Your message dated Fri, 31 Jul 2026 12:20:51 +0000
with message-id <[email protected]>
and subject line Bug#1106071: fixed in dgit 16.1
has caused the Debian Bug report #1106071,
regarding wanted: tag2upload support for pristine-tar
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1106071: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1106071
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: dgit-infrastructure
Version: 13.0
Severity: wishlist

tl;dr:
  tag2upload ought to support, but not recommend or encourage,
  pristine-tar.  But I'm probably not the person to implemnt it.

Desirability of pristine-tar
----------------------------

Currently, tsg2upload doesn't support pristine-tar.  For
new-upstream-version uploads, it will use `git-deborig` which is a
thin wrapper around `git-archive`.  After #1105862 it will try to
detect when the user was trying to use pristine-tar, and fail.

pristine-tar's purpose is to mitigate some of the inconvenience of the
doctrine that Debian should base its work on, and redistribute,
upstream tarballs.  Personally, I think that doctrine is obsolete,
even harmful, for a large majority of upstreams.  Also, pristine-tar
is something of a hack and doesn't always work.

So my personal view is that pristine-tar is largely pointless
complexity to support an inferior workflow - indeed, a workflow that
exposes us to greater upstream supply chain risk since upstream
tarballs are less trustworthy than upstream git.

However, a key goal of tag2upload (and indeed my whole git transition
project) is to try to meet people where they are - and that includes
supporting partial transitions from tarballs+patches to git.  I think
pristine-tar falls into this category.

Therefore I think tag2upload *should* support pristine-tar.

But we should definitely recommend against it, and not put any
barriers in the way of people who don't use pristine-tar.


Implementation
--------------

I have almost never used pristine-tar and I don't intend to adopt it
now.  I don't really know how it works - what git refs it uses, what
the contents are, what invariants it preserves, and so on.  I think
the design and implementation would have to be done by someone who
does understand these things (and can explain them to me).

I think the ingredients (and skills needed) would be:

 * Some new metadata item(s) in the please-upload tag, including
   details of precisely which pristine-tar git objects are to be used,
   and maybe what refs they are to be fetched from if that's not
   obvious.  (Security and correctness design; pristine-tar.)

 * Recheck the code in git-debpush that does pristine-tar detection,
   which we are currently adding as part of #1105862 (which is just to
   detect use of pristine-tar and *reject*, to avoid mistakes).
   If we're going to use it to control the output, rather than merely
   as a safety catch against mistakes, It needs to be reliable.
   (Security and correctness design; pristine-tar; bash.)

 * Code in git-debpush to check that the pristine-tar information is
   consistent with the rest of the git information.  In particular, we
   must check that the tarball implied by pristine-tar is treesame to
   the upstream tag.  IDK if this is true by pristine-tar's design.
   (Security and correctness design; pristine-tar; bash.)

 * Given the design, code in dgit-repos-server to parse the new tag
   metadata, fetch the pristine-tar objects (easy) and run
   pristine-tar (probably also easy).  (Perl; pristine-tar; help from
   tag2upload authors.)

 * Change in tag2upload-service-manager to tolerate but ignore the new
   critical metadata item in the tag.  (Rust; easy.)

 * Test cases in dgit.git.  (Bash; Perl; pristine-tar.  Help wrestling
   the test suite from the src:dgit maintainers.)


References
----------

  https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1105862
    git-debpush check to detect and fail if user wanted pristine-tar

  https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=891033
    request for dgit to use pristine-tar automatically


Anyone who is interested in working on this should please get in
touch.

Ian.

-- 
Ian Jackson <[email protected]>   These opinions are my own.  

Pronouns: they/he.  If I emailed you from @fyvzl.net or @evade.org.uk,
that is a private address which bypasses my fierce spamfilter.

