From: Simon Richter Date: Tue, 28 Apr 2026 11:32:37 GMT Subject: Re: Git generated tarballs and Debian Message-ID: In-Reply-To: Hi, On 4/28/26 7:25 PM, brian m. carlson wrote: > I'll just note that we don't make any guarantees that `git archive` > produces identical output across versions. Incorrectly making that > assumption broke kernel.org when we changed the format in the past. Exactly -- that's why I read the tarball and calculate the checksum of the corresponding tree object, but we have a few cases where we need extra information that isn't in the archive, and I'm wondering where to put that extra information: inside the archive itself, or into an extra file. > Also, if you use `export-subst`, then it's possible to emit short object > IDs, which can differ in length depending on how many objects are in the > repository. It's also possible to use zlib or pigz instead of gzip to > produce tarballs, in which case the compressed data will also differ. export-subst breaks verification completely as soon as a blob changes. Compression isn't an issue, because we're comparing tree checksums. Simon