Autogenerated HTML docs for v2.42.0-526-g3130c1
[git-htmldocs.git] / howto / using-signed-tag-in-pull-request.html
blob56ce9ba420a4a8ea9f04b8662c49fd03fb17d5f6
1 <?xml version="1.0" encoding="UTF-8"?>
2 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN"
3 "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
4 <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en">
5 <head>
6 <meta http-equiv="Content-Type" content="application/xhtml+xml; charset=UTF-8" />
7 <meta name="generator" content="AsciiDoc 10.2.0" />
8 <title>How to use a signed tag in pull requests</title>
9 <style type="text/css">
10 /* Shared CSS for AsciiDoc xhtml11 and html5 backends */
12 /* Default font. */
13 body {
14 font-family: Georgia,serif;
17 /* Title font. */
18 h1, h2, h3, h4, h5, h6,
19 div.title, caption.title,
20 thead, p.table.header,
21 #toctitle,
22 #author, #revnumber, #revdate, #revremark,
23 #footer {
24 font-family: Arial,Helvetica,sans-serif;
27 body {
28 margin: 1em 5% 1em 5%;
31 a {
32 color: blue;
33 text-decoration: underline;
35 a:visited {
36 color: fuchsia;
39 em {
40 font-style: italic;
41 color: navy;
44 strong {
45 font-weight: bold;
46 color: #083194;
49 h1, h2, h3, h4, h5, h6 {
50 color: #527bbd;
51 margin-top: 1.2em;
52 margin-bottom: 0.5em;
53 line-height: 1.3;
56 h1, h2, h3 {
57 border-bottom: 2px solid silver;
59 h2 {
60 padding-top: 0.5em;
62 h3 {
63 float: left;
65 h3 + * {
66 clear: left;
68 h5 {
69 font-size: 1.0em;
72 div.sectionbody {
73 margin-left: 0;
76 hr {
77 border: 1px solid silver;
80 p {
81 margin-top: 0.5em;
82 margin-bottom: 0.5em;
85 ul, ol, li > p {
86 margin-top: 0;
88 ul > li { color: #aaa; }
89 ul > li > * { color: black; }
91 .monospaced, code, pre {
92 font-family: "Courier New", Courier, monospace;
93 font-size: inherit;
94 color: navy;
95 padding: 0;
96 margin: 0;
98 pre {
99 white-space: pre-wrap;
102 #author {
103 color: #527bbd;
104 font-weight: bold;
105 font-size: 1.1em;
107 #email {
109 #revnumber, #revdate, #revremark {
112 #footer {
113 font-size: small;
114 border-top: 2px solid silver;
115 padding-top: 0.5em;
116 margin-top: 4.0em;
118 #footer-text {
119 float: left;
120 padding-bottom: 0.5em;
122 #footer-badges {
123 float: right;
124 padding-bottom: 0.5em;
127 #preamble {
128 margin-top: 1.5em;
129 margin-bottom: 1.5em;
131 div.imageblock, div.exampleblock, div.verseblock,
132 div.quoteblock, div.literalblock, div.listingblock, div.sidebarblock,
133 div.admonitionblock {
134 margin-top: 1.0em;
135 margin-bottom: 1.5em;
137 div.admonitionblock {
138 margin-top: 2.0em;
139 margin-bottom: 2.0em;
140 margin-right: 10%;
141 color: #606060;
144 div.content { /* Block element content. */
145 padding: 0;
148 /* Block element titles. */
149 div.title, caption.title {
150 color: #527bbd;
151 font-weight: bold;
152 text-align: left;
153 margin-top: 1.0em;
154 margin-bottom: 0.5em;
156 div.title + * {
157 margin-top: 0;
160 td div.title:first-child {
161 margin-top: 0.0em;
163 div.content div.title:first-child {
164 margin-top: 0.0em;
166 div.content + div.title {
167 margin-top: 0.0em;
170 div.sidebarblock > div.content {
171 background: #ffffee;
172 border: 1px solid #dddddd;
173 border-left: 4px solid #f0f0f0;
174 padding: 0.5em;
177 div.listingblock > div.content {
178 border: 1px solid #dddddd;
179 border-left: 5px solid #f0f0f0;
180 background: #f8f8f8;
181 padding: 0.5em;
184 div.quoteblock, div.verseblock {
185 padding-left: 1.0em;
186 margin-left: 1.0em;
187 margin-right: 10%;
188 border-left: 5px solid #f0f0f0;
189 color: #888;
