{"thread":{"id":"23169","subject":"Pseudonymous commits","startedAt":"2010-03-25T03:57:40Z","lastAt":"2010-03-25T23:57:22Z","messageCount":13,"participants":["Mike.lifeguard","Theodore Tso","Kris Shannon","Avery Pennarun","Alex Riesen","Santi Béjar","Nicolas Pitre","Chris Packham","Jakub Narebski"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"137764","messageId":"4BAADF34.3080806@gmail.com","threadId":"23169","inReplyTo":null,"subject":"Pseudonymous commits","fromName":"Mike.lifeguard","fromEmail":"mike.lifeguard@gmail.com","sentAt":"2010-03-25T03:57:40Z","receivedAt":"2010-03-25T03:57:40Z","isPatch":false,"sender":{"key":"mike.lifeguard@gmail.com","avatar":"https://gravatar.com/avatar/a12ecdf9f8b0f34d981d1ae8d7e74205358548f48936c86f240308e942544928?d=mp&s=160"},"body":"-----BEGIN PGP SIGNED MESSAGE-----\nHash: SHA1\n\nHi,\n\nGit gives attribution by a \"name\" and an \"email\" - however several\ncontributors I work with are uncomfortable giving that information. I\ncan easily use a pseudonym (I do so for myself), but is there any way to\nnot have an email? Or shall I just use \"not@real.email\"?\n\nWhile on the subject, I'm curious why name+email was decided upon for\nattribution, instead of name + optional-email + optional-URL or\nsomething that might provide additional information or useful metadata.\n\nThanks,\n- -Mike\n\nPS, I still have a question about git-svn & splitting repos with\nfilter-branch under subject \"dcommit-ing from a split repo\"\n-----BEGIN PGP SIGNATURE-----\nVersion: GnuPG v1.4.9 (GNU/Linux)\n\niEYEARECAAYFAkuq3zQACgkQst0AR/DaKHsDZQCgxitnecj1I6NMDIindJuQna/u\nAoUAoNlYAQKHYx5PGYNY3MaeiKXh49qa\n=etTo\n-----END PGP SIGNATURE-----\n"},{"id":"137766","messageId":"4BA51E6B-7325-465A-B23E-7F3C5BF87700@mit.edu","threadId":"23169","inReplyTo":"4BAADF34.3080806@gmail.com","subject":"Re: Pseudonymous commits","fromName":"Theodore Tso","fromEmail":"tytso@mit.edu","sentAt":"2010-03-25T04:39:11Z","receivedAt":"2010-03-25T04:39:11Z","isPatch":false,"sender":{"key":"tytso@mit.edu","avatar":"https://avatars.githubusercontent.com/u/51416?v=4"},"body":"\nOn Mar 24, 2010, at 11:57 PM, Mike.lifeguard wrote:\n> \n> Git gives attribution by a \"name\" and an \"email\" - however several\n> contributors I work with are uncomfortable giving that information. I\n> can easily use a pseudonym (I do so for myself), but is there any way to\n> not have an email? Or shall I just use \"not@real.email\"?\n\nMost projects want some kind of way of communicator with their contributors; and some kind of accountability with their contributors.  Otherwise, how do you know whether said contributor isn't a Chinese intelligence agent trying to insert a backdoor into your program by submitting change using techniques demonstrated by the Underhanded C contest[1]?  :-)\n\n[1] http://underhanded.xcott.com/\n\nOf course, someone can easily claim any random name, and it's not hard to get a mail account; you could pick a random name like \"Mike Lifeguard\", and get a gmail account, for example.  :-)   On the Internet, no one knows whether you are a dog.  (Or a Chinese secret agent.  :-)\n\nBut if someone isn't willing to give even an e-mail address, I would think even the most lax project would probably want to think twice about whether to accept patches from this contributor....