Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.bugs.dist > #1264679
| From | Guillem Jover <guillem@debian.org> |
|---|---|
| Newsgroups | linux.debian.bugs.dist, linux.debian.policy |
| Subject | Bug#1091868: debian-policy: Document Git-Tag-Tagger and Git-Tag-Info fields |
| Date | 2025-10-04 15:40 +0200 |
| Message-ID | <LCaEp-2GPe-5@gated-at.bofh.it> (permalink) |
| References | (7 earlier) <KWvp7-9Q7O-7@gated-at.bofh.it> <K0czM-4OVR-13@gated-at.bofh.it> <KWvp7-9Q7O-5@gated-at.bofh.it> <K0czM-4OVR-13@gated-at.bofh.it> <KWvp7-9Q7O-5@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
Cross-posted to 2 groups.
[Multipart message — attachments visible in raw view] - view raw
Hi! On Wed, 2025-06-11 at 16:14:34 +0100, Sean Whitton wrote: > From 1dd537efa7bff1993273f24f85daf0468f73b302 Mon Sep 17 00:00:00 2001 > From: Sean Whitton <spwhitton@spwhitton.name> > Date: Wed, 1 Jan 2025 19:14:06 +0000 > Subject: [PATCH v4] Document Git-Tag-Tagger and Git-Tag-Info fields > > --- > policy/ch-controlfields.rst | 61 ++++++++++++++++++++++++++++++++++ > policy/upgrading-checklist.rst | 9 +++++ > 2 files changed, 70 insertions(+) > > diff --git a/policy/ch-controlfields.rst b/policy/ch-controlfields.rst > index 3151816..9769235 100644 > --- a/policy/ch-controlfields.rst > +++ b/policy/ch-controlfields.rst > @@ -237,6 +237,10 @@ is described above, in :ref:`s-controlsyntax`. > > - :ref:`Dgit <s-f-Dgit>` > > +- :ref:`Git-Tag-Tagger <s-f-Git-Tag-Tagger>` > + > +- :ref:`Git-Tag-Info <s-f-Git-Tag-Info>` > + I wonder why these use the generic «Git-» namespace instead of «Dgit-» when they seem tied to the dgit/tag2upload implementation? > +``Git-Tag-Info`` > +~~~~~~~~~~~~~~~~ > + > +Other information about the Git tag from which this upload was generated (and > +to which it corresponds) in accordance with the tagging protocol described in > +the :manpage:`tag2upload(5)` manual page and `TAG2UPLOAD-DESIGN.txt > +<https://salsa.debian.org/dgit-team/dgit/-/blob/master/TAG2UPLOAD-DESIGN.txt>`_. > + > +The value is of the form ``tag=TAGOBJID fp=FINGERPRINT`` where ``TAGOBJID`` is > +the Git object ID of the Git annotated tag object, [#]_ and ``FINGERPRINT`` is the > +fingerprint (in hexadecimal, without spaces) of the PGP key used to sign the > +Git tag. Other space-separated ``keyword=value`` items may be introduced in > +the future, and users of this field must ignore items with unknown keywords. > + > +``FINGERPRINT`` is taken from the first field of the ``VALIDSIG`` line emitted > +by :manpage:`gpgv(1)`, as specified in ``/usr/share/doc/gnupg/DETAILS.gz`` > +from the ``gnupg`` package. This will generally be the fingerprint of the > +signing subkey, if one was used, and the primary key's fingerprint otherwise. > + > +The Git annotated tag object is obtainable from the *dgit-repos* server, as > +described under ``Dgit``, above. > + > +Uploads signed by an implemention of the tag2upload service must include this > +field. Uploads not generated in accordance with the tag2upload protocol must > +not include this field. > + Hmm, I don't feel comfortable with Debian Policy growing reliance on GnuPG and its specific interfaces and formats, when IMO we should be making a collective effort to remove reliance on it (due to the schism). I'd feel more comfortable with references to something vendor generic and on its track to be standardized through the OpenPGP Working Group, such as SOPV. So I'm attaching an (untested) patch against dgit which could make it possible to switch the above specification to use SOPV details instead, and allow one of the several SOPV implementations around to be used. If that seems fine, I can submit that to dgit upstream. Thanks, Guillem
Back to linux.debian.bugs.dist | Previous | Next — Next in thread | Find similar | Unroll thread
Bug#1091868: debian-policy: Document Git-Tag-Tagger and Git-Tag-Info fields Guillem Jover <guillem@debian.org> - 2025-10-04 15:40 +0200 Bug#1091868: debian-policy: Document Git-Tag-Tagger and Git-Tag-Info fields Sean Whitton <spwhitton@spwhitton.name> - 2025-10-04 19:20 +0200
csiph-web