Re: [PATCH v3 0/3] fast-import: add mode to re-sign invalid commit signatures
- From
Junio C Hamano <gitster@pobox.com>
- Date
- Mar 10, 2026, 21:20 UTC
- Message-ID
- <xmqqqzprs7o3.fsf@gitster.g>
- In-Reply-To
- <abCFKEHxu7OZr9bm@denethor>
Justin Tobler <jltobler@gmail.com> writes:
Show 6 quoted lines
> From my perspective, "re-sign" implies that the signature was previously > signed, but we are now going to sign it again. Indeed, the resulting > commit signing is functionally the same as if the object never had a > previous signature though. Also, "if-invalid" already implies that the > object is signed, but its signature is invalid. So it could be argued > that "re-sign" is already redundant.
Yup. if-invalid part indeed was why I thought "re-" was redundant.
Also, if a project is redoing its history with such a bulk operation, I wonder if it _still_ makes sense to tie this re-signing to the --signed-{tags,commits} option. Adding signature to commits that were not signed is not covered well with the "--signed-commits=<mode>" option.
A project may have required that all commits and tags to be signed, in which case "--signed-*=sign-if-invalid" would create a new history with everything freshly signed, but if the original history has signed and unsigned commits, and if they want to sign all the objects while rewriting their history, they may find it more handy if we let them do --signed-commits=strip-if-invalid --sign-commits i.e., drop the invalid ones and make sure all commits are signed.