Re: [git patches] libata updates, GPG signed (but see admin notes)
- From
- H. Peter Anvin <hpa@zytor.com>
- Date
- Nov 1, 2011, 00:42 UTC
- Message-ID
- <4EAF4091.2010205@zytor.com>
- In-Reply-To
- <4EAF3556.3000001@garzik.org>
Show 11 quoted lines
> > The main worry is Linus ($human_who_pulls) gets > cryptographically-verified data at the time he pulls. Once Linus > republishes his tree (git push), there will be few, if any, wanting to > verify Jeff Garzik's signature. > > So no, I don't see that as a _driving_ need in the kernel's case. > > And IMO the kernel will be a mix of signed and unsigned content for a > while, possibly forever. >
I think the desire is to be able to deconstruct things if things were to go wrong.
-hpa
-- H. Peter Anvin, Intel Open Source Technology Center I work for Intel. I don't speak on their behalf.