git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] [PATCH] [Outreachy] builtin/patch-id.c: clarify SHA1 usage for patch IDs

From
Junio C Hamano <gitster@pobox.com>
Date
Oct 14, 2025, 22:29 UTC
Message-ID
<xmqqjz0xw20h.fsf@gitster.g>
In-Reply-To
<aO6-LBqhW87GWD-5@fruit.crustytoothpaste.net>
"brian m. carlson" <sandals@crustytoothpaste.net> writes:
Show 15 quoted lines
>>  	if (!the_hash_algo)
>> -		repo_set_hash_algo(the_repository, GIT_HASH_DEFAULT);
>> +		repo_set_hash_algo(the_repository, GIT_HASH_SHA1);
>
> Hmmm.  If I run git patch-id in a SHA-256 repository, then I get a
> SHA-256 output here and it's worked this way since Git 2.29.
>
> I know the comment says what it says, but I personally disagree with
> this approach.  There will be a point in time where SHA-1 is so weak as
> to be useless and people will want to build a Git version without it.
> For instance, many government agencies around the world have a 2030
> deadline for completely stopping all use of SHA-1.  If we continue to
> use SHA-1 here, then this will have to change anyway in a few years, so
> we'd be better off keeping the default algorithm for now and adding an
> option to control which hash is used.

I do not quite agree with that, as SHA-1 in patch-id is merely used as "a hash function with good distribution that we happened to have handy access to" without any security requirement. Being able to compare patch IDs computed long ago stored somewhere with patch ID on a patch that claims to be freshly written and find them the same to say "you know, somebody wrote exactly the same patch 7 years ago" would be valuable, and we do not want to lose it even when you happen to store your payload in a SHA-256 repository.

Previous: brian m. carlsonNext: brian m. carlson
Message 5 of 9 in “[Outreachy] builtin/patch-id.c: clarify SHA1 usage for patch IDs”
  1. [PATCH] [Outreachy] builtin/patch-id.c: clarify SHA1 usage for patch IDsOkhuomon Ajayi, Oct 13, 2025
  2. Junio C HamanoOct 14, 2025
  3. Okhuomon AjayiOct 14, 2025
  4. brian m. carlsonOct 14, 2025
  5. Junio C HamanoOct 14, 2025
  6. brian m. carlsonOct 14, 2025
  7. Okhuomon AjayiOct 14, 2025
  8. Junio C HamanoOct 15, 2025
  9. Kristoffer HaugsbakkOct 15, 2025

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.