git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 2/2] fast-import: add mode to re-sign invalid commit signatures

From
Justin Tobler <jltobler@gmail.com>
Date
Feb 24, 2026, 18:33 UTC
Message-ID
<aZ3sI5LAj-bSt0Oy@denethor>
In-Reply-To
<aZ1wblYGQssyNYsk@pks.im>
On 26/02/24 10:33AM, Patrick Steinhardt wrote:
Show 16 quoted lines
> On Mon, Feb 23, 2026 at 01:41:46PM -0600, Justin Tobler wrote:
> > With git-fast-import(1), handling of signed commits is controlled via
> > the `--signed-commits=<mode>` option. When an invalid signature is
> > encountered, a user may want the option to re-sign the commit as opposed
> > to just stripping the signature. To faciliate this, introduce a
> > "re-sign-if-invalid" mode for the `--signed-commits` option.
> > 
> > Note that commits are re-signed using only the repository object format
> > hash algorithm. If a commit has an additional signature due to the
> > `compatObjectFormat` repository extension being set, the other signature
> > is stripped.
> 
> This part here might use some explanation why this part is not done so
> that a future reader that ends up here doesn't have to wonder whether
> this is done with intent, or whether this was done because it was hard
> to do.
Good point. I'll expand the explaination here in the next version.
Show 14 quoted lines
> > diff --git a/Documentation/git-fast-import.adoc b/Documentation/git-fast-import.adoc
> > index 479c4081da..b902a6e2b0 100644
> > --- a/Documentation/git-fast-import.adoc
> > +++ b/Documentation/git-fast-import.adoc
> > @@ -86,6 +86,9 @@ already trusted to run their own code.
> >  * `strip-if-invalid` will check signatures and, if they are invalid,
> >    will strip them and display a warning. The validation is performed
> >    in the same way as linkgit:git-verify-commit[1] does it.
> > +* `re-sign-if-invalid` is the same as `strip-if-invalid`, but additionally the
> > +  commits with invalid signatures are signed again, so that old invalid
> > +  signatures are replaced with new valid ones.
> 
> Okay. It's a bit curious to say it's the "same as `strip-if-invalid`",
> but I get what you mean by this, and I think a user would, too.

Ya, maybe it would be better to say that it is "similar to `strip-if-invalid`". I'll try to rework the documentation here a little bit in the next version.

Show 23 quoted lines
> > diff --git a/builtin/fast-import.c b/builtin/fast-import.c
> > index b8a7757cfd..e34a373d2f 100644
> > --- a/builtin/fast-import.c
> > +++ b/builtin/fast-import.c
> > @@ -2836,10 +2836,11 @@ static void finalize_commit_buffer(struct strbuf *new_data,
> >  	strbuf_addbuf(new_data, msg);
> >  }
> >  
> > -static void handle_strip_if_invalid(struct strbuf *new_data,
> > -				    struct signature_data *sig_sha1,
> > -				    struct signature_data *sig_sha256,
> > -				    struct strbuf *msg)
> > +static void handle_invalid_signature(struct strbuf *new_data,
> > +				     struct signature_data *sig_sha1,
> > +				     struct signature_data *sig_sha256,
> > +				     struct strbuf *msg,
> > +				     enum sign_mode mode)
> >  {
> >  	struct strbuf tmp_buf = STRBUF_INIT;
> >  	struct signature_check signature_check = { 0 };
> 
> Should we maybe call this `handle_signature_if_invalid()`? Otherwise it
> sounds as if we already know the signature was invalid.
That sounds better. Will adapt.
Show 7 quoted lines
> 
> > @@ -2866,6 +2867,30 @@ static void handle_strip_if_invalid(struct strbuf *new_data,
> >  			warning(_("stripping invalid signature for commit\n"
> >  				  "  allegedly by %s"), signer);
> 
> I wonder: does it still make sense to warn about those stripped
> signatures in case we re-sign anyway?

Ya, good point. I was originally thinking it would still make sense to keep these messages since we are still stripping the signatures, but it might be misleading if are also re-signing them. We could keep these, but add an additional message if re-signing. That might be a little noisy though. Maybe we just adapt the warning message when re-signing.

Show 9 quoted lines
> > +		if (mode == SIGN_RESIGN_IF_INVALID) {
> > +			struct strbuf signature = STRBUF_INIT;
> > +			struct strbuf payload = STRBUF_INIT;
> > +			char *key = get_signing_key();
> > +
> > +			/*
> > +			 * Commits are resigned using the repository object
> 
> Poor commits. Maybe s/resigned/re-signed/?
Poor commits indeed, will change. XD
Show 12 quoted lines
> > +			 * format hash algorithm only. Consequently if
> > +			 * extensions.compatObjectFormat is set, the
> > +			 * compatability hash is not currently used to
> > +			 * additionally sign the commit. If the commit payload
> > +			 * were reconstructed in the compatability format, it
> > +			 * would be possible to generate the other signature
> > +			 * accordingly though.
> > +			 */
> 
> Same as in the commit message, we should document whether this is done
> intentionally, or whether it may require more work going forward. If the
> latter, it might make sense to add a NEEDSWORK comment.

Ya, I think it should be possible to support compatibility hashes in the future. I'll explain this better in a NEEDSWORK comment.

