git/list[1] front-page[2] threads[3] people[4] search[5] about
wed 2026-10-07 17:02 UTC

Re: [RFC PATCH 0/4] sign a SHA-256 digest of the tree in commits and tags

From
Scott Chacon <schacon@gmail.com>
Date
Oct 5, 2026, 14:16 UTC
Message-ID
<CAP2yMaJ+ss9M_27+kBN0q_aFUd-5GNqzQHM2orayKH+enOAG1Q@mail.gmail.com>
In-Reply-To
<asOa6dgpj0qV5QAU@pks.im>
Thanks Steiny,
A quick response,
On Mon, Oct 5, 2026 at 2:41 PM Patrick Steinhardt <ps@pks.im> wrote:
Show 5 quoted lines
> The biggest problem I have is that the ecosystem has been entirely
> unwilling to do anything about the SHA-256 move before we announced that
> this is going to become mandatory. Only then were developers even able
> to convince anybody (especially those paying the wages) to get the time
> to implement support for it.

Bit of a simple question, but is it possible that this is because nobody really finds it a concerning problem?

Show 13 quoted lines
> So there is some kind of ossification happening in the space. But things
> are finally moving now that the due-date is drawing closer. I would be
> extremely hesitant to change course again and drop this breaking change
> now that there finally is some movement. Because the only consequence of
> that would be that the ecosystem will stop working on it again. And even
> more so, I would even expect that this will make the next time we want
> to do a breaking change exponentially harder as the lesson learned is
> that nobody needs to do anything.
>
> Maybe I'm too pessimistic about this, but I don't think so. We've been
> working on this whole transition for almost a decade by now, and only
> now where we're forcing the ecosystem to adapt are large players like
> GitHub even moving.

I want to remind everyone here quickly what "working on this whole transition for a decade" has looked like, because this seems to be phrased like everyone wanted this but GitHub was hesitant and pulled into this important work only by the heroic 3.0 breaking change decision.

GitHub has been essentially the _only one_ pushing this endeavour from the beginning of this problem set.

If we assume Brian, Haggerty, Peff, Taylor and Derrick have been acting on behalf of GitHub, then you Steiny, are essentially the only major contributor to this project in the last decade that is not GitHub/MS (Eric maybe?). Very honestly, nobody else seems to care. GH has single handedly created this issue and then somehow simultaneously been the blocking factor to it's rollout because it also, simultaneously, does not really find it to be an actually important issue. Google maybe helped design the transition plan in 2017, but hasn't seemed to care too much since then. Nobody else has really weighed in, at least with patches.

Scott
Previous: Patrick SteinhardtNext: brian m. carlson
Message 12 of 21 in “sign a SHA-256 digest of the tree in commits and tags”
  1. 0/4 sign a SHA-256 digest of the tree in commits and tagsScott Chacon, Oct 2, 2026
  2. 1/4 tree-sha256: hash the contents of a tree with SHA-256Scott Chacon, Oct 2, 2026
  3. 2/4 tag: add --hash=sha256 to sign a tree-sha256 headerScott Chacon, Oct 2, 2026
  4. 3/4 commit: add --hash=sha256 to sign a tree-sha256 headerScott Chacon, Oct 2, 2026
  5. 4/4 gpg: add gpg.treeHash to sign a tree-sha256 header by defaultScott Chacon, Oct 2, 2026
  6. Junio C HamanoOct 2, 2026
  7. Junio C HamanoOct 2, 2026
  8. Junio C HamanoOct 2, 2026
  9. brian m. carlsonOct 2, 2026
  10. Scott ChaconOct 5, 2026
  11. Patrick SteinhardtOct 5, 2026
  12. Scott ChaconOct 5, 2026
  13. brian m. carlsonOct 5, 2026
  14. Christian CouderOct 6, 2026
  15. Johannes SchindelinOct 6, 2026
  16. Kristoffer HaugsbakkOct 6, 2026
  17. brian m. carlsonOct 6, 2026
  18. brian m. carlsonOct 6, 2026
  19. Junio C HamanoOct 6, 2026
  20. brian m. carlsonOct 6, 2026
  21. Christian CouderOct 7, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.