git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Transparently encrypt repository contents with GPG

From
Michael J Gruber <michaeljgruber+gmane@fastmail.fm>
Date
Mar 13, 2009, 13:56 UTC
Message-ID
<49BA6606.1070403@fastmail.fm>
In-Reply-To
<fabb9a1e0903130417x36121bd5ya8b323e0a80bbd8f@mail.gmail.com>
Sverre Rabbelier venit, vidit, dixit 13.03.2009 12:17:
Show 9 quoted lines
> Heya,
> 
> On Fri, Mar 13, 2009 at 12:15, Thomas Rast <trast@student.ethz.ch>
> wrote:
>> Not to mention that this makes most source-oriented features such
>> as diff, blame, merge, etc., rather useless.
> 
> I would assume that smudge takes care of this somehow, it'd seem
> like a rather useless feature otherwise :).

Sverre was being prophetic with the somehow. Here's a working setup (though I still don't know why not to use luks):

In .gitattributes (or.git/info/a..) use
* filter=gpg diff=gpg
In your config:
[filter "gpg"]
        smudge = gpg -d -q --batch --no-tty
        clean = gpg -ea -q --batch --no-tty -r C920A124
[diff "gpg"]
        textconv = decrypt
This gives you textual diffs even in log! You want use gpg-agent here.

Now for Sverre's prophecy and the helper I haven't shown you yet: It turns out that blobs are not smudged before they are fed to textconv! [Also, it seems that the textconv config does allow parameters, bit I haven't checked thoroughly.]

This means that e.g. when diffing work tree with HEAD textconv is called twice: once is with a smudged file (from the work tree) and once with a cleaned file (from HEAD). That's why I needed a small helper script "decrypt" which does nothing but

#!/bin/sh gpg -d -q --batch --no-tty "$1" || cat $1

Yeah, this assumes gpg errors out because it's fed something unencrypted (and not encrypted with the wrong key) etc. It's only proof of concept quality.

Me thinks it's not right that diff is failing to call smudge here, isn't it?
Michael
Previous: Sverre RabbelierNext: Sverre Rabbelier
Message 7 of 18 in “Transparently encrypt repository contents with GPG”
  1. Matthias NothhaftMar 12, 2009
  2. Sverre RabbelierMar 12, 2009
  3. Michael J GruberMar 13, 2009
  4. Sverre RabbelierMar 13, 2009
  5. Thomas RastMar 13, 2009
  6. Sverre RabbelierMar 13, 2009
  7. Michael J GruberMar 13, 2009
  8. Sverre RabbelierMar 13, 2009
  9. Jeff KingMar 13, 2009
  10. Junio C HamanoMar 13, 2009
  11. Michael J GruberMar 14, 2009
  12. Junio C HamanoMar 14, 2009
  13. Michael J GruberMar 16, 2009
  14. Jeff KingMar 17, 2009
  15. Jeff KingMar 17, 2009
  16. bigbearApr 21, 2012
  17. lalebardeJun 17, 2012
  18. lalebardeJun 18, 2012

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.