git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 3/3] fast-export, fast-import: implement signed-commits

From
Luke Shumaker <lukeshu@lukeshu.com>
Date
Apr 21, 2021, 22:03 UTC
Message-ID
<87eef32t3q.wl-lukeshu@lukeshu.com>
In-Reply-To
<YH9enUedtHjE87ET@camp.crustytoothpaste.net>

On Tue, 20 Apr 2021 17:07:09 -0600, brian m. carlson wrote:

Show 15 quoted lines
> On 2021-04-20 at 17:15:25, Luke Shumaker wrote:
> > I don't believe that's true?  With SHA-1-signed tags, the signature
> > gets included in the fast-import stream as part of the tag message
> > (the `data` line in the BNF).  Since SHA-256-signed tags have their
> > signature as a header (rather than just appending it to the message),
> > we'd have to add a 'gpgsig' sub-command to the 'tag' top-level-command
> > (like I've done to the 'commit' top-level-command).
> 
> If you're using a repository that's SHA-1, then the tag signature that's
> part of the message is a signature over the SHA-1 contents of the
> object, and the gpgsig-sha256 header is a signature over the SHA-256
> contents of the object.  If you're using a repository that's SHA-256,
> it's reversed: the signature at the end of the message covers the
> SHA-256 contents of the object and the gpgsig header covers the SHA-1
> contents.

Good to know! It seems I've been mislead by Documentation/technical/hash-function-transition.txt

> Not implementing this means the CI will fail when the testsuite is run
> in SHA-256 mode, so your patch probably won't be accepted.

Gotcha. I guess I will be implementing it then. I'll let you know if I have any further questions, the information you've given already has been very helpful!

-- 
Happy hacking,
~ Luke Shumaker
Previous: brian m. carlsonNext: Taylor Blau
Message 10 of 15 in “fast-export, fast-import: implement signed-commits”
  1. 0/3 fast-export, fast-import: implement signed-commitsLuke Shumaker, Apr 19, 2021
  2. 1/3 git-fast-import.txt: add missing LF in the BNFLuke Shumaker, Apr 19, 2021
  3. 2/3 fast-export: rename --signed-tags='warn' to 'warn-verbatim'Luke Shumaker, Apr 19, 2021
  4. Taylor BlauApr 20, 2021
  5. Luke ShumakerApr 20, 2021
  6. 3/3 fast-export, fast-import: implement signed-commitsLuke Shumaker, Apr 19, 2021
  7. brian m. carlsonApr 20, 2021
  8. Luke ShumakerApr 20, 2021
  9. brian m. carlsonApr 20, 2021
  10. Luke ShumakerApr 21, 2021
  11. Taylor BlauApr 20, 2021
  12. Luke ShumakerApr 20, 2021
  13. Luke ShumakerApr 20, 2021
  14. Elijah NewrenApr 21, 2021
  15. Luke ShumakerApr 21, 2021

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.