2016-08-26 16:42:49 -0700 | [diff] [blame] | 203 | the destination branch name or add it with the command line flag |
| 204 | `--push-option`, aliased to `-o`. In this example the short topic |
| 205 | tag 'driver/i42' will be saved on each change this push creates or |
Shawn O. Pearce | d50c94e | 2010-07-15 12:24:11 -0700 | [diff] [blame] | 206 | updates: |
| 207 | |
Michael Ochmann | b99feab | 2016-07-06 14:10:22 +0200 | [diff] [blame] | 208 | ---- |
Shawn Pearce | 69928a6 | 2013-02-24 18:01:27 -0800 | [diff] [blame] | 209 | git push ssh://john.doe@git.example.com:29418/kernel/common HEAD:refs/for/experimental%topic=driver/i42 |
Dan Wang | 17ced40 | 2016-08-26 16:42:49 -0700 | [diff] [blame] | 210 | |
| 211 | // this is the same as: |
| 212 | git push ssh://john.doe@git.example.com:29418/kernel/common HEAD:refs/for/experimental -o topic=driver/i42 |
Michael Ochmann | b99feab | 2016-07-06 14:10:22 +0200 | [diff] [blame] | 213 | ---- |
Shawn O. Pearce | d50c94e | 2010-07-15 12:24:11 -0700 | [diff] [blame] | 214 | |
Khai Do | 50eb94e | 2016-03-30 16:50:13 -0700 | [diff] [blame] | 215 | [[message]] |
David Pursehouse | 06eb3eb | 2016-09-01 11:04:03 +0900 | [diff] [blame] | 216 | ==== Message |
| 217 | |
Khai Do | 50eb94e | 2016-03-30 16:50:13 -0700 | [diff] [blame] | 218 | A comment message can be applied to the change by using the `message` (or `m`) |
| 219 | option: |
| 220 | |
Michael Ochmann | b99feab | 2016-07-06 14:10:22 +0200 | [diff] [blame] | 221 | ---- |
Khai Do | 50eb94e | 2016-03-30 16:50:13 -0700 | [diff] [blame] | 222 | git push ssh://john.doe@git.example.com:29418/kernel/common HEAD:refs/for/experimental%m=This_is_a_rebase_on_master |
Michael Ochmann | b99feab | 2016-07-06 14:10:22 +0200 | [diff] [blame] | 223 | ---- |
Khai Do | 50eb94e | 2016-03-30 16:50:13 -0700 | [diff] [blame] | 224 | |
Michael Ochmann | 8129ece | 2016-07-08 11:25:25 +0200 | [diff] [blame] | 225 | [NOTE] |
Khai Do | 50eb94e | 2016-03-30 16:50:13 -0700 | [diff] [blame] | 226 | git push refs parameter does not allow spaces. Use the '_' character instead, |
| 227 | it will then be applied as "This is a rebase on master". |
Khai Do | 50eb94e | 2016-03-30 16:50:13 -0700 | [diff] [blame] | 228 | |
Gustaf Lundh | 4819171 | 2014-10-03 10:29:59 +0200 | [diff] [blame] | 229 | [[review_labels]] |
David Pursehouse | 06eb3eb | 2016-09-01 11:04:03 +0900 | [diff] [blame] | 230 | ==== Review Labels |
| 231 | |
David Pursehouse | 93733b6 | 2014-10-03 12:26:04 +0900 | [diff] [blame] | 232 | Review labels can be applied to the change by using the `label` (or `l`) |
| 233 | option in the reference: |
Gustaf Lundh | e235a06 | 2014-10-03 10:29:59 +0200 | [diff] [blame] | 234 | |
Michael Ochmann | b99feab | 2016-07-06 14:10:22 +0200 | [diff] [blame] | 235 | ---- |
Gustaf Lundh | e235a06 | 2014-10-03 10:29:59 +0200 | [diff] [blame] | 236 | git push ssh://john.doe@git.example.com:29418/kernel/common HEAD:refs/for/experimental%l=Verified+1 |
Michael Ochmann | b99feab | 2016-07-06 14:10:22 +0200 | [diff] [blame] | 237 | ---- |
Gustaf Lundh | e235a06 | 2014-10-03 10:29:59 +0200 | [diff] [blame] | 238 | |
| 239 | The `l='label[score]'` option may be specified more than once to |
| 240 | apply multiple review labels. |
| 241 | |
Michael Ochmann | b99feab | 2016-07-06 14:10:22 +0200 | [diff] [blame] | 242 | ---- |
Khai Do | 4bea1c6 | 2016-02-08 10:02:49 -0800 | [diff] [blame] | 243 | git push ssh://john.doe@git.example.com:29418/kernel/common HEAD:refs/for/experimental%l=Code-Review+1,l=Verified+1 |
Michael Ochmann | b99feab | 2016-07-06 14:10:22 +0200 | [diff] [blame] | 244 | ---- |
Khai Do | 4bea1c6 | 2016-02-08 10:02:49 -0800 | [diff] [blame] | 245 | |
Gustaf Lundh | e235a06 | 2014-10-03 10:29:59 +0200 | [diff] [blame] | 246 | The value is optional. If not specified, it defaults to +1 (if |
