git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Mercurial 0.4b vs git patchbomb benchmark

From
TLTom Lord <lord@emf.net>
Date
Apr 29, 2005, 15:44 UTC
Message-ID
<200504291544.IAA23584@emf.net>
In-Reply-To
<Pine.LNX.4.58.0504290728090.18901@ppc970.osdl.org>
  > ie does mercurial do distributed merges, which git was designed for, and 
  > does mercurial notice single-bit errors in a reasonably secure manner, or 
  > can people just mess with history willy-nilly?
  > For the latter, the cryptographic nature of sha1 is an added bonus - the
  > _big_ issue is that it is a good hash, and an _exteremely_ effective CRC
  > of the data. You can't mess up an archive and lie about it later.

On the other hand, you're asking people to sign whole trees and not just at first-import time but also for every change.

That's an impedence mismatch and undermines the security features of the approach you're taking and here is why:

I shouldn't sign anything I haven't reviewed pretty carefully. For the kernel and in many other situations, it is too expensive to review the whole tree. Thus, the thing actually signed and the thing meant by the signature are not equal. I sign a tree, in this system, because I think the right diffs and only the right diffs have been applied to it. My signature is intended to mean, though, that I vouche for the *diffs*, not the tree.

If I've changed five files, I should be signing a statement of:
	1) my belief about the identity of the immediate ancestor tree
	2) a robust summary of my changes, sufficient to recreate my
	   new tree given a faithful copy of the ancestor

That's a short enough amount of data that a human can really review it and thus it makes the signatures much more meaningful.

Probably doesn't matter much other than in cases where a mainline is undergoing massive batch-patching based mostly on a web of trust.

But in that case --- someone or something generates purported diffs of a tree; someone or something else scans those diffs and decides they look good ---- and then on this basis, something distinct from directly using those diffs occurs. The diffs were used to vette the change; the signature asserts that a certain tree is a faithful result of applying those diffs. Nothing checks that second assertion -- it's taken on faith.

