git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: A shortcoming of the git repo format

From
DLDavid Lang <david.lang@digitalinsight.com>
Date
Apr 28, 2005, 00:46 UTC
Message-ID
<Pine.LNX.4.62.0504271743580.4990@qynat.qvtvafvgr.pbz>
In-Reply-To
<4270320D.5090708@dwheeler.com>
On Wed, 27 Apr 2005, David A. Wheeler wrote:
Show 6 quoted lines
> Linus Torvalds wrote:
>> 
>> On Wed, 27 Apr 2005, H. Peter Anvin wrote:
>> 
>>> I know that.  However, is that going to be true for all versions of the 
>>> repository format over all time?  If so, the repository format is brittle.
<<SNIP>> 
Show 12 quoted lines
>> HOWEVER, that's where "convert-cache" comes in. Any one particular format 
>> may be brittle, but if we accept that, and just say "we can upgrade by 
>> converting the cache", then we should be ok. IOW, we can change from one 
>> brittle format with 160-bit SHA1 names to _another_ brittle format with 
>> 256-bit SHA1 (or other) names.
>
> There's a disadvantage to that, unfortunately: invalidating signatures.
> Yes, you can get people to re-sign their stuff... assuming you can
> find them & convince them to do it (ha!).  More than likely,
> you'll lose signatures that way.  Probably not your TOP priority,
> but there are advantages to being able to go back & years later
> SHOW that someone really did sign something.

all you have to do is to make sure that convert-cache doesn't loose any data and you can always convert back (through as many steps as needed) to check signatures.

no matter what you do, if you change the thing that's being signed the signature is worthless, it doesn't matter if you change it in a flexible or a brittle way, it's different. the brittle approach actually makes it easier to go backwards as you KNOW exactly what it needs to be, there's no possiblity that a later tag was there, but being ignored (except for the signature)

Show 11 quoted lines
> In the long run, I'd really like to see (at least) signed commits,
> and that those signatures would "stick around" cleanly into the future.
> "Breaks" can be handled other ways, but it is DEFINITELY a pain,
> and an avoidable one.
>
> --- David A. Wheeler
> -
> To unsubscribe from this list: send the line "unsubscribe git" in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at  http://vger.kernel.org/majordomo-info.html
>
-- 
There are two ways of constructing a software design. One way is to make it so simple that there are obviously no deficiencies. And the other way is to make it so complicated that there are no obvious deficiencies.
  -- C.A.R. Hoare
Previous: David A. WheelerNext: Daniel Barkalow
Message 23 of 29 in “A shortcoming of the git repo format”
  1. H. Peter AnvinApr 27, 2005
  2. C. Scott AnanianApr 27, 2005
  3. Linus TorvaldsApr 27, 2005
  4. H. Peter AnvinApr 27, 2005
  5. Dave JonesApr 27, 2005
  6. H. Peter AnvinApr 27, 2005
  7. Jon SeymourApr 27, 2005
  8. Linus TorvaldsApr 27, 2005
  9. Petr BaudisApr 27, 2005
  10. Linus TorvaldsApr 27, 2005
  11. The git repo formatBrian O'Mahoney, Apr 27, 2005
  12. H. Peter AnvinApr 27, 2005
  13. Tom LordApr 27, 2005
  14. H. Peter AnvinApr 27, 2005
  15. Linus TorvaldsApr 28, 2005
  16. Paul JacksonApr 28, 2005
  17. Tom LordApr 28, 2005
  18. Ryan AndersonApr 28, 2005
  19. Morgan SchweersApr 28, 2005
  20. Barry SilvermanApr 28, 2005
  21. Linus TorvaldsApr 27, 2005
  22. David A. WheelerApr 28, 2005
  23. David LangApr 28, 2005
  24. Daniel BarkalowApr 27, 2005
  25. H. Peter AnvinApr 27, 2005
  26. Daniel BarkalowApr 28, 2005
  27. H. Peter AnvinApr 28, 2005
  28. David WoodhouseApr 28, 2005
  29. Gerhard SchrenkApr 27, 2005

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.