{"thread":{"id":"33416","subject":"Remote helpers and signed tags","startedAt":"2013-04-07T10:34:18Z","lastAt":"2013-04-17T05:02:21Z","messageCount":14,"participants":["John Keeping","Jonathan Nieder","Sverre Rabbelier","Junio C Hamano"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"213401","messageId":"20130407103418.GT2222@serenity.lan","threadId":"33416","inReplyTo":null,"subject":"Remote helpers and signed tags","fromName":"John Keeping","fromEmail":"john@keeping.me.uk","sentAt":"2013-04-07T10:34:18Z","receivedAt":"2013-04-07T10:34:18Z","isPatch":false,"sender":{"key":"john@keeping.me.uk","avatar":"https://avatars.githubusercontent.com/u/1702081?v=4"},"body":"It appears to be impossible to push signed tags using a remote helper\nthat supports only fast-export.  This is reported against gitifyhg[1]\nbut I think it is actually a Git issue.\n\n[1] https://github.com/buchuki/gitifyhg/issues/59\n\nI can reproduce the error using a trivial remote helper (run this in a\nclone of git.git):\n\n-- >8 --\ncat >git-remote-export <<EOF &&\n#!/bin/sh\n\nalias=$1\nurl=${2-$1}\n\nwhile read -r line\ndo\n\tcase \"$line\" in\n\tcapabilities)\n\t\techo 'export'\n\t\techo 'refspec *:*'\n\t\techo\n\t\t;;\n\tlist)\n\t\techo\n\t\t;;\n\texport)\n\t\twhile read -r line\n\t\tdo\n\t\t\techo \"$line\" >&3\n\t\t\ttest \"$line\" = done && break\n\t\tdone 3>\"$url\"\n\t\techo\n\t\t;;\n\t'')\n\t\texit\n\t\t;;\n\t*)\n\t\techo >&2 \"unsupported command: $line\"\n\t\texit 1\n\t\t;;\n\tesac\ndone\nEOF\nchmod +x git-remote-export &&\nPATH=\"$(pwd):$PATH\" git push \"export::$(pwd)/v1.8.2.export\" v1.8.2\n-- 8< --\n\nThis produces:\n\n    fatal: Encountered signed tag 572a535454612a046e7dd7404dcca94d6243c788;\n        use --signed-tag=<mode> to handle it.\n    fatal: Error while running fast-export\n\nwhich is not particularly helpful for a user who doesn't know how the\nremote helper is implemented, particularly because adding\n--signed-tag=<mode> to the command won't work.\n\nI think there are two problems here:\n\n    1) The error message is misleading: \"--signed-tag\" isn't an option\n       to git-push and as a user I don't know why Git thought I wanted\n       to run fast-export.\n\n    2) There is no way (that I have found) to change the signed-tag\n       behaviour of git-fast-export when it is being invoked for a\n       remote helper.\n\nHow do remote helpers using the \"push\" method handle this?  In that case\nit seems to be completely up to the helper program to decide what to do.\n\nI wonder if the way forward is to do some combination of:\n\n    a) Add a --signed-tags option to git-push, which is either passed to\n       fast-export or given as a new \"option signed-tags\" to the\n       remote-helper when using the push interface (and ignored for the\n       connect interface).\n\n    b) Add a configuration variable to specify how to handle signed tags\n       when pushing to a remote that uses a remote helper that cannot\n       handle them; something like \"remote.<name>.signedTags\".\n\n    c) Improve the \"Error while running fast-export\" message to\n       something more like \"Error pushing with fast-export (using helper\n       git-remote-foo)\".