git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH 3/3] Makefile: make DC_SHA1 the default

From
Junio C Hamano <gitster@pobox.com>
Date
Mar 17, 2017, 17:09 UTC
Message-ID
<20170317170938.20593-4-gitster@pobox.com>
In-Reply-To
<20170317170938.20593-1-gitster@pobox.com>

We used to use the SHA1 implementation from the OpenSSL library by default. As we are trying to be careful against collision attacks after the recent "shattered" announcement, switch the default to encourage people to use DC_SHA1 implementation instead. Those who want to use the implementation from OpenSSL can explicitly ask for it by OPENSSL_SHA1=YesPlease when running "make".

Signed-off-by: Junio C Hamano <gitster@pobox.com>
---
 Makefile | 16 ++++++++++------
 1 file changed, 10 insertions(+), 6 deletions(-)
diff --git a/Makefile b/Makefile
index fc9d89498b..fd4421eeb8 100644
--- a/Makefile
+++ b/Makefile
@@ -146,6 +146,9 @@ all::
 # algorithm. This is slower, but may detect attempted collision attacks.
 # Takes priority over other *_SHA1 knobs.
 #
+# Define OPENSSL_SHA1 environment variable when running make to link
+# with the SHA1 routine from openssl library.
+#
 # Define SHA1_MAX_BLOCK_SIZE to limit the amount of data that will be hashed
 # in one call to the platform's SHA1_Update(). e.g. APPLE_COMMON_CRYPTO
 # wants 'SHA1_MAX_BLOCK_SIZE=1024L*1024L*1024L' defined.
@@ -1390,10 +1393,9 @@ ifdef APPLE_COMMON_CRYPTO
 	SHA1_MAX_BLOCK_SIZE = 1024L*1024L*1024L
 endif
 
-ifdef DC_SHA1
-	LIB_OBJS += sha1dc/sha1.o
-	LIB_OBJS += sha1dc/ubc_check.o
-	BASIC_CFLAGS += -DSHA1_DC
+ifdef OPENSSL_SHA1
+	EXTLIBS += $(LIB_4_CRYPTO)
+	BASIC_CFLAGS += -DSHA1_OPENSSL
 else
 ifdef BLK_SHA1
 	LIB_OBJS += block-sha1/sha1.o
@@ -1407,8 +1409,10 @@ ifdef APPLE_COMMON_CRYPTO
 	COMPAT_CFLAGS += -DCOMMON_DIGEST_FOR_OPENSSL
 	BASIC_CFLAGS += -DSHA1_APPLE
 else
-	EXTLIBS += $(LIB_4_CRYPTO)
-	BASIC_CFLAGS += -DSHA1_OPENSSL
+	DC_SHA1 := YesPlease
+	LIB_OBJS += sha1dc/sha1.o
+	LIB_OBJS += sha1dc/ubc_check.o
+	BASIC_CFLAGS += -DSHA1_DC
 endif
 endif
 endif
-- 
2.12.0-317-g32c43f595f
Previous: Junio C HamanoNext: Junio C Hamano
Message 12 of 20 in “Re-integrate sha1dc”
  1. 0/2 Re-integrate sha1dcLinus Torvalds, Mar 16, 2017
  2. Jeff KingMar 16, 2017
  3. 2/5 sha1dc: adjust header includes for gitJeff King, Mar 16, 2017
  4. 3/5 sha1dc: disable safe_hash featureJeff King, Mar 16, 2017
  5. 4/5 Makefile: add USE_SHA1DC knobJeff King, Mar 16, 2017
  6. Junio C HamanoMar 16, 2017
  7. Jeff KingMar 17, 2017
  8. Junio C HamanoMar 17, 2017
  9. Jeff KingMar 17, 2017
  10. 0/3 Git integration update for DC-SHA1Junio C Hamano, Mar 17, 2017
  11. 1/3 Makefile: add DC_SHA1 knobJunio C Hamano, Mar 17, 2017
  12. 3/3 Makefile: make DC_SHA1 the defaultJunio C Hamano, Mar 17, 2017
  13. Junio C HamanoMar 17, 2017
  14. Jeff KingMar 17, 2017
  15. Jeff KingMar 16, 2017
  16. Junio C HamanoMar 16, 2017
  17. Jeff KingMar 17, 2017
  18. Junio C HamanoMar 17, 2017
  19. Jeff KingMar 17, 2017
  20. Linus TorvaldsMar 16, 2017

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.