{"thread":{"id":"66205","subject":"[PATCH 0/3] treewide: migrate from legacy utime.h to utimensat","startedAt":"2026-08-21T14:23:26Z","lastAt":"2026-08-24T20:25:36Z","messageCount":19,"participants":["Alexey Samsonov via GitGitGadget","Junio C Hamano","brian m. carlson","Weijie Yuan","Oswald Buddenhagen"],"isPatch":true,"patchVersion":1,"patchTotal":3},"messages":[{"id":"551023","messageId":"pull.2209.git.1787322203.gitgitgadget@gmail.com","threadId":"66205","inReplyTo":null,"subject":"[PATCH 0/3] treewide: migrate from legacy utime.h to utimensat","fromName":"Alexey Samsonov via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-08-21T14:23:20Z","receivedAt":"2026-08-21T14:23:26Z","isPatch":true,"body":"utime() function for setting access/modification time for files (and a\ncorresponding <utime.h> header) have been officially removed from POSIX\nstarting from POSIX.1-2024. While existing system library implementations\nstill provide this function for compatibility reasons, its implementation\nmay be removed in the future, or otherwise degrade over time. Some newer\nlibc implementations (e.g. LLVM-libc, currently under development) don't\nprovide utime() function at all.\n\nThis PR switches the git codebase to recommended alternative: utimensat()\nPOSIX function (which supports nanosecond-level precision) from <fcntl.h>,\nand, as a possible fallback for older systems compatibility, utimes()\nfunction from <sys/stat.h>. It also provides the corresponding MinGW\nwrapper.\n\nThe alternative is to unconditionally use utimes() where possible, but given\nthat utimensat is available in glibc starting from 2007, and on BSD systems\nsince 2012 or so, it makes sense to use the newer variant by default.\n\nNo behavior changes is intended or expected (except for Git explicitly\npassing nanosecond-precision timestamps to kernel, where previously only\nsecond-level precision was used).\n\nThis change is generated by Gemini Flash from Antigravity, but all the code\nhas been manually verified by me, and, where applicable, adjusted to match\nthe existing behavior as closely as possible.\n\nSigned-off-by: Alexey Samsonov vonosmas@gmail.com\n\nAlexey Samsonov (3):\n  compat/posix: introduce utimensat(2) wrapper\n  treewide: use utimensat(2) instead of legacy utime(3p)\n  compat/posix: drop legacy <utime.h> header and shims\n\n Makefile                            |  6 +++++\n builtin/pack-objects.c              | 12 +++++----\n commit-graph.c                      | 17 +++++--------\n compat/mingw-posix.h                |  4 +--\n compat/mingw.c                      | 36 ++++++++++++++++++++------\n compat/posix.h                      | 22 +++++++++++++++-\n compat/utimensat.c                  | 39 +++++++++++++++++++++++++++++\n compat/vcbuild/include/sys/utime.h  | 34 -------------------------\n compat/vcbuild/include/utime.h      |  1 -\n configure.ac                        |  6 +++++\n contrib/buildsystems/CMakeLists.txt |  8 ++++--\n copy.c                              | 10 +++++---\n meson.build                         |  2 ++\n object-file.c                       | 12 +++++----\n odb/source-loose.c                  | 10 ++++----\n odb/source-packed.c                 | 12 +++++----\n rerere.c                            |  4 +--\n t/helper/test-chmtime.c             | 20 +++++++++------\n t/t4051/includes.c                  |  1 -\n 19 files changed, 163 insertions(+), 93 deletions(-)\n create mode 100644 compat/utimensat.c\n delete mode 100644 compat/vcbuild/include/sys/utime.h\n delete mode 100644 compat/vcbuild/include/utime.h\n\n\nbase-commit: dea0ea3582e6980ddbc1173cc8e3e9f9db91cde0\nPublished-As: https://github.com/gitgitgadget/git/releases/tag/pr-2209%2Fvonosmas%2Fdrop-utime-h-v1\nFetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-2209/vonosmas/drop-utime-h-v1\nPull-Request: https://github.com/gitgitgadget/git/pull/2209\n-- \ngitgitgadget\n"},{"id":"551024","messageId":"13aa80bc0167aae05498bac1c59846274ee00e9d.1787322203.git.gitgitgadget@gmail.com","threadId":"66205","inReplyTo":"pull.2209.git.1787322203.gitgitgadget@gmail.com","subject":"[PATCH 1/3] compat/posix: introduce utimensat(2) wrapper","fromName":"Alexey Samsonov via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-08-21T14:23:21Z","receivedAt":"2026-08-21T14:23:26Z","isPatch":true,"body":"From: Alexey Samsonov <vonosmas@gmail.com>\n\nIn POSIX.1-2008, utime(3p) was marked as obsolescent in favor of\nutimensat(2) and futimens(2). In the recent POSIX.1-2024 (Issue 8)\nspecification, <utime.h> and utime(3p) were officially removed.\n\nutimensat(2) operates on `struct timespec` rather than the second-only\n`struct utimbuf`, allowing sub-second timestamp updates while also\nproviding support for UTIME_NOW and UTIME_OMIT flags to selectively\nupdate or preserve individual access and modification timestamps.\n\nIntroduce a compatibility layer for utimensat(2):\n- Provide fallback definitions for AT_FDCWD, UTIME_NOW, and UTIME_OMIT\n  in case the system headers lack them.\n- Introduce `ST_ATIME_NSEC(st)` to complement `ST_MTIME_NSEC(st)` and\n  `ST_CTIME_NSEC(st)`.\n- Implement `git_utimensat()` in `compat/utimensat.c` as a fallback using\n  utimes(2) on platforms that define NO_UTIMENSAT.\n- Implement `mingw_utimensat()` in `compat/mingw.c` converting `struct\n  timespec` to Windows FILETIME with 100ns precision.\n- Wire up NO_UTIMENSAT support in Makefile, meson.build,\n  contrib/buildsystems/CMakeLists.txt, and configure.ac.\n\nSubsequent commits will migrate callers across the codebase to\nutimensat(2) and drop the legacy <utime.h> header.\n\nSigned-off-by: Alexey Samsonov <vonosmas@gmail.com>\n---\n Makefile                            |  6 ++++\n compat/mingw-posix.h                |  2 ++\n compat/mingw.c                      | 52 +++++++++++++++++++++++++----\n compat/posix.h                      | 21 ++++++++++++\n compat/utimensat.c                  | 39 ++++++++++++++++++++++\n configure.ac                        |  6 ++++\n contrib/buildsystems/CMakeLists.txt |  8 +++--\n meson.build                         |  2 ++\n 8 files changed, 127 insertions(+), 9 deletions(-)\n create mode 100644 compat/utimensat.c\n\ndiff --git a/Makefile b/Makefile\nindex d4b775953d..64909d48b2 100644\n--- a/Makefile\n+++ b/Makefile\n@@ -70,6 +70,8 @@ include shared.mak\n #\n # Define NO_MKDTEMP if you don't have mkdtemp in the C library.\n #\n+# Define NO_UTIMENSAT if you don't have utimensat.\n+#\n # Define MKDIR_WO_TRAILING_SLASH if your mkdir() can't deal with trailing slash.\n #\n # Define NO_GECOS_IN_PWENT if you don't have pw_gecos in struct passwd\n@@ -2049,6 +2051,10 @@ ifdef NO_WRITEV\n \tCOMPAT_CFLAGS += -DNO_WRITEV\n \tCOMPAT_OBJS += compat/writev.o\n endif\n+ifdef NO_UTIMENSAT\n+\tCOMPAT_CFLAGS += -DNO_UTIMENSAT\n+\tCOMPAT_OBJS += compat/utimensat.o\n+endif\n ifdef NO_FAST_WORKING_DIRECTORY\n \tBASIC_CFLAGS += -DNO_FAST_WORKING_DIRECTORY\n endif\ndiff --git a/compat/mingw-posix.h b/compat/mingw-posix.h\nindex 2d989fd762..aab91d76db 100644\n--- a/compat/mingw-posix.h\n+++ b/compat/mingw-posix.h\n@@ -386,6 +386,8 @@ int mingw_fstat(int fd, struct stat *buf);\n \n int mingw_utime(const char *file_name, const struct utimbuf *times);\n #define utime mingw_utime\n+int mingw_utimensat(int fd, const char *path, const struct timespec times[2], int flag);\n+#define utimensat mingw_utimensat\n size_t mingw_strftime(char *s, size_t max,\n \t\t   const char *format, const struct tm *tm);\n #define strftime mingw_strftime\ndiff --git a/compat/mingw.c b/compat/mingw.c\nindex 4c2f26d454..d09a976191 100644\n--- a/compat/mingw.c\n+++ b/compat/mingw.c\n@@ -1391,22 +1391,33 @@ int mingw_fstat(int fd, struct stat *buf)\n \t}\n }\n \n-static inline void time_t_to_filetime(time_t t, FILETIME *ft)\n+static inline void timespec_to_filetime(const struct timespec *ts, FILETIME *ft)\n {\n-\tlong long winTime = t * 10000000LL + 116444736000000000LL;\n+\tlong long winTime = (long long)ts->tv_sec * 10000000LL + (ts->tv_nsec / 100) + 116444736000000000LL;\n \tft->dwLowDateTime = winTime;\n \tft->dwHighDateTime = winTime >> 32;\n }\n \n-int mingw_utime (const char *file_name, const struct utimbuf *times)\n+int mingw_utimensat(int fd, const char *path, const struct timespec times[2], int flag)\n {\n \tFILETIME mft, aft;\n+\tFILETIME *paft = &aft, *pmft = &mft;\n \tint rc;\n \tDWORD attrs;\n \twchar_t wfilename[MAX_PATH];\n \tHANDLE osfilehandle;\n \n-\tif (xutftowcs_path(wfilename, file_name) < 0)\n+\tif (fd != AT_FDCWD) {\n+\t\terrno = ENOSYS;\n+\t\treturn -1;\n+\t}\n+\n+\tif (flag) {\n+\t\terrno = ENOSYS;\n+\t\treturn -1;\n+\t}\n+\n+\tif (xutftowcs_path(wfilename, path) < 0)\n \t\treturn -1;\n \n \t/* must have write permission */\n@@ -1433,14 +1444,25 @@ int mingw_utime (const char *file_name, const struct utimbuf *times)\n \t}\n \n \tif (times) {\n-\t\ttime_t_to_filetime(times->modtime, &mft);\n-\t\ttime_t_to_filetime(times->actime, &aft);\n+\t\tif (times[0].tv_nsec == UTIME_NOW)\n+\t\t\tGetSystemTimeAsFileTime(&aft);\n+\t\telse if (times[0].tv_nsec == UTIME_OMIT)\n+\t\t\tpaft = NULL;\n+\t\telse\n+\t\t\ttimespec_to_filetime(&times[0], &aft);\n+\n+\t\tif (times[1].tv_nsec == UTIME_NOW)\n+\t\t\tGetSystemTimeAsFileTime(&mft);\n+\t\telse if (times[1].tv_nsec == UTIME_OMIT)\n+\t\t\tpmft = NULL;\n+\t\telse\n+\t\t\ttimespec_to_filetime(&times[1], &mft);\n \t} else {\n \t\tGetSystemTimeAsFileTime(&mft);\n \t\taft = mft;\n \t}\n \n-\tif (!SetFileTime(osfilehandle, NULL, &aft, &mft)) {\n+\tif (!SetFileTime(osfilehandle, NULL, paft, pmft)) {\n \t\terrno = EINVAL;\n \t\trc = -1;\n \t} else\n@@ -1458,6 +1480,22 @@ revert_attrs:\n \treturn rc;\n }\n \n+int mingw_utime(const char *file_name, const struct utimbuf *times)\n+{\n+\tstruct timespec ts[2];\n+\tstruct timespec *tsp = NULL;\n+\n+\tif (times) {\n+\t\tts[0].tv_sec = times->actime;\n+\t\tts[0].tv_nsec = 0;\n+\t\tts[1].tv_sec = times->modtime;\n+\t\tts[1].tv_nsec = 0;\n+\t\ttsp = ts;\n+\t}\n+\n+\treturn mingw_utimensat(AT_FDCWD, file_name, tsp, 0);\n+}\n+\n #undef strftime\n size_t mingw_strftime(char *s, size_t max,\n \t\t      const char *format, const struct tm *tm)\ndiff --git a/compat/posix.h b/compat/posix.h\nindex 71cc731620..3cac1751aa 100644\n--- a/compat/posix.h\n+++ b/compat/posix.h\n@@ -348,6 +348,24 @@ struct git_iovec {\n ssize_t git_writev(int fd, const struct iovec *iov, int iovcnt);\n #endif\n \n+#ifndef AT_FDCWD\n+#define AT_FDCWD (-100)\n+#endif\n+#ifndef UTIME_NOW\n+#define UTIME_NOW ((1L << 30) - 1L)\n+#endif\n+#ifndef UTIME_OMIT\n+#define UTIME_OMIT ((1L << 30) - 2L)\n+#endif\n+\n+#ifdef NO_UTIMENSAT\n+#ifdef utimensat\n+#undef utimensat\n+#endif\n+#define utimensat git_utimensat\n+int git_utimensat(int fd, const char *path, const struct timespec times[2], int flag);\n+#endif\n+\n #ifdef NO_SETENV\n #define setenv gitsetenv\n int gitsetenv(const char *, const char *, int);\n@@ -502,13 +520,16 @@ int git_qsort_s(void *base, size_t nmemb, size_t size,\n \n #ifdef NO_NSEC\n #undef USE_NSEC\n+#define ST_ATIME_NSEC(st) 0\n #define ST_CTIME_NSEC(st) 0\n #define ST_MTIME_NSEC(st) 0\n #else\n #ifdef USE_ST_TIMESPEC\n+#define ST_ATIME_NSEC(st) ((unsigned int)((st).st_atimespec.tv_nsec))\n #define ST_CTIME_NSEC(st) ((unsigned int)((st).st_ctimespec.tv_nsec))\n #define ST_MTIME_NSEC(st) ((unsigned int)((st).st_mtimespec.tv_nsec))\n #else\n+#define ST_ATIME_NSEC(st) ((unsigned int)((st).st_atim.tv_nsec))\n #define ST_CTIME_NSEC(st) ((unsigned int)((st).st_ctim.tv_nsec))\n #define ST_MTIME_NSEC(st) ((unsigned int)((st).st_mtim.tv_nsec))\n #endif\ndiff --git a/compat/utimensat.c b/compat/utimensat.c\nnew file mode 100644\nindex 0000000000..e4c8e8d0b6\n--- /dev/null\n+++ b/compat/utimensat.c\n@@ -0,0 +1,39 @@\n+#include \"../git-compat-util.h\"\n+\n+int git_utimensat(int fd, const char *path, const struct timespec times[2], int flag)\n+{\n+\tstruct timeval tv[2];\n+\tstruct timeval *tvp = NULL;\n+\n+\tif (fd != AT_FDCWD) {\n+\t\terrno = ENOSYS;\n+\t\treturn -1;\n+\t}\n+\n+\tif (flag) {\n+\t\terrno = ENOSYS;\n+\t\treturn -1;\n+\t}\n+\n+\tif (times) {\n+\t\tfor (int i = 0; i < 2; i++) {\n+\t\t\tif (times[i].tv_nsec == UTIME_NOW) {\n+\t\t\t\tstruct timeval now;\n+\t\t\t\tgettimeofday(&now, NULL);\n+\t\t\t\ttv[i] = now;\n+\t\t\t} else if (times[i].tv_nsec == UTIME_OMIT) {\n+\t\t\t\tstruct stat st;\n+\t\t\t\tif (stat(path, &st) < 0)\n+\t\t\t\t\treturn -1;\n+\t\t\t\ttv[i].tv_sec = (i == 0) ? st.st_atime : st.st_mtime;\n+\t\t\t\ttv[i].tv_usec = (i == 0) ? ST_ATIME_NSEC(st) / 1000 : ST_MTIME_NSEC(st) / 1000;\n+\t\t\t} else {\n+\t\t\t\ttv[i].tv_sec = times[i].tv_sec;\n+\t\t\t\ttv[i].tv_usec = times[i].tv_nsec / 1000;\n+\t\t\t}\n+\t\t}\n+\t\ttvp = tv;\n+\t}\n+\n+\treturn utimes(path, tvp);\n+}\ndiff --git a/configure.ac b/configure.ac\nindex cfb50112bf..a37a53f5b5 100644\n--- a/configure.ac\n+++ b/configure.ac\n@@ -1146,6 +1146,12 @@ GIT_CHECK_FUNC(mkdtemp,\n [NO_MKDTEMP=YesPlease])\n GIT_CONF_SUBST([NO_MKDTEMP])\n #\n+# Define NO_UTIMENSAT if you don't have utimensat in the C library.\n+GIT_CHECK_FUNC(utimensat,\n+[NO_UTIMENSAT=],\n+[NO_UTIMENSAT=YesPlease])\n+GIT_CONF_SUBST([NO_UTIMENSAT])\n+#\n # Define NO_INITGROUPS if you don't have initgroups in the C library.\n GIT_CHECK_FUNC(initgroups,\n [NO_INITGROUPS=],\ndiff --git a/contrib/buildsystems/CMakeLists.txt b/contrib/buildsystems/CMakeLists.txt\nindex 8f56203f34..bb1d96802d 100644\n--- a/contrib/buildsystems/CMakeLists.txt\n+++ b/contrib/buildsystems/CMakeLists.txt\n@@ -380,9 +380,9 @@ set(function_checks\n \tstrcasestr memmem strlcpy strtoimax strtoumax strtoull\n \tsetenv mkdtemp poll pread memmem writev)\n \n-#unsetenv,hstrerror are incompatible with windows build\n+#unsetenv,hstrerror,utimensat are incompatible with windows build (provided by compat/mingw.c)\n if(NOT WIN32)\n-\tlist(APPEND function_checks unsetenv hstrerror)\n+\tlist(APPEND function_checks unsetenv hstrerror utimensat)\n endif()\n \n foreach(f ${function_checks})\n@@ -428,6 +428,10 @@ if(NOT HAVE_WRITEV)\n endif()\n \n if(NOT WIN32)\n+\tif(NOT HAVE_UTIMENSAT)\n+\t\tlist(APPEND compat_SOURCES compat/utimensat.c)\n+\tendif()\n+\n \tif(NOT HAVE_UNSETENV)\n \t\tlist(APPEND compat_SOURCES compat/unsetenv.c)\n \tendif()\ndiff --git a/meson.build b/meson.build\nindex d86f2acd2b..a98f63a46c 100644\n--- a/meson.build\n+++ b/meson.build\n@@ -1475,6 +1475,8 @@ else\n     'unsetenv' : ['unsetenv.c'],\n     # provided by compat/mingw.c.\n     'getpagesize' : [],\n+    # provided by compat/mingw.c.\n+    'utimensat' : ['utimensat.c'],\n   }\n \n   if get_option('b_sanitize').contains('address') or get_option('b_sanitize').contains('leak')\n-- \ngitgitgadget\n\n"},{"id":"551025","messageId":"6f5bd13d8e41e02af92df0274dbd435a395d6835.1787322203.git.gitgitgadget@gmail.com","threadId":"66205","inReplyTo":"pull.2209.git.1787322203.gitgitgadget@gmail.com","subject":"[PATCH 2/3] treewide: use utimensat(2) instead of legacy utime(3p)","fromName":"Alexey Samsonov via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-08-21T14:23:22Z","receivedAt":"2026-08-21T14:23:28Z","isPatch":true,"body":"From: Alexey Samsonov <vonosmas@gmail.com>\n\nNow that a compatibility wrapper for utimensat(2) has been introduced,\nmigrate all call sites across the codebase to use utimensat(2) instead of\nthe legacy utime(3p) interface:\n\n- In `commit-graph.c`, use utimensat(2) with UTIME_OMIT and the computed\n  timestamp `now` to bump the commit-graph modification time consistently\n  across all files without needing an extra stat(2) call to preserve atime.