git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: git-send-email with GPG signed commits?

From
Junio C Hamano <gitster@pobox.com>
Date
Oct 20, 2022, 18:03 UTC
Message-ID
<xmqqk04us77b.fsf@gitster.g>
In-Reply-To
<xmqqr0z2s7w4.fsf@gitster.g>
Junio C Hamano <gitster@pobox.com> writes:
Show 7 quoted lines
>> I think you would need some kind of "author-sig" header that signs the
>> commit object bytes _without_ the commit header at all. And that assumes
>> the maintainer's workflow is to never modify a patch in transit, and to
>> apply it at the exact same spot that you wrote it (so that the parent
>> and tree ids remain the same).
>
> Doesn't it immediately break down once you send a 2-patch series?

Ah, if you did not mean "without the committer header", but "without any of the header fields of the commit object", then it would probably work. But then that loses the context to apply the patch completely, so I can apply a patch you author-signed to a place where it wouldn't work and end up with a broken commit.

Start from the original commit object, remove the committer, the author, the tree, and the parent headers, add a parent-tree header that records the tree object of the first parent, and call that a "modified commit object". Then compute the signature over it and the patch text. The e-mailed patch now needs to carry the value of the parent-tree header and the signature.

At the receiving end, the reverse operation can be done and the resulting commit may have two new headers (author-sig and parent-tree). In the resulting commit, parent-tree does not have to match the tree of its first parent, if the integrator chose to apply it on a different commit, and as long as the patch text matches, things should verify.

So, some kind of "author-sig" is certainly possible, but is it practically useful? I am not sure. It still does not even allow typofixes on the receiving end.

Previous: Junio C HamanoNext: Jeff King
Message 7 of 13 in “git-send-email with GPG signed commits?”
  1. Matěj CeplOct 20, 2022
  2. Konstantin RyabitsevOct 20, 2022
  3. Matěj CeplOct 20, 2022
  4. Konstantin RyabitsevOct 20, 2022
  5. Jeff KingOct 20, 2022
  6. Junio C HamanoOct 20, 2022
  7. Junio C HamanoOct 20, 2022
  8. Jeff KingOct 20, 2022
  9. Konstantin RyabitsevOct 20, 2022
  10. rsbecker@nexbridge.comOct 20, 2022
  11. Matěj CeplOct 20, 2022
  12. brian m. carlsonOct 20, 2022
  13. Matěj CeplOct 21, 2022

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.