On 7/23/26 10:56 PM, Numan Siddique wrote:
> On Thu, Jul 23, 2026 at 4:51 PM Ilya Maximets <[email protected]> wrote:
>>
>> On 7/23/26 10:08 PM, Numan Siddique wrote:
>>> On Thu, Jul 23, 2026 at 3:59 PM Ilya Maximets <[email protected]> wrote:
>>>>
>>>> On 7/23/26 9:52 PM, Numan Siddique wrote:
>>>>> Hi OVN and OVS maintainers
>>>>>
>>>>> Jimmy (CC'ed) has raised this PR issue for OVN -
>>>>> https://github.com/ovn-org/ovn/issues/317
>>>>> about protecting the release branches.
>>>>>
>>>>> Are there any reservations against this request ? Or any downsides ?
>>>>>
>>>>> We are setting up pull mirror rules for our downstream OVS and OVN
>>>>> repos and we want to base it on the protected branches.
>>>>>
>>>>> Looks like OVS branches were protected until branch-3.2.
>>>>>
>>>>> Can we branch protections for both OVS and OVN ?
>>>>
>>>> Branch protection is a mechanism to prevent direct pushes, AFAIR.
>>>> So, the only way to merge changes becomes a github PR.  Which is
>>>> not how our development process works.  We rely on maintainers
>>>> pushing code directly to branches where it belongs.  And we trust
>>>> our maintainers to be careful with that.
>>>>
>>>
>>> Thanks Ilya for the reply.
>>>
>>> I think it is possible to have direct pushes from the maintainers even
>>> if the branch is protected
>>> by adding rules to allow maintainers.  But it won't be possible for
>>> the force pushes.
>>>
>>> Let me know if it makes sense to protect the branches and also allow 
>>> maintainers
>>> to push.
>>
>> Maintainers are the only ones with the write access, i.e., the only
>> ones who can push.  Is there a point in protection rules if everyone
>> who can push will still be able to do so?
>>
>> We do also allow maintainers to use force-push for quickly fixing
>> their mistakes.  And mistakes are a part of having write access.
>> Obviously, it's not something that should be used lightly or in any
>> way frequently.  But it's good to have a tool when it is necessary.
> 
> Got it.  I agree there and I myself have done a few mistakes before.
> 
>>
>> I'm also not sure what is the original idea behind only mirroring
>> protected branches?  Could you elaborate?
>>
> 
> From what I understand, security wants to only mirror the upstream
> code from the branches which are protected.

Fun fact:  I just checked and it is possible to create a branch protection
rule with the following configuration:

 1. Allow force pushes (for everyone with push access)
 2. Allow branch deletions (for everyone with push access)
 3. Require linear history.

This rule adds no real restrictions that are meaningful to our development
process.  The only restriction is a linear history that we use anyway.

But, after applying it to a branch, it now shows a shield icon with the
'This branch is protected with branch protections' legend.  And since it
is a legacy branch protection rule, nobody except for the owner can see
what this protection rule actually is.

Similar thing can be done with the branch 'ruleset', but people can see
what the ruleset is enforcing byt clicking on it.

Though rulesets allow creation of a fully restrictive rule and make it
bypassed by everyone with the Write role.  Bypasses are not reported in
the UI, so there will be a rule, but it will never be enforced in practice,
while being reported as 'Active - This ruleset will be enforced'.

All in all, unless you're the organization owner, the branch protection
status on the branches page means absolutely nothing.

> 
> Maybe @[email protected]  can perhaps elaborate more as he
> is the one who created the ticket.
> 
> Thanks
> Numan
> 
>>>
>>>
>>>> Branch protection is enabled on OVS branches that are no longer
>>>> maintained to prevent accidental pushes.  They are just frozen in
>>>> time.  Same could be done for OVN.
>>>
>>> I see.  This explains why older branches have protection.
>>>
>>> Thanks
>>> Numan
>>>
>>>
>>>  But we can't do that for
>>>> currently maintained branches.
>>>
>>>>
>>>> Best regards, Ilya Maximets.
>>

_______________________________________________
dev mailing list
[email protected]
https://mail.openvswitch.org/mailman/listinfo/ovs-dev

Reply via email to