\n- In `copy.c`, use utimensat(2) to copy full sub-second access and\n  modification timestamps from the source file.\n- In `odb/source-packed.c`, `odb/source-loose.c`, and `object-file.c`,\n  use utimensat(2) with `struct timespec` to freshen file timestamps.\n- In `builtin/pack-objects.c`, update the pack timestamp with\n  utimensat(2).\n- In `rerere.c`, touch the postimage file with utimensat(2) passing NULL\n  to set both atime and mtime to current time.\n- In `t/helper/test-chmtime.c`, update file modification times using\n  utimensat(2).\n\nSigned-off-by: Alexey Samsonov <vonosmas@gmail.com>\n---\n builtin/pack-objects.c  | 12 +++++++-----\n commit-graph.c          | 17 ++++++-----------\n copy.c                  | 10 ++++++----\n object-file.c           | 12 +++++++-----\n odb/source-loose.c      | 10 +++++-----\n odb/source-packed.c     | 12 +++++++-----\n rerere.c                |  4 ++--\n t/helper/test-chmtime.c | 19 ++++++++++++-------\n 8 files changed, 52 insertions(+), 44 deletions(-)\n\ndiff --git a/builtin/pack-objects.c b/builtin/pack-objects.c\nindex 1ec5b6f206..35bdbc2b6a 100644\n--- a/builtin/pack-objects.c\n+++ b/builtin/pack-objects.c\n@@ -1438,11 +1438,13 @@ static void write_pack_file(void)\n \t\t\t} else if (!last_mtime) {\n \t\t\t\tlast_mtime = st.st_mtime;\n \t\t\t} else {\n-\t\t\t\tstruct utimbuf utb;\n-\t\t\t\tutb.actime = st.st_atime;\n-\t\t\t\tutb.modtime = --last_mtime;\n-\t\t\t\tif (utime(pack_tmp_name, &utb) < 0)\n-\t\t\t\t\twarning_errno(_(\"failed utime() on %s\"), pack_tmp_name);\n+\t\t\t\tstruct timespec times[2];\n+\t\t\t\ttimes[0].tv_sec = st.st_atime;\n+\t\t\t\ttimes[0].tv_nsec = ST_ATIME_NSEC(st);\n+\t\t\t\ttimes[1].tv_sec = --last_mtime;\n+\t\t\t\ttimes[1].tv_nsec = 0;\n+\t\t\t\tif (utimensat(AT_FDCWD, pack_tmp_name, times, 0) < 0)\n+\t\t\t\t\twarning_errno(_(\"failed utimensat() on %s\"), pack_tmp_name);\n \t\t\t}\n \n \t\t\tstrbuf_addf(&tmpname, \"%s-%s.\", base_name,\ndiff --git a/commit-graph.c b/commit-graph.c\nindex 49e8f63930..08bbba3d98 100644\n--- a/commit-graph.c\n+++ b/commit-graph.c\n@@ -2484,18 +2484,13 @@ static void mark_commit_graphs(struct write_commit_graph_context *ctx)\n {\n \tuint32_t i;\n \ttime_t now = time(NULL);\n+\tstruct timespec times[2] = {\n+\t\t{ .tv_nsec = UTIME_OMIT },\n+\t\t{ .tv_sec = now, .tv_nsec = 0 },\n+\t};\n \n-\tfor (i = ctx->num_commit_graphs_after - 1; i < ctx->num_commit_graphs_before; i++) {\n-\t\tstruct stat st;\n-\t\tstruct utimbuf updated_time;\n-\n-\t\tif (stat(ctx->commit_graph_filenames_before[i], &st) < 0)\n-\t\t\tcontinue;\n-\n-\t\tupdated_time.actime = st.st_atime;\n-\t\tupdated_time.modtime = now;\n-\t\tutime(ctx->commit_graph_filenames_before[i], &updated_time);\n-\t}\n+\tfor (i = ctx->num_commit_graphs_after - 1; i < ctx->num_commit_graphs_before; i++)\n+\t\tutimensat(AT_FDCWD, ctx->commit_graph_filenames_before[i], times, 0);\n }\n \n static void expire_commit_graphs(struct write_commit_graph_context *ctx)\ndiff --git a/copy.c b/copy.c\nindex 6074132050..39673f7829 100644\n--- a/copy.c\n+++ b/copy.c\n@@ -23,12 +23,14 @@ int copy_fd(int ifd, int ofd)\n static int copy_times(const char *dst, const char *src)\n {\n \tstruct stat st;\n-\tstruct utimbuf times;\n+\tstruct timespec times[2];\n \tif (stat(src, &st) < 0)\n \t\treturn -1;\n-\ttimes.actime = st.st_atime;\n-\ttimes.modtime = st.st_mtime;\n-\tif (utime(dst, &times) < 0)\n+\ttimes[0].tv_sec = st.st_atime;\n+\ttimes[0].tv_nsec = ST_ATIME_NSEC(st);\n+\ttimes[1].tv_sec = st.st_mtime;\n+\ttimes[1].tv_nsec = ST_MTIME_NSEC(st);\n+\tif (utimensat(AT_FDCWD, dst, times, 0) < 0)\n \t\treturn -1;\n \treturn 0;\n }\ndiff --git a/object-file.c b/object-file.c\nindex ec35c318bc..5e4ccb36d5 100644\n--- a/object-file.c\n+++ b/object-file.c\n@@ -69,15 +69,17 @@ const char *odb_loose_path(struct odb_source_loose *loose,\n /* Returns 1 if we have successfully freshened the file, 0 otherwise. */\n static int freshen_file(const char *fn, const time_t *mtime)\n {\n-\tstruct utimbuf times, *timesp = NULL;\n+\tstruct timespec times[2], *timesp = NULL;\n \n \tif (mtime) {\n-\t\ttimes.actime = *mtime;\n-\t\ttimes.modtime = *mtime;\n-\t\ttimesp = &times;\n+\t\ttimes[0].tv_sec = *mtime;\n+\t\ttimes[0].tv_nsec = 0;\n+\t\ttimes[1].tv_sec = *mtime;\n+\t\ttimes[1].tv_nsec = 0;\n+\t\ttimesp = times;\n \t}\n \n-\treturn !utime(fn, timesp);\n+\treturn !utimensat(AT_FDCWD, fn, timesp, 0);\n }\n \n /*\ndiff --git a/odb/source-loose.c b/odb/source-loose.c\nindex ef0e919277..1fdaa9f88f 100644\n--- a/odb/source-loose.c\n+++ b/odb/source-loose.c\n@@ -807,14 +807,14 @@ static int write_loose_object(struct odb_source_loose *loose,\n \tclose_loose_object(loose, fd, tmp_file.buf);\n \n \tif (mtime) {\n-\t\tstruct utimbuf utb = {\n-\t\t\t.actime = *mtime,\n-\t\t\t.modtime = *mtime,\n+\t\tstruct timespec times[2] = {\n+\t\t\t{ .tv_sec = *mtime },\n+\t\t\t{ .tv_sec = *mtime },\n \t\t};\n \n-\t\tif (utime(tmp_file.buf, &utb) < 0 &&\n+\t\tif (utimensat(AT_FDCWD, tmp_file.buf, times, 0) < 0 &&\n \t\t    !(flags & ODB_WRITE_OBJECT_SILENT))\n-\t\t\twarning_errno(_(\"failed utime() on %s\"), tmp_file.buf);\n+\t\t\twarning_errno(_(\"failed utimensat() on %s\"), tmp_file.buf);\n \t}\n \n \treturn finalize_object_file_flags(loose->base.odb->repo, tmp_file.buf, filename.buf,\ndiff --git a/odb/source-packed.c b/odb/source-packed.c\nindex 0890704e76..64871ff8da 100644\n--- a/odb/source-packed.c\n+++ b/odb/source-packed.c\n@@ -574,13 +574,15 @@ static int odb_source_packed_freshen_object(struct odb_source *source,\n \t\t\t\t\t    const time_t *mtime)\n {\n \tstruct odb_source_packed *packed = odb_source_packed_downcast(source);\n-\tstruct utimbuf times, *timesp = NULL;\n+\tstruct timespec times[2], *timesp = NULL;\n \tstruct pack_entry e;\n \n \tif (mtime) {\n-\t\ttimes.actime = *mtime;\n-\t\ttimes.modtime = *mtime;\n-\t\ttimesp = &times;\n+\t\ttimes[0].tv_sec = *mtime;\n+\t\ttimes[0].tv_nsec = 0;\n+\t\ttimes[1].tv_sec = *mtime;\n+\t\ttimes[1].tv_nsec = 0;\n+\t\ttimesp = times;\n \t}\n \n \tif (!find_pack_entry(packed, oid, &e))\n@@ -589,7 +591,7 @@ static int odb_source_packed_freshen_object(struct odb_source *source,\n \t\treturn 0;\n \tif (e.p->freshened)\n \t\treturn 1;\n-\tif (utime(e.p->pack_name, timesp))\n+\tif (utimensat(AT_FDCWD, e.p->pack_name, timesp, 0))\n \t\treturn 0;\n \te.p->freshened = 1;\n \ndiff --git a/rerere.c b/rerere.c\nindex 3d3bd0db16..b64771f57f 100644\n--- a/rerere.c\n+++ b/rerere.c\n@@ -658,8 +658,8 @@ static int merge(struct index_state *istate, const struct rerere_id *id, const c\n \t * A successful replay of recorded resolution.\n \t * Mark that \"postimage\" was used to help gc.\n \t */\n-\tif (utime(rerere_path(&buf, id, \"postimage\"), NULL) < 0)\n-\t\twarning_errno(_(\"failed utime() on '%s'\"),\n+\tif (utimensat(AT_FDCWD, rerere_path(&buf, id, \"postimage\"), NULL, 0) < 0)\n+\t\twarning_errno(_(\"failed utimensat() on '%s'\"),\n \t\t\t      rerere_path(&buf, id, \"postimage\"));\n \n \t/* Update \"path\" with the resolution */\ndiff --git a/t/helper/test-chmtime.c b/t/helper/test-chmtime.c\nindex 0e5538833a..a9e6eb78b8 100644\n--- a/t/helper/test-chmtime.c\n+++ b/t/helper/test-chmtime.c\n@@ -105,7 +105,8 @@ int cmd__chmtime(int argc, const char **argv)\n \n \tfor (; i < argc; i++) {\n \t\tstruct stat sb;\n-\t\tstruct utimbuf utb;\n+\t\tstruct timespec times[2];\n+\t\tint64_t mtime_sec;\n \t\tuintmax_t mtime;\n \n \t\tif (stat(argv[i], &sb) < 0) {\n@@ -123,22 +124,26 @@ int cmd__chmtime(int argc, const char **argv)\n \t\t}\n #endif\n \n-\t\tutb.actime = sb.st_atime;\n-\t\tutb.modtime = set_eq ? set_time : sb.st_mtime + set_time;\n+\t\tmtime_sec = set_eq ? set_time : sb.st_mtime + set_time;\n \n-\t\tmtime = utb.modtime < 0 ? 0: utb.modtime;\n+\t\ttimes[0].tv_sec = sb.st_atime;\n+\t\ttimes[0].tv_nsec = ST_ATIME_NSEC(sb);\n+\t\ttimes[1].tv_sec = mtime_sec;\n+\t\ttimes[1].tv_nsec = 0;\n+\n+\t\tmtime = mtime_sec < 0 ? 