git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: weaning distributions off tarballs: extended verification of git tags

From
brian m. carlson <sandals@crustytoothpaste.net>
Date
Feb 28, 2015, 19:14 UTC
Message-ID
<20150228191403.GD514544@vauxhall.crustytoothpaste.net>
In-Reply-To
<1425134885.3150003.233627665.2E48E28B@webmail.messagingengine.com>
On Sat, Feb 28, 2015 at 09:48:05AM -0500, Colin Walters wrote:
Show 5 quoted lines
>The above strawman code allows embedding the SHA256(git archive | tar).  Now,
>in order to make this work, the byte output of "git archive" must never change in the
>future.  I'm not sure how valid an assumption this is.  Timestamps are set to the
>commit timestamp, but I could imagine someone wanting to come along later
>and tweak the output to be compatible with some variant of tar or something.

This is not a safe assumption. Unfortunately, kernel.org assumed that it was the case, and a change broke it. Let's please not make more code that does that.

>We could define the checksum to be over the stream of raw objects, sorted by their checksum,
>and that way be independent of archiving format variations.

This would be a much better idea, assuming you mean "raw git objects". For cryptographic purposes, it's important to make the item boundaries unambiguous, which is usually done using the length. Since the raw git objects include the length, this is sufficient.

If you don't make the boundaries unambiguous, you get the problem you have with v3 OpenPGP keys, where somebody could move bytes from one value to another, creating a different key, but with the same fingerprint (hash value).

-- 
brian m. carlson / brian with sandals: Houston, Texas, US
+1 832 623 2791 | http://www.crustytoothpaste.net/~bmc | My opinion only
OpenPGP: RSA v4 4096b: 88AC E9B2 9196 305B A994 7552 F1BA 225C 0223 B187
Previous: Colin WaltersNext: Morten Welinder
Message 2 of 13 in “weaning distributions off tarballs: extended verification of git tags”
  1. Colin WaltersFeb 28, 2015
  2. brian m. carlsonFeb 28, 2015
  3. Morten WelinderFeb 28, 2015
  4. Colin WaltersMar 2, 2015
  5. Joey HessMar 2, 2015
  6. Sam VilainMar 2, 2015
  7. Junio C HamanoMar 2, 2015
  8. Sam VilainMar 2, 2015
  9. Duy NguyenMar 2, 2015
  10. Junio C HamanoMar 2, 2015
  11. Duy NguyenMar 3, 2015
  12. Michael HaggertyMar 5, 2015
  13. Colin WaltersJul 8, 2015

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.