git/list[1] front-page[2] threads[3] people[4] search[5] about
 

weaning distributions off tarballs: extended verification of git tags

From
Colin Walters <walters@verbum.org>
Date
Feb 28, 2015, 14:48 UTC
Message-ID
<1425134885.3150003.233627665.2E48E28B@webmail.messagingengine.com>
Hi, 

TL;DR: Let's define a standard for embedding stronger checksums in tags and commit messages: https://github.com/cgwalters/homegit/blob/master/bin/git-evtag

I think tarballs should go away as a source distribution mechanism in favor of pure git.  I won't go into too many details of the "why" here (hopefully most of you agree!) but that's the background.
Now, there are a few things that the classical tarball model provides:
- Version numbers compatible with dpkg/rpm/etc
  -> Do the same with your tag names, and use a well known scheme like "v$VERSION"
- The assumption that this source has been run through some tests
  -> Broken assumption, and regardless you want to rerun tests downstream
- Hosting providers typically offer a strong checksum over the entire source
  -> The topic of this post

The above strawman code allows embedding the SHA256(git archive | tar). Now, in order to make this work, the byte output of "git archive" must never change in the future. I'm not sure how valid an assumption this is. Timestamps are set to the commit timestamp, but I could imagine someone wanting to come along later and tweak the output to be compatible with some variant of tar or something.

We could define the checksum to be over the stream of raw objects, sorted by their checksum, and that way be independent of archiving format variations.

Is there agreement that something like this makes sense in the git core? Does the concept make sense? Does anything like this exist today? Other thoughts/objections?

Next: brian m. carlson
Message 1 of 13 in “weaning distributions off tarballs: extended verification of git tags”
  1. Colin WaltersFeb 28, 2015
  2. brian m. carlsonFeb 28, 2015
  3. Morten WelinderFeb 28, 2015
  4. Colin WaltersMar 2, 2015
  5. Joey HessMar 2, 2015
  6. Sam VilainMar 2, 2015
  7. Junio C HamanoMar 2, 2015
  8. Sam VilainMar 2, 2015
  9. Duy NguyenMar 2, 2015
  10. Junio C HamanoMar 2, 2015
  11. Duy NguyenMar 3, 2015
  12. Michael HaggertyMar 5, 2015
  13. Colin WaltersJul 8, 2015

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.