git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: What about SHA-1 collisions?

From
JWJosef Wolf <jw@raven.inka.de>
Date
Nov 6, 2012, 22:09 UTC
Message-ID
<20121106220938.GH28437@raven.wolf.lan>
In-Reply-To
<loom.20121106T223000-502@post.gmane.org>
On Tue, Nov 06, 2012 at 09:41:29PM +0000, John McKown wrote:
> Josef Wolf <jw <at> raven.inka.de> writes:
> > Just for curiosity: what would happen if such a collision would occur within
> > one repository?
> In a sense, this cannot happen.

In the scenario you described, contents of this version of file "b" are lost and replaced by the contents of file "a". So file "b" is broken.

What happens when files "a" and "b" are added into different repositories? File "a" is added to repos "A", and file "b" is added to repos "B". Now it depends from which repository you fetch the collided blob first. If you fetch it from "A", file "b" will be broken. If you fetch first from "B", your "a" will be broken.

It becomes even more interesting, if some commit or tree object would have the same SHA1 as some other object. I guess, in such a case the repository would be completely hosed?

Previous: John McKownNext: Shawn Pearce
Message 3 of 5 in “What about SHA-1 collisions?”
  1. Josef WolfNov 6, 2012
  2. John McKownNov 6, 2012
  3. Josef WolfNov 6, 2012
  4. Shawn PearceNov 7, 2012
  5. Andrew ArdillNov 7, 2012

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.