git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [RFC PATCH 6/6] hex: allow only lowercase object IDs in breaking changes mode

From
Michael Montalbo <mmontalbo@gmail.com>
Date
Aug 5, 2026, 03:09 UTC
Message-ID
<CAC2QwmKS+ojHd31oagdHv1G3h=Sa-BttWpQLv49=kC=PC-1BTQ@mail.gmail.com>
In-Reply-To
<am_AL9dymrkidizF@fruit.crustytoothpaste.net>

On Sun, Aug 2, 2026 at 3:10 PM brian m. carlson <sandals@crustytoothpaste.net> wrote:

Show 5 quoted lines
>
> Modern development effectively requires being clear and definitive about
> what data is accepted and what is not, as well as what meaning is given
> to the data that is accepted.
>

I agree with this idea, and the topic inspired me to explore how mixing upper and lowercase hex oids might be "abused" today. Interestingly, I found out it is possible to mix upper and lowercase formats within one oid. Depending on output path, Git either normalizes the casing or preserves the raw form stored. I didn't come up with a specific way to take advantage of this behavior yet, but one could imagine a scenario where downstream consumers of Git output each have their own way of parsing such an ambiguously formatted oid and behave in different ways that at best may cause confusion and at worst could be used maliciously.

To reproduce a mixed case oid scenario:
    #!/bin/sh
    set -eu
    ( repo=$(mktemp -d); cd "$repo"
      export GIT_PAGER=cat
      git init -q
      git config user.name Tester && git config user.email tester@example.com
      echo one >f && git add f && git commit -qm base
      echo two >f && git commit -qam child
      # Re-spell the child's parent OID with a mixed-case tail, re-store the
      # object.  Nothing else about the commit changes.
      parent=$(git rev-parse HEAD^)
      upper=$(printf %s "$parent" | tr '[:lower:]' '[:upper:]')
      mixed=$(printf %s "$parent" | cut -c1-10)$(printf %s "$parent" |
cut -c11- | tr '[:lower:]' '[:upper:]')
      git cat-file commit HEAD | sed "s/^parent .*/parent $mixed/" >crafted-obj
      crafted=$(git hash-object -w -t commit --stdin <crafted-obj)
      git update-ref refs/heads/mixed "$crafted"
      echo "== the two commit objects differ by one field, case only =="
      git cat-file commit HEAD >canon-obj
      diff canon-obj crafted-obj || true
      echo
      echo "== they are distinct commits =="
      printf 'canonical: %s\nmixed    : %s\n' "$(git rev-parse HEAD)" "$crafted"
      echo
      echo "== both parent spellings resolve to the same object =="
      git rev-parse "$parent" "$upper"
      echo
      echo "== the one parent is spelled two ways, by output path =="
      printf 'raw (as stored) : '; git log -1 --pretty=raw mixed | sed
-n 's/^parent //p'
      printf '%%P  (normalized): '; git log -1 --format='%P' mixed
    )
produces:
    == the two commit objects differ by one field, case only ==
    2c2
    < parent f3b4ff525d82ddcec0cc8597842c73b72e4c5aba
    ---
    > parent f3b4ff525d82DDCEC0CC8597842C73B72E4C5ABA
    == they are distinct commits ==
    canonical: 52d41f6a261b49a18d38933b59a65f2dc919f9ac
    mixed    : ed20e85251a37eb01009faaaa8fbc23baf8bdc72
    == both parent spellings resolve to the same object ==
    f3b4ff525d82ddcec0cc8597842c73b72e4c5aba
    f3b4ff525d82ddcec0cc8597842c73b72e4c5aba
    == the one parent is spelled two ways, by output path ==
    raw (as stored) : f3b4ff525d82DDCEC0CC8597842C73B72E4C5ABA
    %P  (normalized): f3b4ff525d82ddcec0cc8597842c73b72e4c5aba
Previous: brian m. carlsonNext: Phillip Wood
Message 23 of 41 in “Git 3.0: restrict hex object IDs to lowercase only”
  1. 0/6 Git 3.0: restrict hex object IDs to lowercase onlybrian m. carlson, Jul 29, 2026
  2. 2/6 hex: allow specifying hex type with hex2chrbrian m. carlson, Jul 29, 2026
  3. 4/6 hex: label usages of hex parsing for object IDsbrian m. carlson, Jul 29, 2026
  4. Junio C HamanoJul 31, 2026
  5. Junio C HamanoAug 25, 2026
  6. 1/6 hex: add functionality for lowercase-only hexbrian m. carlson, Jul 29, 2026
  7. Junio C HamanoJul 31, 2026
  8. Junio C HamanoAug 25, 2026
  9. brian m. carlsonAug 25, 2026
  10. 3/6 hex: make hex_to_bytes accept kind of hex to usebrian m. carlson, Jul 29, 2026
  11. Junio C HamanoJul 31, 2026
  12. Jeff KingAug 1, 2026
  13. 5/6 object-name: use hexvalbrian m. carlson, Jul 29, 2026
  14. Junio C HamanoAug 25, 2026
  15. Elijah NewrenAug 25, 2026
  16. brian m. carlsonAug 25, 2026
  17. 6/6 hex: allow only lowercase object IDs in breaking changes modebrian m. carlson, Jul 29, 2026
  18. Junio C HamanoJul 31, 2026
  19. Junio C HamanoJul 31, 2026
  20. brian m. carlsonAug 2, 2026
  21. Junio C HamanoAug 4, 2026
  22. brian m. carlsonAug 4, 2026
  23. Michael MontalboAug 5, 2026
  24. Phillip WoodAug 25, 2026
  25. brian m. carlsonAug 25, 2026
  26. Phillip WoodSep 7, 2026
  27. Junio C HamanoAug 25, 2026
  28. Elijah NewrenAug 25, 2026
  29. Junio C HamanoJul 30, 2026
  30. brian m. carlsonJul 30, 2026
  31. Jeff KingAug 1, 2026
  32. Junio C HamanoAug 1, 2026
  33. brian m. carlsonAug 2, 2026
  34. 0/7 Git 3.0: restrict hex object IDs to lowercase onlybrian m. carlson, Sep 7, 2026
  35. 4/7 hex: label usages of hex parsing for object IDsbrian m. carlson, Sep 7, 2026
  36. 2/7 hex: allow specifying hex type with hex2chrbrian m. carlson, Sep 7, 2026
  37. 3/7 hex: make hex_to_bytes accept kind of hex to usebrian m. carlson, Sep 7, 2026
  38. 1/7 hex: add functionality for lowercase-only hexbrian m. carlson, Sep 7, 2026
  39. 5/7 object-name: use hexvalbrian m. carlson, Sep 7, 2026
  40. 6/7 t5324: adjust tests for corrupt commit-graphbrian m. carlson, Sep 7, 2026
  41. 7/7 hex: allow only lowercase object IDs in breaking changes modebrian m. carlson, Sep 7, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.