Re: [PATCH 5/5] fast-import: add '--signed-tags=<mode>' option
On Wed, Oct 08, 2025 at 12:50:53PM +0200, Christian Couder wrote:
Show 24 quoted lines
> On Wed, Oct 8, 2025 at 11:21 AM Patrick Steinhardt <ps@pks.im> wrote:
> >
> > On Tue, Oct 07, 2025 at 02:29:58PM +0200, Christian Couder wrote:
> > > diff --git a/Documentation/git-fast-import.adoc b/Documentation/git-fast-import.adoc
> > > index 85ed7a7270..b74179a6c8 100644
> > > --- a/Documentation/git-fast-import.adoc
> > > +++ b/Documentation/git-fast-import.adoc
> > > @@ -66,6 +66,11 @@ fast-import stream! This option is enabled automatically for
> > > remote-helpers that use the `import` capability, as they are
> > > already trusted to run their own code.
> > >
> > > +--signed-tags=(verbatim|warn-verbatim|warn-strip|strip|abort)::
> > > + Specify how to handle signed tags. Behaves in the same way
> > > + as the same option in linkgit:git-fast-export[1], except that
> > > + default is 'verbatim' (instead of 'abort').
> > > +
> >
> > Nit: I would've ordered this after "--signed-commits", mostly so that
> > these two are ordered alphabetically.
>
> In the fast-export doc --signed-tags is before --signed-commits. Also
> in the previous patch series Junio mentioned that historically signed
> tags came before signed commits. And the other options are not sorted
> alphabetically.
Show 22 quoted lines
> > > + case SIGN_STRIP:
> > > + /* Truncate the buffer to remove the signature */
> > > + strbuf_setlen(msg, sig_offset);
> > > + break;
> >
> > I'm not familiar with the signature format, so it's probably a dumb
> > question: does the signature always extend until the end of the tag
> > message? Doesn't the tag message come after it?
>
> Users can add anything in a tag message, including signatures created
> however they want and copy-pasted there, followed by whatever content
> they want. I don't think we need to take care of those signatures,
> except perhaps to warn in our docs that Git could mistake them with
> the one Git creates.
>
> When Git itself signs a tag, it appends the signature to the tag
> message. See do_sign() in "builtin/tag.c" for more details. It looks
> like 2 signatures can be created in "compat" mode, but the compat
> signature is added into an object header, not appended to the tag
> message.
>
> So I think this is the right thing to do and relatively safe.
Okay, thanks for clarifying.
Patrick