| 247 | the label range allows it). |
| 248 | |
David Ostrovsky | d07bb339 | 2015-01-19 07:43:44 +0100 | [diff] [blame] | 249 | [[change_edit]] |
David Pursehouse | 06eb3eb | 2016-09-01 11:04:03 +0900 | [diff] [blame] | 250 | ==== Change Edits |
| 251 | |
David Ostrovsky | d07bb339 | 2015-01-19 07:43:44 +0100 | [diff] [blame] | 252 | A change edit can be pushed by specifying the `edit` (or `e`) option on |
| 253 | the reference: |
| 254 | |
Michael Ochmann | b99feab | 2016-07-06 14:10:22 +0200 | [diff] [blame] | 255 | ---- |
David Ostrovsky | d07bb339 | 2015-01-19 07:43:44 +0100 | [diff] [blame] | 256 | git push ssh://john.doe@git.example.com:29418/kernel/common HEAD:refs/for/master%edit |
Michael Ochmann | b99feab | 2016-07-06 14:10:22 +0200 | [diff] [blame] | 257 | ---- |
David Ostrovsky | d07bb339 | 2015-01-19 07:43:44 +0100 | [diff] [blame] | 258 | |
| 259 | There is at most one change edit per user and change. In order to push |
| 260 | a change edit the change must already exist. |
| 261 | |
| 262 | [NOTE] |
| 263 | When a change edit already exists for a change then pushing with |
| 264 | `%edit` replaces the existing change edit. This option is useful to |
| 265 | rebase a change edit on the newest patch set when the rebase of the |
| 266 | change edit in the web UI fails due to conflicts. |
| 267 | |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 268 | If you are frequently uploading changes to the same Gerrit server, |
| 269 | consider adding an SSH host block in `~/.ssh/config` to remember |
| 270 | your username, hostname and port number. This permits the use of |
| 271 | shorter URLs on the command line, such as: |
| 272 | |
Michael Ochmann | b99feab | 2016-07-06 14:10:22 +0200 | [diff] [blame] | 273 | ---- |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 274 | $ cat ~/.ssh/config |
| 275 | ... |
| 276 | Host tr |
| 277 | Hostname git.example.com |
| 278 | Port 29418 |
| 279 | User john.doe |
| 280 | |
| 281 | $ git push tr:kernel/common HEAD:refs/for/experimental |
Michael Ochmann | b99feab | 2016-07-06 14:10:22 +0200 | [diff] [blame] | 282 | ---- |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 283 | |
David Pursehouse | 06eb3eb | 2016-09-01 11:04:03 +0900 | [diff] [blame] | 284 | [[reviewers]] |
| 285 | ==== Reviewers |
| 286 | |
Edwin Kempin | b5df3b8 | 2011-10-10 11:31:14 +0200 | [diff] [blame] | 287 | Specific reviewers can be requested and/or additional 'carbon |
David Pursehouse | 93733b6 | 2014-10-03 12:26:04 +0900 | [diff] [blame] | 288 | copies' of the notification message may be sent by including the |
| 289 | `reviewer` (or `r`) and `cc` options in the reference: |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 290 | |
Michael Ochmann | b99feab | 2016-07-06 14:10:22 +0200 | [diff] [blame] | 291 | ---- |
Shawn Pearce | 69928a6 | 2013-02-24 18:01:27 -0800 | [diff] [blame] | 292 | git push tr:kernel/common HEAD:refs/for/experimental%r=a@a.com,cc=b@o.com |
Michael Ochmann | b99feab | 2016-07-06 14:10:22 +0200 | [diff] [blame] | 293 | ---- |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 294 | |
Shawn Pearce | 69928a6 | 2013-02-24 18:01:27 -0800 | [diff] [blame] | 295 | The `r='email'` and `cc='email'` options may be specified as many |
| 296 | times as necessary to cover all interested parties. Gerrit will |
| 297 | automatically avoid sending duplicate email notifications, such as |
| 298 | if one of the specified reviewers or CC addresses had also requested |
| 299 | to receive all new change notifications. |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 300 | |
| 301 | If you are frequently sending changes to the same parties and/or |
| 302 | branches, consider adding a custom remote block to your project's |
| 303 | `.git/config` file: |
| 304 | |
