git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: How to gpg signed email patches?

From
Junio C Hamano <gitster@pobox.com>
Date
Apr 14, 2025, 16:34 UTC
Message-ID
<xmqqfriar9bw.fsf@gitster.g>
In-Reply-To
<D95V0Z9YMEX2.3J99CE4F6ZP8S@lfurio.us>
"Matt Hunter" <m@lfurio.us> writes:
Show 20 quoted lines
> Hi
>
> On Sun Apr 13, 2025 at 3:17 PM EDT, Klaus Frank wrote:
>> how do I get "git send-email" to send the patches gpg signed? I tried
>> first signing the commit but after spending time looking into the
>> documentation I couldn't work out how to do it. All I discovered so far
>> is that the "git send-email" appears to be using "git format-patch"
>> internally and that's where it currently gets lost.
>
> There's a conceptual issue with mailing patches from signed commits.
> Once your patch recipient goes to apply it to their branch, they are
> recorded as the "committer" identity of the new commit object.  This
> would break the validity of any existing signature.
>
> This is likely the reason by the related git tools (format-patch, am)
> ignore this information.
>
> You may have also noticed that commands like git-rebase and
> git-cherry-pick will drop signatures from commits as well, since they
> are being replayed onto a different history, changing the commit data.

Very well said. Protecting the e-mail with GPG is a job for MUA/MSA, that is independent from signature used to sign objects like commits and tags, so the signature over objects cannot be reused by programs like send-email.

But send-email may not have an option to wrap its payload in s-mime or pgp, which can be a separate project worth looking into.

Thanks.
Previous: Klaus FrankNext: brian m. carlson
Message 4 of 10 in “How to gpg signed email patches?”
  1. Klaus FrankApr 13, 2025
  2. Matt HunterApr 13, 2025
  3. Klaus FrankApr 13, 2025
  4. Junio C HamanoApr 14, 2025
  5. brian m. carlsonApr 13, 2025
  6. Klaus FrankApr 14, 2025
  7. brian m. carlsonApr 14, 2025
  8. Junio C HamanoApr 14, 2025
  9. Konstantin RyabitsevApr 14, 2025
  10. Junio C HamanoApr 14, 2025

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.