{"thread":{"id":"62665","subject":"OK to submit l10n PR with signed commits?","startedAt":"2024-12-18T10:08:39Z","lastAt":"2024-12-19T14:47:00Z","messageCount":6,"participants":["Bagas Sanjaya","Junio C Hamano"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"509282","messageId":"Z2KfIl87JOWdcGR3@archie.me","threadId":"62665","inReplyTo":null,"subject":"OK to submit l10n PR with signed commits?","fromName":"Bagas Sanjaya","fromEmail":"bagasdotme@gmail.com","sentAt":"2024-12-18T10:08:34Z","receivedAt":"2024-12-18T10:08:39Z","isPatch":false,"sender":{"key":"bagasdotme@gmail.com","avatar":"https://avatars.githubusercontent.com/u/40219486?v=4"},"body":"Hi,\n\nSo I'm interested in GPG-sign my commits (that is, ``git commit -S``) for l10n\npull request (which I should submit in this cycle). Is it OK to do that?\nDrawbacks?\n\nThanks.\n\n-- \nAn old man doll... just what I always wanted! - Clara\n"},{"id":"509296","messageId":"xmqqzfktujuk.fsf@gitster.g","threadId":"62665","inReplyTo":"Z2KfIl87JOWdcGR3@archie.me","subject":"Re: OK to submit l10n PR with signed commits?","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2024-12-18T14:49:39Z","receivedAt":"2024-12-18T14:49:42Z","isPatch":false,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Bagas Sanjaya <bagasdotme@gmail.com> writes:\n\n> So I'm interested in GPG-sign my commits (that is, ``git commit -S``) for l10n\n> pull request (which I should submit in this cycle). Is it OK to do that?\n> Drawbacks?\n\nInstead of talking first about drawbacks, we should consider the\nupsides.  Why would we even want to see your GPG signature, when\nmost of us do not even have your GPG public key in our keychains?\n\nWhat are we trying to achieve by doing this?\n"},{"id":"509319","messageId":"Z2OAebI4pQ2K57vA@archie.me","threadId":"62665","inReplyTo":"xmqqzfktujuk.fsf@gitster.g","subject":"Re: OK to submit l10n PR with signed commits?","fromName":"Bagas Sanjaya","fromEmail":"bagasdotme@gmail.com","sentAt":"2024-12-19T02:10:01Z","receivedAt":"2024-12-19T02:10:07Z","isPatch":false,"sender":{"key":"bagasdotme@gmail.com","avatar":"https://avatars.githubusercontent.com/u/40219486?v=4"},"body":"On Wed, Dec 18, 2024 at 06:49:39AM -0800, Junio C Hamano wrote:\n> Bagas Sanjaya <bagasdotme@gmail.com> writes:\n> \n> > So I'm interested in GPG-sign my commits (that is, ``git commit -S``) for l10n\n> > pull request (which I should submit in this cycle). Is it OK to do that?\n> > Drawbacks?\n> \n> Instead of talking first about drawbacks, we should consider the\n> upsides.  Why would we even want to see your GPG signature, when\n> most of us do not even have your GPG public key in our keychains?\n> \n> What are we trying to achieve by doing this?\n\nJust to ensure that PR commits are really from the respective authors.\n\n-- \nAn old man doll... just what I always wanted! - Clara\n"},{"id":"509327","messageId":"xmqqh670nrb9.fsf@gitster.g","threadId":"62665","inReplyTo":"Z2OAebI4pQ2K57vA@archie.me","subject":"Re: OK to submit l10n PR with signed commits?","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2024-12-19T06:02:34Z","receivedAt":"2024-12-19T06:02:37Z","isPatch":false,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Bagas Sanjaya <bagasdotme@gmail.com> writes:\n\n> On Wed, Dec 18, 2024 at 06:49:39AM -0800, Junio C Hamano wrote:\n>> Bagas Sanjaya <bagasdotme@gmail.com> writes:\n>> \n>> > So I'm interested in GPG-sign my commits (that is, ``git commit -S``) for l10n\n>> > pull request (which I should submit in this cycle). Is it OK to do that?\n>> > Drawbacks?\n>> \n>> Instead of talking first about drawbacks, we should consider the\n>> upsides.  Why would we even want to see your GPG signature, when\n>> most of us do not even have your GPG public key in our keychains?\n>> \n>> What are we trying to achieve by doing this?\n>\n> Just to ensure that PR commits are really from the respective authors.\n\nYeah, but my point was that it would not ensure, because practically\nnobody has ways to validate the signature was created with your\nprivate key, and public keyservers have been tainted long time ago\nwith fake keys with the same fingerprint, so would not work as a\ngood way to obtain your public key and be sure it is yours.\n\nIf this were \"because we would want to eat our own dogfood\", and if\nwe find bugs in our code when different person sign their commit\nwith their own signature scheme (i.e. you may sign yours with your\nGPG key, somebody else may use their SSH key, and yet other people\nuse their X.509 certs, it might give us valuable insights, but the\nresulting history may be irrevocably tainted if the bug is on the\nsigning side (if the bug is on the verification side, that is OK).\n\nThanks.