git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: git tag -v should verify that the tag signer intended the same tag name as the user is verifying

From
Junio C Hamano <gitster@pobox.com>
Date
Mar 21, 2019, 01:31 UTC
Message-ID
<xmqq1s31ui5s.fsf@gitster-ct.c.googlers.com>
In-Reply-To
<xmqq5zsduinf.fsf@gitster-ct.c.googlers.com>
Junio C Hamano <gitster@pobox.com> writes:
>  * "git tag -v $(git rev-parse v1.0.0)" should work, but the command

Sorry, forget about this part of my message. I completely forgot the discussion we had a few years ago:

https://public-inbox.org/git/CAPc5daV9ZvHqFtdzr565vp6Mv7O66ySr-p5Vi8o6bd6=GyVELg@mail.gmail.com/

In short, "git tag -v TAGNAME" does not take an arbitrary object name, TAGNAME does not go through the usual ref dwimming rules (i.e. checking for .git/%s, .git/tag/%s, .git/heads/%s, ... to find one) but only looks at refs/tags/TAGNAME alone. So we always have the refname it came from when inspecting tag contents that tells what tagname the tag has.

The other point still stands; there are legitimate reasons people would want to have a tag with v1.0.0 tagname in somewhere that is not refs/tags/v1.0.0 and an extra validation must need to make sure it won't error out, even though warning is probably acceptable.

Previous: Junio C HamanoNext: Ævar Arnfjörð Bjarmason
Message 8 of 15 in “git tag -v should verify that the tag signer intended the same tag name as the user is verifying”
  1. Daniel Kahn GillmorMar 20, 2019
  2. Santiago Torres AriasMar 20, 2019
  3. Daniel Kahn GillmorMar 20, 2019
  4. Ævar Arnfjörð BjarmasonMar 20, 2019
  5. Daniel Kahn GillmorMar 22, 2019
  6. Ævar Arnfjörð BjarmasonMar 24, 2019
  7. Junio C HamanoMar 21, 2019
  8. Junio C HamanoMar 21, 2019
  9. Ævar Arnfjörð BjarmasonMar 21, 2019
  10. Daniel Kahn GillmorMar 22, 2019
  11. Junio C HamanoMar 24, 2019
  12. Daniel Kahn GillmorMar 24, 2019
  13. Junio C HamanoMar 25, 2019
  14. Daniel Kahn GillmorMar 26, 2019
  15. Jeff KingMar 26, 2019

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.