git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Mercurial 0.4b vs git patchbomb benchmark

From
TLTom Lord <lord@emf.net>
Date
Apr 29, 2005, 18:54 UTC
Message-ID
<200504291854.LAA26550@emf.net>
In-Reply-To
<2712.10.10.10.24.1114799620.squirrel@linux1>
   From: "Sean" <seanlkml@sympatico.ca>
   On Fri, April 29, 2005 2:08 pm, Tom Lord said:
   > The confusion here is that you are talking about computational complexity
   > while I am talking about complexity measured in hours of labor.
   >
   > You are assuming that the programmer generating the signature blindly
   > trusts the tool to generate the signed document accurately.   I am
   > saying that it should be tractable for human beings to read the documents
   > they are going to sign.
   Developers obviously _do_ read the changes they submit to a project or
   they would lose their trusted status.  That has absolutely nothing to do
   with signing, it's the exact same way things work today, without sigs.

Nobody that I know is endorsing "the way things work today" as especially robust. Lots of people endorse it as successful in the marketplace and has having not failed horribly yet -- but that's not the same thing.

   It's not "blind trust" to expect a script to reproducibly sign documents
   you've decided to submit to a project.

It *is* blind trust to assume without further guarantees that the diff someone sends you (signed or not) describes a tree accurately unless the tree in question is created by a local application of that diff.

In essense, `git' (today) wants *me* to trust that *you* have correctly applied that diff -- evidently in order to speed things up. It makes remote users "patch servers", for no good reason.

Triple signatures, signing both the name of the ancestor, the diff, and the resulting tree are the most robust because I can apply the diff to the ancestor and then *verify* that it matches the signed tree. But systems should neither ask users to sign something too large to read nor rely on signatures of things too large to read.

   The signature is not a QUALITY
   guarantee in and of itself.
Which has nothing to do with any of this except indirectly.
   See?  Signing something does not change the quality guarantee one way or
   the other.  It does not put any additional demands on the developer, so
   it's fine to have an automated script do it.  It's just a way to avoid
   impersonations.

The process should not rely on the security of every developer's machine. The process should not rely on simply trusting quality contributors by reputation (e.g., most cons begin by establishing trust and continue by relying inappropriately on trust-without-verification). This relates to why Linus' self-advertised process should be raising yellow and red cards all over the place: either he is wasting a huge amount of his own time and should be largely replaced by an automated patch queue manager, or he is being trusted to do more than is humanly possible.

