git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [RFC PATCH] builtin:tag:verify_tag: allow gpg output + pretty

From
Jeff King <peff@peff.net>
Date
Apr 23, 2019, 02:13 UTC
Message-ID
<20190423021312.GC16369@sigill.intra.peff.net>
In-Reply-To
<20190422230701.GD6316@genre.crustytoothpaste.net>
On Mon, Apr 22, 2019 at 11:07:01PM +0000, brian m. carlson wrote:
Show 19 quoted lines
> On Mon, Apr 22, 2019 at 12:02:11PM -0400, Jeff King wrote:
> > On Mon, Apr 22, 2019 at 11:46:56AM -0400, Santiago Torres Arias wrote:
> > 
> > > > In some ways I'm less concerned about verify-tag, though, because the
> > > > point is that it should be scriptable. And scraping gpg's stderr is not
> > > > ideal there. We should be parsing --status-fd ourselves and making the
> > > > result available via format specifier, similar to the way "log
> > > > --format=%G?" works.
> > > 
> > > I think that would be great, as we could make it simpler for verifiers
> > > to parse gpg output.
> > 
> > Alternatively, we could make it an option to dump the --status-fd output
> > to stderr (or to a custom fd). That still leaves the caller with the
> > responsibility to parse gpg's output, but at least they're parsing the
> > machine-readable bits and not the regular human-readable stderr.
> 
> Don't we already have that for verify-tag and verify-commit? I recall
> adding "--raw" for that very reason:
Heh. Today I learned about "--raw". :)

Thanks for pointing it out. I do still think it would be nice for some cases to have --format specifiers to get the basic info, but I am glad that we already have a reasonable method that scripts can use.

It might make sense to make it available from the git-tag porcelain, too, but since the point is scripting, I'm not sure it's all that important.

It looks like using "--format" suppresses it, too, which we'd probably want to fix (presumably it's the same as the fix for the non-raw output).

> The idea was that users might want to restrict signatures to using
> subkeys or certain algorithms or what-have-you, and this was the easiest
> way to let people have all of that power.
Yeah, that makes perfect sense.
-Peff
Previous: brian m. carlson
Message 9 of 9 in “builtin:tag:verify_tag: allow gpg output + pretty”
  1. builtin:tag:verify_tag: allow gpg output + prettysantiago@nyu.edu, Apr 12, 2019
  2. Santiago Torres AriasApr 12, 2019
  3. Jeff KingApr 22, 2019
  4. Santiago Torres AriasApr 22, 2019
  5. Jeff KingApr 22, 2019
  6. brian m. carlsonApr 22, 2019
  7. Santiago Torres AriasApr 22, 2019
  8. brian m. carlsonApr 23, 2019
  9. Jeff KingApr 23, 2019

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.