git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH] t1016-compatObjectFormat: Really freeze time for reproduciblity

From
Eric W. Biederman <ebiederm@xmission.com>
Date
Oct 28, 2025, 16:01 UTC
Message-ID
<87frb310d2.fsf_-_@email.froward.int.ebiederm.org>
In-Reply-To
<xmqqms5chyr8.fsf@gitster.g>

The strategy in t1016-compatObjectFormat is to build two trees with identical commits, one tree encoded in sha1 the other tree encoded in sha256 and to use the compatibility code to test and see if the two trees are identical.

GPG signatures include the current time as part of the signature.

To make gpg deterministic I forced the use of gpg --faked-system-time. Unfortunately I did not look closely enough.

By default gpg still allows time to move forward with --faked-system-time. So in those rare instances when the system is heavily loaded an gpg runs slower than other times, signatures over the exact same data differ due to timestamps with a minuscule difference.

Reading through the gpg documentation with a close eye, time can be frozen by including an exclamation point at the end of the argument to --faked-system-time.

Add the exclamation point so gpg really runs with a fixed notion of time, resulting in the exact same data having identical gpg signatures.

That is enough that I can run "t1016-compatObjectFormat.sh --stress" and I don't see any failures.

It is possible a future change to gpg will make replay protection more robust and not provide a way to allow two separate runs of gpg to produce exactly the same signature for exactly the same data. If that happens a deeper comparison of the two repositories will need to be performed. A comparison that simply verifies the signatures and compares the data for equality. For now that is a lot of work for no gain so I am just documenting the possibility.

Signed-off-by: Eric W. Biederman <ebiederm@xmission.com>
---
 t/t1016-compatObjectFormat.sh | 6 ++++++
 t/t1016/gpg                   | 2 +-
 2 files changed, 7 insertions(+), 1 deletion(-)
diff --git a/t/t1016-compatObjectFormat.sh b/t/t1016-compatObjectFormat.sh
index a9af8b239626..0efce53f3aad 100755
--- a/t/t1016-compatObjectFormat.sh
+++ b/t/t1016-compatObjectFormat.sh
@@ -21,6 +21,12 @@ test_description='Test how well compatObjectFormat works'
 # different hash functions result in the same content in the commits.
 # This means that when the commit is translated between hash functions
 # the commit is identical to the commit in the other repository.
+#
+# Similarly this test relies on:
+#	gpg --faked-system-time '20230918T154812!
+# freezing the system time from gpg perspective so that two different
+# runs of gpg applied to the same data result in identical signatures.
+#
 
 compat_hash () {
 	case "$1" in
diff --git a/t/t1016/gpg b/t/t1016/gpg
index 2601cb18a5b3..34d6e055fc9e 100755
--- a/t/t1016/gpg
+++ b/t/t1016/gpg
@@ -1,2 +1,2 @@
 #!/bin/sh
-exec gpg --faked-system-time "20230918T154812" "$@"
+exec gpg --faked-system-time '20230918T154812!' "$@"
-- 
2.41.0
Previous: Junio C HamanoNext: Junio C Hamano
Message 12 of 14 in “t/lib-gpg: ensure GNUPGHOME is created as needed”
  1. 0/2 t/lib-gpg: ensure GNUPGHOME is created as neededTodd Zullinger, Jul 3, 2024
  2. 1/2 t/lib-gpg: add prepare_gnupghome() to create GNUPGHOME dirTodd Zullinger, Jul 3, 2024
  3. 2/2 t/lib-gpg: call prepare_gnupghome() in GPG2 prereqTodd Zullinger, Jul 3, 2024
  4. Todd ZullingerJul 3, 2024
  5. Todd ZullingerFeb 28, 2025
  6. Junio C HamanoOct 26, 2025
  7. Eric W. BiedermanOct 27, 2025
  8. Junio C HamanoOct 27, 2025
  9. Eric W. BiedermanOct 27, 2025
  10. Eric W. BiedermanOct 27, 2025
  11. Junio C HamanoOct 27, 2025
  12. t1016-compatObjectFormat: Really freeze time for reproduciblityEric W. Biederman, Oct 28, 2025
  13. Junio C HamanoOct 28, 2025
  14. Todd ZullingerOct 29, 2025

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.