{"thread":{"id":"25347","subject":"Error when verifying tags signed using 1.7.3.1","startedAt":"2010-10-04T22:13:21Z","lastAt":"2010-11-10T17:41:27Z","messageCount":39,"participants":["Stephan Hugel","Daniel Johnson","Michael J Gruber","Pat Thoyts","Junio C Hamano","Todd Zullinger","Thiago Farina"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"152607","messageId":"AANLkTikguMr4E+1m9QEX1x1beQPaHNBqSNPQUQWcFZgF@mail.gmail.com","threadId":"25347","inReplyTo":null,"subject":"Error when verifying tags signed using 1.7.3.1","fromName":"Stephan Hugel","fromEmail":"urschrei@gmail.com","sentAt":"2010-10-04T22:13:21Z","receivedAt":"2010-10-04T22:13:21Z","isPatch":false,"sender":{"key":"urschrei@gmail.com","avatar":"https://gravatar.com/avatar/f30f25d07ee464316494c88cbd8a88e63245dd91c35944f10167175cff910f31?d=mp&s=160"},"body":"Hello, git list.\nI seem to be unable to verify tags I create and sign using the git -s\ncommand in 1.7.3.1\nExisting tags (i.e. created with 1.7.2.x, using the same key and GnuPG\nversion) can be verified, but attempts to verify created tags result\nin the following:\n\nobject 791abd4848d86ea98071f35bbce4d4b274ef0788\ntype commit\ntag v1.4\ntagger name <name@host.com> 1286228562 +0100\n\nBetter header detection and regex\n-----BEGIN PGP MESSAGE-----\nVersion: GnuPG v1.4.9 (Darwin)\n\niD8DBQBMqkph8Y2TgZsQ1pARAgxrAJ40ATxZw219CWI6FCaDAtbY8UHdoACePF6Q\nPyNkf67w7AA8hkQqLAYGcyI=\n=VLWl\n-----END PGP MESSAGE-----\ngpg: Signature made Mon  4 Oct 22:42:57 2010 IST using DSA key ID 9B10D690\ngpg: BAD signature from \"name <name@host.com>\"\nerror: could not verify the tag 'v1.4'\n\n\nI have confirmed that my key is valid (have\nsigned/encrypted/decrypted/verified using it after this error\noccurred). I have also tried to create a tag using a newly-created\nkey, with the same result. I have attempted to created signed tags in\nmultiple repos. Is this a known bug?\n"},{"id":"152616","messageId":"201010041851.46838.ComputerDruid@gmail.com","threadId":"25347","inReplyTo":"AANLkTikguMr4E+1m9QEX1x1beQPaHNBqSNPQUQWcFZgF@mail.gmail.com","subject":"Re: Error when verifying tags signed using 1.7.3.1","fromName":"Daniel Johnson","fromEmail":"computerdruid@gmail.com","sentAt":"2010-10-04T22:51:24Z","receivedAt":"2010-10-04T22:51:24Z","isPatch":false,"sender":{"key":"computerdruid@gmail.com","avatar":"https://avatars.githubusercontent.com/u/34696?v=4"},"body":"On Monday 04 October 2010 18:13:21 Stephan Hugel wrote:\n> Hello, git list.\n> I seem to be unable to verify tags I create and sign using the git -s\n> command in 1.7.3.1\n> Existing tags (i.e. created with 1.7.2.x, using the same key and GnuPG\n> version) can be verified, but attempts to verify created tags result\n> in the following:\n> \n> object 791abd4848d86ea98071f35bbce4d4b274ef0788\n> type commit\n> tag v1.4\n> tagger name <name@host.com> 1286228562 +0100\n> \n> Better header detection and regex\n> -----BEGIN PGP MESSAGE-----\n> Version: GnuPG v1.4.9 (Darwin)\n> \n> iD8DBQBMqkph8Y2TgZsQ1pARAgxrAJ40ATxZw219CWI6FCaDAtbY8UHdoACePF6Q\n> PyNkf67w7AA8hkQqLAYGcyI=\n> =VLWl\n> -----END PGP MESSAGE-----\n> gpg: Signature made Mon  4 Oct 22:42:57 2010 IST using DSA key ID 9B10D690\n> gpg: BAD signature from \"name <name@host.com>\"\n> error: could not verify the tag 'v1.4'\n> \n> \n> I have confirmed that my key is valid (have\n> signed/encrypted/decrypted/verified using it after this error\n> occurred). I have also tried to create a tag using a newly-created\n> key, with the same result. I have attempted to created signed tags in\n> multiple repos. Is this a known bug?\n\nI can't reproduce this:\n\n$ git --version\ngit version 1.7.3.1\n$ git tag -s test_tag -m \"test_message\"\n$ git tag -v test_tag\nobject dbc2fa2a8507f258a353238cde2d9ba5894a8296\ntype commit\ntag test_tag\ntagger Daniel Johnson <ComputerDruid@gmail.com> 1286231912 -0400\n\ntest_message\ngpg: Signature made Mon 04 Oct 2010 06:38:38 PM EDT using DSA key ID 4A094EDC\ngpg: Good signature from \"Daniel Johnson <ComputerDruid@gmail.com>\"\n\nIs this not what you are doing? do you have any more info about what you are \ndoing to cause this failure?\n"},{"id":"152620","messageId":"AANLkTin1Ysn7Fp32Eoyjo3jjhHwVrc=hMuq+okgKNfmr@mail.gmail.com","threadId":"25347","inReplyTo":"201010041851.46838.ComputerDruid@gmail.com","subject":"Re: Error when verifying tags signed using 1.7.3.1","fromName":"Stephan Hugel","fromEmail":"urschrei@gmail.com","sentAt":"2010-10-04T23:04:51Z","receivedAt":"2010-10-04T23:04:51Z","isPatch":false,"sender":{"key":"urschrei@gmail.com","avatar":"https://gravatar.com/avatar/f30f25d07ee464316494c88cbd8a88e63245dd91c35944f10167175cff910f31?d=mp&s=160"},"body":"On 4 October 2010 23:51, Daniel Johnson <computerdruid@gmail.com> wrote:\n> On Monday 04 October 2010 18:13:21 Stephan Hugel wrote:\n>> Hello, git list.\n>> I seem to be unable to verify tags I create and sign using the git -s\n>> command in 1.7.3.1\n>> Existing tags (i.e. created with 1.7.2.x, using the same key and GnuPG\n>> version) can be verified, but attempts to verify created tags result\n>> in the following:\n>>\n>> object 791abd4848d86ea98071f35bbce4d4b274ef0788\n>> type commit\n>> tag v1.4\n>> tagger name <name@host.com> 1286228562 +0100\n>>\n>> Better header detection and regex\n>> -----BEGIN PGP MESSAGE-----\n>> Version: GnuPG v1.4.9 (Darwin)\n>>\n>> iD8DBQBMqkph8Y2TgZsQ1pARAgxrAJ40ATxZw219CWI6FCaDAtbY8UHdoACePF6Q\n>> PyNkf67w7AA8hkQqLAYGcyI=\n>> =VLWl\n>> -----END PGP MESSAGE-----\n>> gpg: Signature made Mon  4 Oct 22:42:57 2010 IST using DSA key ID 9B10D690\n>> gpg: BAD signature from \"name <name@host.com>\"\n>> error: could not verify the tag 'v1.4'\n>>\n>>\n>> I have confirmed that my key is valid (have\n>> signed/encrypted/decrypted/verified using it after this error\n>> occurred). I have also tried to create a tag using a newly-created\n>> key, with the same result. I have attempted to created signed tags in\n>> multiple repos. Is this a known bug?\n>\n> I can't reproduce this:\n>\n> $ git --version\n> git version 1.7.3.1\n> $ git tag -s test_tag -m \"test_message\"\n> $ git tag -v test_tag\n> object dbc2fa2a8507f258a353238cde2d9ba5894a8296\n> type commit\n> tag test_tag\n> tagger Daniel Johnson <ComputerDruid@gmail.com> 1286231912 -0400\n>\n> test_message\n> gpg: Signature made Mon 04 Oct 2010 06:38:38 PM EDT using DSA key ID 4A094EDC\n> gpg: Good signature from \"Daniel Johnson <ComputerDruid@gmail.com>\"\n>\n> Is this not what you are doing? do you have any more info about what you are\n> doing to cause this failure?\n>\n\nDaniel,\nThose are the exact steps I'm using.\n\nWhen I run tag -v on existing tags, I don't see the\n\n-----BEGIN PGP MESSAGE-----\nVersion: GnuPG v1.4.9 (Darwin)\n\niD8DBQBMqlpo8Y2TgZsQ1pARAmBQAJ9NV0IX7jlzeB8ogddlutFKAjyWJwCfSI5A\nyZeXw/EddYrfdad/VvOrL1o=\n=/0PJ\n-----END PGP MESSAGE——\n\nblock. It's only present on tags created using the current version.\nI've also just upgraded to GnuPG 1.4.10, but the result is the same.\nI'm not sure how else I can determine where the problem arises; I'm\nusing the git and GnuPG versions for OS X built by homebrew, and GnuPG\nis happy to use the same key for en/decryption and signing. I've also\nverified that none of the subkeys are expired, and that the trust db\nis OK.\n\n-- \n\nsteph\n"},{"id":"152623","messageId":"201010041959.48336.ComputerDruid@gmail.com","threadId":"25347","inReplyTo":"AANLkTin1Ysn7Fp32Eoyjo3jjhHwVrc=hMuq+okgKNfmr@mail.gmail.com","subject":"Re: Error when verifying tags signed using 1.7.3.1","fromName":"Daniel Johnson","fromEmail":"computerdruid@gmail.com","sentAt":"2010-10-04T23:59:27Z","receivedAt":"2010-10-04T23:59:27Z","isPatch":false,"sender":{"key":"computerdruid@gmail.com","avatar":"https://avatars.githubusercontent.com/u/34696?v=4"},"body":"On Monday 04 October 2010 19:04:51 Stephan Hugel wrote: \n> Daniel,\n> Those are the exact steps I'm using.\n> \n> When I run tag -v on existing tags, I don't see the\n> \n> -----BEGIN PGP MESSAGE-----\n> Version: GnuPG v1.4.9 (Darwin)\n> \n> iD8DBQBMqlpo8Y2TgZsQ1pARAmBQAJ9NV0IX7jlzeB8ogddlutFKAjyWJwCfSI5A\n> yZeXw/EddYrfdad/VvOrL1o=\n> =/0PJ\n> -----END PGP MESSAGE——\n> \n> block. It's only present on tags created using the current version.\n> I've also just upgraded to GnuPG 1.4.10, but the result is the same.\n> I'm not sure how else I can determine where the problem arises; I'm\n> using the git and GnuPG versions for OS X built by homebrew, and GnuPG\n> is happy to use the same key for en/decryption and signing. I've also\n> verified that none of the subkeys are expired, and that the trust db\n> is OK.\n\nIf you have the tests available, can you try running t7004 to see if it fails \nthere too?\n"},{"id":"152624","messageId":"AANLkTinA9K6BQ_gmNE8H02nGTSduhZWjujj6NiGDRALy@mail.gmail.com","threadId":"25347","inReplyTo":"201010041959.48336.ComputerDruid@gmail.com","subject":"Re: Error when verifying tags signed using 1.7.3.1","fromName":"Stephan Hugel","fromEmail":"urschrei@gmail.com","sentAt":"2010-10-05T00:17:39Z","receivedAt":"2010-10-05T00:17:39Z","isPatch":false,"sender":{"key":"urschrei@gmail.com","avatar":"https://gravatar.com/avatar/f30f25d07ee464316494c88cbd8a88e63245dd91c35944f10167175cff910f31?d=mp&s=160"},"body":"On 5 October 2010 00:59, Daniel Johnson <computerdruid@gmail.com> wrote:\n> On Monday 04 October 2010 19:04:51 Stephan Hugel wrote:\n>> Daniel,\n>> Those are the exact steps I'm using.\n>>\n>> When I run tag -v on existing tags, I don't see the\n>>\n>> -----BEGIN PGP MESSAGE-----\n>> Version: GnuPG v1.4.9 (Darwin)\n>>\n>> iD8DBQBMqlpo8Y2TgZsQ1pARAmBQAJ9NV0IX7jlzeB8ogddlutFKAjyWJwCfSI5A\n>> yZeXw/EddYrfdad/VvOrL1o=\n>> =/0PJ\n>> -----END PGP MESSAGE——\n>>\n>> block. It's only present on tags created using the current version.\n>> I've also just upgraded to GnuPG 1.4.10, but the result is the same.\n>> I'm not sure how else I can determine where the problem arises; I'm\n>> using the git and GnuPG versions for OS X built by homebrew, and GnuPG\n>> is happy to use the same key for en/decryption and signing. I've also\n>> verified that none of the subkeys are expired, and that the trust db\n>> is OK.\n>\n> If you have the tests available, can you try running t7004 to see if it fails\n> there too?\n>\nI rebuilt and installed from source\nPassed all 105 tests in t7004-tag.sh\nProblem remains with tags I create\n\nThis would seem to imply a problem with my key, even though nothing\nelse is complaining about it.\n-- \n\nsteph\n"},{"id":"152652","messageId":"4CAADB19.30707@drmicha.warpmail.net","threadId":"25347","inReplyTo":"AANLkTinA9K6BQ_gmNE8H02nGTSduhZWjujj6NiGDRALy@mail.gmail.com","subject":"Re: Error when verifying tags signed using 1.7.3.1","fromName":"Michael J Gruber","fromEmail":"git@drmicha.warpmail.net","sentAt":"2010-10-05T08:00:25Z","receivedAt":"2010-10-05T08:00:25Z","isPatch":false,"sender":{"key":"git@grubix.eu","avatar":"https://avatars.githubusercontent.com/u/233215?v=4"},"body":"Stephan Hugel venit, vidit, dixit 05.10.2010 02:17:\n> On 5 October 2010 00:59, Daniel Johnson <computerdruid@gmail.com> wrote:\n>> On Monday 04 October 2010 19:04:51 Stephan Hugel wrote:\n>>> Daniel,\n>>> Those are the exact steps I'm using.\n>>>\n>>> When I run tag -v on existing tags, I don't see the\n>>>\n>>> -----BEGIN PGP MESSAGE-----\n>>> Version: GnuPG v1.4.9 (Darwin)\n>>>\n>>> iD8DBQBMqlpo8Y2TgZsQ1pARAmBQAJ9NV0IX7jlzeB8ogddlutFKAjyWJwCfSI5A\n>>> yZeXw/EddYrfdad/VvOrL1o=\n>>> =/0PJ\n>>> -----END PGP MESSAGE——\n>>>\n>>> block. It's only present on tags created using the current version.\n>>> I've also just upgraded to GnuPG 1.4.10, but the result is the same.\n>>> I'm not sure how else I can determine where the problem arises; I'm\n>>> using the git and GnuPG versions for OS X built by homebrew, and GnuPG\n>>> is happy to use the same key for en/decryption and signing. I've also\n>>> verified that none of the subkeys are expired, and that the trust db\n>>> is OK.