git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 0/3] fast-import: add 'strip-if-invalid' mode to --signed-commits=<mode>

From
Christian Couder <christian.couder@gmail.com>
Date
Nov 12, 2025, 07:19 UTC
Message-ID
<CAP8UFD1YqadtkYriePJKUBjzhXAyYjNEk-9rj55ZxbGLRAOd2g@mail.gmail.com>
In-Reply-To
<xmqqjz04mtji.fsf@gitster.g>
On Wed, Nov 5, 2025 at 3:40 PM Junio C Hamano <gitster@pobox.com> wrote:
Show 14 quoted lines
>
> Christian Couder <christian.couder@gmail.com> writes:
>
> > The `--signed-commits=<mode>` option in `git fast-import` allows users
> > to decide what should be done when commits with signatures are
> > imported.
> >
> > For tools like `git filter-repo`, it would be useful to be able to
> > strip signatures when they are invalid, so let's add a new
> > 'strip-if-invalid' mode for that purpose.
>
> Sorry, but I do not get it.  What is your definition of a signature
> being "invalid", and what is your assumptions of how accurate a
> validity check ought to be?

The definition of "valid" is the same as the definition used by `git verify-commit`. The description of this command is:

"Validates the GPG signature created by `git commit -S` on the commit objects given on the command line."

Here we just also "validate" commit signatures in the same way and using the same underlying code. If `git verify-commit` would return 0, we consider the commit signature valid, otherwise we consider it invalid.

I will add such clarification to the documentation of the feature in the v2 I plan to send soon.

> For example, are you assuming that you
> have all the necessary public keys, revocation data and accurate
> clock?
Yes, we assume all that, like `git verify-commit` assumes it has all that too.

If we want to be clearer about what is needed to make sure that commit signatures can be properly validated, I think we should start with working on `git verify-commit` and improve its related documentation, and perhaps even some of its features. It would be simpler to have all the docs and features about this there, and just refer to that command (using for example "see git-verify-commit(1)") in other places. Such `git verify-commit` improvements could be in a separate patch series though.

Or maybe there is a better place, like perhaps the `git tag` documentation, or a dedicated gitsignature(7) page, where all the information about tag and commit signatures could be. Anyway such improvements could also be in a separate series.

Show 7 quoted lines
> Even if you are not changing a single bit in the import,
> some of your early commits' signatures do not "validate" and may
> need to be stripped, and after that happens, wouldn't signatures of
> all later commits become unusable (i.e, you may be able to verify
> that the signature on the original commit object may still be valid,
> but because the commit has to become a child of a rewritten commit,
> in the resulting history the signature would no longer match)?

Yes, I agree it could be an optimization to consider all the subsequent signatures invalid after one of them is invalid, but it would require making sure that the commit history that `git fast-import` receives is completely linear or that we properly track commit history when it's not not linear. I think it's better to start with a relatively simpler implementation like this one though.

Previous: Christian CouderNext: Junio C Hamano
Message 11 of 20 in “fast-import: add 'strip-if-invalid' mode to --signed-commits=<mode>”
  1. 0/3 fast-import: add 'strip-if-invalid' mode to --signed-commits=<mode>Christian Couder, Nov 5, 2025
  2. 1/3 fast-import: refactor finalize_commit_buffer()Christian Couder, Nov 5, 2025
  3. 2/3 commit: refactor verify_commit_buffer()Christian Couder, Nov 5, 2025
  4. 3/3 fast-import: add 'strip-if-invalid' mode to --signed-commits=<mode>Christian Couder, Nov 5, 2025
  5. Junio C HamanoNov 8, 2025
  6. Christian CouderNov 12, 2025
  7. Junio C HamanoNov 12, 2025
  8. Junio C HamanoNov 5, 2025
  9. Elijah NewrenNov 8, 2025
  10. Christian CouderNov 12, 2025
  11. Christian CouderNov 12, 2025
  12. Junio C HamanoNov 12, 2025
  13. 0/3 fast-import: add 'strip-if-invalid' mode to --signed-commits=<mode>Christian Couder, Nov 17, 2025
  14. 1/3 fast-import: refactor finalize_commit_buffer()Christian Couder, Nov 17, 2025
  15. 2/3 commit: refactor verify_commit_buffer()Christian Couder, Nov 17, 2025
  16. 3/3 fast-import: add 'strip-if-invalid' mode to --signed-commits=<mode>Christian Couder, Nov 17, 2025
  17. Elijah NewrenNov 17, 2025
  18. Christian CouderNov 18, 2025
  19. Junio C HamanoNov 18, 2025
  20. Elijah NewrenNov 18, 2025

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.