# Warning: Patch hash format changed (breaking change)

**URL:** <https://discourse.pijul.org/t/warning-patch-hash-format-changed-breaking-change/95>\
**Category:** Development\
**Created:** [October 2, 2017, 4:33am UTC](https://discourse.pijul.org/t/warning-patch-hash-format-changed-breaking-change/95 "2017-10-02T04:33:44Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![pmeunier](https://yyz1.discourse-cdn.com/flex031/user_avatar/discourse.pijul.org/pmeunier/32/4_2.png) [@pmeunier](https://discourse.pijul.org/u/pmeunier)\
**Post date:** [October 2, 2017, 4:33am UTC](https://discourse.pijul.org/t/warning-patch-hash-format-changed-breaking-change/95/1 "2017-10-02T04:33:44Z")

</div>

The patch hashes are currently base64-encodings of the SHA2-512 of the patch as written in binary.

This is not optimal, especially when we need to copy-paste hashes (which does not happen very often for me).

I was thinking of transitionning to base58. Since Pijul 0.8 only supports SHA2-512 hashes, this can be made backwards compatible (looking at the length of the encoded hash is enough to know the encoding).

However, this is not forward-compatible: current versions of Pijul will be in trouble when the hash function is changed in the future.

Alternatively, we can drop support for base64, and release a small conversion tool. What do you think?

---

<div class="post-metadata">

**Author:** ![laumann](https://yyz1.discourse-cdn.com/flex031/user_avatar/discourse.pijul.org/laumann/32/8_2.png) [@laumann](https://discourse.pijul.org/u/laumann)\
**Post date:** [October 2, 2017, 8:14am UTC](https://discourse.pijul.org/t/warning-patch-hash-format-changed-breaking-change/95/2 "2017-10-02T08:14:22Z")

</div>

I am in favour of changing the patch hash format. Some time I implemented hex encoding of patches, but for SHA-512 they become _extremely_ long 🙂

I’m not sure the forwards compatibility is a big issue - if an old version of Pijul needs to work with a different hash patch format, then a small conversion tool might come in handy, but it’d be likely that the old version would have other changes to handle as well.

👍 for base58 from me.

---

<div class="post-metadata">

**Author:** ![pmeunier](https://yyz1.discourse-cdn.com/flex031/user_avatar/discourse.pijul.org/pmeunier/32/4_2.png) [@pmeunier](https://discourse.pijul.org/u/pmeunier)\
**Post date:** [October 2, 2017, 5:21pm UTC](https://discourse.pijul.org/t/warning-patch-hash-format-changed-breaking-change/95/3 "2017-10-02T17:21:58Z")

</div>

In an attempt to implement all breaking changes we are aware of before 0.9, I implemented this.

The Nest and [crates.io](http://crates.io) have been updated. Unfortunately, older versions of Pijul cannot pull or push patches from remote repositories with the new format. Upgrading can be done by:

- `cargo install pijul` to install Pijul ≥ 0.8.2.
- `pijul clone` all your repositories locally. Pijul 0.8.2 knows about the format change, and can clone the old patches.

---

<div class="post-metadata">

**Author:** ![pmeunier](https://yyz1.discourse-cdn.com/flex031/user_avatar/discourse.pijul.org/pmeunier/32/4_2.png) [@pmeunier](https://discourse.pijul.org/u/pmeunier)\
**Post date:** [October 2, 2017, 5:22pm UTC](https://discourse.pijul.org/t/warning-patch-hash-format-changed-breaking-change/95/4 "2017-10-02T17:22:50Z")

</div>



---

<div class="post-metadata">

**Author:** ![lambda](https://yyz1.discourse-cdn.com/flex031/user_avatar/discourse.pijul.org/lambda/32/39_2.png) [@lambda](https://discourse.pijul.org/u/lambda)\
**Post date:** [October 10, 2017, 3:19am UTC](https://discourse.pijul.org/t/warning-patch-hash-format-changed-breaking-change/95/5 "2017-10-10T03:19:41Z")

</div>

Is there any reason for using SHA-512? That seems like an excessive choice for a security level; SHA-256, with a security level of 128 bits, would be sufficient.

However, even better would be SHA-512/256, which is SHA-512 with a different IV truncated to 256 bits. It also has a security level of 128 bits, but it isn’t vulnerable to length-extension attacks like SHA-512 or SHA-256 are. Length extension attacks aren’t likely a problem, since Pijul is just using the hashes as an identifier and checksum but not as a MAC, but it is a good property to have in case anyone ever does make an assumption that would be invalidated by a length-extension attack.

That would cut the length of the identifiers in half, which would help with the slight expansion by switching to base58.

---

<div class="post-metadata">

**Author:** ![pmeunier](https://yyz1.discourse-cdn.com/flex031/user_avatar/discourse.pijul.org/pmeunier/32/4_2.png) [@pmeunier](https://discourse.pijul.org/u/pmeunier)\
**Post date:** [October 10, 2017, 7:22am UTC](https://discourse.pijul.org/t/warning-patch-hash-format-changed-breaking-change/95/6 "2017-10-10T07:22:10Z")

</div>

> [@lambda](#):
>
> Is there any reason for using SHA-512?

Yes. We chose the hardest standardised hash at the time, because it’s always easier to decrease the security level later than to run into security problems.

That said, the design of libpijul on hashes is entirely forward-compatible: actually, the first byte of our patch identifiers indicates which hash function to use (in base64, all hashes started with `A`).

We might add Blake2s instead of SHA2 in the next release, which is capable of producing shorter hashes. Older patches will keep their identifier, though.

---

<div class="post-metadata">

**Author:** ![wscott](https://yyz1.discourse-cdn.com/flex031/user_avatar/discourse.pijul.org/wscott/32/38_2.png) [@wscott](https://discourse.pijul.org/u/wscott)\
**Post date:** [October 12, 2017, 2:46pm UTC](https://discourse.pijul.org/t/warning-patch-hash-format-changed-breaking-change/95/7 "2017-10-12T14:46:55Z")

</div>

Something to consider is the [multihash format](https://github.com/multiformats/multihash) used by IPFS.  
The idea is that the hash and encoding are documented in the output and it would be easier to change things in the future in a backward compatible way.

Someone has even made a Rust version: [https://github.com/google/rust-multihash](https://github.com/google/rust-multihash)

---

<div class="post-metadata">

**Author:** ![dermetfan](https://yyz1.discourse-cdn.com/flex031/user_avatar/discourse.pijul.org/dermetfan/32/94_2.png) [@dermetfan](https://discourse.pijul.org/u/dermetfan)\
**Post date:** [February 22, 2018, 4:43pm UTC](https://discourse.pijul.org/t/warning-patch-hash-format-changed-breaking-change/95/8 "2018-02-22T16:43:27Z")

</div>

Pijul 0.9.0 does not seem to be able to clone my 0.8.0 repository, failing with `error: NoDb`. An empty repo is created.

0.8.3 behaves identically. I couldn’t manage to compile 0.8.2 or 0.8.1 on NixOS 18.03 unstable.

If it helps I can send you an archive as I’m unable to upload to the Nest.

---

<div class="post-metadata">

**Author:** ![lthms](https://yyz1.discourse-cdn.com/flex031/user_avatar/discourse.pijul.org/lthms/32/124_2.png) [@lthms](https://discourse.pijul.org/u/lthms)\
**Post date:** [February 22, 2018, 8:41pm UTC](https://discourse.pijul.org/t/warning-patch-hash-format-changed-breaking-change/95/9 "2018-02-22T20:41:19Z")

</div>

You should wait until `pijul-0.10` is released, I think.