\n\n-- Ted\n"},{"id":"137767","messageId":"4BAAE981.4040205@gmail.com","threadId":"23169","inReplyTo":"4BA51E6B-7325-465A-B23E-7F3C5BF87700@mit.edu","subject":"Re: Pseudonymous commits","fromName":"Mike.lifeguard","fromEmail":"mike.lifeguard@gmail.com","sentAt":"2010-03-25T04:41:37Z","receivedAt":"2010-03-25T04:41:37Z","isPatch":false,"sender":{"key":"mike.lifeguard@gmail.com","avatar":"https://gravatar.com/avatar/a12ecdf9f8b0f34d981d1ae8d7e74205358548f48936c86f240308e942544928?d=mp&s=160"},"body":"-----BEGIN PGP SIGNED MESSAGE-----\nHash: SHA1\n\nOn 10-03-25 01:39 AM, Theodore Tso wrote:\n> How do you know whether said contributor\n> isn't a Chinese intelligence agent trying to insert a backdoor into\n> your program\n\nBecause they are only contributing translations.\n\nNot everyone has important projects like the kernel :)\n\n- -Mike\n-----BEGIN PGP SIGNATURE-----\nVersion: GnuPG v1.4.9 (GNU/Linux)\n\niEYEARECAAYFAkuq6YAACgkQst0AR/DaKHsMcQCgnm5/RfxlTNC0+0Mrw2jtgjez\nIgsAn117HtEZyf1XX88HR9vbSxZiTkQI\n=1Kx1\n-----END PGP SIGNATURE-----\n"},{"id":"137768","messageId":"e51f4f551003242154p7fb20ffch790dd1ada15eca0@mail.gmail.com","threadId":"23169","inReplyTo":"4BAAE981.4040205@gmail.com","subject":"Re: Pseudonymous commits","fromName":"Kris Shannon","fromEmail":"kris@shannon.id.au","sentAt":"2010-03-25T04:54:04Z","receivedAt":"2010-03-25T04:54:04Z","isPatch":false,"sender":{"key":"kris@shannon.id.au","avatar":"https://gravatar.com/avatar/13a7c0b3c50ffacf54f456e543023fd702898bb134165fa805f019930524151f?d=mp&s=160"},"body":"Accountability for translations is even more important because review is\nusually a LOT harder.\n\nOn 25 March 2010 15:41, Mike.lifeguard <mike.lifeguard@gmail.com> wrote:\n> -----BEGIN PGP SIGNED MESSAGE-----\n> Hash: SHA1\n>\n> On 10-03-25 01:39 AM, Theodore Tso wrote:\n>> How do you know whether said contributor\n>> isn't a Chinese intelligence agent trying to insert a backdoor into\n>> your program\n>\n> Because they are only contributing translations.\n>\n> Not everyone has important projects like the kernel :)\n>\n> - -Mike\n> -----BEGIN PGP SIGNATURE-----\n> Version: GnuPG v1.4.9 (GNU/Linux)\n>\n> iEYEARECAAYFAkuq6YAACgkQst0AR/DaKHsMcQCgnm5/RfxlTNC0+0Mrw2jtgjez\n> IgsAn117HtEZyf1XX88HR9vbSxZiTkQI\n> =1Kx1\n> -----END PGP SIGNATURE-----\n> --\n> To unsubscribe from this list: send the line \"unsubscribe git\" in\n> the body of a message to majordomo@vger.kernel.org\n> More majordomo info at  http://vger.kernel.org/majordomo-info.html\n>\n"},{"id":"137769","messageId":"4BAAEDF7.1080107@gmail.com","threadId":"23169","inReplyTo":"e51f4f551003242154p7fb20ffch790dd1ada15eca0@mail.gmail.com","subject":"Re: Pseudonymous commits","fromName":"Mike.lifeguard","fromEmail":"mike.lifeguard@gmail.com","sentAt":"2010-03-25T05:00:39Z","receivedAt":"2010-03-25T05:00:39Z","isPatch":false,"sender":{"key":"mike.lifeguard@gmail.com","avatar":"https://gravatar.com/avatar/a12ecdf9f8b0f34d981d1ae8d7e74205358548f48936c86f240308e942544928?d=mp&s=160"},"body":"-----BEGIN PGP SIGNED MESSAGE-----\nHash: SHA1\n\nOn 10-03-25 01:54 AM, Kris Shannon wrote:\n> Accountability for translations is even more important because review is\n> usually a LOT harder.