Re: [PATCH 0/3] fast-import: add 'strip-if-invalid' mode to --signed-commits=<mode>
- From
Junio C Hamano <gitster@pobox.com>
- Date
- Nov 5, 2025, 14:40 UTC
- Message-ID
- <xmqqjz04mtji.fsf@gitster.g>
- In-Reply-To
- <20251105061918.3688870-1-christian.couder@gmail.com>
Christian Couder <christian.couder@gmail.com> writes:
Show 7 quoted lines
> The `--signed-commits=<mode>` option in `git fast-import` allows users > to decide what should be done when commits with signatures are > imported. > > For tools like `git filter-repo`, it would be useful to be able to > strip signatures when they are invalid, so let's add a new > 'strip-if-invalid' mode for that purpose.
Sorry, but I do not get it. What is your definition of a signature being "invalid", and what is your assumptions of how accurate a validity check ought to be? For example, are you assuming that you have all the necessary public keys, revocation data and accurate clock? Even if you are not changing a single bit in the import, some of your early commits' signatures do not "validate" and may need to be stripped, and after that happens, wouldn't signatures of all later commits become unusable (i.e, you may be able to verify that the signature on the original commit object may still be valid, but because the commit has to become a child of a rewritten commit, in the resulting history the signature would no longer match)?