{"thread":{"id":"58028","subject":"send PGP signed commits/patches with git-send-email(1)","startedAt":"2022-06-17T10:24:37Z","lastAt":"2022-06-21T11:48:07Z","messageCount":7,"participants":["Alejandro Colomar","Fabian Stelzer","Konstantin Ryabitsev","Greg KH"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"457450","messageId":"81caab7d-777e-13fe-89ea-820b7b2f0314@gmail.com","threadId":"58028","inReplyTo":null,"subject":"send PGP signed commits/patches with git-send-email(1)","fromName":"Alejandro Colomar","fromEmail":"alx.manpages@gmail.com","sentAt":"2022-06-17T10:24:21Z","receivedAt":"2022-06-17T10:24:37Z","isPatch":false,"sender":{"key":"alx.manpages@gmail.com","avatar":null},"body":"Hi,\n\nIn Kernel Recipes this month [1], Greg mentioned that git-send-email(1) \ncould be used together with gpg(1) to verify authenticity of the sender.\n\nI couldn't find any documentation about it, and if I create a patch from \na commit that was signed (-S), the PGP signature is not part of the patch.\n\nSo, is there a way to PGP-authenticate patches?\nIf not, could this be added to git(1)?\n\n$ git --version\ngit version 2.36.1\n\nThanks,\n\nAlex\n\n\n[1]: <https://www.youtube.com/watch?v=nhJqaZT94z0>\n\n      - Start of thread Q&A in 1:56:30.\n      - Greg's answer starts in 1:56:57\n      - Specific git-send-email(1) part in 1:57:50\n\n-- \nAlejandro Colomar\n<http://www.alejandro-colomar.es/>\n"},{"id":"457451","messageId":"20220617120016.txjksectzdugqiod@fs","threadId":"58028","inReplyTo":"81caab7d-777e-13fe-89ea-820b7b2f0314@gmail.com","subject":"Re: send PGP signed commits/patches with git-send-email(1)","fromName":"Fabian Stelzer","fromEmail":"fs@gigacodes.de","sentAt":"2022-06-17T12:00:16Z","receivedAt":"2022-06-17T12:00:25Z","isPatch":false,"sender":{"key":"fs@gigacodes.de","avatar":"https://avatars.githubusercontent.com/u/564858?v=4"},"body":"On 17.06.2022 12:24, Alejandro Colomar wrote:\n>Hi,\n>\n>In Kernel Recipes this month [1], Greg mentioned that \n>git-send-email(1) could be used together with gpg(1) to verify \n>authenticity of the sender.\n\nI think he is talking about GPG signing the email containing the patch and \nis not referring to git commit signing.\nUsing GPG to sign your whole email adds trust to a whole lot more than just \nthe sent patch. It can verify the authenticity of the sender, and all the \nrest of the emails content and follow up discussions / review.\n\nIncluding the commits signature in the email might have some benefit but I'm \nnot sure about how much. It could decouple the trust of the patches \nintegrity of the transport used to publish it. For example you could forward \n/ copy a patch and the recipient could still verify the original authors \nsignature.\n\nKonstantin Ryabitsev has done some work in this area especially for kernel \ndevelopment by using email headers:  \nhttps://people.kernel.org/monsieuricon/end-to-end-patch-attestation-with-patatt-and-b4\nhttps://github.com/mricon/patatt\n\n>\n>I couldn't find any documentation about it, and if I create a patch \n>from a commit that was signed (-S), the PGP signature is not part of \n>the patch.\n>\n>So, is there a way to PGP-authenticate patches?\n>If not, could this be added to git(1)?\n>\n>$ git --version\n>git version 2.36.1\n>\n>Thanks,\n>\n>Alex\n>\n>\n>[1]: <https://www.youtube.com/watch?v=nhJqaZT94z0>\n>\n>     - Start of thread Q&A in 1:56:30.\n>     - Greg's answer starts in 1:56:57\n>     - Specific git-send-email(1) part in 1:57:50\n>\n>-- \n>Alejandro Colomar\n><http://www.alejandro-colomar.es/>\n\n\n\n"},{"id":"457452","messageId":"20220617121212.g7w7v3v4ynw6wlq7@meerkat.local","threadId":"58028","inReplyTo":"20220617120016.txjksectzdugqiod@fs","subject":"Re: send PGP signed commits/patches with git-send-email(1)","fromName":"Konstantin Ryabitsev","fromEmail":"konstantin@linuxfoundation.org","sentAt":"2022-06-17T12:12:12Z","receivedAt":"2022-06-17T12:12:18Z","isPatch":false,"sender":{"key":"konstantin@linuxfoundation.org","avatar":"https://gravatar.com/avatar/7cb8827c6de56e1bd2dea16508c6708aa43feed3bf3813bcdacecdf96ceadd79?d=mp&s=160"},"body":"On Fri, Jun 17, 2022 at 02:00:16PM +0200, Fabian Stelzer wrote:\n> Konstantin Ryabitsev has done some work in this area especially for kernel\n> development by using email headers:\n> https://people.kernel.org/monsieuricon/end-to-end-patch-attestation-with-patatt-and-b4\n> https://github.com/mricon/patatt\n\nGreg refers specifically to patatt signatures. They aren't really specific to\nkernel development at all -- they can be used for any patches sent via mail.