\n"},{"id":"213466","messageId":"20130407214626.GC19857@elie.Belkin","threadId":"33416","inReplyTo":"20130407103418.GT2222@serenity.lan","subject":"Re: Remote helpers and signed tags","fromName":"Jonathan Nieder","fromEmail":"jrnieder@gmail.com","sentAt":"2013-04-07T21:46:26Z","receivedAt":"2013-04-07T21:46:26Z","isPatch":false,"sender":{"key":"jrnieder@gmail.com","avatar":"https://avatars.githubusercontent.com/u/281595?v=4"},"body":"Hi John,\n\nJohn Keeping wrote:\n\n> It appears to be impossible to push signed tags using a remote helper\n> that supports only fast-export.\n[...]\n>     fatal: Encountered signed tag 572a535454612a046e7dd7404dcca94d6243c788;\n>         use --signed-tag=<mode> to handle it.\n>     fatal: Error while running fast-export\n>\n> which is not particularly helpful for a user who doesn't know how the\n> remote helper is implemented\n\nYeah, this is idiotic.\n\nThe remote helper infrastructure is certainly being unhelpful here.  I\nwonder if transport-helper should just pass --signed-tag=strip and be\ndone with it (leaving open the possibility of a capability to switch\nto --signed-tag=verbatim when someone wants to teach the testgit\nhelper to support that).  What do you think?\n\nThanks,\nJonathan\n"},{"id":"213481","messageId":"CAGdFq_g+kk-Fy1fcV6D5x4kroRXX63T8wjKNUqqfu39wUkSO6A@mail.gmail.com","threadId":"33416","inReplyTo":"20130407214626.GC19857@elie.Belkin","subject":"Re: Remote helpers and signed tags","fromName":"Sverre Rabbelier","fromEmail":"srabbelier@gmail.com","sentAt":"2013-04-08T00:02:48Z","receivedAt":"2013-04-08T00:02:48Z","isPatch":false,"sender":{"key":"srabbelier@gmail.com","avatar":"https://avatars.githubusercontent.com/u/3098?v=4"},"body":"On Sun, Apr 7, 2013 at 2:46 PM, Jonathan Nieder <jrnieder@gmail.com> wrote:\n> The remote helper infrastructure is certainly being unhelpful here.  I\n> wonder if transport-helper should just pass --signed-tag=strip and be\n> done with it (leaving open the possibility of a capability to switch\n> to --signed-tag=verbatim when someone wants to teach the testgit\n> helper to support that).  What do you think?\n\nI think that's (at least for now) the right thing to do. Passing\nanything but signed-tag=strip should be triggered by a capability from\nthe helper, since most helpers won't know how to deal with signed\ntags.\n\n--\nCheers,\n\nSverre Rabbelier\n"},{"id":"214164","messageId":"cover.1365936811.git.john@keeping.me.uk","threadId":"33416","inReplyTo":"CAGdFq_g+kk-Fy1fcV6D5x4kroRXX63T8wjKNUqqfu39wUkSO6A@mail.gmail.com","subject":"[PATCH 0/3] Handle signed tags with 'export' remote helpers","fromName":"John Keeping","fromEmail":"john@keeping.me.uk","sentAt":"2013-04-14T10:57:05Z","receivedAt":"2013-04-14T10:57:05Z","isPatch":true,"sender":{"key":"john@keeping.me.uk","avatar":"https://avatars.githubusercontent.com/u/1702081?v=4"},"body":"On Sun, Apr 07, 2013 at 05:02:48PM -0700, Sverre Rabbelier wrote:\n> On Sun, Apr 7, 2013 at 2:46 PM, Jonathan Nieder <jrnieder@gmail.com> wrote:\n> > The remote helper infrastructure is certainly being unhelpful here.  I\n> > wonder if transport-helper should just pass --signed-tag=strip and be\n> > done with it (leaving open the possibility of a capability to switch\n> > to --signed-tag=verbatim when someone wants to teach the testgit\n> > helper to support that).  What do you think?\n> \n> I think that's (at least for now) the right thing to do. Passing\n> anything but signed-tag=strip should be triggered by a capability from\n> the helper, since most helpers won't know how to deal with signed\n> tags.\n\nI don't like the idea of silently stripping tags, so how about this?