git/list[1] front-page[2] threads[3] people[4] search[5] about
 

RE: Dealing with corporate email recycling

From
rsbecker@nexbridge.com <rsbecker@nexbridge.com>
Date
Mar 13, 2022, 17:52 UTC
Message-ID
<020501d83703$2f8785f0$8e9691d0$@nexbridge.com>
In-Reply-To
<Yi4oO+ifSK8OH0Mt@camp.crustytoothpaste.net>
On March 13, 2022 1:22 PM, brian m. carlson wrote:
Show 46 quoted lines
>On 2022-03-12 at 22:38:56, Sean Allred wrote:
>> * Proposal: UUIDs
>>
>> To get what we want (i.e., the ability to run `git show HEAD~1`, know
>> that Ada wrote it, and report her current contact information), we
>> need some way of tracking identity over time.  A naive solution could
>> be to extend the mailmap format as recognized by Git:
>>
>>     $ git cat-file blob HEAD~1:.mailmap
>>     A. U. Thor <foo@example.com> [uuid A] <ada@example.com>
>>
>>     $ git cat-file blob HEAD:.mailmap
>>     A. U. Thor <ada@example.com> [uuid A]
>>     Roy G. Biv <foo@example.com> [uuid B] <roy@example.com>
>>
>> Now, when I run `git show HEAD~1`, Git would determine the UUID of the
>> email on the commit using the mailmap version in that tree:
>>
>>     $ git -c mailmap.blob=HEAD~1:.mailmap check-mailmap --uuid
>"<foo@example.com>"
>>     A
>>
>> Then, we can use that UUID to resolve to the current contact information:
>>
>>     $ git check-mailmap --uuid=A
>>     A. U. Thor <ada@example.com>
>>
>> Mailmap-sensitive commands can use this logic internally -- possibly
>> guarded under some new config setting.
>
>It's my intention to implement an approach where people's emails are identified
>by a key fingerprint of some sort and then converted into the proper email
>address by a mailmap that lives outside of the main history.  That is, my email
>address might be
>ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad@ssh-
>sha256.ns.git-scm.com,
>and then we have a mailmap that converts between the two.  If you wanted to
>have a UUID-based one, you could do 77c747a3-1599-4c8c-9569-
>f729c17632e6@uuid.ns.git-scm.com (assuming that namespace were registered).
>
>The benefit to the key part is that you can essentially prove that you are who you
>say you are.  A UUID doesn't have the possibility.
>
>This was discussed briefly at some sort of contributor summit we had at some
>point, but I've been busy and haven't gotten to it yet.  It is on my list of projects,
>however.
This could require a global and security hardened tokenization or signing approach. Email fingerprints from one organization would have to be able to move to another organization easily - potentially as part of the git repo's metadata. I would not use the same key as is used for signing fingerprints (mostly out of paranoia), but this is conceptually similar to the public side of a key-pair. One would have to have access to the private key in order to be a committer/author. Unfortunately, as it stands today, that may be easily spoofed (--committer, --author), so that part of the code would have to change with safeguards on what can be supplied - something I think would be welcome. Keeping with a distributed philosophy is probably essential. Just my take on it.
Previous: brian m. carlsonNext: rsbecker@nexbridge.com
Message 24 of 28 in “Dealing with corporate email recycling”
  1. Sean AllredMar 12, 2022
  2. Junio C HamanoMar 13, 2022
  3. rsbecker@nexbridge.comMar 13, 2022
  4. Sean AllredMar 13, 2022
  5. rsbecker@nexbridge.comMar 13, 2022
  6. Sean AllredMar 13, 2022
  7. rsbecker@nexbridge.comMar 13, 2022
  8. Sean AllredMar 13, 2022
  9. Philip OakleyMar 13, 2022
  10. Sean AllredMar 13, 2022
  11. Junio C HamanoMar 13, 2022
  12. rsbecker@nexbridge.comMar 13, 2022
  13. Junio C HamanoMar 14, 2022
  14. Philip OakleyMar 14, 2022
  15. Junio C HamanoMar 14, 2022
  16. Philip OakleyMar 14, 2022
  17. Sean AllredMar 15, 2022
  18. Philip OakleyMar 15, 2022
  19. Philip OakleyMar 13, 2022
  20. Sean AllredMar 13, 2022
  21. Philip OakleyMar 14, 2022
  22. Ævar Arnfjörð BjarmasonMar 13, 2022
  23. brian m. carlsonMar 13, 2022
  24. rsbecker@nexbridge.comMar 13, 2022
  25. rsbecker@nexbridge.comMar 13, 2022
  26. Sean AllredMar 13, 2022
  27. Sean AllredMar 15, 2022
  28. Peter KreftingMar 18, 2022

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.