From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S934655Ab1KJNwQ (ORCPT ); Thu, 10 Nov 2011 08:52:16 -0500 Received: from casper.infradead.org ([85.118.1.10]:48674 "EHLO casper.infradead.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S932574Ab1KJNwO (ORCPT ); Thu, 10 Nov 2011 08:52:14 -0500 Message-ID: <1320933118.17392.23.camel@i7.infradead.org> Subject: Re: [git patches] libata updates, GPG signed (but see admin notes) From: David Woodhouse To: Linus Torvalds Cc: Jochen Striepe , Shawn Pearce , Junio C Hamano , git@vger.kernel.org, James Bottomley , Jeff Garzik , Andrew Morton , linux-ide@vger.kernel.org, LKML Date: Thu, 10 Nov 2011 13:51:58 +0000 In-Reply-To: References: <7vwrbjlj5r.fsf@alter.siamese.dyndns.org> <7vk47jld5s.fsf@alter.siamese.dyndns.org> <20111103032205.GA25888@pompeji.miese-zwerge.org> Content-Type: text/plain; charset="UTF-8" X-Mailer: Evolution 3.2.1 (3.2.1-2.fc16) Content-Transfer-Encoding: 7bit Mime-Version: 1.0 X-SRS-Rewrite: SMTP reverse-path rewritten from by casper.infradead.org See http://www.infradead.org/rpr.html Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Wed, 2011-11-02 at 21:13 -0700, Linus Torvalds wrote: > No, my main objection to saving the data is that it's ugly and it's > redundant. Sure, in practice you can check the signatures later fine > (with the rare exceptions you mention), but even when you can do it, > what's the big upside? Another objection (although it may not be insurmountable) is that it's not necessarily *entirely* clear what's being signed. In the simple case where I clone your tree, make a few commits with my Signed-off-by:, sign a tag and then ask you to pull, that's easy enough. I'm vouching for what I committed, and not for everything that was in your tree beforehand. But what if I'm working on top of someone else's published git tree? Does a signed tag at the top of *my* work imply that I'm vouching for all of theirs too? In the case where the signature is ephemeral and only used for you to trust my pull request, the answer is simple: If that other work wasn't in your tree yet at the time I send my pull request, I'd damn well better be vouching for it when I ask you to pull it. Nothing new there. But if we're keeping signatures around for auditing purposes, we'd better have a coherent answer to that question. One that isn't "a signature cover everything since the last commit with torvalds@ as the committer", if we want it to be useful for the general case. -- dwmw2