{"thread":{"id":"59150","subject":"[PATCH] request-pull: filter out SSH/X.509 tag signatures","startedAt":"2023-01-25T23:11:23Z","lastAt":"2023-01-26T00:18:35Z","messageCount":5,"participants":["Gwyneth Morgan","Junio C Hamano"],"isPatch":true,"patchVersion":1,"patchTotal":null},"messages":[{"id":"471036","messageId":"20230125230117.3915827-1-gwymor@tilde.club","threadId":"59150","inReplyTo":null,"subject":"[PATCH] request-pull: filter out SSH/X.509 tag signatures","fromName":"Gwyneth Morgan","fromEmail":"gwymor@tilde.club","sentAt":"2023-01-25T23:01:17Z","receivedAt":"2023-01-25T23:11:23Z","isPatch":true,"sender":{"key":"gwymor@tilde.club","avatar":"https://avatars.githubusercontent.com/u/87623694?v=4"},"body":"git request-pull filters PGP signatures out of the tag message, but not\nSSH or X.509 signatures.\n---\n git-request-pull.sh | 2 +-\n 1 file changed, 1 insertion(+), 1 deletion(-)\n\ndiff --git a/git-request-pull.sh b/git-request-pull.sh\nindex 2d0e44656c..01640a044b 100755\n--- a/git-request-pull.sh\n+++ b/git-request-pull.sh\n@@ -153,7 +153,7 @@ for you to fetch changes up to %H:\n if test $(git cat-file -t \"$head\") = tag\n then\n \tgit cat-file tag \"$head\" |\n-\tsed -n -e '1,/^$/d' -e '/^-----BEGIN PGP /q' -e p\n+\tsed -n -e '1,/^$/d' -e '/^-----BEGIN \\(PGP\\|SSH\\|SIGNED\\) /q' -e p\n \techo\n \techo \"----------------------------------------------------------------\"\n fi &&\n"},{"id":"471037","messageId":"xmqq8rhqdwxl.fsf@gitster.g","threadId":"59150","inReplyTo":"20230125230117.3915827-1-gwymor@tilde.club","subject":"Re: [PATCH] request-pull: filter out SSH/X.509 tag signatures","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2023-01-25T23:19:34Z","receivedAt":"2023-01-25T23:19:38Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Gwyneth Morgan <gwymor@tilde.club> writes:\n\n> git request-pull filters PGP signatures out of the tag message, but not\n> SSH or X.509 signatures.\n> ---\n\nPlease sign-off your contribution. \ncf.  Documentation/SubmittingPatches[[sign-off]]\n\n>  git-request-pull.sh | 2 +-\n>  1 file changed, 1 insertion(+), 1 deletion(-)\n>\n> diff --git a/git-request-pull.sh b/git-request-pull.sh\n> index 2d0e44656c..01640a044b 100755\n> --- a/git-request-pull.sh\n> +++ b/git-request-pull.sh\n> @@ -153,7 +153,7 @@ for you to fetch changes up to %H:\n>  if test $(git cat-file -t \"$head\") = tag\n>  then\n>  \tgit cat-file tag \"$head\" |\n> -\tsed -n -e '1,/^$/d' -e '/^-----BEGIN PGP /q' -e p\n> +\tsed -n -e '1,/^$/d' -e '/^-----BEGIN \\(PGP\\|SSH\\|SIGNED\\) /q' -e p\n\nThis makes readers debate themselves if being more specific and\nnarrow like the posted patch is safer and better, or making it\nlooser by just requiring \"^-----BEGIN \" and making it forward\nlooking is sufficient and maintainable.\n\nIf this were signed-off already, I would have said \"let's queue it\nas-is, while waiting for input from others\", but without a sign-off\nI am not queuing (yet).\n\nThanks.\n"},{"id":"471038","messageId":"Y9G+/e5ghEsO3hIb@tilde.club","threadId":"59150","inReplyTo":"xmqq8rhqdwxl.fsf@gitster.g","subject":"Re: [PATCH] request-pull: filter out SSH/X.509 tag signatures","fromName":"Gwyneth Morgan","fromEmail":"gwymor@tilde.club","sentAt":"2023-01-25T23:45:25Z","receivedAt":"2023-01-25T23:45:51Z","isPatch":true,"sender":{"key":"gwymor@tilde.club","avatar":"https://avatars.githubusercontent.com/u/87623694?v=4"},"body":"On 2023-01-25 15:19:34-0800, Junio C Hamano wrote:\n> Please sign-off your contribution. \n> cf.  Documentation/SubmittingPatches[[sign-off]]\n\nOops! I will resend with a sign-off.