git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Git-commits mailing list feed.

From
AGAndreas Gal <gal@uci.edu>
Date
Apr 25, 2005, 02:39 UTC
Message-ID
<Pine.LNX.4.58.0504241930480.1394@sam.ics.uci.edu>
In-Reply-To
<200504250417.17231.FabianFranz@gmx.de>

It may sound a little weird, but we could actually store the signature in the inode/filename. GPG signatures seem to be around 80 bytes of ASC, thats well below MAXPATH and should work even if your repository is somewhere/deep/in/your/filesystem/hierarchy.

1. Signed objects are named sha1-sig (sig is a 80 character signature 
here, not the three letters sig).
2. To make sure we can find objects without their signature, there is 
   always a soft link sha1 -> sha1-sig (fsck can check this and create 
   missing links).
3. To find a signature, just follow the link and look at the real name.
4. Files can be distributed without signature (content is unchanged) and
   you can sign them in your local tree with your own signature, 
   effectively throwing my signature away.

The only limitation is that each object can only be signed by one person. On the other hand, this might not be a limitation at all. If I create a file, I sign it. Nobody else. Same goes for trees and commits that I create. You can sign your own commit object when you merge my stuff, and then push that commit object out (along with your co-signature).

Andreas
On Mon, 25 Apr 2005, Fabian Franz wrote:
Show 31 quoted lines
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
> 
> Am Montag, 25. April 2005 03:50 schrieb Linus Torvalds:
> 
> > Maybe we'll just have signed tags by doing exactly that: just a collection
> > of detached signature files. The question becomes one of how to name such
> > things in a distributed tree. That is the thing that using an object for
> > them would have solved very naturally.
> 
> What about just <sha1 hash of object>.sig or <sha1 hash of object>.asc?
> 
> Or would this violate the concept of the object database to just contain 
> hashes?
> 
> cu
> 
> Fabian
> -----BEGIN PGP SIGNATURE-----
> Version: GnuPG v1.2.4 (GNU/Linux)
> 
> iD8DBQFCbFMsI0lSH7CXz7MRAof0AKCILjPE/M72cMSVNDC/DWYSzmrU/ACggOuS
> ogNPwUf2ASAwmbwixzSTuPs=
> =pW5D
> -----END PGP SIGNATURE-----
> 
> -
> To unsubscribe from this list: send the line "unsubscribe git" in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at  http://vger.kernel.org/majordomo-info.html
> 
Previous: Fabian FranzNext: Linus Torvalds
Message 28 of 55 in “Re: Git-commits mailing list feed.”
  1. David WoodhouseApr 21, 2005
  2. Linus TorvaldsApr 23, 2005
  3. Linus TorvaldsApr 23, 2005
  4. Fabian FranzApr 23, 2005
  5. Andreas GalApr 23, 2005
  6. SeanApr 23, 2005
  7. Thomas GlanzmannApr 23, 2005
  8. SeanApr 23, 2005
  9. Linus TorvaldsApr 23, 2005
  10. Thomas GlanzmannApr 23, 2005
  11. Linus TorvaldsApr 23, 2005
  12. SeanApr 23, 2005
  13. Linus TorvaldsApr 23, 2005
  14. SeanApr 23, 2005
  15. Linus TorvaldsApr 23, 2005
  16. Junio C HamanoApr 23, 2005
  17. Linus TorvaldsApr 23, 2005
  18. Junio C HamanoApr 23, 2005
  19. Paul JakmaApr 24, 2005
  20. Paul JakmaApr 24, 2005
  21. David A. WheelerApr 25, 2005
  22. Paul JakmaApr 25, 2005
  23. David A. WheelerApr 25, 2005
  24. Paul JakmaApr 25, 2005
  25. Paul JakmaApr 25, 2005
  26. Linus TorvaldsApr 25, 2005
  27. Fabian FranzApr 25, 2005
  28. Andreas GalApr 25, 2005
  29. Linus TorvaldsApr 25, 2005
  30. David A. WheelerApr 25, 2005
  31. David GreavesApr 25, 2005
  32. David A. WheelerApr 25, 2005
  33. Paul JakmaApr 25, 2005
  34. Paul JakmaApr 25, 2005
  35. Paul JakmaApr 25, 2005
  36. New option (-H) for rpush/rpull to update HEADAndreas Gal, Apr 25, 2005
  37. Daniel BarkalowApr 25, 2005
  38. Andreas GalApr 25, 2005
  39. Daniel BarkalowApr 25, 2005
  40. Matt DomschApr 25, 2005
  41. Jan HarkesApr 25, 2005
  42. Thomas GlanzmannApr 23, 2005
  43. Thomas GlanzmannApr 23, 2005
  44. Jan HarkesApr 23, 2005
  45. Linus TorvaldsApr 23, 2005
  46. Junio C HamanoApr 23, 2005
  47. Jan HarkesApr 23, 2005
  48. Linus TorvaldsApr 23, 2005
  49. Jan HarkesApr 23, 2005
  50. Git transfer protocols (was: Re: Git-commits mailing list feed)Mike Taht, Apr 23, 2005
  51. Jan HarkesApr 23, 2005
  52. Linus TorvaldsApr 23, 2005
  53. Suggestion: generalize signed tags into "assertion objects"David A. Wheeler, Apr 23, 2005
  54. Jeff GarzikApr 23, 2005
  55. David WoodhouseApr 25, 2005

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.