Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1264679

Bug#1091868: debian-policy: Document Git-Tag-Tagger and Git-Tag-Info fields

From Guillem Jover <guillem@debian.org>
Newsgroups linux.debian.bugs.dist, linux.debian.policy
Subject Bug#1091868: debian-policy: Document Git-Tag-Tagger and Git-Tag-Info fields
Date 2025-10-04 15:40 +0200
Message-ID <LCaEp-2GPe-5@gated-at.bofh.it> (permalink)
References (7 earlier) <KWvp7-9Q7O-7@gated-at.bofh.it> <K0czM-4OVR-13@gated-at.bofh.it> <KWvp7-9Q7O-5@gated-at.bofh.it> <K0czM-4OVR-13@gated-at.bofh.it> <KWvp7-9Q7O-5@gated-at.bofh.it>
Organization linux.* mail to news gateway

Cross-posted to 2 groups.

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

Hi!

On Wed, 2025-06-11 at 16:14:34 +0100, Sean Whitton wrote:
> From 1dd537efa7bff1993273f24f85daf0468f73b302 Mon Sep 17 00:00:00 2001
> From: Sean Whitton <spwhitton@spwhitton.name>
> Date: Wed, 1 Jan 2025 19:14:06 +0000
> Subject: [PATCH v4] Document Git-Tag-Tagger and Git-Tag-Info fields
> 
> ---
>  policy/ch-controlfields.rst    | 61 ++++++++++++++++++++++++++++++++++
>  policy/upgrading-checklist.rst |  9 +++++
>  2 files changed, 70 insertions(+)
> 
> diff --git a/policy/ch-controlfields.rst b/policy/ch-controlfields.rst
> index 3151816..9769235 100644
> --- a/policy/ch-controlfields.rst
> +++ b/policy/ch-controlfields.rst
> @@ -237,6 +237,10 @@ is described above, in :ref:`s-controlsyntax`.
>  
>  -  :ref:`Dgit <s-f-Dgit>`
>  
> +-  :ref:`Git-Tag-Tagger <s-f-Git-Tag-Tagger>`
> +
> +-  :ref:`Git-Tag-Info <s-f-Git-Tag-Info>`
> +

I wonder why these use the generic «Git-» namespace instead of «Dgit-»
when they seem tied to the dgit/tag2upload implementation?

> +``Git-Tag-Info``
> +~~~~~~~~~~~~~~~~
> +
> +Other information about the Git tag from which this upload was generated (and
> +to which it corresponds) in accordance with the tagging protocol described in
> +the :manpage:`tag2upload(5)` manual page and `TAG2UPLOAD-DESIGN.txt
> +<https://salsa.debian.org/dgit-team/dgit/-/blob/master/TAG2UPLOAD-DESIGN.txt>`_.
> +
> +The value is of the form ``tag=TAGOBJID fp=FINGERPRINT`` where ``TAGOBJID`` is
> +the Git object ID of the Git annotated tag object, [#]_ and ``FINGERPRINT`` is the
> +fingerprint (in hexadecimal, without spaces) of the PGP key used to sign the
> +Git tag.  Other space-separated ``keyword=value`` items may be introduced in
> +the future, and users of this field must ignore items with unknown keywords.
> +
> +``FINGERPRINT`` is taken from the first field of the ``VALIDSIG`` line emitted
> +by :manpage:`gpgv(1)`, as specified in ``/usr/share/doc/gnupg/DETAILS.gz``
> +from the ``gnupg`` package.  This will generally be the fingerprint of the
> +signing subkey, if one was used, and the primary key's fingerprint otherwise.
> +
> +The Git annotated tag object is obtainable from the *dgit-repos* server, as
> +described under ``Dgit``, above.
> +
> +Uploads signed by an implemention of the tag2upload service must include this
> +field.  Uploads not generated in accordance with the tag2upload protocol must
> +not include this field.
> +

Hmm, I don't feel comfortable with Debian Policy growing reliance on
GnuPG and its specific interfaces and formats, when IMO we should be
making a collective effort to remove reliance on it (due to the schism).

I'd feel more comfortable with references to something vendor generic
and on its track to be standardized through the OpenPGP Working Group,
such as SOPV. So I'm attaching an (untested) patch against dgit which
could make it possible to switch the above specification to use SOPV
details instead, and allow one of the several SOPV implementations
around to be used. If that seems fine, I can submit that to dgit
upstream.

Thanks,
Guillem

Back to linux.debian.bugs.dist | Previous | Next — Next in thread | Find similar | Unroll thread


Thread

Bug#1091868: debian-policy: Document Git-Tag-Tagger and Git-Tag-Info fields Guillem Jover <guillem@debian.org> - 2025-10-04 15:40 +0200
  Bug#1091868: debian-policy: Document Git-Tag-Tagger and Git-Tag-Info fields Sean Whitton <spwhitton@spwhitton.name> - 2025-10-04 19:20 +0200

csiph-web