git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 2/3] builtin/am.c: add a message-id commit header

From
brian m. carlson <sandals@crustytoothpaste.net>
Date
Oct 16, 2025, 22:41 UTC
Message-ID
<aPF0fmxsPQvxHfCu@fruit.crustytoothpaste.net>
In-Reply-To
<20251016185758.21996-3-James.Bottomley@HansenPartnership.com>
On 2025-10-16 at 18:57:57, James Bottomley wrote:
Show 6 quoted lines
> Now that mailinfo is updated to collect the message_id all the time,
> use this in do_commit to add a "message-id" extra header containing
> the message_id if it exists.  This means that git am will always
> record the message-id if it can be found in the commit.  It will still
> add it to the trailer if -m is specified, keeping the behaviour
> backwards compatible.
This has most of the same downsides as the change ID header.

Yes, Message-IDs have to be globally unique, but sometimes they're not due to implementation bugs. It also allows tracking of changes which may be a problem for privacy reasons, especially when it's always enabled. It's also a side channel where people can exfiltrate information (e.g., cryptographic keys) without much visibility.

In addition, it is not guaranteed that message IDs are suitable for inclusion. They may be missing, malformed, or contain unacceptable content (profanities, discriminatory content, EICAR test virus, etc.)[0][1]. Silently inserting them into every commit without user intervention, especially without a corresponding fsck check, is not a good idea. Commit messages, author lines, and committer lines are at least reasonably visible to the person applying the patch, but many mail clients don't show the message ID by default or at all.

[0] You may think this is not a problem, but someone will do these things if they can, possibly in a major project, because people are inventive at causing chaos and we need to provide them fewer easy ways to do so. People already intentionally sow discord by pushing commits with timestamps beyond 2^63, or even under 2^63 but beyond the expected lifespan of our solar system, which then causes havoc when languages like Ruby try to parse and interpret them. [1] For instance, one of my servers is named "castro" (as in the San Francisco neigbourhood, the Castro), but people, upon hearing the name, are usually horrified to think that I've named my server for the Cuban leader. That name has ended up in many, many message IDs over the years, and I know of still other much less savoury hostnames people have used which will also necessarily appear in message IDs.

-- 
brian m. carlson (they/them)
Toronto, Ontario, CA
Previous: James BottomleyNext: James Bottomley
Message 4 of 14 in “add a message-id header to git”
  1. 0/3 add a message-id header to gitJames Bottomley, Oct 16, 2025
  2. 1/3 mailinfo.c: always collect the message-idJames Bottomley, Oct 16, 2025
  3. 2/3 builtin/am.c: add a message-id commit headerJames Bottomley, Oct 16, 2025
  4. brian m. carlsonOct 16, 2025
  5. 3/3 t4150-am: add a test for message-id header collectionJames Bottomley, Oct 16, 2025
  6. Kristoffer HaugsbakkOct 16, 2025
  7. James BottomleyOct 16, 2025
  8. Kristoffer HaugsbakkOct 16, 2025
  9. Junio C HamanoOct 16, 2025
  10. James BottomleyOct 16, 2025
  11. Junio C HamanoOct 16, 2025
  12. Kristoffer HaugsbakkOct 16, 2025
  13. Kristoffer HaugsbakkOct 16, 2025
  14. Junio C HamanoOct 16, 2025

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.