{"thread":{"id":"32787","subject":"[PATCH 0/3] GPG running out of pipes fixes","startedAt":"2013-01-31T02:01:03Z","lastAt":"2013-01-31T23:57:46Z","messageCount":13,"participants":["Stephen Boyd","Jeff King","Junio C Hamano","Jonathan Nieder"],"isPatch":true,"patchVersion":1,"patchTotal":3},"messages":[{"id":"208326","messageId":"1359597666-10108-1-git-send-email-sboyd@codeaurora.org","threadId":"32787","inReplyTo":null,"subject":"[PATCH 0/3] GPG running out of pipes fixes","fromName":"Stephen Boyd","fromEmail":"sboyd@codeaurora.org","sentAt":"2013-01-31T02:01:03Z","receivedAt":"2013-01-31T02:01:03Z","isPatch":true,"sender":{"key":"bebarino@gmail.com","avatar":"https://avatars.githubusercontent.com/u/38832?v=4"},"body":"While running --show-signatures on the linux kernel I noticed that after\na while git failed with an error message indicating it had run out of \nfile descriptors. The first patch fixes this problem, and the next\ntwo are randmom bits since I was in the area.\n\nStephen Boyd (3):\n  gpg: Close stderr once finished with it in verify_signed_buffer()\n  run-command: Be more informative about what failed\n  gpg: Allow translation of more error messages\n\n gpg-interface.c | 8 +++++---\n run-command.c   | 8 ++++++--\n 2 files changed, 11 insertions(+), 5 deletions(-)\n\n-- \nThe Qualcomm Innovation Center, Inc. is a member of the Code Aurora Forum,\nhosted by The Linux Foundation\n"},{"id":"208327","messageId":"1359597666-10108-2-git-send-email-sboyd@codeaurora.org","threadId":"32787","inReplyTo":"1359597666-10108-1-git-send-email-sboyd@codeaurora.org","subject":"[PATCH 1/3] gpg: Close stderr once finished with it in verify_signed_buffer()","fromName":"Stephen Boyd","fromEmail":"sboyd@codeaurora.org","sentAt":"2013-01-31T02:01:04Z","receivedAt":"2013-01-31T02:01:04Z","isPatch":true,"sender":{"key":"bebarino@gmail.com","avatar":"https://avatars.githubusercontent.com/u/38832?v=4"},"body":"Failing to close the stderr pipe in verify_signed_buffer() causes\ngit to run out of file descriptors if there are many calls to\nverify_signed_buffer(). An easy way to trigger this is to run\n\n git log --show-signature --merges | grep \"key\"\n\non the linux kernel git repo. Eventually it will fail with\n\n error: cannot create pipe for gpg: Too many open files\n error: could not run gpg.\n\nClose the stderr pipe so that this can't happen.\n\nSigned-off-by: Stephen Boyd <sboyd@codeaurora.org>\n---\n gpg-interface.c | 2 ++\n 1 file changed, 2 insertions(+)\n\ndiff --git a/gpg-interface.c b/gpg-interface.c\nindex 0863c61..2c0bed3 100644\n--- a/gpg-interface.c\n+++ b/gpg-interface.c\n@@ -133,6 +133,8 @@ int verify_signed_buffer(const char *payload, size_t payload_size,\n \tif (gpg_output)\n \t\tstrbuf_read(gpg_output, gpg.err, 0);\n \tret = finish_command(&gpg);\n+\tif (gpg_output)\n+\t\tclose(gpg.err);\n \n \tunlink_or_warn(path);\n \n-- \nThe Qualcomm Innovation Center, Inc. is a member of the Code Aurora Forum,\nhosted by The Linux Foundation\n"},{"id":"208329","messageId":"1359597666-10108-3-git-send-email-sboyd@codeaurora.org","threadId":"32787","inReplyTo":"1359597666-10108-1-git-send-email-sboyd@codeaurora.org","subject":"[PATCH 2/3] run-command: Be more informative about what failed","fromName":"Stephen Boyd","fromEmail":"sboyd@codeaurora.org","sentAt":"2013-01-31T02:01:05Z","receivedAt":"2013-01-31T02:01:05Z","isPatch":true,"sender":{"key":"bebarino@gmail.com","avatar":"https://avatars.githubusercontent.com/u/38832?v=4"},"body":"While debugging an error with verify_signed_buffer() the error\nmessages from run-command weren't very useful:\n\n error: cannot create pipe for gpg: Too many open files\n error: could not run gpg.