git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[RFC PATCH 0/4] Teach git fetch to verify signed tags automatically

From
Deskin Miller <deskinm@umich.edu>
Date
Nov 24, 2008, 03:23 UTC
Message-ID
<1227497000-8684-1-git-send-email-deskinm@umich.edu>

It struck me a while back when I fetched a new tagged release from git.git that if I wanted to verify the tag's signature, I'd have to issue another command to do so. Shouldn't git be able to do that for me automatically, when it fetches signed tags? Now it does. Also, 'git remote update' gets this for free.

Individual commit messages explain things reasonably well, I hope; here are a few points for discussion:

-Is refactoring builtin-verify-tag.c the right thing to do?
-Now that the SIGPIPE ignoring is occurring at a lower level, should it be
 removed from cmd_verify_tag?
-Output format: good, bad, ugly?
-What to do if a tag is found to have a bad signature?
Deskin Miller (4):
  Refactor builtin-verify-tag.c
  verify-tag.c: ignore SIGPIPE around gpg invocation
  verify-tag.c: suppress gpg output if asked
  Make git fetch verify signed tags
 Makefile             |    2 +
 builtin-fetch.c      |   25 +++++++++++----
 builtin-verify-tag.c |   61 ++----------------------------------
 t/t7004-tag.sh       |   37 ++++++++++++++++++++++
 verify-tag.c         |   84 ++++++++++++++++++++++++++++++++++++++++++++++++++
 verify-tag.h         |   10 ++++++
 6 files changed, 155 insertions(+), 64 deletions(-)
 create mode 100644 verify-tag.c
 create mode 100644 verify-tag.h
Next: Deskin Miller
Message 1 of 16 in “Teach git fetch to verify signed tags automatically”
  1. 0/4 Teach git fetch to verify signed tags automaticallyDeskin Miller, Nov 24, 2008
  2. 1/4 Refactor builtin-verify-tag.cDeskin Miller, Nov 24, 2008
  3. 2/4 verify-tag.c: ignore SIGPIPE around gpg invocationDeskin Miller, Nov 24, 2008
  4. 3/4 verify-tag.c: suppress gpg output if askedDeskin Miller, Nov 24, 2008
  5. 4/4 Make git fetch verify signed tagsDeskin Miller, Nov 24, 2008
  6. Johannes SchindelinNov 24, 2008
  7. Deskin MillerNov 28, 2008
  8. Johannes SchindelinNov 24, 2008
  9. Deskin MillerNov 28, 2008
  10. Junio C HamanoNov 24, 2008
  11. Junio C HamanoNov 24, 2008
  12. Deskin MillerNov 28, 2008
  13. Johannes SchindelinNov 28, 2008
  14. Johannes SchindelinNov 24, 2008
  15. Deskin MillerNov 28, 2008
  16. Junio C HamanoNov 28, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.