Your message dated Sun, 19 Jul 2026 14:33:43 +0000
with message-id <[email protected]>
and subject line Bug#1106071: fixed in dgit 16.1~exp1
has caused the Debian Bug report #1106071,
regarding wanted: tag2upload support for pristine-tar
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1106071: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1106071
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: dgit-infrastructure
Version: 13.0
Severity: wishlist
tl;dr:
tag2upload ought to support, but not recommend or encourage,
pristine-tar. But I'm probably not the person to implemnt it.
Desirability of pristine-tar
----------------------------
Currently, tsg2upload doesn't support pristine-tar. For
new-upstream-version uploads, it will use `git-deborig` which is a
thin wrapper around `git-archive`. After #1105862 it will try to
detect when the user was trying to use pristine-tar, and fail.
pristine-tar's purpose is to mitigate some of the inconvenience of the
doctrine that Debian should base its work on, and redistribute,
upstream tarballs. Personally, I think that doctrine is obsolete,
even harmful, for a large majority of upstreams. Also, pristine-tar
is something of a hack and doesn't always work.
So my personal view is that pristine-tar is largely pointless
complexity to support an inferior workflow - indeed, a workflow that
exposes us to greater upstream supply chain risk since upstream
tarballs are less trustworthy than upstream git.
However, a key goal of tag2upload (and indeed my whole git transition
project) is to try to meet people where they are - and that includes
supporting partial transitions from tarballs+patches to git. I think
pristine-tar falls into this category.
Therefore I think tag2upload *should* support pristine-tar.
But we should definitely recommend against it, and not put any
barriers in the way of people who don't use pristine-tar.
Implementation
--------------
I have almost never used pristine-tar and I don't intend to adopt it
now. I don't really know how it works - what git refs it uses, what
the contents are, what invariants it preserves, and so on. I think
the design and implementation would have to be done by someone who
does understand these things (and can explain them to me).
I think the ingredients (and skills needed) would be:
* Some new metadata item(s) in the please-upload tag, including
details of precisely which pristine-tar git objects are to be used,
and maybe what refs they are to be fetched from if that's not
obvious. (Security and correctness design; pristine-tar.)
* Recheck the code in git-debpush that does pristine-tar detection,
which we are currently adding as part of #1105862 (which is just to
detect use of pristine-tar and *reject*, to avoid mistakes).
If we're going to use it to control the output, rather than merely
as a safety catch against mistakes, It needs to be reliable.
(Security and correctness design; pristine-tar; bash.)
* Code in git-debpush to check that the pristine-tar information is
consistent with the rest of the git information. In particular, we
must check that the tarball implied by pristine-tar is treesame to
the upstream tag. IDK if this is true by pristine-tar's design.
(Security and correctness design; pristine-tar; bash.)
* Given the design, code in dgit-repos-server to parse the new tag
metadata, fetch the pristine-tar objects (easy) and run
pristine-tar (probably also easy). (Perl; pristine-tar; help from
tag2upload authors.)
* Change in tag2upload-service-manager to tolerate but ignore the new
critical metadata item in the tag. (Rust; easy.)
* Test cases in dgit.git. (Bash; Perl; pristine-tar. Help wrestling
the test suite from the src:dgit maintainers.)
References
----------
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1105862
git-debpush check to detect and fail if user wanted pristine-tar
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=891033
request for dgit to use pristine-tar automatically
Anyone who is interested in working on this should please get in
touch.
Ian.
--
Ian Jackson <[email protected]> These opinions are my own.
Pronouns: they/he. If I emailed you from @fyvzl.net or @evade.org.uk,
that is a private address which bypasses my fierce spamfilter.
--- End Message ---
--- Begin Message ---
Source: dgit
Source-Version: 16.1~exp1
Done: Ian Jackson <[email protected]>
We believe that the bug you reported is fixed in the latest version of
dgit, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Ian Jackson <[email protected]> (supplier of updated dgit package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Sun, 19 Jul 2026 11:05:39 +0100
Source: dgit
Architecture: source
Version: 16.1~exp1
Distribution: experimental
Urgency: medium
Maintainer: Debian tag2upload Delegates <[email protected]>
Changed-By: Ian Jackson <[email protected]>
Closes: 1106071
Changes:
dgit (16.1~exp1) experimental; urgency=medium
.
git-debpush:
* Implement pristine-tar support. Closes: #1106071.
