git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: What's next for "signed push"?

From
Dmitry Ivankov <divanorama@gmail.com>
Date
Sep 29, 2011, 11:50 UTC
Message-ID
<loom.20110929T134216-159@post.gmane.org>
In-Reply-To
<7vfwjgui8s.fsf_-_@alter.siamese.dyndns.org>
Junio C Hamano <gitster <at> pobox.com> writes:
Show 16 quoted lines
>  - It also was hoped that pre-receive or pre-update hook on the receiving
>    end can be used to authenticate and authorize the push itself with the
>    approach by v3, but when the check happens, the signed-notes tree to be
>    used for verification is not connected to any ref in the refs/notes/
>    hierarchy yet (otherwise it won't be pre-* hook). The query interface
>    "git notes show" needs to be updated so that it takes not just a ref
>    via the GIT_NOTES_REF interface, which is defined to specify a ref
>    because some subcommands of "git notes" need to create a new commit and
>    update it, but a bare notes tree commit object name [*1*]. We may need
>    to update "git notes" (at least "show" subcommand) for the use of
>    receiving end; v3 is no longer a simpler "sender only" solution.
> 
> *1* I wouldn't be surprised if it already worked when you give the object
> name of the notes-tree commit to GIT_NOTES_REF when running "git show",
> but that is not really a documented interface and working by accident. The
> environment variable was designed to take a name of the ref.

There's also my old request for comments on refs/notes/ ([RFC] plumbing git- notes, link below). Unexpected thing is that "refs/notes/commits^" is silently accepted, but notes aren't displayed at all.

http://thread.gmane.org/gmane.comp.version-control.git/178149
Previous: Junio C Hamano
Message 4 of 4 in “Signed push progress?”
  1. Robin H. JohnsonSep 28, 2011
  2. Junio C HamanoSep 28, 2011
  3. What's next for "signed push"?Junio C Hamano, Sep 29, 2011
  4. Dmitry IvankovSep 29, 2011

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.