From: H. Peter Anvin Date: Mon, 25 Apr 2005 21:36:00 GMT Subject: Re: git "tag" objects implemented - and a re-done commit Message-ID: <426D62C0.40104@zytor.com> In-Reply-To: Linus Torvalds wrote: > > Anyway, I decided that my original model for tags was the right one, with > a trivial extension. Notably, if you want to tag a single file or a tree > object, go wild. The tag object format is: > > object > type > tag > .. free-form commentary and signature of this all .. > > and the "git-mktag" program verifies that the three first lines are valid > before it accepts it and writes it as a git object. > > Right now the tags don't do anything, except fsck can verify them (not the > signature - git doesn't even specify any particular format, and you may > validly have unsigned tags in your tree), and will print out something > like > > tagged commit e83c5163316f89bfbde7d9ab23ca2e25604af290 (v2.6.12-rc2) > > if you were to have such a tag-object in your object database (you don't, > because I've not generated one, but hey..) > It would be good if the tag object could permit junk lines before the start of the header; in particular, the standard PGP/GPG signed message format looks like: -----BEGIN PGP SIGNED MESSAGE----- object aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa type commit tag foo -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.6 (GNU/Linux) iQEVAwUBQm1hyWx5eAAqlgcFAQEShgf+P/PNJu5h1uAVPp9+xSy8QtIIC/1Zpl6a 2Tp22Bw0hfXUNYoJ7O9TH35wttYbcx8ArXl6JhlMIEcV7rS48H/vmTJgtBwnhLSb epDPbOriLbCl9E0XXPHqrlmQE07H0iZn2dmLyg2REmtdffi3hjSQIkvFSHy72kOe Ho6H+s2hzs/u/ypkQ8Cl82Saqn/Drahj9ehdXLRQ5Nsslr71MhwRCD5M0x+0Uy0B KPjBiyyx6g/qWzIRLZOdkdbSUdXjczlGnm2wwC6/RdBDjeagDBGafaiuNQH8W3sx psfmqKgKZkCBFFlSvwJQAsRFgnVl2vYUAftRaxMnQlCG7COIjNAsdg== =lsn0 -----END PGP SIGNATURE----- As an alternative, the signature can be a separate object, since the object SHA-1 itself acts as a verifier of its self-content; thus, all that is really necessary is an authorized verifier. -hpa