\n\nPatch 1 adds a new 'warn-strip' mode to 'fast-export --signed-tags=...'\nwhich strips tags but issues a warning when doing so.  Then we make\ntransport-helper use that before finally adding a new capability to\nallow a remote helper to change '--signed-tags=warn-strip' into\n'--signed-tags=verbatim'.\n\nJohn Keeping (3):\n  fast-export: add --signed-tags=warn-strip mode\n  transport-helper: pass --signed-tags=warn-strip to fast-export\n  transport-helper: add 'signed-tags' capability\n\n Documentation/git-fast-export.txt   | 10 ++++++----\n Documentation/gitremote-helpers.txt |  4 ++++\n builtin/fast-export.c               |  8 +++++++-\n git-remote-testgit                  |  1 +\n t/t5801-remote-helpers.sh           | 20 ++++++++++++++++++++\n t/t9350-fast-export.sh              |  6 ++++++\n transport-helper.c                  |  7 ++++++-\n 7 files changed, 50 insertions(+), 6 deletions(-)\n\n-- \n1.8.2.694.ga76e9c3.dirty\n"},{"id":"214165","messageId":"8716b887972b0eb1671afd2692416efd588f7d1d.1365936811.git.john@keeping.me.uk","threadId":"33416","inReplyTo":"cover.1365936811.git.john@keeping.me.uk","subject":"[PATCH 1/3] fast-export: add --signed-tags=warn-strip mode","fromName":"John Keeping","fromEmail":"john@keeping.me.uk","sentAt":"2013-04-14T10:57:06Z","receivedAt":"2013-04-14T10:57:06Z","isPatch":true,"sender":{"key":"john@keeping.me.uk","avatar":"https://avatars.githubusercontent.com/u/1702081?v=4"},"body":"This issues a warning while stripping signatures from signed tags, which\nallows us to use it as default behaviour for remote helpers which cannot\nspecify how to handle signed tags.\n\nSigned-off-by: John Keeping <john@keeping.me.uk>\n---\n Documentation/git-fast-export.txt | 10 ++++++----\n builtin/fast-export.c             |  8 +++++++-\n t/t9350-fast-export.sh            |  6 ++++++\n 3 files changed, 19 insertions(+), 5 deletions(-)\n\ndiff --git a/Documentation/git-fast-export.txt b/Documentation/git-fast-export.txt\nindex feab7a3..03fc8c3 100644\n--- a/Documentation/git-fast-export.txt\n+++ b/Documentation/git-fast-export.txt\n@@ -27,15 +27,17 @@ OPTIONS\n \tInsert 'progress' statements every <n> objects, to be shown by\n \t'git fast-import' during import.\n \n---signed-tags=(verbatim|warn|strip|abort)::\n+--signed-tags=(verbatim|warn|warn-strip|strip|abort)::\n \tSpecify how to handle signed tags.  Since any transformation\n \tafter the export can change the tag names (which can also happen\n \twhen excluding revisions) the signatures will not match.\n +\n When asking to 'abort' (which is the default), this program will die\n-when encountering a signed tag.  With 'strip', the tags will be made\n-unsigned, with 'verbatim', they will be silently exported\n-and with 'warn', they will be exported, but you will see a warning.\n+when encountering a signed tag.  With 'strip', the tags will silently\n+be made unsigned, with 'warn-strip' they will be made unsigned but a\n+warning will be displayed, with 'verbatim', they will be silently\n+exported and with 'warn', they will be exported, but you will see a\n+warning.\n \n --tag-of-filtered-object=(abort|drop|rewrite)::\n \tSpecify how to handle tags whose tagged object is filtered out.