git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Is GIT_DEFAULT_HASH flawed?

From
Felipe Contreras <felipe.contreras@gmail.com>
Date
May 8, 2023, 00:34 UTC
Message-ID
<645843afce409_4e6129427@chronos.notmuch>
In-Reply-To
<31868D65-0456-4594-AB2C-C4735B8F1D75@zombino.com>
Adam Majer wrote:
Show 5 quoted lines
> On May 3, 2023 5:44:24 p.m. GMT+02:00, Felipe Contreras <felipe.contreras@gmail.com> wrote:
> >Git was designed to make it *impossible* to confuse two commits with similar
> >data.
> 
> That was never ever the problem here.
But it will be.
Show 6 quoted lines
> >> This is different. But aside, type + size + data are not really much 
> >> different from just having data in a hash function.
> >
> >It's completely different.
> 
> How so? Type and size are just about 2 and a dozen bits of data, respectfully.
Do you understand how checksums work?
Compare these two objects:
 1. 0beec7b5ea3f0fdbc95d0dd47f3c5bc275da8a33
 2. 6ba62a7c5e3e9a260c5a30adf2756882c02f12a6
Are they a) "not much different", or b) "completely different"?
Answer: doesn't matter, they are *different*. Period.
Show 6 quoted lines
> >There are different philosophical views of what "security" means, and it seems
> >pretty clear to me that your view does not align with the view of Linus
> >Torvalds.
> 
> 
> I'm not sure why you are name dropping Linus everywhere
I don't know if you are aware, but Linus Torvalds is the author of git.

He also happens to be the author of the most successful software project in history: Linux.

So generally his design choices are considered to be good.
> or assuming you know more than anyone here about hash functions.
I don't assume such a thing.

But I'm pretty certain not many people are aware of the integrity issues VCSs presented circa 2004, that git hashes solved in 2005, because if they did, they could have created an object model storage similar to git's, and no one did (except Linus Torvalds).

> Your explanation is quite clear to me (and probably everyone else
> here). But I'll just leave it at that.

Is it? Then you would have no trouble steel manning my argument, which you haven't done.

-- 
Felipe Contreras
Previous: Adam MajerNext: demerphq
Message 37 of 58 in “git clone of empty repositories doesn't preserve hash”
  1. Adam MajerApr 5, 2023
  2. Junio C HamanoApr 5, 2023
  3. Adam MajerApr 5, 2023
  4. Jeff KingApr 5, 2023
  5. Junio C HamanoApr 5, 2023
  6. Junio C HamanoApr 5, 2023
  7. Jeff KingApr 5, 2023
  8. brian m. carlsonApr 5, 2023
  9. Adam MajerApr 6, 2023
  10. brian m. carlsonApr 25, 2023
  11. Junio C HamanoApr 25, 2023
  12. Junio C HamanoApr 25, 2023
  13. brian m. carlsonApr 26, 2023
  14. Jeff KingApr 26, 2023
  15. Junio C HamanoApr 26, 2023
  16. doc: GIT_DEFAULT_HASH is and will be ignored during "clone"Junio C Hamano, Apr 26, 2023
  17. brian m. carlsonApr 26, 2023
  18. Jeff KingApr 27, 2023
  19. Jeff KingApr 26, 2023
  20. Junio C HamanoApr 26, 2023
  21. brian m. carlsonApr 26, 2023
  22. 0/2 Fix empty SHA-256 clones with v0 and v1brian m. carlson, Apr 26, 2023
  23. 1/2 http: advertise capabilities when cloning empty reposbrian m. carlson, Apr 26, 2023
  24. Junio C HamanoApr 26, 2023
  25. brian m. carlsonApr 26, 2023
  26. Jeff KingApr 27, 2023
  27. Jeff KingApr 27, 2023
  28. Junio C HamanoApr 27, 2023
  29. 2/2 Honor GIT_DEFAULT_HASH for empty clones without remote algobrian m. carlson, Apr 26, 2023
  30. Junio C HamanoApr 26, 2023
  31. Junio C HamanoApr 26, 2023
  32. Jeff KingApr 27, 2023
  33. Is GIT_DEFAULT_HASH flawed?Felipe Contreras, May 2, 2023
  34. Adam MajerMay 3, 2023
  35. Felipe ContrerasMay 3, 2023
  36. Adam MajerMay 3, 2023
  37. Felipe ContrerasMay 8, 2023
  38. demerphqMay 3, 2023
  39. Felipe ContrerasMay 3, 2023
  40. brian m. carlsonMay 3, 2023
  41. Felipe ContrerasMay 8, 2023
  42. brian m. carlsonMay 8, 2023
  43. Oswald BuddenhagenMay 9, 2023
  44. Junio C HamanoMay 9, 2023
  45. Junio C HamanoApr 26, 2023
  46. Jeff KingApr 27, 2023
  47. 0/1 Fix empty SHA-256 clones with v0 and v1brian m. carlson, May 1, 2023
  48. 1/1 upload-pack: advertise capabilities when cloning empty reposbrian m. carlson, May 1, 2023
  49. Jeff KingMay 1, 2023
  50. Junio C HamanoMay 1, 2023
  51. Junio C HamanoMay 1, 2023
  52. 0/1 Fix empty SHA-256 clones with v0 and v1brian m. carlson, May 17, 2023
  53. 1/1 upload-pack: advertise capabilities when cloning empty reposbrian m. carlson, May 17, 2023
  54. Junio C HamanoMay 17, 2023
  55. brian m. carlsonMay 17, 2023
  56. Jeff KingMay 18, 2023
  57. brian m. carlsonMay 19, 2023
  58. Jeff KingApr 5, 2023

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.