git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: SHA-256 transition

From
Ævar Arnfjörð Bjarmason <avarab@gmail.com>
Date
Jun 24, 2022, 01:19 UTC
Message-ID
<220624.867d56kg04.gmgdl@evledraar.gmail.com>
In-Reply-To
<12140906.O9o76ZdvQC@thunderbird>
On Thu, Jun 23 2022, Stephen Smith wrote:
Show 8 quoted lines
> On Thursday, June 23, 2022 3:21:05 PM MST Ævar Arnfjörð Bjarmason wrote:
>> Finally, I'd really like to thank you for all your work on SHA-256 so
>> far, and really hope that none of what I've said here is discouraging in
>> any way. This thread has received some attention outside this ML (on
>> LWN), so I wanted to clarify some of the points above. Thanks!
>
> I had looked on LWN before I started the thread to see if anything was being 
> discussed and it wasn't.

It wouldn't have helped, as I'm referring to LWN having written an article about this thread that you started :)

It's part of an ongoing series they've had about Git's SHA-256 transition.

Given how LWN makes money I don't know if it's OK to link to it, but it's easy enough to find and/or subscribe to LWN.

> I tend to be an early adopter.   I hadn't seen any new commits in the main git 
> repository in a while and was beginning to wonder if it had been abandoned.   
> This thread has convinced me that isn't the case, but the main person doing 
> the developing being busy.
It was a good discussion, and I'm happy you started it.

I think I've mentioned in some past discussions that it would be nice to have some "gitsecurity" user-facing documentation, and one thing such a thing could include is information that helped users to make an informed decision about how much (if at all) they should be worrying about issues arising from what hash they're using Git with.

But some documentation on the questions raised here would also be good, i.e. "should I use the new hash?", which we could keep somewhat up-to-date, and e.g. talk about the approximate state of major third-party software, such as the forges.

Currently the closest thing we have to that is the rather sparse and scary "THIS OPTION IS EXPERIMENTAL" in git-init(1) when talking about --object-format=sha256.

> I too want to say thank you (Brian) for your hard work.   

And thank you for using & being interested in git, and contributing to the ML!

Previous: Stephen SmithNext: Jonathan Corbet
Message 13 of 21 in “SHA-256 transition”
  1. Stephen SmithJun 20, 2022
  2. rsbecker@nexbridge.comJun 20, 2022
  3. Ævar Arnfjörð BjarmasonJun 21, 2022
  4. rsbecker@nexbridge.comJun 21, 2022
  5. Ævar Arnfjörð BjarmasonJun 21, 2022
  6. brian m. carlsonJun 22, 2022
  7. Stephen SmithJun 23, 2022
  8. brian m. carlsonJun 23, 2022
  9. Junio C HamanoJun 23, 2022
  10. Ævar Arnfjörð BjarmasonJun 23, 2022
  11. Kyle MeyerJun 24, 2022
  12. Stephen SmithJun 24, 2022
  13. Ævar Arnfjörð BjarmasonJun 24, 2022
  14. Jonathan CorbetJun 24, 2022
  15. Jeff KingJun 24, 2022
  16. Ævar Arnfjörð BjarmasonJun 24, 2022
  17. brian m. carlsonJun 25, 2022
  18. Plan for SHA-256 repos to support SHA-1?Eric W. Biederman, Jun 26, 2022
  19. Junio C HamanoJun 26, 2022
  20. brian m. carlsonJun 26, 2022
  21. Jeff KingJul 1, 2022

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.