Michael Ochmann | b99feab | 2016-07-06 14:10:22 +0200 | [diff] [blame] | 305 | ---- |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 306 | $ cat .git/config |
| 307 | ... |
Shawn Pearce | 69928a6 | 2013-02-24 18:01:27 -0800 | [diff] [blame] | 308 | [remote "exp"] |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 309 | url = tr:kernel/common |
Shawn Pearce | 69928a6 | 2013-02-24 18:01:27 -0800 | [diff] [blame] | 310 | push = HEAD:refs/for/experimental%r=a@a.com,cc=b@o.com |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 311 | |
Shawn Pearce | 69928a6 | 2013-02-24 18:01:27 -0800 | [diff] [blame] | 312 | $ git push exp |
Michael Ochmann | b99feab | 2016-07-06 14:10:22 +0200 | [diff] [blame] | 313 | ---- |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 314 | |
| 315 | |
Shawn O. Pearce | 518fe3f | 2009-08-22 15:40:58 -0700 | [diff] [blame] | 316 | [[push_replace]] |
Yuxuan 'fishy' Wang | 61698b1 | 2013-12-20 12:55:51 -0800 | [diff] [blame] | 317 | === Replace Changes |
Shawn O. Pearce | 518fe3f | 2009-08-22 15:40:58 -0700 | [diff] [blame] | 318 | |
| 319 | To add an additional patch set to a change, ensure Change-Id |
| 320 | lines were created in the original commit messages, and just use |
| 321 | `git push URL HEAD:refs/for/...` as <<push_create,described above>>. |
| 322 | Gerrit Code Review will automatically match the commits back to |
| 323 | their original changes by taking advantage of the Change-Id lines. |
| 324 | |
| 325 | If Change-Id lines are not present in the commit messages, consider |
| 326 | amending the message and copying the line from the change's page |
| 327 | on the web, and then using `git push` as described above. |
| 328 | |
| 329 | If Change-Id lines are not available, then the user must use the |
| 330 | manual mapping technique described below. |
| 331 | |
| 332 | For more about Change-Ids, see link:user-changeid.html[Change-Id Lines]. |
| 333 | |
Edwin Kempin | 930187e | 2011-01-27 10:13:42 +0100 | [diff] [blame] | 334 | [[manual_replacement_mapping]] |
Yuxuan 'fishy' Wang | 61698b1 | 2013-12-20 12:55:51 -0800 | [diff] [blame] | 335 | ==== Manual Replacement Mapping |
Shawn O. Pearce | 518fe3f | 2009-08-22 15:40:58 -0700 | [diff] [blame] | 336 | |
Michael Ochmann | 8129ece | 2016-07-08 11:25:25 +0200 | [diff] [blame] | 337 | [NOTE] |
| 338 | -- |
Shawn O. Pearce | 518fe3f | 2009-08-22 15:40:58 -0700 | [diff] [blame] | 339 | The remainder of this section describes a manual method of replacing |
| 340 | changes by matching each commit name to an existing change number. |
| 341 | End-users should instead prefer to use Change-Id lines in their |
| 342 | commit messages, as the process is then fully automated by Gerrit |
| 343 | during normal uploads. |
| 344 | |
| 345 | See above for the preferred technique of replacing changes. |
Michael Ochmann | 8129ece | 2016-07-08 11:25:25 +0200 | [diff] [blame] | 346 | -- |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 347 | |
| 348 | To add an additional patch set to a change, replacing it with an |
| 349 | updated version of the same logical modification, send the new |
| 350 | commit to the change's ref. For example, to add the commit whose |
| 351 | SHA-1 starts with `c0ffee` as a new patch set for change number |
| 352 | `1979`, use the push refspec `c0ffee:refs/changes/1979` as below: |
| 353 | |
Michael Ochmann | b99feab | 2016-07-06 14:10:22 +0200 | [diff] [blame] | 354 | ---- |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 355 | git push ssh://sshusername@hostname:29418/projectname c0ffee:refs/changes/1979 |
Michael Ochmann | b99feab | 2016-07-06 14:10:22 +0200 | [diff] [blame] | 356 | ---- |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 357 | |
| 358 | This form can be combined together with `refs/for/'branchname'` |
| 359 | (above) to simultaneously create new changes and replace changes |
