git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[Summit topic] SHA-256 Updates

From
Johannes Schindelin <johannes.schindelin@gmx.de>
Date
Oct 21, 2021, 11:55 UTC
Message-ID
<nycvar.QRO.7.76.6.2110211147250.56@tvgsbejvaqbjf.bet>
In-Reply-To
<nycvar.QRO.7.76.6.2110211129130.56@tvgsbejvaqbjf.bet>

This session was led by brian m. carlson. Supporting cast: Jonathan "jrnieder" Nieder, Derrick Stolee, Johannes "Dscho" Schindelin, Toon Claes, and Ævar Arnfjörð Bjarmason.

Notes:
 1.  Summarizing where we are with what merged:
     1. We have full SHA256 support \o/
     2. Some minor glitches, updated the docs to reflect that
     3. It works. 2.30 is a good state.
     4. None of the major forges support it yet but that will come
 2.  Interop between SHA256 repositories and SHA1 repositories
     1. Take each object we receive over the wire or create locally and give it
        a sha1 value as well
     2. We have a giant loose object index that maps sha256-id and sha1-id
        values. Hashmap
     3. Will be changed to some tree to allow prefix mapping
     4. index-pack has to take two passes over the pack, because you can’t map
        a commit before you’ve mapped the tree it points to (or more generally
        can’t map an object before the objects it references)
     5. Fortunately blobs don’t point to any other objects so this is
        relatively quick
 3.  Submodules are tricky
     1. They come from a different repository so we don’t have anything to map
        to
     2. What I’m currently doing is requiring that the submodule be present
        locally and storing the mapping separately in the superproject
     3. The mapping isn’t sent over the wire. That could create some complexity
        around malicious histories
 4.  For the same reason we don’t have partial clone working
     1. Might require an on-disk format bump
     2. jrnieder: taking a step back, the hash verifies the full history via
        the Merkle tree property.
     3. However, with partial clone we already relax this: it is no longer
        verifiable, locally.
     4. Therefore, we place a lot of trust on the server.
     5. The server could tell us more information about the edge commits, e.g.
        SHA-1<->SHA-256 mapping
     6. Stolee: if I am sha256 client, that’s what I want, you kind of decide
        up front what you want
     7. jrnieder: at $DAYJOB common partial clone scenario is triangular
        workflow
     8. Stolee: how likely are the multiple hosts not homogenous (all SHA-1, or
        all SHA-256)?
     9. brian: Valuable to be able to work in SHA256 and refer in input+output
        to SHA-1. If someone refers to a SHA-1, you still want to be able to
        see what they’re referring to, to interact with other people, even
        though SHA-1 is insecure
 5.  Multi-pack index: doesn’t work, but won’t be hard to fix
 6.  We write signatures for both objects. When you “git commit --gpg-sign”, it
     can sign in both formats
     1. Verifies in current format
 7.  Timeframe for hosting providers moving to SHA256
     1. Dscho: should we have a multi provider meeting and coordinate that?
        Could be everyone waiting for others
     2. brian: cgit supports SHA256 already, allows self-hosting
     3. jrnieder: with interop, individuals can use SHA256 against servers that
        only support SHA-1. Then that creates pressure for the servers to
        support SHA256 for performance reasons
     4. brian: interop doesn’t exist yet. If GitHub decides I work on that for
        the next two months, I think I could do it. But requires the code
        getting written.
     5. Toon: we at gitlab have sha256 on our radar, but with a very low prio
        https://gitlab.com/groups/gitlab-org/-/epics/794
 8.  jrnieder: Signing: very old Git versions won’t know to invalidate them
     when I commit --amend. How old is “very old”?
     1. brian: somewhere between 2.20 and 2.28. In 2.20 started treating
        everything with “gpgsig” at start as a potential signature.
     2. There were a couple of bugs I fixed in 2.30, working on signature
        interoperability. Tested with sha256.
     3. Updated the transition plan: in tags, the trailing signature is always
