git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [RFC PATCH] builtin:tag:verify_tag: allow gpg output + pretty

From
Santiago Torres Arias <santiago@nyu.edu>
Date
Apr 22, 2019, 15:46 UTC
Message-ID
<20190422154655.sxyrkee7rnywoh2w@LykOS.localdomain>
In-Reply-To
<20190422152726.GB1633@sigill.intra.peff.net>
Show 34 quoted lines
> However, I don't think this patch is quite right, as it causes us to
> dump the whole tag contents to stdout, as well. E.g.:
> 
>   [before]
>   $ git tag -v --format='foo %(tag)' v2.21.0
>   foo v2.21.0
> 
>   [after]
>   $ git tag -v --format='foo %(tag)' v2.21.0
>   object 8104ec994ea3849a968b4667d072fedd1e688642
>   type commit
>   tag v2.21.0
>   tagger Junio C Hamano <gitster@pobox.com> 1551023739 -0800
>   
>   Git 2.21
>   gpg: Signature made Sun Feb 24 10:55:39 2019 EST
>   gpg:                using RSA key E1F036B1FEE7221FC778ECEFB0B5E88696AFE6CB
>   gpg: Good signature from "Junio C Hamano <gitster@pobox.com>" [full]
>   gpg:                 aka "Junio C Hamano <jch@google.com>" [full]
>   gpg:                 aka "Junio C Hamano <junio@pobox.com>" [full]
>   foo v2.21.0
> 
> I think "git verify-tag" would need similar treatment, too:
> 
>   $ git verify-tag v2.21.0
>   gpg: Signature made Sun Feb 24 10:55:39 2019 EST
>   gpg:                using RSA key E1F036B1FEE7221FC778ECEFB0B5E88696AFE6CB
>   gpg: Good signature from "Junio C Hamano <gitster@pobox.com>" [full]
>   gpg:                 aka "Junio C Hamano <jch@google.com>" [full]
>   gpg:                 aka "Junio C Hamano <junio@pobox.com>" [full]
> 
>   $ git verify-tag --format='foo %(tag)' v2.21.0
>   foo v2.21.0
> 

Ah, let me look into these issues. I'm almost sure I also need to review the test suite and adapt it to this behavior.

Show 5 quoted lines
> In some ways I'm less concerned about verify-tag, though, because the
> point is that it should be scriptable. And scraping gpg's stderr is not
> ideal there. We should be parsing --status-fd ourselves and making the
> result available via format specifier, similar to the way "log
> --format=%G?" works.

I think that would be great, as we could make it simpler for verifiers to parse gpg output.

> So I think ultimately that's the direction we want to go, but I think
> in the meantime restoring the gpg output to stderr especially for the
> porcelain "git tag -v" makes sense for human eyes.
Great! let me re-roll and make a more formal take on this.

Thanks! -Santiago

Previous: Jeff KingNext: Jeff King
Message 4 of 9 in “builtin:tag:verify_tag: allow gpg output + pretty”
  1. builtin:tag:verify_tag: allow gpg output + prettysantiago@nyu.edu, Apr 12, 2019
  2. Santiago Torres AriasApr 12, 2019
  3. Jeff KingApr 22, 2019
  4. Santiago Torres AriasApr 22, 2019
  5. Jeff KingApr 22, 2019
  6. brian m. carlsonApr 22, 2019
  7. Santiago Torres AriasApr 22, 2019
  8. brian m. carlsonApr 23, 2019
  9. Jeff KingApr 23, 2019

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.