0 : mtime_sec;\n \t\tif (get) {\n \t\t\tprintf(\"%\"PRIuMAX\"\\n\", mtime);\n \t\t} else if (verbose) {\n \t\t\tprintf(\"%\"PRIuMAX\"\\t%s\\n\", mtime, argv[i]);\n \t\t}\n \n-\t\tif (utb.modtime != sb.st_mtime && utime(argv[i], &utb) < 0) {\n+\t\tif (mtime_sec != sb.st_mtime && utimensat(AT_FDCWD, argv[i], times, 0) < 0) {\n #ifdef GIT_WINDOWS_NATIVE\n \t\t\tif (S_ISDIR(sb.st_mode)) {\n \t\t\t\t/*\n-\t\t\t\t * NEEDSWORK: The Windows version of `utime()`\n-\t\t\t\t * (aka `mingw_utime()`) does not correctly\n+\t\t\t\t * NEEDSWORK: The Windows version of `utimensat()`\n+\t\t\t\t * (aka `mingw_utimensat()`) does not correctly\n \t\t\t\t * handle directory arguments, since it uses\n \t\t\t\t * `_wopen()`.  Ignore it for now since this\n \t\t\t\t * is just a test.\n-- \ngitgitgadget\n\n"},{"id":"551026","messageId":"9c737bd600bac6b6645a10f6b36951985a99262d.1787322203.git.gitgitgadget@gmail.com","threadId":"66205","inReplyTo":"pull.2209.git.1787322203.gitgitgadget@gmail.com","subject":"[PATCH 3/3] compat/posix: drop legacy <utime.h> header and shims","fromName":"Alexey Samsonov via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-08-21T14:23:23Z","receivedAt":"2026-08-21T14:23:29Z","isPatch":true,"body":"From: Alexey Samsonov <vonosmas@gmail.com>\n\nWith all callers across the codebase now converted to utimensat(2), we no\nlonger need to include the legacy <utime.h> header in `compat/posix.h`.\n\nRemove `#include <utime.h>` from `compat/posix.h` and test fixtures,\nremove `mingw_utime()` from `compat/mingw.c`, and delete the legacy\nheader shims in `compat/vcbuild/include/`.\n\nSigned-off-by: Alexey Samsonov <vonosmas@gmail.com>\n---\n compat/mingw-posix.h               |  2 --\n compat/mingw.c                     | 16 --------------\n compat/posix.h                     |  1 -\n compat/vcbuild/include/sys/utime.h | 34 ------------------------------\n compat/vcbuild/include/utime.h     |  1 -\n t/helper/test-chmtime.c            |  1 -\n t/t4051/includes.c                 |  1 -\n 7 files changed, 56 deletions(-)\n delete mode 100644 compat/vcbuild/include/sys/utime.h\n delete mode 100644 compat/vcbuild/include/utime.h\n\ndiff --git a/compat/mingw-posix.h b/compat/mingw-posix.h\nindex aab91d76db..286ca24002 100644\n--- a/compat/mingw-posix.h\n+++ b/compat/mingw-posix.h\n@@ -384,8 +384,6 @@ int mingw_fstat(int fd, struct stat *buf);\n #define lstat mingw_lstat\n \n \n-int mingw_utime(const char *file_name, const struct utimbuf *times);\n-#define utime mingw_utime\n int mingw_utimensat(int fd, const char *path, const struct timespec times[2], int flag);\n #define utimensat mingw_utimensat\n size_t mingw_strftime(char *s, size_t max,\ndiff --git a/compat/mingw.c b/compat/mingw.c\nindex d09a976191..e2ec44fdd2 100644\n--- a/compat/mingw.c\n+++ b/compat/mingw.c\n@@ -1480,22 +1480,6 @@ revert_attrs:\n \treturn rc;\n }\n \n-int mingw_utime(const char *file_name, const struct utimbuf *times)\n-{\n-\tstruct timespec ts[2];\n-\tstruct timespec *tsp = NULL;\n-\n-\tif (times) {\n-\t\tts[0].tv_sec = times->actime;\n-\t\tts[0].tv_nsec = 0;\n-\t\tts[1].tv_sec = times->modtime;\n-\t\tts[1].tv_nsec = 0;\n-\t\ttsp = ts;\n-\t}\n-\n-\treturn mingw_utimensat(AT_FDCWD, file_name, tsp, 0);\n-}\n-\n #undef strftime\n size_t mingw_strftime(char *s, size_t max,\n \t\t      const char *format, const struct tm *tm)\ndiff --git a/compat/posix.h b/compat/posix.h\nindex 3cac1751aa..435ed90f56 100644\n--- a/compat/posix.h\n+++ b/compat/posix.h\n@@ -123,7 +123,6 @@\n #include <signal.h>\n #include <assert.h>\n #include <regex.h>\n-#include <utime.h>\n #include <syslog.h>\n #if !defined(NO_POLL_H)\n #include <poll.h>\ndiff --git a/compat/vcbuild/include/sys/utime.h b/compat/vcbuild/include/sys/utime.h\ndeleted file mode 100644\nindex 582589c70a..0000000000\n--- a/compat/vcbuild/include/sys/utime.h\n+++ /dev/null\n@@ -1,34 +0,0 @@\n-#ifndef\t_UTIME_H_\n-#define\t_UTIME_H_\n-/*\n- * UTIME.H\n- * This file has no copyright assigned and is placed in the Public Domain.\n- * This file is a part of the mingw-runtime package.\n- *\n- * The mingw-runtime package and its code is distributed in the hope that it\n- * will be useful but WITHOUT ANY WARRANTY.  ALL WARRANTIES, EXPRESSED OR\n- * IMPLIED ARE HEREBY DISCLAIMED.  This includes but is not limited to\n- * warranties of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.\n- *\n- * You are free to use this package and its code without limitation.\n- */\n-\n-/*\n- * Structure used by _utime function.\n- */\n-struct _utimbuf\n-{\n-\ttime_t\tactime;\t\t/* Access time */\n-\ttime_t\tmodtime;\t/* Modification time */\n-};\n-\n-#ifndef\t_NO_OLDNAMES\n-/* NOTE: Must be the same as _utimbuf above. */\n-struct utimbuf\n-{\n-\ttime_t\tactime;\n-\ttime_t\tmodtime;\n-};\n-#endif\t/* Not _NO_OLDNAMES */\n-\n-#endif\ndiff --git a/compat/vcbuild/include/utime.h b/compat/vcbuild/include/utime.h\ndeleted file mode 100644\nindex 8285f38fde..0000000000\n--- a/compat/vcbuild/include/utime.h\n+++ /dev/null\n@@ -1 +0,0 @@\n-#include <sys/utime.h>\ndiff --git a/t/helper/test-chmtime.c b/t/helper/test-chmtime.c\nindex a9e6eb78b8..295f55cf47 100644\n--- a/t/helper/test-chmtime.c\n+++ b/t/helper/test-chmtime.c\n@@ -38,7 +38,6 @@\n  */\n #include \"test-tool.h\"\n #include \"git-compat-util.h\"\n-#include <utime.h>\n \n static const char usage_str[] =\n \t\"(-v|--verbose|-g|--get) (+|=|=+|=-|-)<seconds> <file>...\";\ndiff --git a/t/t4051/includes.c b/t/t4051/includes.c\nindex efc68f8bf6..4861f6657b 100644\n--- a/t/t4051/includes.c\n+++ b/t/t4051/includes.c\n@@ -15,6 +15,5 @@\n #include <signal.h>\n #include <assert.h>\n #include <regex.h>\n-#include <utime.h>\n #include <syslog.h>\n #include <End.h>\n-- \ngitgitgadget\n"},{"id":"551034","messageId":"xmqqo6evpeds.fsf@gitster.g","threadId":"66205","inReplyTo":"pull.2209.git.1787322203.gitgitgadget@gmail.com","subject":"Re: [PATCH 0/3] treewide: migrate from legacy utime.h to utimensat","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2026-08-21T17:33:35Z","receivedAt":"2026-08-21T17:33:38Z","isPatch":true,"body":"\"Alexey Samsonov via GitGitGadget\" <gitgitgadget@gmail.com> writes:\n\n> utime() function for setting access/modification time for files (and a\n> corresponding <utime.h> header) have been officially removed from POSIX\n> starting from POSIX.1-2024. While existing system library implementations\n> still provide this function for compatibility reasons, its implementation\n> may be removed in the future, or otherwise degrade over time. Some newer\n> libc implementations (e.g. LLVM-libc, currently under development) don't\n> provide utime() function at all.\n>\n> This PR switches the git codebase to recommended alternative: utimensat()\n> POSIX function (which supports nanosecond-level precision) from <fcntl.h>,\n> and, as a possible fallback for older systems compatibility, utimes()\n> function from <sys/stat.h>. It also provides the corresponding MinGW\n> wrapper.\n>\n> The alternative is to unconditionally use utimes() where possible, but given\n> that utimensat is available in glibc starting from 2007, and on BSD systems\n> since 2012 or so, it makes sense to use the newer variant by default.\n\nI hear that Apple has supported it since macOS 10.13 High Sierra,\nwhich came out in 2017 and reached EOL in 2020, so we should be safe\nthere as well.