git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: git clone of empty repositories doesn't preserve hash

From
Junio C Hamano <gitster@pobox.com>
Date
Apr 26, 2023, 15:08 UTC
Message-ID
<xmqqcz3qwuj7.fsf@gitster.g>
In-Reply-To
<20230426112508.GB130148@coredump.intra.peff.net>
Jeff King <peff@peff.net> writes:
Show 5 quoted lines
> It sounds from your description that your test is running in a mode
> where the client defaults to sha256 (though I'm not sure how, since we
> explicitly document that GIT_DEFAULT_HASH should not affect clone), and
> then you clone an empty sha256 repository via v0, expecting the result
> to be sha256.

Thanks for coming up with an excellent guess that helped come up with a reproduction.

With Brian's patch a bit tweaked (attached below), the test does fail with the current 'master' and passes before the merge in question. And the trace clearly shows that without being told anything about the object format via the capability, the client chooses to honor GIT_DEFAULT_HASH to initialize the new repository with sha256.

There is this entry in the release notes of 2.29.0:
 * "git clone" that clones from SHA-1 repository, while
   GIT_DEFAULT_HASH set to use SHA-256 already, resulted in an
   unusable repository that half-claims to be SHA-256 repository
   with SHA-1 objects and refs.  This has been corrected.

This refers to 47ac9703 (builtin/clone: avoid failure with GIT_DEFAULT_HASH, 2020-09-20). It seems that the "fix" described there was incomplete and did not address "clone a void" case, and the patch under discussion finished the incomplete fix without knowing by accident. The test that was added by 47ac9703 to t5601 does use non-empty repositories (one with SHA-1, the other with SHA-256) and tries to check the interaction with "clone" with the environment variable. With the patch under discussion, this test did not break and "clone" is still ignoring the GIT_DEFAULT_HASH variable.

Also the description in the document of GIT_DEFAULT_HASH makes readers ambivalent:

`GIT_DEFAULT_HASH`::
	If this variable is set, the default hash algorithm for new
	repositories will be set to this value. This value is currently
	ignored when cloning; the setting of the remote repository
	is used instead. The default is "sha1". THIS VARIABLE IS
	EXPERIMENTAL! See `--object-format` in linkgit:git-init[1].

To me, "is currently ignored" hints that the author, or somebody close to the author, of this entry feels that it is a bug that "clone" does not honor it. The log message of 47ac9703 also phrases "failed to honor the GIT_DEFAULT_HASH" as if it were a bad thing [*].

On the other hand, it is clearly documented as experimental so anything that has been relying on the behaviour of any command with a particular value set to this variable are waiting to be broken.

I am torn about this. Even though we may have been very clear that GIT_DEFAULT_HASH should not kick in in this case, "clone" was buggy (in the sense that it did not behave as documented in an empty repository) and whatever thing that changed behaviour that Brian noticed was ignoring the documentation and taking advantage of that "bug", and Hyrum's law ensues.

In the longer term, after/when we allow incremental/over-the-wire migration of object-format, i.e. clone from SHA-1 repository to create SHA-256 repository (or vice versa) and fetching and pushing between them would bidirectionally convert the object format on the fly, it is likely we would teach a new option "--object-format" to "git clone" to say "you would use whatever object format the origin uses by default, but this time, I am telling you to use this format on our side, doing on-the-fly object format conversion as needed".

So it would be OK to make sure that GIT_DEFAULT_HASH is ignored by "clone" as documented now, and even after on-the-fly object-format migration is implemented, I would think.

[Footnote]
* ... but I think it was misguided.  What it says there is this:
    And we also don't want to initialize the repository as SHA-1
    initially, since that means if we're cloning an empty
    repository, we'll have failed to honor the GIT_DEFAULT_HASH
    variable and will end up with a SHA-1 repository, not a SHA-256
    repository.

If this were "When we're cloning an empty repository, we'd have failed to honor the object format the other side has chosen and will end up with a SHA-1 repository, not a SHA-256 repository.", then it is very much in line with the reality before the patch under discussion and also in line with the official stance that "clone" should not honor GIT_DEFAULT_HASH.