Show 21 quoted lines
> I think meanwhile though it's okay that we don't handle compatibility
> hashes yet.
> 
> > diff --git a/gpg-interface.c b/gpg-interface.c
> > index 87fb6605fb..e7eb42d9d6 100644
> > --- a/gpg-interface.c
> > +++ b/gpg-interface.c
> > @@ -1156,6 +1156,8 @@ int parse_sign_mode(const char *arg, enum sign_mode *mode)
> >  		*mode = SIGN_STRIP;
> >  	else if (!strcmp(arg, "strip-if-invalid"))
> >  		*mode = SIGN_STRIP_IF_INVALID;
> > +	else if (!strcmp(arg, "re-sign-if-invalid"))
> > +		*mode = SIGN_RESIGN_IF_INVALID;
> >  	else
> >  		return -1;
> >  	return 0;
> 
> One thing I wonder here is which signing key is actually in use, and how
> the user would specify it. In git-commit(1) you can for example pass
> "--gpg-sign=<key-id>" to specify the key. Do we want to allow the same
> here, where you can pass "--signed-commits=re-sign-if-invalid[=<gpg-key>]"?
This seems sensible. I'll explore this in the next version.
Thanks for the review. :)
-Justin
Previous: Patrick SteinhardtNext: Christian Couder
Message 6 of 60 in “fast-import: add mode to re-sign invalid commit signatures”
  1. 0/2 fast-import: add mode to re-sign invalid commit signaturesJustin Tobler, Feb 23, 2026
  2. 1/2 commit: remove unused forward declarationJustin Tobler, Feb 23, 2026
  3. Patrick SteinhardtFeb 24, 2026
  4. 2/2 fast-import: add mode to re-sign invalid commit signaturesJustin Tobler, Feb 23, 2026
  5. Patrick SteinhardtFeb 24, 2026
  6. Justin ToblerFeb 24, 2026
  7. Christian CouderFeb 24, 2026
  8. brian m. carlsonFeb 24, 2026
  9. Junio C HamanoFeb 24, 2026
  10. Justin ToblerMar 2, 2026
  11. 0/3 fast-import: add mode to re-sign invalid commit signaturesJustin Tobler, Mar 6, 2026
  12. 1/3 commit: remove unused forward declarationJustin Tobler, Mar 6, 2026
  13. 2/3 gpg-interface: introduce sign_buffer_with_key()Justin Tobler, Mar 6, 2026
  14. Christian CouderMar 10, 2026
  15. Justin ToblerMar 10, 2026
  16. 3/3 fast-import: add mode to re-sign invalid commit signaturesJustin Tobler, Mar 6, 2026
  17. Christian CouderMar 10, 2026
  18. Justin ToblerMar 10, 2026
  19. 0/3 fast-import: add mode to re-sign invalid commit signaturesJustin Tobler, Mar 10, 2026
  20. 1/3 commit: remove unused forward declarationJustin Tobler, Mar 10, 2026
  21. Junio C HamanoMar 10, 2026
  22. 2/3 gpg-interface: introduce sign_buffer_with_key()Justin Tobler, Mar 10, 2026
  23. Junio C HamanoMar 10, 2026
  24. 3/3 fast-import: add mode to re-sign invalid commit signaturesJustin Tobler, Mar 10, 2026
  25. Junio C HamanoMar 10, 2026
  26. Justin ToblerMar 10, 2026
  27. Junio C HamanoMar 10, 2026
  28. Justin ToblerMar 10, 2026
  29. Junio C HamanoMar 10, 2026
  30. Justin ToblerMar 10, 2026
  31. 0/3 fast-import: add mode to re-sign invalid commit signaturesJustin Tobler, Mar 11, 2026
  32. 1/3 commit: remove unused forward declarationJustin Tobler, Mar 11, 2026
  33. 2/3 gpg-interface: introduce sign_buffer_with_key()Justin Tobler, Mar 11, 2026
  34. Patrick SteinhardtMar 12, 2026
  35. Justin ToblerMar 12, 2026
  36. 3/3 fast-import: add mode to sign commits with invalid signaturesJustin Tobler, Mar 11, 2026
  37. Patrick SteinhardtMar 12, 2026
  38. Justin ToblerMar 12, 2026
  39. Patrick SteinhardtMar 12, 2026
  40. Justin ToblerMar 12, 2026
  41. 0/3 fast-import: add mode to re-sign invalid commit signaturesJustin Tobler, Mar 12, 2026
  42. 1/3 commit: remove unused forward declarationJustin Tobler, Mar 12, 2026
  43. 2/3 gpg-interface: allow sign_buffer() to use default signing keyJustin Tobler, Mar 12, 2026
  44. Junio C HamanoMar 12, 2026
  45. Justin ToblerMar 12, 2026
  46. 3/3 fast-import: add mode to sign commits with invalid signaturesJustin Tobler, Mar 12, 2026
  47. Junio C HamanoMar 12, 2026
  48. Justin ToblerMar 12, 2026
  49. Jeff KingMar 12, 2026
  50. Justin ToblerMar 13, 2026
  51. Junio C HamanoMar 12, 2026
  52. Justin ToblerMar 12, 2026
  53. 0/3 fast-import: add mode to re-sign invalid commit signaturesJustin Tobler, Mar 13, 2026
  54. 1/3 commit: remove unused forward declarationJustin Tobler, Mar 13, 2026
  55. 2/3 gpg-interface: allow sign_buffer() to use default signing keyJustin Tobler, Mar 13, 2026
  56. Patrick SteinhardtMar 13, 2026
  57. 3/3 fast-import: add mode to sign commits with invalid signaturesJustin Tobler, Mar 13, 2026
  58. Patrick SteinhardtMar 13, 2026
  59. Junio C HamanoMar 13, 2026
  60. Patrick SteinhardtMar 13, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.