On Tue, Jul 28, 2026 at 5:01 PM Numan Siddique <[email protected]> wrote:
> > > > On Tue, Jul 28, 2026, 5:02 a.m. Dumitru Ceara <[email protected]> wrote: > >> Hi all, >> >> On 7/24/26 10:52 AM, Eelco Chaudron wrote: >> > >> > >> > On 23 Jul 2026, at 23:16, Ilya Maximets wrote: >> > >> >> On 7/23/26 10:56 PM, Numan Siddique wrote: >> >>> On Thu, Jul 23, 2026 at 4:51 PM Ilya Maximets <[email protected]> >> wrote: >> >>>> >> >>>> On 7/23/26 10:08 PM, Numan Siddique wrote: >> >>>>> On Thu, Jul 23, 2026 at 3:59 PM Ilya Maximets <[email protected]> >> wrote: >> >>>>>> >> >>>>>> On 7/23/26 9:52 PM, Numan Siddique wrote: >> >>>>>>> Hi OVN and OVS maintainers >> >>>>>>> >> >>>>>>> Jimmy (CC'ed) has raised this PR issue for OVN - >> >>>>>>> https://github.com/ovn-org/ovn/issues/317 >> >>>>>>> about protecting the release branches. >> >>>>>>> >> >>>>>>> Are there any reservations against this request ? Or any >> downsides ? >> >>>>>>> >> >>>>>>> We are setting up pull mirror rules for our downstream OVS and OVN >> >>>>>>> repos and we want to base it on the protected branches. >> >>>>>>> >> >>>>>>> Looks like OVS branches were protected until branch-3.2. >> >>>>>>> >> >>>>>>> Can we branch protections for both OVS and OVN ? >> >>>>>> >> >>>>>> Branch protection is a mechanism to prevent direct pushes, AFAIR. >> >>>>>> So, the only way to merge changes becomes a github PR. Which is >> >>>>>> not how our development process works. We rely on maintainers >> >>>>>> pushing code directly to branches where it belongs. And we trust >> >>>>>> our maintainers to be careful with that. >> >>>>>> >> >>>>> >> >>>>> Thanks Ilya for the reply. >> >>>>> >> >>>>> I think it is possible to have direct pushes from the maintainers >> even >> >>>>> if the branch is protected >> >>>>> by adding rules to allow maintainers. But it won't be possible for >> >>>>> the force pushes. >> >>>>> >> >>>>> Let me know if it makes sense to protect the branches and also >> allow maintainers >> >>>>> to push. >> >>>> >> >>>> Maintainers are the only ones with the write access, i.e., the only >> >>>> ones who can push. Is there a point in protection rules if everyone >> >>>> who can push will still be able to do so? >> >>>> >> >>>> We do also allow maintainers to use force-push for quickly fixing >> >>>> their mistakes. And mistakes are a part of having write access. >> >>>> Obviously, it's not something that should be used lightly or in any >> >>>> way frequently. But it's good to have a tool when it is necessary. >> >>> >> >>> Got it. I agree there and I myself have done a few mistakes before. >> >>> >> >>>> >> >>>> I'm also not sure what is the original idea behind only mirroring >> >>>> protected branches? Could you elaborate? >> >>>> >> >>> >> >>> From what I understand, security wants to only mirror the upstream >> >>> code from the branches which are protected. >> >> >> >> Fun fact: I just checked and it is possible to create a branch >> protection >> >> rule with the following configuration: >> >> >> >> 1. Allow force pushes (for everyone with push access) >> >> 2. Allow branch deletions (for everyone with push access) >> >> 3. Require linear history. >> >> >> >> This rule adds no real restrictions that are meaningful to our >> development >> >> process. The only restriction is a linear history that we use anyway. >> >> >> >> But, after applying it to a branch, it now shows a shield icon with the >> >> 'This branch is protected with branch protections' legend. And since >> it >> >> is a legacy branch protection rule, nobody except for the owner can see >> >> what this protection rule actually is. >> >> >> >> Similar thing can be done with the branch 'ruleset', but people can see >> >> what the ruleset is enforcing byt clicking on it. >> >> >> >> Though rulesets allow creation of a fully restrictive rule and make it >> >> bypassed by everyone with the Write role. Bypasses are not reported in >> >> the UI, so there will be a rule, but it will never be enforced in >> practice, >> >> while being reported as 'Active - This ruleset will be enforced'. >> >> >> >> All in all, unless you're the organization owner, the branch protection >> >> status on the branches page means absolutely nothing. >> > >> > Adding protection without restricting maintainers is just putting a >> "Protected" sticker on the branch, looks good, does nothing. As Ilya found, >> we would basically just get a free badge. Also, it makes no sense to change >> our development process just for this. >> > >> >> I agree, our current process (for both OVS and OVN) requires pushing to >> supported branches. I don't think we should change anything about the >> currently supported branches. >> >> We could, for OVN, protect all the currently unsupported branches >> though. I think that would mean everything < branch-24.03. >> >> I can do that if the other OVN maintainers agree. >> > > +1 from me. > > Numan > I'm fine with that too. Regards, Ales > > >> >>> >> >>> Maybe @[email protected] can perhaps elaborate more as he >> >>> is the one who created the ticket. >> >>> >> >>> Thanks >> >>> Numan >> >>> >> >>>>> >> >>>>> >> >>>>>> Branch protection is enabled on OVS branches that are no longer >> >>>>>> maintained to prevent accidental pushes. They are just frozen in >> >>>>>> time. Same could be done for OVN. >> >>>>> >> >>>>> I see. This explains why older branches have protection. >> >>>>> >> >>>>> Thanks >> >>>>> Numan >> >>>>> >> >>>>> >> >>>>> But we can't do that for >> >>>>>> currently maintained branches. >> >>>>> >> >>>>>> >> >>>>>> Best regards, Ilya Maximets. >> >>>> >> > >> >> Regards, >> Dumitru >> >> > > _______________________________________________ dev mailing list [email protected] https://mail.openvswitch.org/mailman/listinfo/ovs-dev