\n"},{"id":"509333","messageId":"Z2QJ6CEbHyOObeEl@archie.me","threadId":"62665","inReplyTo":"xmqqh670nrb9.fsf@gitster.g","subject":"Re: OK to submit l10n PR with signed commits?","fromName":"Bagas Sanjaya","fromEmail":"bagasdotme@gmail.com","sentAt":"2024-12-19T11:56:24Z","receivedAt":"2024-12-19T11:56:29Z","isPatch":false,"sender":{"key":"bagasdotme@gmail.com","avatar":"https://avatars.githubusercontent.com/u/40219486?v=4"},"body":"On Wed, Dec 18, 2024 at 10:02:34PM -0800, Junio C Hamano wrote:\n> Bagas Sanjaya <bagasdotme@gmail.com> writes:\n> \n> > On Wed, Dec 18, 2024 at 06:49:39AM -0800, Junio C Hamano wrote:\n> >> Bagas Sanjaya <bagasdotme@gmail.com> writes:\n> >> \n> >> > So I'm interested in GPG-sign my commits (that is, ``git commit -S``) for l10n\n> >> > pull request (which I should submit in this cycle). Is it OK to do that?\n> >> > Drawbacks?\n> >> \n> >> Instead of talking first about drawbacks, we should consider the\n> >> upsides.  Why would we even want to see your GPG signature, when\n> >> most of us do not even have your GPG public key in our keychains?\n> >> \n> >> What are we trying to achieve by doing this?\n> >\n> > Just to ensure that PR commits are really from the respective authors.\n> \n> Yeah, but my point was that it would not ensure, because practically\n> nobody has ways to validate the signature was created with your\n> private key, and public keyservers have been tainted long time ago\n> with fake keys with the same fingerprint, so would not work as a\n> good way to obtain your public key and be sure it is yours.\n> \n> If this were \"because we would want to eat our own dogfood\", and if\n> we find bugs in our code when different person sign their commit\n> with their own signature scheme (i.e. you may sign yours with your\n> GPG key, somebody else may use their SSH key, and yet other people\n> use their X.509 certs, it might give us valuable insights, but the\n> resulting history may be irrevocably tainted if the bug is on the\n> signing side (if the bug is on the verification side, that is OK).\n> \n> Thanks.\n\nOK, thanks! I will stick to unsigned commits then.\n\n-- \nAn old man doll... just what I always wanted! - Clara\n"},{"id":"509336","messageId":"xmqqzfkrlogv.fsf@gitster.g","threadId":"62665","inReplyTo":"xmqqh670nrb9.fsf@gitster.g","subject":"Re: OK to submit l10n PR with signed commits?","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2024-12-19T14:46:56Z","receivedAt":"2024-12-19T14:47:00Z","isPatch":false,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Junio C Hamano <gitster@pobox.com> writes:\n\n>>> Instead of talking first about drawbacks, we should consider the\n>>> upsides.  Why would we even want to see your GPG signature, when\n>>> most of us do not even have your GPG public key in our keychains?\n>>> \n>>> What are we trying to achieve by doing this?\n>>\n>> Just to ensure that PR commits are really from the respective authors.\n>\n> Yeah, but my point was that it would not ensure, because practically\n> nobody has ways to validate the signature was created with your\n> private key, and public keyservers have been tainted long time ago\n> with fake keys with the same fingerprint, so would not work as a\n> good way to obtain your public key and be sure it is yours.\n\nI think I should rethink this.\n\nEven though I think it is fair to say that more than 99% of people\nwon't have your public key and even if somebody gave them saying\n\"this is Bagas' key\", they do not have a way to independently verify\nit is truly your key (and I think the same thing can be said of my\nkey).  But in today's world, there are a few places that it does not\nmatter all that much that you and I do not have each others' keys:\nhosting sites.\n\nI think both GitHub and GitLab lets you register your public key, so\nwhen they are about to show a commit (or a tag for that matter),\nthey can\n\n - notice it is signed;\n - look up the author/tagger/committer ident of the Git object;\n - look up the ident in their user database;\n - find the key(s) of that user account; and\n - verify the signature using the key(s).\n\nand display the user account that the Git object is signed by a key\nregistered to it.\n\nNow there may be ways to contaminate hosting sites with fake keys\nthat have the same fingerprints as the real ones registered to fake\nuser accounts, and that may render such a feature at the hosting\nsites less useful.  I haven't thought through the security\nimplications.\n\nOf course, $CORP or other organizations can have their members\nregister their public keys and do pretty much the same thing within\ntheir closed world.  Safeguarding the public key database is their\nproblem so I won't be worried about, unlike hosting sites where\npractically anybody and their dogs can create accounts ;-).\n\nThanks.\n"}]}