\ndiff --git a/builtin/fast-export.c b/builtin/fast-export.c\nindex 725c0a7..d60d675 100644\n--- a/builtin/fast-export.c\n+++ b/builtin/fast-export.c\n@@ -24,7 +24,7 @@ static const char *fast_export_usage[] = {\n };\n \n static int progress;\n-static enum { ABORT, VERBATIM, WARN, STRIP } signed_tag_mode = ABORT;\n+static enum { ABORT, VERBATIM, WARN, WARN_STRIP, STRIP } signed_tag_mode = ABORT;\n static enum { ERROR, DROP, REWRITE } tag_of_filtered_mode = ERROR;\n static int fake_missing_tagger;\n static int use_done_feature;\n@@ -40,6 +40,8 @@ static int parse_opt_signed_tag_mode(const struct option *opt,\n \t\tsigned_tag_mode = VERBATIM;\n \telse if (!strcmp(arg, \"warn\"))\n \t\tsigned_tag_mode = WARN;\n+\telse if (!strcmp(arg, \"warn-strip\"))\n+\t\tsigned_tag_mode = WARN_STRIP;\n \telse if (!strcmp(arg, \"strip\"))\n \t\tsigned_tag_mode = STRIP;\n \telse\n@@ -428,6 +430,10 @@ static void handle_tag(const char *name, struct tag *tag)\n \t\t\t\t/* fallthru */\n \t\t\tcase VERBATIM:\n \t\t\t\tbreak;\n+\t\t\tcase WARN_STRIP:\n+\t\t\t\twarning (\"Stripping signature from tag %s\",\n+\t\t\t\t\t sha1_to_hex(tag->object.sha1));\n+\t\t\t\t/* fallthru */\n \t\t\tcase STRIP:\n \t\t\t\tmessage_size = signature + 1 - message;\n \t\t\t\tbreak;\ndiff --git a/t/t9350-fast-export.sh b/t/t9350-fast-export.sh\nindex 9320b4f..2471bc6 100755\n--- a/t/t9350-fast-export.sh\n+++ b/t/t9350-fast-export.sh\n@@ -146,6 +146,12 @@ test_expect_success 'signed-tags=strip' '\n \n '\n \n+test_expect_success 'signed-tags=warn-strip' '\n+\tgit fast-export --signed-tags=warn-strip sign-your-name >output 2>err &&\n+\t! grep PGP output &&\n+\ttest -s err\n+'\n+\n test_expect_success 'setup submodule' '\n \n \tgit checkout -f master &&\n-- \n1.8.2.694.ga76e9c3.dirty\n"},{"id":"214166","messageId":"1d7cbf61d07f1f0490806f7516c622087ebed05d.1365936811.git.john@keeping.me.uk","threadId":"33416","inReplyTo":"cover.1365936811.git.john@keeping.me.uk","subject":"[PATCH 2/3] transport-helper: pass --signed-tags=warn-strip to fast-export","fromName":"John Keeping","fromEmail":"john@keeping.me.uk","sentAt":"2013-04-14T10:57:07Z","receivedAt":"2013-04-14T10:57:07Z","isPatch":true,"sender":{"key":"john@keeping.me.uk","avatar":"https://avatars.githubusercontent.com/u/1702081?v=4"},"body":"Currently, attempting to push a signed tag to a remote helper which uses\nfast-export results in the remote helper failing because the default\nfast-export action for signed tags is \"abort\".  This is not helpful for\nusers because there is no way to pass additional arguments to\nfast-export here, either from the remote helper or from the command\nline.\n\nIn general, the signature will be invalidated by whatever transformation\na remote helper performs on a tag to push it to a repository in a\ndifferent format so the correct behaviour is to strip the tag.  Doing\nthis silently may surprise people, so use \"warn-strip\" to issue a\nwarning when a signed tag is encountered.\n\nSigned-off-by: John Keeping <john@keeping.me.uk>\n---\n t/t5801-remote-helpers.sh | 10 ++++++++++\n transport-helper.c        |  3 ++-\n 2 files changed, 12 insertions(+), 1 deletion(-)\n\ndiff --git a/t/t5801-remote-helpers.sh b/t/t5801-remote-helpers.sh\nindex f387027..9b287db 100755\n--- a/t/t5801-remote-helpers.sh\n+++ b/t/t5801-remote-helpers.sh\n@@ -6,6 +6,7 @@\n test_description='Test remote-helper import and export commands'\n \n . ./test-lib.sh\n+. \"$TEST_DIRECTORY\"/lib-gpg.sh\n \n if ! type \"${BASH-bash}\" >/dev/null 2>&1; then\n \tskip_all='skipping remote-testgit tests, bash not available'\n@@ -166,4 +167,13 @@ test_expect_success 'push ref with existing object' '\n \tcompare_refs local dup server dup\n '\n \n+test_expect_success GPG 'push signed tag' '\n+\t(cd local &&\n+\tgit checkout master &&\n+\tgit tag -s -m signed-tag signed-tag &&\n+\tgit push origin signed-tag\n+\t) &&\n+\tcompare_refs local signed-tag^{} server signed-tag^{}\n+'\n+\n test_done\ndiff --git a/transport-helper.c b/transport-helper.c\nindex dcd8d97..3ce8259 100644\n--- a/transport-helper.c\n+++ b/transport-helper.c\n@@ -410,9 +410,10 @@ static int get_exporter(struct transport *transport,\n \t/* we need to duplicate helper->in because we want to use it after\n \t * fastexport is done with it. */\n \tfastexport->out = dup(helper->in);\n-\tfastexport->argv = xcalloc(5 + revlist_args->nr, sizeof(*fastexport->argv));\n+\tfastexport->argv = xcalloc(6 + revlist_args->nr, sizeof(*fastexport->argv));\n \tfastexport->argv[argc++] = \"fast-export\";\n \tfastexport->argv[argc++] = \"--use-done-feature\";\n+\tfastexport->argv[argc++] = \"--signed-tags=warn-strip\";\n \tif (data->export_marks)\n \t\tfastexport->argv[argc++] = data->export_marks;\n \tif (data->import_marks)\n-- \n1.8.2.694.ga76e9c3.dirty\n"},{"id":"214167","messageId":"5a121757b7fb1142e5b0a42a19c45e0431deda3b.1365936811.git.john@keeping.me.uk","threadId":"33416","inReplyTo":"cover.1365936811.git.john@keeping.me.uk","subject":"[PATCH 3/3] transport-helper: add 'signed-tags' capability","fromName":"John Keeping","fromEmail":"john@keeping.me.uk","sentAt":"2013-04-14T10:57:08Z","receivedAt":"2013-04-14T10:57:08Z","isPatch":true,"sender":{"key":"john@keeping.me.uk","avatar":"https://avatars.githubusercontent.com/u/1702081?v=4"},"body":"This allows a remote helper using the 'export' protocol to specify that\nit supports signed tags, changing the handing from 'warn-strip' to\n'verbatim'.\n\nSigned-off-by: John Keeping <john@keeping.me.uk>\n---\n Documentation/gitremote-helpers.txt |  4 ++++\n git-remote-testgit                  |  1 +\n t/t5801-remote-helpers.sh           | 12 +++++++++++-\n transport-helper.c                  |  6 +++++-\n 4 files changed, 21 insertions(+), 2 deletions(-)\n\ndiff --git a/Documentation/gitremote-helpers.txt b/Documentation/gitremote-helpers.txt\nindex f506031..da74641 100644\n--- a/Documentation/gitremote-helpers.txt\n+++ b/Documentation/gitremote-helpers.txt\n@@ -202,6 +202,10 @@ capability then it should advertise `refspec *:*`.\n \tmarks specified in <file> before processing any input. For details,\n \tread up on '--import-marks=<file>' in linkgit:git-fast-export[1].\n \n+'signed-tags'::\n+\tThis modifies the 'export' capability, instructing Git to pass\n+\t'--signed-tags=verbatim' to linkgit:git-fast-export[1].  In the\n+\tabsence of this capability, Git will use '--signed-tags=warn-strip'.\n \n \n \ndiff --git a/git-remote-testgit b/git-remote-testgit\nindex b395c8d..e7ed3a3 100755\n--- a/git-remote-testgit\n+++ b/git-remote-testgit\n@@ -38,6 +38,7 @@ do\n \t\t\techo \"*import-marks $gitmarks\"\n \t\t\techo \"*export-marks $gitmarks\"\n \t\tfi\n+\t\ttest -n \"$GIT_REMOTE_TESTGIT_SIGNED_TAGS\" && echo \"signed-tags\"\n \t\techo\n \t\t;;\n \tlist)\ndiff --git a/t/t5801-remote-helpers.sh b/t/t5801-remote-helpers.sh\nindex 9b287db..69212cd 100755\n--- a/t/t5801-remote-helpers.sh\n+++ b/t/t5801-remote-helpers.sh\n@@ -173,7 +173,17 @@ test_expect_success GPG 'push signed tag' '\n \tgit tag -s -m signed-tag