\n\nb4 (the tool used by many maintainers to retrieve patches from lists) will\ncheck patatt-style signatures (in addition to DKIM signatures) to help verify\nthat the patches come from trusted sources and aren't someone pretending to be\nsomeone else.\n\n-K\n"},{"id":"457602","messageId":"YrGoqEi3shil7pkM@kroah.com","threadId":"58028","inReplyTo":"20220617121212.g7w7v3v4ynw6wlq7@meerkat.local","subject":"Re: send PGP signed commits/patches with git-send-email(1)","fromName":"Greg KH","fromEmail":"gregkh@linuxfoundation.org","sentAt":"2022-06-21T11:16:56Z","receivedAt":"2022-06-21T11:17:08Z","isPatch":false,"sender":{"key":"gregkh@linuxfoundation.org","avatar":"https://gravatar.com/avatar/e6d9136f6e3bdcb59f0e5fd15565f382da42523d273824958b9e23e73cf38e04?d=mp&s=160"},"body":"On Fri, Jun 17, 2022 at 08:12:12AM -0400, Konstantin Ryabitsev wrote:\n> On Fri, Jun 17, 2022 at 02:00:16PM +0200, Fabian Stelzer wrote:\n> > Konstantin Ryabitsev has done some work in this area especially for kernel\n> > development by using email headers:\n> > https://people.kernel.org/monsieuricon/end-to-end-patch-attestation-with-patatt-and-b4\n> > https://github.com/mricon/patatt\n> \n> Greg refers specifically to patatt signatures. They aren't really specific to\n> kernel development at all -- they can be used for any patches sent via mail.\n> \n> b4 (the tool used by many maintainers to retrieve patches from lists) will\n> check patatt-style signatures (in addition to DKIM signatures) to help verify\n> that the patches come from trusted sources and aren't someone pretending to be\n> someone else.\n\nYes, I was referring to patatt here, as linked by Konstantin's blog post\nabove.  It's part of the b4 tool (well, a git subproject in it), real\nlink is at:\n\thttps://git.kernel.org/pub/scm/utils/patatt/patatt.git\n\nthanks,\n\ngreg k-h\n"},{"id":"457603","messageId":"03af9a8e-cf2c-8a32-330d-debad956683d@gmail.com","threadId":"58028","inReplyTo":"YrGoqEi3shil7pkM@kroah.com","subject":"Re: send PGP signed commits/patches with git-send-email(1)","fromName":"Alejandro Colomar","fromEmail":"alx.manpages@gmail.com","sentAt":"2022-06-21T11:34:01Z","receivedAt":"2022-06-21T11:34:15Z","isPatch":false,"sender":{"key":"alx.manpages@gmail.com","avatar":null},"body":"Hi!\n\nOn 6/21/22 13:16, Greg KH wrote:\n> On Fri, Jun 17, 2022 at 08:12:12AM -0400, Konstantin Ryabitsev wrote:\n>> On Fri, Jun 17, 2022 at 02:00:16PM +0200, Fabian Stelzer wrote:\n>>> Konstantin Ryabitsev has done some work in this area especially for kernel\n>>> development by using email headers:\n>>> https://people.kernel.org/monsieuricon/end-to-end-patch-attestation-with-patatt-and-b4\n>>> https://github.com/mricon/patatt\n>>\n>> Greg refers specifically to patatt signatures. They aren't really specific to\n>> kernel development at all -- they can be used for any patches sent via mail.\n>>\n>> b4 (the tool used by many maintainers to retrieve patches from lists) will\n>> check patatt-style signatures (in addition to DKIM signatures) to help verify\n>> that the patches come from trusted sources and aren't someone pretending to be\n>> someone else.\n> \n> Yes, I was referring to patatt here, as linked by Konstantin's blog post\n> above.  It's part of the b4 tool (well, a git subproject in it), real\n> link is at:\n> \thttps://git.kernel.org/pub/scm/utils/patatt/patatt.git\n\nThank you all for the info.\nIt works like charm (I still need to learn b4(1), but patatt(1) is \nenough for me right now). :)\n\nCheers,\n\nAlex\n\n-- \nAlejandro Colomar\n<http://www.alejandro-colomar.es/>\n"},{"id":"457604","messageId":"YrGvQi8kiFf4a/Tk@kroah.com","threadId":"58028","inReplyTo":"03af9a8e-cf2c-8a32-330d-debad956683d@gmail.com","subject":"Re: send PGP signed commits/patches with git-send-email(1)","fromName":"Greg KH","fromEmail":"gregkh@linuxfoundation.org","sentAt":"2022-06-21T11:45:06Z","receivedAt":"2022-06-21T11:45:18Z","isPatch":false,"sender":{"key":"gregkh@linuxfoundation.org","avatar":"https://gravatar.com/avatar/e6d9136f6e3bdcb59f0e5fd15565f382da42523d273824958b9e23e73cf38e04?d=mp&s=160"},"body":"On Tue, Jun 21, 2022 at 01:34:01PM +0200, Alejandro Colomar wrote:\n> Hi!