pub fn split_signed_commit(raw: &[u8]) -> Result<Option<(Vec<u8>, String)>>Expand description
Split a raw commit object into (payload-as-signed, armored signature).
Git signs the commit object with the gpgsig header removed; the header’s
value spans continuation lines (each prefixed with one space). Returns
Ok(None) for an unsigned commit.
Every other header whose name starts with gpgsig (gpgsig-sha256, or a
made-up gpgsig-foo) is removed too, continuation lines and all, because
git removes it: that is the “other signature” arm of
parse_buffer_signed_by_header in git’s commit.c. Keeping such a header
made this payload a superset of git’s, so anyone could add one to a
validly signed commit — fsck-clean, still GOOD to git — and have it
reported here as a bad signature by its real signer.