signed-tag &&\n \tgit push origin signed-tag\n \t) &&\n-\tcompare_refs local signed-tag^{} server signed-tag^{}\n+\tcompare_refs local signed-tag^{} server signed-tag^{} &&\n+\ttest_must_fail compare_refs local signed-tag server signed-tag\n+'\n+\n+test_expect_success GPG 'push signed tag with signed-tags capability' '\n+\t(cd local &&\n+\tgit checkout master &&\n+\tgit tag -s -m signed-tag signed-tag-2 &&\n+\tGIT_REMOTE_TESTGIT_SIGNED_TAGS=1 git push origin signed-tag-2\n+\t) &&\n+\tcompare_refs local signed-tag-2 server signed-tag-2\n '\n \n test_done\ndiff --git a/transport-helper.c b/transport-helper.c\nindex 3ce8259..5f8d075 100644\n--- a/transport-helper.c\n+++ b/transport-helper.c\n@@ -25,6 +25,7 @@ struct helper_data {\n \t\toption : 1,\n \t\tpush : 1,\n \t\tconnect : 1,\n+\t\tsigned_tags : 1,\n \t\tno_disconnect_req : 1;\n \tchar *export_marks;\n \tchar *import_marks;\n@@ -191,6 +192,8 @@ static struct child_process *get_helper(struct transport *transport)\n \t\t\trefspecs[refspec_nr++] = xstrdup(capname + strlen(\"refspec \"));\n \t\t} else if (!strcmp(capname, \"connect\")) {\n \t\t\tdata->connect = 1;\n+\t\t} else if (!strcmp(capname, \"signed-tags\")) {\n+\t\t\tdata->signed_tags = 1;\n \t\t} else if (!prefixcmp(capname, \"export-marks \")) {\n \t\t\tstruct strbuf arg = STRBUF_INIT;\n \t\t\tstrbuf_addstr(&arg, \"--export-marks=\");\n@@ -413,7 +416,8 @@ static int get_exporter(struct transport *transport,\n \tfastexport->argv = xcalloc(6 + revlist_args->nr, sizeof(*fastexport->argv));\n \tfastexport->argv[argc++] = \"fast-export\";\n \tfastexport->argv[argc++] = \"--use-done-feature\";\n-\tfastexport->argv[argc++] = \"--signed-tags=warn-strip\";\n+\tfastexport->argv[argc++] = data->signed_tags ?\n+\t\t\"--signed-tags=verbatim\" : \"--signed-tags=warn-strip\";\n \tif (data->export_marks)\n \t\tfastexport->argv[argc++] = data->export_marks;\n \tif (data->import_marks)\n-- \n1.8.2.694.ga76e9c3.dirty\n"},{"id":"214428","messageId":"CAGdFq_jCO_+qj87rtcFyFG2tot8Ah2706X2dm82F6=GBV-g6nw@mail.gmail.com","threadId":"33416","inReplyTo":"8716b887972b0eb1671afd2692416efd588f7d1d.1365936811.git.john@keeping.me.uk","subject":"Re: [PATCH 1/3] fast-export: add --signed-tags=warn-strip mode","fromName":"Sverre Rabbelier","fromEmail":"srabbelier@gmail.com","sentAt":"2013-04-16T04:09:53Z","receivedAt":"2013-04-16T04:09:53Z","isPatch":true,"sender":{"key":"srabbelier@gmail.com","avatar":"https://avatars.githubusercontent.com/u/3098?v=4"},"body":"On Sun, Apr 14, 2013 at 3:57 AM, John Keeping <john@keeping.me.uk> wrote:\n> This issues a warning while stripping signatures from signed tags, which\n> allows us to use it as default behaviour for remote helpers which cannot\n> specify how to handle signed tags.\n\nPerhaps it makes sense to instead count the number of signed tags and\nemit \"Stripped signature from %d tags\"? For example, for git.git it\nwould be on the order of a hundred warning lines.\n\n--\nCheers,\n\nSverre Rabbelier\n"},{"id":"214434","messageId":"7vk3o3nktl.fsf@alter.siamese.dyndns.org","threadId":"33416","inReplyTo":"CAGdFq_jCO_+qj87rtcFyFG2tot8Ah2706X2dm82F6=GBV-g6nw@mail.gmail.com","subject":"Re: [PATCH 1/3] fast-export: add --signed-tags=warn-strip mode","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2013-04-16T04:47:18Z","receivedAt":"2013-04-16T04:47:18Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Sverre Rabbelier <srabbelier@gmail.com> writes:\n\n> On Sun, Apr 14, 2013 at 3:57 AM, John Keeping <john@keeping.me.uk> wrote:\n>> This issues a warning while stripping signatures from signed tags, which\n>> allows us to use it as default behaviour for remote helpers which cannot\n>> specify how to handle signed tags.