\n"},{"id":"551052","messageId":"aonIVn-ZQoMKWCAd@fruit.crustytoothpaste.net","threadId":"66205","inReplyTo":"pull.2209.git.1787322203.gitgitgadget@gmail.com","subject":"Re: [PATCH 0/3] treewide: migrate from legacy utime.h to utimensat","fromName":"brian m. carlson","fromEmail":"sandals@crustytoothpaste.net","sentAt":"2026-08-22T16:03:35Z","receivedAt":"2026-08-22T16:03:43Z","isPatch":true,"body":"On 2026-08-21 at 14:23:20, Alexey Samsonov via GitGitGadget wrote:\n> utime() function for setting access/modification time for files (and a\n> corresponding <utime.h> header) have been officially removed from POSIX\n> starting from POSIX.1-2024. While existing system library implementations\n> still provide this function for compatibility reasons, its implementation\n> may be removed in the future, or otherwise degrade over time. Some newer\n> libc implementations (e.g. LLVM-libc, currently under development) don't\n> provide utime() function at all.\n> \n> This PR switches the git codebase to recommended alternative: utimensat()\n> POSIX function (which supports nanosecond-level precision) from <fcntl.h>,\n> and, as a possible fallback for older systems compatibility, utimes()\n> function from <sys/stat.h>. It also provides the corresponding MinGW\n> wrapper.\n\nI seem to remember that we cannot use the *at functions because of\nWindows and the fact that it doesn't offer the proper semantics.  I'm\ncurious as to how you did this, but I didn't read the series because of\nthe below.\n\n> The alternative is to unconditionally use utimes() where possible, but given\n> that utimensat is available in glibc starting from 2007, and on BSD systems\n> since 2012 or so, it makes sense to use the newer variant by default.\n> \n> No behavior changes is intended or expected (except for Git explicitly\n> passing nanosecond-precision timestamps to kernel, where previously only\n> second-level precision was used).\n> \n> This change is generated by Gemini Flash from Antigravity, but all the code\n> has been manually verified by me, and, where applicable, adjusted to match\n> the existing behavior as closely as possible.\n\nUnfortunately, I don't think that's allowed.  From SubmittingPatches[0]:\n\n    The Developer's Certificate of Origin requires contributors to certify\n    that they know the origin of their contributions to the project and\n    that they have the right to submit it under the project's license.\n    It's not yet clear that this can be legally satisfied when submitting\n    significant amount of content that has been generated by AI tools.\n\nI therefore haven't read this series to avoid being influenced by code\nwe're not allowed to include.\n\n[0] https://git-scm.com/docs/SubmittingPatches#ai\n-- \nbrian m. carlson (they/them)\nToronto, Ontario, CA\n"},{"id":"551055","messageId":"xmqqzeyeujde.fsf@gitster.g","threadId":"66205","inReplyTo":"aonIVn-ZQoMKWCAd@fruit.crustytoothpaste.net","subject":"Re: [PATCH 0/3] treewide: migrate from legacy utime.h to utimensat","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2026-08-22T17:59:09Z","receivedAt":"2026-08-22T17:59:11Z","isPatch":true,"body":"\"brian m. carlson\" <sandals@crustytoothpaste.net> writes:\n\n> On 2026-08-21 at 14:23:20, Alexey Samsonov via GitGitGadget wrote:\n>> This change is generated by Gemini Flash from Antigravity, but all the code\n>> has been manually verified by me, and, where applicable, adjusted to match\n>> the existing behavior as closely as possible.\n>\n> Unfortunately, I don't think that's allowed.  From SubmittingPatches[0]:\n>\n>     The Developer's Certificate of Origin requires contributors to certify\n>     that they know the origin of their contributions to the project and\n>     that they have the right to submit it under the project's license.\n>     It's not yet clear that this can be legally satisfied when submitting\n>     significant amount of content that has been generated by AI tools.\n>\n> I therefore haven't read this series to avoid being influenced by code\n> we're not allowed to include.\n>\n> [0] https://git-scm.com/docs/SubmittingPatches#ai\n\nYour stance, as I understand it, is that Alexey's DCO is not valid\nbecause, acting as a copy editor of Antigravity/Gemini's work,\nAlexey cannot possibly know where the code was copied from.  And we\ncannot accept work that is not covered by a valid DCO.\n\nI think that is a much more prudent attitude than being cavalier\nabout legal issues.  I used to think, \"Hey, the person claims in the\nDCO that the code is appropriately licensed, so if it turns out to\nbe a false claim later, that is his or her problem, not ours.\"\n\nBut that is not how things work.\n\nIf work submitted under a DCO later turns out to be based on\nsomething we cannot legally use, the submitter may of course be in\ntrouble, but we would also need to bear the cost of ripping it out;\nthe later we discover the problem, the more substantial the effort\nnecessary to deal with the fallout will be.\n\nStepping back a bit, though, is the situation really all that\ndifferent between a relatively new author who discloses their use of\nAI and another author similarly unknown to us who claims it is all\ntheir own work?  Either way, if the code turns out to be unusable,\nwe would still be on the hook for participating in the infringement\nand would bear the cost of ripping it out.\n\nWhat worries me a bit is that there may not be much difference\nbetween \"you said that you relayed AI output, so we won't talk to\nyou\" and \"we do not know you well enough to trust you, so we won't\ntalk to you\".\n\n"},{"id":"551058","messageId":"aooRdiVdjovWSFiG@fruit.crustytoothpaste.net","threadId":"66205","inReplyTo":"xmqqzeyeujde.fsf@gitster.g","subject":"Re: [PATCH 0/3] treewide: migrate from legacy utime.h to utimensat","fromName":"brian m. carlson","fromEmail":"sandals@crustytoothpaste.net","sentAt":"2026-08-22T21:15:35Z","receivedAt":"2026-08-22T21:15:38Z","isPatch":true,"body":"On 2026-08-22 at 17:59:09, Junio C Hamano wrote:\n> \"brian m. carlson\" <sandals@crustytoothpaste.net> writes:\n> \n> > On 2026-08-21 at 14:23:20, Alexey Samsonov via GitGitGadget wrote:\n> >> This change is generated by Gemini Flash from Antigravity, but all the code\n> >> has been manually verified by me, and, where applicable, adjusted to match\n> >> the existing behavior as closely as possible.\n> >\n> > Unfortunately, I don't think that's allowed.  From SubmittingPatches[0]:\n> >\n> >     The Developer's Certificate of Origin requires contributors to certify\n> >     that they know the origin of their contributions to the project and\n> >     that they have the right to submit it under the project's license.\n> >     It's not yet clear that this can be legally satisfied when submitting\n> >     significant amount of content that has been generated by AI tools.\n> >\n> > I therefore haven't read this series to avoid being influenced by code\n> > we're not allowed to include.\n> >\n> > [0] https://git-scm.com/docs/SubmittingPatches#ai\n> \n> Your stance, as I understand it, is that Alexey's DCO is not valid\n> because, acting as a copy editor of Antigravity/Gemini's work,\n> Alexey cannot possibly know where the code was copied from.  And we\n> cannot accept work that is not covered by a valid DCO.\n\nYes.  We know that in some cases LLMs regurgitate code that is\nsubstantially similar to training inputs and we don't know what the\nlegal status of the output of an LLM is, especially since there is\nactive litigation around the world.\n\nThe DCO was invented to provide a legal assertion by an author that they\nare only submitting code they legally have the right to submit and I\ndon't think there's enough legal clarity for us to know that with an\nLLM.\n\n> I think that is a much more prudent attitude than being cavalier\n> about legal issues.  I used to think, \"Hey, the person claims in the\n> DCO that the code is appropriately licensed, so if it turns out to\n> be a false claim later, that is his or her problem, not ours.\"\n> \n> But that is not how things work.