Skip to content

Commit d9cb0e6

Browse files
LukeShugitster
authored andcommitted
fast-export, fast-import: add support for signed-commits
fast-export has a --signed-tags= option that controls how to handle tag signatures. However, there is no equivalent for commit signatures; it just silently strips the signature out of the commit (analogously to --signed-tags=strip). While signatures are generally problematic for fast-export/fast-import (because hashes are likely to change), if they're going to support tag signatures, there's no reason to not also support commit signatures. So, implement a --signed-commits= option that mirrors the --signed-tags= option. On the fast-export side, try to be as much like signed-tags as possible, in both implementation and in user-interface. This will change the default behavior to '--signed-commits=abort' from what is now '--signed-commits=strip'. In order to provide an escape hatch for users of third-party tools that call fast-export and do not yet know of the --signed-commits= option, add an environment variable 'FAST_EXPORT_SIGNED_COMMITS_NOABORT=1' that changes the default to '--signed-commits=warn-strip'. Signed-off-by: Luke Shumaker <[email protected]> Signed-off-by: Christian Couder <[email protected]> Signed-off-by: Junio C Hamano <[email protected]>
1 parent dda9bff commit d9cb0e6

File tree

5 files changed

+253
-20
lines changed

5 files changed

+253
-20
lines changed

Documentation/git-fast-export.adoc

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -44,6 +44,17 @@ affecting tags or any commit in their history will be performed by you
4444
or by fast-export or fast-import, or if you do not care that the
4545
resulting tag will have an invalid signature.
4646

47+
--signed-commits=(verbatim|warn-verbatim|warn-strip|strip|abort)::
48+
Specify how to handle signed commits. Behaves exactly as
49+
'--signed-tags', but for commits. Default is 'abort'.
50+
+
51+
Earlier versions this command that did not have '--signed-commits'
52+
behaved as if '--signed-commits=strip'. As an escape hatch for users
53+
of tools that call 'git fast-export' but do not yet support
54+
'--signed-commits', you may set the environment variable
55+
'FAST_EXPORT_SIGNED_COMMITS_NOABORT=1' in order to change the default
56+
from 'abort' to 'warn-strip'.
57+
4758
--tag-of-filtered-object=(abort|drop|rewrite)::
4859
Specify how to handle tags whose tagged object is filtered out.
4960
Since revisions and files to export can be limited by path,

Documentation/git-fast-import.adoc

Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -431,12 +431,21 @@ and control the current import process. More detailed discussion
431431
Create or update a branch with a new commit, recording one logical
432432
change to the project.
433433

434+
////
435+
Yes, it's intentional that the 'gpgsig' line doesn't have a trailing
436+
`LF`; the definition of `data` has a byte-count prefix, so it
437+
doesn't need an `LF` to act as a terminator (and `data` also already
438+
includes an optional trailing `LF?` just in case you want to include
439+
one).
440+
////
441+
434442
....
435443
'commit' SP <ref> LF
436444
mark?
437445
original-oid?
438446
('author' (SP <name>)? SP LT <email> GT SP <when> LF)?
439447
'committer' (SP <name>)? SP LT <email> GT SP <when> LF
448+
('gpgsig' SP <alg> LF data)?
440449
('encoding' SP <encoding> LF)?
441450
data
442451
('from' SP <commit-ish> LF)?
@@ -505,6 +514,15 @@ that was selected by the --date-format=<fmt> command-line option.
505514
See ``Date Formats'' above for the set of supported formats, and
506515
their syntax.
507516

517+
`gpgsig`
518+
^^^^^^^^
519+
520+
The optional `gpgsig` command is used to include a PGP/GPG signature
521+
that signs the commit data.
522+
523+
Here <alg> specifies which hashing algorithm is used for this
524+
signature, either `sha1` or `sha256`.
525+
508526
`encoding`
509527
^^^^^^^^^^
510528
The optional `encoding` command indicates the encoding of the commit

builtin/fast-export.c

Lines changed: 103 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -35,8 +35,11 @@ static const char *fast_export_usage[] = {
3535
NULL
3636
};
3737

