{"thread":{"id":"53649","subject":"GPG Commit Signing Project","startedAt":"2020-06-10T18:09:49Z","lastAt":"2020-06-12T17:03:44Z","messageCount":5,"participants":["Jimit Bhalavat","Junio C Hamano","dwh@linuxprogrammer.org","brian m. carlson"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"399431","messageId":"E7E8DC8B-BB7D-42E1-BD0E-EF59775B9E75@rams.colostate.edu","threadId":"53649","inReplyTo":null,"subject":"GPG Commit Signing Project","fromName":"Jimit Bhalavat","fromEmail":"jimit@rams.colostate.edu","sentAt":"2020-06-10T18:06:07Z","receivedAt":"2020-06-10T18:09:49Z","isPatch":false,"sender":{"key":"jimit@rams.colostate.edu","avatar":null},"body":"Good Afternoon, \n\nI am Jimit Bhalavat, and I am a Junior at Colorado State University and my major is Computer Science. Recently, I accepted to work on Hyperledger Git Commit Signing Project through The Linux Foundation and my mentor is David Huseby. I am writing to you in order to ask you if you are the maintainer for the GPG Signing Project? \n\nWhich branches are for refactoring/new features in the GPG Commit Signing Project?\n\nThank you so much. Have a great rest of your day.\n\nBest,\nJimit Bhalavat."},{"id":"399437","messageId":"xmqq1rmmg1ds.fsf@gitster.c.googlers.com","threadId":"53649","inReplyTo":"E7E8DC8B-BB7D-42E1-BD0E-EF59775B9E75@rams.colostate.edu","subject":"Re: GPG Commit Signing Project","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2020-06-10T19:35:27Z","receivedAt":"2020-06-10T19:35:37Z","isPatch":false,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Jimit Bhalavat <jimit@rams.colostate.edu> writes:\n\n> I am Jimit Bhalavat, and I am a Junior at Colorado State\n> University and my major is Computer Science. Recently, I accepted\n> to work on Hyperledger Git Commit Signing Project through The\n> Linux Foundation and my mentor is David Huseby. I am writing to\n> you in order to ask you if you are the maintainer for the GPG\n> Signing Project?\n>\n> Which branches are for refactoring/new features in the GPG Commit\n> Signing Project?\n\nThe fact that I know almost nothing about \"Hyperledger Git Commit\nSigning Project\" (other than the search term returns some hits from\nthe search engines [*1*]) makes me suspect that whatever branch I\ncontrol is not suitable to contribute to that project, which does\nnot have much to do with the Git project, where this mailing list is\nits home for.  Perhaps ask your mentor first?\n\n\n[Reference]\n\n*1* https://wiki.hyperledger.org/display/INTERN/Git+signing+with+DIDs\n"},{"id":"399573","messageId":"20200612015556.4kvsfcwabuaxuiuc@dev","threadId":"53649","inReplyTo":"xmqq1rmmg1ds.fsf@gitster.c.googlers.com","subject":"Re: GPG Commit Signing Project","fromName":"","fromEmail":"dwh@linuxprogrammer.org","sentAt":"2020-06-12T01:55:56Z","receivedAt":"2020-06-12T01:56:01Z","isPatch":false,"sender":{"key":"dwh@linuxprogrammer.org","avatar":null},"body":"On 10.06.2020 12:35, Junio C Hamano wrote:\n>The fact that I know almost nothing about \"Hyperledger Git Commit\n>Signing Project\" (other than the search term returns some hits from\n>the search engines [*1*]) makes me suspect that whatever branch I\n>control is not suitable to contribute to that project, which does\n>not have much to do with the Git project, where this mailing list is\n>its home for.  Perhaps ask your mentor first?\n\nHello Junio,\n\nI thought I should jump in here and introduce myself and give Jimit\na little help. My name is Dave Huseby and I'm Jimit's mentor. I'm also\nthe Security Maven for the Hyperledger Project. Jimit was selected for\nour Summer 2020 mentorship project to work on our ongoing efforts to\nsupport alternative signing tools in Git. Last summer a series of\npatches were submitted by Ibrahim and it was not accepted, although\nwe did get some good feedback.\n\nThe feedback from the Git community was that the refactor of the\nsigning system organized the signing-tool-specific C code into\n\"drivers\" for each signing tool instead of being configuration based.