| 360 | during one network transaction. |
| 361 | |
| 362 | For example, consider the following sequence of events: |
| 363 | |
Michael Ochmann | b99feab | 2016-07-06 14:10:22 +0200 | [diff] [blame] | 364 | ---- |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 365 | $ git commit -m A ; # create 3 commits |
| 366 | $ git commit -m B |
| 367 | $ git commit -m C |
| 368 | |
| 369 | $ git push ... HEAD:refs/for/master ; # upload for review |
| 370 | ... A is 1500 ... |
| 371 | ... B is 1501 ... |
| 372 | ... C is 1502 ... |
| 373 | |
| 374 | $ git rebase -i HEAD~3 ; # edit "A", insert D before B |
| 375 | ; # now series is A'-D-B'-C' |
Shawn O. Pearce | d607846 | 2009-11-02 10:37:01 -0800 | [diff] [blame] | 376 | $ git push ... |
| 377 | HEAD:refs/for/master |
| 378 | HEAD~3:refs/changes/1500 |
| 379 | HEAD~1:refs/changes/1501 |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 380 | HEAD~0:refs/changes/1502 ; # upload replacements |
Michael Ochmann | b99feab | 2016-07-06 14:10:22 +0200 | [diff] [blame] | 381 | ---- |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 382 | |
| 383 | At the final step during the push Gerrit will attach A' as a new |
| 384 | patch set on change 1500; B' as a new patch set on change 1501; C' |
| 385 | as a new patch set on 1502; and D will be created as a new change. |
| 386 | |
| 387 | Ensuring D is created as a new change requires passing the refspec |
| 388 | `HEAD:refs/for/branchname`, otherwise Gerrit will ignore D and |
| 389 | won't do anything with it. For this reason it is a good idea to |
| 390 | always include the create change refspec when uploading replacements. |
| 391 | |
| 392 | |
Edwin Kempin | 913eab1 | 2011-05-06 08:18:24 +0200 | [diff] [blame] | 393 | [[bypass_review]] |
Yuxuan 'fishy' Wang | 61698b1 | 2013-12-20 12:55:51 -0800 | [diff] [blame] | 394 | === Bypass Review |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 395 | |
| 396 | Changes (and annotated tags) can be pushed directly into a |
| 397 | repository, bypassing the review process. This is primarily useful |
| 398 | for a project owner to create new branches, create annotated tags |
| 399 | for releases, or to force-update a branch whose history needed to |
| 400 | be rewritten. |
| 401 | |
| 402 | Gerrit restricts direct pushes that bypass review to: |
| 403 | |
Jonathan Nieder | 5758f18 | 2015-03-30 11:28:55 -0700 | [diff] [blame] | 404 | * `+refs/heads/*+`: any branch can be updated, created, deleted, |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 405 | or rewritten by the pusher. |
Jonathan Nieder | 5758f18 | 2015-03-30 11:28:55 -0700 | [diff] [blame] | 406 | * `+refs/tags/*+`: annotated tag objects pointing to any other type |
Nico Sallembien | 950e415 | 2010-03-16 15:45:33 -0700 | [diff] [blame] | 407 | of Git object can be created. |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 408 | |
Fredrik Luthander | c10f9e7 | 2012-01-23 17:00:45 +0100 | [diff] [blame] | 409 | To push branches, the proper access rights must be configured first. |
| 410 | Here follows a few examples of how to configure this in Gerrit: |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 411 | |
| 412 | * Update: Any existing branch can be fast-forwarded to a new commit. |
| 413 | This is the safest mode as commits cannot be discarded. Creation |
Fredrik Luthander | c10f9e7 | 2012-01-23 17:00:45 +0100 | [diff] [blame] | 414 | of new branches is rejected. Can be configured with |
| 415 | link:access-control.html#category_push_direct['Push'] access. |
| 416 | * Create: Allows creation of a new branch if the name does not |
| 417 | already designate an existing branch name. Needs |
| 418 | link:access-control.html#category_create['Create Reference'] |
| 419 | configured. Please note that once created, this permission doesn't |