\n\nIt's my understanding that in many places there's a difference between\nknowingly doing something and doing something without knowledge.  For\nexample, Canada's Copyright Act uses the text, \"that the person knows or\nshould have known infringes copyright\".\n\nSo we do have more of a legal problem if we knowingly distribute code\nthat infringes copyright or which we suspect may do so.\n\n> If work submitted under a DCO later turns out to be based on\n> something we cannot legally use, the submitter may of course be in\n> trouble, but we would also need to bear the cost of ripping it out;\n> the later we discover the problem, the more substantial the effort\n> necessary to deal with the fallout will be.\n\nYes, that's true.  We still have the fallout and issues in terms of\nproject management to deal with, but fewer legal problems.\n\n> Stepping back a bit, though, is the situation really all that\n> different between a relatively new author who discloses their use of\n> AI and another author similarly unknown to us who claims it is all\n> their own work?  Either way, if the code turns out to be unusable,\n> we would still be on the hook for participating in the infringement\n> and would bear the cost of ripping it out.\n> \n> What worries me a bit is that there may not be much difference\n> between \"you said that you relayed AI output, so we won't talk to\n> you\" and \"we do not know you well enough to trust you, so we won't\n> talk to you\".\n\nIf somebody comes to our project and lies to us about the provenance of\ntheir work, that's very serious.  Saying, \"I wrote this with AI,\" when\nwe don't allow AI is being honest and ethical and disclosing relevant\ndetails to the project.  It may be that we can't accept their code for\nthat reason, but they have participated in the project in good faith.\nWe could certainly accept other patches from such a person written\nwithout AI.\n\nBut if a contributor misleads us about the origin of their code, whether\nit came from AI or was taken without credit from another project,\nthen they're not at all acting in good faith and we will likely not\nallow them to continue to contribute to the project.  Moreover, they\nwill also be unwelcome in most other projects as well because they'll be\nviewed as dishonest.\n\nThat doesn't affect whether we end up having negative consequences from\ndistributing that code, true.  But at some point, we have to trust that\nmost people are honest or our community and society break down.\n-- \nbrian m. carlson (they/them)\nToronto, Ontario, CA\n"},{"id":"551072","messageId":"aor07LvsXOy1p7vh@wyuan.org","threadId":"66205","inReplyTo":"xmqqzeyeujde.fsf@gitster.g","subject":"Re: [PATCH 0/3] treewide: migrate from legacy utime.h to utimensat","fromName":"Weijie Yuan","fromEmail":"wy@wyuan.org","sentAt":"2026-08-23T13:26:04Z","receivedAt":"2026-08-23T13:26:14Z","isPatch":true,"body":"[+cc Johannes Schindelin]\n\nOn Sat, Aug 22, 2026 at 10:59:09AM -0700, Junio C Hamano wrote:\n> \"brian m. carlson\" <sandals@crustytoothpaste.net> writes:\n> \n> > On 2026-08-21 at 14:23:20, Alexey Samsonov via GitGitGadget wrote:\n> >> This change is generated by Gemini Flash from Antigravity, but all the code\n> >> has been manually verified by me, and, where applicable, adjusted to match\n> >> the existing behavior as closely as possible.\n> >\n> > Unfortunately, I don't think that's allowed.  From SubmittingPatches[0]:\n> >\n> >     The Developer's Certificate of Origin requires contributors to certify\n> >     that they know the origin of their contributions to the project and\n> >     that they have the right to submit it under the project's license.\n> >     It's not yet clear that this can be legally satisfied when submitting\n> >     significant amount of content that has been generated by AI tools.\n> >\n> > I therefore haven't read this series to avoid being influenced by code\n> > we're not allowed to include.\n> >\n> > [0] https://git-scm.com/docs/SubmittingPatches#ai\n> \n> Your stance, as I understand it, is that Alexey's DCO is not valid\n> because, acting as a copy editor of Antigravity/Gemini's work,\n> Alexey cannot possibly know where the code was copied from.  And we\n> cannot accept work that is not covered by a valid DCO.\n> \n> I think that is a much more prudent attitude than being cavalier\n> about legal issues.  I used to think, \"Hey, the person claims in the\n> DCO that the code is appropriately licensed, so if it turns out to\n> be a false claim later, that is his or her problem, not ours.\"\n> \n> But that is not how things work.\n> \n> If work submitted under a DCO later turns out to be based on\n> something we cannot legally use, the submitter may of course be in\n> trouble, but we would also need to bear the cost of ripping it out;\n> the later we discover the problem, the more substantial the effort\n> necessary to deal with the fallout will be.\n\nSorry to interject here, but I seem to remember that dscho already has a\nfew commits with an Assisted-by trailer that have made it into master.\nI´m not entirely sure what kind of assistance he received either, but as\nyou suggest, it seems better to mention this here sooner rather than\nlater.\n\n(I also mentioned this part here [1], with full respect to Johannes)\n\n> Stepping back a bit, though, is the situation really all that\n> different between a relatively new author who discloses their use of\n> AI and another author similarly unknown to us who claims it is all\n> their own work?  Either way, if the code turns out to be unusable,\n> we would still be on the hook for participating in the infringement\n> and would bear the cost of ripping it out.\n\n> What worries me a bit is that there may not be much difference\n> between \"you said that you relayed AI output, so we won't talk to\n> you\" and \"we do not know you well enough to trust you, so we won't\n> talk to you\".\n\nBut I think that, from Linus's point of view, the chain of trust matters\nmore than whether AI was used in the first place:\n\n| So AI giveth, and AI taketh away. But the basic issue shouldn't be AI\n| per se, it should be that notion of \"trust\". [2]\n\nOf course, I also understand that the Git community doesn't need to\ncompletely follow the rules from kernel community.\n\nThanks.\n\n[1] https://lore.kernel.org/git/aorxVo_6_U1ceaKm@wyuan.org/\n[2] https://lore.kernel.org/all/CAHk-=wgbGarE7Ozw4VG6oUKDj9pk-8DRoDiX00bo1MwEMm9UWQ@mail.gmail.com/\n"},{"id":"551076","messageId":"xmqqa4qcvp1o.fsf@gitster.g","threadId":"66205","inReplyTo":"aooRdiVdjovWSFiG@fruit.crustytoothpaste.net","subject":"Re: [PATCH 0/3] treewide: migrate from legacy utime.h to utimensat","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2026-08-23T15:23:31Z","receivedAt":"2026-08-23T15:23:33Z","isPatch":true,"body":"\"brian m. carlson\" <sandals@crustytoothpaste.net> writes:\n\n> On 2026-08-22 at 17:59:09, Junio C Hamano wrote:\n>> \"brian m. carlson\" <sandals@crustytoothpaste.net> writes:\n>> \n>> > I therefore haven't read this series to avoid being influenced by code\n>> > we're not allowed to include.\n\nMore on this a bit later...\n\n> So we do have more of a legal problem if we knowingly distribute code\n> that infringes copyright or which we suspect may do so.\n\nProjects like the Linux kernel ask you to disclose your use of AI\n(and have other requirements on your use), but I haven't read\nexactly why they want it.  I wish they instead said, \"We do not want\nto be blamed for knowingly infringing.  While we do not particularly\nencourage you to use AI, if you use one, do not tell us\" ;-).\n\n> If somebody comes to our project and lies to us about the provenance of\n> their work, that's very serious.  Saying, \"I wrote this with AI,\" when\n> we don't allow AI is being honest and ethical and disclosing relevant\n> details to the project.  