\n\nI didn't say the translations weren't reviewed, or the translators were\nunaccountable. They are in both cases.\n\nIn any case, is the answer \"git can't do that\" or not? Because that's\nactually the answer I'm interested in.\n\nThanks,\n- -Mike\n-----BEGIN PGP SIGNATURE-----\nVersion: GnuPG v1.4.9 (GNU/Linux)\n\niEYEARECAAYFAkuq7fcACgkQst0AR/DaKHvjLwCgxLt0Nf7a6u1s15hgtqOpAWAm\nmRcAoKnax9/54hbNXpGHlvMYRrwTj85C\n=4ele\n-----END PGP SIGNATURE-----\n"},{"id":"137777","messageId":"32541b131003242214o2b05e5cbn1668872daea7e887@mail.gmail.com","threadId":"23169","inReplyTo":"4BAAEDF7.1080107@gmail.com","subject":"Re: Pseudonymous commits","fromName":"Avery Pennarun","fromEmail":"apenwarr@gmail.com","sentAt":"2010-03-25T05:14:18Z","receivedAt":"2010-03-25T05:14:18Z","isPatch":false,"sender":{"key":"apenwarr@gmail.com","avatar":"https://avatars.githubusercontent.com/u/20592?v=4"},"body":"On Thu, Mar 25, 2010 at 1:00 AM, Mike.lifeguard\n<mike.lifeguard@gmail.com> wrote:\n> On 10-03-25 01:54 AM, Kris Shannon wrote:\n>> Accountability for translations is even more important because review is\n>> usually a LOT harder.\n>\n> I didn't say the translations weren't reviewed, or the translators were\n> unaccountable. They are in both cases.\n\nI think the point is that if you don't even have contact information\nfor them, they can't *really* be accountable.  But of course that's up\nto you.\n\n> In any case, is the answer \"git can't do that\" or not? Because that's\n> actually the answer I'm interested in.\n\nEvery committer (and author) in git has a (nonempty, I think) name and\nan email address, and that's how you identify the committer (and\nauthor).  What you do with those fields is between you and your\nproject maintainer.\n\nHave fun,\n\nAvery\n"},{"id":"137791","messageId":"81b0412b1003250218t3205e12cj5a5013d97e2c0e38@mail.gmail.com","threadId":"23169","inReplyTo":"4BAAEDF7.1080107@gmail.com","subject":"Re: Pseudonymous commits","fromName":"Alex Riesen","fromEmail":"raa.lkml@gmail.com","sentAt":"2010-03-25T09:18:51Z","receivedAt":"2010-03-25T09:18:51Z","isPatch":false,"sender":{"key":"raa.lkml@gmail.com","avatar":"https://avatars.githubusercontent.com/u/324101?v=4"},"body":"On Thu, Mar 25, 2010 at 06:00, Mike.lifeguard <mike.lifeguard@gmail.com> wrote:\n> In any case, is the answer \"git can't do that\" or not? Because that's\n> actually the answer I'm interested in.\n\ngit commit --author \"I am not Mike Lifeguard <mike.lifeguard@gmail.com>\"\n"},{"id":"137794","messageId":"adf1fd3d1003250405i621fcb18uc918c67474c37115@mail.gmail.com","threadId":"23169","inReplyTo":"4BAAEDF7.1080107@gmail.com","subject":"Re: Pseudonymous commits","fromName":"Santi Béjar","fromEmail":"santi@agolina.net","sentAt":"2010-03-25T11:05:20Z","receivedAt":"2010-03-25T11:05:20Z","isPatch":false,"sender":{"key":"santi@agolina.net","avatar":null},"body":"On Thu, Mar 25, 2010 at 6:00 AM, Mike.lifeguard\n<mike.lifeguard@gmail.com> wrote:\n> In any case, is the answer \"git can't do that\" or not? Because that's\n> actually the answer I'm interested in.\n\nGit uses the author/committer info for diferent things. First, it is a\nunique identifier (name+email); second it is used when dealing with\nmails (in and out mails).