| 420 | grant the right to update the branch with further commits (see above |
| 421 | for update details). |
| 422 | * Delete: Implies Update, but also allows an existing |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 423 | branch to be deleted. Since a force push is effectively a delete |
| 424 | followed by a create, but performed atomically on the server and |
| 425 | logged, this also permits forced push updates to branches. |
Fredrik Luthander | c10f9e7 | 2012-01-23 17:00:45 +0100 | [diff] [blame] | 426 | To grant this access, configure |
| 427 | link:access-control.html#category_push_direct['Push'] with the |
| 428 | 'Force' option ticked. |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 429 | |
Edwin Kempin | 62c1568 | 2016-09-05 14:32:38 +0200 | [diff] [blame] | 430 | To push annotated tags, the `Create Annotated Tag` project right must |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 431 | be granted to one (or more) of the user's groups. There is only |
| 432 | one level of access in this category. |
| 433 | |
Edwin Kempin | 62c1568 | 2016-09-05 14:32:38 +0200 | [diff] [blame] | 434 | Project owners may wish to grant themselves `Create Annotated Tag` |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 435 | only at times when a new release is being prepared, and otherwise |
| 436 | grant nothing at all. This ensures that accidental pushes don't |
| 437 | make undesired changes to the public repository. |
| 438 | |
| 439 | |
Edwin Kempin | bfa0621 | 2013-04-04 16:06:39 +0200 | [diff] [blame] | 440 | [[auto_merge]] |
Yuxuan 'fishy' Wang | 61698b1 | 2013-12-20 12:55:51 -0800 | [diff] [blame] | 441 | === Auto-Merge during Push |
Edwin Kempin | bfa0621 | 2013-04-04 16:06:39 +0200 | [diff] [blame] | 442 | |
| 443 | Changes can be directly submitted on push. This is primarily useful |
| 444 | for teams that don't want to do code review but want to use Gerrit's |
| 445 | submit strategies to handle contention on busy branches. Using |
Sebastian Schuberth | 8329b01 | 2016-03-15 14:48:33 +0100 | [diff] [blame] | 446 | `%submit` creates a change and submits it immediately: |
Edwin Kempin | bfa0621 | 2013-04-04 16:06:39 +0200 | [diff] [blame] | 447 | |
Michael Ochmann | b99feab | 2016-07-06 14:10:22 +0200 | [diff] [blame] | 448 | ---- |
Edwin Kempin | bfa0621 | 2013-04-04 16:06:39 +0200 | [diff] [blame] | 449 | git push ssh://john.doe@git.example.com:29418/kernel/common HEAD:refs/for/master%submit |
Michael Ochmann | b99feab | 2016-07-06 14:10:22 +0200 | [diff] [blame] | 450 | ---- |
Edwin Kempin | bfa0621 | 2013-04-04 16:06:39 +0200 | [diff] [blame] | 451 | |
| 452 | On auto-merge of a change neither labels nor submit rules are checked. |
| 453 | If the merge fails the change stays open, but when pushing a new patch |
| 454 | set the merge can be reattempted by using `%submit` again. |
| 455 | |
Sebastian Schuberth | 8329b01 | 2016-03-15 14:48:33 +0100 | [diff] [blame] | 456 | This requires the caller to have link:access-control.html#category_submit[Submit] |
| 457 | permission on `refs/for/<ref>` (e.g. on `refs/for/refs/heads/master`). |
| 458 | Note how this is different from the `Submit` permission on `refs/heads/<ref>`, |
| 459 | and in particular you typically do not want to apply the `Submit` permission |
| 460 | on `refs/*` (unless you are ok with bypassing submit rules). |
Edwin Kempin | bfa0621 | 2013-04-04 16:06:39 +0200 | [diff] [blame] | 461 | |
Shawn Pearce | 5d8a290 | 2013-04-22 11:50:23 -0700 | [diff] [blame] | 462 | [[base]] |
Yuxuan 'fishy' Wang | 61698b1 | 2013-12-20 12:55:51 -0800 | [diff] [blame] | 463 | === Selecting Merge Base |
Shawn Pearce | 5d8a290 | 2013-04-22 11:50:23 -0700 | [diff] [blame] | 464 | |
| 465 | By default new changes are opened only for new unique commits |
| 466 | that have never before been seen by the Gerrit server. Clients |
