Re: [PATCH v3 5/5] fast-import: add '--signed-tags=<mode>' option
- From
Christian Couder <christian.couder@gmail.com>
- Date
- Oct 24, 2025, 09:27 UTC
- Message-ID
- <CAP8UFD01-JDZisaqMUEGd7-WJ29r0eLcXuV3RjqeWNtoJ3-QmA@mail.gmail.com>
- In-Reply-To
- <CABPp-BGQ=3Tuik-PCerkaK4R0b1roSVLXLKs2-+E11vDrH6WaQ@mail.gmail.com>
On Fri, Oct 24, 2025 at 4:04 AM Elijah Newren <newren@gmail.com> wrote:
> > On Mon, Oct 13, 2025 at 4:49 AM Christian Couder > <christian.couder@gmail.com> wrote:
Show 16 quoted lines
> > +--signed-tags=(verbatim|warn-verbatim|warn-strip|strip|abort):: > > + Specify how to handle signed tags. Behaves in the same way > > + as the same option in linkgit:git-fast-export[1], except that > > + default is 'verbatim' (instead of 'abort'). > > Sorry for not catching this earlier with the --signed-commits series > (was otherwise occupied), but this worries me. If we ship with this > as the default, people will come to depend upon it, and I think it's a > bad long term default. Long term, we'd want to check if the > signatures are valid and keep if so and do something else if not (e.g. > re-sign or abort or strip). Maybe verbatim is better than abort out > of the options you've implemented so far, but I think setting the > default now to verbatim means people start depending on it and we > cannot change it later. Could we change to 'abort', for both this and > --signed-commits, before the 2.52 release, and then re-discuss once > you have the other options implemented?
"verbatim" was already the default long before this patch series. Any tag signature was copied as-is, as part of the tag message. So it's possible that users have relied on this for a long time.
For the --signed-commits series, "verbatim" was also the default before the series. Even if importing commit signatures has been implemented more recently and even if this is marked as experimental, it's the default in Git 2.51. So regular users could already rely on it.
The --signed-commits series has been merged to 'master' and this series has recently been merged to 'next'. They aren't part of a release, but at this point I think we should send separate patches to change the default if we want to do that.
As I plan to work soon on the new modes that would check signatures and do something based on that, and as you say that it would likely be better if such a new mode becomes the default, I am reluctant to change the default mode right now, only to have to change it again hopefully in a few weeks or months. If you want to do it, then feel free to send patches changing the default though.
> This all looks good to me, other than the default as noted above.
Thanks for your review.