fast-export, fast-import: add support for signed-commits

fast-export has a --signed-tags= option that controls how to handle tag signatures. However, there is no equivalent for commit signatures; it just silently strips the signature out of the commit (analogously to --signed-tags=strip). While signatures are generally problematic for fast-export/fast-import (because hashes are likely to change), if they're going to support tag signatures, there's no reason to not also support commit signatures. So, implement a --signed-commits= option that mirrors the --signed-tags= option. On the fast-export side, try to be as much like signed-tags as possible, in both implementation and in user-interface. This will change the default behavior to '--signed-commits=abort' from what is now '--signed-commits=strip'. In order to provide an escape hatch for users of third-party tools that call fast-export and do not yet know of the --signed-commits= option, add an environment variable 'FAST_EXPORT_SIGNED_COMMITS_NOABORT=1' that changes the default to '--signed-commits=warn-strip'. Signed-off-by: Luke Shumaker <lukeshu@datawire.io> Signed-off-by: Christian Couder <chriscool@tuxfamily.org> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Luke Shumaker committed Mar 10, 2025 at 16:57 UTC d9cb0e6ff8b369b0410ac8fb11657f5096d74b8e
5 files changed +253 -20
Documentation/git-fast-export.adoc
+11
@@ -44,6 +44,17 @@ affecting tags or any commit in their history will be performed by you
44 or by fast-export or fast-import, or if you do not care that the
45 resulting tag will have an invalid signature.
46
47 +--signed-commits=(verbatim|warn-verbatim|warn-strip|strip|abort)::
48 + Specify how to handle signed commits. Behaves exactly as
49 + '--signed-tags', but for commits. Default is 'abort'.
50 ++
51 +Earlier versions this command that did not have '--signed-commits'
52 +behaved as if '--signed-commits=strip'. As an escape hatch for users
53 +of tools that call 'git fast-export' but do not yet support
54 +'--signed-commits', you may set the environment variable
55 +'FAST_EXPORT_SIGNED_COMMITS_NOABORT=1' in order to change the default
56 +from 'abort' to 'warn-strip'.
57 +
58 --tag-of-filtered-object=(abort|drop|rewrite)::
59 Specify how to handle tags whose tagged object is filtered out.
60 Since revisions and files to export can be limited by path,
Documentation/git-fast-import.adoc
+18
@@ -431,12 +431,21 @@ and control the current import process. More detailed discussion
431 Create or update a branch with a new commit, recording one logical
432 change to the project.
433
434 +////
435 +Yes, it's intentional that the 'gpgsig' line doesn't have a trailing
436 +`LF`; the definition of `data` has a byte-count prefix, so it
437 +doesn't need an `LF` to act as a terminator (and `data` also already
438 +includes an optional trailing `LF?` just in case you want to include
439 +one).
440 +////
441 +
442 ....
443 'commit' SP <ref> LF
444 mark?
445 original-oid?
446 ('author' (SP <name>)? SP LT <email> GT SP <when> LF)?
447 'committer' (SP <name>)? SP LT <email> GT SP <when> LF
448 + ('gpgsig' SP <alg> LF data)?
449 ('encoding' SP <encoding> LF)?
450 data
451 ('from' SP <commit-ish> LF)?
@@ -505,6 +514,15 @@ that was selected by the --date-format=<fmt> command-line option.
514 See ``Date Formats'' above for the set of supported formats, and
515 their syntax.
516
517 +`gpgsig`
518 +^^^^^^^^
519 +
520 +The optional `gpgsig` command is used to include a PGP/GPG signature
521 +that signs the commit data.
522 +
523 +Here <alg> specifies which hashing algorithm is used for this
524 +signature, either `sha1` or `sha256`.
