git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Mercurial 0.4b vs git patchbomb benchmark

From
TLTom Lord <lord@emf.net>
Date
Apr 29, 2005, 17:34 UTC
Message-ID
<200504291734.KAA25263@emf.net>
In-Reply-To
<Pine.LNX.4.58.0504290854270.18901@ppc970.osdl.org>
   From: Linus Torvalds <torvalds@osdl.org>
   On Fri, 29 Apr 2005, Tom Lord wrote:
   > 
   > On the other hand, you're asking people to sign whole trees and not
   > just at first-import time but also for every change.
   I don't agree.
Let's be more precise, then.
   Sure, the commit determins the whole tree end result, but if you want to 
   sign the _tree_, you can do so: just tag the actual _tree_ object as "this 
   tree has been verified to be bug-free and non-baby-seal-clubbing".
   But that's not what people do with tags. They sign a _commit_ object. And
   yes, the commit object points to the tree, but it also points to the whole
   history of other commit objects (and thus all historical trees etc), and 
   together with just common sense it is very obvious that what you're really 
   signing is that "point in time".
   If you want to clarify it, you can always just say so in the tag. Instead 
   of saying "I tag this as something I have verified every byte of", you can 
   say "this was what I released as xxx", or "this commit contains my change" 
   or something.
A programmer publishing a change to the kernel has three pieces of 
data in play.  They are:
nn
	1) the ancestry of their modified tree
	2) the complete contents of their modified tree
	3) input data for a patching program (let's call it "PATCH")
	   which, at the very least, satisfies the equation:
		MOD_TREE = PATCH (this_diff, ORIG_TREE)

An upstream consumer, most often, is (should be) using (1) and (3). In your system, the upstream consumer is given (1) and (2) and must compute (3) for themselves. The upstream consumer can also be provided a signed version of (3) but if clients are mostly relying on the (2) then there are multiple vulnerabilities there.

The set of pairs of type (1) and (2) is a dual space to the set of pairs of type (1) and (3). In that sense, it makes no mathematical difference whether the programmer signs a {(1),(3)} pair or a {(1),(2)} pair since either way, the other pair can be trivially derived.

On the other hand, signing documents which represent a {(1),(3)} pair with robust accuracy is, in most cases, much much less expensive than signing {(1),(2)} pairs with robust accuracy. This is a bit like the difference between "*I* didn't set loose any mice in the house" vs. "I have searched every corner of the house and swear there are no mice here."

Another way to say that is that if someone gives me a signed {(1),(3)} pair I am likely to be much more confident that the signature represents an in-depth endorsement of the content as opposed to "here is what the tools on my system happened to generate -- I hope it's what I meant".

   > If I've changed five files, I should be signing a statement of:
   > 
   > 	1) my belief about the identity of the immediate ancestor tree
   > 	2) a robust summary of my changes, sufficient to recreate my
   > 	   new tree given a faithful copy of the ancestor
   So _do_ exactly that. You can say that in the tag you're signing.

Which is pretty much exactly what Arch does except that, in the case of Arch, the signed diff is actually used directly to produce the mod tree. There isn't a step in the process where a programmer reads a purported diff, assumes that the signed tree accurately reflects that diff, and then merges against the signed tree rather than the diff.

The Arch approach also has the win that the signed diffs are useful even in the absense of the ORIG_TREE. In the Arch world, we use this for the form of selective merging that we call "cherry-picking" (picking the desired changes from somebody else's line of development while skipping those which are not desired -- yet still being able to proceed with bidirectional merging in a simple way).

The Arch approach also has the win that it amounts to delta-compression, simplifying the design of efficient transports and helping to tame I/O bandwidth costs in the local case. A lot of good features simply "fall out" of this approach.

This is kind of a yin-yang thing. It's also valuable, in my view, to sign {(1),(2)} pairs. It's also (in a more obscure way) valuable to sign {(1),(2),(3)} triples, especially if clients are regularly validating them by making sure the triple describes a true diff application. So one ultimately wants both functionalities, really.

Signing trees which are really defined by a diff is a handy checksum on the accuracy of tools which people are using but it isn't a substitute for signing the diff itself and using it as the primary definition of the tree it generates when combined with the immediate ancestor(s).

Signing trees is also handy when that signature is then further linked to a set of binaries.

Signing trees also is easier to implement and so gets git off the ground faster.

