Re: [IGNORETHIS/PATCH] Choosing the sha1 prefix of your commits
- From
Nguyen Thai Ngoc Duy <pclouds@gmail.com>
- Date
- Oct 20, 2011, 09:14 UTC
- Message-ID
- <CACsJy8B7CJ3VO-UKCym2kgfOOPadL25gt2sxApk95nKoWVk2yQ@mail.gmail.com>
- In-Reply-To
- <7vvcrk9td7.fsf@alter.siamese.dyndns.org>
On Thu, Oct 20, 2011 at 3:31 PM, Junio C Hamano <gitster@pobox.com> wrote:
Show 19 quoted lines
> Jeff King <peff@peff.net> writes: > >> And nothing shows up in the body, because git truncates at the NUL we >> added: >> >> $ git show >> commit 31337a1093af2d97eb2e6c08b261c2946395fdd3 >> Author: Jeff King <peff@peff.net> >> Date: Wed Oct 19 15:34:00 2011 -0400 >> >> 10 >> >> diff --git a/file b/file > > But you cannot hide from "cat-file commit" ;-) > > With the recent push to more (perceived) security, it may probably make > sense to teach "log" family commands to quote-show ^@ and what is behind > in their output by default, perhaps with an option to turn it off.
What about NUL in file name in tree objects? Suppose the original tree has an entry named "goodthing". With luck, they might be able to create a new tree object with the entry renamed to "evil\x001234" that has the same SHA-1. Could that possibly cause any problems?
-- Duy