git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Security problem

From
Junio C Hamano <junkio@cox.net>
Date
Jun 16, 2006, 00:12 UTC
Message-ID
<7vbqsuc60q.fsf@assigned-by-dhcp.cox.net>
In-Reply-To
<200606151709.22752.lan@academsoft.ru>
Alexander Litvinov <lan@academsoft.ru> writes:
> Why does not git-checkout check if file content match name of the object ?
Good point.  We could do a few things:
 - entry.c:write_entry() could validate after read_sha1_file(). 
 - read_sha1_file() could do the checking; this has performance
   implications, though.

Cloning over git aware protocols validate the objects coming over the wire, so it may make sense to cheat and do the former, so that we do not have to pay the validation cost every time we access any object.

Next: Linus Torvalds
Message 1 of 8 in “Re: Security problem”
  1. Junio C HamanoJun 16, 2006
  2. Linus TorvaldsJun 16, 2006
  3. Linus TorvaldsJun 16, 2006
  4. Alexander LitvinovJun 16, 2006
  5. Linus TorvaldsJun 16, 2006
  6. Alexander LitvinovJun 16, 2006
  7. Linus TorvaldsJun 16, 2006
  8. Alexander LitvinovJun 16, 2006

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.