git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: GPG Commit Signing Project

From
Junio C Hamano <gitster@pobox.com>
Date
Jun 12, 2020, 17:03 UTC
Message-ID
<xmqqd0642p3q.fsf@gitster.c.googlers.com>
In-Reply-To
<20200612022407.GC6569@camp.crustytoothpaste.net>
"brian m. carlson" <sandals@crustytoothpaste.net> writes:
Show 18 quoted lines
> On 2020-06-12 at 01:55:56, dwh@linuxprogrammer.org wrote:
>> I now think even that proposal is overly complicated. I think the
>> easiest solution is to simply standardize the existing pipe-fork
>> interface as the way GPG talks to all signing tools. For signing tools
>> that have different command line interfaces than GPG, we can create
>> adapter scripts. Tools that want to be compatible can adapt.
>
> This becomes pretty tricky because Git parses OpenPGP headers in a
> variety of places (e.g., at the end of tags).  If your proposal is to
> wrap new formats in a fake OpenPGP format, like some existing tools do,
> then that would be viable, but otherwise you're going to require either
> Git to know about your signing format specifically (which is not a
> sustainable approach) or some sort of configuration framework like has
> been previously discussed.
>
> If you're going to wrap things in a fake OpenPGP format, then you don't
> actually need to send any patches to Git at all; you can simply set
> gpg.program and continue.
True enough ;-)  Thanks for a concise summary of the situation.
Previous: brian m. carlson
Message 5 of 5 in “GPG Commit Signing Project”
  1. Jimit BhalavatJun 10, 2020
  2. Junio C HamanoJun 10, 2020
  3. dwh@linuxprogrammer.orgJun 12, 2020
  4. brian m. carlsonJun 12, 2020
  5. Junio C HamanoJun 12, 2020

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.