\n\nIf you don´t use email (for review, or contributions) you can build\nthe identifier as you want without the need to be name and email, it\nis up to the project. For my private projects I use name=Santi\nemail=santi, so the author/committer info is \"Santi <santi>\" and I\nhaven´t found problems. Note that I don´t send/reveive emails to\ncontribute, just fetch and push. Maybe it would be better to use a\nuser.email that resemble an email, with @ and such.\n\nHTH,\nSanti\n"},{"id":"137808","messageId":"alpine.LFD.2.00.1003251459540.694@xanadu.home","threadId":"23169","inReplyTo":"4BAAE981.4040205@gmail.com","subject":"Re: Pseudonymous commits","fromName":"Nicolas Pitre","fromEmail":"nico@fluxnic.net","sentAt":"2010-03-25T19:02:44Z","receivedAt":"2010-03-25T19:02:44Z","isPatch":false,"sender":{"key":"nico@fluxnic.net","avatar":"https://avatars.githubusercontent.com/u/702790?v=4"},"body":"On Thu, 25 Mar 2010, Mike.lifeguard wrote:\n\n> On 10-03-25 01:39 AM, Theodore Tso wrote:\n> > How do you know whether said contributor\n> > isn't a Chinese intelligence agent trying to insert a backdoor into\n> > your program\n> \n> Because they are only contributing translations.\n\nJust take over authorship of the patch yourself then.\n\nOr pick a generic email address such as the translator's mailing list \nemail address or the like.\n\n\nNicolas\n"},{"id":"137810","messageId":"4BABB8DC.7060906@gmail.com","threadId":"23169","inReplyTo":"alpine.LFD.2.00.1003251459540.694@xanadu.home","subject":"Re: Pseudonymous commits","fromName":"Mike.lifeguard","fromEmail":"mike.lifeguard@gmail.com","sentAt":"2010-03-25T19:26:20Z","receivedAt":"2010-03-25T19:26:20Z","isPatch":false,"sender":{"key":"mike.lifeguard@gmail.com","avatar":"https://gravatar.com/avatar/a12ecdf9f8b0f34d981d1ae8d7e74205358548f48936c86f240308e942544928?d=mp&s=160"},"body":"-----BEGIN PGP SIGNED MESSAGE-----\nHash: SHA1\n\nIn the end, I managed to convince them they wouldn't be spammed (hope\nI'm right), and I used their real emails. Nonetheless, I appreciate the\nhelp.\n\nIf you're still in the helping mood (and know what you're talking\nabout), I'm still looking for help with a case where an SVN repo is\nsplit into separate git repositories & being unable to dcommit changes\nback to SVN. The archived email is:\nhttp://article.gmane.org/gmane.comp.version-control.git/142654\n\nThanks,\n- -Mike\n-----BEGIN PGP SIGNATURE-----\nVersion: GnuPG v1.4.9 (GNU/Linux)\n\niEYEARECAAYFAkuruNwACgkQst0AR/DaKHsN/QCg2wyWwps6FEibNlBI5hlf9Fwd\nODcAoKkcjpxNkPrVxlT690F2znoAUzlU\n=rkB8\n-----END PGP SIGNATURE-----\n"},{"id":"137814","messageId":"alpine.LFD.2.00.1003251605560.694@xanadu.home","threadId":"23169","inReplyTo":"4BABB8DC.7060906@gmail.com","subject":"Re: Pseudonymous commits","fromName":"Nicolas Pitre","fromEmail":"nico@fluxnic.net","sentAt":"2010-03-25T20:14:08Z","receivedAt":"2010-03-25T20:14:08Z","isPatch":false,"sender":{"key":"nico@fluxnic.net","avatar":"https://avatars.githubusercontent.com/u/702790?v=4"},"body":"On Thu, 25 Mar 2010, Mike.lifeguard wrote:\n\n> In the end, I managed to convince them they wouldn't be spammed (hope\n> I'm right), and I used their real emails. Nonetheless, I appreciate the\n> help.