git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] request-pull: filter out SSH/X.509 tag signatures

From
Gwyneth Morgan <gwymor@tilde.club>
Date
Jan 25, 2023, 23:45 UTC
Message-ID
<Y9G+/e5ghEsO3hIb@tilde.club>
In-Reply-To
<xmqq8rhqdwxl.fsf@gitster.g>
On 2023-01-25 15:19:34-0800, Junio C Hamano wrote:
> Please sign-off your contribution. 
> cf.  Documentation/SubmittingPatches[[sign-off]]
Oops! I will resend with a sign-off.
Show 18 quoted lines
> >  git-request-pull.sh | 2 +-
> >  1 file changed, 1 insertion(+), 1 deletion(-)
> >
> > diff --git a/git-request-pull.sh b/git-request-pull.sh
> > index 2d0e44656c..01640a044b 100755
> > --- a/git-request-pull.sh
> > +++ b/git-request-pull.sh
> > @@ -153,7 +153,7 @@ for you to fetch changes up to %H:
> >  if test $(git cat-file -t "$head") = tag
> >  then
> >  	git cat-file tag "$head" |
> > -	sed -n -e '1,/^$/d' -e '/^-----BEGIN PGP /q' -e p
> > +	sed -n -e '1,/^$/d' -e '/^-----BEGIN \(PGP\|SSH\|SIGNED\) /q' -e p
> 
> This makes readers debate themselves if being more specific and
> narrow like the posted patch is safer and better, or making it
> looser by just requiring "^-----BEGIN " and making it forward
> looking is sufficient and maintainable.

I could imagine someone having a tag with a line starting that way (not realizing it's a common pattern for signatures to take) and being confused at why it's being removed. The likelihood of someone doing that, and using request-pull with that tag, is pretty low though, so I don't have a strong preference.

Previous: Junio C HamanoNext: Gwyneth Morgan
Message 3 of 5 in “request-pull: filter out SSH/X.509 tag signatures”
  1. request-pull: filter out SSH/X.509 tag signaturesGwyneth Morgan, Jan 25, 2023
  2. Junio C HamanoJan 25, 2023
  3. Gwyneth MorganJan 25, 2023
  4. request-pull: filter out SSH/X.509 tag signaturesGwyneth Morgan, Jan 25, 2023
  5. Junio C HamanoJan 26, 2023

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.