\n>>\n>> If you have the tests available, can you try running t7004 to see if it fails\n>> there too?\n>>\n> I rebuilt and installed from source\n> Passed all 105 tests in t7004-tag.sh\n> Problem remains with tags I create\n> \n> This would seem to imply a problem with my key, even though nothing\n> else is complaining about it.\n\nHere's a very basic way to check: If foo is your tag, do\n\ngit cat-file tag foo > a\ngit cat-file tag foo > a.sig\n\nFrom the file \"a\", delete the signature (everything lines between and\nincluding \"-----BEGIN/END PGP SIGNATURE-----\"), invoking an editor or\nyour favorite sed/awk/perl magic.\n\na is the data on which git invoked gpg for signing the tag. (I'm not\nsure why gpg can't notice the inline sig directly but that doesn't\nmatter; maybe because it is none ;))\n\nNow, gpg --verify a.sig should check the signature a.sig for a. Doing\nthat, maybe with --verbose, you may find out whether the tag object is\nbogus or git misunderstands gpg's response. If your key is on a key\nserver you can also share the file a.sig with us so that we can check.\n\nMichael\n"},{"id":"152658","messageId":"87aamtq8mw.fsf@fox.patthoyts.tk","threadId":"25347","inReplyTo":"201010041959.48336.ComputerDruid@gmail.com","subject":"Re: Error when verifying tags signed using 1.7.3.1","fromName":"Pat Thoyts","fromEmail":"patthoyts@users.sourceforge.net","sentAt":"2010-10-05T09:41:27Z","receivedAt":"2010-10-05T09:41:27Z","isPatch":false,"sender":{"key":"patthoyts@users.sourceforge.net","avatar":"https://avatars.githubusercontent.com/u/30739?v=4"},"body":">On Monday 04 October 2010 19:04:51 Stephan Hugel wrote: \n>> Daniel,\n>> Those are the exact steps I'm using.\n>> \n>> When I run tag -v on existing tags, I don't see the\n>> \n>> -----BEGIN PGP MESSAGE-----\n>> Version: GnuPG v1.4.9 (Darwin)\n>> \n>> iD8DBQBMqlpo8Y2TgZsQ1pARAmBQAJ9NV0IX7jlzeB8ogddlutFKAjyWJwCfSI5A\n>> yZeXw/EddYrfdad/VvOrL1o=\n>> =/0PJ\n>> -----END PGP MESSAGE——\n>> \n>> block. It's only present on tags created using the current version.\n>> I've also just upgraded to GnuPG 1.4.10, but the result is the same.\n>> I'm not sure how else I can determine where the problem arises; I'm\n>> using the git and GnuPG versions for OS X built by homebrew, and GnuPG\n>> is happy to use the same key for en/decryption and signing. I've also\n>> verified that none of the subkeys are expired, and that the trust db\n>> is OK.\n\nWhen I try this using 1.7.3.1 the tag signature header says \"PGP\nSIGNATURE\" and not \"PGP MESSAGE\". I wonder if you just have some odd\ngpg settings.\n\nC:\\src\\git-gui>git version\ngit version 1.7.2.3.msysgit.0\n\nC:\\src\\git-gui>git tag -s -a -m \"test\" test1\n\nYou need a passphrase to unlock the secret key for\nuser: \"Pat Thoyts <patthoyts@googlemail.com>\"\n1024-bit RSA key, ID F084E489, created 1995-04-11\n\n\nC:\\src\\git-gui>git cat-file tag test1\nobject 00e9de72c8f9b7c048bb56a59be9567d69dc1e01\ntype commit\ntag test1\ntagger Pat Thoyts <patthoyts@users.sourceforge.net> 1286268190 +0100\n\ntest\n-----BEGIN PGP SIGNATURE-----\nVersion: GnuPG v1.4.7 (MingW32)\n\niQCVAwUATKrlHmB90JXwhOSJAQJx2QP+OVRpcPyGgi2HF3OyOQ7immsMHpXb4ySx\nnhvt7iWEfMlzm/8/+LlW6NnYkcTkAW3g3pgECXTAzXgUqhj9ectrprLg5XFT717O\nSHJ4qyai08stlC86kHVLyYhdi2C96rgtN9+63CQUl4R7Ofv/l+IRE22IYES5942Z\nLZgpbtPyp7w=\n=Oydf\n-----END PGP SIGNATURE-----\n\nC:\\src\\git-gui>git verify-tag test1\ngpg: Signature made 10/05/10 09:43:10 using RSA key ID F084E489\ngpg: Good signature from \"Pat Thoyts <patthoyts@googlemail.com>\"\ngpg:                 aka \"Pat Thoyts <patthoyts@users.sourceforge.net>\"\n\n-- \nPat Thoyts                            http://www.patthoyts.tk/\nPGP fingerprint 2C 6E 98 07 2C 59 C8 97  10 CE 11 E6 04 E0 B9 DD\n"},{"id":"152673","messageId":"AANLkTikVYSwGjJUgA8KUdNrkHL3+1mSjv8efLwO5+C9E@mail.gmail.com","threadId":"25347","inReplyTo":"4CAADB19.30707@drmicha.warpmail.net","subject":"Re: Error when verifying tags signed using 1.7.3.1","fromName":"Stephan Hugel","fromEmail":"urschrei@gmail.com","sentAt":"2010-10-05T13:28:51Z","receivedAt":"2010-10-05T13:28:51Z","isPatch":false,"sender":{"key":"urschrei@gmail.com","avatar":"https://gravatar.com/avatar/f30f25d07ee464316494c88cbd8a88e63245dd91c35944f10167175cff910f31?d=mp&s=160"},"body":"On 5 October 2010 09:00, Michael J Gruber <git@drmicha.warpmail.net> wrote:\n> Stephan Hugel venit, vidit, dixit 05.10.2010 02:17:\n>> On 5 October 2010 00:59, Daniel Johnson <computerdruid@gmail.com> wrote:\n>>> On Monday 04 October 2010 19:04:51 Stephan Hugel wrote:\n>>>> Daniel,\n>>>> Those are the exact steps I'm using.\n>>>>\n>>>> When I run tag -v on existing tags, I don't see the\n>>>>\n>>>> -----BEGIN PGP MESSAGE-----\n>>>> Version: GnuPG v1.4.9 (Darwin)\n>>>>\n>>>> iD8DBQBMqlpo8Y2TgZsQ1pARAmBQAJ9NV0IX7jlzeB8ogddlutFKAjyWJwCfSI5A\n>>>> yZeXw/EddYrfdad/VvOrL1o=\n>>>> =/0PJ\n>>>> -----END PGP MESSAGE——\n>>>>\n>>>> block. It's only present on tags created using the current version.\n>>>> I've also just upgraded to GnuPG 1.4.10, but the result is the same.\n>>>> I'm not sure how else I can determine where the problem arises; I'm\n>>>> using the git and GnuPG versions for OS X built by homebrew, and GnuPG\n>>>> is happy to use the same key for en/decryption and signing. I've also\n>>>> verified that none of the subkeys are expired, and that the trust db\n>>>> is OK.\n>>>\n>>> If you have the tests available, can you try running t7004 to see if it fails\n>>> there too?\n>>>\n>> I rebuilt and installed from source\n>> Passed all 105 tests in t7004-tag.sh\n>> Problem remains with tags I create\n>>\n>> This would seem to imply a problem with my key, even though nothing\n>> else is complaining about it.\n>\n> Here's a very basic way to check: If foo is your tag, do\n>\n> git cat-file tag foo > a\n> git cat-file tag foo > a.sig\n>\n> From the file \"a\", delete the signature (everything lines between and\n> including \"-----BEGIN/END PGP SIGNATURE-----\"), invoking an editor or\n> your favorite sed/awk/perl magic.\n>\n> a is the data on which git invoked gpg for signing the tag. (I'm not\n> sure why gpg can't notice the inline sig directly but that doesn't\n> matter; maybe because it is none ;))\n>\n> Now, gpg --verify a.sig should check the signature a.sig for a. Doing\n> that, maybe with --verbose, you may find out whether the tag object is\n> bogus or git misunderstands gpg's response. If your key is on a key\n> server you can also share the file a.sig with us so that we can check.\n>\n> Michael\n>\nMichael,\nWhen I do this, gpg is able to verify the signature. So does this mean\nthat gnupg is failing to ignore the PGP block (possibly because it\nexpects \"SIGNATURE\", not \"MESSAGE\"?)\n\n\n-- \n\nsteph\n"},{"id":"152677","messageId":"4CAB3F1F.4030108@drmicha.warpmail.net","threadId":"25347","inReplyTo":"AANLkTikVYSwGjJUgA8KUdNrkHL3+1mSjv8efLwO5+C9E@mail.gmail.com","subject":"Re: Error when verifying tags signed using 1.7.3.1","fromName":"Michael J Gruber","fromEmail":"git@drmicha.warpmail.net","sentAt":"2010-10-05T15:07:11Z","receivedAt":"2010-10-05T15:07:11Z","isPatch":false,"sender":{"key":"git@grubix.eu","avatar":"https://avatars.githubusercontent.com/u/233215?v=4"},"body":"Stephan Hugel venit, vidit, dixit 05.10.2010 15:28:\n> On 5 October 2010 09:00, Michael J Gruber <git@drmicha.warpmail.net> wrote:\n>> Stephan Hugel venit, vidit, dixit 05.10.2010 02:17:\n>>> On 5 October 2010 00:59, Daniel Johnson <computerdruid@gmail.com> wrote:\n>>>> On Monday 04 October 2010 19:04:51 Stephan Hugel wrote:\n>>>>> Daniel,\n>>>>> Those are the exact steps I'm using.\n>>>>>\n>>>>> When I run tag -v on existing tags, I don't see the\n>>>>>\n>>>>> -----BEGIN PGP MESSAGE-----\n>>>>> Version: GnuPG v1.4.9 (Darwin)\n>>>>>\n>>>>> iD8DBQBMqlpo8Y2TgZsQ1pARAmBQAJ9NV0IX7jlzeB8ogddlutFKAjyWJwCfSI5A\n>>>>> yZeXw/EddYrfdad/VvOrL1o=\n>>>>> =/0PJ\n>>>>> -----END PGP MESSAGE——\n>>>>>\n>>>>> block. It's only present on tags created using the current version.\n>>>>> I've also just upgraded to GnuPG 1.4.10, but the result is the same.\n>>>>> I'm not sure how else I can determine where the problem arises; I'm\n>>>>> using the git and GnuPG versions for OS X built by homebrew, and GnuPG\n>>>>> is happy to use the same key for en/decryption and signing. I've also\n>>>>> verified that none of the subkeys are expired, and that the trust db\n>>>>> is OK.\n>>>>\n>>>> If you have the tests available, can you try running t7004 to see if it fails\n>>>> there too?\n>>>>\n>>> I rebuilt and installed from source\n>>> Passed all 105 tests in t7004-tag.sh\n>>> Problem remains with tags I create\n>>>\n>>> This would seem to imply a problem with my key, even though nothing\n>>> else is complaining about it.\n>>\n>> Here's a very basic way to check: If foo is your tag, do\n>>\n>> git cat-file tag foo > a\n>> git cat-file tag foo > a.sig\n>>\n>> From the file \"a\", delete the signature (everything lines between and\n>> including \"-----BEGIN/END PGP SIGNATURE-----\"), invoking an editor or\n>> your favorite sed/awk/perl magic.\n>>\n>> a is the data on which git invoked gpg for signing the tag. (I'm not\n>> sure why gpg can't notice the inline sig directly but that doesn't\n>> matter; maybe because it is none ;))\n>>\n>> Now, gpg --verify a.sig should check the signature a.sig for a. Doing\n>> that, maybe with --verbose, you may find out whether the tag object is\n>> bogus or git misunderstands gpg's response. If your key is on a key\n>> server you can also share the file a.sig with us so that we can check.\n>>\n>> Michael\n>>\n> Michael,\n> When I do this, gpg is able to verify the signature. So does this mean\n> that gnupg is failing to ignore the PGP block (possibly because it\n> expects \"SIGNATURE\", not \"MESSAGE\"?)\n\nDo you have \"MESSAGE\" in there???\n\nCan you share the output of \"git verify-tag --verbose yourtag\" with us?\nIn any case, this command should give the same as the edited \"a\" above\non stdout, and gpg's repsonse on stderr. It should not contain any\n\"----BEGIN/END...\".\n\nYou haven't tinkered with your gpg options lately, have you? ;)\n\nMichael\n"},{"id":"152678","messageId":"AANLkTinqZddKc5ikVBnm+rqFFWtSy7DuByuPK58B4UEt@mail.gmail.com","threadId":"25347","inReplyTo":"4CAB3F1F.4030108@drmicha.warpmail.net","subject":"Re: Error when verifying tags signed using 1.7.3.1","fromName":"Stephan Hugel","fromEmail":"urschrei@gmail.com","sentAt":"2010-10-05T15:19:55Z","receivedAt":"2010-10-05T15:19:55Z","isPatch":false,"sender":{"key":"urschrei@gmail.com","avatar":"https://gravatar.com/avatar/f30f25d07ee464316494c88cbd8a88e63245dd91c35944f10167175cff910f31?d=mp&s=160"},"body":"On 5 October 2010 16:07, Michael J Gruber <git@drmicha.warpmail.net> wrote:\n> Stephan Hugel venit, vidit, dixit 05.10.2010 15:28:\n>> On 5 October 2010 09:00, Michael J Gruber <git@drmicha.warpmail.net> wrote:\n>>> Stephan Hugel venit, vidit, dixit 05.10.2010 02:17:\n>>>> On 5 October 2010 00:59, Daniel Johnson <computerdruid@gmail.com> wrote:\n>>>>> On Monday 04 October 2010 19:04:51 Stephan Hugel wrote:\n>>>>>> Daniel,\n>>>>>> Those are the exact steps I'm using.\n>>>>>>\n>>>>>> When I run tag -v on existing tags, I don't see the\n>>>>>>\n>>>>>> -----BEGIN PGP MESSAGE-----\n>>>>>> Version: GnuPG v1.4.9 (Darwin)\n>>>>>>\n>>>>>> iD8DBQBMqlpo8Y2TgZsQ1pARAmBQAJ9NV0IX7jlzeB8ogddlutFKAjyWJwCfSI5A\n>>>>>> yZeXw/EddYrfdad/VvOrL1o=\n>>>>>> =/0PJ\n>>>>>> -----END PGP MESSAGE——\n>>>>>>\n>>>>>> block. It's only present on tags created using the current version.\n>>>>>> I've also just upgraded to GnuPG 1.4.10, but the result is the same.\n>>>>>> I'm not sure how else I can determine where the problem arises; I'm\n>>>>>> using the git and GnuPG versions for OS X built by homebrew, and GnuPG\n>>>>>> is happy to use the same key for en/decryption and signing. I've also\n>>>>>> verified that none of the subkeys are expired, and that the trust db\n>>>>>> is OK.\n>>>>>\n>>>>> If you have the tests available, can you try running t7004 to see if it fails\n>>>>> there too?