git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: commit-message attack for extracting sensitive data from rewritten Git history

From
Johannes Sixt <j.sixt@viscovery.net>
Date
Apr 9, 2013, 06:03 UTC
Message-ID
<5163AF2C.2020107@viscovery.net>
In-Reply-To
<20130408215457.GB11227@sigill.intra.peff.net>
Am 4/8/2013 23:54, schrieb Jeff King:
Show 6 quoted lines
> Yeah, it would make sense for filter-branch to have a "--map-commit-ids"
> option or similar that does the update. At first I thought it might take
> two passes, but I don't think it is necessary, as long as we traverse
> the commits topologically (i.e., you cannot have mentioned X in a commit
> that is an ancestor of X, so you do not have to worry about mapping it
> until after it has been processed).
Topological traversal is not sufficient. Consider this history:
     o--A--o--
    /     /
 --o--B--o

If A mentions B (think of cherry-pick -x), then you must ensure that the branch containing B was traversed first.

-- Hannes
Previous: Jeff KingNext: Jeff King
Message 4 of 6 in “commit-message attack for extracting sensitive data from rewritten Git history”
  1. Roberto TyleyApr 7, 2013
  2. Junio C HamanoApr 8, 2013
  3. Jeff KingApr 8, 2013
  4. Johannes SixtApr 9, 2013
  5. Jeff KingApr 9, 2013
  6. Roberto TyleyApr 9, 2013

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.