git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH/RFC] builtin/tag: Changes argument format for verify

From
Jeff King <peff@peff.net>
Date
Mar 3, 2016, 22:26 UTC
Message-ID
<20160303222636.GA26712@sigill.intra.peff.net>
In-Reply-To
<20160303220502.GA2234@LykOS>
On Thu, Mar 03, 2016 at 05:05:03PM -0500, Santiago Torres wrote:
Show 7 quoted lines
> I've been trying to shape these changes into sensible patch, but it is
> not as trivial as I originally thought. I think the issue lies in the
> tag desambiguation aspect of the git-tag command.
> 
> It seems that verify-tag can take either the refname or the hash of the
> object. However, git tag --verify takes only the refname, so it doesn't
> resolve the tag-sha1 if that's specified as an argument.

Right. Git-tag's arguments are tag-names, _not_ general sha1 expressions. So we look at "refs/tags/<whatever>", and nothing else. I think this should remain the case. Even though it may seem like a convenience to fall back to resolving the sha1, I think it introduces unexpected corner cases.

> Also, would it make sense to remove the verify-tag command altogether?
No, I don't think so, for two reasons.

One is simply that it would break backwards compatibility. Verify-tag is the advertised "plumbing" command for scripts to use, and we do not want to break them. So even if its features were totally subsumed by "git tag --verify", we would keep it anyway.

The second is that I don't think it is quite the same thing as "tag --verify". Verify-tag is plumbing for operating on a tag object; that's why it takes an arbitrary sha1 expression. But git-tag is a general command for operating on tag-names defined in refs/tags. We've already seen one difference there (how we resolve the arguments), but as time goes on, there may be others. E.g., "tag --verify" may learn to validate additional elements of the tag, like whether the refname matches what is in the signed object (that's just an example; I don't know if it's a good idea or not, but I just meant to illustrate the conceptual difference between the two).

> On the same line, it seems that there used to be a --raw flag on the
> verify-tag command, should I propagate this to git tag --verify?

I'm not sure if it is necessary. It's primarily for machine consumption, and in that case, I'd expect people to use the verify-tag plumbing.

-Peff
Previous: Santiago Torres
Message 6 of 6 in “builtin/tag: Changes argument format for verify”
  1. builtin/tag: Changes argument format for verifysantiago@nyu.edu, Feb 27, 2016
  2. Jeff KingFeb 27, 2016
  3. Santiago TorresFeb 27, 2016
  4. Jeff KingFeb 27, 2016
  5. Santiago TorresMar 3, 2016
  6. Jeff KingMar 3, 2016

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.