git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Making bit-by-bit reproducible Git Bundles?

From
Junio C Hamano <gitster@pobox.com>
Date
Mar 13, 2025, 13:36 UTC
Message-ID
<xmqqzfhpqcgo.fsf@gitster.g>
In-Reply-To
<20250313051538.GA94015@coredump.intra.peff.net>
Jeff King <peff@peff.net> writes:
Show 8 quoted lines
> .... But there are some gotchas:
>
>   1. It's stable only for a given Git version, and with a particular set
> ...
>   2. There is no way to pass pack-objects options down through
> ...
>   3. It will be really slow. We're throwing out all of the deltas and
> ...
There also is 4.
    4. We do not control zlib, so even with the same Git binary, the
       zlib implementation that is dynamically linked to us is free
       to produce better compressed base object (or compressed
       delta).
3. is not a downside if the priority of the requestor is about
bit-for-bit reproducibility (iow, "no matter what the cost").
Show 14 quoted lines
>   # print all commits in topological order, with ties broken by
>   # committer date, which should be stable. And then follow up with the
>   # trees and blobs for each.
>   git rev-list --topo-order --objects HEAD >objects
>
>   # now print the contents of each object (preceded by its name, type,
>   # and length, so there's no chance of weird prepending or appending
>   # attacks). We cut off the path information from rev-list here, since
>   # the ordered set of objects is all we care about.
>   cut -d' ' -f1 objects |
>   git cat-file --batch >content
>
>   # and then take a hash over that content; this will be unambiguous.
>   sha256sum <content
Gross but probably stable ;-)
Previous: Jeff KingNext: Simon Josefsson
Message 6 of 11 in “Making bit-by-bit reproducible Git Bundles?”
  1. Simon JosefssonMar 12, 2025
  2. Junio C HamanoMar 12, 2025
  3. Kyle LippincottMar 13, 2025
  4. Simon JosefssonMar 13, 2025
  5. Jeff KingMar 13, 2025
  6. Junio C HamanoMar 13, 2025
  7. Simon JosefssonMar 13, 2025
  8. Kyle LippincottMar 13, 2025
  9. Junio C HamanoMar 13, 2025
  10. Jeff KingMar 14, 2025
  11. rsbecker@nexbridge.comMar 14, 2025

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.