But there's more to do, if a serious system is desired.
-t
Previous: Linus TorvaldsNext: Linus Torvalds
Message 66 of 116 in “Mercurial 0.3 vs git benchmarks”
  1. Matt MackallApr 26, 2005
  2. Daniel PhillipsApr 26, 2005
  3. Linus TorvaldsApr 26, 2005
  4. Mike TahtApr 26, 2005
  5. Linus TorvaldsApr 26, 2005
  6. Linus TorvaldsApr 26, 2005
  7. Chris MasonApr 26, 2005
  8. Magnus DammApr 26, 2005
  9. Chris MasonApr 26, 2005
  10. Magnus DammApr 26, 2005
  11. Chris MasonApr 26, 2005
  12. Andrew MortonApr 26, 2005
  13. Linus TorvaldsApr 26, 2005
  14. H. Peter AnvinApr 26, 2005
  15. Andrew MortonApr 26, 2005
  16. H. Peter AnvinApr 26, 2005
  17. Florian WeimerApr 27, 2005
  18. Thomas GlanzmannApr 27, 2005
  19. H. Peter AnvinApr 27, 2005
  20. Thomas GlanzmannApr 27, 2005
  21. Theodore Ts'oApr 27, 2005
  22. Thomas GlanzmannApr 27, 2005
  23. H. Peter AnvinApr 27, 2005
  24. Thomas GlanzmannApr 27, 2005
  25. Florian WeimerApr 27, 2005
  26. Florian WeimerApr 27, 2005
  27. H. Peter AnvinApr 27, 2005
  28. Florian WeimerApr 27, 2005
  29. Theodore Ts'oApr 27, 2005
  30. Theodore Ts'oApr 27, 2005
  31. Ingo MolnarApr 27, 2005
  32. Bill DavidsenApr 27, 2005
  33. Linus TorvaldsApr 27, 2005
  34. Linus TorvaldsApr 26, 2005
  35. Chris MasonApr 26, 2005
  36. Chris MasonApr 26, 2005
  37. H. Peter AnvinApr 26, 2005
  38. Bill DavidsenApr 26, 2005
  39. Bill DavidsenApr 26, 2005
  40. Matt MackallApr 26, 2005
  41. Linus TorvaldsApr 26, 2005
  42. Chris WedgwoodApr 26, 2005
  43. Andreas GalApr 26, 2005
  44. Linus TorvaldsApr 26, 2005
  45. Mercurial 0.4b vs git patchbomb benchmarkMatt Mackall, Apr 29, 2005
  46. SeanApr 29, 2005
  47. Matt MackallApr 29, 2005
  48. SeanApr 29, 2005
  49. Linus TorvaldsApr 29, 2005
  50. Morten WelinderApr 29, 2005
  51. Matt MackallApr 29, 2005
  52. Bill DavidsenMay 2, 2005
  53. SeanMay 2, 2005
  54. Linus TorvaldsMay 2, 2005
  55. Matt MackallMay 2, 2005
  56. Linus TorvaldsMay 2, 2005
  57. Matt MackallMay 3, 2005
  58. Linus TorvaldsMay 3, 2005
  59. Matt MackallMay 3, 2005
  60. Linus TorvaldsMay 3, 2005
  61. Linus TorvaldsMay 3, 2005
  62. Matt MackallMay 3, 2005
  63. Chris WedgwoodMay 3, 2005
  64. Tom LordApr 29, 2005
  65. Linus TorvaldsApr 29, 2005
  66. Tom LordApr 29, 2005
  67. Linus TorvaldsApr 29, 2005
  68. Tom LordApr 29, 2005
  69. SeanApr 29, 2005
  70. Tom LordApr 29, 2005
  71. SeanApr 29, 2005
  72. Tom LordApr 29, 2005
  73. Tom LordApr 29, 2005
  74. Noel MaddyApr 29, 2005
  75. Tom LordApr 29, 2005
  76. Andrew Timberlake-NewellApr 29, 2005
  77. Tom LordApr 29, 2005
  78. Andrew Timberlake-NewellApr 29, 2005
  79. Morgan SchweersApr 29, 2005
  80. Noel MaddyApr 29, 2005
  81. git network protocolDavid Lang, Apr 29, 2005
  82. Daniel BarkalowApr 29, 2005
  83. Tom LordApr 29, 2005
  84. Denys DuchierApr 29, 2005
  85. Signed commit vulnerabilities? (was: Mercurial 0.4b vs git patchbomb benchmark)Kevin Smith, Apr 29, 2005
  86. Bill DavidsenMay 2, 2005
  87. Matt MackallApr 29, 2005
  88. Linus TorvaldsApr 29, 2005
  89. Matt MackallApr 29, 2005
  90. Linus TorvaldsApr 29, 2005
  91. Matt MackallApr 29, 2005
  92. Linus TorvaldsApr 29, 2005
  93. Matt MackallApr 29, 2005
  94. Bill DavidsenApr 29, 2005
  95. Andrea ArcangeliApr 29, 2005
  96. Olivier GalibertApr 29, 2005
  97. Andrea ArcangeliApr 29, 2005
  98. Andrea ArcangeliApr 29, 2005
  99. Matt MackallApr 29, 2005
  100. Andrea ArcangeliApr 30, 2005
  101. Matt MackallApr 30, 2005
  102. Andrea ArcangeliApr 30, 2005
  103. Bill DavidsenMay 2, 2005
  104. valdis.kletnieks@vt.eduMay 2, 2005
  105. Bill DavidsenMay 3, 2005
  106. David A. WheelerMay 4, 2005
  107. Andrea ArcangeliMay 2, 2005
  108. Linus TorvaldsMay 2, 2005
  109. Daniel JacobowitzMay 2, 2005
  110. Linus TorvaldsMay 2, 2005
  111. Edgar ToernigMay 2, 2005
  112. Sam RavnborgMay 2, 2005
  113. Ryan AndersonMay 2, 2005
  114. Linus TorvaldsMay 2, 2005
  115. Kyle MoffettMay 2, 2005
  116. Bill DavidsenMay 3, 2005

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.