git/list[1] front-page[2] threads[3] people[4] search[5] about
wed 2026-10-07 17:26 UTC

Re: [PATCH v2 3/3] fast-import: add mode to re-sign invalid commit signatures

From
Christian Couder <christian.couder@gmail.com>
Date
Mar 10, 2026, 09:27 UTC
Message-ID
<CAP8UFD3p84U0FhjGXNqagtDi=Cd3+QBHqGb3_ceWy-tdeLc43g@mail.gmail.com>
In-Reply-To
<20260306205359.1723254-4-jltobler@gmail.com>
On Fri, Mar 6, 2026 at 9:54 PM Justin Tobler <jltobler@gmail.com> wrote:
Show 5 quoted lines
> @@ -825,6 +825,9 @@ static void handle_commit(struct commit *commit, struct rev_info *rev,
>                 case SIGN_STRIP_IF_INVALID:
>                         die(_("'strip-if-invalid' is not a valid mode for "
>                               "git fast-export with --signed-commits=<mode>"));
> +               case SIGN_RESIGN_IF_INVALID:

Everywhere in this patch, I think "RE_SIGN" might be more consistent than "RESIGN" for this name.

> +                       die(_("'re-sign-if-invalid' is not a valid mode for "
> +                             "git fast-export with --signed-commits=<mode>"));
[...]
Show 36 quoted lines
> @@ -2856,15 +2858,52 @@ static void handle_strip_if_invalid(struct strbuf *new_data,
>                 const char *subject;
>                 int subject_len = find_commit_subject(msg->buf, &subject);
>
> -               if (subject_len > 100)
> -                       warning(_("stripping invalid signature for commit '%.100s...'\n"
> -                                 "  allegedly by %s"), subject, signer);
> -               else if (subject_len > 0)
> -                       warning(_("stripping invalid signature for commit '%.*s'\n"
> -                                 "  allegedly by %s"), subject_len, subject, signer);
> -               else
> -                       warning(_("stripping invalid signature for commit\n"
> -                                 "  allegedly by %s"), signer);
> +               if (mode == SIGN_STRIP_IF_INVALID) {
> +                       if (subject_len > 100)
> +                               warning(_("stripping invalid signature for commit '%.100s...'\n"
> +                                         "  allegedly by %s"), subject, signer);
> +                       else if (subject_len > 0)
> +                               warning(_("stripping invalid signature for commit '%.*s'\n"
> +                                         "  allegedly by %s"), subject_len, subject, signer);
> +                       else
> +                               warning(_("stripping invalid signature for commit\n"
> +                                         "  allegedly by %s"), signer);
> +               } else if (mode == SIGN_RESIGN_IF_INVALID) {
> +                       struct strbuf signature = STRBUF_INIT;
> +                       struct strbuf payload = STRBUF_INIT;
> +
> +                       if (subject_len > 100)
> +                               warning(_("re-signing invalid signature for commit '%.100s...'\n"
> +                                         "  allegedly by %s"), subject, signer);
> +                       else if (subject_len > 0)
> +                               warning(_("re-signing invalid signature for commit '%.*s'\n"
> +                                         "  allegedly by %s"), subject_len, subject, signer);
> +                       else
> +                               warning(_("re-signing invalid signature for commit\n"
> +                                         "  allegedly by %s"), signer);
Maybe a helper function could be used to avoid duplicating the warning logic.
Show 5 quoted lines
> +                       /*
> +                        * NEEDSWORK: To properly support interoperability mode
> +                        * when re-signing commit signatures, the commit buffer
> +                        * must be provided in both the repository and
> +                        * compatability object formats. As currently
s/compatability/compatibility/
> +                        * implemented, only the repository object format is
> +                        * considered meaning compatability signatures cannot be
s/compatability/compatibility/
Show 15 quoted lines
> +                        * generated. Thus, attempting to re-sign commit
> +                        * signatures in interoperability mode is currently
> +                        * unsupported.
> +                        */
> +                       if (the_repository->compat_hash_algo)
> +                               die(_("re-signing signatures in interoperability mode is unsupported"));
> +
> +                       strbuf_addstr(&payload, signature_check.payload);
> +                       if (sign_buffer_with_key(&payload, &signature, signed_commit_keyid))
> +                               die(_("failed to sign commit object"));
> +                       add_header_signature(new_data, &signature, the_hash_algo);
> +
> +                       strbuf_release(&signature);
> +                       strbuf_release(&payload);
> +               }

Except for these small issues and the few nits in the previous patch, this looks good to me. Thanks for working on it.

