git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v3 2/3] t/: port helper/test-sha1.c to unit-tests/t-hash.c

From
Jeff King <peff@peff.net>
Date
Jun 16, 2024, 04:52 UTC
Message-ID
<20240616045259.GA17750@coredump.intra.peff.net>
In-Reply-To
<6fhpz4aqq7jr6ca2durig7e5a37g6ndzjjc2v46kjjkldohtja@tu7cdo4tu2r6>
On Sun, Jun 16, 2024 at 01:44:07AM +0530, Ghanshyam Thakkar wrote:
Show 21 quoted lines
> On Fri, 24 May 2024, Junio C Hamano <gitster@pobox.com> wrote:
> > Christian Couder <christian.couder@gmail.com> writes:
> > 
> > >> Can we refactor this test to stop doing that? E.g., would it work if we
> > >> used git-hash-object(1) to check that SHA1DC does its thing? Then we
> > >> could get rid of the helper altogether, as far as I understand.
> > >
> > > It could perhaps work if we used git-hash-object(1) instead of
> > > `test-tool sha1` in t0013-sha1dc to check that SHA1DC does its thing,
> > > but we could do that in a separate patch or patch series.
> > 
> > Yeah, I think such a plan to make preliminary refactoring as a
> > separate series, and then have another series to get rid of
> > "test-tool sha1" (and "test-tool sha256" as well?) on top of it
> > would work well.
> 
> It seems that git-hash-object does not die (or give an error) when
> providing t0013/shattered-1.pdf, and gives a different hash than the
> one explicitly mentioned t0013-sha1dc.sh. I suppose it is silently
> replacing the hash when it detects the collision. Is this an expected
> behaviour?

The shattered files do not create a collision (nor trigger the detection in sha1dc) when hashed as Git objects. The reason is that Git objects are not a straight hash of the contents, but have the object type and size prepended. One _could_ use the same techniques that created the shattered files to create a colliding set of Git objects, but AFAIK nobody has done so (and it probably costs tens of thousands of USD, though perhaps getting cheaper every year).

So no, git-hash-object can't be used to test this. You have to directly hash some contents with sha1, and I don't think there is any way to do that with regular Git commands. Anything working with objects will use the type+size format. We also use sha1 for the csum-file.[ch] mechanism, where it is a straight hash of the contents (and we use this for packfiles, etc). But there's not an easy way to feed an arbitrary file to that system.

It's possible there might be a way to abuse hashfd_check() to feed an arbitrary file. E.g., stick shattered-1.pdf into a .pack file or something, then ask "index-pack --verify" to check it. But I don't think even that works, because before we even get to the final checksum, we're verifying the actual contents as we go.

So I think we need to keep some mechanism for computing the sha1 of arbitrary contents.

-Peff
Previous: Ghanshyam ThakkarNext: Junio C Hamano
Message 20 of 35 in “strbuf: introduce strbuf_addstrings() to repeatedly add a string”
  1. Achu LumaFeb 26, 2024
  2. [Outreachy][PATCH 2/2] Port helper/test-sha256.c and helper/test-sha1.c to unit-tests/t-hash.cAchu Luma, Feb 26, 2024
  3. Junio C HamanoFeb 26, 2024
  4. Christian CouderFeb 26, 2024
  5. Junio C HamanoFeb 26, 2024
  6. Christian CouderFeb 27, 2024
  7. [Outreachy][PATCH v2 1/2] strbuf: introduce strbuf_addstrings() to repeatedly add a stringAchu Luma, Feb 29, 2024
  8. [Outreachy][PATCH v2 2/2] Port helper/test-sha256.c and helper/test-sha1.c to unit-tests/t-hash.cAchu Luma, Feb 29, 2024
  9. Christian CouderMar 6, 2024
  10. Patrick SteinhardtMar 26, 2024
  11. Christian CouderMar 26, 2024
  12. Ghanshyam ThakkarMay 16, 2024
  13. 0/3 Port t0015-hash to the unit testing frameworkGhanshyam Thakkar, May 23, 2024
  14. 1/3 strbuf: introduce strbuf_addstrings() to repeatedly add a stringGhanshyam Thakkar, May 23, 2024
  15. 2/3 t/: port helper/test-sha1.c to unit-tests/t-hash.cGhanshyam Thakkar, May 23, 2024
  16. Patrick SteinhardtMay 24, 2024
  17. Christian CouderMay 24, 2024
  18. Junio C HamanoMay 24, 2024
  19. Ghanshyam ThakkarJun 15, 2024
  20. Jeff KingJun 16, 2024
  21. Junio C HamanoJun 17, 2024
  22. Ghanshyam ThakkarJun 21, 2024
  23. 3/3 t/: port helper/test-sha256.c to unit-tests/t-hash.cGhanshyam Thakkar, May 23, 2024
  24. Patrick SteinhardtMay 24, 2024
  25. Ghanshyam ThakkarMay 25, 2024
  26. 0/2 t/: port helper/test-{sha1, sha256} to unit-tests/t-hashGhanshyam Thakkar, May 26, 2024
  27. 1/2 strbuf: introduce strbuf_addstrings() to repeatedly add a stringGhanshyam Thakkar, May 26, 2024
  28. 2/2 t/: migrate helper/test-{sha1, sha256} to unit-tests/t-hashGhanshyam Thakkar, May 26, 2024
  29. Patrick SteinhardtMay 29, 2024
  30. Junio C HamanoMay 29, 2024
  31. [GSoC][PATCH v5 0/2] t/: migrate helper/test-{sha1, sha256} to unit-tests/t-hashGhanshyam Thakkar, May 29, 2024
  32. 1/2 strbuf: introduce strbuf_addstrings() to repeatedly add a stringGhanshyam Thakkar, May 29, 2024
  33. 2/2 t/: migrate helper/test-{sha1, sha256} to unit-tests/t-hashGhanshyam Thakkar, May 29, 2024
  34. Patrick SteinhardtMay 29, 2024
  35. Junio C HamanoMay 29, 2024

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.