git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH v2 4/5] fast-export: handle all kinds of tag signatures

From
Christian Couder <christian.couder@gmail.com>
Date
Oct 9, 2025, 12:24 UTC
Message-ID
<20251009122457.1273701-5-christian.couder@gmail.com>
In-Reply-To
<20251009122457.1273701-1-christian.couder@gmail.com>

Currently the handle_tag() function in "builtin/fast-export.c" searches only for "\n-----BEGIN PGP SIGNATURE-----\n" in the tag message to find a tag signature.

This doesn't handle all kinds of OpenPGP signatures as some can start with "-----BEGIN PGP MESSAGE-----" too, and this doesn't handle SSH and X.509 signatures either as they use "-----BEGIN SSH SIGNATURE-----" and "-----BEGIN SIGNED MESSAGE-----" respectively.

To handle all these kinds of tag signatures supported by Git, let's use the parse_signed_buffer() function to properly find signatures in tag messages.

Signed-off-by: Christian Couder <chriscool@tuxfamily.org>
---
 builtin/fast-export.c  |  7 +++----
 t/t9350-fast-export.sh | 36 ++++++++++++++++++++++++++++++++++++
 2 files changed, 39 insertions(+), 4 deletions(-)
diff --git a/builtin/fast-export.c b/builtin/fast-export.c
index dc2486f9a8..7adbc55f0d 100644
--- a/builtin/fast-export.c
+++ b/builtin/fast-export.c
@@ -931,9 +931,8 @@ static void handle_tag(const char *name, struct tag *tag)
 
 	/* handle signed tags */
 	if (message) {
-		const char *signature = strstr(message,
-					       "\n-----BEGIN PGP SIGNATURE-----\n");
-		if (signature)
+		size_t sig_offset = parse_signed_buffer(message, message_size);
+		if (sig_offset < message_size)
 			switch (signed_tag_mode) {
 			case SIGN_ABORT:
 				die("encountered signed tag %s; use "
@@ -950,7 +949,7 @@ static void handle_tag(const char *name, struct tag *tag)
 					oid_to_hex(&tag->object.oid));
 				/* fallthru */
 			case SIGN_STRIP:
-				message_size = signature + 1 - message;
+				message_size = sig_offset;
 				break;
 			}
 	}
diff --git a/t/t9350-fast-export.sh b/t/t9350-fast-export.sh
index 21ff26939c..3d153a4805 100755
--- a/t/t9350-fast-export.sh
+++ b/t/t9350-fast-export.sh
@@ -279,6 +279,42 @@ test_expect_success 'signed-tags=warn-strip' '
 	test -s err
 '
 
+test_expect_success GPGSM 'setup X.509 signed tag' '
+	test_config gpg.format x509 &&
+	test_config user.signingkey $GIT_COMMITTER_EMAIL &&
+
+	git tag -s -m "X.509 signed tag" x509-signed $(git rev-parse HEAD) &&
+	ANNOTATED_TAG_COUNT=$((ANNOTATED_TAG_COUNT + 1))
+'
+
+test_expect_success GPGSM 'signed-tags=verbatim with X.509' '
+	git fast-export --signed-tags=verbatim x509-signed > output &&
+	test_grep "SIGNED MESSAGE" output
+'
+
+test_expect_success GPGSM 'signed-tags=strip with X.509' '
+	git fast-export --signed-tags=strip x509-signed > output &&
+	test_grep ! "SIGNED MESSAGE" output
+'
+
+test_expect_success GPGSSH 'setup SSH signed tag' '
+	test_config gpg.format ssh &&
+	test_config user.signingkey "${GPGSSH_KEY_PRIMARY}" &&
+
+	git tag -s -m "SSH signed tag" ssh-signed $(git rev-parse HEAD) &&
+	ANNOTATED_TAG_COUNT=$((ANNOTATED_TAG_COUNT + 1))
+'
+
+test_expect_success GPGSSH 'signed-tags=verbatim with SSH' '
+	git fast-export --signed-tags=verbatim ssh-signed > output &&
+	test_grep "SSH SIGNATURE" output
+'
+
+test_expect_success GPGSSH 'signed-tags=strip with SSH' '
+	git fast-export --signed-tags=strip ssh-signed > output &&
+	test_grep ! "SSH SIGNATURE" output
+'
+
 test_expect_success GPG 'set up signed commit' '
 
