git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [RFC PATCH 6/6] hex: allow only lowercase object IDs in breaking changes mode

From
brian m. carlson <sandals@crustytoothpaste.net>
Date
Aug 25, 2026, 21:36 UTC
Message-ID
<ao4K44RP66mjnpd7@fruit.crustytoothpaste.net>
In-Reply-To
<d6940aa6-9336-481b-8ee5-5e3d9f3d3a50@gmail.com>
On 2026-08-25 at 09:04:36, Phillip Wood wrote:
Show 24 quoted lines
> Hi brian
> 
> On 30/07/2026 00:32, brian m. carlson wrote:
> > Git has historically allowed either lowercase or uppercase hex for
> > object IDs, but it has always emitted only lowercase.  This has caused
> > people to expect only lowercase and not handle uppercase.
> > 
> > As an example, Git's own example hooks look for "[0-9a-f]" in several
> > places, but there are many other Git-adjacent pieces of software,
> > including Gitolite, which make the assumption that object IDs are always
> > lowercase.  This is not to criticize the authors of these projects, but
> > rather to point out how common this assumption is.  In fact, it's so
> > common that we have only one test in our codebase that fails when we
> > reject uppercase object IDs.
> > 
> > More critically, it leads people to make security-based assumptions that
> > an object ID either does not contain uppercase characters or that an
> > object ID can be expressed uniquely in hex form, neither of which are
> > currently true.  Git itself normally uses binary object IDs, which
> > avoids many of these problems, but most other projects deal primarily in
> > hex object IDs, so they are more affected.
> 
> Can you say a bit more about the security problems please - I'm trying to
> understand why ABCDEF is a security risk when abcdef^0 isn't.

There's two cases I've seen. The first is that people assume an object ID is unique in hex form. So if we have some policy to enforce, say, that we can't allow certain objects, people will check against the lowercase version when they may get the uppercase version somewhere (say, user input or a specially crafted protocol message), which bypasses the check.

The other case is where we try to distinguish between an object ID and a ref, branch, or tag. If our regexp has `[0-9a-f]{40}` or `[0-9a-f]{64}` and we assume that if it matches it's an object ID and if it's not it's a ref, that's not correct here. We'd need to match the uppercase version as well, but experience shows that people overwhelmingly do not do that.

-- 
brian m. carlson (they/them)
Toronto, Ontario, CA
Previous: Phillip WoodNext: Phillip Wood
Message 25 of 41 in “Git 3.0: restrict hex object IDs to lowercase only”
  1. 0/6 Git 3.0: restrict hex object IDs to lowercase onlybrian m. carlson, Jul 29, 2026
  2. 2/6 hex: allow specifying hex type with hex2chrbrian m. carlson, Jul 29, 2026
  3. 4/6 hex: label usages of hex parsing for object IDsbrian m. carlson, Jul 29, 2026
  4. Junio C HamanoJul 31, 2026
  5. Junio C HamanoAug 25, 2026
  6. 1/6 hex: add functionality for lowercase-only hexbrian m. carlson, Jul 29, 2026
  7. Junio C HamanoJul 31, 2026
  8. Junio C HamanoAug 25, 2026
  9. brian m. carlsonAug 25, 2026
  10. 3/6 hex: make hex_to_bytes accept kind of hex to usebrian m. carlson, Jul 29, 2026
  11. Junio C HamanoJul 31, 2026
  12. Jeff KingAug 1, 2026
  13. 5/6 object-name: use hexvalbrian m. carlson, Jul 29, 2026
  14. Junio C HamanoAug 25, 2026
  15. Elijah NewrenAug 25, 2026
  16. brian m. carlsonAug 25, 2026
  17. 6/6 hex: allow only lowercase object IDs in breaking changes modebrian m. carlson, Jul 29, 2026
  18. Junio C HamanoJul 31, 2026
  19. Junio C HamanoJul 31, 2026
  20. brian m. carlsonAug 2, 2026
  21. Junio C HamanoAug 4, 2026
  22. brian m. carlsonAug 4, 2026
  23. Michael MontalboAug 5, 2026
  24. Phillip WoodAug 25, 2026
  25. brian m. carlsonAug 25, 2026
  26. Phillip WoodSep 7, 2026
  27. Junio C HamanoAug 25, 2026
  28. Elijah NewrenAug 25, 2026
  29. Junio C HamanoJul 30, 2026
  30. brian m. carlsonJul 30, 2026
  31. Jeff KingAug 1, 2026
  32. Junio C HamanoAug 1, 2026
  33. brian m. carlsonAug 2, 2026
  34. 0/7 Git 3.0: restrict hex object IDs to lowercase onlybrian m. carlson, Sep 7, 2026
  35. 4/7 hex: label usages of hex parsing for object IDsbrian m. carlson, Sep 7, 2026
  36. 2/7 hex: allow specifying hex type with hex2chrbrian m. carlson, Sep 7, 2026
  37. 3/7 hex: make hex_to_bytes accept kind of hex to usebrian m. carlson, Sep 7, 2026
  38. 1/7 hex: add functionality for lowercase-only hexbrian m. carlson, Sep 7, 2026
  39. 5/7 object-name: use hexvalbrian m. carlson, Sep 7, 2026
  40. 6/7 t5324: adjust tests for corrupt commit-graphbrian m. carlson, Sep 7, 2026
  41. 7/7 hex: allow only lowercase object IDs in breaking changes modebrian m. carlson, Sep 7, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.