        the current signature, other ones go in the header.
 9.  Updating other hosting provider glue to support sha256
     1. jrnieder: e.g. GitHub API, UIs, …. Is it hard, similar to the Git part,
        or a little easier?
     2. brian: hardest part is libgit2. Lots of hardcoded oids in its testsuite
     3. Libraries tend to be the hardest piece --- e.g. Gerrit will need JGit
        updates
     4. Dscho: gitk also has some references to hardcoded 40-length
     5. Ævar: some patches on the mailing list for gitk and git-gui to adapt
        them, from Carlos
     6. brian: hopefully the ecosystem learns from this experience and doesn’t
        just hardcode 64 here :)
 10. Interop code only supports 2 algorithms. Hopefully finish this transition
     before we need the next one :)
Previous: Johannes SchindelinNext: Johannes Schindelin
Message 9 of 58 in “Notes from the Git Contributors' Summit 2021, virtual, Oct 19/20”
  1. Johannes SchindelinOct 21, 2021
  2. [Summit topic] Crazy (and not so crazy) ideasJohannes Schindelin, Oct 21, 2021
  3. Son Luong NgocOct 21, 2021
  4. scripting speedups [was: [Summit topic] Crazy (and not so crazy) ideas]Eric Wong, Oct 26, 2021
  5. Ævar Arnfjörð BjarmasonOct 30, 2021
  6. test suite speedups via some not-so-crazy ideas (was: scripting speedups[...])Ævar Arnfjörð Bjarmason, Nov 3, 2021
  7. Junio C HamanoNov 3, 2021
  8. Johannes SchindelinNov 2, 2021
  9. [Summit topic] SHA-256 UpdatesJohannes Schindelin, Oct 21, 2021
  10. [Summit topic] Server-side merge/rebase: needs and wants?Johannes Schindelin, Oct 21, 2021
  11. Bagas SanjayaOct 22, 2021
  12. Johannes SchindelinOct 22, 2021
  13. Ævar Arnfjörð BjarmasonOct 23, 2021
  14. Taylor BlauNov 8, 2021
  15. Ævar Arnfjörð BjarmasonNov 9, 2021
  16. Christian CouderNov 30, 2021
  17. [Summit topic] Submodules and how to make them worth usingJohannes Schindelin, Oct 21, 2021
  18. [Summit topic] Sparse checkout behavior and plansJohannes Schindelin, Oct 21, 2021
  19. [Summit topic] The state of getting a reftable backend working in git.gitJohannes Schindelin, Oct 21, 2021
  20. Han-Wen NienhuysOct 25, 2021
  21. Ævar Arnfjörð BjarmasonOct 25, 2021
  22. Han-Wen NienhuysOct 26, 2021
  23. Philip OakleyOct 28, 2021
  24. Philip OakleyOct 26, 2021
  25. [Summit topic] Documentation (translations, FAQ updates, new user-focused, general improvements, etc.)Johannes Schindelin, Oct 21, 2021
  26. Jean-Noël AvilaOct 22, 2021
  27. Ævar Arnfjörð BjarmasonOct 22, 2021
  28. Jean-Noël AvilaOct 27, 2021
  29. Jeff KingOct 27, 2021
  30. [Summit topic] Increasing diversity & inclusion (transition to `main`, etc)Johannes Schindelin, Oct 21, 2021
  31. Son Luong NgocOct 21, 2021
  32. vale check, was Re: [Summit topic] Increasing diversity & inclusion (transition to `main`, etc)Johannes Schindelin, Oct 22, 2021
  33. Johannes SchindelinOct 22, 2021
  34. [Summit topic] Improving Git UXJohannes Schindelin, Oct 21, 2021
  35. changing the experimental 'git switch' (was: [Summit topic] Improving Git UX)Ævar Arnfjörð Bjarmason, Oct 21, 2021
  36. Junio C HamanoOct 21, 2021
  37. Bagas SanjayaOct 22, 2021
  38. martinOct 22, 2021
  39. Ævar Arnfjörð BjarmasonOct 22, 2021
  40. Sergey OrganovOct 22, 2021
  41. martinOct 22, 2021
  42. Sergey OrganovOct 23, 2021
  43. MartinOct 24, 2021
  44. Junio C HamanoOct 24, 2021
  45. Ævar Arnfjörð BjarmasonOct 25, 2021
  46. Junio C HamanoOct 25, 2021
  47. Sergey OrganovOct 25, 2021
  48. Ævar Arnfjörð BjarmasonOct 25, 2021
  49. Sergey OrganovOct 27, 2021
  50. [Summit topic] Improving reviewer quality of life (patchwork, subsystem lists?, etc)Johannes Schindelin, Oct 21, 2021
  51. Konstantin RyabitsevOct 21, 2021
  52. Ævar Arnfjörð BjarmasonOct 22, 2021
  53. Missing notes, was Re: Notes from the Git Contributors' Summit 2021, virtual, Oct 19/20Johannes Schindelin, Oct 22, 2021
  54. Johannes SchindelinOct 22, 2021
  55. Johannes SchindelinOct 22, 2021
  56. Johannes SchindelinOct 22, 2021
  57. Let's have public Git chalk talks, was Re: Notes from the Git Contributors' Summit 2021, virtual, Oct 19/20Johannes Schindelin, Oct 22, 2021
  58. Ævar Arnfjörð BjarmasonOct 25, 2021

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.