\n>>>>>\n>>>> I rebuilt and installed from source\n>>>> Passed all 105 tests in t7004-tag.sh\n>>>> Problem remains with tags I create\n>>>>\n>>>> This would seem to imply a problem with my key, even though nothing\n>>>> else is complaining about it.\n>>>\n>>> Here's a very basic way to check: If foo is your tag, do\n>>>\n>>> git cat-file tag foo > a\n>>> git cat-file tag foo > a.sig\n>>>\n>>> From the file \"a\", delete the signature (everything lines between and\n>>> including \"-----BEGIN/END PGP SIGNATURE-----\"), invoking an editor or\n>>> your favorite sed/awk/perl magic.\n>>>\n>>> a is the data on which git invoked gpg for signing the tag. (I'm not\n>>> sure why gpg can't notice the inline sig directly but that doesn't\n>>> matter; maybe because it is none ;))\n>>>\n>>> Now, gpg --verify a.sig should check the signature a.sig for a. Doing\n>>> that, maybe with --verbose, you may find out whether the tag object is\n>>> bogus or git misunderstands gpg's response. If your key is on a key\n>>> server you can also share the file a.sig with us so that we can check.\n>>>\n>>> Michael\n>>>\n>> Michael,\n>> When I do this, gpg is able to verify the signature. So does this mean\n>> that gnupg is failing to ignore the PGP block (possibly because it\n>> expects \"SIGNATURE\", not \"MESSAGE\"?)\n>\n> Do you have \"MESSAGE\" in there???\n>\n> Can you share the output of \"git verify-tag --verbose yourtag\" with us?\n> In any case, this command should give the same as the edited \"a\" above\n> on stdout, and gpg's repsonse on stderr. It should not contain any\n> \"----BEGIN/END...\".\n>\n> You haven't tinkered with your gpg options lately, have you? ;)\n>\n> Michael\n>\n\nMichael,\nYes, it's \"MESSAGE\".\nHere's the complete process:\n\n$ git --version\ngit version 1.7.3.1\n\n$ git tag -s test_tag\n\n[editor opens, I enter message, save, close]\n\nYou need a passphrase to unlock the secret key for\nuser: \"Stephan Hugel <urschrei@gmail.com>\"\n1024-bit DSA key, ID 9B10D690, created 2008-09-06\n\n[I enter passphrase]\n\n[process completes]\n\n$ git verify-tag --verbose test_tag\nobject 791abd4848d86ea98071f35bbce4d4b274ef0788\ntype commit\ntag test_tag\ntagger Stephan Hügel <urschrei@gmail.com> 1286291263 +0100\n\nTest tag\n-----BEGIN PGP MESSAGE-----\nVersion: GnuPG v1.4.10 (Darwin)\n\niD8DBQBMqz9G8Y2TgZsQ1pARAh2bAJ0WuNWsNa+eJq3aYMlwvOFX5eRUngCfZAcM\nhnt1Aomaz5SY0yofv9BwGWg=\n=+AKs\n-----END PGP MESSAGE-----\ngpg: Signature made Tue  5 Oct 16:07:50 2010 IST using DSA key ID 9B10D690\ngpg: BAD signature from \"Stephan Hugel <urschrei@gmail.com>\"\n\n\nNow, if I manually append the tag contents to a file:\n\n$ git cat-file tag test_tag > a\n$ git cat-file tag test_tag > a.sig\n$ less a.sig\n\nobject 791abd4848d86ea98071f35bbce4d4b274ef0788\ntype commit\ntag test_tag\ntagger Stephan Hügel <urschrei@gmail.com> 1286291263 +0100\n\nTest tag\n-----BEGIN PGP MESSAGE-----\nVersion: GnuPG v1.4.10 (Darwin)\n\niD8DBQBMqz9G8Y2TgZsQ1pARAh2bAJ0WuNWsNa+eJq3aYMlwvOFX5eRUngCfZAcM\nhnt1Aomaz5SY0yofv9BwGWg=\n=+AKs\n-----END PGP MESSAGE——\n\n[remove PGP block (identical to the above block) from a]\n\n$ gpg --verify a.sig\ngpg: Signature made Tue  5 Oct 16:07:50 2010 IST using DSA key ID 9B10D690\ngpg: Good signature from \"Stephan Hugel <urschrei@gmail.com>\"\n\nI've also just had a look at my gnupg.conf: the only options in it are:\ndefault-key 9B10D690\ncharset utf8\nkeyserver hkp://keyserver.ubuntu.com\nauto-key-locate hkp://keyserver.ubuntu.com\nutf8-strings\nrfc1991\n\nNothing else.\n-- \n\nsteph\n"},{"id":"152682","messageId":"4CAB46C0.9000807@drmicha.warpmail.net","threadId":"25347","inReplyTo":"AANLkTinqZddKc5ikVBnm+rqFFWtSy7DuByuPK58B4UEt@mail.gmail.com","subject":"Re: Error when verifying tags signed using 1.7.3.1","fromName":"Michael J Gruber","fromEmail":"git@drmicha.warpmail.net","sentAt":"2010-10-05T15:39:44Z","receivedAt":"2010-10-05T15:39:44Z","isPatch":false,"sender":{"key":"git@grubix.eu","avatar":"https://avatars.githubusercontent.com/u/233215?v=4"},"body":"Stephan Hugel venit, vidit, dixit 05.10.2010 17:19:\n> On 5 October 2010 16:07, Michael J Gruber <git@drmicha.warpmail.net> wrote:\n>> Stephan Hugel venit, vidit, dixit 05.10.2010 15:28:\n>>> On 5 October 2010 09:00, Michael J Gruber <git@drmicha.warpmail.net> wrote:\n>>>> Stephan Hugel venit, vidit, dixit 05.10.2010 02:17:\n>>>>> On 5 October 2010 00:59, Daniel Johnson <computerdruid@gmail.com> wrote:\n>>>>>> On Monday 04 October 2010 19:04:51 Stephan Hugel wrote:\n>>>>>>> Daniel,\n>>>>>>> Those are the exact steps I'm using.\n>>>>>>>\n>>>>>>> When I run tag -v on existing tags, I don't see the\n>>>>>>>\n>>>>>>> -----BEGIN PGP MESSAGE-----\n>>>>>>> Version: GnuPG v1.4.9 (Darwin)\n>>>>>>>\n>>>>>>> iD8DBQBMqlpo8Y2TgZsQ1pARAmBQAJ9NV0IX7jlzeB8ogddlutFKAjyWJwCfSI5A\n>>>>>>> yZeXw/EddYrfdad/VvOrL1o=\n>>>>>>> =/0PJ\n>>>>>>> -----END PGP MESSAGE——\n>>>>>>>\n>>>>>>> block. It's only present on tags created using the current version.\n>>>>>>> I've also just upgraded to GnuPG 1.4.10, but the result is the same.\n>>>>>>> I'm not sure how else I can determine where the problem arises; I'm\n>>>>>>> using the git and GnuPG versions for OS X built by homebrew, and GnuPG\n>>>>>>> is happy to use the same key for en/decryption and signing. I've also\n>>>>>>> verified that none of the subkeys are expired, and that the trust db\n>>>>>>> is OK.\n>>>>>>\n>>>>>> If you have the tests available, can you try running t7004 to see if it fails\n>>>>>> there too?\n>>>>>>\n>>>>> I rebuilt and installed from source\n>>>>> Passed all 105 tests in t7004-tag.sh\n>>>>> Problem remains with tags I create\n>>>>>\n>>>>> This would seem to imply a problem with my key, even though nothing\n>>>>> else is complaining about it.\n>>>>\n>>>> Here's a very basic way to check: If foo is your tag, do\n>>>>\n>>>> git cat-file tag foo > a\n>>>> git cat-file tag foo > a.sig\n>>>>\n>>>> From the file \"a\", delete the signature (everything lines between and\n>>>> including \"-----BEGIN/END PGP SIGNATURE-----\"), invoking an editor or\n>>>> your favorite sed/awk/perl magic.\n>>>>\n>>>> a is the data on which git invoked gpg for signing the tag. (I'm not\n>>>> sure why gpg can't notice the inline sig directly but that doesn't\n>>>> matter; maybe because it is none ;))\n>>>>\n>>>> Now, gpg --verify a.sig should check the signature a.sig for a. Doing\n>>>> that, maybe with --verbose, you may find out whether the tag object is\n>>>> bogus or git misunderstands gpg's response. If your key is on a key\n>>>> server you can also share the file a.sig with us so that we can check.\n>>>>\n>>>> Michael\n>>>>\n>>> Michael,\n>>> When I do this, gpg is able to verify the signature. So does this mean\n>>> that gnupg is failing to ignore the PGP block (possibly because it\n>>> expects \"SIGNATURE\", not \"MESSAGE\"?)\n>>\n>> Do you have \"MESSAGE\" in there???\n>>\n>> Can you share the output of \"git verify-tag --verbose yourtag\" with us?\n>> In any case, this command should give the same as the edited \"a\" above\n>> on stdout, and gpg's repsonse on stderr. It should not contain any\n>> \"----BEGIN/END...\".\n>>\n>> You haven't tinkered with your gpg options lately, have you? ;)\n>>\n>> Michael\n>>\n> \n> Michael,\n> Yes, it's \"MESSAGE\".\n> Here's the complete process:\n> \n> $ git --version\n> git version 1.7.3.1\n> \n> $ git tag -s test_tag\n> \n> [editor opens, I enter message, save, close]\n> \n> You need a passphrase to unlock the secret key for\n> user: \"Stephan Hugel <urschrei@gmail.com>\"\n> 1024-bit DSA key, ID 9B10D690, created 2008-09-06\n> \n> [I enter passphrase]\n> \n> [process completes]\n> \n> $ git verify-tag --verbose test_tag\n> object 791abd4848d86ea98071f35bbce4d4b274ef0788\n> type commit\n> tag test_tag\n> tagger Stephan Hügel <urschrei@gmail.com> 1286291263 +0100\n> \n> Test tag\n> -----BEGIN PGP MESSAGE-----\n> Version: GnuPG v1.4.10 (Darwin)\n> \n> iD8DBQBMqz9G8Y2TgZsQ1pARAh2bAJ0WuNWsNa+eJq3aYMlwvOFX5eRUngCfZAcM\n> hnt1Aomaz5SY0yofv9BwGWg=\n> =+AKs\n> -----END PGP MESSAGE-----\n> gpg: Signature made Tue  5 Oct 16:07:50 2010 IST using DSA key ID 9B10D690\n> gpg: BAD signature from \"Stephan Hugel <urschrei@gmail.com>\"\n> \n> \n> Now, if I manually append the tag contents to a file:\n> \n> $ git cat-file tag test_tag > a\n> $ git cat-file tag test_tag > a.sig\n> $ less a.sig\n> \n> object 791abd4848d86ea98071f35bbce4d4b274ef0788\n> type commit\n> tag test_tag\n> tagger Stephan Hügel <urschrei@gmail.com> 1286291263 +0100\n> \n> Test tag\n> -----BEGIN PGP MESSAGE-----\n> Version: GnuPG v1.4.10 (Darwin)\n> \n> iD8DBQBMqz9G8Y2TgZsQ1pARAh2bAJ0WuNWsNa+eJq3aYMlwvOFX5eRUngCfZAcM\n> hnt1Aomaz5SY0yofv9BwGWg=\n> =+AKs\n> -----END PGP MESSAGE——\n> \n> [remove PGP block (identical to the above block) from a]\n> \n> $ gpg --verify a.sig\n> gpg: Signature made Tue  5 Oct 16:07:50 2010 IST using DSA key ID 9B10D690\n> gpg: Good signature from \"Stephan Hugel <urschrei@gmail.com>\"\n> \n> I've also just had a look at my gnupg.conf: the only options in it are:\n> default-key 9B10D690\n> charset utf8\n> keyserver hkp://keyserver.ubuntu.com\n> auto-key-locate hkp://keyserver.ubuntu.com\n> utf8-strings\n> rfc1991\n> \n> Nothing else.\n\nThe last one is the trouble maker, and you must have added it around the\ntime of upgrading git...\n\nNow, git should be able to cope with that, of course.\n\nMichael\n"},{"id":"152683","messageId":"5cea498f34522d603a1561bfe69e2f92caa39ced.1286293083.git.git@drmicha.warpmail.net","threadId":"25347","inReplyTo":"4CAB46C0.9000807@drmicha.warpmail.net","subject":"[PATCH] tag,verify-tag: do not trip over rfc1991 signatures","fromName":"Michael J Gruber","fromEmail":"git@drmicha.warpmail.net","sentAt":"2010-10-05T15:40:07Z","receivedAt":"2010-10-05T15:40:07Z","isPatch":true,"sender":{"key":"git@grubix.eu","avatar":"https://avatars.githubusercontent.com/u/233215?v=4"},"body":"Currently, git expects \"-----BEGIN PGP SIGNATURE-----\" at the beginning of a\nsignature. But gpg uses \"MESSAGE\" instead of \"SIGNATURE\" when used with\nthe \"rfc1991\" option. This leads to git's faling to verify it's own\nsigned tags.\n\nBe more lenient and take \"-----BEGIN PGP \" as the indicator.\n\nReported-by: Stephan Hugel <urschrei@gmail.com>\nSigned-off-by: Michael J Gruber <git@drmicha.warpmail.net>\n---\n builtin/tag.c        |    6 +++---\n builtin/verify-tag.c |    2 +-\n 2 files changed, 4 insertions(+), 4 deletions(-)\n\ndiff --git a/builtin/tag.c b/builtin/tag.c\nindex d311491..04bec17 100644\n--- a/builtin/tag.c\n+++ b/builtin/tag.c\n@@ -29,7 +29,7 @@ struct tag_filter {\n \tstruct commit_list *with_commit;\n };\n \n-#define PGP_SIGNATURE \"-----BEGIN PGP SIGNATURE-----\"\n+#define PGP_SIGNATURE \"-----BEGIN PGP \"\n \n static int show_reference(const char *refname, const unsigned char *sha1,\n \t\t\t  int flag, void *cb_data)\n@@ -72,7 +72,7 @@ static int show_reference(const char *refname, const unsigned char *sha1,\n \t\t/* only take up to \"lines\" lines, and strip the signature */\n \t\tfor (i = 0, sp += 2;\n \t\t\t\ti < filter->lines && sp < buf + size &&\n-\t\t\t\tprefixcmp(sp, PGP_SIGNATURE \"\\n\");\n+\t\t\t\tprefixcmp(sp, PGP_SIGNATURE);\n \t\t\t\ti++) {\n \t\t\tif (i)\n \t\t\t\tprintf(\"\\n    \");\n@@ -256,7 +256,7 @@ static void write_tag_body(int fd, const unsigned char *sha1)\n \t\treturn;\n \t}\n \tsp += 2; /* skip the 2 LFs */\n-\teob = strstr(sp, \"\\n\" PGP_SIGNATURE \"\\n\");\n+\teob = strstr(sp, \"\\n\" PGP_SIGNATURE);\n \tif (eob)\n \t\tlen = eob - sp;\n \telse\ndiff --git a/builtin/verify-tag.c b/builtin/verify-tag.c\nindex 9f482c2..3c85d0a 100644\n--- a/builtin/verify-tag.c\n+++ b/builtin/verify-tag.c\n@@ -17,7 +17,7 @@ static const char * const verify_tag_usage[] = {\n \t\tNULL\n };\n \n-#define PGP_SIGNATURE \"-----BEGIN PGP SIGNATURE-----\"\n+#define PGP_SIGNATURE \"-----BEGIN PGP \"\n \n static int run_gpg_verify(const char *buf, unsigned long size, int verbose)\n {\n-- \n1.7.3.98.g5ad7d\n"},{"id":"152686","messageId":"AANLkTimW89OxR-ahPL9htEWotK6sN+8G9E6_6=gvSjW9@mail.gmail.com","threadId":"25347","inReplyTo":"4CAB46C0.9000807@drmicha.warpmail.net","subject":"Re: Error when verifying tags signed using 1.7.3.1","fromName":"Stephan Hugel","fromEmail":"urschrei@gmail.com","sentAt":"2010-10-05T15:45:01Z","receivedAt":"2010-10-05T15:45:01Z","isPatch":false,"sender":{"key":"urschrei@gmail.com","avatar":"https://gravatar.com/avatar/f30f25d07ee464316494c88cbd8a88e63245dd91c35944f10167175cff910f31?d=mp&s=160"},"body":"On 5 October 2010 16:39, Michael J Gruber <git@drmicha.warpmail.net> wrote:\n> Stephan Hugel venit, vidit, dixit 05.10.2010 17:19:\n>> On 5 October 2010 16:07, Michael J Gruber <git@drmicha.warpmail.net> wrote:\n>>> Stephan Hugel venit, vidit, dixit 05.10.2010 15:28:\n>>>> On 5 October 2010 09:00, Michael J Gruber <git@drmicha.warpmail.net> wrote:\n>>>>> Stephan Hugel venit, vidit, dixit 05.10.2010 02:17:\n>>>>>> On 5 October 2010 00:59, Daniel Johnson <computerdruid@gmail.com> wrote:\n>>>>>>> On Monday 04 October 2010 19:04:51 Stephan Hugel wrote:\n>>>>>>>> Daniel,\n>>>>>>>> Those are the exact steps I'm using.