git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Gitorious should use CRC128 / 256 / 512 instead of SHA-1

From
Konstantin Ryabitsev <konstantin@linuxfoundation.org>
Date
Jan 13, 2023, 16:27 UTC
Message-ID
<20230113162721.qwl2asjo542cxe3c@meerkat.local>
In-Reply-To
<a2e6fdc3-fbb0-821c-078f-1ad4e55dc8e3@selasky.org>
On Fri, Jan 13, 2023 at 05:06:57PM +0100, Hans Petter Selasky wrote:
> OK, if you say so. Though in my mind 46K rebases of millions of commits seem
> a lot overhead.

Not to discourage you, but you seem to be making statements without a good understanding of how git works. If there is a history rewrite (even one that for some reason goes back millions of commits) all hash calculations will happen exactly once -- on the system of the person who's rewriting the history. After they push it, it's just a bunch of objects that everyone else merely downloads.

> However, if history can be edited anyway, why do you need the cryptographic
> hash algorithm. Why not use a non-cryptographic one?

The answer is, unhelpfully, "because that's how git works." Every commit is a standalone object that references the previous commit, plus includes hashes of all trees, and those include hashes of all blobs. SHA-1 was picked because of its speed and the fact that it guarantees an extremely low potential for collisions (even better with SHA256). As a side-effect, it's easy to calculate the integrity of the entire tree, including its history, by verifying its hashes (this is what git fsck does).

Hashes aren't really "cryptographic" anyway (they just happen to be used all over the place in cryptography). It's really just a one-way function to reduce content of arbitrary size to a set of bytes of a determined size (and give a relatively high assurance of it being collision-free).

-K
Previous: Hans Petter SelaskyNext: Hans Petter Selasky
Message 18 of 26 in “Gitorious should use CRC128 / 256 / 512 instead of SHA-1”
  1. Hans Petter SelaskyJan 13, 2023
  2. Konstantin KhomoutovJan 13, 2023
  3. Hans Petter SelaskyJan 13, 2023
  4. rsbecker@nexbridge.comJan 13, 2023
  5. Hans Petter SelaskyJan 13, 2023
  6. Konstantin RyabitsevJan 13, 2023
  7. Hans Petter SelaskyJan 13, 2023
  8. rsbecker@nexbridge.comJan 13, 2023
  9. Hans Petter SelaskyJan 13, 2023
  10. Hans Petter SelaskyJan 13, 2023
  11. Konstantin RyabitsevJan 13, 2023
  12. Hans Petter SelaskyJan 13, 2023
  13. Hans Petter SelaskyJan 13, 2023
  14. Konstantin RyabitsevJan 13, 2023
  15. Hans Petter SelaskyJan 13, 2023
  16. Konstantin RyabitsevJan 13, 2023
  17. Hans Petter SelaskyJan 13, 2023
  18. Konstantin RyabitsevJan 13, 2023
  19. Hans Petter SelaskyJan 13, 2023
  20. Hans Petter SelaskyJan 13, 2023
  21. Konstantin RyabitsevJan 13, 2023
  22. Hans Petter SelaskyJan 13, 2023
  23. Hans Petter SelaskyJan 13, 2023
  24. Philip OakleyJan 13, 2023
  25. Konstantin RyabitsevJan 13, 2023
  26. Konstantin KhomoutovJan 13, 2023

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.