It may be that we can't accept their code for\n> that reason, but they have participated in the project in good faith.\n> We could certainly accept other patches from such a person written\n> without AI.\n\nBut that contradicts what you yourself did, doesn't it?  An honest\ndeveloper who discloses their use of AI admits that their eyes are\nalready contaminated by AI output, because they did not avoid being\ninfluenced as you did.  So are they unwelcome now?\n\nStepping back a bit, even before the AI era, a human developer may\nhave seen code elsewhere that they are not allowed to include in a\nparticular project.  Learning from what others did is the nature of\nour work, and it is inevitable.  Is it reasonable for BSD-only\nprojects to declare that those who are familiar with constructs that\nappear in Git code after working on it are unwelcome, because their\ncontributions may be contaminated by what they have seen in a GPLed\nproject?\n\nI very much appreciate that you are treading very cautiously on the\nsafer side, but I hope that the actual balance lies on a somewhat\nmore practical side that trusts humans.\n\n> That doesn't affect whether we end up having negative consequences from\n> distributing that code, true.  But at some point, we have to trust that\n> most people are honest or our community and society break down.\n\nTrue. True.\n\nThanks.\n"},{"id":"551077","messageId":"xmqq5x10vowf.fsf@gitster.g","threadId":"66205","inReplyTo":"aor07LvsXOy1p7vh@wyuan.org","subject":"Re: [PATCH 0/3] treewide: migrate from legacy utime.h to utimensat","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2026-08-23T15:26:40Z","receivedAt":"2026-08-23T15:26:42Z","isPatch":true,"body":"Weijie Yuan <wy@wyuan.org> writes:\n\n> Sorry to interject here, but I seem to remember that dscho already has a\n> few commits with an Assisted-by trailer that have made it into master.\n> I´m not entirely sure what kind of assistance he received either, but as\n> you suggest, it seems better to mention this here sooner rather than\n> later.\n\nWe know Johannes well enough to trust that his patches were sent\nwith sufficient due diligence.  So...?\n"},{"id":"551080","messageId":"aosVkqwcsmAWrDr6@wyuan.org","threadId":"66205","inReplyTo":"xmqq5x10vowf.fsf@gitster.g","subject":"Re: [PATCH 0/3] treewide: migrate from legacy utime.h to utimensat","fromName":"Weijie Yuan","fromEmail":"wy@wyuan.org","sentAt":"2026-08-23T15:45:22Z","receivedAt":"2026-08-23T15:45:28Z","isPatch":true,"body":"On Sun, Aug 23, 2026 at 08:26:40AM -0700, Junio C Hamano wrote:\n> Weijie Yuan <wy@wyuan.org> writes:\n> \n> > Sorry to interject here, but I seem to remember that dscho already has a\n> > few commits with an Assisted-by trailer that have made it into master.\n> > I´m not entirely sure what kind of assistance he received either, but as\n> > you suggest, it seems better to mention this here sooner rather than\n> > later.\n> \n> We know Johannes well enough to trust that his patches were sent\n> with sufficient due diligence.  So...?\n\n<xmqqzeyeujde.fsf@gitster.g>:\n> If work submitted under a DCO later turns out to be based on\n> something we cannot legally use, the submitter may of course be in\n> trouble, but we would also need to bear the cost of ripping it out;\n> the later we discover the problem, the more substantial the effort\n> necessary to deal with the fallout will be.\n\nWhat I meant is that you said we should be wary of content that might\ncarry legal risks, if I understand correctly. And as far as I remember,\nJohannes is the only person recently who has proactively disclosed that\nhis patches were AI-assisted. I appreciate that disclosure, so I was\nsimply pointing it out. Of course, I have no doubt about the quality of\nhis patches.\n\nSo what I mean is that we have already had cases where people\nvoluntarily disclosed their use of AI, but there did not seem to be much\ndiscussion about it at the time. This time, Brian brought the issue up\nfor discussion, and I really appreciate both of you doing so.\n\nThanks.\n"},{"id":"551101","messageId":"xmqqfr04thhe.fsf@gitster.g","threadId":"66205","inReplyTo":"aosVkqwcsmAWrDr6@wyuan.org","subject":"Re: [PATCH 0/3] treewide: migrate from legacy utime.h to utimensat","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2026-08-24T01:49:49Z","receivedAt":"2026-08-24T01:49:52Z","isPatch":true,"body":"Weijie Yuan <wy@wyuan.org> writes:\n\n>> We know Johannes well enough to trust that his patches were sent\n>> with sufficient due diligence.  So...?\n>\n> <xmqqzeyeujde.fsf@gitster.g>:\n>> If work submitted under a DCO later turns out to be based on\n>> something we cannot legally use, the submitter may of course be in\n>> trouble, but we would also need to bear the cost of ripping it out;\n>> the later we discover the problem, the more substantial the effort\n>> necessary to deal with the fallout will be.\n>\n> What I meant is that you said we should be wary of content that might\n> carry legal risks,...\n\nI am not sure what your point is.  Is there any part in \"we trust\nDscho well enough to trust that he sent them with sufficient due\ndiligence\" that was hard for you to understand?\n\n"},{"id":"551127","messageId":"aow2uARRxSQZR4wB@wyuan.org","threadId":"66205","inReplyTo":"xmqqfr04thhe.fsf@gitster.g","subject":"Re: [PATCH 0/3] treewide: migrate from legacy utime.h to utimensat","fromName":"Weijie Yuan","fromEmail":"wy@wyuan.org","sentAt":"2026-08-24T12:19:04Z","receivedAt":"2026-08-24T12:19:21Z","isPatch":true,"body":"On Sun, Aug 23, 2026 at 06:49:49PM -0700, Junio C Hamano wrote:\n> Weijie Yuan <wy@wyuan.org> writes:\n> \n> >> We know Johannes well enough to trust that his patches were sent\n> >> with sufficient due diligence.  So...?\n> >\n> > <xmqqzeyeujde.fsf@gitster.g>:\n> >> If work submitted under a DCO later turns out to be based on\n> >> something we cannot legally use, the submitter may of course be in\n> >> trouble, but we would also need to bear the cost of ripping it out;\n> >> the later we discover the problem, the more substantial the effort\n> >> necessary to deal with the fallout will be.\n> >\n> > What I meant is that you said we should be wary of content that might\n> > carry legal risks,...\n> \n> I am not sure what your point is.  Is there any part in \"we trust\n> Dscho well enough to trust that he sent them with sufficient due\n> diligence\" that was hard for you to understand?\n\nApologies, and please forget it. I must be feeling dizzy.\n\nThanks.\n"},{"id":"551137","messageId":"aoxkQHCGJENGxV2I@wyuan.org","threadId":"66205","inReplyTo":"xmqqfr04thhe.fsf@gitster.g","subject":"Re: [PATCH 0/3] treewide: migrate from legacy utime.h to utimensat","fromName":"Weijie Yuan","fromEmail":"wy@wyuan.org","sentAt":"2026-08-24T15:33:20Z","receivedAt":"2026-08-24T15:33:39Z","isPatch":true,"body":"On Sun, Aug 23, 2026 at 06:49:49PM -0700, Junio C Hamano wrote:\n> Weijie Yuan <wy@wyuan.org> writes:\n> \n> >> We know Johannes well enough to trust that his patches were sent\n> >> with sufficient due diligence.  So...?\n> >\n> > <xmqqzeyeujde.fsf@gitster.g>:\n> >> If work submitted under a DCO later turns out to be based on\n> >> something we cannot legally use, the submitter may of course be in\n> >> trouble, but we would also need to bear the cost of ripping it out;\n> >> the later we discover the problem, the more substantial the effort\n> >> necessary to deal with the fallout will be.\n> >\n> > What I meant is that you said we should be wary of content that might\n> > carry legal risks,...\n> \n> I am not sure what your point is.  Is there any part in \"we trust\n> Dscho well enough to trust that he sent them with sufficient due\n> diligence\" that was hard for you to understand?