git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Transparently encrypt repository contents with GPG

From
Junio C Hamano <gitster@pobox.com>
Date
Mar 13, 2009, 20:23 UTC
Message-ID
<7vy6v9f9zn.fsf@gitster.siamese.dyndns.org>
In-Reply-To
<49BA6606.1070403@fastmail.fm>
Michael J Gruber <michaeljgruber+gmane@fastmail.fm> writes:
Show 13 quoted lines
> In .gitattributes (or.git/info/a..) use
>
> * filter=gpg diff=gpg
>
> In your config:
>
> [filter "gpg"]
>         smudge = gpg -d -q --batch --no-tty
>         clean = gpg -ea -q --batch --no-tty -r C920A124
> [diff "gpg"]
>         textconv = decrypt
>
> This gives you textual diffs even in log! You want use gpg-agent here.
Don't do this.
Think why the smudge/clean pair exists.

The version controlled data, the contents, may not be suitable for consumption in the work tree in its verbatim form. For example, a cross platform project would want to consistently use LF line termination inside a repository, but on a platform whose tools expect CRLF line endings, the contents cannot be used verbatim. We "smudge" the contents running unix2dos when checking things out on such platforms, and "clean" the platform specific CRLF line endings by running dos2unix when checking things in. By doing so, you can see what really got changed between versions without getting distracted, and more importantly, "you" in this sentence is not limited to the human end users alone.

git internally runs diff and xdelta to see what was changed, so that:
 * it can reduce storage requirement when it runs pack-objects;
 * it can check what path in the preimage was similar to what other path
   in the postimage, to deduce a rename;
 * it can check what blocks of lines in the postimage came from what other
   blocks of lines in the preimage, to pass blames across file boundaries.

If your "clean" encrypts and "smudge" decrypts, it means you are refusing all the benifit git offers. You are making a pair of similar "smudged" contents totally dissimilar in their "clean" counterparts. That is simply backwards.

As the sole raison d'etre of diff.textconv is to allow potentially lossy conversion (e.g. msword-to-text) applied to the preimage and postimage pair of contents (that are supposed to be "clean") before giving a textual diff to human consumption, the above config may appear to work, but if you really want an encrypted repository, you should be using an encrypting filesystem. That would give an added benefit that the work tree associated with your repository would also be encrypted.

Previous: Jeff KingNext: Michael J Gruber
Message 10 of 18 in “Transparently encrypt repository contents with GPG”
  1. Matthias NothhaftMar 12, 2009
  2. Sverre RabbelierMar 12, 2009
  3. Michael J GruberMar 13, 2009
  4. Sverre RabbelierMar 13, 2009
  5. Thomas RastMar 13, 2009
  6. Sverre RabbelierMar 13, 2009
  7. Michael J GruberMar 13, 2009
  8. Sverre RabbelierMar 13, 2009
  9. Jeff KingMar 13, 2009
  10. Junio C HamanoMar 13, 2009
  11. Michael J GruberMar 14, 2009
  12. Junio C HamanoMar 14, 2009
  13. Michael J GruberMar 16, 2009
  14. Jeff KingMar 17, 2009
  15. Jeff KingMar 17, 2009
  16. bigbearApr 21, 2012
  17. lalebardeJun 17, 2012
  18. lalebardeJun 18, 2012

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.