git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Is the sha256 object format experimental or not?

From
brian m. carlson <sandals@crustytoothpaste.net>
Date
May 10, 2021, 22:42 UTC
Message-ID
<YJm23HESQb1Z6h8y@camp.crustytoothpaste.net>
In-Reply-To
<87lf8mu642.fsf@evledraar.gmail.com>
On 2021-05-10 at 12:22:00, Ævar Arnfjörð Bjarmason wrote:
Show 12 quoted lines
> 
> On Sun, May 09 2021, brian m. carlson wrote:
> > You can't do that.  SHA-256 repositories already exist and that would
> > break compatibility.
> 
> From memory this is at least the second time you've brought up this
> point on-list.
> 
> My feeling is that almost nobody's using sha256 currently, and we have a
> very prominent ALL CAPS warning saying the format is experimental and
> may change, see ff233d8dda1 (Documentation: mark
> `--object-format=sha256` as experimental, 2020-08-16).

Yes, I agreed to such text because others thought it was a good idea in case we needed to make a change. However, we don't need to make an incompatible change here, so we should avoid that if possible.

Almost nobody is using it because the main forges don't yet support it, because it's going to be just as much work to support it there as it has been in Git. We won't be making it easier by making deliberately incompatible changes when we don't have to.

> I agree with the docs as they stand, and don't think we should hold back
> on changing the object format for sha256 in general if there's a
> compelling reason to do so.

I am using it and I know of other people who are using it. There are people whose companies cannot use SHA-1 for compliance reasons and are already making use of it.

The problem here is a chicken and egg: nobody's going to use SHA-256 support if it's experimental and their entire repo might end up totally useless, and it's not going to become stable if nobody uses it.

Show 5 quoted lines
> But it seems to me that if the main person pushing the sha256 effort
> disagrees with the content of
> Documentation/object-format-disclaimer.txt, we'd be better off at this
> point discussing a patch to change the wording there to something to the
> effect that we consider the format set in stone at this point.

I've been pretty clear up front that I thought the data was stable and we should avoid making incompatible changes. It may be that it is still experimental and may change incompatibly, but if we can avoid that problem, we should.

I don't personally intend to send a patch removing the note about it being experimental until I've finished getting object interop done, since that's the major issue where we might need to make an incompatible change, but that work is moving slowly.

-- 
brian m. carlson (he/him or they/them)
Houston, Texas, US
Previous: Ævar Arnfjörð BjarmasonNext: dwh@linuxprogrammer.org
Message 9 of 19 in “Preserving the ability to have both SHA1 and SHA256 signatures”
  1. dwh@linuxprogrammer.orgMay 8, 2021
  2. Christian CouderMay 8, 2021
  3. Junio C HamanoMay 8, 2021
  4. Felipe ContrerasMay 8, 2021
  5. Stefan MochMay 8, 2021
  6. Junio C HamanoMay 8, 2021
  7. brian m. carlsonMay 9, 2021
  8. Is the sha256 object format experimental or not?Ævar Arnfjörð Bjarmason, May 10, 2021
  9. brian m. carlsonMay 10, 2021
  10. dwh@linuxprogrammer.orgMay 13, 2021
  11. Konstantin RyabitsevMay 13, 2021
  12. dwh@linuxprogrammer.orgMay 13, 2021
  13. Konstantin RyabitsevMay 14, 2021
  14. dwh@linuxprogrammer.orgMay 14, 2021
  15. Junio C HamanoMay 13, 2021
  16. dwh@linuxprogrammer.orgMay 13, 2021
  17. Ævar Arnfjörð BjarmasonMay 14, 2021
  18. dwh@linuxprogrammer.orgMay 14, 2021
  19. Jonathan NiederMay 18, 2021

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.