Re: [PATCH 0/2] fast-import: add mode to re-sign invalid commit signatures
- From
Justin Tobler <jltobler@gmail.com>
- Date
- Mar 2, 2026, 22:49 UTC
- Message-ID
- <aaYStamdm-LCiaP-@denethor>
- In-Reply-To
- <aZ4pFUJApZosh9Gc@fruit.crustytoothpaste.net>
On 26/02/24 10:41PM, brian m. carlson wrote:
Show 6 quoted lines
> If you're _not_ going to implement that in interoperability mode, then > I'd rather you just die in that case so that the test fails and then I > or someone else will fix it. `extensions.compatObjectFormat` is > presently experimental and the data formats will change, so nobody > should be relying on it working as it stands right now. There _will_ be > more compatibility breakage coming in future series, for instance.
That sounds very sensible. In the next version I'll update to instead die() as unsupported if we attempt to re-sign commit signatures in interoperability mode.
Show 7 quoted lines
> I _would_ recommend regardless that you add a test like in t7004's > "signed tag with embedded PGP message" if you apply this to tags as well > as commits. That requires a special case in our interoperability code > (since it normally converts things that look like signatures, but when > we're _generating_ a tag, we don't want to do that since there are no > signatures yet) and making sure we do the same thing in fast-import will > avoid corruption in our conversions.
Thanks, I'll look into this. This patch series currently only applies this new mode to commits, but I plan to tackle tag signatures in a separate followup series.
Thanks, -Justin