git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [RFC PATCH 6/6] hex: allow only lowercase object IDs in breaking changes mode

From
brian m. carlson <sandals@crustytoothpaste.net>
Date
Aug 2, 2026, 22:09 UTC
Message-ID
<am_AL9dymrkidizF@fruit.crustytoothpaste.net>
In-Reply-To
<xmqqv79vha69.fsf@gitster.g>
On 2026-07-31 at 07:48:14, Junio C Hamano wrote:
Show 8 quoted lines
> "brian m. carlson" <sandals@crustytoothpaste.net> writes:
> 
> > Git has historically allowed either lowercase or uppercase hex for
> > object IDs, but it has always emitted only lowercase.  This has caused
> > people to expect only lowercase and not handle uppercase.
> 
> It is violation of Postel's Law by other people.  We do not
> necessarily have to follow suit.

Postel's Law was a great idea on the early Internet, but it is unfortunately no longer a good idea. The problem is that being liberal in what you accept these days usually has security implications.

TLS cannot be liberal in what it accepts because that means potentially allowing attacker-controlled data. Even HTTP cannot do that because we've seen where refusing to reject requests with both Content-Length and Transfer-Encoding: chunked means that two parts of a backend can disagree on the content, allowing request smuggling.

We've seen these problems in our code where not caring about CR comes back to bite us on Windows in a security-sensitive way.

Modern development effectively requires being clear and definitive about what data is accepted and what is not, as well as what meaning is given to the data that is accepted.

Show 7 quoted lines
> Even though I said throwing object names in a single category makes
> sense, it may make sense to treat the object names that we locally
> use to access our own object database and those that we use when
> talking with _other_ people on the net separately for the Robustness
> principle, we keep being strict in what we produce and stick to
> lowercase, while accepting uppercase produced by those third-party
> reimplementations of Git.

Unfortunately, that also doesn't fix most of the security problems I've seen, which involve object IDs that get passed on the command line when tools invoke Git. It does fix the problem with round-tripping objects between hash algorithms, though, but I don't really want to audit every use of oid_to_hex in our codebase to half-fix this situation.

-- 
brian m. carlson (they/them)
Toronto, Ontario, CA
Previous: Junio C HamanoNext: Junio C Hamano
Message 20 of 41 in “Git 3.0: restrict hex object IDs to lowercase only”
  1. 0/6 Git 3.0: restrict hex object IDs to lowercase onlybrian m. carlson, Jul 29, 2026
  2. 2/6 hex: allow specifying hex type with hex2chrbrian m. carlson, Jul 29, 2026
  3. 4/6 hex: label usages of hex parsing for object IDsbrian m. carlson, Jul 29, 2026
  4. Junio C HamanoJul 31, 2026
  5. Junio C HamanoAug 25, 2026
  6. 1/6 hex: add functionality for lowercase-only hexbrian m. carlson, Jul 29, 2026
  7. Junio C HamanoJul 31, 2026
  8. Junio C HamanoAug 25, 2026
  9. brian m. carlsonAug 25, 2026
  10. 3/6 hex: make hex_to_bytes accept kind of hex to usebrian m. carlson, Jul 29, 2026
  11. Junio C HamanoJul 31, 2026
  12. Jeff KingAug 1, 2026
  13. 5/6 object-name: use hexvalbrian m. carlson, Jul 29, 2026
  14. Junio C HamanoAug 25, 2026
  15. Elijah NewrenAug 25, 2026
  16. brian m. carlsonAug 25, 2026
  17. 6/6 hex: allow only lowercase object IDs in breaking changes modebrian m. carlson, Jul 29, 2026
  18. Junio C HamanoJul 31, 2026
  19. Junio C HamanoJul 31, 2026
  20. brian m. carlsonAug 2, 2026
  21. Junio C HamanoAug 4, 2026
  22. brian m. carlsonAug 4, 2026
  23. Michael MontalboAug 5, 2026
  24. Phillip WoodAug 25, 2026
  25. brian m. carlsonAug 25, 2026
  26. Phillip WoodSep 7, 2026
  27. Junio C HamanoAug 25, 2026
  28. Elijah NewrenAug 25, 2026
  29. Junio C HamanoJul 30, 2026
  30. brian m. carlsonJul 30, 2026
  31. Jeff KingAug 1, 2026
  32. Junio C HamanoAug 1, 2026
  33. brian m. carlsonAug 2, 2026
  34. 0/7 Git 3.0: restrict hex object IDs to lowercase onlybrian m. carlson, Sep 7, 2026
  35. 4/7 hex: label usages of hex parsing for object IDsbrian m. carlson, Sep 7, 2026
  36. 2/7 hex: allow specifying hex type with hex2chrbrian m. carlson, Sep 7, 2026
  37. 3/7 hex: make hex_to_bytes accept kind of hex to usebrian m. carlson, Sep 7, 2026
  38. 1/7 hex: add functionality for lowercase-only hexbrian m. carlson, Sep 7, 2026
  39. 5/7 object-name: use hexvalbrian m. carlson, Sep 7, 2026
  40. 6/7 t5324: adjust tests for corrupt commit-graphbrian m. carlson, Sep 7, 2026
  41. 7/7 hex: allow only lowercase object IDs in breaking changes modebrian m. carlson, Sep 7, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.