git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Review process improvements

From
Konstantin Ryabitsev <konstantin@linuxfoundation.org>
Date
Dec 22, 2021, 21:32 UTC
Message-ID
<20211222213247.5dnj3zlj53lh6l32@meerkat.local>
In-Reply-To
<xmqqh7b0juk5.fsf@gitster.g>
On Wed, Dec 22, 2021 at 11:42:02AM -0800, Junio C Hamano wrote:
Show 11 quoted lines
> > This would require pretending that we're authorized to send mail from the
> > domain name of the commit author, so this unfortunately won't work (and hence
> > the reason why GGG does it this way). E.g. say you have:
> >
> > From: foo@redhat.com
> > Subject: [PATCH] Fix foo
> 
> Would it help to use "Sender:"?  When GGG or any other automation
> are trying to send e-mail on behalf of the person shown on "From:",
> I thought that it is the mechanism for them to use to identify
> themselves.
Indeed, that's how the DKIM standard wanted to deal with this problem, however
when the DMARC RFC was being drafted, this approach was deemed insufficient.
They have a good explanation for it -- there is no standard among UI clients
to handle the Sender/From discrepancy. Most MUAs will happily ignore the
Sender: field and will only show what is in From:, so this approach was
considered ineffective against phishing attacks. An attacker could easily
register a domain, set DKIM records, and then use any From: they wanted as
long as they used a valid Sender: header, knowing that it would be ignored by
most mail clients.

So, DMARC deliberately ignores the Sender: header and *only* pays attention to the From: field for its purpose.

-K
Previous: Junio C HamanoNext: Johannes Schindelin
Message 11 of 22 in “Review process improvements”
  1. Emily ShafferDec 16, 2021
  2. rsbecker@nexbridge.comDec 16, 2021
  3. Junio C HamanoDec 17, 2021
  4. Konstantin RyabitsevDec 17, 2021
  5. Christian CouderDec 20, 2021
  6. Mark BrownDec 20, 2021
  7. Ævar Arnfjörð BjarmasonDec 22, 2021
  8. Fabian StelzerDec 22, 2021
  9. Konstantin RyabitsevDec 22, 2021
  10. Junio C HamanoDec 22, 2021
  11. Konstantin RyabitsevDec 22, 2021
  12. Why GitGitGadget does not use Sender:, was Re: Review process improvementsJohannes Schindelin, Jan 10, 2022
  13. Junio C HamanoJan 10, 2022
  14. Stefan HajnocziDec 23, 2021
  15. Ævar Arnfjörð BjarmasonDec 20, 2021
  16. Eric SunshineDec 20, 2021
  17. João Victor BonfimDec 20, 2021
  18. Emily ShafferJan 5, 2022
  19. João Victor BonfimJan 9, 2022
  20. brian m. carlsonDec 21, 2021
  21. Emily ShafferJan 5, 2022
  22. Matthias AßhauerJan 9, 2022

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.