38+
enum sign_mode { SIGN_ABORT, SIGN_VERBATIM, SIGN_STRIP, SIGN_WARN_VERBATIM, SIGN_WARN_STRIP };
39+
3840
static int progress;
39-
static enum signed_tag_mode { SIGNED_TAG_ABORT, VERBATIM, WARN_VERBATIM, WARN_STRIP, STRIP } signed_tag_mode = SIGNED_TAG_ABORT;
41+
static enum sign_mode signed_tag_mode = SIGN_ABORT;
42+
static enum sign_mode signed_commit_mode = SIGN_ABORT;
4043
static enum tag_of_filtered_mode { TAG_FILTERING_ABORT, DROP, REWRITE } tag_of_filtered_mode = TAG_FILTERING_ABORT;
4144
static enum reencode_mode { REENCODE_ABORT, REENCODE_YES, REENCODE_NO } reencode_mode = REENCODE_ABORT;
4245
static int fake_missing_tagger;
@@ -53,23 +56,24 @@ static int anonymize;
5356
static struct hashmap anonymized_seeds;
5457
static struct revision_sources revision_sources;
5558

56-
static int parse_opt_signed_tag_mode(const struct option *opt,
59+
static int parse_opt_sign_mode(const struct option *opt,
5760
const char *arg, int unset)
5861
{
59-
enum signed_tag_mode *val = opt->value;
60-
61-
if (unset || !strcmp(arg, "abort"))
62-
*val = SIGNED_TAG_ABORT;
62+
enum sign_mode *val = opt->value;
63+
if (unset)
64+
return 0;
65+
else if (!strcmp(arg, "abort"))
66+
*val = SIGN_ABORT;
6367
else if (!strcmp(arg, "verbatim") || !strcmp(arg, "ignore"))
64-
*val = VERBATIM;
68+
*val = SIGN_VERBATIM;
6569
else if (!strcmp(arg, "warn-verbatim") || !strcmp(arg, "warn"))
66-
*val = WARN_VERBATIM;
70+
*val = SIGN_WARN_VERBATIM;
6771
else if (!strcmp(arg, "warn-strip"))
68-
*val = WARN_STRIP;
72+
*val = SIGN_WARN_STRIP;
6973
else if (!strcmp(arg, "strip"))
70-
*val = STRIP;
74+
*val = SIGN_STRIP;
7175
else
72-
return error("Unknown signed-tags mode: %s", arg);
76+
return error("Unknown %s mode: %s", opt->long_name, arg);
7377
return 0;
7478
}
7579

@@ -611,6 +615,43 @@ static void anonymize_ident_line(const char **beg, const char **end)
611615
*end = out->buf + out->len;
612616
}
613617

618+
/*
619+
* find_commit_multiline_header is similar to find_commit_header,
620+
* except that it handles multi-line headers, rather than simply
621+
* returning the first line of the header.
622+
*
623+
* The returned string has had the ' ' line continuation markers
624+
* removed, and points to allocated memory that must be free()d (not
625+
* to memory within 'msg').
626+
*
627+
* If the header is found, then *end is set to point at the '\n' in
628+
* msg that immediately follows the header value.
629+
*/
630+
static const char *find_commit_multiline_header(const char *msg,
631+
const char *key,
632+
const char **end)
633+
{
634+
struct strbuf val = STRBUF_INIT;
635+
const char *bol, *eol;
636+
size_t len;
637+
638+
bol = find_commit_header(msg, key, &len);
639+
if (!bol)
640+
return NULL;
641+
eol = bol + len;
642+
strbuf_add(&val, bol, len);
643+
644+
while (eol[0] == '\n' && eol[1] == ' ') {
645+
bol = eol + 2;
646+
eol = strchrnul(bol, '\n');
647+
strbuf_addch(&val, '\n');
648+
strbuf_add(&val, bol, eol - bol);
649+
}
650+
651+
*end = eol;
652+
return strbuf_detach(&val, NULL);
653+
}
654+
614655
static void handle_commit(struct commit *commit, struct rev_info *rev,
615656
struct string_list *paths_of_changed_objects)
616657
{
@@ -619,6 +660,7 @@ static void handle_commit(struct commit *commit, struct rev_info *rev,
619660
const char *author, *author_end, *committer, *committer_end;
620661
const char *encoding = NULL;
621662
size_t encoding_len;
663+
const char *signature_alg = NULL, *signature = NULL;
622664
const char *message;
623665
char *reencoded = NULL;
624666
struct commit_list *p;
@@ -645,17 +687,25 @@ static void handle_commit(struct commit *commit, struct rev_info *rev,
645687
commit_buffer_cursor = committer_end = strchrnul(committer, '\n');
646688

