git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] doc: clarify distinction between sign-off and pgp-signing

From
Philip Oakley <philipoakley@iee.org>
Date
Jan 27, 2017, 21:44 UTC
Message-ID
<F290D7175C2C4E728A7A3C767F5B80BF@PhilipOakley>
In-Reply-To
<CAGZ79kb29usw4WyMdy3c5-rGH1nEcQ1gUabzdAtGgOW9zfTCDA@mail.gmail.com>
From: "Stefan Beller" <sbeller@google.com>
Show 42 quoted lines
> On Fri, Jan 27, 2017 at 12:01 PM,  <cornelius.weig@tngtech.com> wrote:
>> From: Cornelius Weig <cornelius.weig@tngtech.com>
>>
>> The documentation for submission discourages pgp-signing, but demands
>> a proper sign-off by contributors. However, when skimming the headings,
>> the wording of the section for sign-off could mistakenly be understood
>> as concerning pgp-signing. Thus, new contributors could oversee the
>> necessary sign-off.
>>
>> This commit improves the wording such that the section about sign-off
>> cannot be misunderstood as pgp-signing. In addition, the paragraph about
>> pgp-signing is changed such that it avoids the impression that
>> pgp-signing could be relevant at later stages of the submission.
>>
>> Signed-off-by: Cornelius Weig <cornelius.weig@tngtech.com>
>> Signed-off-by: Junio C Hamano <gitster@pobox.com>
>> Signed-off-by: Philip Oakley <philipoakley@iee.org>
>> Signed-off-by: Stefan Beller <sbeller@google.com>
>> ---
>>
>> Notes:
>>     This patch summarizes the suggested changes.
>>
>>     As I don't know what is appropriate, I took the liberty to add 
>> everybody's
>>     sign-off who was involved in the discussion in alphabetic order.
>
> Heh, my first though was to conclude you haven't read the
> sign off part, yet apart from the changed header.
> /me goes back and actually reads the DCO again.
> And actually these sign offs were there in other patches in this area,
> so you'd claim (a) that yours was just created partly by you and having
> other patches that were also signed off (b), whose sign offs you
> merely copy over to here.
>
> And then after reading I realized I slightly confused the signing
> myself as the sign offs are also used to track the flow of a patch.
> These sign offs suggest that you made the patch initially, then
> passed it to Junio, then to Philip and then to me.
> And Junio will sign it again when applying the patch.
>
> So maybe s/signed-off-by/helped-by/?
Helped-by: Philip Oakley <philipoakley@iee.org>
is sufficient for me (if that).
Show 50 quoted lines
>
> The patch with the aggregation looks good to me.
>
> Thanks,
> Stefan
>
>>
>>  Documentation/SubmittingPatches | 13 ++++++-------
>>  1 file changed, 6 insertions(+), 7 deletions(-)
>>
>> diff --git a/Documentation/SubmittingPatches 
>> b/Documentation/SubmittingPatches
>> index 08352de..3faf7eb 100644
>> --- a/Documentation/SubmittingPatches
>> +++ b/Documentation/SubmittingPatches
>> @@ -216,12 +216,11 @@ that it will be postponed.
>>  Exception:  If your mailer is mangling patches then someone may ask
>>  you to re-send them using MIME, that is OK.
>>
>> -Do not PGP sign your patch, at least for now.  Most likely, your
>> -maintainer or other people on the list would not have your PGP
>> -key and would not bother obtaining it anyway.  Your patch is not
>> -judged by who you are; a good patch from an unknown origin has a
>> -far better chance of being accepted than a patch from a known,
>> -respected origin that is done poorly or does incorrect things.
>> +Do not PGP sign your patch. Most likely, your maintainer or other people 
>> on the
>> +list would not have your PGP key and would not bother obtaining it 
>> anyway.
>> +Your patch is not judged by who you are; a good patch from an unknown 
>> origin
>> +has a far better chance of being accepted than a patch from a known, 
>> respected
>> +origin that is done poorly or does incorrect things.
>>
>>  If you really really really really want to do a PGP signed
>>  patch, format it as "multipart/signed", not a text/plain message
>> @@ -246,7 +245,7 @@ patch.
>>       *2* The mailing list: git@vger.kernel.org
>>
>>
>> -(5) Sign your work
>> +(5) Certify your work by adding your "Signed-off-by: " line
>>
>>  To improve tracking of who did what, we've borrowed the
>>  "sign-off" procedure from the Linux kernel project on patches
>> --
>> 2.10.2
>>
> 
Previous: Stefan Beller
Message 7 of 7 in “doc: clarify distinction between sign-off and pgp-signing”
  1. doc: clarify distinction between sign-off and pgp-signingcornelius.weig@tngtech.com, Jan 27, 2017
  2. Cornelius WeigJan 27, 2017
  3. Junio C HamanoJan 27, 2017
  4. Stefan BellerJan 27, 2017
  5. Cornelius WeigJan 27, 2017
  6. Stefan BellerJan 27, 2017
  7. Philip OakleyJan 27, 2017

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.