git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: GIT vs Other: Need argument

From
Linus Torvalds <torvalds@linux-foundation.org>
Date
Apr 17, 2007, 15:28 UTC
Message-ID
<Pine.LNX.4.64.0704170816390.5473@woody.linux-foundation.org>
In-Reply-To
<vpqejmjjrdp.fsf@bauges.imag.fr>
On Tue, 17 Apr 2007, Matthieu Moy wrote:
> 
> * Perhaps your boss will be interested in the "data integrity" (i.e.
>   git fsck) problem too.
The data integrity thing is a lot more than just fsck.

I care a lot about my data, and it's an area where a *lot* of systems fall down. CVS is just about the worst (basically no checksums or sanity checking anywhere), and you can pretty much have total data corruption without ever even _realizing_, until you try to get some old version.

Even more interesting with CVS is that you can have total data corruption and you'll not realize it *even*as* you use the data. Lots of people and projects have been known to happily move *,v files around and edit the CVS repo files by hand to make things look right, which means that not only did you do a "rename" in CVS, you actually renamed *retroactively* too - you made history look wrong!

So with CVS, you actually have no guarantees what-so-ever that when you check out something old, you'll get what you actually used to have. You can tag things as much as you want - if people end up editing the CVS files (and people *do* that), you'll never have any indication that the history you checked out isn't the "real" history. So you can check out some old version that you made a release to a customer off, and may be totally unable to recreate the customer problem, because the release you checked out doesn't even compile any more!

You can actually do the same with most other SCM's. It may need somebody who is actually malicious, but even that isn't necessarily the case. Lots of SCM's don't have any checksums *at*all* on their data - the only way you'd ever know that something bad happened and you had disk corruption, is when you check something out and it just looks corrupted!

In other words, in a lot of SCM's, you're actually *lucky* if the corruption is so serious that it's not just a subtle "data is wrong" thing, it's so pervasive that you actually get an error from the SCM.

In git, every *single* piece of data is not just checksummed, it's CHECKSUMMED. Yeah, we use CRC's and Adler32 for some things, but even those are actually *also* protected at a higher level by real cryptographic hashes. You simply *cannot* corrupt data by mistake and not know about it. You can lose it, you can corrupt it, but it *will* be noticed.

If that doesn't make you feel good about your data, I don't know what will. Git will not replace backups in any way, shape, or form (although you can obviously use git itself to _do_ those backups - the joy of distributed SCMS), but it will tell you when you *need* those backups.

Guaranteed.

And I can tell you that that is actually very rare. I doubt *any* commercial SCM will come even close. They might have checksums, but nothing really strong. It might be a CRC or even weaker. Or it might be nothing at all (and sadly, that's the *common* case).

