feat: import Chinese-localized Buzz source snapshot
Docker image / Build (linux/amd64) (push) Has been cancelled
Docker image / Build (linux/arm64) (push) Has been cancelled
Docker image / Merge release multi-arch manifest (push) Has been cancelled
Docker image / Merge debug multi-arch manifest (push) Has been cancelled
Docker image / Build public push gateway (linux/amd64) (push) Has been cancelled
Docker image / Build public push gateway (linux/arm64) (push) Has been cancelled
Docker image / Publish public push gateway image (push) Has been cancelled
Sprig image / Build (linux/amd64) (push) Has been cancelled
Sprig image / Build (linux/arm64) (push) Has been cancelled
Sprig image / Merge multi-arch manifest (push) Has been cancelled
Harbor Buzz Orchestra / Python tests and lint (push) Has been cancelled
CI / Detect Changed Paths (push) Has been cancelled
CI / Rust Lint (push) Has been cancelled
CI / Unit Tests (push) Has been cancelled
CI / Desktop Core (push) Has been cancelled
CI / Desktop Smoke E2E (1) (push) Has been cancelled
CI / Desktop Smoke E2E (2) (push) Has been cancelled
CI / Desktop Smoke E2E (3) (push) Has been cancelled
CI / Desktop Smoke E2E (4) (push) Has been cancelled
CI / Desktop (push) Has been cancelled
CI / Desktop E2E Relay (push) Has been cancelled
CI / Desktop E2E Integration (1/2) (push) Has been cancelled
CI / Desktop E2E Integration (2/2) (push) Has been cancelled
CI / Desktop E2E Integration (push) Has been cancelled
CI / Backend Integration (relay e2e) (push) Has been cancelled
CI / Relay E2E (push) Has been cancelled
CI / Web (push) Has been cancelled
CI / Mobile (push) Has been cancelled
CI / Security (push) Has been cancelled
CI / Dead Token Reference Guard (push) Has been cancelled
CI / Server Cross-Compile (aarch64-unknown-linux-musl) (push) Has been cancelled
CI / Server Cross-Compile (x86_64-unknown-linux-musl) (push) Has been cancelled
CI / Windows Rust (x86_64-pc-windows-msvc) (push) Has been cancelled
CI / Desktop Build (macOS) (push) Has been cancelled
helm chart / lint + unittest + render matrix (push) Has been cancelled
helm chart / install on kind (gated) (push) Has been cancelled
helm chart / publish chart to GHCR (push) Has been cancelled
Mesh Lifecycle / Relay-Driven Mesh Lifecycle Smoke (push) Has been cancelled
Sprig / Build (aarch64-unknown-linux-musl) (push) Has been cancelled
Sprig / Build (x86_64-unknown-linux-musl) (push) Has been cancelled
Sprig / Publish rolling release (push) Has been cancelled
Sprig / Publish tagged release (push) Has been cancelled
Docker image / Build (linux/amd64) (push) Has been cancelled
Docker image / Build (linux/arm64) (push) Has been cancelled
Docker image / Merge release multi-arch manifest (push) Has been cancelled
Docker image / Merge debug multi-arch manifest (push) Has been cancelled
Docker image / Build public push gateway (linux/amd64) (push) Has been cancelled
Docker image / Build public push gateway (linux/arm64) (push) Has been cancelled
Docker image / Publish public push gateway image (push) Has been cancelled
Sprig image / Build (linux/amd64) (push) Has been cancelled
Sprig image / Build (linux/arm64) (push) Has been cancelled
Sprig image / Merge multi-arch manifest (push) Has been cancelled
Harbor Buzz Orchestra / Python tests and lint (push) Has been cancelled
CI / Detect Changed Paths (push) Has been cancelled
CI / Rust Lint (push) Has been cancelled
CI / Unit Tests (push) Has been cancelled
CI / Desktop Core (push) Has been cancelled
CI / Desktop Smoke E2E (1) (push) Has been cancelled
CI / Desktop Smoke E2E (2) (push) Has been cancelled
CI / Desktop Smoke E2E (3) (push) Has been cancelled
CI / Desktop Smoke E2E (4) (push) Has been cancelled
CI / Desktop (push) Has been cancelled
CI / Desktop E2E Relay (push) Has been cancelled
CI / Desktop E2E Integration (1/2) (push) Has been cancelled
CI / Desktop E2E Integration (2/2) (push) Has been cancelled
CI / Desktop E2E Integration (push) Has been cancelled
CI / Backend Integration (relay e2e) (push) Has been cancelled
CI / Relay E2E (push) Has been cancelled
CI / Web (push) Has been cancelled
CI / Mobile (push) Has been cancelled
CI / Security (push) Has been cancelled
CI / Dead Token Reference Guard (push) Has been cancelled
CI / Server Cross-Compile (aarch64-unknown-linux-musl) (push) Has been cancelled
CI / Server Cross-Compile (x86_64-unknown-linux-musl) (push) Has been cancelled
CI / Windows Rust (x86_64-pc-windows-msvc) (push) Has been cancelled
CI / Desktop Build (macOS) (push) Has been cancelled
helm chart / lint + unittest + render matrix (push) Has been cancelled
helm chart / install on kind (gated) (push) Has been cancelled
helm chart / publish chart to GHCR (push) Has been cancelled
Mesh Lifecycle / Relay-Driven Mesh Lifecycle Smoke (push) Has been cancelled
Sprig / Build (aarch64-unknown-linux-musl) (push) Has been cancelled
Sprig / Build (x86_64-unknown-linux-musl) (push) Has been cancelled
Sprig / Publish rolling release (push) Has been cancelled
Sprig / Publish tagged release (push) Has been cancelled
Signed-off-by: cls_宁波本机 <908705107@qq.com>
This commit is contained in:
@@ -0,0 +1,45 @@
|
||||
[package]
|
||||
name = "git-sign-nostr"
|
||||
version.workspace = true
|
||||
edition.workspace = true
|
||||
rust-version.workspace = true
|
||||
license.workspace = true
|
||||
repository.workspace = true
|
||||
description = "NIP-GS git commit/tag signing program using Nostr secp256k1 keys"
|
||||
readme = "README.md"
|
||||
publish = false # internal workspace tool, not published to crates.io
|
||||
|
||||
[lib]
|
||||
name = "git_sign_nostr"
|
||||
path = "src/lib.rs"
|
||||
|
||||
[[bin]]
|
||||
name = "git-sign-nostr"
|
||||
path = "src/main.rs"
|
||||
|
||||
[dependencies]
