Re: Git generated tarballs and Debian
- From
Simon Richter <simon.richter@hogyros.de>
- Date
- Apr 28, 2026, 11:32 UTC
- Message-ID
- <a54d57b6-9270-406a-9056-ffaa939c6c21@hogyros.de>
- In-Reply-To
- <afCLFJX86yEPKKfk@fruit.crustytoothpaste.net>
Hi,
On 4/28/26 7:25 PM, brian m. carlson wrote:
> I'll just note that we don't make any guarantees that `git archive` > produces identical output across versions. Incorrectly making that > assumption broke kernel.org when we changed the format in the past.
Exactly -- that's why I read the tarball and calculate the checksum of the corresponding tree object, but we have a few cases where we need extra information that isn't in the archive, and I'm wondering where to put that extra information: inside the archive itself, or into an extra file.
> Also, if you use `export-subst`, then it's possible to emit short object > IDs, which can differ in length depending on how many objects are in the > repository. It's also possible to use zlib or pigz instead of gzip to > produce tarballs, in which case the compressed data will also differ.
export-subst breaks verification completely as soon as a blob changes.
Compression isn't an issue, because we're comparing tree checksums.
Simon