\n\n> >  git-request-pull.sh | 2 +-\n> >  1 file changed, 1 insertion(+), 1 deletion(-)\n> >\n> > diff --git a/git-request-pull.sh b/git-request-pull.sh\n> > index 2d0e44656c..01640a044b 100755\n> > --- a/git-request-pull.sh\n> > +++ b/git-request-pull.sh\n> > @@ -153,7 +153,7 @@ for you to fetch changes up to %H:\n> >  if test $(git cat-file -t \"$head\") = tag\n> >  then\n> >  \tgit cat-file tag \"$head\" |\n> > -\tsed -n -e '1,/^$/d' -e '/^-----BEGIN PGP /q' -e p\n> > +\tsed -n -e '1,/^$/d' -e '/^-----BEGIN \\(PGP\\|SSH\\|SIGNED\\) /q' -e p\n> \n> This makes readers debate themselves if being more specific and\n> narrow like the posted patch is safer and better, or making it\n> looser by just requiring \"^-----BEGIN \" and making it forward\n> looking is sufficient and maintainable.\n\nI could imagine someone having a tag with a line starting that way (not\nrealizing it's a common pattern for signatures to take) and being\nconfused at why it's being removed. The likelihood of someone doing\nthat, and using request-pull with that tag, is pretty low though, so I\ndon't have a strong preference.\n"},{"id":"471039","messageId":"20230125234725.3918563-1-gwymor@tilde.club","threadId":"59150","inReplyTo":"20230125230117.3915827-1-gwymor@tilde.club","subject":"[PATCH v2] request-pull: filter out SSH/X.509 tag signatures","fromName":"Gwyneth Morgan","fromEmail":"gwymor@tilde.club","sentAt":"2023-01-25T23:47:27Z","receivedAt":"2023-01-25T23:48:57Z","isPatch":true,"sender":{"key":"gwymor@tilde.club","avatar":"https://avatars.githubusercontent.com/u/87623694?v=4"},"body":"git request-pull filters PGP signatures out of the tag message, but not\nSSH or X.509 signatures.\n\nSigned-off-by: Gwyneth Morgan <gwymor@tilde.club>\n---\n git-request-pull.sh | 2 +-\n 1 file changed, 1 insertion(+), 1 deletion(-)\n\ndiff --git a/git-request-pull.sh b/git-request-pull.sh\nindex 2d0e44656c..01640a044b 100755\n--- a/git-request-pull.sh\n+++ b/git-request-pull.sh\n@@ -153,7 +153,7 @@ for you to fetch changes up to %H:\n if test $(git cat-file -t \"$head\") = tag\n then\n \tgit cat-file tag \"$head\" |\n-\tsed -n -e '1,/^$/d' -e '/^-----BEGIN PGP /q' -e p\n+\tsed -n -e '1,/^$/d' -e '/^-----BEGIN \\(PGP\\|SSH\\|SIGNED\\) /q' -e p\n \techo\n \techo \"----------------------------------------------------------------\"\n fi &&\n"},{"id":"471040","messageId":"xmqq4jsedu7c.fsf@gitster.g","threadId":"59150","inReplyTo":"20230125234725.3918563-1-gwymor@tilde.club","subject":"Re: [PATCH v2] request-pull: filter out SSH/X.509 tag signatures","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2023-01-26T00:18:31Z","receivedAt":"2023-01-26T00:18:35Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Gwyneth Morgan <gwymor@tilde.club> writes:\n\n> git request-pull filters PGP signatures out of the tag message, but not\n> SSH or X.509 signatures.\n>\n> Signed-off-by: Gwyneth Morgan <gwymor@tilde.club>\n> ---\n>  git-request-pull.sh | 2 +-\n>  1 file changed, 1 insertion(+), 1 deletion(-)\n>\n> diff --git a/git-request-pull.sh b/git-request-pull.sh\n> index 2d0e44656c..01640a044b 100755\n> --- a/git-request-pull.sh\n> +++ b/git-request-pull.sh\n> @@ -153,7 +153,7 @@ for you to fetch changes up to %H:\n>  if test $(git cat-file -t \"$head\") = tag\n>  then\n>  \tgit cat-file tag \"$head\" |\n> -\tsed -n -e '1,/^$/d' -e '/^-----BEGIN PGP /q' -e p\n> +\tsed -n -e '1,/^$/d' -e '/^-----BEGIN \\(PGP\\|SSH\\|SIGNED\\) /q' -e p\n>  \techo\n>  \techo \"----------------------------------------------------------------\"\n>  fi &&\n\nThanks, queued.\n"}]}