git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: verifying git file contents without checking out history?

From
Junio C Hamano <gitster@pobox.com>
Date
Nov 19, 2012, 04:55 UTC
Message-ID
<7vtxsmxkcp.fsf@alter.siamese.dyndns.org>
In-Reply-To
<1353287836-sup-270@nixos>
Marc Weber <marco-oweber@gmx.de> writes:
> git clone --depth=20 $url; git checkout $hash
>
> How to verify that I have the contents I think I have - given that I
> trust my local git executable?

Define what you mean by "contents". Do you care only about the tree state recorded in that $hash, and you also trust that $hash is the correct one?

  $ git cat-object commit $hash | git hash-object --stdin -t commit

would be a way to verify that you do have the commit object everybody else calls $hash, and you can verify the objects contained within the commit whose name is $hash (i.e. its tree and its parents) in a similar way. Use "git ls-tree $tree" to find out the objects your top-level tree recorded in the commit $hash, and you can verify the contents recorded in the tree object recursively.

Previous: Marc WeberNext: Marc Weber
Message 2 of 3 in “verifying git file contents without checking out history?”
  1. Marc WeberNov 19, 2012
  2. Junio C HamanoNov 19, 2012
  3. Marc WeberNov 19, 2012

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.