525 +
526 `encoding`
527 ^^^^^^^^^^
528 The optional `encoding` command indicates the encoding of the commit
builtin/fast-export.c
+103 -20
@@ -35,8 +35,11 @@ static const char *fast_export_usage[] = {
35 NULL
36 };
37
38 +enum sign_mode { SIGN_ABORT, SIGN_VERBATIM, SIGN_STRIP, SIGN_WARN_VERBATIM, SIGN_WARN_STRIP };
39 +
40 static int progress;
39 -static enum signed_tag_mode { SIGNED_TAG_ABORT, VERBATIM, WARN_VERBATIM, WARN_STRIP, STRIP } signed_tag_mode = SIGNED_TAG_ABORT;
41 +static enum sign_mode signed_tag_mode = SIGN_ABORT;
42 +static enum sign_mode signed_commit_mode = SIGN_ABORT;
43 static enum tag_of_filtered_mode { TAG_FILTERING_ABORT, DROP, REWRITE } tag_of_filtered_mode = TAG_FILTERING_ABORT;
44 static enum reencode_mode { REENCODE_ABORT, REENCODE_YES, REENCODE_NO } reencode_mode = REENCODE_ABORT;
45 static int fake_missing_tagger;
@@ -53,23 +56,24 @@ static int anonymize;
56 static struct hashmap anonymized_seeds;
57 static struct revision_sources revision_sources;
58
56 -static int parse_opt_signed_tag_mode(const struct option *opt,
59 +static int parse_opt_sign_mode(const struct option *opt,
60 const char *arg, int unset)
61 {
59 - enum signed_tag_mode *val = opt->value;
60 -
61 - if (unset || !strcmp(arg, "abort"))
62 - *val = SIGNED_TAG_ABORT;
62 + enum sign_mode *val = opt->value;
63 + if (unset)
64 + return 0;
65 + else if (!strcmp(arg, "abort"))
66 + *val = SIGN_ABORT;
67 else if (!strcmp(arg, "verbatim") || !strcmp(arg, "ignore"))
64 - *val = VERBATIM;
68 + *val = SIGN_VERBATIM;
69 else if (!strcmp(arg, "warn-verbatim") || !strcmp(arg, "warn"))
66 - *val = WARN_VERBATIM;
70 + *val = SIGN_WARN_VERBATIM;
71 else if (!strcmp(arg, "warn-strip"))
68 - *val = WARN_STRIP;
72 + *val = SIGN_WARN_STRIP;
73 else if (!strcmp(arg, "strip"))
70 - *val = STRIP;
74 + *val = SIGN_STRIP;
75 else
72 - return error("Unknown signed-tags mode: %s", arg);
76 + return error("Unknown %s mode: %s", opt->long_name, arg);
77 return 0;
78 }
79
@@ -611,6 +615,43 @@ static void anonymize_ident_line(const char **beg, const char **end)
615 *end = out->buf + out->len;
616 }
617
618 +/*
619 + * find_commit_multiline_header is similar to find_commit_header,
620 + * except that it handles multi-line headers, rather than simply
621 + * returning the first line of the header.
622 + *
623 + * The returned string has had the ' ' line continuation markers
624 + * removed, and points to allocated memory that must be free()d (not
625 + * to memory within 'msg').
626 + *
627 + * If the header is found, then *end is set to point at the '\n' in
628 + * msg that immediately follows the header value.
629 + */
630 +static const char *find_commit_multiline_header(const char *msg,
631 + const char *key,
632 + const char **end)
633 +{
634 + struct strbuf val = STRBUF_INIT;
635 + const char *bol, *eol;
636 + size_t len;
637 +
638 + bol = find_commit_header(msg, key, &len);
639 + if (!bol)
640 + return NULL;
641 + eol = bol + len;
642 + strbuf_add(&val, bol, len);
643 +
644 + while (eol[0] == '\n' && eol[1] == ' ') {
645 + bol = eol + 2;
646 + eol = strchrnul(bol, '\n');
647 + strbuf_addch(&val, '\n');
648 + strbuf_add(&val, bol, eol - bol);
649 + }
650 +
651 + *end = eol;
652 + return strbuf_detach(&val, NULL);
653 +}
654 +
655 static void handle_commit(struct commit *commit, struct rev_info *rev,
656 struct string_list *paths_of_changed_objects)
657 {
@@ -619,6 +660,7 @@ static void handle_commit(struct commit *commit, struct rev_info *rev,
660 const char *author, *author_end, *committer, *committer_end;
661 const char *encoding = NULL;
662 size_t encoding_len;
663 + const char *signature_alg = NULL, *signature = NULL;
664 const char *message;
665 char *reencoded = NULL;
666 struct commit_list *p;
@@ -645,17 +687,25 @@ static void handle_commit(struct commit *commit, struct rev_info *rev,
687 commit_buffer_cursor = committer_end = strchrnul(committer, '\n');
688
689 /*
648 - * find_commit_header() gets a `+ 1` because
649 - * commit_buffer_cursor points at the trailing "\n" at the end
650 - * of the previous line, but find_commit_header() wants a
690 + * find_commit_header() and find_commit_multiline_header() get
691 + * a `+ 1` because commit_buffer_cursor points at the trailing
692 + * "\n" at the end of the previous line, but they want a
693 * pointer to the beginning of the next line.
