Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.bugs.dist > #1250956 > unrolled thread
| Started by | Andrej Shadura <andrewsh@debian.org> |
|---|---|
| First post | 2025-06-24 15:10 +0200 |
| Last post | 2025-08-06 17:00 +0200 |
| Articles | 11 — 4 participants |
Back to article view | Back to linux.debian.bugs.dist
Bug#1108267: git-debpush should allow selecting the key to sign with Andrej Shadura <andrewsh@debian.org> - 2025-06-24 15:10 +0200
Bug#1108267: git-debpush should allow selecting the key to sign with Sean Whitton <spwhitton@spwhitton.name> - 2025-06-24 18:00 +0200
Bug#1108267: git-debpush should allow selecting the key to sign with "Andrej Shadura" <andrewsh@debian.org> - 2025-06-24 18:40 +0200
Bug#1108267: git-debpush should allow selecting the key to sign with Ian Jackson <ijackson@chiark.greenend.org.uk> - 2025-06-24 18:40 +0200
Bug#1108267: git-debpush should allow selecting the key to sign with Ian Jackson <ijackson@chiark.greenend.org.uk> - 2025-06-24 18:40 +0200
Bug#1108267: git-debpush should allow selecting the key to sign with Sean Whitton <spwhitton@spwhitton.name> - 2025-06-25 11:50 +0200
Bug#1108267: git-debpush should allow selecting the key to sign with "Andrej Shadura" <andrewsh@debian.org> - 2025-06-25 11:50 +0200
Bug#1108267: git-debpush should allow selecting the key to sign with Ian Jackson <ijackson@chiark.greenend.org.uk> - 2025-07-17 13:50 +0200
Bug#1108267: git-debpush should allow selecting the key to sign with Ian Jackson <ijackson@chiark.greenend.org.uk> - 2025-07-17 13:50 +0200
Bug#1108267: git-debpush should allow selecting the key to sign with Sean Whitton <spwhitton@spwhitton.name> - 2025-07-18 11:10 +0200
Bug#1108267: Newcomer bugs Ian Jackson <ijackson@chiark.greenend.org.uk> - 2025-08-06 17:00 +0200
| From | Andrej Shadura <andrewsh@debian.org> |
|---|---|
| Date | 2025-06-24 15:10 +0200 |
| Subject | Bug#1108267: git-debpush should allow selecting the key to sign with |
| Message-ID | <L1bzs-cPc7-9@gated-at.bofh.it> |
Package: git-debpush Version: 13.4 Severity: normal Hi, I use multiple email addresses when committing, and often commit using my non-Debian email address. When I run git-debpush, this will result in the tag being signed by a key that’s not in the keyring, resulting in tag2upload rejecting my upload. Please allow selecting the key to be used for signing using one or more of these: * DEB_SIGN_KEYID environment variable * DEBSIGN_KEYID variable in ~/.devscripts * a setting in the Git config, e.g. debpush.keyid, dgit.keyid etc. -- Cheers, Andrej
[toc] | [next] | [standalone]
| From | Sean Whitton <spwhitton@spwhitton.name> |
|---|---|
| Date | 2025-06-24 18:00 +0200 |
| Message-ID | <L1edY-cQEw-3@gated-at.bofh.it> |
| In reply to | #1250956 |
[Multipart message — attachments visible in raw view] — view raw
Hello, On Tue 24 Jun 2025 at 02:45pm +02, Andrej Shadura wrote: > Package: git-debpush > Version: 13.4 > Severity: normal > > Hi, > > I use multiple email addresses when committing, and often commit using > my non-Debian email address. When I run git-debpush, this will result > in the tag being signed by a key that’s not in the keyring, resulting in > tag2upload rejecting my upload. > > Please allow selecting the key to be used for signing using one or more > of these: > > * DEB_SIGN_KEYID environment variable > * DEBSIGN_KEYID variable in ~/.devscripts > * a setting in the Git config, e.g. debpush.keyid, dgit.keyid etc. This is a something of a minefield because there are also DEBFULLNAME and DEBEMAIL. In my ~/.devscripts I have both DEB_SIGN_KEYID and DEBSIGN_KEYID; I have no idea why. Do you have references for these two variables? It would be better to rely on existing env vars / config rather than adding new git config options. -- Sean Whitton
[toc] | [prev] | [next] | [standalone]
| From | "Andrej Shadura" <andrewsh@debian.org> |
|---|---|
| Date | 2025-06-24 18:40 +0200 |
| Message-ID | <L1eQG-cR8a-15@gated-at.bofh.it> |
