git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: upstreaming https://github.com/cgwalters/git-evtag ?

From
Stefan Beller <sbeller@google.com>
Date
Jan 8, 2018, 20:49 UTC
Message-ID
<CAGZ79kZ8AXezcX1_5WJsUJMHiHCzj2B=Uj8+4K3VF+cC6mTCqA@mail.gmail.com>
In-Reply-To
<20180108204029.m42qyezojak4kohh@LykOS.localdomain>
On Mon, Jan 8, 2018 at 12:40 PM, Santiago Torres <santiago@nyu.edu> wrote:
Show 9 quoted lines
> Hi,
>
> I personally like the idea of git-evtags, but I feel that they could be
> made so that push certificates (and being hash-algorithm agnostic)
> should provide the same functionality with less code.
>
> To me, a git evtag is basically a signed tag + a data structure similar
> to a push certificate embedded in it. I wonder if, with the current
> tooling in git, this could be done as a custom command...

In that case, why not migrate Git to a new hash function instead of adding a very niche fixup?

See Documentation/technical/hash-function-transition.txt for how to do it.

Personally I'd dislike to include ev-tags as it might send a signal of "papering over sha1 issues instead of fixing it".

push certificates are somewhat underdocumented, see the
git-push man page, which contains
       --[no-]signed, --signed=(true|false|if-asked)
           GPG-sign the push request to update refs on the
           receiving side, to allow it to be checked by the
           hooks and/or be logged. If false or --no-signed, no
           signing will be attempted. If true or --signed, the
           push will fail if the server does not support signed
           pushes. If set to if-asked, sign if and only if the
           server supports signed pushes. The push will also
           fail if the actual call to gpg --sign fails. See git-
           receive-pack(1) for the details on the receiving end.
Going to receive-pack(1), there is an excerpt:
      When accepting a signed push (see git-push(1)), the
       signed push certificate is stored in a blob and an
       environment variable GIT_PUSH_CERT can be consulted for
       its object name. See the description of post-receive hook
       for an example. In addition, the certificate is verified
       using GPG and the result is exported with the following
       environment variables:
...
Stefan
Previous: Santiago TorresNext: Santiago Torres
Message 6 of 11 in “upstreaming https://github.com/cgwalters/git-evtag ?”
  1. Colin WaltersJan 8, 2018
  2. Johannes SchindelinJan 8, 2018
  3. Santiago TorresJan 8, 2018
  4. Colin WaltersJan 8, 2018
  5. Santiago TorresJan 8, 2018
  6. Stefan BellerJan 8, 2018
  7. Santiago TorresJan 8, 2018
  8. Colin WaltersJan 9, 2018
  9. Santiago TorresJan 9, 2018
  10. Jonathan NiederJan 9, 2018
  11. Santiago TorresJan 10, 2018

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.