git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: How to clone git repository with git-svn meta-data included?

From
Shawn O. Pearce <spearce@spearce.org>
Date
Dec 8, 2008, 16:10 UTC
Message-ID
<20081208161049.GB31551@spearce.org>
In-Reply-To
<493C1F36.7050504@tuffmail.com>
Grzegorz Kossakowski <grek@tuffmail.com> wrote:
Show 17 quoted lines
> Peter Harris pisze:
> >> What if A was not fair and has rewritten a few commits coming from B so they contain malicious code?
> >> How we can detect something like that and how C be sure that what he merges is really work
> >> attributed by correct names?
> > 
> > If C doesn't trust A, C should not pull from A. C should pull only
> > from (trusted) B. Presumably B knows who (of A and B) did which work,
> > and B's repository can be trusted?
> > 
> > If neither of A or B can be trusted, then you have problems that a
> > computer cannot solve for you.
> 
> Yep, I was having in mind the case when both A and B are untrusted. I don't want my computer to
> check if something coming from A or B is safe or not I just want to know which bits are coming from
> A and which from B.
> 
> This is really important for us because of legal reasons.
ASF probably has issues similar to that of the Android project.

In Android we built Gerrit[1] to handle this validation of identity for us, and to keep track of the contributor agreements each individual and corporation has signed. Changes aren't accepted into Gerrit unless the user has an accepted CLA in the data store.

*1* http://review.source.android.com/

Gerrit 2 is actively under development and is being ported off of Google App Engine, into a pure Java webapp. I'm running it under Jetty, but it should work just as well under Tomcat. :-)

If the ASF becomes more committed to supporting Git, Gerrit may be
a good way to answer some of the questions you are having about
validating identity of changes.  Plus its a handy source code
review tool.
 
Show 5 quoted lines
> > You could maybe use signed tags ("git help tag") - each contributor
> > could sign a certain tree state, [...]
> 
> The question is why Git doesn't sign all commits by default but only tags? Creating tags all the
> time is rather tedious process and seems to have no sense, right?
Yea, its tedious to unlock your GnuPG key every time you make a
commit.  Especially if you are just rebasing a series or something
to fix a minor mistake 5 commits back before uploading somewhere.
 
> Does it mean that with current Git design it's the best to not use advanced features of Git like
> tree merging but simply go with posting e-mails with patches instead if contributors cannot be trusted?

Most Git projects rely on patches sent to an email list, with a single maintainer applying them to to his/her repository, and publishing the result. The maintainer is thus forced to keep track of the CLAs (if the project uses such things) and just trust the From address of the message.

CLAs in the kernel and in git itself are less enforced than say what ASF or Android requires.

Some Git projects give write access to the master repository to multiple trusted parties; SAMBA and X.org are good examples of this sort of strategy. But I think in these cases those who have write access are also very long standing members of the development community who have known each other in person for many years, perhaps far longer than a DVCS concept has existed. So trust between those with direct write access is slightly less of an issue for these projects.

So long story short, I think Gerrit may be worth the ASF's time, if Git is a serious consideration for replacing SVN. But while a project is based in SVN I think the best you can do with Git is publish an automatically updated git-svn mirror and permit only use of "git svn dcommit" to upload back into the SVN repository.

-- 
Shawn.
Previous: Michael J GruberNext: Grzegorz Kossakowski
Message 16 of 17 in “How to clone git repository with git-svn meta-data included?”
  1. Grzegorz KossakowskiDec 6, 2008
  2. Jacob HelwigDec 7, 2008
  3. Nick AndrewDec 8, 2008
  4. Peter HarrisDec 7, 2008
  5. Grzegorz KossakowskiDec 7, 2008
  6. Peter HarrisDec 7, 2008
  7. Grzegorz KossakowskiDec 7, 2008
  8. Peter HarrisDec 7, 2008
  9. Michael J GruberDec 8, 2008
  10. Grzegorz KossakowskiDec 8, 2008
  11. Peter HarrisDec 8, 2008
  12. Grzegorz KossakowskiDec 8, 2008
  13. Sam VilainDec 9, 2008
  14. Grzegorz KossakowskiDec 9, 2008
  15. Michael J GruberDec 9, 2008
  16. Shawn O. PearceDec 8, 2008
  17. Grzegorz KossakowskiDec 8, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.