192 div.quoteblock > div.attribution {
193 padding-top: 0.5em;
194 text-align: right;
197 div.verseblock > pre.content {
198 font-family: inherit;
199 font-size: inherit;
201 div.verseblock > div.attribution {
202 padding-top: 0.75em;
203 text-align: left;
205 /* DEPRECATED: Pre version 8.2.7 verse style literal block. */
206 div.verseblock + div.attribution {
207 text-align: left;
210 div.admonitionblock .icon {
211 vertical-align: top;
212 font-size: 1.1em;
213 font-weight: bold;
214 text-decoration: underline;
215 color: #527bbd;
216 padding-right: 0.5em;
218 div.admonitionblock td.content {
219 padding-left: 0.5em;
220 border-left: 3px solid #dddddd;
223 div.exampleblock > div.content {
224 border-left: 3px solid #dddddd;
225 padding-left: 0.5em;
228 div.imageblock div.content { padding-left: 0; }
229 span.image img { border-style: none; vertical-align: text-bottom; }
230 a.image:visited { color: white; }
232 dl {
233 margin-top: 0.8em;
234 margin-bottom: 0.8em;
236 dt {
237 margin-top: 0.5em;
238 margin-bottom: 0;
239 font-style: normal;
240 color: navy;
242 dd > *:first-child {
243 margin-top: 0.1em;
246 ul, ol {
247 list-style-position: outside;
249 ol.arabic {
250 list-style-type: decimal;
252 ol.loweralpha {
253 list-style-type: lower-alpha;
255 ol.upperalpha {
256 list-style-type: upper-alpha;
258 ol.lowerroman {
259 list-style-type: lower-roman;
261 ol.upperroman {
262 list-style-type: upper-roman;
265 div.compact ul, div.compact ol,
266 div.compact p, div.compact p,
267 div.compact div, div.compact div {
268 margin-top: 0.1em;
269 margin-bottom: 0.1em;
272 tfoot {
273 font-weight: bold;
275 td > div.verse {
276 white-space: pre;
279 div.hdlist {
280 margin-top: 0.8em;
281 margin-bottom: 0.8em;
283 div.hdlist tr {
284 padding-bottom: 15px;
286 dt.hdlist1.strong, td.hdlist1.strong {
287 font-weight: bold;
289 td.hdlist1 {
290 vertical-align: top;
291 font-style: normal;
292 padding-right: 0.8em;
293 color: navy;
295 td.hdlist2 {
296 vertical-align: top;
298 div.hdlist.compact tr {
299 margin: 0;
300 padding-bottom: 0;
303 .comment {
304 background: yellow;
307 .footnote, .footnoteref {
308 font-size: 0.8em;
311 span.footnote, span.footnoteref {
312 vertical-align: super;
315 #footnotes {
316 margin: 20px 0 20px 0;
317 padding: 7px 0 0 0;
320 #footnotes div.footnote {
321 margin: 0 0 5px 0;
324 #footnotes hr {
325 border: none;
326 border-top: 1px solid silver;
327 height: 1px;
328 text-align: left;
329 margin-left: 0;
330 width: 20%;
331 min-width: 100px;
334 div.colist td {
335 padding-right: 0.5em;
336 padding-bottom: 0.3em;
337 vertical-align: top;
339 div.colist td img {
340 margin-top: 0.3em;
343 @media print {
344 #footer-badges { display: none; }
347 #toc {
348 margin-bottom: 2.5em;
351 #toctitle {
352 color: #527bbd;
353 font-size: 1.1em;
354 font-weight: bold;
355 margin-top: 1.0em;
356 margin-bottom: 0.1em;
359 div.toclevel0, div.toclevel1, div.toclevel2, div.toclevel3, div.toclevel4 {
360 margin-top: 0;
361 margin-bottom: 0;
363 div.toclevel2 {
364 margin-left: 2em;
365 font-size: 0.9em;
367 div.toclevel3 {
368 margin-left: 4em;
369 font-size: 0.9em;
371 div.toclevel4 {
372 margin-left: 6em;
373 font-size: 0.9em;
376 span.aqua { color: aqua; }
377 span.black { color: black; }
378 span.blue { color: blue; }
379 span.fuchsia { color: fuchsia; }
380 span.gray { color: gray; }
381 span.green { color: green; }
382 span.lime { color: lime; }
383 span.maroon { color: maroon; }
384 span.navy { color: navy; }
385 span.olive { color: olive; }
386 span.purple { color: purple; }
