Re: SHA1 collisions found
- From
Jeff King <peff@peff.net>
- Date
- Feb 26, 2017, 00:46 UTC
- Message-ID
- <20170226004657.zowlojdzqrrcalsm@sigill.intra.peff.net>
- In-Reply-To
- <D74A82FF-BF00-481F-9B2A-4AF8EF3D062F@gmail.com>
On Sat, Feb 25, 2017 at 11:35:27PM +0100, Lars Schneider wrote:
Show 10 quoted lines
> > So we don't actually know how Git would behave in the face of a SHA-1 > > collision. It would be pretty easy to simulate it with something like: > [...] > > That's a good idea! I wonder if it would make sense to setup an > additional job in TravisCI that patches every Git version with some hash > collisions and then runs special tests. This way we could ensure Git > behaves reasonable in case of a collision. E.g. by printing errors and > not crashing or corrupting the repo. Do you think that would be worth > the effort?
I think it would be interesting to see the results under various scenarios. I don't know that it would be all that interesting from an ongoing CI perspective. But we wouldn't know until somebody actually writes the tests and we see what they do.
-Peff