 	# Generate a commit with both "gpgsig" and "encoding" set, so
-- 
2.51.0.438.g6987fc0bae
Previous: Christian CouderNext: Christian Couder
Message 36 of 52 in “fast-import: start controlling how tag signatures are handled”
  1. 0/5 fast-import: start controlling how tag signatures are handledChristian Couder, Oct 7, 2025
  2. 1/5 doc: git-tag: stop focussing on GPG signed tagsChristian Couder, Oct 7, 2025
  3. Patrick SteinhardtOct 8, 2025
  4. Christian CouderOct 8, 2025
  5. Patrick SteinhardtOct 8, 2025
  6. 2/5 lib-gpg: allow tests with the GPGSM prereq firstChristian Couder, Oct 7, 2025
  7. Patrick SteinhardtOct 8, 2025
  8. Christian CouderOct 8, 2025
  9. Collin FunkOct 9, 2025
  10. Todd ZullingerOct 9, 2025
  11. Christian CouderOct 9, 2025
  12. Junio C HamanoOct 9, 2025
  13. Christian CouderOct 9, 2025
  14. 3/5 t9350: properly count annotated tagsChristian Couder, Oct 7, 2025
  15. Patrick SteinhardtOct 8, 2025
  16. Christian CouderOct 8, 2025
  17. 4/5 fast-export: handle all kinds of tag signaturesChristian Couder, Oct 7, 2025
  18. Patrick SteinhardtOct 8, 2025
  19. Christian CouderOct 8, 2025
  20. Christian CouderOct 9, 2025
  21. 5/5 fast-import: add '--signed-tags=<mode>' optionChristian Couder, Oct 7, 2025
  22. Patrick SteinhardtOct 8, 2025
  23. Christian CouderOct 8, 2025
  24. Patrick SteinhardtOct 8, 2025
  25. 0/5 fast-import: start controlling how tag signatures are handledChristian Couder, Oct 9, 2025
  26. 1/5 doc: git-tag: stop focusing on GPG signed tagsChristian Couder, Oct 9, 2025
  27. Junio C HamanoOct 10, 2025
  28. Christian CouderOct 10, 2025
  29. 2/5 lib-gpg: allow tests with GPGSM or GPGSSH prereq firstChristian Couder, Oct 9, 2025
  30. Patrick SteinhardtOct 10, 2025
  31. Todd ZullingerOct 10, 2025
  32. Junio C HamanoOct 10, 2025
  33. Todd ZullingerOct 11, 2025
  34. Junio C HamanoOct 12, 2025
  35. 3/5 t9350: properly count annotated tagsChristian Couder, Oct 9, 2025
  36. 4/5 fast-export: handle all kinds of tag signaturesChristian Couder, Oct 9, 2025
  37. 5/5 fast-import: add '--signed-tags=<mode>' optionChristian Couder, Oct 9, 2025
  38. Junio C HamanoOct 9, 2025
  39. 0/5 fast-import: start controlling how tag signatures are handledChristian Couder, Oct 13, 2025
  40. 1/5 doc: git-tag: stop focusing on GPG signed tagsChristian Couder, Oct 13, 2025
  41. Elijah NewrenOct 24, 2025
  42. 2/5 lib-gpg: allow tests with GPGSM or GPGSSH prereq firstChristian Couder, Oct 13, 2025
  43. 3/5 t9350: properly count annotated tagsChristian Couder, Oct 13, 2025
  44. Elijah NewrenOct 24, 2025
  45. 4/5 fast-export: handle all kinds of tag signaturesChristian Couder, Oct 13, 2025
  46. Elijah NewrenOct 24, 2025
  47. 5/5 fast-import: add '--signed-tags=<mode>' optionChristian Couder, Oct 13, 2025
  48. Elijah NewrenOct 24, 2025
  49. Christian CouderOct 24, 2025
  50. Junio C HamanoOct 24, 2025
  51. Christian CouderOct 13, 2025
  52. Elijah NewrenOct 24, 2025

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.