git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Weird shallow-tree conversion state, and branches of shallow trees

From
Linus Torvalds <torvalds@linux-foundation.org>
Date
Apr 16, 2007, 17:00 UTC
Message-ID
<Pine.LNX.4.64.0704160934050.5473@woody.linux-foundation.org>
In-Reply-To
<20070416033209.GI2689@curie-int.orbis-terrarum.net>
On Sun, 15 Apr 2007, Robin H. Johnson wrote:
>
> The checksum file (named Manifest) we are talking about is for a single
> subdirectory, and is signed as proof that it was not modified between
> the developer and submission to the tree. 

Well, in git, you can actyally just take the tree entry for that subdirectory, and it already is cryptographic proof that two subdirectories match.

(It's not signed, but if you actually want to sign it, you can do so, either inside git - by using a tag object that points to that subdirectory - or outside git by just creating a Manifest that contains a list of subdirectories and their tree SHA1's, and signing that).

In fact, in git, there's an explicit command to generate that "Manifest of directories in the top level", and it's called

	git ls-tree HEAD

and it will give you cryptographic hashes of each file/directory in the top level of a repository. So just sign that, ie do

	git ls-tree HEAD > Manifest
	gpg -sa -u "$username" Manifest 

or something like that. And you're done. Add the "-r" flag to get the recursive manifest containing *all* files, rather than just the SHA1's of the directories themselves.

Of course, you could just sign and tag the HEAD itself, which is what the kernel does, since one signature will guarantee everything under it.

> As I wrote originally, this is the Gentoo distribution tree, it's NOT
> delineated by well-defined releases in the conventional sense.

We do that for the daily (or rather, nightly) snapshots for the kernel. There's no "Manifest", but look at

	http://www.kernel.org/pub/linux/kernel/v2.6/snapshots/
and you'll see files like
	patch-2.6.21-rc6-git8.bz2       15-Apr-2007 07:01   38K 	 
	patch-2.6.21-rc6-git8.bz2.sign  15-Apr-2007 07:01  248   
	patch-2.6.21-rc6-git8.gz        15-Apr-2007 07:01   42K  
	patch-2.6.21-rc6-git8.gz.sign   15-Apr-2007 07:01  248   
	patch-2.6.21-rc6-git8.id        15-Apr-2007 07:01   41   
	patch-2.6.21-rc6-git8.log       15-Apr-2007 07:01   63K  
	patch-2.6.21-rc6-git8.sign      15-Apr-2007 07:01  248  

where only the patches are signed, but the system *could* have signed the ID file too (the 41-byte "patch-2.6.21-rc6-git8.id" contains the 40-byte HEX representation of the SHA of the HEAD of the snapshot, and a newline).

That 41-byte ID file really is sufficient to describe the whole thing, after all (although you then need to have the git tree in question to actually get the list of files, aka the "Manifest", so if you want that list, you'd have to do the "git ls-tree" thing.

> There are presently 11571 Manifest files in the tree. Our tools will
> not allow commits to each package of things that radically break the
> package (semantic correctness and some automatic validation, but thinkos
> can still get through the checks).

Sure. And every single Manifest file is pointless *inside* git, since git maintains its own cryptographically secure manifest file anyway. But it's trivial to generate them for external use, if you want to.

> The 'release' process for the tree runs automatically every 30 minutes,
> and consists of more validation checks, updating a cache directory,
> producing a signed master Manifest [1] and publishing everything to the
> rsync servers.

That sounds like the nightly snapshots the kernel does, except we only do them nightly, and we don't actually validate anythign at all, we just sign things as being from the "master.kernel.org" site (so the signature does mean something, but only that *that* site thinks it is valid).

> The entire point of the checksums is to allow end users to validate
> content that has been exported, with only minimal tools.

If you do a single 41-byte thing, you could use git itself to validate the whole tree. But if you want to have people able to validate any random single file in a tar-file without having git installed, you'd have to:

 - have the "full manifest" (aka "git ls-tree -r HEAD")
 - have a trivial script that generates "git ID's" of files, which looks 
   something like this:
	#!/bin/sh
	# generate a "git ID" for one or more files
	while test -n "$1"
	do
		file="$1"
		len=$(stat --format "%s" "$file")
		echo -n " $file (blob $len): "
		# Generate the "git ID" for a blob:
		( echo -e -n "blob $len\0" ; cat "$file") | sha1sum
		shift
	done

and now you can check each file in the Manifest even without having git installed.

			Linus
Previous: Robin H. JohnsonNext: Daniel Barkalow
Message 21 of 34 in “Weird shallow-tree conversion state, and branches of shallow trees”
  1. Robin H. JohnsonApr 12, 2007
  2. Johannes SchindelinApr 14, 2007
  3. Robin H. JohnsonApr 15, 2007
  4. David LangApr 15, 2007
  5. Robin H. JohnsonApr 15, 2007
  6. Shawn O. PearceApr 15, 2007
  7. Nguyen Thai Ngoc DuyApr 15, 2007
  8. Jakub NarebskiApr 15, 2007
  9. Linus TorvaldsApr 15, 2007
  10. Andy ParkinsApr 15, 2007
  11. Linus TorvaldsApr 15, 2007
  12. Bill LearApr 16, 2007
  13. Andy ParkinsApr 16, 2007
  14. Julian PhillipsApr 16, 2007
  15. Robin H. JohnsonApr 16, 2007
  16. Theodore TsoApr 16, 2007
  17. Nguyen Thai Ngoc DuyApr 16, 2007
  18. Linus TorvaldsApr 16, 2007
  19. Nguyen Thai Ngoc DuyApr 16, 2007
  20. Robin H. JohnsonApr 16, 2007
  21. Linus TorvaldsApr 16, 2007
  22. Daniel BarkalowApr 17, 2007
  23. Linus TorvaldsApr 16, 2007
  24. Andy ParkinsApr 16, 2007
  25. Sven VerdoolaegeApr 16, 2007
  26. Linus TorvaldsApr 16, 2007
  27. David LangApr 16, 2007
  28. David LangApr 17, 2007
  29. Andy ParkinsApr 17, 2007
  30. Junio C HamanoApr 16, 2007
  31. Andy ParkinsApr 16, 2007
  32. Junio C HamanoApr 17, 2007
  33. Andy ParkinsApr 17, 2007
  34. Robin H. JohnsonApr 15, 2007

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.