\n>\n> Perhaps it makes sense to instead count the number of signed tags and\n> emit \"Stripped signature from %d tags\"? For example, for git.git it\n> would be on the order of a hundred warning lines.\n\nWhen you see 78 in the output and you know you have 92 tags in the\nrepository, is that sufficient to let you go on, or do we also need\nan easy way to tell which ones are those 78 that were stripped and\nthe remaining 14 were not stripped?\n\nThere is no reason to worry about \"some signed tags are stripped but\nnot others\", so it feels that the number alone should be sufficient,\nI guess.  If those remaining 14 weren't stripped, that is (at least\nat the moment) by definition because they are unsigned, annotated\ntags.\n"},{"id":"214435","messageId":"CAGdFq_gCeE8gRxmRYkGkm+kn6_Vo22_8g7+eLMuj-+pKjJjPcA@mail.gmail.com","threadId":"33416","inReplyTo":"7vk3o3nktl.fsf@alter.siamese.dyndns.org","subject":"Re: [PATCH 1/3] fast-export: add --signed-tags=warn-strip mode","fromName":"Sverre Rabbelier","fromEmail":"srabbelier@gmail.com","sentAt":"2013-04-16T04:50:42Z","receivedAt":"2013-04-16T04:50:42Z","isPatch":true,"sender":{"key":"srabbelier@gmail.com","avatar":"https://avatars.githubusercontent.com/u/3098?v=4"},"body":"On Mon, Apr 15, 2013 at 9:47 PM, Junio C Hamano <gitster@pobox.com> wrote:\n> When you see 78 in the output and you know you have 92 tags in the\n> repository, is that sufficient to let you go on, or do we also need\n> an easy way to tell which ones are those 78 that were stripped and\n> the remaining 14 were not stripped?\n>\n> There is no reason to worry about \"some signed tags are stripped but\n> not others\", so it feels that the number alone should be sufficient,\n> I guess.  If those remaining 14 weren't stripped, that is (at least\n> at the moment) by definition because they are unsigned, annotated\n> tags.\n\nOr because they were not exported? Perhaps \"78 tags stripped, 92\nexported in total\".\n\n--\nCheers,\n\nSverre Rabbelier\n"},{"id":"214439","messageId":"20130416053228.GB14567@elie.Belkin","threadId":"33416","inReplyTo":"7vk3o3nktl.fsf@alter.siamese.dyndns.org","subject":"Re: [PATCH 1/3] fast-export: add --signed-tags=warn-strip mode","fromName":"Jonathan Nieder","fromEmail":"jrnieder@gmail.com","sentAt":"2013-04-16T05:32:28Z","receivedAt":"2013-04-16T05:32:28Z","isPatch":true,"sender":{"key":"jrnieder@gmail.com","avatar":"https://avatars.githubusercontent.com/u/281595?v=4"},"body":"Junio C Hamano wrote:\n> Sverre Rabbelier <srabbelier@gmail.com> writes:\n\n>> Perhaps it makes sense to instead count the number of signed tags and\n>> emit \"Stripped signature from %d tags\"? For example, for git.git it\n>> would be on the order of a hundred warning lines.\n>\n> When you see 78 in the output and you know you have 92 tags in the\n> repository, is that sufficient to let you go on, or do we also need\n> an easy way to tell which ones are those 78 that were stripped and\n> the remaining 14 were not stripped?\n\nI suspect the actually relevant information is\n\n\twarning: stripping signature before pushing signed tags\n\nThe count and the list of signed tags are not too important.