git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Git-commits mailing list feed.

From
David A. Wheeler <dwheeler@dwheeler.com>
Date
Apr 25, 2005, 02:13 UTC
Message-ID
<426C5266.6050200@dwheeler.com>
In-Reply-To
<Pine.LNX.4.62.0504250212200.14200@sheen.jakma.org>
Paul Jakma wrote:
> On Sun, 24 Apr 2005, David A. Wheeler wrote:
> Hmm, what do you mean by "repeating what gets signed"?
Forget it, irrelevant.  I vaguely remembered some problem with
gpg's detached signatures, but it was probably either a really
early alpha version or someone was using "--clearsign" instead
of "--armor".  I just did a quick check with:
  gpg --armor --detach -o junk.sig junk.c
and it worked "as expected"; no repeat of the data.
Show 6 quoted lines
>> Yes, and see my earlier posting.  It'd be easy to store signatures in
>> the current objects directory, of course.  The trick is to be able
>> to go from signed-object to the signature;
> Two ways:
> 1. An index of sigs to signed-object.
> (or more generally: objects to referring-objects)

Right. I suggested putting it in the same directory as the objects, so that rsync users get them "for free", but a separate directory has its own advantages & that'd be fine too. In fact, the more I think about it, I think it'd be cleaner to have it separate. You could prepend on top of the signature (if signatures are separate from assertions) WHAT got signed so that the index could be recreated from scratch when desired.

> 2. Just give people the URI of the signature, let them (or their
>    tools) follow the 'parent' link to the object of interest

If you mean "the signatures aren't stored with the objects", NO. Please don't! If the signatures are not stored in the database, then over time they'll get lost. It's important to me to store the record of trust, as well as what changed, so that ANYONE can later go back and verify that things are as they're supposed to be, or exactly who trusted what.

> I think it might be more useful just to provide a general index to 
> lookup 'referring' objects (if git does not already - I dont think it 
> does, but I dont know enough to know for sure).

git definitely doesn't have this currently, though you could run the fsck tools which end up creating a lot of the info (but it's then thrown away).

 > So you could ask "which
> {commit,tag,signature,tree}(s) refer(s) to this object?" - that general 
> concept will always work.

Yes. The problem is that maintaining the index is a pain. It's probably worth it for signatures, because the primary use is the other direction ("who signed this?"); it's not clear that the other direction is common for other data.

--- David A. Wheeler
Previous: Paul JakmaNext: Paul Jakma
Message 23 of 55 in “Re: Git-commits mailing list feed.”
  1. David WoodhouseApr 21, 2005
  2. Linus TorvaldsApr 23, 2005
  3. Linus TorvaldsApr 23, 2005
  4. Fabian FranzApr 23, 2005
  5. Andreas GalApr 23, 2005
  6. SeanApr 23, 2005
  7. Thomas GlanzmannApr 23, 2005
  8. SeanApr 23, 2005
  9. Linus TorvaldsApr 23, 2005
  10. Thomas GlanzmannApr 23, 2005
  11. Linus TorvaldsApr 23, 2005
  12. SeanApr 23, 2005
  13. Linus TorvaldsApr 23, 2005
  14. SeanApr 23, 2005
  15. Linus TorvaldsApr 23, 2005
  16. Junio C HamanoApr 23, 2005
  17. Linus TorvaldsApr 23, 2005
  18. Junio C HamanoApr 23, 2005
  19. Paul JakmaApr 24, 2005
  20. Paul JakmaApr 24, 2005
  21. David A. WheelerApr 25, 2005
  22. Paul JakmaApr 25, 2005
  23. David A. WheelerApr 25, 2005
  24. Paul JakmaApr 25, 2005
  25. Paul JakmaApr 25, 2005
  26. Linus TorvaldsApr 25, 2005
  27. Fabian FranzApr 25, 2005
  28. Andreas GalApr 25, 2005
  29. Linus TorvaldsApr 25, 2005
  30. David A. WheelerApr 25, 2005
  31. David GreavesApr 25, 2005
  32. David A. WheelerApr 25, 2005
  33. Paul JakmaApr 25, 2005
  34. Paul JakmaApr 25, 2005
  35. Paul JakmaApr 25, 2005
  36. New option (-H) for rpush/rpull to update HEADAndreas Gal, Apr 25, 2005
  37. Daniel BarkalowApr 25, 2005
  38. Andreas GalApr 25, 2005
  39. Daniel BarkalowApr 25, 2005
  40. Matt DomschApr 25, 2005
  41. Jan HarkesApr 25, 2005
  42. Thomas GlanzmannApr 23, 2005
  43. Thomas GlanzmannApr 23, 2005
  44. Jan HarkesApr 23, 2005
  45. Linus TorvaldsApr 23, 2005
  46. Junio C HamanoApr 23, 2005
  47. Jan HarkesApr 23, 2005
  48. Linus TorvaldsApr 23, 2005
  49. Jan HarkesApr 23, 2005
  50. Git transfer protocols (was: Re: Git-commits mailing list feed)Mike Taht, Apr 23, 2005
  51. Jan HarkesApr 23, 2005
  52. Linus TorvaldsApr 23, 2005
  53. Suggestion: generalize signed tags into "assertion objects"David A. Wheeler, Apr 23, 2005
  54. Jeff GarzikApr 23, 2005
  55. David WoodhouseApr 25, 2005

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.