\n>>>>>>>>\n>>>>>>>> When I run tag -v on existing tags, I don't see the\n>>>>>>>>\n>>>>>>>> -----BEGIN PGP MESSAGE-----\n>>>>>>>> Version: GnuPG v1.4.9 (Darwin)\n>>>>>>>>\n>>>>>>>> iD8DBQBMqlpo8Y2TgZsQ1pARAmBQAJ9NV0IX7jlzeB8ogddlutFKAjyWJwCfSI5A\n>>>>>>>> yZeXw/EddYrfdad/VvOrL1o=\n>>>>>>>> =/0PJ\n>>>>>>>> -----END PGP MESSAGE——\n>>>>>>>>\n>>>>>>>> block. It's only present on tags created using the current version.\n>>>>>>>> I've also just upgraded to GnuPG 1.4.10, but the result is the same.\n>>>>>>>> I'm not sure how else I can determine where the problem arises; I'm\n>>>>>>>> using the git and GnuPG versions for OS X built by homebrew, and GnuPG\n>>>>>>>> is happy to use the same key for en/decryption and signing. I've also\n>>>>>>>> verified that none of the subkeys are expired, and that the trust db\n>>>>>>>> is OK.\n>>>>>>>\n>>>>>>> If you have the tests available, can you try running t7004 to see if it fails\n>>>>>>> there too?\n>>>>>>>\n>>>>>> I rebuilt and installed from source\n>>>>>> Passed all 105 tests in t7004-tag.sh\n>>>>>> Problem remains with tags I create\n>>>>>>\n>>>>>> This would seem to imply a problem with my key, even though nothing\n>>>>>> else is complaining about it.\n>>>>>\n>>>>> Here's a very basic way to check: If foo is your tag, do\n>>>>>\n>>>>> git cat-file tag foo > a\n>>>>> git cat-file tag foo > a.sig\n>>>>>\n>>>>> From the file \"a\", delete the signature (everything lines between and\n>>>>> including \"-----BEGIN/END PGP SIGNATURE-----\"), invoking an editor or\n>>>>> your favorite sed/awk/perl magic.\n>>>>>\n>>>>> a is the data on which git invoked gpg for signing the tag. (I'm not\n>>>>> sure why gpg can't notice the inline sig directly but that doesn't\n>>>>> matter; maybe because it is none ;))\n>>>>>\n>>>>> Now, gpg --verify a.sig should check the signature a.sig for a. Doing\n>>>>> that, maybe with --verbose, you may find out whether the tag object is\n>>>>> bogus or git misunderstands gpg's response. If your key is on a key\n>>>>> server you can also share the file a.sig with us so that we can check.\n>>>>>\n>>>>> Michael\n>>>>>\n>>>> Michael,\n>>>> When I do this, gpg is able to verify the signature. So does this mean\n>>>> that gnupg is failing to ignore the PGP block (possibly because it\n>>>> expects \"SIGNATURE\", not \"MESSAGE\"?)\n>>>\n>>> Do you have \"MESSAGE\" in there???\n>>>\n>>> Can you share the output of \"git verify-tag --verbose yourtag\" with us?\n>>> In any case, this command should give the same as the edited \"a\" above\n>>> on stdout, and gpg's repsonse on stderr. It should not contain any\n>>> \"----BEGIN/END...\".\n>>>\n>>> You haven't tinkered with your gpg options lately, have you? ;)\n>>>\n>>> Michael\n>>>\n>>\n>> Michael,\n>> Yes, it's \"MESSAGE\".\n>> Here's the complete process:\n>>\n>> $ git --version\n>> git version 1.7.3.1\n>>\n>> $ git tag -s test_tag\n>>\n>> [editor opens, I enter message, save, close]\n>>\n>> You need a passphrase to unlock the secret key for\n>> user: \"Stephan Hugel <urschrei@gmail.com>\"\n>> 1024-bit DSA key, ID 9B10D690, created 2008-09-06\n>>\n>> [I enter passphrase]\n>>\n>> [process completes]\n>>\n>> $ git verify-tag --verbose test_tag\n>> object 791abd4848d86ea98071f35bbce4d4b274ef0788\n>> type commit\n>> tag test_tag\n>> tagger Stephan Hügel <urschrei@gmail.com> 1286291263 +0100\n>>\n>> Test tag\n>> -----BEGIN PGP MESSAGE-----\n>> Version: GnuPG v1.4.10 (Darwin)\n>>\n>> iD8DBQBMqz9G8Y2TgZsQ1pARAh2bAJ0WuNWsNa+eJq3aYMlwvOFX5eRUngCfZAcM\n>> hnt1Aomaz5SY0yofv9BwGWg=\n>> =+AKs\n>> -----END PGP MESSAGE-----\n>> gpg: Signature made Tue  5 Oct 16:07:50 2010 IST using DSA key ID 9B10D690\n>> gpg: BAD signature from \"Stephan Hugel <urschrei@gmail.com>\"\n>>\n>>\n>> Now, if I manually append the tag contents to a file:\n>>\n>> $ git cat-file tag test_tag > a\n>> $ git cat-file tag test_tag > a.sig\n>> $ less a.sig\n>>\n>> object 791abd4848d86ea98071f35bbce4d4b274ef0788\n>> type commit\n>> tag test_tag\n>> tagger Stephan Hügel <urschrei@gmail.com> 1286291263 +0100\n>>\n>> Test tag\n>> -----BEGIN PGP MESSAGE-----\n>> Version: GnuPG v1.4.10 (Darwin)\n>>\n>> iD8DBQBMqz9G8Y2TgZsQ1pARAh2bAJ0WuNWsNa+eJq3aYMlwvOFX5eRUngCfZAcM\n>> hnt1Aomaz5SY0yofv9BwGWg=\n>> =+AKs\n>> -----END PGP MESSAGE——\n>>\n>> [remove PGP block (identical to the above block) from a]\n>>\n>> $ gpg --verify a.sig\n>> gpg: Signature made Tue  5 Oct 16:07:50 2010 IST using DSA key ID 9B10D690\n>> gpg: Good signature from \"Stephan Hugel <urschrei@gmail.com>\"\n>>\n>> I've also just had a look at my gnupg.conf: the only options in it are:\n>> default-key 9B10D690\n>> charset utf8\n>> keyserver hkp://keyserver.ubuntu.com\n>> auto-key-locate hkp://keyserver.ubuntu.com\n>> utf8-strings\n>> rfc1991\n>>\n>> Nothing else.\n>\n> The last one is the trouble maker, and you must have added it around the\n> time of upgrading git...\n>\n> Now, git should be able to cope with that, of course.\n>\n> Michael\n>\nI can confirm that disabling that option in gpg.conf results in a tag\nusing \"SIGNATURE\" being written, which can be subsequently verified.\n\n\n-- \n\nsteph\n"},{"id":"152710","messageId":"7vr5g45qqx.fsf@alter.siamese.dyndns.org","threadId":"25347","inReplyTo":"5cea498f34522d603a1561bfe69e2f92caa39ced.1286293083.git.git@drmicha.warpmail.net","subject":"Re: [PATCH] tag,verify-tag: do not trip over rfc1991 signatures","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2010-10-05T20:28:06Z","receivedAt":"2010-10-05T20:28:06Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Michael J Gruber <git@drmicha.warpmail.net> writes:\n\n> Currently, git expects \"-----BEGIN PGP SIGNATURE-----\" at the beginning of a\n> signature. But gpg uses \"MESSAGE\" instead of \"SIGNATURE\" when used with\n> the \"rfc1991\" option. This leads to git's faling to verify it's own\n> signed tags.\n>\n> Be more lenient and take \"-----BEGIN PGP \" as the indicator.\n\nThanks, but it bothers me that the patch is a bit inconsistently lenient.\n\nHow many variants of PGP implementations are there?  For example, I'd ask\nthese without doing my own research because I am lazy:\n\n 1. Does everybody place five dashes at the beginning (IOW, is there an\n    odd variant that puts four or six)?\n\n 2. Does everybody follow the dashes immediately with \"BEGIN\" (IOW, is\n    there an odd variant that puts a SP between them)?\n\n 3. Does everybody spell \"BEGIN PGP \" the same way, in all uppercase?\n\n 4. Does everybody place five dashes at the end (IOW, is there an odd\n    variant that puts four or six)?\n\n 5. Does everybody follow the \"BEGIN PGP SOMETHING\" immediately with\n    dashes without SP?\n\nYour patch seem to answer <yes, yes, yes, no, no> to the above question.\nI'd find it saner if the patched code at least checked that the line ends\nwith 5 dashes.\n"},{"id":"152714","messageId":"20101005204201.GF7629@inocybe.localdomain","threadId":"25347","inReplyTo":"5cea498f34522d603a1561bfe69e2f92caa39ced.1286293083.git.git@drmicha.warpmail.net","subject":"Re: [PATCH] tag,verify-tag: do not trip over rfc1991 signatures","fromName":"Todd Zullinger","fromEmail":"tmz@pobox.com","sentAt":"2010-10-05T20:42:02Z","receivedAt":"2010-10-05T20:42:02Z","isPatch":true,"sender":{"key":"tmz@pobox.com","avatar":"https://avatars.githubusercontent.com/u/806319?v=4"},"body":"Michael J Gruber wrote:\n> Currently, git expects \"-----BEGIN PGP SIGNATURE-----\" at the beginning of a\n> signature. But gpg uses \"MESSAGE\" instead of \"SIGNATURE\" when used with\n> the \"rfc1991\" option. This leads to git's faling to verify it's own\n> signed tags.\n>\n> Be more lenient and take \"-----BEGIN PGP \" as the indicator.\n\nAnother way to go might be to add --gnupg (or --openpgp) to the gpg\noptions used for tagging.  That overrides an option like rfc1991 in\nthe gnupg config file.\n\nWhether that's preferable to accepting these older-style messages is\ndebatable.  Using rfc1991 implies pgp-2.x compatibility, which means\nusing md5 as the algorithm.  It could be seen as a weakness to accept\nsuch signatures.\n\n(Oh, and you probably saw this already, but s/faling/failing. ;)\n\n-- \nTodd        OpenPGP -> KeyID: 0xBEAF0CE3 | URL: www.pobox.com/~tmz/pgp\n~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\nThe best cure for insomnia is to get a lot of sleep.\n    -- W.C. Fields\n\n"},{"id":"152715","messageId":"4CAB8DBB.3030706@drmicha.warpmail.net","threadId":"25347","inReplyTo":"7vr5g45qqx.fsf@alter.siamese.dyndns.org","subject":"Re: [PATCH] tag,verify-tag: do not trip over rfc1991 signatures","fromName":"Michael J Gruber","fromEmail":"git@drmicha.warpmail.net","sentAt":"2010-10-05T20:42:35Z","receivedAt":"2010-10-05T20:42:35Z","isPatch":true,"sender":{"key":"git@grubix.eu","avatar":"https://avatars.githubusercontent.com/u/233215?v=4"},"body":"Junio C Hamano venit, vidit, dixit 05.10.2010 22:28:\n> Michael J Gruber <git@drmicha.warpmail.net> writes:\n> \n>> Currently, git expects \"-----BEGIN PGP SIGNATURE-----\" at the beginning of a\n>> signature. But gpg uses \"MESSAGE\" instead of \"SIGNATURE\" when used with\n>> the \"rfc1991\" option. This leads to git's faling to verify it's own\n>> signed tags.\n>>\n>> Be more lenient and take \"-----BEGIN PGP \" as the indicator.\n> \n> Thanks, but it bothers me that the patch is a bit inconsistently lenient.\n> \n> How many variants of PGP implementations are there?  For example, I'd ask\n> these without doing my own research because I am lazy:\n> \n>  1. Does everybody place five dashes at the beginning (IOW, is there an\n>     odd variant that puts four or six)?\n> \n>  2. Does everybody follow the dashes immediately with \"BEGIN\" (IOW, is\n>     there an odd variant that puts a SP between them)?\n> \n>  3. Does everybody spell \"BEGIN PGP \" the same way, in all uppercase?\n> \n>  4. Does everybody place five dashes at the end (IOW, is there an odd\n>     variant that puts four or six)?\n> \n>  5. Does everybody follow the \"BEGIN PGP SOMETHING\" immediately with\n>     dashes without SP?\n> \n> Your patch seem to answer <yes, yes, yes, no, no> to the above question.\n\nOn 4,5, my patch only implies that I (suggest we) don't care.\n\n> I'd find it saner if the patched code at least checked that the line ends\n> with 5 dashes.\n\nAlternatively, we can just say we support gnupg/openpg but not pgp 2.0,\nand running gpg with pgp 2.0 options is discouraged even by gpg's man page.\n\nThe main issue here is that we create a detached signature (rather than\na clear text signature) but then lump it together with the content (the\ntag object sans sig). The boundary mark between the two is not\ncontrolled by us but by gpg (and its options).\n\nIn order to verify the sig, *we* have to split the lump again but we\ndon't really know the boundary mark. It's insane by design. We should\nhave used a non-volatile boundary mark.