git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Remote helpers and signed tags

From
John Keeping <john@keeping.me.uk>
Date
Apr 7, 2013, 10:34 UTC
Message-ID
<20130407103418.GT2222@serenity.lan>

It appears to be impossible to push signed tags using a remote helper that supports only fast-export. This is reported against gitifyhg[1] but I think it is actually a Git issue.

[1] https://github.com/buchuki/gitifyhg/issues/59

I can reproduce the error using a trivial remote helper (run this in a clone of git.git):

-- >8 -- cat >git-remote-export <<EOF && #!/bin/sh

alias=$1 url=${2-$1}

while read -r line
do
	case "$line" in
	capabilities)
		echo 'export'
		echo 'refspec *:*'
		echo
		;;
	list)
		echo
		;;
	export)
		while read -r line
		do
			echo "$line" >&3
			test "$line" = done && break
		done 3>"$url"
		echo
		;;
	'')
		exit
		;;
	*)
		echo >&2 "unsupported command: $line"
		exit 1
		;;
	esac
done
EOF
chmod +x git-remote-export &&
PATH="$(pwd):$PATH" git push "export::$(pwd)/v1.8.2.export" v1.8.2
-- 8< --
This produces:
    fatal: Encountered signed tag 572a535454612a046e7dd7404dcca94d6243c788;
        use --signed-tag=<mode> to handle it.
    fatal: Error while running fast-export

which is not particularly helpful for a user who doesn't know how the remote helper is implemented, particularly because adding --signed-tag=<mode> to the command won't work.

I think there are two problems here:
    1) The error message is misleading: "--signed-tag" isn't an option
       to git-push and as a user I don't know why Git thought I wanted
       to run fast-export.
    2) There is no way (that I have found) to change the signed-tag
       behaviour of git-fast-export when it is being invoked for a
       remote helper.

How do remote helpers using the "push" method handle this? In that case it seems to be completely up to the helper program to decide what to do.

I wonder if the way forward is to do some combination of:
    a) Add a --signed-tags option to git-push, which is either passed to
       fast-export or given as a new "option signed-tags" to the
       remote-helper when using the push interface (and ignored for the
       connect interface).
    b) Add a configuration variable to specify how to handle signed tags
       when pushing to a remote that uses a remote helper that cannot
       handle them; something like "remote.<name>.signedTags".
    c) Improve the "Error while running fast-export" message to
       something more like "Error pushing with fast-export (using helper
       git-remote-foo)".
Next: Jonathan Nieder
Message 1 of 14 in “Remote helpers and signed tags”
  1. John KeepingApr 7, 2013
  2. Jonathan NiederApr 7, 2013
  3. Sverre RabbelierApr 8, 2013
  4. 0/3 Handle signed tags with 'export' remote helpersJohn Keeping, Apr 14, 2013
  5. 1/3 fast-export: add --signed-tags=warn-strip modeJohn Keeping, Apr 14, 2013
  6. Sverre RabbelierApr 16, 2013
  7. Junio C HamanoApr 16, 2013
  8. Sverre RabbelierApr 16, 2013
  9. John KeepingApr 16, 2013
  10. Junio C HamanoApr 17, 2013
  11. Sverre RabbelierApr 17, 2013
  12. Jonathan NiederApr 16, 2013
  13. 2/3 transport-helper: pass --signed-tags=warn-strip to fast-exportJohn Keeping, Apr 14, 2013
  14. 3/3 transport-helper: add 'signed-tags' capabilityJohn Keeping, Apr 14, 2013

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.