# [PATCH] request-pull: filter out SSH/X.509 tag signatures

5 messages from 2023-01-25 to 2023-01-26. Participants: Gwyneth Morgan, Junio C Hamano.
Thread: https://gitlist.dev/t/59150

## Gwyneth Morgan, 2023-01-25 23:01

Subject: [PATCH] request-pull: filter out SSH/X.509 tag signatures
Message-ID: <20230125230117.3915827-1-gwymor@tilde.club>
URL: https://gitlist.dev/e/20230125230117.3915827-1-gwymor%40tilde.club

```
git request-pull filters PGP signatures out of the tag message, but not
SSH or X.509 signatures.
---
 git-request-pull.sh | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/git-request-pull.sh b/git-request-pull.sh
index 2d0e44656c..01640a044b 100755
--- a/git-request-pull.sh
+++ b/git-request-pull.sh
@@ -153,7 +153,7 @@ for you to fetch changes up to %H:
 if test $(git cat-file -t "$head") = tag
 then
 	git cat-file tag "$head" |
-	sed -n -e '1,/^$/d' -e '/^-----BEGIN PGP /q' -e p
+	sed -n -e '1,/^$/d' -e '/^-----BEGIN \(PGP\|SSH\|SIGNED\) /q' -e p
 	echo
 	echo "----------------------------------------------------------------"
 fi &&

```

## Junio C Hamano, 2023-01-25 23:19

Subject: Re: [PATCH] request-pull: filter out SSH/X.509 tag signatures
Message-ID: <xmqq8rhqdwxl.fsf@gitster.g>
URL: https://gitlist.dev/e/xmqq8rhqdwxl.fsf%40gitster.g
In-Reply-To: <20230125230117.3915827-1-gwymor@tilde.club>

```
Gwyneth Morgan <gwymor@tilde.club> writes:

> git request-pull filters PGP signatures out of the tag message, but not
> SSH or X.509 signatures.
> ---

Please sign-off your contribution. 
cf.  Documentation/SubmittingPatches[[sign-off]]

>  git-request-pull.sh | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/git-request-pull.sh b/git-request-pull.sh
> index 2d0e44656c..01640a044b 100755
> --- a/git-request-pull.sh
> +++ b/git-request-pull.sh
> @@ -153,7 +153,7 @@ for you to fetch changes up to %H:
>  if test $(git cat-file -t "$head") = tag
>  then
>  	git cat-file tag "$head" |
> -	sed -n -e '1,/^$/d' -e '/^-----BEGIN PGP /q' -e p
> +	sed -n -e '1,/^$/d' -e '/^-----BEGIN \(PGP\|SSH\|SIGNED\) /q' -e p

This makes readers debate themselves if being more specific and
narrow like the posted patch is safer and better, or making it
looser by just requiring "^-----BEGIN " and making it forward
looking is sufficient and maintainable.

If this were signed-off already, I would have said "let's queue it
as-is, while waiting for input from others", but without a sign-off
I am not queuing (yet).

Thanks.

```

## Gwyneth Morgan, 2023-01-25 23:45

Subject: Re: [PATCH] request-pull: filter out SSH/X.509 tag signatures
Message-ID: <Y9G+/e5ghEsO3hIb@tilde.club>
URL: https://gitlist.dev/e/Y9G%2B%2Fe5ghEsO3hIb%40tilde.club
In-Reply-To: <xmqq8rhqdwxl.fsf@gitster.g>

```
On 2023-01-25 15:19:34-0800, Junio C Hamano wrote:
> Please sign-off your contribution. 
> cf.  Documentation/SubmittingPatches[[sign-off]]

Oops! I will resend with a sign-off.

> >  git-request-pull.sh | 2 +-
> >  1 file changed, 1 insertion(+), 1 deletion(-)
> >
> > diff --git a/git-request-pull.sh b/git-request-pull.sh
> > index 2d0e44656c..01640a044b 100755
> > --- a/git-request-pull.sh
> > +++ b/git-request-pull.sh
> > @@ -153,7 +153,7 @@ for you to fetch changes up to %H:
> >  if test $(git cat-file -t "$head") = tag
> >  then
> >  	git cat-file tag "$head" |
> > -	sed -n -e '1,/^$/d' -e '/^-----BEGIN PGP /q' -e p
> > +	sed -n -e '1,/^$/d' -e '/^-----BEGIN \(PGP\|SSH\|SIGNED\) /q' -e p
> 
> This makes readers debate themselves if being more specific and
> narrow like the posted patch is safer and better, or making it
> looser by just requiring "^-----BEGIN " and making it forward
> looking is sufficient and maintainable.

I could imagine someone having a tag with a line starting that way (not
realizing it's a common pattern for signatures to take) and being
confused at why it's being removed. The likelihood of someone doing
that, and using request-pull with that tag, is pretty low though, so I
don't have a strong preference.

```

## Gwyneth Morgan, 2023-01-25 23:47

Subject: [PATCH v2] request-pull: filter out SSH/X.509 tag signatures
Message-ID: <20230125234725.3918563-1-gwymor@tilde.club>
URL: https://gitlist.dev/e/20230125234725.3918563-1-gwymor%40tilde.club
In-Reply-To: <20230125230117.3915827-1-gwymor@tilde.club>

```
git request-pull filters PGP signatures out of the tag message, but not
SSH or X.509 signatures.

Signed-off-by: Gwyneth Morgan <gwymor@tilde.club>
---
 git-request-pull.sh | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/git-request-pull.sh b/git-request-pull.sh
index 2d0e44656c..01640a044b 100755
--- a/git-request-pull.sh
+++ b/git-request-pull.sh
@@ -153,7 +153,7 @@ for you to fetch changes up to %H:
 if test $(git cat-file -t "$head") = tag
 then
 	git cat-file tag "$head" |
-	sed -n -e '1,/^$/d' -e '/^-----BEGIN PGP /q' -e p
+	sed -n -e '1,/^$/d' -e '/^-----BEGIN \(PGP\|SSH\|SIGNED\) /q' -e p
 	echo
 	echo "----------------------------------------------------------------"
 fi &&

```

## Junio C Hamano, 2023-01-26 00:18

Subject: Re: [PATCH v2] request-pull: filter out SSH/X.509 tag signatures
Message-ID: <xmqq4jsedu7c.fsf@gitster.g>
URL: https://gitlist.dev/e/xmqq4jsedu7c.fsf%40gitster.g
In-Reply-To: <20230125234725.3918563-1-gwymor@tilde.club>

```
Gwyneth Morgan <gwymor@tilde.club> writes:

> git request-pull filters PGP signatures out of the tag message, but not
> SSH or X.509 signatures.
>
> Signed-off-by: Gwyneth Morgan <gwymor@tilde.club>
> ---
>  git-request-pull.sh | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/git-request-pull.sh b/git-request-pull.sh
> index 2d0e44656c..01640a044b 100755
> --- a/git-request-pull.sh
> +++ b/git-request-pull.sh
> @@ -153,7 +153,7 @@ for you to fetch changes up to %H:
>  if test $(git cat-file -t "$head") = tag
>  then
>  	git cat-file tag "$head" |
> -	sed -n -e '1,/^$/d' -e '/^-----BEGIN PGP /q' -e p
> +	sed -n -e '1,/^$/d' -e '/^-----BEGIN \(PGP\|SSH\|SIGNED\) /q' -e p
>  	echo
>  	echo "----------------------------------------------------------------"
>  fi &&

Thanks, queued.

```
