git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] Receive-pack: include entire SHA1 in nonce

From
Brian Gernhardt <brian@gernhardtsoftware.com>
Date
Sep 25, 2014, 18:03 UTC
Message-ID
<84433534-D6A9-4FD3-BA53-DCD610B64251@gernhardtsoftware.com>
In-Reply-To
<xmqqa95nbn7g.fsf@gitster.dls.corp.google.com>
On Sep 25, 2014, at 1:54 PM, Junio C Hamano <gitster@pobox.com> wrote:
Show 18 quoted lines
> Junio C Hamano <gitster@pobox.com> writes:
> 
>> I am not happy with this version, either, though, because now we
>> have an uninitialized piece of memory at the end of sha1[20] of the
>> caller, which is given to sha1_to_hex() to produce garbage.  It is
>> discarded by %.*s format so there is no negative net effect, but I
>> suspect that the compiler would not see that through.
> 
> ... and if we want to fix that, we would end up with a set of
> changes, somewhat ugly like this.
> 
> Which might be an improvement, but let's start with your "sizeof(arg)
> is the size of a pointer, even when the definition of arg[] is
> spelled with bra-ket, a dummy maintainer!" fix.
> 
> I'd like to have your sign-off.  I'd also prefer to retitle it as
> something like "hmac_sha1: copy the entire SHA-1 hash out", as it is
> deliberate that we do not include the entire SHA-1 in nonce.
It's been long enough since I've done any crypto, so I didn't really know what the algorithm should look like.  Mostly I remember "doing it right is hard", so don't feel too bad.  Making the commit message accurate is perfectly fine, and all the patches you've posted look right at first glance (and to make test as well), so I'm fine with a 
Signed-off-by: Brian Gernhardt <brian@gernhardtsoftware.com>
attached to whatever commit is actually appropriate instead of the minimum to make my compiler happy.  :-)
~~ Brian
Previous: Junio C Hamano
Message 5 of 5 in “Receive-pack: include entire SHA1 in nonce”
  1. Receive-pack: include entire SHA1 in nonceBrian Gernhardt, Sep 25, 2014
  2. Junio C HamanoSep 25, 2014
  3. Junio C HamanoSep 25, 2014
  4. Junio C HamanoSep 25, 2014
  5. Brian GernhardtSep 25, 2014

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.