\n\nI'll check whether we can somehow feed the whole lump to gpg and make it\nrecognize the attached-detached signature. That way we'd be as\ncompatible as gpg.\n\nMichael\n"},{"id":"152720","messageId":"4CAB8EE5.5020405@drmicha.warpmail.net","threadId":"25347","inReplyTo":"20101005204201.GF7629@inocybe.localdomain","subject":"Re: [PATCH] tag,verify-tag: do not trip over rfc1991 signatures","fromName":"Michael J Gruber","fromEmail":"git@drmicha.warpmail.net","sentAt":"2010-10-05T20:47:33Z","receivedAt":"2010-10-05T20:47:33Z","isPatch":true,"sender":{"key":"git@grubix.eu","avatar":"https://avatars.githubusercontent.com/u/233215?v=4"},"body":"Todd Zullinger venit, vidit, dixit 05.10.2010 22:42:\n> Michael J Gruber wrote:\n>> Currently, git expects \"-----BEGIN PGP SIGNATURE-----\" at the beginning of a\n>> signature. But gpg uses \"MESSAGE\" instead of \"SIGNATURE\" when used with\n>> the \"rfc1991\" option. This leads to git's faling to verify it's own\n>> signed tags.\n>>\n>> Be more lenient and take \"-----BEGIN PGP \" as the indicator.\n> \n> Another way to go might be to add --gnupg (or --openpgp) to the gpg\n> options used for tagging.  That overrides an option like rfc1991 in\n> the gnupg config file.\n> \n> Whether that's preferable to accepting these older-style messages is\n> debatable.  Using rfc1991 implies pgp-2.x compatibility, which means\n> using md5 as the algorithm.  It could be seen as a weakness to accept\n> such signatures.\n\nThe problem is that we never did this, i.e. we always allowed people to\ncreate such signatures. They never verified, though, even though they\nwere valid. If that's reason enough to discount the usual compatibility\nargument then adding --gnupg would be best.\n\n> (Oh, and you probably saw this already, but s/faling/failing. ;)\n\n:|\n\nMichael\n"},{"id":"152722","messageId":"AANLkTimg+=WW-mcB6RzORjDCV9rpLbc0NJhhg7Wd=0vp@mail.gmail.com","threadId":"25347","inReplyTo":"4CAB8DBB.3030706@drmicha.warpmail.net","subject":"Re: [PATCH] tag,verify-tag: do not trip over rfc1991 signatures","fromName":"Stephan Hugel","fromEmail":"urschrei@gmail.com","sentAt":"2010-10-05T20:51:51Z","receivedAt":"2010-10-05T20:51:51Z","isPatch":true,"sender":{"key":"urschrei@gmail.com","avatar":"https://gravatar.com/avatar/f30f25d07ee464316494c88cbd8a88e63245dd91c35944f10167175cff910f31?d=mp&s=160"},"body":"On 5 October 2010 21:42, Michael J Gruber <git@drmicha.warpmail.net> wrote:\n> Junio C Hamano venit, vidit, dixit 05.10.2010 22:28:\n>> Michael J Gruber <git@drmicha.warpmail.net> writes:\n>>\n>>> Currently, git expects \"-----BEGIN PGP SIGNATURE-----\" at the beginning of a\n>>> signature. But gpg uses \"MESSAGE\" instead of \"SIGNATURE\" when used with\n>>> the \"rfc1991\" option. This leads to git's faling to verify it's own\n>>> signed tags.\n>>>\n>>> Be more lenient and take \"-----BEGIN PGP \" as the indicator.\n>>\n>> Thanks, but it bothers me that the patch is a bit inconsistently lenient.\n>>\n>> How many variants of PGP implementations are there?  For example, I'd ask\n>> these without doing my own research because I am lazy:\n>>\n>>  1. Does everybody place five dashes at the beginning (IOW, is there an\n>>     odd variant that puts four or six)?\n>>\n>>  2. Does everybody follow the dashes immediately with \"BEGIN\" (IOW, is\n>>     there an odd variant that puts a SP between them)?\n>>\n>>  3. Does everybody spell \"BEGIN PGP \" the same way, in all uppercase?\n>>\n>>  4. Does everybody place five dashes at the end (IOW, is there an odd\n>>     variant that puts four or six)?\n>>\n>>  5. Does everybody follow the \"BEGIN PGP SOMETHING\" immediately with\n>>     dashes without SP?\n>>\n>> Your patch seem to answer <yes, yes, yes, no, no> to the above question.\n>\n> On 4,5, my patch only implies that I (suggest we) don't care.\n>\n>> I'd find it saner if the patched code at least checked that the line ends\n>> with 5 dashes.\n>\n> Alternatively, we can just say we support gnupg/openpg but not pgp 2.0,\n> and running gpg with pgp 2.0 options is discouraged even by gpg's man page.\n>\n> The main issue here is that we create a detached signature (rather than\n> a clear text signature) but then lump it together with the content (the\n> tag object sans sig). The boundary mark between the two is not\n> controlled by us but by gpg (and its options).\n>\n> In order to verify the sig, *we* have to split the lump again but we\n> don't really know the boundary mark. It's insane by design. We should\n> have used a non-volatile boundary mark.\n>\n> I'll check whether we can somehow feed the whole lump to gpg and make it\n> recognize the attached-detached signature. That way we'd be as\n> compatible as gpg.\n>\n> Michael\n>\n5 dashes + BEGIN [other stuff] and\n5 dashes + END\nwas part of RFC1991:\nhttp://tools.ietf.org/html/rfc1991#section-2.4.1\n\nWhich was obsoleted by RFC4880 :\nhttp://tools.ietf.org/html/rfc4880#section-6.2\n5 dashes + BEGIN [some different stuff]\n5 dashes + END\n\nAside from the above considerations, 5 dashes + BEGIN\nwould appear to conform to both the old and the current spec. Since\nthe current implementation of GnuPG only offers the rfc1991\ncompatibility options, complying with both covers all (i.e. both)\npossibilties, no?\n-- \n\nsteph\n"},{"id":"152723","messageId":"4CAB90EC.1080302@drmicha.warpmail.net","threadId":"25347","inReplyTo":"AANLkTimg+=WW-mcB6RzORjDCV9rpLbc0NJhhg7Wd=0vp@mail.gmail.com","subject":"Re: [PATCH] tag,verify-tag: do not trip over rfc1991 signatures","fromName":"Michael J Gruber","fromEmail":"git@drmicha.warpmail.net","sentAt":"2010-10-05T20:56:12Z","receivedAt":"2010-10-05T20:56:12Z","isPatch":true,"sender":{"key":"git@grubix.eu","avatar":"https://avatars.githubusercontent.com/u/233215?v=4"},"body":"Stephan Hugel venit, vidit, dixit 05.10.2010 22:51:\n> On 5 October 2010 21:42, Michael J Gruber <git@drmicha.warpmail.net> wrote:\n>> Junio C Hamano venit, vidit, dixit 05.10.2010 22:28:\n>>> Michael J Gruber <git@drmicha.warpmail.net> writes:\n>>>\n>>>> Currently, git expects \"-----BEGIN PGP SIGNATURE-----\" at the beginning of a\n>>>> signature. But gpg uses \"MESSAGE\" instead of \"SIGNATURE\" when used with\n>>>> the \"rfc1991\" option. This leads to git's faling to verify it's own\n>>>> signed tags.\n>>>>\n>>>> Be more lenient and take \"-----BEGIN PGP \" as the indicator.\n>>>\n>>> Thanks, but it bothers me that the patch is a bit inconsistently lenient.\n>>>\n>>> How many variants of PGP implementations are there?  For example, I'd ask\n>>> these without doing my own research because I am lazy:\n>>>\n>>>  1. Does everybody place five dashes at the beginning (IOW, is there an\n>>>     odd variant that puts four or six)?\n>>>\n>>>  2. Does everybody follow the dashes immediately with \"BEGIN\" (IOW, is\n>>>     there an odd variant that puts a SP between them)?\n>>>\n>>>  3. Does everybody spell \"BEGIN PGP \" the same way, in all uppercase?\n>>>\n>>>  4. Does everybody place five dashes at the end (IOW, is there an odd\n>>>     variant that puts four or six)?\n>>>\n>>>  5. Does everybody follow the \"BEGIN PGP SOMETHING\" immediately with\n>>>     dashes without SP?\n>>>\n>>> Your patch seem to answer <yes, yes, yes, no, no> to the above question.\n>>\n>> On 4,5, my patch only implies that I (suggest we) don't care.\n>>\n>>> I'd find it saner if the patched code at least checked that the line ends\n>>> with 5 dashes.\n>>\n>> Alternatively, we can just say we support gnupg/openpg but not pgp 2.0,\n>> and running gpg with pgp 2.0 options is discouraged even by gpg's man page.\n>>\n>> The main issue here is that we create a detached signature (rather than\n>> a clear text signature) but then lump it together with the content (the\n>> tag object sans sig). The boundary mark between the two is not\n>> controlled by us but by gpg (and its options).\n>>\n>> In order to verify the sig, *we* have to split the lump again but we\n>> don't really know the boundary mark. It's insane by design. We should\n>> have used a non-volatile boundary mark.\n>>\n>> I'll check whether we can somehow feed the whole lump to gpg and make it\n>> recognize the attached-detached signature. That way we'd be as\n>> compatible as gpg.\n>>\n>> Michael\n>>\n> 5 dashes + BEGIN [other stuff] and\n> 5 dashes + END\n> was part of RFC1991:\n> http://tools.ietf.org/html/rfc1991#section-2.4.1\n> \n> Which was obsoleted by RFC4880 :\n> http://tools.ietf.org/html/rfc4880#section-6.2\n> 5 dashes + BEGIN [some different stuff]\n> 5 dashes + END\n> \n> Aside from the above considerations, 5 dashes + BEGIN\n> would appear to conform to both the old and the current spec. Since\n> the current implementation of GnuPG only offers the rfc1991\n> compatibility options, complying with both covers all (i.e. both)\n> possibilties, no?\n\nSo, we (c|sh)ould really check for the two variants rather than being\nlenient, right? I'll bite the v2 apple.\n\nMichael\n"},{"id":"155281","messageId":"cover.1289041051.git.git@drmicha.warpmail.net","threadId":"25347","inReplyTo":"4CAB90EC.1080302@drmicha.warpmail.net","subject":"[PATCH 0/5] Handling of rfc1991 signatures","fromName":"Michael J Gruber","fromEmail":"git@drmicha.warpmail.net","sentAt":"2010-11-06T11:04:05Z","receivedAt":"2010-11-06T11:04:05Z","isPatch":true,"sender":{"key":"git@grubix.eu","avatar":"https://avatars.githubusercontent.com/u/233215?v=4"},"body":"This mini-series fixes the handling of signed tags for users\nwith \"rfc1991\" in their gpg config. In fact, the refactoring\ndone in the middle three patches would be worthwhile even\nwithout the side effect of having to fix the handling in\none place only rather than three...\n\nMichael J Gruber (5):\n  t/t7004-tag: test handling of rfc1991 signatures\n  verify-tag: factor out signature detection\n  tag: factor out sig detection for body edits\n  tag: factor out sig detection for tag display\n  tag: recognize rfc1991 signatures\n\n builtin/tag.c        |   16 ++++------------\n builtin/verify-tag.c |   10 ++--------\n t/t7004-tag.sh       |   43 +++++++++++++++++++++++++++++++++++++++++++\n tag.c                |   12 ++++++++++++\n tag.h                |    4 ++++\n 5 files changed, 65 insertions(+), 20 deletions(-)\n\n-- \n1.7.3.2.193.g78bbb\n"},{"id":"155283","messageId":"c20fb62cefcd42533e47f6f1bf5817712e5ebf9a.1289041051.git.git@drmicha.warpmail.net","threadId":"25347","inReplyTo":"4CAB90EC.1080302@drmicha.warpmail.net","subject":"[PATCH 1/5] t/t7004-tag: test handling of rfc1991 signatures","fromName":"Michael J Gruber","fromEmail":"git@drmicha.warpmail.net","sentAt":"2010-11-06T11:04:06Z","receivedAt":"2010-11-06T11:04:06Z","isPatch":true,"sender":{"key":"git@grubix.eu","avatar":"https://avatars.githubusercontent.com/u/233215?v=4"},"body":"Currently, git expects \"-----BEGIN PGP SIGNATURE-----\" at the beginning of a\nsignature. But gpg uses \"MESSAGE\" instead of \"SIGNATURE\" when used with\nthe \"rfc1991\" option. This leads to git's failing to verify it's own\nsigned tags, among other problems.\n\nAdd tests for all code paths (tag -v, tag -l -n largenumber, tag -f\nwithout -m) where signature detection matters.\n\nReported-by: Stephan Hugel <urschrei@gmail.com>\nSigned-off-by: Michael J Gruber <git@drmicha.warpmail.net>\n---\n t/t7004-tag.sh |   43 +++++++++++++++++++++++++++++++++++++++++++\n 1 files changed, 43 insertions(+), 0 deletions(-)\n\ndiff --git a/t/t7004-tag.sh b/t/t7004-tag.sh\nindex ac943f5..22dcc45 100755\n--- a/t/t7004-tag.sh\n+++ b/t/t7004-tag.sh\n@@ -1030,6 +1030,49 @@ test_expect_success GPG \\\n \ttest_cmp expect actual\n '\n \n+# usage with rfc1991 signatures\n+echo \"rfc1991\" > gpghome/gpg.conf\n+get_tag_header rfc1991-signed-tag $commit commit $time >expect\n+echo \"RFC1991 signed tag\" >>expect\n+echo '-----BEGIN PGP MESSAGE-----' >>expect\n+test_expect_success GPG \\\n+\t'creating a signed tag with rfc1991' '\n+\tgit tag -s -m \"RFC1991 signed tag\" rfc1991-signed-tag $commit &&\n+\tget_tag_msg rfc1991-signed-tag >actual &&\n+\ttest_cmp expect actual\n+'\n+\n+cat >fakeeditor <<'EOF'\n+#!