694 */
695 +
696 if (*commit_buffer_cursor == '\n') {
697 encoding = find_commit_header(commit_buffer_cursor + 1, "encoding", &encoding_len);
698 if (encoding)
699 commit_buffer_cursor = encoding + encoding_len;
700 }
701
702 + if (*commit_buffer_cursor == '\n') {
703 + if ((signature = find_commit_multiline_header(commit_buffer_cursor + 1, "gpgsig", &commit_buffer_cursor)))
704 + signature_alg = "sha1";
705 + else if ((signature = find_commit_multiline_header(commit_buffer_cursor + 1, "gpgsig-sha256", &commit_buffer_cursor)))
706 + signature_alg = "sha256";
707 + }
708 +
709 message = strstr(commit_buffer_cursor, "\n\n");
710 if (message)
711 message += 2;
@@ -719,6 +769,31 @@ static void handle_commit(struct commit *commit, struct rev_info *rev,
769 printf("%.*s\n%.*s\n",
770 (int)(author_end - author), author,
771 (int)(committer_end - committer), committer);
772 + if (signature) {
773 + switch (signed_commit_mode) {
774 + case SIGN_ABORT:
775 + die("encountered signed commit %s; use "
776 + "--signed-commits=<mode> to handle it",
777 + oid_to_hex(&commit->object.oid));
778 + case SIGN_WARN_VERBATIM:
779 + warning("exporting signed commit %s",
780 + oid_to_hex(&commit->object.oid));
781 + /* fallthru */
782 + case SIGN_VERBATIM:
783 + printf("gpgsig %s\ndata %u\n%s",
784 + signature_alg,
785 + (unsigned)strlen(signature),
786 + signature);
787 + break;
788 + case SIGN_WARN_STRIP:
789 + warning("stripping signature from commit %s",
790 + oid_to_hex(&commit->object.oid));
791 + /* fallthru */
792 + case SIGN_STRIP:
793 + break;
794 + }
795 + free((char *)signature);
796 + }
797 if (!reencoded && encoding)
798 printf("encoding %.*s\n", (int)encoding_len, encoding);
799 printf("data %u\n%s",
@@ -834,21 +909,21 @@ static void handle_tag(const char *name, struct tag *tag)
909 "\n-----BEGIN PGP SIGNATURE-----\n");
910 if (signature)
911 switch (signed_tag_mode) {
837 - case SIGNED_TAG_ABORT:
912 + case SIGN_ABORT:
913 die("encountered signed tag %s; use "
914 "--signed-tags=<mode> to handle it",
915 oid_to_hex(&tag->object.oid));
841 - case WARN_VERBATIM:
916 + case SIGN_WARN_VERBATIM:
917 warning("exporting signed tag %s",
918 oid_to_hex(&tag->object.oid));
919 /* fallthru */
845 - case VERBATIM:
920 + case SIGN_VERBATIM:
921 break;
847 - case WARN_STRIP:
922 + case SIGN_WARN_STRIP:
923 warning("stripping signature from tag %s",
924 oid_to_hex(&tag->object.oid));
925 /* fallthru */
851 - case STRIP:
926 + case SIGN_STRIP:
927 message_size = signature + 1 - message;
928 break;
929 }
@@ -1194,6 +1269,7 @@ int cmd_fast_export(int argc,
1269 const char *prefix,
1270 struct repository *repo UNUSED)
1271 {
1272 + const char *env_signed_commits_noabort;
1273 struct rev_info revs;
1274 struct commit *commit;
1275 char *export_filename = NULL,
@@ -1207,7 +1283,10 @@ int cmd_fast_export(int argc,
1283 N_("show progress after <n> objects")),
1284 OPT_CALLBACK(0, "signed-tags", &signed_tag_mode, N_("mode"),
1285 N_("select handling of signed tags"),
1210 - parse_opt_signed_tag_mode),
1286 + parse_opt_sign_mode),
1287 + OPT_CALLBACK(0, "signed-commits", &signed_commit_mode, N_("mode"),