387 span.red { color: red; }
388 span.silver { color: silver; }
389 span.teal { color: teal; }
390 span.white { color: white; }
391 span.yellow { color: yellow; }
393 span.aqua-background { background: aqua; }
394 span.black-background { background: black; }
395 span.blue-background { background: blue; }
396 span.fuchsia-background { background: fuchsia; }
397 span.gray-background { background: gray; }
398 span.green-background { background: green; }
399 span.lime-background { background: lime; }
400 span.maroon-background { background: maroon; }
401 span.navy-background { background: navy; }
402 span.olive-background { background: olive; }
403 span.purple-background { background: purple; }
404 span.red-background { background: red; }
405 span.silver-background { background: silver; }
406 span.teal-background { background: teal; }
407 span.white-background { background: white; }
408 span.yellow-background { background: yellow; }
410 span.big { font-size: 2em; }
411 span.small { font-size: 0.6em; }
413 span.underline { text-decoration: underline; }
414 span.overline { text-decoration: overline; }
415 span.line-through { text-decoration: line-through; }
417 div.unbreakable { page-break-inside: avoid; }
421 * xhtml11 specific
423 * */
425 div.tableblock {
426 margin-top: 1.0em;
427 margin-bottom: 1.5em;
429 div.tableblock > table {
430 border: 3px solid #527bbd;
432 thead, p.table.header {
433 font-weight: bold;
434 color: #527bbd;
436 p.table {
437 margin-top: 0;
439 /* Because the table frame attribute is overridden by CSS in most browsers. */
440 div.tableblock > table[frame="void"] {
441 border-style: none;
443 div.tableblock > table[frame="hsides"] {
444 border-left-style: none;
445 border-right-style: none;
447 div.tableblock > table[frame="vsides"] {
448 border-top-style: none;
449 border-bottom-style: none;
454 * html5 specific
456 * */
458 table.tableblock {
459 margin-top: 1.0em;
460 margin-bottom: 1.5em;
462 thead, p.tableblock.header {
463 font-weight: bold;
464 color: #527bbd;
466 p.tableblock {
467 margin-top: 0;
469 table.tableblock {
470 border-width: 3px;
471 border-spacing: 0px;
472 border-style: solid;
473 border-color: #527bbd;
474 border-collapse: collapse;
476 th.tableblock, td.tableblock {
477 border-width: 1px;
478 padding: 4px;
479 border-style: solid;
480 border-color: #527bbd;
483 table.tableblock.frame-topbot {
484 border-left-style: hidden;
485 border-right-style: hidden;
487 table.tableblock.frame-sides {
488 border-top-style: hidden;
489 border-bottom-style: hidden;
491 table.tableblock.frame-none {
492 border-style: hidden;
495 th.tableblock.halign-left, td.tableblock.halign-left {
496 text-align: left;
498 th.tableblock.halign-center, td.tableblock.halign-center {
499 text-align: center;
501 th.tableblock.halign-right, td.tableblock.halign-right {
502 text-align: right;
505 th.tableblock.valign-top, td.tableblock.valign-top {
506 vertical-align: top;
508 th.tableblock.valign-middle, td.tableblock.valign-middle {
509 vertical-align: middle;
511 th.tableblock.valign-bottom, td.tableblock.valign-bottom {
512 vertical-align: bottom;
517 * manpage specific
519 * */
521 body.manpage h1 {
522 padding-top: 0.5em;
523 padding-bottom: 0.5em;
524 border-top: 2px solid silver;
525 border-bottom: 2px solid silver;
527 body.manpage h2 {
528 border-style: none;
530 body.manpage div.sectionbody {
531 margin-left: 3em;
534 @media print {
535 body.manpage div#toc { display: none; }
539 </style>
540 <script type="text/javascript">
541 /*<![CDATA[*/
542 var asciidoc = { // Namespace.
