git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] Prevent users from adding the file that has all-zero SHA-1

From
MMMikael Magnusson <mikachu@gmail.com>
Date
Sep 18, 2011, 17:06 UTC
Message-ID
<CAHYJk3TRHu0whbdPQXzs2ELpoiEqZPxeWmz_V4HQzj5XfAJDBA@mail.gmail.com>
In-Reply-To
<1316259574-1291-1-git-send-email-pclouds@gmail.com>
2011/9/17 Nguyễn Thái Ngọc Duy <pclouds@gmail.com>:
Show 18 quoted lines
> This particular SHA-1 has special meaning to git, very much like NULL
> in C. If a user adds a file that has this SHA-1, unexpected things can
> happen.
>
> Granted, the chance is probably near zero because the content must
> also start with valid blob header. But extra safety does not harm.
>
> Signed-off-by: Nguyễn Thái Ngọc Duy <pclouds@gmail.com>
> ---
>  Another way than die() is to detect this situation and update header a
>  little to give different SHA-1 (for example a leading 0 in object
>  size in header). Older git versions may not be happy with such an
>  approach.
>
>  The same check can be added to commit, tree, tag creation and fsck.
>  Maybe I'm too paranoid.
>
>  By the way, are any other SHA-1s sensitive to git like this one?

Bad things will happen if you get an object with the same hash as any already existing one, and AFAIK, there are no checks for this. I don't think there's much point in treating 000...0 more specially than HEAD^0 for example. The only two hashes that mean something in an empty repo I guess are this one and the empty tree hash though.

PS there's a typo in your error message, "unluckly".
-- 
Mikael Magnusson
Previous: Nguyễn Thái Ngọc DuyNext: Nguyen Thai Ngoc Duy
Message 2 of 5 in “Prevent users from adding the file that has all-zero SHA-1”
  1. Prevent users from adding the file that has all-zero SHA-1Nguyễn Thái Ngọc Duy, Sep 17, 2011
  2. Mikael MagnussonSep 18, 2011
  3. Nguyen Thai Ngoc DuySep 19, 2011
  4. Ramkumar RamachandraSep 20, 2011
  5. Nguyen Thai Ngoc DuySep 20, 2011

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.