threads / discuss / 2032

Allow "-u" flag to tag signing

Subject: Allow "-u" flag to tag signing

## tl;dr

4 messages between Oct 6, 2005 and Oct 6, 2005.

replies: 3people: 4as markdown or json

Linus Torvalds· Oct 6, 2005, 16:58 UTC · lore

The current "git tag -s" thing always uses the tagger name as the signing user key, which is very irritating, since my key is under my email address, but the tagger key obviously contains the actual machine name too.

Now, I could just use "GIT_COMMITTER_EMAIL" and force it to be my real email, but I actually think that it's nice to see which machine I use for my work.

So rather than force my tagger ID to have to match the gpg key name, just support the "-u" flag to "git tag" instead. It implicitly enables signing, since it doesn't make any sense without it. Thus:

	git tag -u <gpg-key-name> <tag-name> [<tagged-object>]
will use the named gpg key for signing.
Signed-off-by: Linus Torvalds <torvalds@osdl.org>
---
Not very well tested, but I re-did my v2.6.14-rc3 tag with this, since I'd 
messed up the comments (and called it v2.6.14-rc2 in there ;)
So it may even work.
diff --git a/git-tag.sh b/git-tag.sh
--- a/git-tag.sh
+++ b/git-tag.sh
@@ -12,6 +12,7 @@ annotate=
 signed=
 force=
 message=
+username=
 while case "$#" in 0) break ;; esac
 do
     case "$1" in
@@ -30,6 +31,12 @@ do
 	shift
 	message="$1"
 	;;
+    -u)
+	annotate=1
+	signed=1
+	shift
+	username="$1"
+	;;
     -*)
         usage
 	;;
@@ -70,8 +77,11 @@ if [ "$annotate" ]; then
     ( echo -e "object $object\ntype $type\ntag $name\ntagger $tagger\n"; cat .tagmsg ) > .tmp-tag
     rm -f .tmp-tag.asc .tagmsg
     if [ "$signed" ]; then
-	me=$(expr "$tagger" : '\(.*>\)') &&
-	gpg -bsa -u "$me" .tmp-tag &&
+	{
+		[ "$username" ] ||
+		username=$(expr "$tagger" : '\(.*>\)')
+	} &&
+	gpg -bsa -u "$username" .tmp-tag &&
 	cat .tmp-tag.asc >>.tmp-tag ||
 	die "failed to sign the tag with GPG."
     fi
H. Peter Anvin· Oct 6, 2005, 17:15 UTC · re: Linus Torvalds · lore

Re: Allow "-u" flag to tag signing

Linus Torvalds wrote:
Show 16 quoted lines
> The current "git tag -s" thing always uses the tagger name as the signing 
> user key, which is very irritating, since my key is under my email 
> address, but the tagger key obviously contains the actual machine name 
> too.
> 
> Now, I could just use "GIT_COMMITTER_EMAIL" and force it to be my real 
> email, but I actually think that it's nice to see which machine I use for 
> my work. 
> 
> So rather than force my tagger ID to have to match the gpg key name, just 
> support the "-u" flag to "git tag" instead. It implicitly enables signing, 
> since it doesn't make any sense without it. Thus:
> 
> 	git tag -u <gpg-key-name> <tag-name> [<tagged-object>]
> 
> will use the named gpg key for signing.

This is important for another reason as well: a lot of people have multiple keys.

	-hpa
Junio C Hamano· Oct 6, 2005, 20:17 UTC · re: H. Peter Anvin · lore

Re: Allow "-u" flag to tag signing

"H. Peter Anvin" <hpa@zytor.com> writes:
Show 7 quoted lines
>> ... It implicitly enables signing, since it doesn't make any
>> sense without it. Thus:
>> 	git tag -u <gpg-key-name> <tag-name> [<tagged-object>]
>> will use the named gpg key for signing.
>
> This is important for another reason as well: a lot of people have 
> multiple keys.
Agreed.  Thanks both.  Will apply.
Chris Wright· Oct 6, 2005, 23:32 UTC · re: Linus Torvalds · lore

Re: Allow "-u" flag to tag signing

* Linus Torvalds (torvalds@osdl.org) wrote:
Show 7 quoted lines
> So rather than force my tagger ID to have to match the gpg key name, just 
> support the "-u" flag to "git tag" instead. It implicitly enables signing, 
> since it doesn't make any sense without it. Thus:
> 
> 	git tag -u <gpg-key-name> <tag-name> [<tagged-object>]
> 
> will use the named gpg key for signing.

Nice, I've had a hack something like this locally here as well, and been meaning to cleanup and submit.

thanks, -chris

← back to recent threads