544 /////////////////////////////////////////////////////////////////////
545 // Table Of Contents generator
546 /////////////////////////////////////////////////////////////////////
548 /* Author: Mihai Bazon, September 2002
549 * http://students.infoiasi.ro/~mishoo
551 * Table Of Content generator
552 * Version: 0.4
554 * Feel free to use this script under the terms of the GNU General Public
555 * License, as long as you do not remove or alter this notice.
558 /* modified by Troy D. Hanson, September 2006. License: GPL */
559 /* modified by Stuart Rackham, 2006, 2009. License: GPL */
561 // toclevels = 1..4.
562 toc: function (toclevels) {
564 function getText(el) {
565 var text = "";
566 for (var i = el.firstChild; i != null; i = i.nextSibling) {
567 if (i.nodeType == 3 /* Node.TEXT_NODE */) // IE doesn't speak constants.
568 text += i.data;
569 else if (i.firstChild != null)
570 text += getText(i);
572 return text;
575 function TocEntry(el, text, toclevel) {
576 this.element = el;
577 this.text = text;
578 this.toclevel = toclevel;
581 function tocEntries(el, toclevels) {
582 var result = new Array;
583 var re = new RegExp('[hH]([1-'+(toclevels+1)+'])');
584 // Function that scans the DOM tree for header elements (the DOM2
585 // nodeIterator API would be a better technique but not supported by all
586 // browsers).
587 var iterate = function (el) {
588 for (var i = el.firstChild; i != null; i = i.nextSibling) {
589 if (i.nodeType == 1 /* Node.ELEMENT_NODE */) {
590 var mo = re.exec(i.tagName);
591 if (mo && (i.getAttribute("class") || i.getAttribute("className")) != "float") {
592 result[result.length] = new TocEntry(i, getText(i), mo[1]-1);
594 iterate(i);
598 iterate(el);
599 return result;
602 var toc = document.getElementById("toc");
603 if (!toc) {
604 return;
607 // Delete existing TOC entries in case we're reloading the TOC.
608 var tocEntriesToRemove = [];
609 var i;
610 for (i = 0; i < toc.childNodes.length; i++) {
611 var entry = toc.childNodes[i];
612 if (entry.nodeName.toLowerCase() == 'div'
613 && entry.getAttribute("class")
614 && entry.getAttribute("class").match(/^toclevel/))
615 tocEntriesToRemove.push(entry);
617 for (i = 0; i < tocEntriesToRemove.length; i++) {
618 toc.removeChild(tocEntriesToRemove[i]);
621 // Rebuild TOC entries.
622 var entries = tocEntries(document.getElementById("content"), toclevels);
623 for (var i = 0; i < entries.length; ++i) {
624 var entry = entries[i];
625 if (entry.element.id == "")
626 entry.element.id = "_toc_" + i;
627 var a = document.createElement("a");
628 a.href = "#" + entry.element.id;
629 a.appendChild(document.createTextNode(entry.text));
630 var div = document.createElement("div");
631 div.appendChild(a);
632 div.className = "toclevel" + entry.toclevel;
633 toc.appendChild(div);
635 if (entries.length == 0)
636 toc.parentNode.removeChild(toc);
640 /////////////////////////////////////////////////////////////////////
641 // Footnotes generator
642 /////////////////////////////////////////////////////////////////////
644 /* Based on footnote generation code from:
645 * http://www.brandspankingnew.net/archive/2005/07/format_footnote.html
648 footnotes: function () {
649 // Delete existing footnote entries in case we're reloading the footnodes.
650 var i;
651 var noteholder = document.getElementById("footnotes");
652 if (!noteholder) {
653 return;
655 var entriesToRemove = [];
656 for (i = 0; i < noteholder.childNodes.length; i++) {
657 var entry = noteholder.childNodes[i];
658 if (entry.nodeName.toLowerCase() == 'div' && entry.getAttribute("class") == "footnote")
659 entriesToRemove.push(entry);
661 for (i = 0; i < entriesToRemove.length; i++) {
662 noteholder.removeChild(entriesToRemove[i]);
665 // Rebuild footnote entries.
666 var cont = document.getElementById("content");
667 var spans = cont.getElementsByTagName("span");
668 var refs = {};
669 var n = 0;
670 for (i=0; i<spans.length; i++) {
671 if (spans[i].className == "footnote") {
672 n++;
673 var note = spans[i].getAttribute("data-note");
674 if (!note) {
675 // Use [\s\S] in place of . so multi-line matches work.
