git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [RFC PATCH 0/6] Git 3.0: restrict hex object IDs to lowercase only

From
Jeff King <peff@peff.net>
Date
Aug 1, 2026, 14:45 UTC
Message-ID
<20260801144527.GF2041176@coredump.intra.peff.net>
In-Reply-To
<amu_rzanuYc_2lww@fruit.crustytoothpaste.net>
On Thu, Jul 30, 2026 at 09:18:40PM +0000, brian m. carlson wrote:
Show 6 quoted lines
> The situation is presently that Git will accept them and this leads to
> surprising behaviour, but almost all adjacent software rejects or
> mishandles them.  I'm arguing that we should stop accepting hex object
> ID formats that cannot be effectively used in the Git ecosystem but
> whose presence is effectively only ever the source of misbehaviour and
> security vulnerabilities.
Another interesting case is upper-case hex within objects:
  $ git rev-parse HEAD
  b85b9595a8136c79551340c3d73443a62eddd893
  $ git cat-file commit HEAD |
    perl -lpe '
        if (/^parent (.*)/) {
		$_ = "parent " . uc($1);
	}
    ' |
    git hash-object -w -t commit --stdin
  5a08c6b3f06d91c4a09c8d7ea6e9c8ce200b7698

Now there's a parallel history of otherwise identical commits. I think this is mostly "if it hurts don't do it", but we generally try to avoid multiple representations of the same data within the object model.

I think only commits and tags are subject to this (because the tree hashes are binary). I don't know if you'd be able to stumble into this accidentally with most Git commands. We don't intentionally normalize case anywhere, but I think most code will round-trip through a binary hash at some point (so "git commit-tree 1234ABCD" would incidentally normalize the case).

-Peff
Previous: brian m. carlsonNext: Junio C Hamano
Message 31 of 41 in “Git 3.0: restrict hex object IDs to lowercase only”
  1. 0/6 Git 3.0: restrict hex object IDs to lowercase onlybrian m. carlson, Jul 29, 2026
  2. 2/6 hex: allow specifying hex type with hex2chrbrian m. carlson, Jul 29, 2026
  3. 4/6 hex: label usages of hex parsing for object IDsbrian m. carlson, Jul 29, 2026
  4. Junio C HamanoJul 31, 2026
  5. Junio C HamanoAug 25, 2026
  6. 1/6 hex: add functionality for lowercase-only hexbrian m. carlson, Jul 29, 2026
  7. Junio C HamanoJul 31, 2026
  8. Junio C HamanoAug 25, 2026
  9. brian m. carlsonAug 25, 2026
  10. 3/6 hex: make hex_to_bytes accept kind of hex to usebrian m. carlson, Jul 29, 2026
  11. Junio C HamanoJul 31, 2026
  12. Jeff KingAug 1, 2026
  13. 5/6 object-name: use hexvalbrian m. carlson, Jul 29, 2026
  14. Junio C HamanoAug 25, 2026
  15. Elijah NewrenAug 25, 2026
  16. brian m. carlsonAug 25, 2026
  17. 6/6 hex: allow only lowercase object IDs in breaking changes modebrian m. carlson, Jul 29, 2026
  18. Junio C HamanoJul 31, 2026
  19. Junio C HamanoJul 31, 2026
  20. brian m. carlsonAug 2, 2026
  21. Junio C HamanoAug 4, 2026
  22. brian m. carlsonAug 4, 2026
  23. Michael MontalboAug 5, 2026
  24. Phillip WoodAug 25, 2026
  25. brian m. carlsonAug 25, 2026
  26. Phillip WoodSep 7, 2026
  27. Junio C HamanoAug 25, 2026
  28. Elijah NewrenAug 25, 2026
  29. Junio C HamanoJul 30, 2026
  30. brian m. carlsonJul 30, 2026
  31. Jeff KingAug 1, 2026
  32. Junio C HamanoAug 1, 2026
  33. brian m. carlsonAug 2, 2026
  34. 0/7 Git 3.0: restrict hex object IDs to lowercase onlybrian m. carlson, Sep 7, 2026
  35. 4/7 hex: label usages of hex parsing for object IDsbrian m. carlson, Sep 7, 2026
  36. 2/7 hex: allow specifying hex type with hex2chrbrian m. carlson, Sep 7, 2026
  37. 3/7 hex: make hex_to_bytes accept kind of hex to usebrian m. carlson, Sep 7, 2026
  38. 1/7 hex: add functionality for lowercase-only hexbrian m. carlson, Sep 7, 2026
  39. 5/7 object-name: use hexvalbrian m. carlson, Sep 7, 2026
  40. 6/7 t5324: adjust tests for corrupt commit-graphbrian m. carlson, Sep 7, 2026
  41. 7/7 hex: allow only lowercase object IDs in breaking changes modebrian m. carlson, Sep 7, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.