git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Commit signing

From
Shawn O. Pearce <spearce@spearce.org>
Date
Jan 15, 2007, 10:43 UTC
Message-ID
<20070115104336.GD12257@spearce.org>
In-Reply-To
<Pine.LNX.4.63.0701151126540.22628@wbgn013.biozentrum.uni-wuerzburg.de>
Johannes Schindelin <Johannes.Schindelin@gmx.de> wrote:
Show 7 quoted lines
> On Mon, 15 Jan 2007, Shawn O. Pearce wrote:
> > A commit-msg hook could probably implement the signing.
> 
> But it would only sign the _message_. You would have to sign the whole 
> _raw_ commit message, to include also the ancestry. But there is no hook 
> _between_ constructing that _raw_ commit message and actually writing the 
> commit object (this would have to be in builtin-commit-tree.c:151).

Sorry, I was assuming people knew what was in the grey matter upstairs. :-)

I meant to say something along the lines of:
  A commit-msg hook could probably implement the signing.  However
  doing that would require generating the raw commit data using the
  current timestamp, and that would require having git-commit.sh set
  the timestamp into GIT_COMMITTER_DATE and GIT_AUTHOR_DATE before
  it runs the hook, or before git-commit-tree.  Clearly an ugly mess.

Johannes is right. A proper signing would probably need to be done in commit-tree itself. Or commit-tree would need to be invoked to create a dummy commit, fetch it back out with cat-file, sign that, then regenerate the commit with the same prior timestamps. Ugly.

But I don't really see a need for commit signing in Git. The best way to shuttle commits around in Git-space is through published repositories. You probably want to grab whatever is on that repository, and you either trust the repository owner or you don't. If you don't trust the owner, but you trust the pusher, than using 1 annotated tag per push is reasonable and gives you something to verify the repository owner isn't playing games. If you don't trust the pusher than you should be reviewing the changes before deciding to keep them in your project.

But even then annotated tags are overkill. You could just receive the commit SHA1 out-of-band from the pusher (e.g. email, like Junio's hidden X-master-at header) and verify that by hand. 8 digits is probably more than enough to hand-verify the entire commit chain you are receiving.

-- 
Shawn.
Previous: Johannes SchindelinNext: Karl Hasselström
Message 8 of 21 in “Commit signing”
  1. Andy ParkinsJan 15, 2007
  2. Matthias KestenholzJan 15, 2007
  3. Shawn O. PearceJan 15, 2007
  4. Shawn O. PearceJan 15, 2007
  5. Johannes SchindelinJan 15, 2007
  6. Daniel BarkalowJan 15, 2007
  7. Johannes SchindelinJan 15, 2007
  8. Shawn O. PearceJan 15, 2007
  9. Karl HasselströmJan 15, 2007
  10. Andy ParkinsJan 15, 2007
  11. Shawn O. PearceJan 15, 2007
  12. Johannes SchindelinJan 15, 2007
  13. Andy ParkinsJan 15, 2007
  14. Johannes SchindelinJan 15, 2007
  15. Andy ParkinsJan 15, 2007
  16. Martin LanghoffJan 15, 2007
  17. Andy ParkinsJan 15, 2007
  18. Martin LanghoffJan 15, 2007
  19. Johannes SchindelinJan 15, 2007
  20. Jakub NarebskiJan 15, 2007
  21. Jeff KingJan 15, 2007

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.