676 // Because JavaScript has no s (dotall) regex flag.
677 note = spans[i].innerHTML.match(/\s*\[([\s\S]*)]\s*/)[1];
678 spans[i].innerHTML =
679 "[<a id='_footnoteref_" + n + "' href='#_footnote_" + n +
680 "' title='View footnote' class='footnote'>" + n + "</a>]";
681 spans[i].setAttribute("data-note", note);
683 noteholder.innerHTML +=
684 "<div class='footnote' id='_footnote_" + n + "'>" +
685 "<a href='#_footnoteref_" + n + "' title='Return to text'>" +
686 n + "</a>. " + note + "</div>";
687 var id =spans[i].getAttribute("id");
688 if (id != null) refs["#"+id] = n;
691 if (n == 0)
692 noteholder.parentNode.removeChild(noteholder);
693 else {
694 // Process footnoterefs.
695 for (i=0; i<spans.length; i++) {
696 if (spans[i].className == "footnoteref") {
697 var href = spans[i].getElementsByTagName("a")[0].getAttribute("href");
698 href = href.match(/#.*/)[0]; // Because IE return full URL.
699 n = refs[href];
700 spans[i].innerHTML =
701 "[<a href='#_footnote_" + n +
702 "' title='View footnote' class='footnote'>" + n + "</a>]";
708 install: function(toclevels) {
709 var timerId;
711 function reinstall() {
712 asciidoc.footnotes();
713 if (toclevels) {
714 asciidoc.toc(toclevels);
718 function reinstallAndRemoveTimer() {
719 clearInterval(timerId);
720 reinstall();
723 timerId = setInterval(reinstall, 500);
724 if (document.addEventListener)
725 document.addEventListener("DOMContentLoaded", reinstallAndRemoveTimer, false);
726 else
727 window.onload = reinstallAndRemoveTimer;
731 asciidoc.install();
732 /*]]>*/
733 </script>
734 </head>
735 <body class="article">
736 <div id="header">
737 <h1>How to use a signed tag in pull requests</h1>
738 <span id="revdate">2023-10-29</span>
739 </div>
740 <div id="content">
741 <div id="preamble">
742 <div class="sectionbody">
743 <div class="paragraph"><p>A typical distributed workflow using Git is for a contributor to fork a
744 project, build on it, publish the result to her public repository, and ask
745 the "upstream" person (often the owner of the project where she forked
746 from) to pull from her public repository. Requesting such a "pull" is made
747 easy by the <code>git request-pull</code> command.</p></div>
748 <div class="paragraph"><p>Earlier, a typical pull request may have started like this:</p></div>
749 <div class="listingblock">
750 <div class="content">
751 <pre><code> The following changes since commit 406da78032179...:
753 Froboz 3.2 (2011-09-30 14:20:57 -0700)
755 are available in the Git repository at:
757 example.com:/git/froboz.git for-xyzzy</code></pre>
758 </div></div>
759 <div class="paragraph"><p>followed by a shortlog of the changes and a diffstat.</p></div>
760 <div class="paragraph"><p>The request was for a branch name (e.g. <code>for-xyzzy</code>) in the public
761 repository of the contributor, and even though it stated where the
762 contributor forked her work from, the message did not say anything about
763 the commit to expect at the tip of the for-xyzzy branch. If the site that
764 hosts the public repository of the contributor cannot be fully trusted, it
765 was unnecessarily hard to make sure what was pulled by the integrator was
766 genuinely what the contributor had produced for the project. Also there
767 was no easy way for third-party auditors to later verify the resulting
768 history.</p></div>
769 <div class="paragraph"><p>Starting from Git release v1.7.9, a contributor can add a signed tag to
770 the commit at the tip of the history and ask the integrator to pull that
771 signed tag. When the integrator runs <code>git pull</code>, the signed tag is
772 automatically verified to assure that the history is not tampered with.