Checksums-Sha1:
7714e7c1968a55b4603768bf5fae23d768706273 2553 dgit_16.1~exp1.dsc
e9599c39ea8330b845b12668c0a2e723322e4946 1064413 dgit_16.1~exp1.tar.gz
f0fd3e97bd9a2d40a1f62e7002aa1161171039f7 1367548 dgit_16.1~exp1.git.tar.xz
0d72d13a0281cf463981c49a917d17c78e566807 17542 dgit_16.1~exp1_source.buildinfo
Checksums-Sha256:
80e033273a98fa23efd2349423d18b78293bcf9c9471a1a1fc77e709787c1de9 2553
dgit_16.1~exp1.dsc
98e38096caad622bc3dce68990a5c318dc792cc03b743944ed4245fc5626eb3d 1064413
dgit_16.1~exp1.tar.gz
5507d35425d1a4a0693069671fd83745ea8d95996373784e5d680612ab17c684 1367548
dgit_16.1~exp1.git.tar.xz
155905e8a8aa1181ab7ada8820cf0cacaba4a22b2fc8efdf7c281d7f25226d6f 17542
dgit_16.1~exp1_source.buildinfo
Files:
185e8f5ca6960380afe14c979eac8adb 2553 devel optional dgit_16.1~exp1.dsc
af9198f05330bfa58805eb7327d29aeb 1064413 devel optional dgit_16.1~exp1.tar.gz
6dbfef83cd048d7e5d151ff32e23a331 1367548 devel optional
dgit_16.1~exp1.git.tar.xz
248234a2092e20ffdf7b1f362bf0b8a7 17542 devel optional
dgit_16.1~exp1_source.buildinfo
Git-Tag-Info: tag=6bd84406fadbc0b5df8b501c65368d6dc8dccc92
fp=41638114d132883b25a20ddd47515757d8002456
Git-Tag-Tagger: Ian Jackson <[email protected]>
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmpc3J8ACgkQYG0ITkaD
wHlxchAA7b2QLiS1F8GYh+Ylsnj+bGHGyZnh3rNDbbmN9U5pgNM9QYhGM5R1pISf
Sx9HcMd0fKJ0YoAOJd5OoNbC191Ktw1hDbn/47v8mhzS35K48s3OtoB/ZaxdXvru
3ofwxHABj42EXnkC+uryATxyunO0bjpA3Eik75x/mT3YSout35vqKqbV/Qh509Bn
Xyxq6VGI9evZoAhrEq4O0tbsUXnJMqrty0OZcs3m7uLt+nLNQQ0Rzvy0E/QWZ7bp
/ASrCBxX1aohDmi3+1nivvfu1ClTKHNDuHM3y8SiIhlSgocvxRBGNniFb2m0ASDE
MQw29jW82/p3Ay/D8n3Oa1WyrFL/KvL3cH7NSLIZyhl+7FyUs6g04x0VZnxLklfM
rt/glWezqLM0yW4mJULN78H6/tWkzfOA3yRxSEq2KKnVbhY5JSvAQJAGbkzxynv4
Jr+QsnWQCwh0o9JTolQuZmzyS/5RGroLe2zSItZfPGzCMbrYhSbvG7FkXVJ8bgW1
hgExZjL37qKuDKj8eG7xSc0ej0A9gxK/ljx4ki4Fh/cbUeOlxDC3tiUK6GFVzyf5
xBXp/+S4Faz6fWxkw3CurFMBYlHt4L0OiMRtZxNyZcSCRFN4DWsMOY8kJlVG/WqY
sMLmLquzPGVcvHc2ziuFHZZfLolQV9yQ/3R+29JGeGWkQ6P7vng=
=bYY+
-----END PGP SIGNATURE-----
pgpSZj5YVYlzB.pgp
Description: PGP signature
--- End Message ---