From mboxrd@z Thu Jan 1 00:00:00 1970 From: Konrad Rzeszutek Wilk Subject: Re: pvops0 git tree signing? Date: Tue, 8 Jun 2010 09:37:19 -0400 Message-ID: <20100608133719.GC4775@phenom.dumpdata.com> References: <4C0E2EE7.8000305@invisiblethingslab.com> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Return-path: Content-Disposition: inline In-Reply-To: <4C0E2EE7.8000305@invisiblethingslab.com> List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Sender: xen-devel-bounces@lists.xensource.com Errors-To: xen-devel-bounces@lists.xensource.com To: Joanna Rutkowska Cc: "xen-devel@lists.xensource.com" List-Id: xen-devel@lists.xenproject.org On Tue, Jun 08, 2010 at 01:52:07PM +0200, Joanna Rutkowska wrote: > So, any plans to start signing the pvops kernel commits? I'm really > reluctant to build and sign, and then distribute, an RPM with the > sources fetched from this repo, if I cannot verify they are authentic in > any way. I can easily imagine packagers from other distributions would > think similar. > > It's really just a matter of signing Jeremy's key with the "Xen.org > master key" (0x79BAD9D8), and then typing git tag -s after every major > commit, no? I don't know whether we are truly at a release stage yet? (there are still tons of bugs). Or were you thinking more in terms of whenever Jeremy merges Greg KH's stable 2.6.32 and then tag it?