Re: [RFC PATCH 0/4] sign a SHA-256 digest of the tree in commits and tags
- From
Christian Couder <christian.couder@gmail.com>
- Date
- Oct 6, 2026, 09:00 UTC
- Message-ID
- <CAP8UFD096CdR9MXd+VHk7Zf9rCJEnGTEiBhCc0mJdMmE3U_gOg@mail.gmail.com>
- In-Reply-To
- <asAAn8NZwB29WhGR@fruit.crustytoothpaste.net>
On Fri, Oct 2, 2026 at 9:15 PM brian m. carlson <sandals@crustytoothpaste.net> wrote:
Show 10 quoted lines
> The thing you really want is the interoperability work, which can > automatically rewrite repositories from one hash algorithm to another > during a clone or fetch operation. Yes, it isn't quite that simple for > submodules, but if you recursively clone the repository and all its > submodules, it should be possible to rewrite it in place, although that > hasn't been written yet. That work has not yet been sent upstream > because some of it was written at $DAYJOB, which requires that we use > Outlook and we all know that Outlook corrupts patches. However, there > is some intention for another company to handle the polishing and > sending, so it should be available sooner or later.
Sorry for the possibly stupid following questions, but I think the answers might help us get a better idea of what might be needed to get a smoother transition.
And yeah, I know that many people have said that merging all your interoperability work should not block Git 3.0. But if it can ensure a smoother transition, we might want to get at least part of it merged soon, and the rest in a good shape, anyway.
Is the current state of the work publicly available somewhere? Or could you make it publicly available somewhere? (Fine if it's only as patches in a tarball.)
Is the submodule work the only missing part of the interoperability work?
How much work is this? (At one point it seemed to me that it was around 200 patches.)
If you were to work full time on upstreaming it, how long would you expect it would take you?
If some of us could help you, how could we best help?
Could you say which company is interested in helping with this? Would that company be willing to work openly with others on this?
Are there some tests or kinds of automated ways to check that things work as expected under realistic conditions like:
- using real world repos (large ones, old ones, with submodules, etc), - mixing a number of new and old clients and servers, - interacting with other implementations (JGit, libgit2, gitoxide, forges, CI, etc)?
Thanks for all your work on this in your free time, Christian.