From: Tom Lord Date: Fri, 29 Apr 2005 19:28:41 GMT Subject: Re: Mercurial 0.4b vs git patchbomb benchmark Message-ID: <200504291928.MAA27145@emf.net> In-Reply-To: <2944.10.10.10.24.1114802002.squirrel@linux1> Think of it this way: (a) Joe, the mainline maintainer, gets a trusted message containing a diff. (b) Joe reads the diff, it makes great sense, he wants to merge. (c) Joe downloads a tree. Supposedly that tree is the result of applying this diff. The tree, not the diff, is used for merging. You can see the logical whole there... now the practical one: (d) Joe is repeating (a..c) at an unfathomably high rate. At a low rate, he could be double-checking enough that that the diff-vs-tree problem isn't that serious. But at the rate he operates, exploits appear all along the patch-flow pipeline because so much stuff goes unchecked. Joe may be scan the changes he's merged before committing but, if his rate is high, that scan *must*, out of biological and physical necessity, be shallow. Exploits can occur on the submitter machine, in the communication channel, and on Joe's machine. Social exploits can occur because of the separation between a submitter saying "this is what I'm doing" vs. the reality of what the submitter is doing. -t