git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v3 2/3] fast-export: rename --signed-tags='warn' to 'warn-verbatim'

From
Junio C Hamano <gitster@pobox.com>
Date
Apr 30, 2021, 00:03 UTC
Message-ID
<xmqqeeesfxl2.fsf@gitster.g>
In-Reply-To
<87pmycq5h7.wl-lukeshu@lukeshu.com>
Luke Shumaker <lukeshu@lukeshu.com> writes:
Show 5 quoted lines
> How about:
>
> | Specify how to handle signed tags.  Since any transformation after the
> | export (or during the export, such as excluding revisions) can change
> | the hashes being signed, the signatures may not match.

I find it a bit worrying that it is unclear what the signature may not match. Knowing Git, I know the answer is "contents that is signed", and I want to make sure it is clear for all readers.

Would "may become invalid" be better?  I dunno.
Show 9 quoted lines
> | When asking to 'abort' (which is the default), this program will die
> | when encountering a signed tag.  With 'strip', the tags will silently
> | be made unsigned, with 'warn-strip' they will be made unsigned but a
> | warning will be displayed, with 'verbatim', they will be silently
> | exported and with 'warn-verbatim' (or 'warn', a deprecated synonym),
> | they will be exported, but you will see a warning.  'verbatim' should
> | not be used unless you know that no transformations affecting tags
> | will be performed, or unless you do not care that the resulting tag
> | will have an invalid signature.
OK.

As the current version of "fast-import" has no way to specify what is done to incoming signed tags, it may be the best we can do to discourage 'verbatim'. But if it learns "--signed-tags=<disposition>", I think the resulting ecosystem would become much better.

In the ideal world, I would imagine that we want to encourage to always write out the original signatures to the export stream, let any intermediary filters process the stream, and at the very end stage at fast-import, have the --signed-commit/tag option to control what is done to such signatures. The set of plausible options are what you invented for the export side in this series, plus "if the signature still matches, keep it, otherwise strip with warning".

If we want to get closer to such an ideal world (you can point out I am wrong and why such a world is not ideal, of course, though), we probably do not want to add "--signed-commit" to "fast-export", as it will have to get deprecated when the ideal world happens. Rather, the future would deprecate the existing "--signed-tags" option from "fast-export" instead.

Previous: Luke ShumakerNext: Luke Shumaker
Message 13 of 60 in “fast-export, fast-import: implement signed-commits”
  1. 0/3 fast-export, fast-import: implement signed-commitsLuke Shumaker, Apr 22, 2021
  2. 1/3 git-fast-import.txt: add missing LF in the BNFLuke Shumaker, Apr 22, 2021
  3. 2/3 fast-export: rename --signed-tags='warn' to 'warn-verbatim'Luke Shumaker, Apr 22, 2021
  4. Eric SunshineApr 22, 2021
  5. Luke ShumakerApr 22, 2021
  6. Luke ShumakerApr 22, 2021
  7. 3/3 fast-export, fast-import: implement signed-commitsLuke Shumaker, Apr 22, 2021
  8. 0/3 fast-export, fast-import: implement signed-commitsLuke Shumaker, Apr 23, 2021
  9. 1/3 git-fast-import.txt: add missing LF in the BNFLuke Shumaker, Apr 23, 2021
  10. 2/3 fast-export: rename --signed-tags='warn' to 'warn-verbatim'Luke Shumaker, Apr 23, 2021
  11. Junio C HamanoApr 28, 2021
  12. Luke ShumakerApr 29, 2021
  13. Junio C HamanoApr 30, 2021
  14. 3/3 fast-export, fast-import: implement signed-commitsLuke Shumaker, Apr 23, 2021
  15. Junio C HamanoApr 28, 2021
  16. Luke ShumakerApr 29, 2021
  17. Elijah NewrenApr 29, 2021
  18. Junio C HamanoApr 29, 2021
  19. Elijah NewrenApr 30, 2021
  20. Junio C HamanoApr 30, 2021
  21. Luke ShumakerApr 30, 2021
  22. Luke ShumakerApr 30, 2021
  23. Elijah NewrenApr 30, 2021
  24. Luke ShumakerApr 30, 2021
  25. 0/5 fast-export, fast-import: add support for signed-commitsLuke Shumaker, Apr 30, 2021
  26. 1/5 git-fast-import.txt: add missing LF in the BNFLuke Shumaker, Apr 30, 2021
  27. 2/5 fast-export: rename --signed-tags='warn' to 'warn-verbatim'Luke Shumaker, Apr 30, 2021
  28. 3/5 git-fast-export.txt: clarify why 'verbatim' may not be a good ideaLuke Shumaker, Apr 30, 2021
  29. 4/5 fast-export: do not modify memory from get_commit_bufferLuke Shumaker, Apr 30, 2021
  30. Junio C HamanoMay 3, 2021
  31. 5/5 fast-export, fast-import: add support for signed-commitsLuke Shumaker, Apr 30, 2021
  32. Junio C HamanoMay 3, 2021
  33. 0/6 fast-export, fast-import: add support for signed-commitsChristian Couder, Feb 24, 2025
  34. 1/6 git-fast-import.adoc: add missing LF in the BNFChristian Couder, Feb 24, 2025
  35. 2/6 fast-export: fix missing whitespace after switchChristian Couder, Feb 24, 2025
  36. 3/6 fast-export: rename --signed-tags='warn' to 'warn-verbatim'Christian Couder, Feb 24, 2025
  37. 4/6 git-fast-export.txt: clarify why 'verbatim' may not be a good ideaChristian Couder, Feb 24, 2025
  38. Elijah NewrenFeb 24, 2025
  39. Christian CouderMar 10, 2025
  40. 5/6 fast-export: do not modify memory from get_commit_bufferChristian Couder, Feb 24, 2025
  41. 6/6 fast-export, fast-import: add support for signed-commitsChristian Couder, Feb 24, 2025
  42. Elijah NewrenFeb 25, 2025
  43. Junio C HamanoFeb 25, 2025
  44. Christian CouderMar 10, 2025
  45. Junio C HamanoFeb 24, 2025
  46. Elijah NewrenFeb 25, 2025
  47. Patrick SteinhardtFeb 25, 2025
  48. Elijah NewrenFeb 25, 2025
  49. Junio C HamanoFeb 25, 2025
  50. Christian CouderMar 10, 2025
  51. Phillip WoodFeb 25, 2025
  52. Christian CouderMar 10, 2025
  53. 0/6 fast-export, fast-import: add support for signed-commitsChristian Couder, Mar 10, 2025
  54. 1/6 git-fast-import.adoc: add missing LF in the BNFChristian Couder, Mar 10, 2025
  55. 2/6 fast-export: fix missing whitespace after switchChristian Couder, Mar 10, 2025
  56. 3/6 fast-export: rename --signed-tags='warn' to 'warn-verbatim'Christian Couder, Mar 10, 2025
  57. 4/6 git-fast-export.adoc: clarify why 'verbatim' may not be a good ideaChristian Couder, Mar 10, 2025
  58. 5/6 fast-export: do not modify memory from get_commit_bufferChristian Couder, Mar 10, 2025
  59. 6/6 fast-export, fast-import: add support for signed-commitsChristian Couder, Mar 10, 2025
  60. Elijah NewrenMar 10, 2025

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.