|
||||
# Base64 armor encoding/decoding for NIP-GS signature envelopes.
|
||||
# Not in workspace deps — each crate pins independently (same pattern as
|
||||
# buzz-relay, buzz-cli, git-credential-nostr).
|
||||
base64 = "0.22"
|
||||
|
||||
# Hex encoding for BIP-340 signatures and public keys.
|
||||
hex = { workspace = true }
|
||||
|
||||
# Secret key zeroization on drop.
|
||||
zeroize = { workspace = true, features = ["derive"] }
|
||||
|
||||
# Nostr key parsing (nsec/npub bech32), secp256k1 Schnorr signing, SHA-256.
|
||||
# Uses the full default feature set because we need: Keys, PublicKey,
|
||||
# FromBech32, and the re-exported bitcoin::secp256k1 + bitcoin::hashes.
|
||||
nostr = { workspace = true }
|
||||
|
||||
# JSON parsing for NIP-OA auth tag and envelope verification.
|
||||
serde_json = { workspace = true }
|
||||
|
||||
# Timestamp formatting for GnuPG VALIDSIG status lines.
|
||||
chrono = { workspace = true }
|
||||
|
||||
# Unix-specific: O_NOFOLLOW for keyfile open, fcntl for fd validation.
|
||||
[target.'cfg(unix)'.dependencies]
|
||||
libc = "0.2"
|
||||
@@ -0,0 +1,46 @@
|
||||
# git-sign-nostr
|
||||
|
||||
NIP-GS signing program — signs git commits and tags with Nostr secp256k1 keys
|
||||
using BIP-340 Schnorr signatures.
|
||||
|
||||
## Usage
|
||||
|
||||
```bash
|
||||
# Configure git to use nostr signing
|
||||
git config gpg.format x509
|
||||
git config gpg.x509.program /path/to/git-sign-nostr
|
||||
git config commit.gpgsign true
|
||||
git config tag.gpgsign true
|
||||
git config user.signingkey <hex-pubkey>
|
||||
|
||||
# Set the private key (env var)
|
||||
export NOSTR_PRIVATE_KEY=<hex-or-nsec>
|
||||
|
||||
# Optional: NIP-OA owner attestation
|
||||
export BUZZ_AUTH_TAG='["auth","<owner-pk>","<conditions>","<owner-sig>"]'
|
||||
|
||||
# Commits are now automatically signed
|
||||
git commit -m "signed with nostr"
|
||||
|
||||
# Verify
|
||||
git verify-commit HEAD
|
||||
```
|
||||
|
||||
## Key Loading Priority
|
||||
|
||||
1. `NOSTR_PRIVATE_KEY` environment variable
|
||||
2. `BUZZ_PRIVATE_KEY` environment variable
|
||||
3. Keyfile at path from `git config nostr.keyfile`
|
||||
|
||||
Keys may be hex (64 chars) or NIP-19 bech32 (`nsec1...`).
|
||||
|
||||
## How It Works
|
||||
|
||||
Git invokes this program as a signing/verification backend:
|
||||
|
||||
- **Sign:** `git-sign-nostr --status-fd=2 -bsau <keyid>` — reads payload from
|
||||
stdin, writes armored signature to stdout, status lines to fd 2 (stderr)
|
||||
- **Verify:** `git-sign-nostr --status-fd=1 --verify <sigfile> -` — reads
|
||||
payload from stdin, verifies signature from file, status lines to fd 1 (stdout)
|
||||
|
||||
See [NIP-GS](../../docs/nips/NIP-GS.md) for the full specification.
|
||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,3 @@
|
||||
fn main() {
|
||||
std::process::exit(git_sign_nostr::run());
|
||||
}
|
||||
Reference in New Issue
Block a user