-t
Previous: Chris WedgwoodNext: Linus Torvalds
Message 64 of 116 in “Mercurial 0.3 vs git benchmarks”
  1. Matt MackallApr 26, 2005
  2. Daniel PhillipsApr 26, 2005
  3. Linus TorvaldsApr 26, 2005
  4. Mike TahtApr 26, 2005
  5. Linus TorvaldsApr 26, 2005
  6. Linus TorvaldsApr 26, 2005
  7. Chris MasonApr 26, 2005
  8. Magnus DammApr 26, 2005
  9. Chris MasonApr 26, 2005
  10. Magnus DammApr 26, 2005
  11. Chris MasonApr 26, 2005
  12. Andrew MortonApr 26, 2005
  13. Linus TorvaldsApr 26, 2005
  14. H. Peter AnvinApr 26, 2005
  15. Andrew MortonApr 26, 2005
  16. H. Peter AnvinApr 26, 2005
  17. Florian WeimerApr 27, 2005
  18. Thomas GlanzmannApr 27, 2005
  19. H. Peter AnvinApr 27, 2005
  20. Thomas GlanzmannApr 27, 2005
  21. Theodore Ts'oApr 27, 2005
  22. Thomas GlanzmannApr 27, 2005
  23. H. Peter AnvinApr 27, 2005
  24. Thomas GlanzmannApr 27, 2005
  25. Florian WeimerApr 27, 2005
  26. Florian WeimerApr 27, 2005
  27. H. Peter AnvinApr 27, 2005
  28. Florian WeimerApr 27, 2005
  29. Theodore Ts'oApr 27, 2005
  30. Theodore Ts'oApr 27, 2005
  31. Ingo MolnarApr 27, 2005
  32. Bill DavidsenApr 27, 2005
  33. Linus TorvaldsApr 27, 2005
  34. Linus TorvaldsApr 26, 2005
  35. Chris MasonApr 26, 2005
  36. Chris MasonApr 26, 2005
  37. H. Peter AnvinApr 26, 2005
  38. Bill DavidsenApr 26, 2005
  39. Bill DavidsenApr 26, 2005
  40. Matt MackallApr 26, 2005
  41. Linus TorvaldsApr 26, 2005
  42. Chris WedgwoodApr 26, 2005
  43. Andreas GalApr 26, 2005
  44. Linus TorvaldsApr 26, 2005
  45. Mercurial 0.4b vs git patchbomb benchmarkMatt Mackall, Apr 29, 2005
  46. SeanApr 29, 2005
  47. Matt MackallApr 29, 2005
  48. SeanApr 29, 2005
  49. Linus TorvaldsApr 29, 2005
  50. Morten WelinderApr 29, 2005
  51. Matt MackallApr 29, 2005
  52. Bill DavidsenMay 2, 2005
  53. SeanMay 2, 2005
  54. Linus TorvaldsMay 2, 2005
  55. Matt MackallMay 2, 2005
  56. Linus TorvaldsMay 2, 2005
  57. Matt MackallMay 3, 2005
  58. Linus TorvaldsMay 3, 2005
  59. Matt MackallMay 3, 2005
  60. Linus TorvaldsMay 3, 2005
  61. Linus TorvaldsMay 3, 2005
  62. Matt MackallMay 3, 2005
  63. Chris WedgwoodMay 3, 2005
  64. Tom LordApr 29, 2005
  65. Linus TorvaldsApr 29, 2005
  66. Tom LordApr 29, 2005
  67. Linus TorvaldsApr 29, 2005
  68. Tom LordApr 29, 2005
  69. SeanApr 29, 2005
  70. Tom LordApr 29, 2005
  71. SeanApr 29, 2005
  72. Tom LordApr 29, 2005
  73. Tom LordApr 29, 2005
  74. Noel MaddyApr 29, 2005
  75. Tom LordApr 29, 2005
  76. Andrew Timberlake-NewellApr 29, 2005
  77. Tom LordApr 29, 2005
  78. Andrew Timberlake-NewellApr 29, 2005
  79. Morgan SchweersApr 29, 2005
  80. Noel MaddyApr 29, 2005
  81. git network protocolDavid Lang, Apr 29, 2005
  82. Daniel BarkalowApr 29, 2005
  83. Tom LordApr 29, 2005
  84. Denys DuchierApr 29, 2005
  85. Signed commit vulnerabilities? (was: Mercurial 0.4b vs git patchbomb benchmark)Kevin Smith, Apr 29, 2005
  86. Bill DavidsenMay 2, 2005
  87. Matt MackallApr 29, 2005
  88. Linus TorvaldsApr 29, 2005
  89. Matt MackallApr 29, 2005
  90. Linus TorvaldsApr 29, 2005
  91. Matt MackallApr 29, 2005
  92. Linus TorvaldsApr 29, 2005
  93. Matt MackallApr 29, 2005
  94. Bill DavidsenApr 29, 2005
  95. Andrea ArcangeliApr 29, 2005
  96. Olivier GalibertApr 29, 2005
  97. Andrea ArcangeliApr 29, 2005
  98. Andrea ArcangeliApr 29, 2005
  99. Matt MackallApr 29, 2005
  100. Andrea ArcangeliApr 30, 2005
  101. Matt MackallApr 30, 2005
  102. Andrea ArcangeliApr 30, 2005
  103. Bill DavidsenMay 2, 2005
  104. valdis.kletnieks@vt.eduMay 2, 2005
  105. Bill DavidsenMay 3, 2005
  106. David A. WheelerMay 4, 2005
  107. Andrea ArcangeliMay 2, 2005
  108. Linus TorvaldsMay 2, 2005
  109. Daniel JacobowitzMay 2, 2005
  110. Linus TorvaldsMay 2, 2005
  111. Edgar ToernigMay 2, 2005
  112. Sam RavnborgMay 2, 2005
  113. Ryan AndersonMay 2, 2005
  114. Linus TorvaldsMay 2, 2005
  115. Kyle MoffettMay 2, 2005
  116. Bill DavidsenMay 3, 2005

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.