Introduce receive.denyDeletes
Occasionally, it may be useful to prevent branches from getting deleted from a centralized repository, particularly when no administrative access to the server is available to undo it via reflog. It also makes receive.denyNonFastForwards more useful if it is used for access control since it prevents force-updating by deleting and re-creating a ref. Signed-off-by: Jan Krüger <> Acked-by: Shawn O. Pearce <> Signed-off-by: Junio C Hamano <>
diff --git a/t/ b/t/
index 544771d..6fe2f87 100755
--- a/t/
+++ b/t/
@@ -103,6 +103,17 @@ unset GIT_CONFIG GIT_CONFIG_LOCAL
export HOME ;# this way we force the victim/.git/config to be used.
+test_expect_failure \
+ 'pushing a delete should be denied with denyDeletes' '
+ cd victim &&
+ git config receive.denyDeletes true &&
+ git branch extra master &&
+ cd .. &&
+ test -f victim/.git/refs/heads/extra &&
+ test_must_fail git send-pack ./victim/.git/ :extra master
+rm -f victim/.git/refs/heads/extra
test_expect_success \
'pushing with --force should be denied with denyNonFastforwards' '
cd victim &&