fix(git): normalize tar headers of git archives - #2124
Draft
matthiasbruns wants to merge 1 commit into
Draft
matthiasbruns wants to merge 1 commit into
matthiasbruns wants to merge 1 commit into
Conversation
Signed-off-by: Matthias Bruns <git@matthiasbruns.com> On-behalf-of: SAP <matthias.bruns@sap.com>
matthiasbruns
added a commit
to open-component-model/open-component-model
that referenced
this pull request
Sep 25, 2026
On-behalf-of: SAP <matthias.bruns@sap.com> <!-- markdownlint-disable MD041 --> #### What this PR does / why we need it Adds git access resource repo and typing. During this PR we found out that ocmv1 packs tars differently: Things we could fix here; - bring over the tar layout to match the tar contents from v1 (opt in) Things we will fix in ocmv1 - digest calculation based on tars with uname and other host infos in the file headers - this cannot work during verify on v1 and v2 - see open-component-model/ocm#2124 #### Which issue(s) this PR fixes Contributes: open-component-model/ocm-project#1257 --------- Signed-off-by: Matthias Bruns <git@matthiasbruns.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
On-behalf-of: SAP matthias.bruns@sap.com
What this PR does / why we need it
The
gitaccess andgitinput archive a temporary checkout withtarutils.TgzFs, which takes owner, group and permissions fromLstat. Their digest therefore depends on the user, umask and temporary directory that built it: the same commit gives different digests for the v1 CLI and the v1 library on the same machine, and OCM v2 cannot verify any of them.This adds an opt-in
NormalizeHeadersoption totarutils.TarFileSystemOptions(uid/gid 0, no user/group names, no access/change time, permissions from the file type and executable bit) and enables it forblobaccess/git. OtherPackFsIntoTarcallers are unchanged. For the same commit the archive is now byte-identical to OCM v2'sbindings/go/gitoutput.Digests of existing git access resources change once; they have to be re-added or re-digested.
Which issue(s) this PR is related to
Related to open-component-model/ocm-project#1341