| In reply to | #1250967 |
Hi, On Tue, 24 Jun 2025, at 17:50, Sean Whitton wrote: >> Please allow selecting the key to be used for signing using one or more >> of these: >> >> * DEB_SIGN_KEYID environment variable >> * DEBSIGN_KEYID variable in ~/.devscripts >> * a setting in the Git config, e.g. debpush.keyid, dgit.keyid etc. > This is a something of a minefield because there are also DEBFULLNAME > and DEBEMAIL. Well, these are for changelog trailers/commit metadata. I sometimes use my work email in those, but that key is not in the Debian keyring. > In my ~/.devscripts I have both DEB_SIGN_KEYID and DEBSIGN_KEYID; I have > no idea why. Do you have references for these two variables? DEBSIGN_* is only used by debsign and only as a ~/.devscripts variable, not as an environment variable. DEB_SIGN_* is used by dpkg-buildpackage and only as an environment variable. I source ~/. devscripts from my ~/.profile and export some of those, likely you did something similar back in the day :) > It would be better to rely on existing env vars / config rather than > adding new git config options. Yes, but OTOH dgit has already set the precedent. -- Cheers, Andrej
[toc] | [prev] | [next] | [standalone]
| From | Ian Jackson <ijackson@chiark.greenend.org.uk> |
|---|---|
| Date | 2025-06-24 18:40 +0200 |
| Message-ID | <L1eQG-cR8a-27@gated-at.bofh.it> |
| In reply to | #1250973 |
Andrej Shadura writes ("Bug#1108267: git-debpush should allow selecting the key to sign with"):
> On Tue, 24 Jun 2025, at 17:50, Sean Whitton wrote:
> > In my ~/.devscripts I have both DEB_SIGN_KEYID and DEBSIGN_KEYID; I have
> > no idea why. Do you have references for these two variables?
>
> DEBSIGN_* is only used by debsign and only as a ~/.devscripts variable, not as an environment variable. DEB_SIGN_* is used by dpkg-buildpackage and only as an environment variable.
>
> I source ~/. devscripts from my ~/.profile and export some of those, likely you did something similar back in the day :)
Urgh, this is a bit of a mess, isn't it?
I'm pretty sure we don't want git-debpush to read ~/.devscrfipts.
Ian.
--
Ian Jackson <ijackson@chiark.greenend.org.uk> These opinions are my own.
Pronouns: they/he. If I emailed you from @fyvzl.net or @evade.org.uk,
that is a private address which bypasses my fierce spamfilter.
[toc] | [prev] | [next] | [standalone]
| From | Ian Jackson <ijackson@chiark.greenend.org.uk> |
|---|---|
| Date | 2025-06-24 18:40 +0200 |
| Message-ID | <L1eQG-cR8a-5@gated-at.bofh.it> |
| In reply to | #1250956 |
Andrej Shadura writes ("Bug#1108267: git-debpush should allow selecting the key to sign with"):
> I use multiple email addresses when committing, and often commit using
> my non-Debian email address. When I run git-debpush, this will result
> in the tag being signed by a key that’s not in the keyring, resulting in
> tag2upload rejecting my upload.
I'm not sure why the committer is relevant? Do you just mean that
your git is configured by default to use a name and email that don't
correspond to your key? But I don't think those influence key
selection at all.
Currently, git-debpush just uses git-tag and by default allows git-tag
to choose which key to use. I believe git-tag then just lets gnupg
decide.
I think your desired behaviour is that the git-debpush tag has the
your default git committer name/email but is signed by your Debian
key? Or do you want it to have a different name/email in the tag?
Sean Whitton writes ("Bug#1108267: git-debpush should allow selecting the key to sign with"):
> This is a something of a minefield because there are also DEBFULLNAME
> and DEBEMAIL.
Arguably we should use those for the tagger line in the tag?
> In my ~/.devscripts I have both DEB_SIGN_KEYID and DEBSIGN_KEYID; I have
> no idea why. Do you have references for these two variables?
Sean, you'll want to read RTFM debsign(1). It actually explains the
behaviour (!) See in particular its CONFIGURATION VARIABLES section,
and the description of `-mmaintainer`.