| 467 | may override that behavior and force new changes to be created |
| 468 | by setting the merge base SHA-1 using the '%base' argument: |
| 469 | |
Michael Ochmann | b99feab | 2016-07-06 14:10:22 +0200 | [diff] [blame] | 470 | ---- |
Shawn Pearce | 5d8a290 | 2013-04-22 11:50:23 -0700 | [diff] [blame] | 471 | git push ssh://john.doe@git.example.com:29418/kernel/common HEAD:refs/for/master%base=$(git rev-parse origin/master) |
Michael Ochmann | b99feab | 2016-07-06 14:10:22 +0200 | [diff] [blame] | 472 | ---- |
Shawn Pearce | 5d8a290 | 2013-04-22 11:50:23 -0700 | [diff] [blame] | 473 | |
Sasa Zivkov | bc011a1 | 2013-11-07 16:08:31 +0100 | [diff] [blame] | 474 | It is also possible to specify more than one '%base' argument. |
| 475 | This may be useful when pushing a merge commit. Note that the '%' |
| 476 | character has only to be provided once, for the first '%base' |
| 477 | argument: |
| 478 | |
Michael Ochmann | b99feab | 2016-07-06 14:10:22 +0200 | [diff] [blame] | 479 | ---- |
Sasa Zivkov | bc011a1 | 2013-11-07 16:08:31 +0100 | [diff] [blame] | 480 | git push ssh://john.doe@git.example.com:29418/kernel/common HEAD:refs/for/master%base=commit-id1,base=commit-id2 |
Michael Ochmann | b99feab | 2016-07-06 14:10:22 +0200 | [diff] [blame] | 481 | ---- |
Sasa Zivkov | bc011a1 | 2013-11-07 16:08:31 +0100 | [diff] [blame] | 482 | |
Dave Borowitz | a01219a | 2016-09-09 10:18:26 -0400 | [diff] [blame] | 483 | [[merged]] |
| 484 | === Creating Changes for Merged Commits |
| 485 | |
| 486 | Normally, changes are only created for commits that have not yet |
| 487 | been merged into the branch. In some cases, you may want to review a |
| 488 | change that has already been merged. A new change for a merged commit |
| 489 | can be created by using the '%merged' argument: |
| 490 | |
| 491 | ---- |
| 492 | git push ssh://john.doe@git.example.com:29418/kernel/common my-merged-commit:refs/for/master%merged |
| 493 | ---- |
| 494 | |
| 495 | This only creates one merged change at a time, corresponding to |
| 496 | exactly `my-merged-commit`. It doesn't walk all of history up to that |
| 497 | point, which could be slow and create lots of unintended new changes. |
| 498 | To create multiple new changes, run push multiple times. |
| 499 | |
Shawn Pearce | 5d8a290 | 2013-04-22 11:50:23 -0700 | [diff] [blame] | 500 | |
Yuxuan 'fishy' Wang | 61698b1 | 2013-12-20 12:55:51 -0800 | [diff] [blame] | 501 | == repo upload |
Shawn O. Pearce | 518fe3f | 2009-08-22 15:40:58 -0700 | [diff] [blame] | 502 | |
| 503 | repo is a multiple repository management tool, most commonly |
| 504 | used by the Android Open Source Project. For more details, see |
Orgad Shaneh | c9e11de | 2012-12-24 16:49:09 +0200 | [diff] [blame] | 505 | link:http://source.android.com/source/using-repo.html[using repo]. |
Shawn O. Pearce | 518fe3f | 2009-08-22 15:40:58 -0700 | [diff] [blame] | 506 | |
| 507 | [[repo_create]] |
Yuxuan 'fishy' Wang | 61698b1 | 2013-12-20 12:55:51 -0800 | [diff] [blame] | 508 | === Create Changes |
Shawn O. Pearce | 518fe3f | 2009-08-22 15:40:58 -0700 | [diff] [blame] | 509 | |
| 510 | To upload changes to a project using `repo`, ensure the manifest's |
| 511 | review field has been configured to point to the Gerrit server. |
| 512 | Only the hostname or the web address needs to be given in the |
| 513 | manifest file. During upload `repo` will automatically determine the |
| 514 | correct port number by reading `http://'reviewhostname'/ssh_info` |
| 515 | when its invoked. |
| 516 | |
| 517 | Each new commit uploaded by `repo upload` will be converted into |
| 518 | a change record on the server. Other users (e.g. project owners) |
| 519 | who have configured Gerrit to notify them of new changes will be |
| 520 | automatically sent an email message. Additional notifications can |