773 In addition, the resulting merge commit records the content of the signed
774 tag, so that other people can verify that the branch merged by the
775 integrator was signed by the contributor, without fetching the signed tag
776 used to validate the pull request separately and keeping it in the refs
777 namespace.</p></div>
778 <div class="paragraph"><p>This document describes the workflow between the contributor and the
779 integrator, using Git v1.7.9 or later.</p></div>
780 </div>
781 </div>
782 <div class="sect1">
783 <h2 id="_a_contributor_or_a_lieutenant">A contributor or a lieutenant</h2>
784 <div class="sectionbody">
785 <div class="paragraph"><p>After preparing her work to be pulled, the contributor uses <code>git tag -s</code>
786 to create a signed tag:</p></div>
787 <div class="listingblock">
788 <div class="content">
789 <pre><code> $ git checkout work
790 $ ... "git pull" from sublieutenants, "git commit" your own work ...
791 $ git tag -s -m "Completed frotz feature" frotz-for-xyzzy work</code></pre>
792 </div></div>
793 <div class="paragraph"><p>Note that this example uses the <code>-m</code> option to create a signed tag with
794 just a one-liner message, but this is for illustration purposes only. It
795 is advisable to compose a well-written explanation of what the topic does
796 to justify why it is worthwhile for the integrator to pull it, as this
797 message will eventually become part of the final history after the
798 integrator responds to the pull request (as we will see later).</p></div>
799 <div class="paragraph"><p>Then she pushes the tag out to her public repository:</p></div>
800 <div class="listingblock">
801 <div class="content">
802 <pre><code> $ git push example.com:/git/froboz.git/ +frotz-for-xyzzy</code></pre>
803 </div></div>
804 <div class="paragraph"><p>There is no need to push the <code>work</code> branch or anything else.</p></div>
805 <div class="paragraph"><p>Note that the above command line used a plus sign at the beginning of
806 <code>+frotz-for-xyzzy</code> to allow forcing the update of a tag, as the same
807 contributor may want to reuse a signed tag with the same name after the
808 previous pull request has already been responded to.</p></div>
809 <div class="paragraph"><p>The contributor then prepares a message to request a "pull":</p></div>
810 <div class="listingblock">
811 <div class="content">
812 <pre><code> $ git request-pull v3.2 example.com:/git/froboz.git/ frotz-for-xyzzy &gt;msg.txt</code></pre>
813 </div></div>
814 <div class="paragraph"><p>The arguments are:</p></div>
815 <div class="olist arabic"><ol class="arabic">
816 <li>
818 the version of the integrator&#8217;s commit the contributor based her work on;
819 </p>
820 </li>
821 <li>
823 the URL of the repository, to which the contributor has pushed what she
824 wants to get pulled; and
825 </p>
826 </li>
827 <li>
829 the name of the tag the contributor wants to get pulled (earlier, she could
830 write only a branch name here).
831 </p>
832 </li>
833 </ol></div>
834 <div class="paragraph"><p>The resulting msg.txt file begins like so:</p></div>
835 <div class="listingblock">
836 <div class="content">
837 <pre><code> The following changes since commit 406da78032179...:
839 Froboz 3.2 (2011-09-30 14:20:57 -0700)
841 are available in the Git repository at:
843 example.com:/git/froboz.git tags/frotz-for-xyzzy
845 for you to fetch changes up to 703f05ad5835c...:
847 Add tests and documentation for frotz (2011-12-02 10:02:52 -0800)
849 -----------------------------------------------
850 Completed frotz feature
851 -----------------------------------------------</code></pre>
852 </div></div>
853 <div class="paragraph"><p>followed by a shortlog of the changes and a diffstat. Comparing this with
854 the earlier illustration of the output from the traditional <code>git request-pull</code>
855 command, the reader should notice that:</p></div>
856 <div class="olist arabic"><ol class="arabic">
857 <li>
859 The tip commit to expect is shown to the integrator; and
860 </p>
861 </li>
862 <li>
864 The signed tag message is shown prominently between the dashed lines
865 before the shortlog.
