git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [Request for Documentation] Differentiate signed (commits/tags/pushes)

From
Junio C Hamano <gitster@pobox.com>
Date
Mar 6, 2017, 23:03 UTC
Message-ID
<xmqq8toiypn0.fsf@junio-linux.mtv.corp.google.com>
In-Reply-To
<xmqqshmqm4ur.fsf@junio-linux.mtv.corp.google.com>
Junio C Hamano <gitster@pobox.com> writes:
Show 19 quoted lines
> Stefan Beller <sbeller@google.com> writes:
>
>> What is the difference between signed commits and tags?
>> (Not from a technical perspective, but for the end user)
> ...
>> A signed push can certify that a given payload (consisting
>> of multiple commits on possibly multiple branches) was transmitted
>> to a remote, which can be recorded by the remote as e.g. a proof
>> of work.
> ...
> A signed push is _NOT_ about certifying the objects in the history
> DAG.  It is about certifying the _intent_ of pointing _REFS_ into
> points in the object graph.
> ...
> Historically, "tag -s" came a lot earlier.  When a project for
> whatever reason wants signature for each and every commit so that
> they somehow can feel good, without "commit -s", it would have made
> us unnecessary work to scale tag namespace only because there will
> be tons of pointless tags.  "commit -s" was a remedy for that.

While we are enumerating them, it is worth mentioning the mergetag header of a commit object.

This is added to a (merge) commit object when you merged a signed tag that points at a commit, and the intent is to eliminate the need to _keep_ the ref around that is created only for the purpose of "please pull from me, I tagged and signed the tip of the history I want you to pull" request. From that point of view, you could say it is also reducing the load on refs/tags/ namespace, but more importantly by not requiring the ref around, it allows you to verify that the merge commit merged the correct tag with _only_ the commit object by reproducing the payload of the signed tag that was merged in the commit object in full.

Previous: Junio C HamanoNext: Jeff King
Message 8 of 13 in “[Request for Documentation] Differentiate signed (commits/tags/pushes)”
  1. Stefan BellerMar 6, 2017
  2. Junio C HamanoMar 6, 2017
  3. Stefan BellerMar 6, 2017
  4. Junio C HamanoMar 7, 2017
  5. Stefan BellerMar 7, 2017
  6. Jakub NarębskiMar 6, 2017
  7. Junio C HamanoMar 7, 2017
  8. Junio C HamanoMar 6, 2017
  9. Jeff KingMar 7, 2017
  10. Tom JonesMar 7, 2017
  11. Stefan BellerMar 7, 2017
  12. Jeff KingMar 8, 2017
  13. Matthieu MoyMar 7, 2017

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.