Linux's first Git commit and colliding SHA prefixes
Summary
Kees Cook demonstrates in practice why automated Linux tools must not treat Git commit prefixes as unique identifiers. The colliding prefix is 1da177e4c3f4. At the time, 590 Linux commits used this prefix in Fixes tags.
Ideas
- Twelve-character SHA prefixes can already collide in large repositories.
- The deliberately generated commit shares the prefix of the first Linux Git commit.
- Fixes tags carry human-readable references, not permanently unique database keys.
- Parsers must detect ambiguous prefixes and handle them in a controlled way.
- A prepared collision provides a reproducible test for existing tools.
Insights
- Growing amounts of data eventually turn theoretical probabilities into operational bugs.
- Convenient short forms become dangerous as soon as machines interpret them as identities.
- Robust formats explicitly distinguish between display, reference and unique identifier.
Facts
- The search took about six hours with an RTX 3080.
Recommendations
- In scripts, use full object IDs or check short IDs for uniqueness.
- Test commit parsers specifically with known prefix collisions.
References
Links to the original source and the Web Archive open in a new tab.