-t
Previous: SeanNext: Sean
Message 70 of 116 in “Mercurial 0.3 vs git benchmarks”
  1. Matt MackallApr 26, 2005
  2. Daniel PhillipsApr 26, 2005
  3. Linus TorvaldsApr 26, 2005
  4. Mike TahtApr 26, 2005
  5. Linus TorvaldsApr 26, 2005
  6. Linus TorvaldsApr 26, 2005
  7. Chris MasonApr 26, 2005
  8. Magnus DammApr 26, 2005
  9. Chris MasonApr 26, 2005
  10. Magnus DammApr 26, 2005
  11. Chris MasonApr 26, 2005
  12. Andrew MortonApr 26, 2005
  13. Linus TorvaldsApr 26, 2005
  14. H. Peter AnvinApr 26, 2005
  15. Andrew MortonApr 26, 2005
  16. H. Peter AnvinApr 26, 2005
  17. Florian WeimerApr 27, 2005
  18. Thomas GlanzmannApr 27, 2005
  19. H. Peter AnvinApr 27, 2005
  20. Thomas GlanzmannApr 27, 2005
  21. Theodore Ts'oApr 27, 2005
  22. Thomas GlanzmannApr 27, 2005
  23. H. Peter AnvinApr 27, 2005
  24. Thomas GlanzmannApr 27, 2005
  25. Florian WeimerApr 27, 2005
  26. Florian WeimerApr 27, 2005
  27. H. Peter AnvinApr 27, 2005
  28. Florian WeimerApr 27, 2005
  29. Theodore Ts'oApr 27, 2005
  30. Theodore Ts'oApr 27, 2005
  31. Ingo MolnarApr 27, 2005
  32. Bill DavidsenApr 27, 2005
  33. Linus TorvaldsApr 27, 2005
  34. Linus TorvaldsApr 26, 2005
  35. Chris MasonApr 26, 2005
  36. Chris MasonApr 26, 2005
  37. H. Peter AnvinApr 26, 2005
  38. Bill DavidsenApr 26, 2005
  39. Bill DavidsenApr 26, 2005
  40. Matt MackallApr 26, 2005
  41. Linus TorvaldsApr 26, 2005
  42. Chris WedgwoodApr 26, 2005
  43. Andreas GalApr 26, 2005
  44. Linus TorvaldsApr 26, 2005
  45. Mercurial 0.4b vs git patchbomb benchmarkMatt Mackall, Apr 29, 2005
  46. SeanApr 29, 2005
  47. Matt MackallApr 29, 2005
  48. SeanApr 29, 2005
  49. Linus TorvaldsApr 29, 2005
  50. Morten WelinderApr 29, 2005
  51. Matt MackallApr 29, 2005
  52. Bill DavidsenMay 2, 2005
  53. SeanMay 2, 2005
  54. Linus TorvaldsMay 2, 2005
  55. Matt MackallMay 2, 2005
  56. Linus TorvaldsMay 2, 2005
  57. Matt MackallMay 3, 2005
  58. Linus TorvaldsMay 3, 2005
  59. Matt MackallMay 3, 2005
  60. Linus TorvaldsMay 3, 2005
  61. Linus TorvaldsMay 3, 2005
  62. Matt MackallMay 3, 2005
  63. Chris WedgwoodMay 3, 2005
  64. Tom LordApr 29, 2005
  65. Linus TorvaldsApr 29, 2005
  66. Tom LordApr 29, 2005
  67. Linus TorvaldsApr 29, 2005
  68. Tom LordApr 29, 2005
  69. SeanApr 29, 2005
  70. Tom LordApr 29, 2005
  71. SeanApr 29, 2005
  72. Tom LordApr 29, 2005
  73. Tom LordApr 29, 2005
  74. Noel MaddyApr 29, 2005
  75. Tom LordApr 29, 2005
  76. Andrew Timberlake-NewellApr 29, 2005
  77. Tom LordApr 29, 2005
  78. Andrew Timberlake-NewellApr 29, 2005
  79. Morgan SchweersApr 29, 2005
  80. Noel MaddyApr 29, 2005
  81. git network protocolDavid Lang, Apr 29, 2005
  82. Daniel BarkalowApr 29, 2005
  83. Tom LordApr 29, 2005
  84. Denys DuchierApr 29, 2005
  85. Signed commit vulnerabilities? (was: Mercurial 0.4b vs git patchbomb benchmark)Kevin Smith, Apr 29, 2005
  86. Bill DavidsenMay 2, 2005
  87. Matt MackallApr 29, 2005
  88. Linus TorvaldsApr 29, 2005
  89. Matt MackallApr 29, 2005
  90. Linus TorvaldsApr 29, 2005
  91. Matt MackallApr 29, 2005
  92. Linus TorvaldsApr 29, 2005
  93. Matt MackallApr 29, 2005
  94. Bill DavidsenApr 29, 2005
  95. Andrea ArcangeliApr 29, 2005
  96. Olivier GalibertApr 29, 2005
  97. Andrea ArcangeliApr 29, 2005
  98. Andrea ArcangeliApr 29, 2005
  99. Matt MackallApr 29, 2005
  100. Andrea ArcangeliApr 30, 2005
  101. Matt MackallApr 30, 2005
  102. Andrea ArcangeliApr 30, 2005
  103. Bill DavidsenMay 2, 2005
  104. valdis.kletnieks@vt.eduMay 2, 2005
  105. Bill DavidsenMay 3, 2005
  106. David A. WheelerMay 4, 2005
  107. Andrea ArcangeliMay 2, 2005
  108. Linus TorvaldsMay 2, 2005
  109. Daniel JacobowitzMay 2, 2005
  110. Linus TorvaldsMay 2, 2005
  111. Edgar ToernigMay 2, 2005
  112. Sam RavnborgMay 2, 2005
  113. Ryan AndersonMay 2, 2005
  114. Linus TorvaldsMay 2, 2005
  115. Kyle MoffettMay 2, 2005
  116. Bill DavidsenMay 3, 2005

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.