git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: send PGP signed commits/patches with git-send-email(1)

From
Fabian Stelzer <fs@gigacodes.de>
Date
Jun 17, 2022, 12:00 UTC
Message-ID
<20220617120016.txjksectzdugqiod@fs>
In-Reply-To
<81caab7d-777e-13fe-89ea-820b7b2f0314@gmail.com>
On 17.06.2022 12:24, Alejandro Colomar wrote:
Show 5 quoted lines
>Hi,
>
>In Kernel Recipes this month [1], Greg mentioned that 
>git-send-email(1) could be used together with gpg(1) to verify 
>authenticity of the sender.

I think he is talking about GPG signing the email containing the patch and is not referring to git commit signing. Using GPG to sign your whole email adds trust to a whole lot more than just the sent patch. It can verify the authenticity of the sender, and all the rest of the emails content and follow up discussions / review.

Including the commits signature in the email might have some benefit but I'm not sure about how much. It could decouple the trust of the patches integrity of the transport used to publish it. For example you could forward / copy a patch and the recipient could still verify the original authors signature.

Konstantin Ryabitsev has done some work in this area especially for kernel development by using email headers: https://people.kernel.org/monsieuricon/end-to-end-patch-attestation-with-patatt-and-b4 https://github.com/mricon/patatt

Show 25 quoted lines
>
>I couldn't find any documentation about it, and if I create a patch 
>from a commit that was signed (-S), the PGP signature is not part of 
>the patch.
>
>So, is there a way to PGP-authenticate patches?
>If not, could this be added to git(1)?
>
>$ git --version
>git version 2.36.1
>
>Thanks,
>
>Alex
>
>
>[1]: <https://www.youtube.com/watch?v=nhJqaZT94z0>
>
>     - Start of thread Q&A in 1:56:30.
>     - Greg's answer starts in 1:56:57
>     - Specific git-send-email(1) part in 1:57:50
>
>-- 
>Alejandro Colomar
><http://www.alejandro-colomar.es/>
Previous: Alejandro ColomarNext: Konstantin Ryabitsev
Message 2 of 7 in “send PGP signed commits/patches with git-send-email(1)”
  1. Alejandro ColomarJun 17, 2022
  2. Fabian StelzerJun 17, 2022
  3. Konstantin RyabitsevJun 17, 2022
  4. Greg KHJun 21, 2022
  5. Alejandro ColomarJun 21, 2022
  6. Greg KHJun 21, 2022
  7. Alejandro ColomarJun 21, 2022

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.