Gentoo Archives: gentoo-dev

From: Kent Fredric <kentfredric@×××××.com>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] My masterplan for git migration (+ looking for infra to test it)
Date: Sun, 14 Sep 2014 23:15:56
Message-Id: CAATnKFDcF=gQWQqHX+C2+LPm8bodxVLLg=nZRFRkF9VsReXTEg@mail.gmail.com
In Reply to: Re: [gentoo-dev] My masterplan for git migration (+ looking for infra to test it) by hasufell
1 On 15 September 2014 10:56, hasufell <hasufell@g.o> wrote:
2
3 > According to Robin, it's not about rebasing, it's about signing all
4 > commits so that messing with the blob (even if it has the same sha-1)
5 > will cause signature verification failure.
6 >
7
8 Correct me if I'm wrong, but wouldn't a SHA1 attack on the tree object or
9 file blobs be completely invisible to the commit SHA1?
10
11 As the Signature only signs content of the commit object, not any of the
12 nodes it refers to.
13
14 Granted, getting a tree/file object to replicate might be interesting.
15
16 --
17 Kent
18
19 *KENTNL* - https://metacpan.org/author/KENTNL