1288 + N_("select handling of signed commits"),
1289 + parse_opt_sign_mode),
1290 OPT_CALLBACK(0, "tag-of-filtered-object", &tag_of_filtered_mode, N_("mode"),
1291 N_("select handling of tags that tag filtered objects"),
1292 parse_opt_tag_of_filtered_mode),
@@ -1248,6 +1327,10 @@ int cmd_fast_export(int argc,
1327 if (argc == 1)
1328 usage_with_options (fast_export_usage, options);
1329
1330 + env_signed_commits_noabort = getenv("FAST_EXPORT_SIGNED_COMMITS_NOABORT");
1331 + if (env_signed_commits_noabort && *env_signed_commits_noabort)
1332 + signed_commit_mode = SIGN_WARN_STRIP;
1333 +
1334 /* we handle encodings */
1335 git_config(git_default_config, NULL);
1336
builtin/fast-import.c
+23
@@ -2719,10 +2719,13 @@ static struct hash_list *parse_merge(unsigned int *count)
2719
2720 static void parse_new_commit(const char *arg)
2721 {
2722 + static struct strbuf sig = STRBUF_INIT;
2723 static struct strbuf msg = STRBUF_INIT;
2724 + struct string_list siglines = STRING_LIST_INIT_NODUP;
2725 struct branch *b;
2726 char *author = NULL;
2727 char *committer = NULL;
2728 + char *sig_alg = NULL;
2729 char *encoding = NULL;
2730 struct hash_list *merge_list = NULL;
2731 unsigned int merge_count;
@@ -2746,6 +2749,13 @@ static void parse_new_commit(const char *arg)
2749 }
2750 if (!committer)
2751 die("Expected committer but didn't get one");
2752 + if (skip_prefix(command_buf.buf, "gpgsig ", &v)) {
2753 + sig_alg = xstrdup(v);
2754 + read_next_command();
2755 + parse_data(&sig, 0, NULL);
2756 + read_next_command();
2757 + } else
2758 + strbuf_setlen(&sig, 0);
2759 if (skip_prefix(command_buf.buf, "encoding ", &v)) {
2760 encoding = xstrdup(v);
2761 read_next_command();
@@ -2819,10 +2829,23 @@ static void parse_new_commit(const char *arg)
2829 strbuf_addf(&new_data,
2830 "encoding %s\n",
2831 encoding);
2832 + if (sig_alg) {
2833 + if (!strcmp(sig_alg, "sha1"))
2834 + strbuf_addstr(&new_data, "gpgsig ");
2835 + else if (!strcmp(sig_alg, "sha256"))
2836 + strbuf_addstr(&new_data, "gpgsig-sha256 ");
2837 + else
2838 + die("Expected gpgsig algorithm sha1 or sha256, got %s", sig_alg);
2839 + string_list_split_in_place(&siglines, sig.buf, "\n", -1);
2840 + strbuf_add_separated_string_list(&new_data, "\n ", &siglines);
2841 + strbuf_addch(&new_data, '\n');
2842 + }
2843 strbuf_addch(&new_data, '\n');
2844 strbuf_addbuf(&new_data, &msg);
2845 + string_list_clear(&siglines, 1);
2846 free(author);
2847 free(committer);
2848 + free(sig_alg);
2849 free(encoding);
2850
2851 if (!store_object(OBJ_COMMIT, &new_data, NULL, &b->oid, next_mark))
t/t9350-fast-export.sh
+98
@@ -8,6 +8,7 @@ GIT_TEST_DEFAULT_INITIAL_BRANCH_NAME=main
8 export GIT_TEST_DEFAULT_INITIAL_BRANCH_NAME
9
10 . ./test-lib.sh
11 +. "$TEST_DIRECTORY/lib-gpg.sh"
12
13 test_expect_success 'setup' '
14
@@ -284,10 +285,107 @@ test_expect_success 'signed-tags=warn-strip' '
285 test -s err
286 '
287
288 +test_expect_success GPG 'set up signed commit' '
289 +
290 + # Generate a commit with both "gpgsig" and "encoding" set, so
291 + # that we can test that fast-import gets the ordering correct
292 + # between the two.