Where the original description breaks down is when the other side is SHA-1 and this side has GIT_DEFAULT_HASH set to SHA-256. If we honored the variable, we'd create a SHA-256 repository that will talk to SHA-1 repository before the rest of the system is ready.

 t/t5700-protocol-v1.sh | 13 +++++++++++++
 1 file changed, 13 insertions(+)
diff --git i/t/t5700-protocol-v1.sh w/t/t5700-protocol-v1.sh
index 6c8d4c6cf1..2f39dd2e05 100755
--- i/t/t5700-protocol-v1.sh
+++ w/t/t5700-protocol-v1.sh
@@ -244,6 +244,19 @@ test_expect_success 'push with ssh:// using protocol v1' '
 	grep "push< version 1" log
 '
 
+test_expect_success 'clone propagates object-format from empty repo' '
+	test_when_finished "rm -fr src256 dst256" &&
+
+	echo sha256 >expect &&
+	git init --object-format=sha256 src256 &&
+	GIT_DEFAULT_HASH=sha256 \
+	GIT_TRACE_PACKET=1 \
+	git clone --no-local src256 dst256 &&
+	git -C dst256 rev-parse --show-object-format >actual &&
+
+	test_cmp expect actual
+'
+
 # Test protocol v1 with 'http://' transport
 #
 . "$TEST_DIRECTORY"/lib-httpd.sh
Previous: Jeff KingNext: Junio C Hamano
Message 15 of 58 in “git clone of empty repositories doesn't preserve hash”
  1. Adam MajerApr 5, 2023
  2. Junio C HamanoApr 5, 2023
  3. Adam MajerApr 5, 2023
  4. Jeff KingApr 5, 2023
  5. Junio C HamanoApr 5, 2023
  6. Junio C HamanoApr 5, 2023
  7. Jeff KingApr 5, 2023
  8. brian m. carlsonApr 5, 2023
  9. Adam MajerApr 6, 2023
  10. brian m. carlsonApr 25, 2023
  11. Junio C HamanoApr 25, 2023
  12. Junio C HamanoApr 25, 2023
  13. brian m. carlsonApr 26, 2023
  14. Jeff KingApr 26, 2023
  15. Junio C HamanoApr 26, 2023
  16. doc: GIT_DEFAULT_HASH is and will be ignored during "clone"Junio C Hamano, Apr 26, 2023
  17. brian m. carlsonApr 26, 2023
  18. Jeff KingApr 27, 2023
  19. Jeff KingApr 26, 2023
  20. Junio C HamanoApr 26, 2023
  21. brian m. carlsonApr 26, 2023
  22. 0/2 Fix empty SHA-256 clones with v0 and v1brian m. carlson, Apr 26, 2023
  23. 1/2 http: advertise capabilities when cloning empty reposbrian m. carlson, Apr 26, 2023
  24. Junio C HamanoApr 26, 2023
  25. brian m. carlsonApr 26, 2023
  26. Jeff KingApr 27, 2023
  27. Jeff KingApr 27, 2023
  28. Junio C HamanoApr 27, 2023
  29. 2/2 Honor GIT_DEFAULT_HASH for empty clones without remote algobrian m. carlson, Apr 26, 2023
  30. Junio C HamanoApr 26, 2023
  31. Junio C HamanoApr 26, 2023
  32. Jeff KingApr 27, 2023
  33. Is GIT_DEFAULT_HASH flawed?Felipe Contreras, May 2, 2023
  34. Adam MajerMay 3, 2023
  35. Felipe ContrerasMay 3, 2023
  36. Adam MajerMay 3, 2023
  37. Felipe ContrerasMay 8, 2023
  38. demerphqMay 3, 2023
  39. Felipe ContrerasMay 3, 2023
  40. brian m. carlsonMay 3, 2023
  41. Felipe ContrerasMay 8, 2023
  42. brian m. carlsonMay 8, 2023
  43. Oswald BuddenhagenMay 9, 2023
  44. Junio C HamanoMay 9, 2023
  45. Junio C HamanoApr 26, 2023
  46. Jeff KingApr 27, 2023
  47. 0/1 Fix empty SHA-256 clones with v0 and v1brian m. carlson, May 1, 2023
  48. 1/1 upload-pack: advertise capabilities when cloning empty reposbrian m. carlson, May 1, 2023
  49. Jeff KingMay 1, 2023
  50. Junio C HamanoMay 1, 2023
  51. Junio C HamanoMay 1, 2023
  52. 0/1 Fix empty SHA-256 clones with v0 and v1brian m. carlson, May 17, 2023
  53. 1/1 upload-pack: advertise capabilities when cloning empty reposbrian m. carlson, May 17, 2023
  54. Junio C HamanoMay 17, 2023
  55. brian m. carlsonMay 17, 2023
  56. Jeff KingMay 18, 2023
  57. brian m. carlsonMay 19, 2023
  58. Jeff KingApr 5, 2023

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.