647689
/*
648-
* find_commit_header() gets a `+ 1` because
649-
* commit_buffer_cursor points at the trailing "\n" at the end
650-
* of the previous line, but find_commit_header() wants a
690+
* find_commit_header() and find_commit_multiline_header() get
691+
* a `+ 1` because commit_buffer_cursor points at the trailing
692+
* "\n" at the end of the previous line, but they want a
651693
* pointer to the beginning of the next line.
652694
*/
695+
653696
if (*commit_buffer_cursor == '\n') {
654697
encoding = find_commit_header(commit_buffer_cursor + 1, "encoding", &encoding_len);
655698
if (encoding)
656699
commit_buffer_cursor = encoding + encoding_len;
657700
}
658701

702+
if (*commit_buffer_cursor == '\n') {
703+
if ((signature = find_commit_multiline_header(commit_buffer_cursor + 1, "gpgsig", &commit_buffer_cursor)))
704+
signature_alg = "sha1";
705+
else if ((signature = find_commit_multiline_header(commit_buffer_cursor + 1, "gpgsig-sha256", &commit_buffer_cursor)))
706+
signature_alg = "sha256";
707+
}
708+
659709
message = strstr(commit_buffer_cursor, "\n\n");
660710
if (message)
661711
message += 2;
@@ -719,6 +769,31 @@ static void handle_commit(struct commit *commit, struct rev_info *rev,
719769
printf("%.*s\n%.*s\n",
720770
(int)(author_end - author), author,
721771
(int)(committer_end - committer), committer);
772+
if (signature) {
773+
switch (signed_commit_mode) {
774+
case SIGN_ABORT:
775+
die("encountered signed commit %s; use "
776+
"--signed-commits=<mode> to handle it",
777+
oid_to_hex(&commit->object.oid));
778+
case SIGN_WARN_VERBATIM:
779+
warning("exporting signed commit %s",
780+
oid_to_hex(&commit->object.oid));
781+
/* fallthru */
782+
case SIGN_VERBATIM:
783+
printf("gpgsig %s\ndata %u\n%s",
784+
signature_alg,
785+
(unsigned)strlen(signature),
786+
signature);
787+
break;
788+
case SIGN_WARN_STRIP:
789+
warning("stripping signature from commit %s",
790+
oid_to_hex(&commit->object.oid));
791+
/* fallthru */
792+
case SIGN_STRIP:
793+
break;
794+
}
795+
free((char *)signature);
796+
}
722797
if (!reencoded && encoding)
723798
printf("encoding %.*s\n", (int)encoding_len, encoding);
724799
printf("data %u\n%s",
@@ -834,21 +909,21 @@ static void handle_tag(const char *name, struct tag *tag)
834909
"\n-----BEGIN PGP SIGNATURE-----\n");
835910
if (signature)
836911
switch (signed_tag_mode) {
837-
case SIGNED_TAG_ABORT:
912+
case SIGN_ABORT:
838913
die("encountered signed tag %s; use "
839914
"--signed-tags=<mode> to handle it",
840915
oid_to_hex(&tag->object.oid));
841-
case WARN_VERBATIM:
916+
case SIGN_WARN_VERBATIM:
842917
warning("exporting signed tag %s",
843918
oid_to_hex(&tag->object.oid));
844919
/* fallthru */
845-
case VERBATIM:
920+
case SIGN_VERBATIM:
846921
break;
847-
case WARN_STRIP:
922+
case SIGN_WARN_STRIP:
848923
warning("stripping signature from tag %s",
849924
oid_to_hex(&tag->object.oid));
850925
/* fallthru */
851-
case STRIP:
926+
case SIGN_STRIP:
852927
message_size = signature + 1 - message;
853928
break;
854929
}
@@ -1194,6 +1269,7 @@ int cmd_fast_export(int argc,
11941269
const char *prefix,
11951270
struct repository *repo UNUSED)
11961271
{
1272+
const char *env_signed_commits_noabort;
11971273
struct rev_info revs;
11981274
struct commit *commit;
11991275
char *export_filename = NULL,
@@ -1207,7 +1283,10 @@ int cmd_fast_export(int argc,
12071283
N_("show progress after <n> objects")),
12081284
OPT_CALLBACK(0, "signed-tags", &signed_tag_mode, N_("mode"),
12091285
N_("select handling of signed tags"),
1210-
parse_opt_signed_tag_mode),
1286+
parse_opt_sign_mode),
1287+
OPT_CALLBACK(0, "signed-commits", &signed_commit_mode, N_("mode"),
1288+
N_("select handling of signed commits"),
1289+
parse_opt_sign_mode),
12111290
OPT_CALLBACK(0, "tag-of-filtered-object", &tag_of_filtered_mode, N_("mode"),
12121291
N_("select handling of tags that tag filtered objects"),
12131292
parse_opt_tag_of_filtered_mode),
@@ -1248,6 +1327,10 @@ int cmd_fast_export(int argc,
12481327
if (argc == 1)
12491328
usage_with_options (fast_export_usage, options);
12501329