> It would be better to rely on existing env vars / config rather than
> adding new git config options.
I agree with this.
Open questions (which may overlap):
Q1. How mkuch do we want to mimic the behaviour of debsign (which in
turn is trying to mirror the behaviour of dpkg-source but AFAICT
with extra env vars) ?
Q3. What is the flow of information/defaults:
(a) Calculate the tagger line (name and email address) order.
Then use that as the default for the key username.
(b) Do the tagger name and email address separately from
the key username / keyid (so name/email address env vars and
command line options don't influence key selecction) ?
(c) Always just use the name/email from git for the tagger line,
and only allow overriding of the -u option to git-tag.
Q4. Which env vars are we going to use? DEBFULLNAME/DEBEMAIL are very
commonly set and many tools use them. DEBSIGN_KEY seems useful.
DEBSIGN_MAINT ?
Q5. Are we going to have the d/changelog Changed-by information
influence the tagger line and/or key selection? debsign does.
dgit allows the dchangelog to influence author/committer lines and
I think also tagger lines.
Ian.
--
Ian Jackson <ijackson@chiark.greenend.org.uk> These opinions are my own.
Pronouns: they/he. If I emailed you from @fyvzl.net or @evade.org.uk,
that is a private address which bypasses my fierce spamfilter.
[toc] | [prev] | [next] | [standalone]
| From | Sean Whitton <spwhitton@spwhitton.name> |
|---|---|
| Date | 2025-06-25 11:50 +0200 |
| Message-ID | <L1uVs-d1Qp-5@gated-at.bofh.it> |
| In reply to | #1250971 |
[Multipart message — attachments visible in raw view] — view raw
Hello,
On Tue 24 Jun 2025 at 05:28pm +01, Ian Jackson wrote:
> Sean Whitton writes ("Bug#1108267: git-debpush should allow selecting the key
> to sign with"):
>> This is a something of a minefield because there are also DEBFULLNAME
>> and DEBEMAIL.
>
> Arguably we should use those for the tagger line in the tag?
I think we should leave it the same as the commit identity.
>> In my ~/.devscripts I have both DEB_SIGN_KEYID and DEBSIGN_KEYID; I have
>> no idea why. Do you have references for these two variables?
>
> Sean, you'll want to read RTFM debsign(1). It actually explains the
> behaviour (!) See in particular its CONFIGURATION VARIABLES section,
> and the description of `-mmaintainer`.
Thanks.
>> It would be better to rely on existing env vars / config rather than
>> adding new git config options.
>
> I agree with this.
>
> Open questions (which may overlap):
>
> Q1. How mkuch do we want to mimic the behaviour of debsign (which in
> turn is trying to mirror the behaviour of dpkg-source but AFAICT
> with extra env vars) ?
If people don't have to reconfigure anything and git-debpush just works,
and we don't make things completely incomprehensible to someone new who
hasn't (and may never) use debsign), that's a win.
> Q3. What is the flow of information/defaults:
> (a) Calculate the tagger line (name and email address) order.
> Then use that as the default for the key username.
> (b) Do the tagger name and email address separately from
> the key username / keyid (so name/email address env vars and
> command line options don't influence key selecction) ?
> (c) Always just use the name/email from git for the tagger line,
> and only allow overriding of the -u option to git-tag.
(d) Always just use the name/email from git for the tagger line *but*
select a keyid intelligently based on DEBFULLNAME/DEBEMAIL ?
