git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [RFC PATCH 0/4] sign a SHA-256 digest of the tree in commits and tags

From
brian m. carlson <sandals@crustytoothpaste.net>
Date
Oct 6, 2026, 23:40 UTC
Message-ID
<asWHAyDpUPdS6vuE@fruit.crustytoothpaste.net>
In-Reply-To
<xmqqzewqbgk2.fsf@gitster.g>
On 2026-10-06 at 22:38:37, Junio C Hamano wrote:
Show 6 quoted lines
> If your time were corporate-funded, and if I declared that we would
> accept no changes other than the SHA-256 interoperability work and
> perhaps other low-impact changes, and that we would give anyone
> helping with the SHA-256 interoperability work the power to veto any
> topics that may interfere with quick integration of their work for N
> months, would it have worked better, I wonder?

It might have. I don't want to say that the ODB work and other in-flight topics aren't valuable because I feel the opposite, in fact, but they just make things a moving target and if I'm doing less things in my personal time, it makes it hard to keep up.

As I mentioned, one of the main impediments to my time being corporate-funded at the moment is that I can't send out patches from $DAYJOB because we're forced to use Outlook, which will corrupt patches, and I don't want to send out work patches from my personal address. I don't mind if other people wanted to send out those patches, though, so that kind of collaboration could work if I could get my employer to agree (which is likely, given the fact that I previously spent time working on it, but not guaranteed).

I think if we could get someone to polish and upstream patches while I work on the next steps at work, that might work well, but of course I don't want to be very prescriptive about how others contribute. As I said, there's plenty of things that need to be done such that we can have several people working on things and I'm grateful for any assistance I can get. Even someone rebasing things, resolving conflicts, and fixing tests would be super helpful.

One thing is that we would need reviews if we want to get patches merged in a timely manner and that's kind of difficult at the moment. That was an issue for the original SHA-256 work, in fact, as well.

Show 6 quoted lines
> Such an arrangement certainly requires buy-in from other
> stakeholders.  Employers who fund scalability work would not only
> have to wait their turn, but might also need to be convinced to
> divert their resources to help this effort, so that the magic
> number N becomes smaller and they get their turn sooner, for
> example.
Of course.
-- 
brian m. carlson (they/them)
Toronto, Ontario, CA
Previous: Junio C HamanoNext: Christian Couder
Message 18 of 22 in “sign a SHA-256 digest of the tree in commits and tags”
  1. 0/4 sign a SHA-256 digest of the tree in commits and tagsScott Chacon, Oct 2, 2026
  2. 1/4 tree-sha256: hash the contents of a tree with SHA-256Scott Chacon, Oct 2, 2026
  3. Junio C HamanoOct 2, 2026
  4. 2/4 tag: add --hash=sha256 to sign a tree-sha256 headerScott Chacon, Oct 2, 2026
  5. Junio C HamanoOct 2, 2026
  6. 3/4 commit: add --hash=sha256 to sign a tree-sha256 headerScott Chacon, Oct 2, 2026
  7. 4/4 gpg: add gpg.treeHash to sign a tree-sha256 header by defaultScott Chacon, Oct 2, 2026
  8. Junio C HamanoOct 2, 2026
  9. brian m. carlsonOct 2, 2026
  10. Scott ChaconOct 5, 2026
  11. Patrick SteinhardtOct 5, 2026
  12. Scott ChaconOct 5, 2026
  13. brian m. carlsonOct 5, 2026
  14. Johannes SchindelinOct 6, 2026
  15. Kristoffer HaugsbakkOct 6, 2026
  16. brian m. carlsonOct 6, 2026
  17. Junio C HamanoOct 6, 2026
  18. brian m. carlsonOct 6, 2026
  19. Christian CouderOct 6, 2026
  20. brian m. carlsonOct 6, 2026
  21. Christian CouderOct 7, 2026
  22. brian m. carlsonOct 7, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.