git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH v2 7/7] hex: allow only lowercase object IDs in breaking changes mode

From
brian m. carlson <sandals@crustytoothpaste.net>
Date
Sep 7, 2026, 19:59 UTC
Message-ID
<20260907195941.1024289-8-sandals@crustytoothpaste.net>
In-Reply-To
<20260907195941.1024289-1-sandals@crustytoothpaste.net>

Git has historically allowed either lowercase or uppercase hex for object IDs, but it has always emitted only lowercase. This has caused people to expect only lowercase and not handle uppercase.

As an example, Git's own example hooks look for "[0-9a-f]" in several places, but there are many other Git-adjacent pieces of software, including Gitolite, which make the assumption that object IDs are always lowercase. This is not to criticize the authors of these projects, but rather to point out how common this assumption is. In fact, it's so common that we had only one test in our codebase that failed when we reject uppercase object IDs.

More critically, it leads people to make security-based assumptions that an object ID either does not contain uppercase characters or that an object ID can be expressed uniquely in hex form, neither of which are currently true. Git itself normally uses binary object IDs, which avoids many of these problems, but most other projects deal primarily in hex object IDs, so they are more affected.

In preparation for Git 3.0, only allow lowercase hex object IDs in breaking changes mode and document this as well. Add a new test to verify we reject new uppercase object IDs.

Signed-off-by: brian m. carlson <sandals@crustytoothpaste.net>
---
 Documentation/BreakingChanges.adoc | 5 +++++
 hex-ll.h                           | 4 ++++
 t/t1503-rev-parse-verify.sh        | 5 +++++
 3 files changed, 14 insertions(+)
diff --git a/Documentation/BreakingChanges.adoc b/Documentation/BreakingChanges.adoc
index 73bb939359..dbc46d14e3 100644
--- a/Documentation/BreakingChanges.adoc
+++ b/Documentation/BreakingChanges.adoc
@@ -171,6 +171,11 @@ JGit, libgit2 and Gitoxide need to support it.
   matches the default branch name used in new repositories by many of the
   big Git forges.
 
+* Git will accept hex object IDs only in lowercase. The fact that Git has
+	historically allowed uppercase characters in hex object IDs has been the
+	source of a variety of bugs and security problems in software using Git. We
+	don't expect most users to notice any change.
+
 * Git will require Rust as a mandatory part of the build process. While Git
   already started to adopt Rust in Git 2.49, all parts written in Rust are
   optional for the time being. This includes:
diff --git a/hex-ll.h b/hex-ll.h
index 9da76f17e8..2f9c8d7c25 100644
--- a/hex-ll.h
+++ b/hex-ll.h
@@ -6,7 +6,11 @@ enum hexkind {
 	HEX_KIND_LOWER = 1,
 };
 
+#ifdef WITH_BREAKING_CHANGES
+#define HEX_KIND_OID HEX_KIND_LOWER
+#else
 #define HEX_KIND_OID HEX_KIND_MIXED
+#endif
 
 extern const signed char hexval_table[256];
 extern const signed char hexval_lc_table[256];
diff --git a/t/t1503-rev-parse-verify.sh b/t/t1503-rev-parse-verify.sh
index 87638a4a2c..f07b45de5a 100755
--- a/t/t1503-rev-parse-verify.sh
+++ b/t/t1503-rev-parse-verify.sh
@@ -60,6 +60,11 @@ test_expect_success 'works with one good rev' '
 	test "$rev_head" = "$HASH4"
 '
 
+test_expect_success WITH_BREAKING_CHANGES 'rejects uppercase revs' '
+	UC_HASH=$(echo "$HASH1" | tr a-f A-F) &&
+	test_must_fail git rev-parse --verify "$UC_HASH"
+'
+
 test_expect_success 'fails with any bad rev or many good revs' '
 	test_must_fail git rev-parse --verify 2>error &&
 	test_grep "single revision" error &&
Previous: brian m. carlson
Message 41 of 41 in “Git 3.0: restrict hex object IDs to lowercase only”
  1. 0/6 Git 3.0: restrict hex object IDs to lowercase onlybrian m. carlson, Jul 29, 2026
  2. 2/6 hex: allow specifying hex type with hex2chrbrian m. carlson, Jul 29, 2026
  3. 4/6 hex: label usages of hex parsing for object IDsbrian m. carlson, Jul 29, 2026
  4. Junio C HamanoJul 31, 2026
  5. Junio C HamanoAug 25, 2026
  6. 1/6 hex: add functionality for lowercase-only hexbrian m. carlson, Jul 29, 2026
  7. Junio C HamanoJul 31, 2026
  8. Junio C HamanoAug 25, 2026
  9. brian m. carlsonAug 25, 2026
  10. 3/6 hex: make hex_to_bytes accept kind of hex to usebrian m. carlson, Jul 29, 2026
  11. Junio C HamanoJul 31, 2026
  12. Jeff KingAug 1, 2026
  13. 5/6 object-name: use hexvalbrian m. carlson, Jul 29, 2026
  14. Junio C HamanoAug 25, 2026
  15. Elijah NewrenAug 25, 2026
  16. brian m. carlsonAug 25, 2026
  17. 6/6 hex: allow only lowercase object IDs in breaking changes modebrian m. carlson, Jul 29, 2026
  18. Junio C HamanoJul 31, 2026
  19. Junio C HamanoJul 31, 2026
  20. brian m. carlsonAug 2, 2026
  21. Junio C HamanoAug 4, 2026
  22. brian m. carlsonAug 4, 2026
  23. Michael MontalboAug 5, 2026
  24. Phillip WoodAug 25, 2026
  25. brian m. carlsonAug 25, 2026
  26. Phillip WoodSep 7, 2026
  27. Junio C HamanoAug 25, 2026
  28. Elijah NewrenAug 25, 2026
  29. Junio C HamanoJul 30, 2026
  30. brian m. carlsonJul 30, 2026
  31. Jeff KingAug 1, 2026
  32. Junio C HamanoAug 1, 2026
  33. brian m. carlsonAug 2, 2026
  34. 0/7 Git 3.0: restrict hex object IDs to lowercase onlybrian m. carlson, Sep 7, 2026
  35. 4/7 hex: label usages of hex parsing for object IDsbrian m. carlson, Sep 7, 2026
  36. 2/7 hex: allow specifying hex type with hex2chrbrian m. carlson, Sep 7, 2026
  37. 3/7 hex: make hex_to_bytes accept kind of hex to usebrian m. carlson, Sep 7, 2026
  38. 1/7 hex: add functionality for lowercase-only hexbrian m. carlson, Sep 7, 2026
  39. 5/7 object-name: use hexvalbrian m. carlson, Sep 7, 2026
  40. 6/7 t5324: adjust tests for corrupt commit-graphbrian m. carlson, Sep 7, 2026
  41. 7/7 hex: allow only lowercase object IDs in breaking changes modebrian m. carlson, Sep 7, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.