From: Johannes Sixt Date: Tue, 09 Apr 2013 06:03:24 GMT Subject: Re: commit-message attack for extracting sensitive data from rewritten Git history Message-ID: <5163AF2C.2020107@viscovery.net> In-Reply-To: <20130408215457.GB11227@sigill.intra.peff.net> Am 4/8/2013 23:54, schrieb Jeff King: > Yeah, it would make sense for filter-branch to have a "--map-commit-ids" > option or similar that does the update. At first I thought it might take > two passes, but I don't think it is necessary, as long as we traverse > the commits topologically (i.e., you cannot have mentioned X in a commit > that is an ancestor of X, so you do not have to worry about mapping it > until after it has been processed). Topological traversal is not sufficient. Consider this history: o--A--o-- / / --o--B--o If A mentions B (think of cherry-pick -x), then you must ensure that the branch containing B was traversed first. -- Hannes