git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Commit signing

From
Johannes Schindelin <johannes.schindelin@gmx.de>
Date
Jan 15, 2007, 10:31 UTC
Message-ID
<Pine.LNX.4.63.0701151126540.22628@wbgn013.biozentrum.uni-wuerzburg.de>
In-Reply-To
<20070115101529.GB12257@spearce.org>
Hi,
On Mon, 15 Jan 2007, Shawn O. Pearce wrote:
Show 43 quoted lines
> Andy Parkins <andyparkins@gmail.com> wrote:
> > I was just talking to another developer in my office about version control.  
> > He's working with Windows so has chosen Monotone for a version control 
> > system.  I didn't have any huge objections, as I'm sure monotone can be 
> > migrated to git without much trouble (they look to support the same features 
> > from my brief reading).
> > 
> > Of course my favourite is git, but we were talking about the certificates 
> > needed by monotone for each developer.  I assume that monotone therefore 
> > signs every commit.  It obviously crossed my mind as to how one would do that 
> > with git?  We obviously already have the ability to sign a tag, but is there 
> > a way in which one could sign every commit.
> > 
> > The more I think about it, the more it could be a reasonable question.  In my 
> > own repository I can obviously create whatever commits i like, claiming them 
> > to be from whomever I like just by altering a few config settings.  If I put 
> > a few of those in my own repository and then managed to persuade Junio to 
> > pull from me - wouldn't I have faked commits from another developer?  
> > However, I wouldn't be able to fake a gpg signature.
> 
> You could sign the content of the raw commit and include the signature
> in the payload, much like we do with tags.  E.g.:
> 
> 	tree 4b825dc642cb6eb9a060e54bf8d69288fbee4904
> 	parent 5064201cfd47822e567456fb1d6a76a5e81da800
> 	parent e6987d056595deace8cba91ce0a2524bb91770a9
> 	author Shawn O. Pearce <spearce.org> 1168855184 -0400
> 	committer Shawn O. Pearce <spearce.org> 1168855184 -0400
> 
> 	Merge branch 'branch' into 'master'.
> 
> 	-----BEGIN PGP SIGNATURE-----
> 	Version: GnuPG v1.4.6 (GNU/Linux)
> 
> 	iD8DBQBFiY2zwMbZpPMRm5oRAll0AJ0ZR+Bu8zjMVe8eEKR8Xr+3QMtndACcC2Kl
> 	aWSkKLptN0LAOpDinq+aqOc=
> 	=dZlu
> 	-----END PGP SIGNATURE-----
> 
> But that's horribly ugly and probably vast overkill.  Plus the only
> way to really verify each commit is to have the complete database of
> PGP public keys handy.  A commit-msg hook could probably implement
> the signing.

But it would only sign the _message_. You would have to sign the whole _raw_ commit message, to include also the ancestry. But there is no hook _between_ constructing that _raw_ commit message and actually writing the commit object (this would have to be in builtin-commit-tree.c:151).

Ciao, Dscho

Previous: Daniel BarkalowNext: Shawn O. Pearce
Message 7 of 21 in “Commit signing”
  1. Andy ParkinsJan 15, 2007
  2. Matthias KestenholzJan 15, 2007
  3. Shawn O. PearceJan 15, 2007
  4. Shawn O. PearceJan 15, 2007
  5. Johannes SchindelinJan 15, 2007
  6. Daniel BarkalowJan 15, 2007
  7. Johannes SchindelinJan 15, 2007
  8. Shawn O. PearceJan 15, 2007
  9. Karl HasselströmJan 15, 2007
  10. Andy ParkinsJan 15, 2007
  11. Shawn O. PearceJan 15, 2007
  12. Johannes SchindelinJan 15, 2007
  13. Andy ParkinsJan 15, 2007
  14. Johannes SchindelinJan 15, 2007
  15. Andy ParkinsJan 15, 2007
  16. Martin LanghoffJan 15, 2007
  17. Andy ParkinsJan 15, 2007
  18. Martin LanghoffJan 15, 2007
  19. Johannes SchindelinJan 15, 2007
  20. Jakub NarebskiJan 15, 2007
  21. Jeff KingJan 15, 2007

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.