\nSee Brian's comment here:\n\nhttps://public-inbox.org/git/20190826231543.GD11334@genre.crustytoothpaste.net/\n\nIbrahim's mentorship ended with him sending a new proposal for a config\nbased approach to solve this problem here:\n\nhttps://public-inbox.org/git/R3X1WzWH0sgOh85GuUmXwsTC6CPKysi4TRzN_BPecDVGr__ET2-mitZ2DZA0_bpKkzLRtnTtoomIWxZtL52_1XkihYBVBAuWMpSdwoboixY=@pm.me/T/#u\n\nI now think even that proposal is overly complicated. I think the\neasiest solution is to simply standardize the existing pipe-fork\ninterface as the way GPG talks to all signing tools. For signing tools\nthat have different command line interfaces than GPG, we can create\nadapter scripts. Tools that want to be compatible can adapt.\n\nI'll outline a new proposal in a follow up email.\n\nCheers!\nDave\n"},{"id":"399574","messageId":"20200612022407.GC6569@camp.crustytoothpaste.net","threadId":"53649","inReplyTo":"20200612015556.4kvsfcwabuaxuiuc@dev","subject":"Re: GPG Commit Signing Project","fromName":"brian m. carlson","fromEmail":"sandals@crustytoothpaste.net","sentAt":"2020-06-12T02:24:07Z","receivedAt":"2020-06-12T02:24:15Z","isPatch":false,"sender":{"key":"sandals@crustytoothpaste.net","avatar":"https://avatars.githubusercontent.com/u/497054?v=4"},"body":"On 2020-06-12 at 01:55:56, dwh@linuxprogrammer.org wrote:\n> I now think even that proposal is overly complicated. I think the\n> easiest solution is to simply standardize the existing pipe-fork\n> interface as the way GPG talks to all signing tools. For signing tools\n> that have different command line interfaces than GPG, we can create\n> adapter scripts. Tools that want to be compatible can adapt.\n\nThis becomes pretty tricky because Git parses OpenPGP headers in a\nvariety of places (e.g., at the end of tags).  If your proposal is to\nwrap new formats in a fake OpenPGP format, like some existing tools do,\nthen that would be viable, but otherwise you're going to require either\nGit to know about your signing format specifically (which is not a\nsustainable approach) or some sort of configuration framework like has\nbeen previously discussed.\n\nIf you're going to wrap things in a fake OpenPGP format, then you don't\nactually need to send any patches to Git at all; you can simply set\ngpg.program and continue.\n-- \nbrian m. carlson: Houston, Texas, US\nOpenPGP: https://keybase.io/bk2204\n"},{"id":"399608","messageId":"xmqqd0642p3q.fsf@gitster.c.googlers.com","threadId":"53649","inReplyTo":"20200612022407.GC6569@camp.crustytoothpaste.net","subject":"Re: GPG Commit Signing Project","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2020-06-12T17:03:37Z","receivedAt":"2020-06-12T17:03:44Z","isPatch":false,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"\"brian m. carlson\" <sandals@crustytoothpaste.net> writes:\n\n> On 2020-06-12 at 01:55:56, dwh@linuxprogrammer.org wrote:\n>> I now think even that proposal is overly complicated. I think the\n>> easiest solution is to simply standardize the existing pipe-fork\n>> interface as the way GPG talks to all signing tools. For signing tools\n>> that have different command line interfaces than GPG, we can create\n>> adapter scripts. Tools that want to be compatible can adapt.\n>\n> This becomes pretty tricky because Git parses OpenPGP headers in a\n> variety of places (e.g., at the end of tags).  If your proposal is to\n> wrap new formats in a fake OpenPGP format, like some existing tools do,\n> then that would be viable, but otherwise you're going to require either\n> Git to know about your signing format specifically (which is not a\n> sustainable approach) or some sort of configuration framework like has\n> been previously discussed.\n>\n> If you're going to wrap things in a fake OpenPGP format, then you don't\n> actually need to send any patches to Git at all; you can simply set\n> gpg.program and continue.\n\nTrue enough ;-)  Thanks for a concise summary of the situation.\n\n"}]}