From: brian m. carlson Date: Wed, 12 Nov 2025 23:54:34 GMT Subject: [PATCH] object-file: disallow adding submodules of different hash algo Message-ID: <20251112235434.1499699-1-sandals@crustytoothpaste.net> In-Reply-To: The design of the hash algorithm transition plan is that objects stored must be entirely in one algorithm since we lack any way to indicate a mix of algorithms. This also includes submodules, but we have traditionally not enforced this, which leads to various problems when trying to clone or check out the the submodule from the remote. Since this cannot work in the general case, restrict adding a submodule of a different algorithm to the index. Add tests for git add and git submodule add that these are rejected. Note that we cannot check this in git fsck because the malformed submodule is stored in the tree as an object ID which is either truncated (when a SHA-256 submodule is added to a SHA-1 repository) or padded with zeros (when a SHA-1 submodule is added to a SHA-256 repository). We cannot detect even the latter case because someone could have an actual submodule that actually ends in 24 zeros, which would be a false positive. Signed-off-by: brian m. carlson --- object-file.c | 6 +++++- t/t3700-add.sh | 27 +++++++++++++++++++++++++++ t/t7400-submodule-basic.sh | 27 +++++++++++++++++++++++++++ 3 files changed, 59 insertions(+), 1 deletion(-) diff --git a/object-file.c b/object-file.c index 4675c8ed6b..8c43c52ed0 100644 --- a/object-file.c +++ b/object-file.c @@ -1661,7 +1661,11 @@ int index_path(struct index_state *istate, struct object_id *oid, strbuf_release(&sb); break; case S_IFDIR: - return repo_resolve_gitlink_ref(istate->repo, path, "HEAD", oid); + if (repo_resolve_gitlink_ref(istate->repo, path, "HEAD", oid)) + return -1; + if (&hash_algos[oid->algo] != istate->repo->hash_algo) + return error(_("cannot add a submodule of a different hash algorithm")); + break; default: return error(_("%s: unsupported file type"), path); } diff --git a/t/t3700-add.sh b/t/t3700-add.sh index df580a5806..b075eb9b11 100755 --- a/t/t3700-add.sh +++ b/t/t3700-add.sh @@ -541,6 +541,33 @@ test_expect_success 'all statuses changed in folder if . is given' ' ) ' +test_expect_success 'cannot add a submodule of a different algorithm' ' + git init --object-format=sha256 sha256 && + ( + cd sha256 && + test_commit abc && + git init --object-format=sha1 submodule && + ( + cd submodule && + test_commit def + ) && + test_must_fail git add submodule && + test $(git ls-files --stage | grep ^160000 | wc -l) -eq 0 + ) && + git init --object-format=sha1 sha1 && + ( + cd sha1 && + test_commit abc && + git init --object-format=sha256 submodule && + ( + cd submodule && + test_commit def + ) && + test_must_fail git add submodule && + test $(git ls-files --stage | grep ^160000 | wc -l) -eq 0 + ) +' + test_expect_success CASE_INSENSITIVE_FS 'path is case-insensitive' ' path="$(pwd)/BLUB" && touch "$path" && diff --git a/t/t7400-submodule-basic.sh b/t/t7400-submodule-basic.sh index fd3e7e355e..b190182d62 100755 --- a/t/t7400-submodule-basic.sh +++ b/t/t7400-submodule-basic.sh @@ -407,6 +407,33 @@ test_expect_success 'submodule add in subdirectory with relative path should fai test_grep toplevel output.err ' +test_expect_success 'submodule add of a different algorithm fails' ' + git init --object-format=sha256 sha256 && + ( + cd sha256 && + test_commit abc && + git init --object-format=sha1 submodule && + ( + cd submodule && + test_commit def + ) && + test_must_fail git submodule add "$submodurl" submodule && + test $(git ls-files --stage | grep ^160000 | wc -l) -eq 0 + ) && + git init --object-format=sha1 sha1 && + ( + cd sha1 && + test_commit abc && + git init --object-format=sha256 submodule && + ( + cd submodule && + test_commit def + ) && + test_must_fail git submodule add "$submodurl" submodule && + test $(git ls-files --stage | grep ^160000 | wc -l) -eq 0 + ) +' + test_expect_success 'setup - add an example entry to .gitmodules' ' git config --file=.gitmodules submodule.example.url git://example.com/init.git '