--- End Message ---
--- Begin Message ---
Source: dgit
Source-Version: 16.1
Done: Ian Jackson <[email protected]>

We believe that the bug you reported is fixed in the latest version of
dgit, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Ian Jackson <[email protected]> (supplier of updated dgit package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Fri, 31 Jul 2026 12:18:04 +0100
Source: dgit
Architecture: source
Version: 16.1
Distribution: unstable
Urgency: medium
Maintainer: Debian tag2upload Delegates <[email protected]>
Changed-By: Ian Jackson <[email protected]>
Closes: 1106071 1142508
Changes:
 dgit (16.1) unstable; urgency=medium
 .
   git-debpush:
   * git-debpush(1): New FILES and BEHAVIOUR sections;
     remove mention of no-longer-relevant --force-pristine-tar.
     [Report from gregor herrmann]  Closes: #1142508.
 .
 dgit (16.1~exp1) experimental; urgency=medium
 .
   git-debpush:
   * Implement pristine-tar support.  Closes: #1106071.
Checksums-Sha1:
 dd4bb10d0956b92c1b1886fb1e7c1345d4b8d664 2528 dgit_16.1.dsc
 fea28353669b4383fe1daa5a779b7e67010dcaaa 1066226 dgit_16.1.tar.gz
 d0cafd4f90cdd6dda5e0beaac5f980a31ef28f18 1368888 dgit_16.1.git.tar.xz
 471722389294b99be694f5acc6db9b0055f9ae57 17522 dgit_16.1_source.buildinfo
Checksums-Sha256:
 d7aeadbe6513f78ee4fa1c3e267793c8cf3299221f92a2ed0b98742024dba2f0 2528 
dgit_16.1.dsc
 2d71313e6ca9feeb1dd4965656a7cf7a0ff0ede62955075876a0c608170488ad 1066226 
dgit_16.1.tar.gz
 fab85d4e2bd723a87fb12f35495b4a9379d018bc255cffa3379b49aaf09178dd 1368888 
dgit_16.1.git.tar.xz
 afe7f1ce0404dff0abbd34ac50a5be688ea6cbe4f6e6174bcae2dc86c8cada10 17522 
dgit_16.1_source.buildinfo
Files:
 1ba8b9791b153d58eb168f896ce02f1d 2528 devel optional dgit_16.1.dsc
 d5670e66f8538a8f22192b2c657b3bc5 1066226 devel optional dgit_16.1.tar.gz
 cf3499eb07348f94b2c3d84f71a7cc6b 1368888 devel optional dgit_16.1.git.tar.xz
 4b73e247dca895560744b63d71f0b7df 17522 devel optional 
dgit_16.1_source.buildinfo
Git-Tag-Info: tag=04d71a5360b5c3962660abacbf4da09ba88d049e 
fp=41638114d132883b25a20ddd47515757d8002456
Git-Tag-Tagger: Ian Jackson <[email protected]>

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmpskJAACgkQYG0ITkaD
wHngBg//ZveQQmZGbu9VS1uAnC1vjvilW1tBrkzrl3hAtsMdS7G+Tsd3X9TP8Aii
BTsC/fAIp2Hb809p9heD2hmq0yVFkSBOB1sg7wvOnqr4Jm+x6Mp9BHZdoLUThQT9
7L1Sa7s6NFScWQw5iH/ODSXKnc1+7CSsbcx5PmMsAUQ+alIrFPoHh+9eiLBwqxvt
5HG4cpGXTFXlDxddRCViNL1WG0c/3QnVXlHUQF0eHBNH+piK8EMqFxi4eztk3eKt
KpVK9VKefapRdBL9+Iv4DzTnMc7xca1m1kwcRjyUnE49EMru6d3OPOFu1Q39hOxU
aftxRgI69VL/52+6zdu2WDxWiccqpXaGFnln2rqN0jIWlbs1eYgZr4ZQH8vIc6as
jfS6EIohnCbQQYh/nUUn4iZ/UgOIJPTfBovyxCKfuUWm0F2q9WvYnVcnhav36p5q
/Rwf26hK0dlpxUBuFTzSte/YyQvcefvG9V1gQCf33MHZy7fIkPQKTp0yczpP26bZ
sxhyF+WG5m8caT/jBp5aD6ndY8DBbnW965p1gwODIWtfusV/wzFnNzJzXheKbkCG
P2sOBaFb6KBmgmtzNgazKqNgN++09rry6AFXokFcbCn5dmU4v86Flwuz0yztYLbY
7AvaNH6LfW3UKvGZbFVR82wBVP8upWY7sZGgc+iH6vv7wi3IwpU=
=OcJG
-----END PGP SIGNATURE-----

Attachment: pgpaN9QoVlZyY.pgp
Description: PGP signature


--- End Message ---

Reply via email to