\n"},{"id":"214466","messageId":"20130416084252.GK2278@serenity.lan","threadId":"33416","inReplyTo":"CAGdFq_gCeE8gRxmRYkGkm+kn6_Vo22_8g7+eLMuj-+pKjJjPcA@mail.gmail.com","subject":"Re: [PATCH 1/3] fast-export: add --signed-tags=warn-strip mode","fromName":"John Keeping","fromEmail":"john@keeping.me.uk","sentAt":"2013-04-16T08:42:52Z","receivedAt":"2013-04-16T08:42:52Z","isPatch":true,"sender":{"key":"john@keeping.me.uk","avatar":"https://avatars.githubusercontent.com/u/1702081?v=4"},"body":"On Mon, Apr 15, 2013 at 09:50:42PM -0700, Sverre Rabbelier wrote:\n> On Mon, Apr 15, 2013 at 9:47 PM, Junio C Hamano <gitster@pobox.com> wrote:\n> > When you see 78 in the output and you know you have 92 tags in the\n> > repository, is that sufficient to let you go on, or do we also need\n> > an easy way to tell which ones are those 78 that were stripped and\n> > the remaining 14 were not stripped?\n> >\n> > There is no reason to worry about \"some signed tags are stripped but\n> > not others\", so it feels that the number alone should be sufficient,\n> > I guess.  If those remaining 14 weren't stripped, that is (at least\n> > at the moment) by definition because they are unsigned, annotated\n> > tags.\n> \n> Or because they were not exported? Perhaps \"78 tags stripped, 92\n> exported in total\".\n\nI think I prefer Jonathan's suggestion to this one if we need to change\nit.\n\nThe reason I didn't do this initially was that I assumed that from a\nremote helper we would, in general, not be pushing any tags which\nalready exist, so the number of tags to push will be small.\n\nPrinting one message per tag also matches the current behaviour for\n--signed-tags=warn.  I don't want to make the behaviour for \"warn\" and\n\"warn-strip\" different, so should \"warn\" also print a summary message\ninstead of a message for each tag?\n"},{"id":"214572","messageId":"7vtxn5hieo.fsf@alter.siamese.dyndns.org","threadId":"33416","inReplyTo":"20130416084252.GK2278@serenity.lan","subject":"Re: [PATCH 1/3] fast-export: add --signed-tags=warn-strip mode","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2013-04-17T04:48:15Z","receivedAt":"2013-04-17T04:48:15Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"John Keeping <john@keeping.me.uk> writes:\n\n> Printing one message per tag also matches the current behaviour for\n> --signed-tags=warn.  I don't want to make the behaviour for \"warn\" and\n> \"warn-strip\" different,...\n\nThat is a valid point. Nobody has complained that the current\nwarning is too noisy, so perhaps the patch is good as-is?\n\nWhat do others think?\n \n"},{"id":"214573","messageId":"CAGdFq_gx0W-TfLpVMbXHiZbDmMK49aUMubKmn08nF3U+AE5_RA@mail.gmail.com","threadId":"33416","inReplyTo":"7vtxn5hieo.fsf@alter.siamese.dyndns.org","subject":"Re: [PATCH 1/3] fast-export: add --signed-tags=warn-strip mode","fromName":"Sverre Rabbelier","fromEmail":"srabbelier@gmail.com","sentAt":"2013-04-17T05:02:21Z","receivedAt":"2013-04-17T05:02:21Z","isPatch":true,"sender":{"key":"srabbelier@gmail.com","avatar":"https://avatars.githubusercontent.com/u/3098?v=4"},"body":"On Tue, Apr 16, 2013 at 9:48 PM, Junio C Hamano <gitster@pobox.com> wrote:\n> That is a valid point. Nobody has complained that the current\n> warning is too noisy, so perhaps the patch is good as-is?\n\nAh, hadn't realized that. Probably fine then.\n\n--\nCheers,\n\nSverre Rabbelier\n"}]}