From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from pigeon.gentoo.org ([208.92.234.80] helo=lists.gentoo.org) by finch.gentoo.org with esmtp (Exim 4.60) (envelope-from ) id 1SbXXK-0003MP-P4 for garchives@archives.gentoo.org; Mon, 04 Jun 2012 13:41:34 +0000 Received: from pigeon.gentoo.org (localhost [127.0.0.1]) by pigeon.gentoo.org (Postfix) with SMTP id 050DDE059B; Mon, 4 Jun 2012 13:41:10 +0000 (UTC) Received: from mail-bk0-f53.google.com (mail-bk0-f53.google.com [209.85.214.53]) by pigeon.gentoo.org (Postfix) with ESMTP id AB624E0700 for ; Mon, 4 Jun 2012 13:40:06 +0000 (UTC) Received: by bkcjk13 with SMTP id jk13so4102382bkc.40 for ; Mon, 04 Jun 2012 06:40:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:sender:in-reply-to:references:date :x-google-sender-auth:message-id:subject:from:to:content-type; bh=cXqrCo9QzRLffYwxlJrK7rKQEMDMDC18RFQpVMLgPMk=; b=RP/9A+g2ZLOLaxa2G4sT0y3DT284nnZvCNUWQZxL1U/0W8BE8lYmJWhgKDdQXbtKl6 BHzDJVwS3IDRH/rUFRDK3EA0jxnzmiVMdoZlBnjj+3yiWQAYhjwCxmC1U21VmPivtO1X sZ8TBmGtzsvJJKva4ubQGRlpQaluyWStzONrVQY3lZs5Sx7lvvyUVDPSJBZXKx2qljdZ wh6wGDBjtguGsh29bPHHSGucorP3s/x6JHxmicfI5REMCuyvUOscIBtKZ3mQMg2F9xV2 KIEw/9anJ1lNjgaILgD8vnUcV8K2acB+JVUVNj5fSFCpQf9lwLffP8UNShNtRCS0sS0w xKQw== Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-Id: Gentoo Linux mail X-BeenThere: gentoo-dev@lists.gentoo.org Reply-to: gentoo-dev@lists.gentoo.org MIME-Version: 1.0 Received: by 10.204.152.196 with SMTP id h4mr6982627bkw.131.1338817205738; Mon, 04 Jun 2012 06:40:05 -0700 (PDT) Sender: freemanrich@gmail.com Received: by 10.204.149.211 with HTTP; Mon, 4 Jun 2012 06:40:05 -0700 (PDT) In-Reply-To: References: <201206031239.21744.dilfridge@gentoo.org> <201206032135.49757.dilfridge@gentoo.org> Date: Mon, 4 Jun 2012 09:40:05 -0400 X-Google-Sender-Auth: xMy_P_03iSTsjTQNJqwSR8MrGgc Message-ID: Subject: Re: [gentoo-dev] Git braindump: 1 of N: merging & git signing From: Rich Freeman To: gentoo-dev@lists.gentoo.org Content-Type: text/plain; charset=ISO-8859-1 X-Archives-Salt: c96fb1b0-21a6-496a-a7bc-e3a9edd2d71e X-Archives-Hash: 6f64f15d8579433a63665409dffa3fa2 On Mon, Jun 4, 2012 at 8:45 AM, Dirkjan Ochtman wrote: > > Well, it doesn't seem like a big deal IF there's an explicit merge > commit that's signed by a dev. I'm not sure about that. If you were verifying a tree, how would you identify which commits were merged in by what dev, using an automated algorithm? The only thing the merge commit contains is a list of two parents, and a tree. It doesn't say which one is which, unless we can rely on their order. Now, all those intermediate commits were never actually published via rsync, so their integrity isn't a direct issue. However, I'm not sure how easy automated verification would be. Rich