\n> \n> On 6/21/22 13:16, Greg KH wrote:\n> > On Fri, Jun 17, 2022 at 08:12:12AM -0400, Konstantin Ryabitsev wrote:\n> > > On Fri, Jun 17, 2022 at 02:00:16PM +0200, Fabian Stelzer wrote:\n> > > > Konstantin Ryabitsev has done some work in this area especially for kernel\n> > > > development by using email headers:\n> > > > https://people.kernel.org/monsieuricon/end-to-end-patch-attestation-with-patatt-and-b4\n> > > > https://github.com/mricon/patatt\n> > > \n> > > Greg refers specifically to patatt signatures. They aren't really specific to\n> > > kernel development at all -- they can be used for any patches sent via mail.\n> > > \n> > > b4 (the tool used by many maintainers to retrieve patches from lists) will\n> > > check patatt-style signatures (in addition to DKIM signatures) to help verify\n> > > that the patches come from trusted sources and aren't someone pretending to be\n> > > someone else.\n> > \n> > Yes, I was referring to patatt here, as linked by Konstantin's blog post\n> > above.  It's part of the b4 tool (well, a git subproject in it), real\n> > link is at:\n> > \thttps://git.kernel.org/pub/scm/utils/patatt/patatt.git\n> \n> Thank you all for the info.\n> It works like charm (I still need to learn b4(1), but patatt(1) is enough\n> for me right now). :)\n\nThey are independent, patatt I use when sending patches, b4 I use when\naccepting patches.  If you never have to accept patches, and read the\nmailing lists using the normal way, no need to use b4.\n\nthanks,\n\ngreg k-h\n"},{"id":"457605","messageId":"dd666e99-b0f6-a05a-532d-13bb3428e8b6@gmail.com","threadId":"58028","inReplyTo":"YrGvQi8kiFf4a/Tk@kroah.com","subject":"Re: send PGP signed commits/patches with git-send-email(1)","fromName":"Alejandro Colomar","fromEmail":"alx.manpages@gmail.com","sentAt":"2022-06-21T11:47:41Z","receivedAt":"2022-06-21T11:48:07Z","isPatch":false,"sender":{"key":"alx.manpages@gmail.com","avatar":null},"body":"Hi Greg,\n\nOn 6/21/22 13:45, Greg KH wrote:\n> On Tue, Jun 21, 2022 at 01:34:01PM +0200, Alejandro Colomar wrote:\n>> Hi!\n>>\n>> On 6/21/22 13:16, Greg KH wrote:\n>>> On Fri, Jun 17, 2022 at 08:12:12AM -0400, Konstantin Ryabitsev wrote:\n>>>> On Fri, Jun 17, 2022 at 02:00:16PM +0200, Fabian Stelzer wrote:\n>>>>> Konstantin Ryabitsev has done some work in this area especially for kernel\n>>>>> development by using email headers:\n>>>>> https://people.kernel.org/monsieuricon/end-to-end-patch-attestation-with-patatt-and-b4\n>>>>> https://github.com/mricon/patatt\n>>>>\n>>>> Greg refers specifically to patatt signatures. They aren't really specific to\n>>>> kernel development at all -- they can be used for any patches sent via mail.\n>>>>\n>>>> b4 (the tool used by many maintainers to retrieve patches from lists) will\n>>>> check patatt-style signatures (in addition to DKIM signatures) to help verify\n>>>> that the patches come from trusted sources and aren't someone pretending to be\n>>>> someone else.\n>>>\n>>> Yes, I was referring to patatt here, as linked by Konstantin's blog post\n>>> above.  It's part of the b4 tool (well, a git subproject in it), real\n>>> link is at:\n>>> \thttps://git.kernel.org/pub/scm/utils/patatt/patatt.git\n>>\n>> Thank you all for the info.\n>> It works like charm (I still need to learn b4(1), but patatt(1) is enough\n>> for me right now). :)\n> \n> They are independent, patatt I use when sending patches, b4 I use when\n> accepting patches.  If you never have to accept patches, and read the\n> mailing lists using the normal way, no need to use b4.\n\nOh, I do need to accept patches, for the man-pages :)\nBut for now, the traffic isn't so high as to need to learn b4(1).\nBut yes, I would like to learn a bit more about it to simplify some things.\n\nCheers,\n\nAlex\n\n\n-- \nAlejandro Colomar\n<http://www.alejandro-colomar.es/>\n"}]}