Scope GPG commit-signature lookups by project_id

What does this MR do and why?

Updates the GpgSignature application code to use the composite (project_id, commit_sha) uniqueness introduced by the migration in !233288 (merged). This is MR 2 of 2 for parent #562042 (closed).

The change mirrors the SSH signatures precedent exactly (CommitSignatures::SshSignature and Gitlab::Ssh::Commit), which made the same move earlier.

References

Screenshots or screen recordings

Not applicable — no UI change.

How to set up and validate locally

  1. In a rails console, pick two projects that can hold the same commit SHA (e.g. a project and a fork), or two projects sharing a seeded SHA.
  2. Create a GPG signature for the same commit_sha in each project via CommitSignatures::GpgSignature.safe_create!(...):
    sha = '0beec7b5ea3f0fdbc95d0dd47f3c5bc275da8a33'
    s1 = CommitSignatures::GpgSignature.safe_create!(commit_sha: sha, project: project1, gpg_key_primary_keyid: key.keyid)
    s2 = CommitSignatures::GpgSignature.safe_create!(commit_sha: sha, project: project2, gpg_key_primary_keyid: key.keyid)
    s1.id != s2.id # => true (two distinct rows, one per project)
  3. Confirm Gitlab::Gpg::Commit#signature resolves each project's commit to its own signature and issues a single batched query (no N+1) when several commits are loaded together.

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Edited by Hunter Stewart

Merge request reports

Loading
Loading