--
Sean Whitton
[toc] | [prev] | [next] | [standalone]
| From | "Andrej Shadura" <andrewsh@debian.org> |
|---|---|
| Date | 2025-06-25 11:50 +0200 |
| Message-ID | <L1uVs-d1Qp-7@gated-at.bofh.it> |
| In reply to | #1251023 |
Hello, On Wed, 25 Jun 2025, at 11:38, Sean Whitton wrote: >> Q3. What is the flow of information/defaults: >> (a) Calculate the tagger line (name and email address) order. >> Then use that as the default for the key username. >> (b) Do the tagger name and email address separately from >> the key username / keyid (so name/email address env vars and >> command line options don't influence key selecction) ? >> (c) Always just use the name/email from git for the tagger line, >> and only allow overriding of the -u option to git-tag. > > (d) Always just use the name/email from git for the tagger line *but* > select a keyid intelligently based on DEBFULLNAME/DEBEMAIL ? This won’t work as DEBFULLNAME/DEBEMAIL is what goes into the changelog, not what the uploads are signed with. In my case, DEBEMAIL is andrewsh@collabora.co.uk for some packages, but I don’t have that key in the Debian keyring. And I want to keep it that way. The usual upload workflow allows this, as does dgit. -- Cheers, Andrej
[toc] | [prev] | [next] | [standalone]
| From | Ian Jackson <ijackson@chiark.greenend.org.uk> |
|---|---|
| Date | 2025-07-17 13:50 +0200 |
| Message-ID | <L9vhD-E2B-9@gated-at.bofh.it> |
| In reply to | #1251024 |
What is blocking us here is the fact that we don't really know other people's use cases, and we've got hung up on DEBEMAIL etc. We think we know Andrej's use case. (I spoke to Andrej about this irl.) I suggest that we change git-debpush to honour DEBSIGN_KEYID in the environment (as debsign does) and call this bug done. It would override git config and the default, but be overridden by -u. I think this doesn't prevent us possiby honouring DEBEMAIL and DEBFULLNAME later (for tagger field, or key selectdion). Sean, does this SGTY? Ian. -- Ian Jackson <ijackson@chiark.greenend.org.uk> These opinions are my own. Pronouns: they/he. If I emailed you from @fyvzl.net or @evade.org.uk, that is a private address which bypasses my fierce spamfilter.
[toc] | [prev] | [next] | [standalone]
| From | Ian Jackson <ijackson@chiark.greenend.org.uk> |
|---|---|
| Date | 2025-07-17 13:50 +0200 |
| Message-ID | <L9vhD-E2B-7@gated-at.bofh.it> |
| In reply to | #1253047 |
Ian Jackson writes ("Re: Bug#1108267: git-debpush should allow selecting the key to sign with"):
> I suggest that we change git-debpush to honour DEBSIGN_KEYID in the
> environment (as debsign does) and call this bug done. It would
> override git config and the default, but be overridden by -u.
I misread the debsign docs. I mean DEB_SIGN_KEYID in the envirionment
as dpkg-buildpackage does. (DEBSIGN_KEYID is only in ~/.devscripts.)
Ian.
--
Ian Jackson <ijackson@chiark.greenend.org.uk> These opinions are my own.
Pronouns: they/he. If I emailed you from @fyvzl.net or @evade.org.uk,
that is a private address which bypasses my fierce spamfilter.
[toc] | [prev] | [next] | [standalone]
| From | Sean Whitton <spwhitton@spwhitton.name> |
|---|---|
| Date | 2025-07-18 11:10 +0200 |
| Message-ID | <L9Pgl-RfX-11@gated-at.bofh.it> |
| In reply to | #1253047 |
[Multipart message — attachments visible in raw view] — view raw
Hello, On Thu 17 Jul 2025 at 10:43am +01, Ian Jackson wrote: > What is blocking us here is the fact that we don't really know other > people's use cases, and we've got hung up on DEBEMAIL etc. We think > we know Andrej's use case. (I spoke to Andrej about this irl.) > > I suggest that we change git-debpush to honour DEBSIGN_KEYID in the > environment (as debsign does) and call this bug done. It would > override git config and the default, but be overridden by -u. > > I think this doesn't prevent us possiby honouring DEBEMAIL and > DEBFULLNAME later (for tagger field, or key selectdion). > > Sean, does this SGTY? Yes, I think this is okay. We should probably be willing to change our mind with an incompatible change if it turns out this is the wrong default for large numbers of people. -- Sean Whitton
[toc] | [prev] | [next] | [standalone]
| From | Ian Jackson <ijackson@chiark.greenend.org.uk> |
|---|---|
| Date | 2025-08-06 17:00 +0200 |
| Subject | Bug#1108267: Newcomer bugs |
| Message-ID | <LgNMt-5zgh-1@gated-at.bofh.it> |
| In reply to | #1250956 |
tags -1 + newcomer We think these bugs would make good places to start playing with src:dgit. Ian. -- Ian Jackson <ijackson@chiark.greenend.org.uk> These opinions are my own. Pronouns: they/he. If I emailed you from @fyvzl.net or @evade.org.uk, that is a private address which bypasses my fierce spamfilter.
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.bugs.dist
csiph-web