You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Git查找本地未暂存重要文件的删除者?

How to Identify Who Deleted Uncommitted Files in a Shared Git Workspace

Since the deletion only exists in the working directory (not staged or committed), Git doesn’t natively track who made this change—Git’s history only starts at the commit level. But there are several practical workarounds to narrow down the culprit, depending on your system setup:

1. Check User Shell Histories

Most shells (like Bash, Zsh) keep a log of commands each user runs. On a multi-user machine, you can inspect these history files to see if someone executed an rm command targeting the missing files.

  • For Bash, look at ~/.bash_history (replace ~ with each user’s home directory)
  • For Zsh, check ~/.zsh_history

Search for the filename with a command like:

grep "missing-filename.txt" /home/user1/.bash_history

Note: Users can modify or clear their shell history, so this isn’t 100% foolproof, but it’s a quick starting point.

2. Inspect System-Level Audit Logs

If your machine has audit logging enabled (common on Linux systems with auditd), you can trace exactly when and by whom the files were deleted.

  • First, confirm auditd is running:
systemctl status auditd
  • Use ausearch to find deletion events for your files:
ausearch -m DELETE -f /path/to/missing-file.txt

This will show the timestamp, user ID, and process that deleted the file. If auditd isn’t enabled, you’ll need to turn it on for future incidents, but it won’t help with the current one.

3. Check for Stashed Changes

Sometimes users stash uncommitted changes instead of committing them. You can check each user’s Git stashes to see if the deletion is hidden there:

  • Switch to each user’s account (or use sudo -u user git ...), then list stashes:
git stash list
  • For each stash entry, view its contents to check for the deleted files:
git stash show stash@{0}

If you find a stash containing the deletion, the user who owns that stash is likely responsible.

4. Cross-Reference Timestamps with User Activity

While this won’t directly name the user, checking when the files were removed can help narrow down suspects. Use the parent directory’s metadata to get a rough deletion timestamp:

  • On Linux, run:
stat /path/to/parent-directory

Then check system logs (like /var/log/auth.log or /var/log/syslog) for user logins or activity around that timestamp to cross-reference.


Once you’ve identified the user, you can restore the files with:

git checkout HEAD -- /path/to/missing-file.txt

内容的提问来源于stack exchange,提问作者Mugen

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.12 05:34:22