[PATCH v3 0/5] fast-import: start controlling how tag signatures are handled
- From
Christian Couder <christian.couder@gmail.com>
- Date
- Oct 13, 2025, 08:48 UTC
- Message-ID
- <20251013084857.1646783-1-christian.couder@gmail.com>
- In-Reply-To
- <20251007122958.1089680-1-christian.couder@gmail.com>
Introduction ------------
Tools like `git-filter-repo` should be able to control how tag signatures are handled when regenerating repository content after it has been filtered. For this purpose, they need a way for `git fast-import` to control how tag signatures are handled.
A previous series [1] added a '--signed-commits=<mode>' option to `git fast-import` to control how commit signatures are handled, so this is adding a similar '--signed-tags=<mode>' for tag signatures.
For now this new option behaves in a very similar way as the option with the same name that already exists in `git fast-export`. Especially it supports exactly the same <mode>s and the same aliases for these modes. For example "ignore" is a synonym for "verbatim".
This way, both `git fast-export` and `git fast-import` have both a '--signed-tags=<mode>' and a '--signed-commits=<mode>' supporting the same <mode>s.
In the future I want to implement new <mode>s like "strip-if-invalid", "re-sign", "re-sign-if-invalid" in `git fast-import` for both tag and commit signatures. These might be a bit more complex, so for now I prefer to start with the simple modes.
[1] https://lore.kernel.org/git/20250917181427.3193500-1-christian.couder@gmail.com/
Note about the different patches --------------------------------
Patch 1/5 (doc: git-tag: stop focussing on GPG signed tags) is a documentation update for `git tag`. It could go in a separate series or be dropped altogether, but while working on this I thought that it would be a good thing to do, as the doc is quite outdated.
Patches 2/5, 3/5 and 4/5 are preparatory patches for the main one which is patch 5/5 (fast-import: add '--signed-tags=<mode>' option).
I wanted '--signed-tags=<mode>' to work for all kinds of signature in tags (OpenPGP, X.509 and SSH) but soon realized that the '--signed-tags=<mode>' option of `git fast-export` worked only for OpenPGP signatures, so I fixed that issue in patch 4/5 (fast-export: handle all kinds of tag signatures).
While working on the tests in patch 4/5, I found a few things to improve that could belong to other patches so that's how I came up with patches 2/5 and 3/5.
Changes since v2 ----------------
Thanks to Patrick Steinhardt, Todd Zullinger and Collin Funk who reviewed or commented on the v1 and v2.
There is a single change in the first patch (doc: git-tag: stop focusing on GPG signed tags) where the description of the `-v | --verify` option of `git tag` has been improved.
CI tests --------
I haven't run CI tests because there is a single documentation change since v2 that is very unlikely to make things break.
Range diff since v2 -------------------
1: eb65af631d ! 1: ac67d927ad doc: git-tag: stop focusing on GPG signed tags
@@ Documentation/git-tag.adoc: OPTIONS
-v::
--verify::
- Verify the GPG signature of the given tag names.
-+ Verify the signature of the given tag names.
++ Verify the cryptographic signature of the given tags.
-n<num>::
<num> specifies how many lines from the annotation, if any,
2: 640204ef26 = 2: f0208527ff lib-gpg: allow tests with GPGSM or GPGSSH prereq first
3: 8f788bafe1 = 3: e9e3d8c081 t9350: properly count annotated tags
4: d62a43905c = 4: 8d318a0046 fast-export: handle all kinds of tag signatures
5: 9094f37b46 = 5: 962ad96b4a fast-import: add '--signed-tags=<mode>' optionChristian Couder (5): doc: git-tag: stop focusing on GPG signed tags lib-gpg: allow tests with GPGSM or GPGSSH prereq first t9350: properly count annotated tags fast-export: handle all kinds of tag signatures fast-import: add '--signed-tags=<mode>' option
Documentation/git-fast-import.adoc | 5 ++ Documentation/git-tag.adoc | 48 ++++++++++++------ builtin/fast-export.c | 7 ++- builtin/fast-import.c | 43 ++++++++++++++++ t/lib-gpg.sh | 24 +++++++-- t/meson.build | 1 + t/t9306-fast-import-signed-tags.sh | 80 ++++++++++++++++++++++++++++++ t/t9350-fast-export.sh | 48 ++++++++++++++++-- 8 files changed, 229 insertions(+), 27 deletions(-) create mode 100755 t/t9306-fast-import-signed-tags.sh
-- 2.51.0.438.g6987fc0bae