/bin/sh\n+cp \"$1\" actual\n+EOF\n+chmod +x fakeeditor\n+\n+test_expect_failure GPG \\\n+\t'reediting a signed tag body omits signature' '\n+\techo \"RFC1991 signed tag\" >expect &&\n+\tGIT_EDITOR=./fakeeditor git tag -f -s rfc1991-signed-tag $commit &&\n+\ttest_cmp expect actual\n+'\n+\n+test_expect_failure GPG \\\n+\t'verifying rfc1991 signature' '\n+\tgit tag -v rfc1991-signed-tag\n+'\n+\n+test_expect_failure GPG \\\n+\t'list tag with rfc1991 signature' '\n+\techo \"rfc1991-signed-tag RFC1991 signed tag\" >expect &&\n+\tgit tag -l -n1 rfc1991-signed-tag >actual &&\n+\ttest_cmp expect actual &&\n+\tgit tag -l -n2 rfc1991-signed-tag >actual &&\n+\ttest_cmp expect actual &&\n+\tgit tag -l -n999 rfc1991-signed-tag >actual &&\n+\ttest_cmp expect actual\n+'\n+\n+rm -f gpghome/gpg.conf\n+\n # try to sign with bad user.signingkey\n git config user.signingkey BobTheMouse\n test_expect_success GPG \\\n-- \n1.7.3.2.193.g78bbb\n"},{"id":"155282","messageId":"970e9c2c52aea06c330c330f12b95750d9e9dabd.1289041051.git.git@drmicha.warpmail.net","threadId":"25347","inReplyTo":"4CAB90EC.1080302@drmicha.warpmail.net","subject":"[PATCH 2/5] verify-tag: factor out signature detection","fromName":"Michael J Gruber","fromEmail":"git@drmicha.warpmail.net","sentAt":"2010-11-06T11:04:07Z","receivedAt":"2010-11-06T11:04:07Z","isPatch":true,"sender":{"key":"git@grubix.eu","avatar":"https://avatars.githubusercontent.com/u/233215?v=4"},"body":"into tag.h/c for later reuse and modification.\n\nSigned-off-by: Michael J Gruber <git@drmicha.warpmail.net>\n---\n builtin/verify-tag.c |   10 ++--------\n tag.c                |   11 +++++++++++\n tag.h                |    3 +++\n 3 files changed, 16 insertions(+), 8 deletions(-)\n\ndiff --git a/builtin/verify-tag.c b/builtin/verify-tag.c\nindex 9f482c2..86cac6d 100644\n--- a/builtin/verify-tag.c\n+++ b/builtin/verify-tag.c\n@@ -17,13 +17,11 @@ static const char * const verify_tag_usage[] = {\n \t\tNULL\n };\n \n-#define PGP_SIGNATURE \"-----BEGIN PGP SIGNATURE-----\"\n-\n static int run_gpg_verify(const char *buf, unsigned long size, int verbose)\n {\n \tstruct child_process gpg;\n \tconst char *args_gpg[] = {\"gpg\", \"--verify\", \"FILE\", \"-\", NULL};\n-\tchar path[PATH_MAX], *eol;\n+\tchar path[PATH_MAX];\n \tsize_t len;\n \tint fd, ret;\n \n@@ -37,11 +35,7 @@ static int run_gpg_verify(const char *buf, unsigned long size, int verbose)\n \tclose(fd);\n \n \t/* find the length without signature */\n-\tlen = 0;\n-\twhile (len < size && prefixcmp(buf + len, PGP_SIGNATURE)) {\n-\t\teol = memchr(buf + len, '\\n', size - len);\n-\t\tlen += eol ? eol - (buf + len) + 1 : size - len;\n-\t}\n+\tlen = parse_signature(buf, size);\n \tif (verbose)\n \t\twrite_in_full(1, buf, len);\n \ndiff --git a/tag.c b/tag.c\nindex 28641cf..5f9626c 100644\n--- a/tag.c\n+++ b/tag.c\n@@ -133,3 +133,14 @@ int parse_tag(struct tag *item)\n \tfree(data);\n \treturn ret;\n }\n+\n+size_t parse_signature(const char *buf, unsigned long size)\n+{\n+\tchar *eol;\n+\tsize_t len = 0;\n+\twhile (len < size && prefixcmp(buf + len, PGP_SIGNATURE)) {\n+\t\teol = memchr(buf + len, '\\n', size - len);\n+\t\tlen += eol ? eol - (buf + len) + 1 : size - len;\n+\t}\n+\treturn len;\n+}\ndiff --git a/tag.h b/tag.h\nindex 4766272..4ba2a42 100644\n--- a/tag.h\n+++ b/tag.h\n@@ -3,6 +3,8 @@\n \n #include \"object.h\"\n \n+#define PGP_SIGNATURE \"-----BEGIN PGP SIGNATURE-----\"\n+\n extern const char *tag_type;\n \n struct tag {\n@@ -16,5 +18,6 @@ extern struct tag *lookup_tag(const unsigned char *sha1);\n extern int parse_tag_buffer(struct tag *item, void *data, unsigned long size);\n extern int parse_tag(struct tag *item);\n extern struct object *deref_tag(struct object *, const char *, int);\n+extern size_t parse_signature(const char *buf, unsigned long size);\n \n #endif /* TAG_H */\n-- \n1.7.3.2.193.g78bbb\n"},{"id":"155284","messageId":"2d5bee89df29aeedefeadb73a26633ffe1af9a67.1289041051.git.git@drmicha.warpmail.net","threadId":"25347","inReplyTo":"4CAB90EC.1080302@drmicha.warpmail.net","subject":"[PATCH 3/5] tag: factor out sig detection for body edits","fromName":"Michael J Gruber","fromEmail":"git@drmicha.warpmail.net","sentAt":"2010-11-06T11:04:08Z","receivedAt":"2010-11-06T11:04:08Z","isPatch":true,"sender":{"key":"git@grubix.eu","avatar":"https://avatars.githubusercontent.com/u/233215?v=4"},"body":"Use the factored out code for sig detection when editing existing\ntag bodies (tag -a -f without -m).\n\nSigned-off-by: Michael J Gruber <git@drmicha.warpmail.net>\n---\n builtin/tag.c |   12 ++----------\n 1 files changed, 2 insertions(+), 10 deletions(-)\n\ndiff --git a/builtin/tag.c b/builtin/tag.c\nindex d311491..66feeb0 100644\n--- a/builtin/tag.c\n+++ b/builtin/tag.c\n@@ -29,8 +29,6 @@ struct tag_filter {\n \tstruct commit_list *with_commit;\n };\n \n-#define PGP_SIGNATURE \"-----BEGIN PGP SIGNATURE-----\"\n-\n static int show_reference(const char *refname, const unsigned char *sha1,\n \t\t\t  int flag, void *cb_data)\n {\n@@ -242,8 +240,7 @@ static void write_tag_body(int fd, const unsigned char *sha1)\n {\n \tunsigned long size;\n \tenum object_type type;\n-\tchar *buf, *sp, *eob;\n-\tsize_t len;\n+\tchar *buf, *sp;\n \n \tbuf = read_sha1_file(sha1, &type, &size);\n \tif (!buf)\n@@ -256,12 +253,7 @@ static void write_tag_body(int fd, const unsigned char *sha1)\n \t\treturn;\n \t}\n \tsp += 2; /* skip the 2 LFs */\n-\teob = strstr(sp, \"\\n\" PGP_SIGNATURE \"\\n\");\n-\tif (eob)\n-\t\tlen = eob - sp;\n-\telse\n-\t\tlen = buf + size - sp;\n-\twrite_or_die(fd, sp, len);\n+\twrite_or_die(fd, sp, parse_signature(sp, buf + size - sp));\n \n \tfree(buf);\n }\n-- \n1.7.3.2.193.g78bbb\n"},{"id":"155280","messageId":"581c3740a07c6a9470d7dba13d23721881095d42.1289041051.git.git@drmicha.warpmail.net","threadId":"25347","inReplyTo":"4CAB90EC.1080302@drmicha.warpmail.net","subject":"[PATCH 4/5] tag: factor out sig detection for tag display","fromName":"Michael J Gruber","fromEmail":"git@drmicha.warpmail.net","sentAt":"2010-11-06T11:04:09Z","receivedAt":"2010-11-06T11:04:09Z","isPatch":true,"sender":{"key":"git@grubix.eu","avatar":"https://avatars.githubusercontent.com/u/233215?v=4"},"body":"Use the factored out code for sig detection when displaying tags.\n\nSigned-off-by: Michael J Gruber <git@drmicha.warpmail.net>\n---\n builtin/tag.c |    4 ++--\n 1 files changed, 2 insertions(+), 2 deletions(-)\n\ndiff --git a/builtin/tag.c b/builtin/tag.c\nindex 66feeb0..617a58f 100644\n--- a/builtin/tag.c\n+++ b/builtin/tag.c\n@@ -68,9 +68,9 @@ static int show_reference(const char *refname, const unsigned char *sha1,\n \t\t\treturn 0;\n \t\t}\n \t\t/* only take up to \"lines\" lines, and strip the signature */\n+\t\tsize = parse_signature(buf, size);\n \t\tfor (i = 0, sp += 2;\n-\t\t\t\ti < filter->lines && sp < buf + size &&\n-\t\t\t\tprefixcmp(sp, PGP_SIGNATURE \"\\n\");\n+\t\t\t\ti < filter->lines && sp < buf + size;\n \t\t\t\ti++) {\n \t\t\tif (i)\n \t\t\t\tprintf(\"\\n    \");\n-- \n1.7.3.2.193.g78bbb\n"},{"id":"155285","messageId":"553a88c4ac00e681e605b81f3ce10342a881ac2f.1289041051.git.git@drmicha.warpmail.net","threadId":"25347","inReplyTo":"4CAB90EC.1080302@drmicha.warpmail.net","subject":"[PATCH 5/5] tag: recognize rfc1991 signatures","fromName":"Michael J Gruber","fromEmail":"git@drmicha.warpmail.net","sentAt":"2010-11-06T11:04:10Z","receivedAt":"2010-11-06T11:04:10Z","isPatch":true,"sender":{"key":"git@grubix.eu","avatar":"https://avatars.githubusercontent.com/u/233215?v=4"},"body":"We have always been creating rfc1991 signatures for users with \"rfc1991\"\nin their gpg config but failed to recognize them (tag -l -n largenumber)\nand verify them (tag -v, verify-tag).\n\nMake good use of the refactored signature detection and let us recognize\nand verify those signatures also.\n\nSigned-off-by: Michael J Gruber <git@drmicha.warpmail.net>\n---\n t/t7004-tag.sh |    6 +++---\n tag.c          |    3 ++-\n tag.h          |    1 +\n 3 files changed, 6 insertions(+), 4 deletions(-)\n\ndiff --git a/t/t7004-tag.sh b/t/t7004-tag.sh\nindex 22dcc45..4fe45a4 100755\n--- a/t/t7004-tag.sh\n+++ b/t/t7004-tag.sh\n@@ -1048,19 +1048,19 @@ cp \"$1\" actual\n EOF\n chmod +x fakeeditor\n \n-test_expect_failure GPG \\\n+test_expect_success GPG \\\n \t'reediting a signed tag body omits signature' '\n \techo \"RFC1991 signed tag\" >expect &&\n \tGIT_EDITOR=./fakeeditor git tag -f -s rfc1991-signed-tag $commit &&\n \ttest_cmp expect actual\n '\n \n-test_expect_failure GPG \\\n+test_expect_success GPG \\\n \t'verifying rfc1991 signature' '\n \tgit tag -v rfc1991-signed-tag\n '\n \n-test_expect_failure GPG \\\n+test_expect_success GPG \\\n \t'list tag with rfc1991 signature' '\n \techo \"rfc1991-signed-tag RFC1991 signed tag\" >expect &&\n \tgit tag -l -n1 rfc1991-signed-tag >actual &&\ndiff --git a/tag.c b/tag.c\nindex 5f9626c..18a5142 100644\n--- a/tag.c\n+++ b/tag.c\n@@ -138,7 +138,8 @@ size_t parse_signature(const char *buf, unsigned long size)\n {\n \tchar *eol;\n \tsize_t len = 0;\n-\twhile (len < size && prefixcmp(buf + len, PGP_SIGNATURE)) {\n+\twhile (len < size && prefixcmp(buf + len, PGP_SIGNATURE)\n+\t\t\t&& prefixcmp(buf + len, PGP_MESSAGE)) {\n \t\teol = memchr(buf + len, '\\n', size - len);\n \t\tlen += eol ? eol - (buf + len) + 1 : size - len;\n \t}\ndiff --git a/tag.h b/tag.h\nindex 4ba2a42..134d572 100644\n--- a/tag.h\n+++ b/tag.h\n@@ -4,6 +4,7 @@\n #include \"object.h\"\n \n #define PGP_SIGNATURE \"-----BEGIN PGP SIGNATURE-----\"\n+#define PGP_MESSAGE \"-----BEGIN PGP MESSAGE-----\"\n \n extern const char *tag_type;\n \n-- \n1.7.3.2.193.g78bbb\n"},{"id":"155296","messageId":"AANLkTi=hHk5Ot-5E5kUQy7x+UgYP8O7KV8qgrvLJ3=X0@mail.gmail.com","threadId":"25347","inReplyTo":"970e9c2c52aea06c330c330f12b95750d9e9dabd.1289041051.git.git@drmicha.warpmail.net","subject":"Re: [PATCH 2/5] verify-tag: factor out signature detection","fromName":"Thiago Farina","fromEmail":"tfransosi@gmail.com","sentAt":"2010-11-06T17:40:25Z","receivedAt":"2010-11-06T17:40:25Z","isPatch":true,"sender":{"key":"tfransosi@gmail.com","avatar":"https://avatars.githubusercontent.com/u/970071?v=4"},"body":"On Sat, Nov 6, 2010 at 9:04 AM, Michael J Gruber\n<git@drmicha.warpmail.net> wrote:\n> diff --git a/tag.h b/tag.h\n> index 4766272..4ba2a42 100644\n> --- a/tag.h\n> +++ b/tag.h\n> @@ -3,6 +3,8 @@\n>\n>  #include \"object.h\"\n>\n> +#define PGP_SIGNATURE \"-----BEGIN PGP SIGNATURE-----\"\n> +\n\nnit: I'd move this into the tag.c file. It's only used there now.\n"},{"id":"155297","messageId":"AANLkTi=ZmBdJWKj1z0HE=tFoftzDSJaU5=Ji_1ywcA8+@mail.gmail.com","threadId":"25347","inReplyTo":"553a88c4ac00e681e605b81f3ce10342a881ac2f.1289041051.git.git@drmicha.warpmail.net","subject":"Re: [PATCH 5/5] tag: recognize rfc1991 signatures","fromName":"Thiago Farina","fromEmail":"tfransosi@gmail.com","sentAt":"2010-11-06T17:46:51Z","receivedAt":"2010-11-06T17:46:51Z","isPatch":true,"sender":{"key":"tfransosi@gmail.com","avatar":"https://avatars.githubusercontent.com/u/970071?v=4"},"body":"On Sat, Nov 6, 2010 at 9:04 AM, Michael J Gruber\n<git@drmicha.warpmail.net> wrote:\n> diff --git a/tag.c b/tag.c\n> index 5f9626c..18a5142 100644\n> --- a/tag.c\n> +++ b/tag.c\n> @@ -138,7 +138,8 @@ size_t parse_signature(const char *buf, unsigned long size)\n>  {\n>        char *eol;\n>        size_t len = 0;\n> -       while (len < size && prefixcmp(buf + len, PGP_SIGNATURE)) {\n> +       while (len < size && prefixcmp(buf + len, PGP_SIGNATURE)\n> +                       && prefixcmp(buf + len, PGP_MESSAGE)) {\n\nnit: I think this && should be in the end of the previous line. (Not\nsure what is the preferred style though, comments?).