1330+
env_signed_commits_noabort = getenv("FAST_EXPORT_SIGNED_COMMITS_NOABORT");
1331+
if (env_signed_commits_noabort && *env_signed_commits_noabort)
1332+
signed_commit_mode = SIGN_WARN_STRIP;
1333+
12511334
/* we handle encodings */
12521335
git_config(git_default_config, NULL);
12531336

builtin/fast-import.c

Lines changed: 23 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2719,10 +2719,13 @@ static struct hash_list *parse_merge(unsigned int *count)
27192719

27202720
static void parse_new_commit(const char *arg)
27212721
{
2722+
static struct strbuf sig = STRBUF_INIT;
27222723
static struct strbuf msg = STRBUF_INIT;
2724+
struct string_list siglines = STRING_LIST_INIT_NODUP;
27232725
struct branch *b;
27242726
char *author = NULL;
27252727
char *committer = NULL;
2728+
char *sig_alg = NULL;
27262729
char *encoding = NULL;
27272730
struct hash_list *merge_list = NULL;
27282731
unsigned int merge_count;
@@ -2746,6 +2749,13 @@ static void parse_new_commit(const char *arg)
27462749
}
27472750
if (!committer)
27482751
die("Expected committer but didn't get one");
2752+
if (skip_prefix(command_buf.buf, "gpgsig ", &v)) {
2753+
sig_alg = xstrdup(v);
2754+
read_next_command();
2755+
parse_data(&sig, 0, NULL);
2756+
read_next_command();
2757+
} else
2758+
strbuf_setlen(&sig, 0);
27492759
if (skip_prefix(command_buf.buf, "encoding ", &v)) {
27502760
encoding = xstrdup(v);
27512761
read_next_command();
@@ -2819,10 +2829,23 @@ static void parse_new_commit(const char *arg)
28192829
strbuf_addf(&new_data,
28202830
"encoding %s\n",
28212831
encoding);
2832+
if (sig_alg) {
2833+
if (!strcmp(sig_alg, "sha1"))
2834+
strbuf_addstr(&new_data, "gpgsig ");
2835+
else if (!strcmp(sig_alg, "sha256"))
2836+
strbuf_addstr(&new_data, "gpgsig-sha256 ");
2837+
else
2838+
die("Expected gpgsig algorithm sha1 or sha256, got %s", sig_alg);
2839+
string_list_split_in_place(&siglines, sig.buf, "\n", -1);
2840+
strbuf_add_separated_string_list(&new_data, "\n ", &siglines);
2841+
strbuf_addch(&new_data, '\n');
2842+
}
28222843
strbuf_addch(&new_data, '\n');
28232844
strbuf_addbuf(&new_data, &msg);
2845+
string_list_clear(&siglines, 1);
28242846
free(author);
28252847
free(committer);
2848+
free(sig_alg);
28262849
free(encoding);
28272850

28282851
if (!store_object(OBJ_COMMIT, &new_data, NULL, &b->oid, next_mark))

0 commit comments

Comments
 (0)