From: Patrick Steinhardt Date: Wed, 08 Oct 2025 11:53:36 GMT Subject: Re: [PATCH 5/5] fast-import: add '--signed-tags=' option Message-ID: In-Reply-To: On Wed, Oct 08, 2025 at 12:50:53PM +0200, Christian Couder wrote: > On Wed, Oct 8, 2025 at 11:21 AM Patrick Steinhardt wrote: > > > > On Tue, Oct 07, 2025 at 02:29:58PM +0200, Christian Couder wrote: > > > diff --git a/Documentation/git-fast-import.adoc b/Documentation/git-fast-import.adoc > > > index 85ed7a7270..b74179a6c8 100644 > > > --- a/Documentation/git-fast-import.adoc > > > +++ b/Documentation/git-fast-import.adoc > > > @@ -66,6 +66,11 @@ fast-import stream! This option is enabled automatically for > > > remote-helpers that use the `import` capability, as they are > > > already trusted to run their own code. > > > > > > +--signed-tags=(verbatim|warn-verbatim|warn-strip|strip|abort):: > > > + Specify how to handle signed tags. Behaves in the same way > > > + as the same option in linkgit:git-fast-export[1], except that > > > + default is 'verbatim' (instead of 'abort'). > > > + > > > > Nit: I would've ordered this after "--signed-commits", mostly so that > > these two are ordered alphabetically. > > In the fast-export doc --signed-tags is before --signed-commits. Also > in the previous patch series Junio mentioned that historically signed > tags came before signed commits. And the other options are not sorted > alphabetically. Okay, makes sense. > > > + case SIGN_STRIP: > > > + /* Truncate the buffer to remove the signature */ > > > + strbuf_setlen(msg, sig_offset); > > > + break; > > > > I'm not familiar with the signature format, so it's probably a dumb > > question: does the signature always extend until the end of the tag > > message? Doesn't the tag message come after it? > > Users can add anything in a tag message, including signatures created > however they want and copy-pasted there, followed by whatever content > they want. I don't think we need to take care of those signatures, > except perhaps to warn in our docs that Git could mistake them with > the one Git creates. > > When Git itself signs a tag, it appends the signature to the tag > message. See do_sign() in "builtin/tag.c" for more details. It looks > like 2 signatures can be created in "compat" mode, but the compat > signature is added into an object header, not appended to the tag > message. > > So I think this is the right thing to do and relatively safe. Okay, thanks for clarifying. Patrick