\n\nOh, if your project is public and accessible through gitweb then \nspammers will certainly scan it and pick up their email addresses.  \nMaybe some of them might even go as far as cloning Git repositories just \nfor that purpose.  Only local spam filtering may help in that case.\n\n> If you're still in the helping mood (and know what you're talking\n> about), I'm still looking for help with a case where an SVN repo is\n> split into separate git repositories & being unable to dcommit changes\n> back to SVN. The archived email is:\n> http://article.gmane.org/gmane.comp.version-control.git/142654\n\nI know a little about Git, but not git-svn.  Someone else will have to \nhelp you with that one.\n\n\nNicolas\n"},{"id":"137816","messageId":"a038bef51003251430v35ab602v661f24888d637afa@mail.gmail.com","threadId":"23169","inReplyTo":"alpine.LFD.2.00.1003251605560.694@xanadu.home","subject":"Re: Pseudonymous commits","fromName":"Chris Packham","fromEmail":"judge.packham@gmail.com","sentAt":"2010-03-25T21:30:27Z","receivedAt":"2010-03-25T21:30:27Z","isPatch":false,"sender":{"key":"judge.packham@gmail.com","avatar":"https://avatars.githubusercontent.com/u/155667?v=4"},"body":"On Thu, Mar 25, 2010 at 1:14 PM, Nicolas Pitre <nico@fluxnic.net> wrote:\n> On Thu, 25 Mar 2010, Mike.lifeguard wrote:\n>\n>> In the end, I managed to convince them they wouldn't be spammed (hope\n>> I'm right), and I used their real emails. Nonetheless, I appreciate the\n>> help.\n>\n> Oh, if your project is public and accessible through gitweb then\n> spammers will certainly scan it and pick up their email addresses.\n> Maybe some of them might even go as far as cloning Git repositories just\n> for that purpose.  Only local spam filtering may help in that case.\n>\n\nSounds like it'd be a really good option to have in gitweb to\nobfuscate email addresses a-la gmane and practically every other web\nbased mailing list/news reader. Could be fairly low hanging fruit with\na decent payoff (not that I'm volunteering). Can't do much about clone\nand spam.\n"},{"id":"137819","messageId":"m34ok4j6qi.fsf@localhost.localdomain","threadId":"23169","inReplyTo":"alpine.LFD.2.00.1003251459540.694@xanadu.home","subject":"Re: Pseudonymous commits","fromName":"Jakub Narebski","fromEmail":"jnareb@gmail.com","sentAt":"2010-03-25T23:57:22Z","receivedAt":"2010-03-25T23:57:22Z","isPatch":false,"sender":{"key":"jnareb@gmail.com","avatar":"https://avatars.githubusercontent.com/u/2706?v=4"},"body":"Nicolas Pitre <nico@fluxnic.net> writes:\n\n> On Thu, 25 Mar 2010, Mike.lifeguard wrote:\n> \n> > On 10-03-25 01:39 AM, Theodore Tso wrote:\n> > > How do you know whether said contributor\n> > > isn't a Chinese intelligence agent trying to insert a backdoor into\n> > > your program\n> > \n> > Because they are only contributing translations.\n> \n> Just take over authorship of the patch yourself then.\n> \n> Or pick a generic email address such as the translator's mailing list \n> email address or the like.\n\nIn the case of translations one cal use generic \"language team\"\nmailing list, i.e. <LL@li.org> (where LL is ISO code of language,\ne.g. 'de@li.org' for translations to German, etc.).\n\n-- \nJakub Narebski\nPoland\nShadeHawk on #git\n"}]}