git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Tags

From
Eric W. Biederman <ebiederm@xmission.com>
Date
Jul 2, 2005, 18:31 UTC
Message-ID
<m1fyuxdpq4.fsf@ebiederm.dsl.xmission.com>
In-Reply-To
<42C6D5AD.9070304@zytor.com>
"H. Peter Anvin" <hpa@zytor.com> writes:
Show 7 quoted lines
> Eric W. Biederman wrote:
>> ?? Isn't that what ssh is?
>> To some extent a lot depends on how active you expect people to
>> try and forge things.  If there is an expectation of honesty
>> you are fine.
>
> I can't afford to have that.

So you are now your requirements are more stringent then sourceforge? Sourcefore limited things by reducing the scope of commits per project. But once you had commit access to a project you could do just about anything.

Show 6 quoted lines
>> If you want to build one mondo repository with thousands of developers
>> having write access you need to be more careful.  But as far as I know
>> none of that is specific to tags.
>
> Well, you're wrong.  Tags is the only part of git which cannot be protected by
> git's own self-validation system.

Which is why I suggested having tags in sync with the committer information, that way you are as valid as the commit record in git. Although I suspect the multiple head solution is probably better, and simply limiting the people who can commit to an individual head will achieve what is necessary. One user per head?

One thing arch has shown is that you can sucessfully move authentication/permission checking to the underlying environment if you structure things carefully.

I guess the problem is really we want to structure things so that a user who has downloaded the code can verify they have the release/tag is what they are looking for. You can detect a spoofed file in objects by simply verifying the sha1 of the file.

For a file that you can't internally verify that way the traditional way to handle that is to create a file with a gpg signature. So is there anything wrong with adding .git/refs/tags/tag-name.sign that is a traditional signature file? That will at least give you an end to end consistency check. (Hmm. Why didn't I suggest this before?)

If you don't want to mirror and propagate data you need to do consistency checks earlier in the process, and I have probably had some poor suggestions on how to implement those. But if everything is setup so we can verify things once we have the code downloaded, where you perform the checks is simply a matter of optimization.

Eric
Previous: H. Peter AnvinNext: Matthias Urlichs
Message 55 of 86 in “"git-send-pack"”
  1. Linus TorvaldsJun 30, 2005
  2. A Large Angry SCMJun 30, 2005
  3. A Large Angry SCMJun 30, 2005
  4. Linus TorvaldsJun 30, 2005
  5. Jan HarkesJun 30, 2005
  6. Mike TahtJun 30, 2005
  7. Linus TorvaldsJun 30, 2005
  8. Matthias UrlichsJul 1, 2005
  9. Linus TorvaldsJun 30, 2005
  10. Junio C HamanoJun 30, 2005
  11. Daniel BarkalowJun 30, 2005
  12. Linus TorvaldsJun 30, 2005
  13. H. Peter AnvinJun 30, 2005
  14. Linus TorvaldsJun 30, 2005
  15. H. Peter AnvinJun 30, 2005
  16. Linus TorvaldsJul 1, 2005
  17. H. Peter AnvinJul 1, 2005
  18. Mike TahtJul 1, 2005
  19. H. Peter AnvinJul 2, 2005
  20. Linus TorvaldsJul 2, 2005
  21. H. Peter AnvinJul 2, 2005
  22. Linus TorvaldsJul 2, 2005
  23. H. Peter AnvinJul 2, 2005
  24. Linus TorvaldsJul 2, 2005
  25. H. Peter AnvinJul 2, 2005
  26. Tony LuckJul 2, 2005
  27. H. Peter AnvinJul 2, 2005
  28. A Large Angry SCMJul 2, 2005
  29. Daniel BarkalowJun 30, 2005
  30. Linus TorvaldsJun 30, 2005
  31. Daniel BarkalowJul 1, 2005
  32. Linus TorvaldsJun 30, 2005
  33. Dan HolmsandJun 30, 2005
  34. Daniel BarkalowJun 30, 2005
  35. Linus TorvaldsJun 30, 2005
  36. H. Peter AnvinJun 30, 2005
  37. Linus TorvaldsJun 30, 2005
  38. H. Peter AnvinJun 30, 2005
  39. H. Peter AnvinJun 30, 2005
  40. Linus TorvaldsJun 30, 2005
  41. H. Peter AnvinJun 30, 2005
  42. Matthias UrlichsJul 1, 2005
  43. Jan HarkesJul 1, 2005
  44. TagsEric W. Biederman, Jul 1, 2005
  45. H. Peter AnvinJul 1, 2005
  46. Eric W. BiedermanJul 1, 2005
  47. H. Peter AnvinJul 1, 2005
  48. Eric W. BiedermanJul 1, 2005
  49. Daniel BarkalowJul 1, 2005
  50. H. Peter AnvinJul 2, 2005
  51. Eric W. BiedermanJul 2, 2005
  52. H. Peter AnvinJul 2, 2005
  53. Eric W. BiedermanJul 2, 2005
  54. H. Peter AnvinJul 2, 2005
  55. Eric W. BiedermanJul 2, 2005
  56. Matthias UrlichsJul 2, 2005
  57. H. Peter AnvinJul 2, 2005
  58. Linus TorvaldsJul 2, 2005
  59. H. Peter AnvinJul 2, 2005
  60. A Large Angry SCMJul 2, 2005
  61. Linus TorvaldsJul 2, 2005
  62. A Large Angry SCMJul 2, 2005
  63. Linus TorvaldsJul 3, 2005
  64. Petr BaudisJul 2, 2005
  65. Linus TorvaldsJul 2, 2005
  66. Dan HolmsandJul 3, 2005
  67. Kevin SmithJul 3, 2005
  68. Eric W. BiedermanJul 5, 2005
  69. Daniel BarkalowJul 5, 2005
  70. Eric W. BiedermanJul 5, 2005
  71. Linus TorvaldsJul 5, 2005
  72. Junio C HamanoJul 5, 2005
  73. Matthias UrlichsJul 6, 2005
  74. Eric W. BiedermanJul 7, 2005
  75. Linus TorvaldsJul 2, 2005
  76. Jan HarkesJul 2, 2005
  77. Jan HarkesJul 2, 2005
  78. Matthias UrlichsJul 2, 2005
  79. Petr BaudisJul 1, 2005
  80. H. Peter AnvinJul 1, 2005
  81. Matthias UrlichsJul 1, 2005
  82. Petr BaudisJul 1, 2005
  83. H. Peter AnvinJul 1, 2005
  84. Daniel BarkalowJul 1, 2005
  85. Petr BaudisJul 1, 2005
  86. Daniel BarkalowJun 30, 2005

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.