| 521 | be sent through command line options. |
| 522 | |
| 523 | For more details on using `repo upload`, see `repo help upload`. |
| 524 | |
| 525 | [[repo_replace]] |
Yuxuan 'fishy' Wang | 61698b1 | 2013-12-20 12:55:51 -0800 | [diff] [blame] | 526 | === Replace Changes |
Shawn O. Pearce | 518fe3f | 2009-08-22 15:40:58 -0700 | [diff] [blame] | 527 | |
| 528 | To replace changes, ensure Change-Id lines were created in the |
Cecilia Svensson | cd2491d | 2012-01-20 14:22:30 +0100 | [diff] [blame] | 529 | commit messages, and just use `repo upload`. |
| 530 | Gerrit Code Review will automatically match the commits back to |
| 531 | their original changes by taking advantage of their Change-Id lines. |
Shawn O. Pearce | 518fe3f | 2009-08-22 15:40:58 -0700 | [diff] [blame] | 532 | |
| 533 | If Change-Id lines are not present in the commit messages, consider |
| 534 | amending the message and copying the line from the change's page |
| 535 | on the web. |
| 536 | |
| 537 | If Change-Id lines are not available, then the user must use the much |
Cecilia Svensson | cd2491d | 2012-01-20 14:22:30 +0100 | [diff] [blame] | 538 | more <<manual_replacement_mapping,manual mapping technique>> offered |
| 539 | by using `git push` to a specific `refs/changes/change#` reference. |
Shawn O. Pearce | 518fe3f | 2009-08-22 15:40:58 -0700 | [diff] [blame] | 540 | |
| 541 | For more about Change-Ids, see link:user-changeid.html[Change-Id Lines]. |
| 542 | |
| 543 | |
Yuxuan 'fishy' Wang | 61698b1 | 2013-12-20 12:55:51 -0800 | [diff] [blame] | 544 | == Gritty Details |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 545 | |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 546 | As Gerrit implements the entire SSH and Git server stack within its |
| 547 | own process space, Gerrit maintains complete control over how the |
| 548 | repository is updated, and what responses are sent to the `git push` |
| 549 | client invoked by the end-user, or by `repo upload`. This allows |
Jonathan Nieder | 5758f18 | 2015-03-30 11:28:55 -0700 | [diff] [blame] | 550 | Gerrit to provide magical refs, such as `+refs/for/*+` for new |
| 551 | change submission and `+refs/changes/*+` for change replacement. |
Shawn O. Pearce | e61a3c6 | 2009-01-29 08:42:41 -0800 | [diff] [blame] | 552 | When a push request is received to create a ref in one of these |
| 553 | namespaces Gerrit performs its own logic to update the database, |
| 554 | and then lies to the client about the result of the operation. |
| 555 | A successful result causes the client to believe that Gerrit has |
| 556 | created the ref, but in reality Gerrit hasn't created the ref at all. |
| 557 | |
| 558 | By implementing the entire server stack, Gerrit is also able to |
| 559 | perform project level access control checks (to verify the end-user |
| 560 | is permitted to access a project) prior to advertising the available |
| 561 | refs, and potentially leaking information to a snooping client. |
| 562 | Clients cannot tell the difference between 'project not found' and |
| 563 | 'project exists, but access is denied'. |
| 564 | |
| 565 | Gerrit can also ensure users have completed a valid Contributor |
| 566 | Agreement prior to accepting any transferred objects, and if an |
| 567 | agreement is required, but not completed, it aborts the network |
| 568 | connection before data is sent. This ensures that project owners |
| 569 | can be certain any object available in their repository has been |
| 570 | supplied under at least one valid agreement. |
Shawn O. Pearce | 5500e69 | 2009-05-28 15:55:01 -0700 | [diff] [blame] | 571 | |
| 572 | GERRIT |
| 573 | ------ |
| 574 | Part of link:index.html[Gerrit Code Review] |
Yuxuan 'fishy' Wang | 99cb68d | 2013-10-31 17:26:00 -0700 | [diff] [blame] | 575 | |
| 576 | SEARCHBOX |
| 577 | --------- |