git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: email as a bona fide git transport

From
Konstantin Ryabitsev <konstantin@linuxfoundation.org>
Date
Oct 18, 2019, 18:00 UTC
Message-ID
<20191018180026.GD25456@chatter.i7.local>
In-Reply-To
<20191018161121.6qe5kkweh4u77gvn@LykOS.localdomain>
On Fri, Oct 18, 2019 at 12:11:22PM -0400, Santiago Torres Arias wrote:
Show 22 quoted lines
>> It's smaller, but it's not a one-liner. Here's a comparison using 
>> ED25519
>> keys of the same length:
>>
>> minisign:
>>
>> RWQ4kF9UdFgeSt3LqnS3WnrLlx2EnuIFW7euw5JnLUHY/79ipftmj7A2ug7FiR2WmnFNoSacWr7llBuyInVmRL/VRovj1LFtvA0=
>>
>> pgp:
>>
>> -----BEGIN PGP SIGNATURE-----
>>
>> iHUEARYIAB0WIQR2vl2yUnHhSB5njDW2xBzjVmSZbAUCXaniFAAKCRC2xBzjVmSZ
>> bHA5AP46sSPFJfL2tbXwswvj0v2DjLAQ9doxl9bfj9iPZu+3qwEAw5qAMbjw9teL
>> L7+NbJ0WVniDWTgt+5ruQ2V9vyfYxAc=
>> =B/St
>
>Yeah, the discrepancy mostly comes from pgp embedding a timestamp and a
>longer keyid (+a full keyid fingerprint in pgp 2.1+). Minisign keyids
>are 8 random bytes, apparently.
>
>It doesn't seem like an amazing win in terms of succintness, imvho...

There isn't, but ED25519 subkeys are still very rare among developers. Many have 4096-bit RSA subkeys, and you can imagine how large the sigs from those are.

I want to underline that my use of minisign was specifically for patches sent via email, without the intent of preserving them in git history (which is why in my proposal they are put under the `---` cutoff). Git itself would continue to use PGP signing.

(This also means that we don't necessarily need to make this a native part of git -- it can be accomplished by a combination of wrappers, git-format-patch parameters, and a pre-applypatch hook. However, the likelihood of adoption in this case would be very low.)

-K
Previous: Santiago Torres AriasNext: Pratyush Yadav
Message 25 of 36 in “email as a bona fide git transport”
  1. Vegard NossumOct 16, 2019
  2. Willy TarreauOct 16, 2019
  3. Santiago Torres AriasOct 16, 2019
  4. Greg KHOct 17, 2019
  5. Konstantin RyabitsevOct 17, 2019
  6. Greg KHOct 18, 2019
  7. Konstantin RyabitsevOct 18, 2019
  8. Willy TarreauOct 18, 2019
  9. Nicolas BelouinOct 18, 2019
  10. Santiago Torres AriasOct 18, 2019
  11. Laurent PinchartOct 20, 2019
  12. Vegard NossumOct 18, 2019
  13. Theodore Y. Ts'oOct 18, 2019
  14. Vegard NossumOct 18, 2019
  15. Theodore Y. Ts'oOct 18, 2019
  16. Willy TarreauOct 20, 2019
  17. Vegard NossumOct 20, 2019
  18. Vegard NossumOct 22, 2019
  19. Theodore Y. Ts'oOct 22, 2019
  20. Vegard NossumOct 22, 2019
  21. Eric WongOct 22, 2019
  22. Santiago Torres AriasOct 18, 2019
  23. Konstantin RyabitsevOct 18, 2019
  24. Santiago Torres AriasOct 18, 2019
  25. Konstantin RyabitsevOct 18, 2019
  26. Pratyush YadavOct 16, 2019
  27. Vegard NossumOct 17, 2019
  28. Theodore Y. Ts'oOct 17, 2019
  29. Vegard NossumOct 17, 2019
  30. Theodore Y. Ts'oOct 17, 2019
  31. Steven RostedtOct 17, 2019
  32. Jonathan NiederOct 16, 2019
  33. Vegard NossumOct 17, 2019
  34. Junio C HamanoOct 17, 2019
  35. Vegard NossumOct 17, 2019
  36. Eric WongOct 18, 2019

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.