Previous: Christian CouderNext: Justin Tobler
Message 16 of 60 in “fast-import: add mode to re-sign invalid commit signatures”
  1. 0/2 fast-import: add mode to re-sign invalid commit signaturesJustin Tobler, Feb 23, 2026
  2. 1/2 commit: remove unused forward declarationJustin Tobler, Feb 23, 2026
  3. 2/2 fast-import: add mode to re-sign invalid commit signaturesJustin Tobler, Feb 23, 2026
  4. Patrick SteinhardtFeb 24, 2026
  5. Patrick SteinhardtFeb 24, 2026
  6. Christian CouderFeb 24, 2026
  7. Justin ToblerFeb 24, 2026
  8. brian m. carlsonFeb 24, 2026
  9. Junio C HamanoFeb 24, 2026
  10. Justin ToblerMar 2, 2026
  11. 1/3 commit: remove unused forward declarationJustin Tobler, Mar 6, 2026
  12. 0/3 fast-import: add mode to re-sign invalid commit signaturesJustin Tobler, Mar 6, 2026
  13. 2/3 gpg-interface: introduce sign_buffer_with_key()Justin Tobler, Mar 6, 2026
  14. 3/3 fast-import: add mode to re-sign invalid commit signaturesJustin Tobler, Mar 6, 2026
  15. Christian CouderMar 10, 2026
  16. Christian CouderMar 10, 2026
  17. Justin ToblerMar 10, 2026
  18. Justin ToblerMar 10, 2026
  19. 0/3 fast-import: add mode to re-sign invalid commit signaturesJustin Tobler, Mar 10, 2026
  20. 1/3 commit: remove unused forward declarationJustin Tobler, Mar 10, 2026
  21. 2/3 gpg-interface: introduce sign_buffer_with_key()Justin Tobler, Mar 10, 2026
  22. 3/3 fast-import: add mode to re-sign invalid commit signaturesJustin Tobler, Mar 10, 2026
  23. Junio C HamanoMar 10, 2026
  24. Justin ToblerMar 10, 2026
  25. Junio C HamanoMar 10, 2026
  26. Justin ToblerMar 10, 2026
  27. Junio C HamanoMar 10, 2026
  28. Junio C HamanoMar 10, 2026
  29. Junio C HamanoMar 10, 2026
  30. Justin ToblerMar 10, 2026
  31. 0/3 fast-import: add mode to re-sign invalid commit signaturesJustin Tobler, Mar 11, 2026
  32. 1/3 commit: remove unused forward declarationJustin Tobler, Mar 11, 2026
  33. 2/3 gpg-interface: introduce sign_buffer_with_key()Justin Tobler, Mar 11, 2026
  34. 3/3 fast-import: add mode to sign commits with invalid signaturesJustin Tobler, Mar 11, 2026
  35. Patrick SteinhardtMar 12, 2026
  36. Patrick SteinhardtMar 12, 2026
  37. Justin ToblerMar 12, 2026
  38. Justin ToblerMar 12, 2026
  39. Patrick SteinhardtMar 12, 2026
  40. Justin ToblerMar 12, 2026
  41. 0/3 fast-import: add mode to re-sign invalid commit signaturesJustin Tobler, Mar 12, 2026
  42. 1/3 commit: remove unused forward declarationJustin Tobler, Mar 12, 2026
  43. 2/3 gpg-interface: allow sign_buffer() to use default signing keyJustin Tobler, Mar 12, 2026
  44. 3/3 fast-import: add mode to sign commits with invalid signaturesJustin Tobler, Mar 12, 2026
  45. Junio C HamanoMar 12, 2026
  46. Junio C HamanoMar 12, 2026
  47. Junio C HamanoMar 12, 2026
  48. Justin ToblerMar 12, 2026
  49. Justin ToblerMar 12, 2026
  50. Justin ToblerMar 12, 2026
  51. Jeff KingMar 12, 2026
  52. Justin ToblerMar 13, 2026
  53. 0/3 fast-import: add mode to re-sign invalid commit signaturesJustin Tobler, Mar 13, 2026
  54. 1/3 commit: remove unused forward declarationJustin Tobler, Mar 13, 2026
  55. 2/3 gpg-interface: allow sign_buffer() to use default signing keyJustin Tobler, Mar 13, 2026
  56. 3/3 fast-import: add mode to sign commits with invalid signaturesJustin Tobler, Mar 13, 2026
  57. Junio C HamanoMar 13, 2026
  58. Patrick SteinhardtMar 13, 2026
  59. Patrick SteinhardtMar 13, 2026
  60. Patrick SteinhardtMar 13, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.