git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: git "tag" objects implemented - and a re-done commit

From
Linus Torvalds <torvalds@osdl.org>
Date
Apr 27, 2005, 15:37 UTC
Message-ID
<Pine.LNX.4.58.0504270833210.18901@ppc970.osdl.org>
In-Reply-To
<pan.2005.04.27.03.36.51.65390@smurf.noris.de>
On Wed, 27 Apr 2005, Matthias Urlichs wrote:
Show 9 quoted lines
>
> Hi, Linus Torvalds wrote:
> 
> > And if two different developers tag exactly the same object with exactly 
> > the same tag-name and exactly the same signature, then they get the same 
> > tag object, and that's fine. They should.
> 
> ... except that they can't. I mean, the signature is done by different
> people at different times, so it can't well be identical.

You'd quite possibly use some shared secret key for some work. For example, say you're a company, and any "release person" can sign the work..

Also, since you can tag things without signing anything at all, it's even more trivial to get the same tag that way.

Signing tags really makes sense when you want somebody _else_ to trust it. But unsigned tags are perfectly practical from a _private_ perspective: let's say that you just want to remember certain events but you don't need to tell anybody else about them - what you'd do is to just create your own local tag, and there's no real reason to sign it, since you'll never tell anybody else about it anyway.

(One such thing could be to create a tag every time you compile and install a new kernel: your "tag" is just a way to remember what your installed kernel was built against, and is meaningless to anybody else. In fact, you might well decide to just remove such tags periodically).

		Linus
Previous: Matthias UrlichsNext: H. Peter Anvin
Message 10 of 14 in “git "tag" objects implemented - and a re-done commit”
  1. Linus TorvaldsApr 25, 2005
  2. Andreas GalApr 25, 2005
  3. Linus TorvaldsApr 25, 2005
  4. Andreas GalApr 25, 2005
  5. Linus TorvaldsApr 25, 2005
  6. Linus TorvaldsApr 25, 2005
  7. SeanApr 26, 2005
  8. Ryan AndersonApr 26, 2005
  9. Matthias UrlichsApr 27, 2005
  10. Linus TorvaldsApr 27, 2005
  11. H. Peter AnvinApr 25, 2005
  12. Linus TorvaldsApr 25, 2005
  13. Petr BaudisApr 25, 2005
  14. Linus TorvaldsApr 25, 2005

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.