293 + test_config i18n.commitEncoding ISO-8859-1 &&
294 + git checkout -f -b commit-signing main &&
295 + echo Sign your name >file-sign &&
296 + git add file-sign &&
297 + git commit -S -m "signed commit" &&
298 + COMMIT_SIGNING=$(git rev-parse --verify commit-signing)
299 +
300 +'
301 +
302 +test_expect_success GPG 'signed-commits default' '
303 +
304 + sane_unset FAST_EXPORT_SIGNED_COMMITS_NOABORT &&
305 + test_must_fail git fast-export --reencode=no commit-signing &&
306 +
307 + FAST_EXPORT_SIGNED_COMMITS_NOABORT=1 git fast-export --reencode=no commit-signing >output 2>err &&
308 + ! grep ^gpgsig output &&
309 + grep "^encoding ISO-8859-1" output &&
310 + test -s err &&
311 + sed "s/commit-signing/commit-strip-signing/" output | (
312 + cd new &&
313 + git fast-import &&
314 + STRIPPED=$(git rev-parse --verify refs/heads/commit-strip-signing) &&
315 + test $COMMIT_SIGNING != $STRIPPED
316 + )
317 +
318 +'
319 +
320 +test_expect_success GPG 'signed-commits=abort' '
321 +
322 + test_must_fail git fast-export --signed-commits=abort commit-signing
323 +
324 +'
325 +
326 +test_expect_success GPG 'signed-commits=verbatim' '
327 +
328 + git fast-export --signed-commits=verbatim --reencode=no commit-signing >output &&
329 + grep "^gpgsig sha" output &&
330 + grep "encoding ISO-8859-1" output &&
331 + (
332 + cd new &&
333 + git fast-import &&
334 + STRIPPED=$(git rev-parse --verify refs/heads/commit-signing) &&
335 + test $COMMIT_SIGNING = $STRIPPED
336 + ) <output
337 +
338 +'
339 +
340 +test_expect_success GPG 'signed-commits=warn-verbatim' '
341 +
342 + git fast-export --signed-commits=warn-verbatim --reencode=no commit-signing >output 2>err &&
343 + grep "^gpgsig sha" output &&
344 + grep "encoding ISO-8859-1" output &&
345 + test -s err &&
346 + (
347 + cd new &&
348 + git fast-import &&
349 + STRIPPED=$(git rev-parse --verify refs/heads/commit-signing) &&
350 + test $COMMIT_SIGNING = $STRIPPED
351 + ) <output
352 +
353 +'
354 +
355 +test_expect_success GPG 'signed-commits=strip' '
356 +
357 + git fast-export --signed-commits=strip --reencode=no commit-signing >output &&
358 + ! grep ^gpgsig output &&
359 + grep "^encoding ISO-8859-1" output &&
360 + sed "s/commit-signing/commit-strip-signing/" output | (
361 + cd new &&
362 + git fast-import &&
363 + STRIPPED=$(git rev-parse --verify refs/heads/commit-strip-signing) &&
364 + test $COMMIT_SIGNING != $STRIPPED
365 + )
366 +
367 +'
368 +
369 +test_expect_success GPG 'signed-commits=warn-strip' '
370 +
371 + git fast-export --signed-commits=warn-strip --reencode=no commit-signing >output 2>err &&
372 + ! grep ^gpgsig output &&
373 + grep "^encoding ISO-8859-1" output &&
374 + test -s err &&
375 + sed "s/commit-signing/commit-strip-signing/" output | (
376 + cd new &&
377 + git fast-import &&
378 + STRIPPED=$(git rev-parse --verify refs/heads/commit-strip-signing) &&
379 + test $COMMIT_SIGNING != $STRIPPED
380 + )
381 +
382 +'
383 +
384 test_expect_success 'setup submodule' '
385
386 test_config_global protocol.file.allow always &&
387 git checkout -f main &&
388 + test_might_fail git update-ref -d refs/heads/commit-signing &&
389 mkdir sub &&
390 (
391 cd sub &&