From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.io!.POSTED.blaine.gmane.org!not-for-mail From: Eli Zaretskii Newsgroups: gmane.emacs.devel Subject: Re: Signing git tags for releases Date: Thu, 09 Dec 2021 09:37:20 +0200 Message-ID: <83pmq6ut3j.fsf@gnu.org> References: <87tufpy9ii.fsf@gnus.org> Injection-Info: ciao.gmane.io; posting-host="blaine.gmane.org:116.202.254.214"; logging-data="37807"; mail-complaints-to="usenet@ciao.gmane.io" Cc: larsi@gnus.org, emacs-devel@gnu.org To: Stefan Kangas Original-X-From: emacs-devel-bounces+ged-emacs-devel=m.gmane-mx.org@gnu.org Thu Dec 09 08:38:48 2021 Return-path: Envelope-to: ged-emacs-devel@m.gmane-mx.org Original-Received: from lists.gnu.org ([209.51.188.17]) by ciao.gmane.io with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1mvE0t-0009fJ-Dd for ged-emacs-devel@m.gmane-mx.org; Thu, 09 Dec 2021 08:38:47 +0100 Original-Received: from localhost ([::1]:37538 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1mvE0s-00063R-32 for ged-emacs-devel@m.gmane-mx.org; Thu, 09 Dec 2021 02:38:46 -0500 Original-Received: from eggs.gnu.org ([209.51.188.92]:47550) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1mvDzl-0005M1-3Q for emacs-devel@gnu.org; Thu, 09 Dec 2021 02:37:37 -0500 Original-Received: from [2001:470:142:3::e] (port=33214 helo=fencepost.gnu.org) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1mvDzk-0001fL-MG; Thu, 09 Dec 2021 02:37:36 -0500 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=gnu.org; s=fencepost-gnu-org; h=References:Subject:In-Reply-To:To:From:Date: mime-version; bh=/DaCGltYeMAVCDT81YmxpkyMXBLwa3lojT/oHxkUsGI=; b=dcbSeaOy3F2l AvPREZ5V9mV3gQQ18+EdxzmVycGbAtkRoIdL6jKR8OdX+lVlf92Kf+Dz3dTGv9Y23+S9nqzFG4kmW j0PHETYnmqL45bU1E0T6S8iZZW6pwBdc6/6wFKorKS7OP9xu8zPrWrZ4X9C7OiMrP+QBl/9rEgeVp 70zHh+VVjTPO+ikmhTwXXln98X0qy4f2JgarkVubEnEmuWwa47WiV4m/jYkup0l+NfGrIizAEuIaf YcyQVAkV2VnQ0dFvIRkjn8TzPbT1fyOdCFe7AWP5of5z+80kk7rfM2XwPDr7iMESVw61ztyjGPw2u TyOr+MFksfnXD17jYAxfjA==; Original-Received: from [87.69.77.57] (port=1981 helo=home-c4e4a596f7) by fencepost.gnu.org with esmtpsa (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1mvDzk-0005nb-GM; Thu, 09 Dec 2021 02:37:36 -0500 In-Reply-To: (message from Stefan Kangas on Wed, 8 Dec 2021 14:06:33 -0800) X-BeenThere: emacs-devel@gnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: "Emacs development discussions." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: emacs-devel-bounces+ged-emacs-devel=m.gmane-mx.org@gnu.org Original-Sender: "Emacs-devel" Xref: news.gmane.io gmane.emacs.devel:281453 Archived-At: > From: Stefan Kangas > Date: Wed, 8 Dec 2021 14:06:33 -0800 > Cc: emacs-devel@gnu.org > > There have been no other comments within a week, besides the one from > Teemu Likonen who spotted a mistake in the patch I proposed. > > If anyone has anything more to add here, there is still some time to > speak up before it is time for the second pretest. If I don't see any > further comments until then, I will go ahead with the proposed plan. At least one important aspect remains un-discussed: how do we make sure the keys of those who sign tags are made available for the others, who'd like to verify the signatures. This will have to be described in CONTRIBUTE, with enough detail for people to follow even if they aren't experts in GnuPG use. More generally, what exactly is proposed? I think it would be good to see some text for CONTRIBUTE and/or make-tarball.txt (or other docs) with what will be the procedures related to this. IOW, I don't think the discussion, such as it was, was detailed enough, and I won't be surprised if people didn't really understand what we are going to change and how. This gap needs to be filled before we can conclude that "everyone is in favor". Thanks.