\n"},{"id":"155415","messageId":"7vlj53pqdk.fsf@alter.siamese.dyndns.org","threadId":"25347","inReplyTo":"AANLkTi=ZmBdJWKj1z0HE=tFoftzDSJaU5=Ji_1ywcA8+@mail.gmail.com","subject":"Re: [PATCH 5/5] tag: recognize rfc1991 signatures","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2010-11-08T19:27:51Z","receivedAt":"2010-11-08T19:27:51Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Thiago Farina <tfransosi@gmail.com> writes:\n\n> On Sat, Nov 6, 2010 at 9:04 AM, Michael J Gruber\n> <git@drmicha.warpmail.net> wrote:\n>> diff --git a/tag.c b/tag.c\n>> index 5f9626c..18a5142 100644\n>> --- a/tag.c\n>> +++ b/tag.c\n>> @@ -138,7 +138,8 @@ size_t parse_signature(const char *buf, unsigned long size)\n>>  {\n>>        char *eol;\n>>        size_t len = 0;\n>> -       while (len < size && prefixcmp(buf + len, PGP_SIGNATURE)) {\n>> +       while (len < size && prefixcmp(buf + len, PGP_SIGNATURE)\n>> +                       && prefixcmp(buf + len, PGP_MESSAGE)) {\n>\n> nit: I think this && should be in the end of the previous line. (Not\n> sure what is the preferred style though, comments?).\n\nI personally prefer to lay out a multi-line expression so that you can see\nthe parse tree when you tilt your head the same way as when you view ;-),\ni.e. what Michael wrote, but when I inherited the codebase, nobody wrote\nmulti-line expressions that way, so the standard coding style here has\nbecome \"&& at the end\" due to the \"mimic the surrounding code\" rule.\n"},{"id":"155502","messageId":"7vwrommn6j.fsf@alter.siamese.dyndns.org","threadId":"25347","inReplyTo":"c20fb62cefcd42533e47f6f1bf5817712e5ebf9a.1289041051.git.git@drmicha.warpmail.net","subject":"Re: [PATCH 1/5] t/t7004-tag: test handling of rfc1991 signatures","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2010-11-09T17:17:24Z","receivedAt":"2010-11-09T17:17:24Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Michael J Gruber <git@drmicha.warpmail.net> writes:\n\n> Currently, git expects \"-----BEGIN PGP SIGNATURE-----\" at the beginning of a\n> signature. But gpg uses \"MESSAGE\" instead of \"SIGNATURE\" when used with\n> the \"rfc1991\" option. This leads to git's failing to verify it's own\n> signed tags, among other problems.\n>\n> Add tests for all code paths (tag -v, tag -l -n largenumber, tag -f\n> without -m) where signature detection matters.\n>\n> Reported-by: Stephan Hugel <urschrei@gmail.com>\n> Signed-off-by: Michael J Gruber <git@drmicha.warpmail.net>\n> ---\n>  t/t7004-tag.sh |   43 +++++++++++++++++++++++++++++++++++++++++++\n>  1 files changed, 43 insertions(+), 0 deletions(-)\n>\n> diff --git a/t/t7004-tag.sh b/t/t7004-tag.sh\n> index ac943f5..22dcc45 100755\n> --- a/t/t7004-tag.sh\n> +++ b/t/t7004-tag.sh\n> @@ -1030,6 +1030,49 @@ test_expect_success GPG \\\n>  \ttest_cmp expect actual\n>  '\n>  \n> +# usage with rfc1991 signatures\n> +echo \"rfc1991\" > gpghome/gpg.conf\n> +get_tag_header rfc1991-signed-tag $commit commit $time >expect\n> +echo \"RFC1991 signed tag\" >>expect\n> +echo '-----BEGIN PGP MESSAGE-----' >>expect\n> +test_expect_success GPG \\\n> +\t'creating a signed tag with rfc1991' '\n> +\tgit tag -s -m \"RFC1991 signed tag\" rfc1991-signed-tag $commit &&\n> +\tget_tag_msg rfc1991-signed-tag >actual &&\n> +\ttest_cmp expect actual\n> +'\n> +\n> +cat >fakeeditor <<'EOF'\n> +#!/bin/sh\n> +cp \"$1\" actual\n> +EOF\n> +chmod +x fakeeditor\n> +\n> +test_expect_failure GPG \\\n> +...\n> +'\n> +\n> +rm -f gpghome/gpg.conf\n\nShouldn't this line be placed much earlier in the sequence, to make sure\nthat people without --rfc1991 can grok new style signatures?  Better yet,\nshouldn't the script test rfc1991-signed tags both with and without the\nrfc1991 configuration?\n"},{"id":"155503","messageId":"4CD9839B.6060406@drmicha.warpmail.net","threadId":"25347","inReplyTo":"7vwrommn6j.fsf@alter.siamese.dyndns.org","subject":"Re: [PATCH 1/5] t/t7004-tag: test handling of rfc1991 signatures","fromName":"Michael J Gruber","fromEmail":"git@drmicha.warpmail.net","sentAt":"2010-11-09T17:23:39Z","receivedAt":"2010-11-09T17:23:39Z","isPatch":true,"sender":{"key":"git@grubix.eu","avatar":"https://avatars.githubusercontent.com/u/233215?v=4"},"body":"Junio C Hamano venit, vidit, dixit 09.11.2010 18:17:\n> Michael J Gruber <git@drmicha.warpmail.net> writes:\n> \n>> Currently, git expects \"-----BEGIN PGP SIGNATURE-----\" at the beginning of a\n>> signature. But gpg uses \"MESSAGE\" instead of \"SIGNATURE\" when used with\n>> the \"rfc1991\" option. This leads to git's failing to verify it's own\n>> signed tags, among other problems.\n>>\n>> Add tests for all code paths (tag -v, tag -l -n largenumber, tag -f\n>> without -m) where signature detection matters.\n>>\n>> Reported-by: Stephan Hugel <urschrei@gmail.com>\n>> Signed-off-by: Michael J Gruber <git@drmicha.warpmail.net>\n>> ---\n>>  t/t7004-tag.sh |   43 +++++++++++++++++++++++++++++++++++++++++++\n>>  1 files changed, 43 insertions(+), 0 deletions(-)\n>>\n>> diff --git a/t/t7004-tag.sh b/t/t7004-tag.sh\n>> index ac943f5..22dcc45 100755\n>> --- a/t/t7004-tag.sh\n>> +++ b/t/t7004-tag.sh\n>> @@ -1030,6 +1030,49 @@ test_expect_success GPG \\\n>>  \ttest_cmp expect actual\n>>  '\n>>  \n>> +# usage with rfc1991 signatures\n>> +echo \"rfc1991\" > gpghome/gpg.conf\n>> +get_tag_header rfc1991-signed-tag $commit commit $time >expect\n>> +echo \"RFC1991 signed tag\" >>expect\n>> +echo '-----BEGIN PGP MESSAGE-----' >>expect\n>> +test_expect_success GPG \\\n>> +\t'creating a signed tag with rfc1991' '\n>> +\tgit tag -s -m \"RFC1991 signed tag\" rfc1991-signed-tag $commit &&\n>> +\tget_tag_msg rfc1991-signed-tag >actual &&\n>> +\ttest_cmp expect actual\n>> +'\n>> +\n>> +cat >fakeeditor <<'EOF'\n>> +#!/bin/sh\n>> +cp \"$1\" actual\n>> +EOF\n>> +chmod +x fakeeditor\n>> +\n>> +test_expect_failure GPG \\\n>> +...\n>> +'\n>> +\n>> +rm -f gpghome/gpg.conf\n> \n> Shouldn't this line be placed much earlier in the sequence, to make sure\n> that people without --rfc1991 can grok new style signatures?  Better yet,\n> shouldn't the script test rfc1991-signed tags both with and without the\n> rfc1991 configuration?\n\nThe --rfc1991 option matters for the creation of signatures only, not\nfor the verification (and neither for display/listing with git, of course).\n\nMichael\n"},{"id":"155553","messageId":"7vhbfqjaho.fsf@alter.siamese.dyndns.org","threadId":"25347","inReplyTo":"4CD9839B.6060406@drmicha.warpmail.net","subject":"Re: [PATCH 1/5] t/t7004-tag: test handling of rfc1991 signatures","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2010-11-10T00:19:47Z","receivedAt":"2010-11-10T00:19:47Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Michael J Gruber <git@drmicha.warpmail.net> writes:\n\n> The --rfc1991 option matters for the creation of signatures only, not\n> for the verification (and neither for display/listing with git, of course).\n\nDoesn't the above statement assume a bit too much about how the current\nversion of gpg behaves, I have to wonder?\n"},{"id":"155578","messageId":"4CDA569F.5090901@drmicha.warpmail.net","threadId":"25347","inReplyTo":"7vhbfqjaho.fsf@alter.siamese.dyndns.org","subject":"Re: [PATCH 1/5] t/t7004-tag: test handling of rfc1991 signatures","fromName":"Michael J Gruber","fromEmail":"git@drmicha.warpmail.net","sentAt":"2010-11-10T08:23:59Z","receivedAt":"2010-11-10T08:23:59Z","isPatch":true,"sender":{"key":"git@grubix.eu","avatar":"https://avatars.githubusercontent.com/u/233215?v=4"},"body":"Junio C Hamano venit, vidit, dixit 10.11.2010 01:19:\n> Michael J Gruber <git@drmicha.warpmail.net> writes:\n> \n>> The --rfc1991 option matters for the creation of signatures only, not\n>> for the verification (and neither for display/listing with git, of course).\n> \n> Doesn't the above statement assume a bit too much about how the current\n> version of gpg behaves, I have to wonder?\n\n[Note: I'm sick and may sound even more grumpy than usual...]\n\n* This test (and the patches) is about making signed tags work for\npeople with rfc1991 in their options. This is why I put rfc1991 in gpg's\noption file.\n\nNote that git always produced rfc1991 sigs for those users, and always\nfailed to verify/list them properly, no matter what gpg option is active\nduring the verify/list phase.\n\n* If you /also/ want to test that users without --rfc1991 can very those\nrfc1991 sigs one would need an additional test after the \"rm...\". I'm\ntelling you that --rfc1991 is completely irrelevant for what gpg\naccepts, and thus the additional test is completely superfluous. gpg is\nlenient about what it accepts (within existing rfc's) and strict about\nwhat it produces (according to what you tell it to do), just like it\nshould. This is by design and intentional, not version dependent or by\nchance. (Even requesting strict openpgp mode does not change this.)\n\nSo, the rm needs to stay where it is.\n\nI could repeat the three tests again after the rm, albeit in different\norder so that the first one has no chance of rewriting the rfc1991 sig\ninto an openpgp sig. I have no objection against that, it does no good\nand no harm.\n\nMichael\n"},{"id":"155582","messageId":"cover.1289387142.git.git@drmicha.warpmail.net","threadId":"25347","inReplyTo":"cover.1289041051.git.git@drmicha.warpmail.net","subject":"[PATCHv2 0/5] Handling of rfc1991 signatures","fromName":"Michael J Gruber","fromEmail":"git@drmicha.warpmail.net","sentAt":"2010-11-10T11:17:25Z","receivedAt":"2010-11-10T11:17:25Z","isPatch":false,"sender":{"key":"git@grubix.eu","avatar":"https://avatars.githubusercontent.com/u/233215?v=4"},"body":"This mini-series fixes the handling of signed tags for users\nwith \"rfc1991\" in their gpg config. In fact, the refactoring\ndone in the middle three patches would be worthwhile even\nwithout the side effect of having to fix the handling in\none place only rather than three...\n\nv2 has these changes:\n* additional tests for dealing with rfc1991 sigs without the rfc1991 option set (1/5)\n* macros in tag.c rather than tag.h since they are used only in tag.c (2/5)\n* logical && at eol for continued logical expression in C (5/5)\n\nMichael J Gruber (5):\n  t/t7004-tag: test handling of rfc1991 signatures\n  verify-tag: factor out signature detection\n  tag: factor out sig detection for body edits\n  tag: factor out sig detection for tag display\n  tag: recognize rfc1991 signatures\n\n builtin/tag.c        |   16 +++---------\n builtin/verify-tag.c |   10 +------\n t/t7004-tag.sh       |   66 ++++++++++++++++++++++++++++++++++++++++++++++++++\n tag.c                |   15 +++++++++++\n tag.h                |    1 +\n 5 files changed, 88 insertions(+), 20 deletions(-)\n\n-- \n1.7.3.2.193.g78bbb\n"},{"id":"155583","messageId":"5bad237fcbe2b01481d350b24bd7daea2dd0bd64.1289387142.git.git@drmicha.warpmail.net","threadId":"25347","inReplyTo":"cover.1289041051.git.git@drmicha.warpmail.net","subject":"[PATCHv2 1/5] t/t7004-tag: test handling of rfc1991 signatures","fromName":"Michael J Gruber","fromEmail":"git@drmicha.warpmail.net","sentAt":"2010-11-10T11:17:26Z","receivedAt":"2010-11-10T11:17:26Z","isPatch":false,"sender":{"key":"git@grubix.eu","avatar":"https://avatars.githubusercontent.com/u/233215?v=4"},"body":"Currently, git expects \"-----BEGIN PGP SIGNATURE-----\" at the beginning of a\nsignature. But gpg uses \"MESSAGE\" instead of \"SIGNATURE\" when used with\nthe \"rfc1991\" option. This leads to git's failing to verify it's own\nsigned tags, among other problems.\n\nAdd tests for all code paths (tag -v, tag -l -n largenumber, tag -f\nwithout -m) where signature detection matters.\n\nReported-by: Stephan Hugel <urschrei@gmail.com>\nSigned-off-by: Michael J Gruber <git@drmicha.warpmail.net>\n---\n t/t7004-tag.sh |   66 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++\n 1 files changed, 66 insertions(+), 0 deletions(-)\n\ndiff --git a/t/t7004-tag.sh b/t/t7004-tag.sh\nindex ac943f5..c7d49e1 100755\n--- a/t/t7004-tag.sh\n+++ b/t/t7004-tag.sh\n@@ -1030,6 +1030,72 @@ test_expect_success GPG \\\n \ttest_cmp expect actual\n '\n \n+# usage with rfc1991 signatures\n+echo \"rfc1991\" > gpghome/gpg.conf\n+get_tag_header rfc1991-signed-tag $commit commit $time >expect\n+echo \"RFC1991 signed tag\" >>expect\n+echo '-----BEGIN PGP MESSAGE-----' >>expect\n+test_expect_success GPG \\\n+\t'creating a signed tag with rfc1991' '\n+\tgit tag -s -m \"RFC1991 signed tag\" rfc1991-signed-tag $commit &&\n+\tget_tag_msg rfc1991-signed-tag >actual &&\n+\ttest_cmp expect actual\n+'\n+\n+cat >fakeeditor <<'EOF'\n+#!