git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: removing content from git history

From
Nicolas Pitre <nico@cam.org>
Date
Feb 21, 2007, 18:39 UTC
Message-ID
<alpine.LRH.0.82.0702211321040.31945@xanadu.home>
In-Reply-To
<Pine.LNX.4.64.0702211009520.4043@woody.linux-foundation.org>
On Wed, 21 Feb 2007, Linus Torvalds wrote:
Show 8 quoted lines
> 
> 
> On Wed, 21 Feb 2007, Nicolas Pitre wrote:
> So supermodules might be a way to solve it in a better (and safer - the 
> "remove objects from the public tree" thing is very error prone, since if 
> you *ever* expose the object by mistake, its now public) way. But I don't 
> think the "filter out objects" thing is necessarily fundamentally flawed 
> as an approach.

Well if you really wanted to do such a thing then you could use a new object type that only serves as a stub pretending to be another object which SHA1 would have been xyz. When referenced this object would generate a warning indicating to the user that given object has been excised out, but otherwise the whole reachability validation would still work as usual.

And since this object would be distributed through standard mechanisms then there would be no need for protocol extensions.

I don't know if this could help creating SHA1 collisions though. We've dismissed them as highly improbable because the likelihood of a collision to hide compromised material would most probably require a binary blob somewhere to balance the hash and would hardly be compilable/undetected. But with object stubs with the ability to pretend having any possible SHA1 is in fact a nice way to hide 20-byte binary blobs in the hash chain possibly making it "easier" to create "useful" collisions. This is where I see a weakening of the trust model.

Nicolas
Previous: Linus TorvaldsNext: Michael Hendricks
Message 16 of 25 in “removing content from git history”
  1. Michael HendricksFeb 21, 2007
  2. Shawn O. PearceFeb 21, 2007
  3. J. Bruce FieldsFeb 21, 2007
  4. Linus TorvaldsFeb 21, 2007
  5. Linus TorvaldsFeb 21, 2007
  6. Shawn O. PearceFeb 21, 2007
  7. Linus TorvaldsFeb 21, 2007
  8. Shawn O. PearceFeb 21, 2007
  9. Bill LearOct 9, 2007
  10. J. Bruce FieldsOct 9, 2007
  11. Bill LearOct 9, 2007
  12. Johannes SchindelinOct 10, 2007
  13. Linus TorvaldsFeb 21, 2007
  14. Nicolas PitreFeb 21, 2007
  15. Linus TorvaldsFeb 21, 2007
  16. Nicolas PitreFeb 21, 2007
  17. Michael HendricksFeb 21, 2007
  18. Shawn O. PearceFeb 21, 2007
  19. Linus TorvaldsFeb 21, 2007
  20. Linus TorvaldsFeb 21, 2007
  21. Nicolas PitreFeb 21, 2007
  22. Junio C HamanoFeb 21, 2007
  23. Nicolas PitreFeb 21, 2007
  24. Junio C HamanoFeb 21, 2007
  25. Nicolas PitreFeb 21, 2007

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.