git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: saving "git push --signed" certificate blobs

From
Junio C Hamano <gitster@pobox.com>
Date
Dec 30, 2014, 17:48 UTC
Message-ID
<xmqqiogtrptu.fsf@gitster.dls.corp.google.com>
In-Reply-To
<54A22586.70001@gmail.com>
Sitaram Chamarty <sitaramc@gmail.com> writes:
Show 22 quoted lines
> Just wanted to say there's a little script at [1] that saves the certificate
> blobs generated on the server side by "git push --signed".
>
> Quoting from the source:
>
> # Collects the cert blob on push and saves it, then, if a certain number of
> # signed pushes have been seen, processes all the "saved" blobs in one go,
> # adding them to the special ref 'refs/push-certs'.  This is done in a way
> # that allows searching for all the certs pertaining to one specific branch
> # (thanks to Junio Hamano for this idea plus general brainstorming).
>
> Note that although I posted it in the gitolite ML, this has very little to do
> with gitolite.  Any git server can use it, with only one very minor change [2]
> needed.
>
> sitaram
>
> [1]: https://groups.google.com/forum/#!topic/gitolite/7cSrU6JorEY
>
> [2]: Either set the GL_OPTIONS_GPC_PENDING environment variable by reading its
> value from 'git config', or replace the only line that uses that variable, with
> some other "test".
Nicely done.

We'd need to give you a tool to make it easy to create a "validated chain of certificates" out of

    $ git log refs/push-certs -- refs/heads/master

to make the history this script creates truly useful, but I think it is a very good start.

I can see that you tried to make the log output "human readable" by reformatting $cf, I am not sure if it gives us much value. I would have expected that you would just use the blob contents for the log message as-is, so that

    $ git log --pretty=raw refs/push-certs -- refs/heads/master |
      validate-cert-chain

can just work on blobs (shown in the "log" output) without having to extract the blobs by doing something like

    $ git rev-list refs/push-certs -- refs/heads/master |
      while read commit
      do
		git cat-file blob $commit:refs/heads/master |
                validate-cert
      done

By the way, you seem to like "cat" too much, though. You don't have to cat a single file into a pipeline.

Thanks.
Previous: Sitaram ChamartyNext: Sitaram Chamarty
Message 2 of 3 in “saving "git push --signed" certificate blobs”
  1. Sitaram ChamartyDec 30, 2014
  2. Junio C HamanoDec 30, 2014
  3. Sitaram ChamartyJan 1, 2015

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.