866 </p>
867 </li>
868 </ol></div>
869 <div class="paragraph"><p>The latter is why the contributor would want to justify why pulling her
870 work is worthwhile when creating the signed tag. The contributor then
871 opens her favorite MUA, reads msg.txt, edits and sends it to her upstream
872 integrator.</p></div>
873 </div>
874 </div>
875 <div class="sect1">
876 <h2 id="_integrator">Integrator</h2>
877 <div class="sectionbody">
878 <div class="paragraph"><p>After receiving such a pull request message, the integrator fetches and
879 integrates the tag named in the request, with:</p></div>
880 <div class="listingblock">
881 <div class="content">
882 <pre><code> $ git pull example.com:/git/froboz.git/ tags/frotz-for-xyzzy</code></pre>
883 </div></div>
884 <div class="paragraph"><p>This operation will always open an editor to allow the integrator to fine
885 tune the commit log message when merging a signed tag. Also, pulling a
886 signed tag will always create a merge commit even when the integrator does
887 not have any new commit since the contributor&#8217;s work forked (i.e. <em>fast
888 forward</em>), so that the integrator can properly explain what the merge is
889 about and why it was made.</p></div>
890 <div class="paragraph"><p>In the editor, the integrator will see something like this:</p></div>
891 <div class="listingblock">
892 <div class="content">
893 <pre><code> Merge tag 'frotz-for-xyzzy' of example.com:/git/froboz.git/
895 Completed frotz feature
896 # gpg: Signature made Fri 02 Dec 2011 10:03:01 AM PST using RSA key ID 96AFE6CB
897 # gpg: Good signature from "Con Tributor &lt;nitfol@example.com&gt;"</code></pre>
898 </div></div>
899 <div class="paragraph"><p>Notice that the message recorded in the signed tag "Completed frotz
900 feature" appears here, and again that is why it is important for the
901 contributor to explain her work well when creating the signed tag.</p></div>
902 <div class="paragraph"><p>As usual, the lines commented with <code>#</code> are stripped out. The resulting
903 commit records the signed tag used for this validation in a hidden field
904 so that it can later be used by others to audit the history. There is no
905 need for the integrator to keep a separate copy of the tag in his
906 repository (i.e. <code>git tag -l</code> won&#8217;t list the <code>frotz-for-xyzzy</code> tag in the
907 above example), and there is no need to publish the tag to his public
908 repository, either.</p></div>
909 <div class="paragraph"><p>After the integrator responds to the pull request and her work becomes
910 part of the permanent history, the contributor can remove the tag from
911 her public repository, if she chooses, in order to keep the tag namespace
912 of her public repository clean, with:</p></div>
913 <div class="listingblock">
914 <div class="content">
915 <pre><code> $ git push example.com:/git/froboz.git :frotz-for-xyzzy</code></pre>
916 </div></div>
917 </div>
918 </div>
919 <div class="sect1">
920 <h2 id="_auditors">Auditors</h2>
921 <div class="sectionbody">
922 <div class="paragraph"><p>The <code>--show-signature</code> option can be given to <code>git log</code> or <code>git show</code> and
923 shows the verification status of the embedded signed tag in merge commits
924 created when the integrator responded to a pull request of a signed tag.</p></div>
925 <div class="paragraph"><p>A typical output from <code>git show --show-signature</code> may look like this:</p></div>
926 <div class="listingblock">
927 <div class="content">
928 <pre><code> $ git show --show-signature
929 commit 02306ef6a3498a39118aef9df7975bdb50091585
930 merged tag 'frotz-for-xyzzy'
931 gpg: Signature made Fri 06 Jan 2012 12:41:49 PM PST using RSA key ID 96AFE6CB
932 gpg: Good signature from "Con Tributor &lt;nitfol@example.com&gt;"
933 Merge: 406da78 703f05a
934 Author: Inte Grator &lt;xyzzy@example.com&gt;
935 Date: Tue Jan 17 13:49:41 2012 -0800
937 Merge tag 'frotz-for-xyzzy' of example.com:/git/froboz.git/
939 Completed frotz feature
941 * tag 'frotz-for-xyzzy' (100 commits)
942 Add tests and documentation for frotz
943 ...</code></pre>
944 </div></div>
945 <div class="paragraph"><p>There is no need for the auditor to explicitly fetch the contributor&#8217;s
946 signature, or to even be aware of what tag(s) the contributor and integrator
947 used to communicate the signature. All the required information is recorded
948 as part of the merge commit.</p></div>
949 </div>
950 </div>
951 </div>
952 <div id="footnotes"><hr /></div>
953 <div id="footer">
954 <div id="footer-text">
955 Last updated
956 2023-10-30 08:42:31 JST
957 </div>
958 </div>
959 </body>
960 </html>