git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Commit signing

From
Johannes Schindelin <johannes.schindelin@gmx.de>
Date
Jan 15, 2007, 11:08 UTC
Message-ID
<Pine.LNX.4.63.0701151201100.22628@wbgn013.biozentrum.uni-wuerzburg.de>
In-Reply-To
<20070115105616.GE12257@spearce.org>
Hi,
On Mon, 15 Jan 2007, Shawn O. Pearce wrote:
Show 14 quoted lines
> Andy Parkins <andyparkins@gmail.com> wrote:
> 
> > I don't think the argument that Matthias offered ("You just explained 
> > why no one should pull from people he does not trust.") is a good one.  
> > One might not want trust to be transitive.  Just because I trust you, 
> > doesn't not mean that I trust those who you trust.  The path of 
> > getting commits in via a trusted person, perhaps even via multiple 
> > levels of transitive trust might not be something that is wanted in 
> > every project.  Having signed commits would at least give the option.
> 
> Yes, that's very valid.  But if you trust me and I've gone and built 100 
> commits on top of something I got from someone else I trust but that you 
> don't trust, you are going to reject all of my changes and ask that I 
> rewrite them?  That's quite paranoid.
It is not only paranoid. It is bad practice.

We might be tempted to forget in these horrible times that distrust itself is a perpetuum mobile. Distrust results in distrust. And nobody being distrusted likes that fact. It makes for a bad working environment, for less code quality, and quite often, people get ideas from being distrusted: "If they think I could include a backdoor, well, that might actually be a good idea!".

Please have a look at the Linux kernel development, or for that matter, git development itself. Here, people care, people trust, people respect each other (sometimes YELLING, to keep discussions exciting). And the result is: nice code.

Ciao, Dscho

Previous: Shawn O. PearceNext: Andy Parkins
Message 12 of 21 in “Commit signing”
  1. Andy ParkinsJan 15, 2007
  2. Matthias KestenholzJan 15, 2007
  3. Shawn O. PearceJan 15, 2007
  4. Shawn O. PearceJan 15, 2007
  5. Johannes SchindelinJan 15, 2007
  6. Daniel BarkalowJan 15, 2007
  7. Johannes SchindelinJan 15, 2007
  8. Shawn O. PearceJan 15, 2007
  9. Karl HasselströmJan 15, 2007
  10. Andy ParkinsJan 15, 2007
  11. Shawn O. PearceJan 15, 2007
  12. Johannes SchindelinJan 15, 2007
  13. Andy ParkinsJan 15, 2007
  14. Johannes SchindelinJan 15, 2007
  15. Andy ParkinsJan 15, 2007
  16. Martin LanghoffJan 15, 2007
  17. Andy ParkinsJan 15, 2007
  18. Martin LanghoffJan 15, 2007
  19. Johannes SchindelinJan 15, 2007
  20. Jakub NarebskiJan 15, 2007
  21. Jeff KingJan 15, 2007

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.