				Linus
Previous: Martin LanghoffNext: Matthieu Moy
Message 6 of 120 in “GIT vs Other: Need argument”
  1. Pietro MascagniApr 17, 2007
  2. Matthieu MoyApr 17, 2007
  3. Andy ParkinsApr 17, 2007
  4. Alex RiesenApr 17, 2007
  5. Martin LanghoffApr 17, 2007
  6. Linus TorvaldsApr 17, 2007
  7. Matthieu MoyApr 17, 2007
  8. Martin LanghoffApr 17, 2007
  9. Alex RiesenApr 17, 2007
  10. Dana HowApr 25, 2007
  11. Alex RiesenApr 25, 2007
  12. Tomash BrechkoApr 17, 2007
  13. Guilhem BonnefilleApr 17, 2007
  14. Andy ParkinsApr 17, 2007
  15. Shawn O. PearceApr 17, 2007
  16. Marcin KasperskiApr 17, 2007
  17. Johannes SchindelinApr 18, 2007
  18. Linus TorvaldsApr 18, 2007
  19. Nicolas PitreApr 18, 2007
  20. Bill LearApr 18, 2007
  21. Matthieu MoyApr 18, 2007
  22. Nicolas PitreApr 18, 2007
  23. Matthieu MoyApr 19, 2007
  24. Petr BaudisApr 19, 2007
  25. Matthieu MoyApr 20, 2007
  26. Theodore TsoApr 18, 2007
  27. Guilhem BonnefilleApr 18, 2007
  28. Linus TorvaldsApr 18, 2007
  29. Daniel BarkalowApr 18, 2007
  30. Michael K. EdwardsApr 18, 2007
  31. Johannes SchindelinApr 19, 2007
  32. Matthieu MoyApr 19, 2007
  33. Johannes SchindelinApr 19, 2007
  34. Alex RiesenApr 19, 2007
  35. Christian MICHONApr 19, 2007
  36. Johannes SchindelinApr 19, 2007
  37. Christian MICHONApr 19, 2007
  38. Linus TorvaldsApr 19, 2007
  39. Marcin KasperskiApr 19, 2007
  40. Linus TorvaldsApr 19, 2007
  41. Carl WorthApr 23, 2007
  42. Josef WeidendorferApr 23, 2007
  43. Carl WorthApr 23, 2007
  44. Junio C HamanoApr 23, 2007
  45. Carl WorthApr 23, 2007
  46. Linus TorvaldsApr 23, 2007
  47. Brian GernhardtApr 23, 2007
  48. Daniel BarkalowApr 24, 2007
  49. Junio C HamanoApr 24, 2007
  50. J. Bruce FieldsApr 24, 2007
  51. Linus TorvaldsApr 24, 2007
  52. J. Bruce FieldsApr 30, 2007
  53. Making git disappear when talking about my code (was: Re: GIT vs Other: Need argument)Carl Worth, Apr 25, 2007
  54. Carl WorthApr 25, 2007
  55. Linus TorvaldsApr 25, 2007
  56. Carl WorthApr 25, 2007
  57. Nicolas PitreApr 25, 2007
  58. Carl WorthApr 25, 2007
  59. Junio C HamanoApr 25, 2007
  60. Nicolas PitreApr 25, 2007
  61. Carl WorthApr 25, 2007
  62. Nicolas PitreApr 25, 2007
  63. Linus TorvaldsApr 25, 2007
  64. Daniel BarkalowApr 25, 2007
  65. Junio C HamanoApr 25, 2007
  66. Linus TorvaldsApr 25, 2007
  67. Nicolas PitreApr 25, 2007
  68. Daniel BarkalowApr 25, 2007
  69. Carl WorthApr 25, 2007
  70. Daniel BarkalowApr 25, 2007
  71. Nicolas PitreApr 25, 2007
  72. Junio C HamanoApr 23, 2007
  73. Johannes SchindelinApr 19, 2007
  74. History cleanup/rewriting script for gitJan Harkes, Apr 20, 2007
  75. Johannes SchindelinApr 20, 2007
  76. Petr BaudisApr 20, 2007
  77. Jan HarkesApr 20, 2007
  78. Marcin KasperskiApr 19, 2007
  79. Johannes SchindelinApr 19, 2007
  80. Marcin KasperskiApr 19, 2007
  81. Johannes SchindelinApr 19, 2007
  82. J. Bruce FieldsApr 19, 2007
  83. Theodore TsoApr 19, 2007
  84. [ANNOUNCE] Cogito is for salePetr Baudis, Apr 19, 2007
  85. Matthieu MoyApr 19, 2007
  86. Junio C HamanoApr 19, 2007
  87. Johannes SchindelinApr 19, 2007
  88. Guilhem BonnefilleApr 18, 2007
  89. Andy ParkinsApr 18, 2007
  90. Steven GrimmApr 18, 2007
  91. Jakub NarebskiApr 19, 2007
  92. Steven GrimmApr 19, 2007
  93. Jakub NarebskiApr 19, 2007
  94. Johannes SchindelinApr 19, 2007
  95. Julian PhillipsApr 19, 2007
  96. Steven GrimmApr 19, 2007
  97. Johannes SchindelinApr 19, 2007
  98. Junio C HamanoApr 19, 2007
  99. Junio C HamanoApr 19, 2007
  100. Steven GrimmApr 19, 2007
  101. Junio C HamanoApr 19, 2007
  102. Shawn O. PearceApr 20, 2007
  103. Jakub NarebskiApr 20, 2007
  104. Karl HasselströmApr 20, 2007
  105. Junio C HamanoApr 20, 2007
  106. Petr BaudisApr 20, 2007
  107. Junio C HamanoApr 20, 2007
  108. Steven GrimmApr 20, 2007
  109. Yann DirsonApr 18, 2007
  110. Sam VilainApr 18, 2007
  111. Yann DirsonApr 18, 2007
  112. Dana HowApr 25, 2007
  113. Marcin KasperskiApr 19, 2007
  114. Alex RiesenApr 19, 2007
  115. Andy ParkinsApr 19, 2007
  116. Shawn O. PearceApr 20, 2007
  117. Eric BlakeApr 20, 2007
  118. Johannes SchindelinApr 19, 2007
  119. Marcin KasperskiApr 19, 2007
  120. Johannes SchindelinApr 19, 2007

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.