/bin/sh\n+cp \"$1\" actual\n+EOF\n+chmod +x fakeeditor\n+\n+test_expect_failure GPG \\\n+\t'reediting a signed tag body omits signature' '\n+\techo \"RFC1991 signed tag\" >expect &&\n+\tGIT_EDITOR=./fakeeditor git tag -f -s rfc1991-signed-tag $commit &&\n+\ttest_cmp expect actual\n+'\n+\n+test_expect_failure GPG \\\n+\t'verifying rfc1991 signature' '\n+\tgit tag -v rfc1991-signed-tag\n+'\n+\n+test_expect_failure GPG \\\n+\t'list tag with rfc1991 signature' '\n+\techo \"rfc1991-signed-tag RFC1991 signed tag\" >expect &&\n+\tgit tag -l -n1 rfc1991-signed-tag >actual &&\n+\ttest_cmp expect actual &&\n+\tgit tag -l -n2 rfc1991-signed-tag >actual &&\n+\ttest_cmp expect actual &&\n+\tgit tag -l -n999 rfc1991-signed-tag >actual &&\n+\ttest_cmp expect actual\n+'\n+\n+rm -f gpghome/gpg.conf\n+\n+test_expect_failure GPG \\\n+\t'verifying rfc1991 signature without --rfc1991' '\n+\tgit tag -v rfc1991-signed-tag\n+'\n+\n+test_expect_failure GPG \\\n+\t'list tag with rfc1991 signature without --rfc1991' '\n+\techo \"rfc1991-signed-tag RFC1991 signed tag\" >expect &&\n+\tgit tag -l -n1 rfc1991-signed-tag >actual &&\n+\ttest_cmp expect actual &&\n+\tgit tag -l -n2 rfc1991-signed-tag >actual &&\n+\ttest_cmp expect actual &&\n+\tgit tag -l -n999 rfc1991-signed-tag >actual &&\n+\ttest_cmp expect actual\n+'\n+\n+test_expect_failure GPG \\\n+\t'reediting a signed tag body omits signature' '\n+\techo \"RFC1991 signed tag\" >expect &&\n+\tGIT_EDITOR=./fakeeditor git tag -f -s rfc1991-signed-tag $commit &&\n+\ttest_cmp expect actual\n+'\n+\n # try to sign with bad user.signingkey\n git config user.signingkey BobTheMouse\n test_expect_success GPG \\\n-- \n1.7.3.2.193.g78bbb\n"},{"id":"155584","messageId":"9dd97bd6e2b0443bff1083192b579320931432a7.1289387142.git.git@drmicha.warpmail.net","threadId":"25347","inReplyTo":"cover.1289041051.git.git@drmicha.warpmail.net","subject":"[PATCHv2 2/5] verify-tag: factor out signature detection","fromName":"Michael J Gruber","fromEmail":"git@drmicha.warpmail.net","sentAt":"2010-11-10T11:17:27Z","receivedAt":"2010-11-10T11:17:27Z","isPatch":false,"sender":{"key":"git@grubix.eu","avatar":"https://avatars.githubusercontent.com/u/233215?v=4"},"body":"into tag.h/c for later reuse and modification.\n\nSigned-off-by: Michael J Gruber <git@drmicha.warpmail.net>\n---\n builtin/verify-tag.c |   10 ++--------\n tag.c                |   13 +++++++++++++\n tag.h                |    1 +\n 3 files changed, 16 insertions(+), 8 deletions(-)\n\ndiff --git a/builtin/verify-tag.c b/builtin/verify-tag.c\nindex 9f482c2..86cac6d 100644\n--- a/builtin/verify-tag.c\n+++ b/builtin/verify-tag.c\n@@ -17,13 +17,11 @@ static const char * const verify_tag_usage[] = {\n \t\tNULL\n };\n \n-#define PGP_SIGNATURE \"-----BEGIN PGP SIGNATURE-----\"\n-\n static int run_gpg_verify(const char *buf, unsigned long size, int verbose)\n {\n \tstruct child_process gpg;\n \tconst char *args_gpg[] = {\"gpg\", \"--verify\", \"FILE\", \"-\", NULL};\n-\tchar path[PATH_MAX], *eol;\n+\tchar path[PATH_MAX];\n \tsize_t len;\n \tint fd, ret;\n \n@@ -37,11 +35,7 @@ static int run_gpg_verify(const char *buf, unsigned long size, int verbose)\n \tclose(fd);\n \n \t/* find the length without signature */\n-\tlen = 0;\n-\twhile (len < size && prefixcmp(buf + len, PGP_SIGNATURE)) {\n-\t\teol = memchr(buf + len, '\\n', size - len);\n-\t\tlen += eol ? eol - (buf + len) + 1 : size - len;\n-\t}\n+\tlen = parse_signature(buf, size);\n \tif (verbose)\n \t\twrite_in_full(1, buf, len);\n \ndiff --git a/tag.c b/tag.c\nindex 28641cf..d4f3080 100644\n--- a/tag.c\n+++ b/tag.c\n@@ -4,6 +4,8 @@\n #include \"tree.h\"\n #include \"blob.h\"\n \n+#define PGP_SIGNATURE \"-----BEGIN PGP SIGNATURE-----\"\n+\n const char *tag_type = \"tag\";\n \n struct object *deref_tag(struct object *o, const char *warn, int warnlen)\n@@ -133,3 +135,14 @@ int parse_tag(struct tag *item)\n \tfree(data);\n \treturn ret;\n }\n+\n+size_t parse_signature(const char *buf, unsigned long size)\n+{\n+\tchar *eol;\n+\tsize_t len = 0;\n+\twhile (len < size && prefixcmp(buf + len, PGP_SIGNATURE)) {\n+\t\teol = memchr(buf + len, '\\n', size - len);\n+\t\tlen += eol ? eol - (buf + len) + 1 : size - len;\n+\t}\n+\treturn len;\n+}\ndiff --git a/tag.h b/tag.h\nindex 4766272..8522370 100644\n--- a/tag.h\n+++ b/tag.h\n@@ -16,5 +16,6 @@ extern struct tag *lookup_tag(const unsigned char *sha1);\n extern int parse_tag_buffer(struct tag *item, void *data, unsigned long size);\n extern int parse_tag(struct tag *item);\n extern struct object *deref_tag(struct object *, const char *, int);\n+extern size_t parse_signature(const char *buf, unsigned long size);\n \n #endif /* TAG_H */\n-- \n1.7.3.2.193.g78bbb\n"},{"id":"155585","messageId":"a463b5b983213c630b800b961fc7bc10c3b4bc5e.1289387142.git.git@drmicha.warpmail.net","threadId":"25347","inReplyTo":"cover.1289041051.git.git@drmicha.warpmail.net","subject":"[PATCHv2 3/5] tag: factor out sig detection for body edits","fromName":"Michael J Gruber","fromEmail":"git@drmicha.warpmail.net","sentAt":"2010-11-10T11:17:28Z","receivedAt":"2010-11-10T11:17:28Z","isPatch":false,"sender":{"key":"git@grubix.eu","avatar":"https://avatars.githubusercontent.com/u/233215?v=4"},"body":"Use the factored out code for sig detection when editing existing\ntag bodies (tag -a -f without -m).\n\nSigned-off-by: Michael J Gruber <git@drmicha.warpmail.net>\n---\n builtin/tag.c |   12 ++----------\n 1 files changed, 2 insertions(+), 10 deletions(-)\n\ndiff --git a/builtin/tag.c b/builtin/tag.c\nindex d311491..66feeb0 100644\n--- a/builtin/tag.c\n+++ b/builtin/tag.c\n@@ -29,8 +29,6 @@ struct tag_filter {\n \tstruct commit_list *with_commit;\n };\n \n-#define PGP_SIGNATURE \"-----BEGIN PGP SIGNATURE-----\"\n-\n static int show_reference(const char *refname, const unsigned char *sha1,\n \t\t\t  int flag, void *cb_data)\n {\n@@ -242,8 +240,7 @@ static void write_tag_body(int fd, const unsigned char *sha1)\n {\n \tunsigned long size;\n \tenum object_type type;\n-\tchar *buf, *sp, *eob;\n-\tsize_t len;\n+\tchar *buf, *sp;\n \n \tbuf = read_sha1_file(sha1, &type, &size);\n \tif (!buf)\n@@ -256,12 +253,7 @@ static void write_tag_body(int fd, const unsigned char *sha1)\n \t\treturn;\n \t}\n \tsp += 2; /* skip the 2 LFs */\n-\teob = strstr(sp, \"\\n\" PGP_SIGNATURE \"\\n\");\n-\tif (eob)\n-\t\tlen = eob - sp;\n-\telse\n-\t\tlen = buf + size - sp;\n-\twrite_or_die(fd, sp, len);\n+\twrite_or_die(fd, sp, parse_signature(sp, buf + size - sp));\n \n \tfree(buf);\n }\n-- \n1.7.3.2.193.g78bbb\n"},{"id":"155586","messageId":"fb76f7e44236f2e4ac2e4e26f1eb2128fb9943df.1289387142.git.git@drmicha.warpmail.net","threadId":"25347","inReplyTo":"cover.1289041051.git.git@drmicha.warpmail.net","subject":"[PATCHv2 4/5] tag: factor out sig detection for tag display","fromName":"Michael J Gruber","fromEmail":"git@drmicha.warpmail.net","sentAt":"2010-11-10T11:17:29Z","receivedAt":"2010-11-10T11:17:29Z","isPatch":false,"sender":{"key":"git@grubix.eu","avatar":"https://avatars.githubusercontent.com/u/233215?v=4"},"body":"Use the factored out code for sig detection when displaying tags.\n\nSigned-off-by: Michael J Gruber <git@drmicha.warpmail.net>\n---\n builtin/tag.c |    4 ++--\n 1 files changed, 2 insertions(+), 2 deletions(-)\n\ndiff --git a/builtin/tag.c b/builtin/tag.c\nindex 66feeb0..617a58f 100644\n--- a/builtin/tag.c\n+++ b/builtin/tag.c\n@@ -68,9 +68,9 @@ static int show_reference(const char *refname, const unsigned char *sha1,\n \t\t\treturn 0;\n \t\t}\n \t\t/* only take up to \"lines\" lines, and strip the signature */\n+\t\tsize = parse_signature(buf, size);\n \t\tfor (i = 0, sp += 2;\n-\t\t\t\ti < filter->lines && sp < buf + size &&\n-\t\t\t\tprefixcmp(sp, PGP_SIGNATURE \"\\n\");\n+\t\t\t\ti < filter->lines && sp < buf + size;\n \t\t\t\ti++) {\n \t\t\tif (i)\n \t\t\t\tprintf(\"\\n    \");\n-- \n1.7.3.2.193.g78bbb\n"},{"id":"155587","messageId":"052734203b66fea86fda1b9aee0cf1975a3a6f9c.1289387142.git.git@drmicha.warpmail.net","threadId":"25347","inReplyTo":"cover.1289041051.git.git@drmicha.warpmail.net","subject":"[PATCHv2 5/5] tag: recognize rfc1991 signatures","fromName":"Michael J Gruber","fromEmail":"git@drmicha.warpmail.net","sentAt":"2010-11-10T11:17:30Z","receivedAt":"2010-11-10T11:17:30Z","isPatch":false,"sender":{"key":"git@grubix.eu","avatar":"https://avatars.githubusercontent.com/u/233215?v=4"},"body":"We have always been creating rfc1991 signatures for users with \"rfc1991\"\nin their gpg config but failed to recognize them (tag -l -n largenumber)\nand verify them (tag -v, verify-tag).\n\nMake good use of the refactored signature detection and let us recognize\nand verify those signatures also.\n\nSigned-off-by: Michael J Gruber <git@drmicha.warpmail.net>\n---\n t/t7004-tag.sh |   12 ++++++------\n tag.c          |    4 +++-\n 2 files changed, 9 insertions(+), 7 deletions(-)\n\ndiff --git a/t/t7004-tag.sh b/t/t7004-tag.sh\nindex c7d49e1..6841c23 100755\n--- a/t/t7004-tag.sh\n+++ b/t/t7004-tag.sh\n@@ -1048,19 +1048,19 @@ cp \"$1\" actual\n EOF\n chmod +x fakeeditor\n \n-test_expect_failure GPG \\\n+test_expect_success GPG \\\n \t'reediting a signed tag body omits signature' '\n \techo \"RFC1991 signed tag\" >expect &&\n \tGIT_EDITOR=./fakeeditor git tag -f -s rfc1991-signed-tag $commit &&\n \ttest_cmp expect actual\n '\n \n-test_expect_failure GPG \\\n+test_expect_success GPG \\\n \t'verifying rfc1991 signature' '\n \tgit tag -v rfc1991-signed-tag\n '\n \n-test_expect_failure GPG \\\n+test_expect_success GPG \\\n \t'list tag with rfc1991 signature' '\n \techo \"rfc1991-signed-tag RFC1991 signed tag\" >expect &&\n \tgit tag -l -n1 rfc1991-signed-tag >actual &&\n@@ -1073,12 +1073,12 @@ test_expect_failure GPG \\\n \n rm -f gpghome/gpg.conf\n \n-test_expect_failure GPG \\\n+test_expect_success GPG \\\n \t'verifying rfc1991 signature without --rfc1991' '\n \tgit tag -v rfc1991-signed-tag\n '\n \n-test_expect_failure GPG \\\n+test_expect_success GPG \\\n \t'list tag with rfc1991 signature without --rfc1991' '\n \techo \"rfc1991-signed-tag RFC1991 signed tag\" >expect &&\n \tgit tag -l -n1 rfc1991-signed-tag >actual &&\n@@ -1089,7 +1089,7 @@ test_expect_failure GPG \\\n \ttest_cmp expect actual\n '\n \n-test_expect_failure GPG \\\n+test_expect_success GPG \\\n \t'reediting a signed tag body omits signature' '\n \techo \"RFC1991 signed tag\" >expect &&\n \tGIT_EDITOR=./fakeeditor git tag -f -s rfc1991-signed-tag $commit &&\ndiff --git a/tag.c b/tag.c\nindex d4f3080..f789744 100644\n--- a/tag.c\n+++ b/tag.c\n@@ -5,6 +5,7 @@\n #include \"blob.h\"\n \n #define PGP_SIGNATURE \"-----BEGIN PGP SIGNATURE-----\"\n+#define PGP_MESSAGE \"-----BEGIN PGP MESSAGE-----\"\n \n const char *tag_type = \"tag\";\n \n@@ -140,7 +141,8 @@ size_t parse_signature(const char *buf, unsigned long size)\n {\n \tchar *eol;\n \tsize_t len = 0;\n-\twhile (len < size && prefixcmp(buf + len, PGP_SIGNATURE)) {\n+\twhile (len < size && prefixcmp(buf + len, PGP_SIGNATURE) &&\n+\t\t\tprefixcmp(buf + len, PGP_MESSAGE)) {\n \t\teol = memchr(buf + len, '\\n', size - len);\n \t\tlen += eol ? eol - (buf + len) + 1 : size - len;\n \t}\n-- \n1.7.3.2.193.g78bbb\n"},{"id":"155605","messageId":"7vk4klhy9k.fsf@alter.siamese.dyndns.org","threadId":"25347","inReplyTo":"cover.1289387142.git.git@drmicha.warpmail.net","subject":"Re: [PATCHv2 0/5] Handling of rfc1991 signatures","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2010-11-10T17:41:27Z","receivedAt":"2010-11-10T17:41:27Z","isPatch":false,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Thanks, will queue.\n"}]}