git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [RFC/PATCH v1] Add Travis CI support

From
Junio C Hamano <gitster@pobox.com>
Date
Sep 25, 2015, 18:29 UTC
Message-ID
<xmqqa8sa4ak4.fsf@gitster.mtv.corp.google.com>
In-Reply-To
<20150925162615.GF8417@sigill.intra.peff.net>
Jeff King <peff@peff.net> writes:
> If the point is for clients not to trust GitHub, though, it doesn't
> really matter what GitHub does with the cert, as long as it is put
> somewhere that clients know to get it.

Correct. A spiffy Web interface that says "Click this button and we show you the output of GPG signature verification" would not help. The push certificate is all about allowing third-parties to conduct an independent audit, so anything the hosting site computes using the certificates does not add value, unless the certificates themselves are exported for such an independent audit.

If somebody found a change to "git push" that makes it pick the user's wallet and sends a few coins every time it talks to the hosting site, the hosting site can say it is not their doing by showing that the tip of the commit that contains such a change came from me, and it is not their evil doing. Push certificates help the hosting site prove their innocence, and those who do not trust the site can still be convinced by the claim.

There is one scenario that signed push would not help very much, though. The hosting site cannot deny that it did not receive a push.

Following such an incident (perhaps the evil change came as a side effect of a innocuous looking patch), I would push a commit that fixes such an issue out to the hosting site (with signed commit). But if the hosting site deliberately keeps the tip of the branch unmodified (e.g. you can appear to accept the push to the pusher, without updating what is served to the general public), there will be more people who will fetch from the hosting site to contaminate their copy of git and the damage will spread in the meantime.

When I finally complain to the hosting site that it is deliberately rejecting the fix that would rob them the illicit revenue source, it does not help the hosting site to keep copies of push certificates when it wants to refute such a complaint. "We publish all push certificates and there is no record that gitster already tried to fix the issue" has to be taken with faith in that scenario.

So push certificate is not perfect. But it does protect hosting sites and projects hosted on them.

>  So I wonder if it would be
> helpful to have a microformat that the client would use to look at this.
> E.g., it would fetch the cert tree, then confirm that the current ref
> values match the latest cert.

Yeah, that is one possibility. Just a single flat file that concatenates all the push cert in the received order would do as an export format, too ;-)

Previous: Jeff KingNext: Jeff King
Message 29 of 31 in “Add Travis CI support”
  1. Add Travis CI supportlarsxschneider@gmail.com, Sep 24, 2015
  2. Add Travis CI supportlarsxschneider@gmail.com, Sep 24, 2015
  3. Junio C HamanoSep 25, 2015
  4. Dennis KaarsemakerSep 25, 2015
  5. Johannes SchindelinSep 25, 2015
  6. Luke DiamandSep 25, 2015
  7. Junio C HamanoSep 25, 2015
  8. Lars SchneiderSep 26, 2015
  9. Matthieu MoySep 27, 2015
  10. Stefan BellerSep 28, 2015
  11. Matthieu MoySep 28, 2015
  12. Junio C HamanoSep 28, 2015
  13. Matthieu MoySep 28, 2015
  14. Roberto TyleyOct 3, 2015
  15. Junio C HamanoOct 4, 2015
  16. Junio C HamanoOct 4, 2015
  17. Dennis KaarsemakerOct 4, 2015
  18. Johannes SchindelinOct 4, 2015
  19. Matthieu MoyOct 4, 2015
  20. Junio C HamanoOct 4, 2015
  21. Dennis KaarsemakerOct 4, 2015
  22. Matthieu MoyOct 5, 2015
  23. Junio C HamanoOct 5, 2015
  24. Sebastian SchuberthOct 12, 2015
  25. Junio C HamanoOct 4, 2015
  26. Jeff KingOct 4, 2015
  27. Sebastian SchuberthOct 2, 2015
  28. Jeff KingSep 25, 2015
  29. Junio C HamanoSep 25, 2015
  30. Jeff KingSep 25, 2015
  31. Shawn PearceSep 26, 2015

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.