\n\nSorry, I think I failed to make my actual question clear in my previous\nreplies.\n\nI do understand, and agree with, your point that you trust Johannes to\nhave submitted his patches with sufficient due diligence. I was not\ntrying to question Johannes or your trust in him.\n\nWhat I was trying to understand is how that fits with the particular DCO\nconcern being discussed here.\n\nYou pointed out that if something submitted under the DCO later turns\nout to be based on material we cannot legally use, the project also\nbears the cost of removing it, and that the fallout becomes worse the\nlater such a problem is discovered.\n\nAs I understand brian's concern, if a significant amount of a\ncontribution is generated by an AI tool, there may be uncertainty over\nwhether the submitter can make the DCO certification with sufficient\nconfidence.\n\nThat is why Johannes's existing commits with an Assisted-by trailer\ncame to mind. I am not claiming that those commits necessarily contain\nAI-generated content of the kind brian is concerned about; I do not know\nwhat the assistance actually consisted of.\n\nBut if the disclosed assistance did involve generated content of that\nkind, wouldn't the same DCO question arise? And if we do not know\nwhether it did, isn't that the sort of question that, following your\npoint above, would be better clarified sooner rather than later?\n\nAt the same time, I can also see the point behind your:\n\n\"if you use one, do not tell us\" ;-)\n\nThinking about it from that angle also makes me wonder about\nAssisted-by trailers themselves. If I understand the point behind\n\"if you use one, do not tell us\" correctly, then perhaps we should\nsimply not encourage Assisted-by: LLM trailers, since such a trailer\nexplicitly records the very fact that we might prefer the project not\nto be told about.\n\nOf course, I am simply worried that an Assisted-by trailer might\ncreate some legal risk. I am not a lawyer, though, so I do not know\nwhether that concern is actually well-founded.\n\nOn the other hand, I can also understand why the kernel community made\na different trade-off and prefers disclosure. Knowing that a tool was\ninvolved gives the maintainer additional information, and the maintainer\ncan then decide according to their own judgment whether that information\nshould affect how the patch is handled. (possibly there are other reasons)\n\nThat was what I was trying, rather unsuccessfully, to get at before. I\nam sorry that my earlier replies made it sound as though I was singling\nout Johannes as a problematic case.\n\nSorry again for the confusion and the noise.\n\nThanks,\nWeijie\n"},{"id":"551140","messageId":"xmqqjypfqz9e.fsf@gitster.g","threadId":"66205","inReplyTo":"aoxkQHCGJENGxV2I@wyuan.org","subject":"Re: [PATCH 0/3] treewide: migrate from legacy utime.h to utimensat","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2026-08-24T16:06:21Z","receivedAt":"2026-08-24T16:06:23Z","isPatch":true,"body":"Weijie Yuan <wy@wyuan.org> writes:\n\n> What I was trying to understand is how that fits with the particular DCO\n> concern being discussed here.\n\nYou may never be able to tell where the AI output came from, but you\ncan see if the updated code has resemblance to fixes we applied in\nthe past to correct similar problems, for example.  After all, you\nyourself without help by AI can copy our code to your patch to\nenhance our code, and that is perfectly legit.\n\nTake for example 5fe676f448 (t1300: remove global config settings\ninjected by test-lib.sh, 2026-04-26) that added\n\n      test_might_fail git config --global --unset-all safe.bareRepository\n\nthat clearly mimicked the tests that prepared the stage by clearing\na relevant configuration variable done in an earier 313eec177a\n(safe.directory: allow \"lead/ing/path/*\" match, 2024-05-29).\n\nBy \"sufficient due diligence\", what I meant was that I trust Dscho\nwell enough that he's done a similar analysis to make sure that he\nis copying from ourselves.\n\n\n"},{"id":"551141","messageId":"xmqqfr03qyhk.fsf@gitster.g","threadId":"66205","inReplyTo":"xmqqjypfqz9e.fsf@gitster.g","subject":"Re: [PATCH 0/3] treewide: migrate from legacy utime.h to utimensat","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2026-08-24T16:23:03Z","receivedAt":"2026-08-24T16:23:06Z","isPatch":true,"body":"Junio C Hamano <gitster@pobox.com> writes:\n\n> By \"sufficient due diligence\", what I meant was that I trust Dscho\n> well enough that he's done a similar analysis to make sure that he\n> is copying from ourselves.\n\n... or wrote things using what he learned from other places that are\nOK to copy from (like code of BSD licensed projects).\n"},{"id":"551142","messageId":"aoxydzcI0m_y-gsK@wyuan.org","threadId":"66205","inReplyTo":"xmqqfr03qyhk.fsf@gitster.g","subject":"Re: [PATCH 0/3] treewide: migrate from legacy utime.h to utimensat","fromName":"Weijie Yuan","fromEmail":"wy@wyuan.org","sentAt":"2026-08-24T16:33:59Z","receivedAt":"2026-08-24T16:34:13Z","isPatch":true,"body":"> Weijie Yuan <wy@wyuan.org> writes:\n> \n> > What I was trying to understand is how that fits with the particular DCO\n> > concern being discussed here.\n> \n> You may never be able to tell where the AI output came from, but you\n> can see if the updated code has resemblance to fixes we applied in\n> the past to correct similar problems, for example.  After all, you\n> yourself without help by AI can copy our code to your patch to\n> enhance our code, and that is perfectly legit.\n> \n> Take for example 5fe676f448 (t1300: remove global config settings\n> injected by test-lib.sh, 2026-04-26) that added\n> \n>       test_might_fail git config --global --unset-all safe.bareRepository\n> \n> that clearly mimicked the tests that prepared the stage by clearing\n> a relevant configuration variable done in an earier 313eec177a\n> (safe.directory: allow \"lead/ing/path/*\" match, 2024-05-29).\n> \n> By \"sufficient due diligence\", what I meant was that I trust Dscho\n> well enough that he's done a similar analysis to make sure that he\n> is copying from ourselves.\n\n> ... or wrote things using what he learned from other places that are\n> OK to copy from (like code of BSD licensed projects).\n\nAh, I see it clearly now. This could make us able to keep the\nprovenance of the patch under control.\n\nThanks so much for taking the time to give me this example and\nexplanation.  And very sorry for bringing Dscho into the discussion,\nsorry.\n\nApologize for my recklessness.  Thank you very much.\n"},{"id":"551151","messageId":"aoyot_mI2uX8VL8c@ugly.lan","threadId":"66205","inReplyTo":"xmqqjypfqz9e.fsf@gitster.g","subject":"Re: [PATCH 0/3] treewide: migrate from legacy utime.h to utimensat","fromName":"Oswald Buddenhagen","fromEmail":"oswald.buddenhagen@gmx.de","sentAt":"2026-08-24T20:25:27Z","receivedAt":"2026-08-24T20:25:36Z","isPatch":true,"body":"On Mon, Aug 24, 2026 at 09:06:21AM -0700, Junio C Hamano wrote:\n>By \"sufficient due diligence\", what I meant was that I trust Dscho\n>well enough that he's done a similar analysis to make sure that he\n>is copying from ourselves.\n>\ni think the salient point is that it is never reasonable to make that \nassumption when an AI tool is used. some of the tools now reportedly \ndetect themselves when they are outright plagiarizing (and identifying \nthe tool in a trailer would actually give some assurance in that \nregard), but if the tool fails or doesn't have the feature in the first \nplace, then all bets are off. Literally No-one (TM) will use multiple \ncode search engines to check whether the generated code doesn't contain \nsufficiently large fragments that are (near-)verbatim copies from \nincompatibly licensed code bases.\n"}]}