\n\nbecause they didn't indicate *which* pipe couldn't be created.\n\nPrint which pipe failed to be created in the error message so we\ncan more easily debug similar problems in the future.\n\nFor example, the above error now prints:\n\n error: cannot create stderr pipe for gpg: Too many open files\n error: could not run gpg.\n\nSigned-off-by: Stephen Boyd <sboyd@codeaurora.org>\n---\n run-command.c | 8 ++++++--\n 1 file changed, 6 insertions(+), 2 deletions(-)\n\ndiff --git a/run-command.c b/run-command.c\nindex 12d4ddb..016dd05 100644\n--- a/run-command.c\n+++ b/run-command.c\n@@ -274,6 +274,7 @@ int start_command(struct child_process *cmd)\n \tint need_in, need_out, need_err;\n \tint fdin[2], fdout[2], fderr[2];\n \tint failed_errno = failed_errno;\n+\tchar *str;\n \n \t/*\n \t * In case of errors we must keep the promise to close FDs\n@@ -286,6 +287,7 @@ int start_command(struct child_process *cmd)\n \t\t\tfailed_errno = errno;\n \t\t\tif (cmd->out > 0)\n \t\t\t\tclose(cmd->out);\n+\t\t\tstr = \"stdin\";\n \t\t\tgoto fail_pipe;\n \t\t}\n \t\tcmd->in = fdin[1];\n@@ -301,6 +303,7 @@ int start_command(struct child_process *cmd)\n \t\t\t\tclose_pair(fdin);\n \t\t\telse if (cmd->in)\n \t\t\t\tclose(cmd->in);\n+\t\t\tstr = \"stdout\";\n \t\t\tgoto fail_pipe;\n \t\t}\n \t\tcmd->out = fdout[0];\n@@ -318,9 +321,10 @@ int start_command(struct child_process *cmd)\n \t\t\t\tclose_pair(fdout);\n \t\t\telse if (cmd->out)\n \t\t\t\tclose(cmd->out);\n+\t\t\tstr = \"stderr\";\n fail_pipe:\n-\t\t\terror(\"cannot create pipe for %s: %s\",\n-\t\t\t\tcmd->argv[0], strerror(failed_errno));\n+\t\t\terror(\"cannot create %s pipe for %s: %s\",\n+\t\t\t\tstr, cmd->argv[0], strerror(failed_errno));\n \t\t\terrno = failed_errno;\n \t\t\treturn -1;\n \t\t}\n-- \nThe Qualcomm Innovation Center, Inc. is a member of the Code Aurora Forum,\nhosted by The Linux Foundation\n"},{"id":"208328","messageId":"1359597666-10108-4-git-send-email-sboyd@codeaurora.org","threadId":"32787","inReplyTo":"1359597666-10108-1-git-send-email-sboyd@codeaurora.org","subject":"[PATCH 3/3] gpg: Allow translation of more error messages","fromName":"Stephen Boyd","fromEmail":"sboyd@codeaurora.org","sentAt":"2013-01-31T02:01:06Z","receivedAt":"2013-01-31T02:01:06Z","isPatch":true,"sender":{"key":"bebarino@gmail.com","avatar":"https://avatars.githubusercontent.com/u/38832?v=4"},"body":"Mark these strings for translation so that error messages are\nprinted in the user's language of choice.\n\nSigned-off-by: Stephen Boyd <sboyd@codeaurora.org>\n---\n gpg-interface.c | 6 +++---\n 1 file changed, 3 insertions(+), 3 deletions(-)\n\ndiff --git a/gpg-interface.c b/gpg-interface.c\nindex 2c0bed3..474c037 100644\n--- a/gpg-interface.c\n+++ b/gpg-interface.c\n@@ -109,10 +109,10 @@ int verify_signed_buffer(const char *payload, size_t payload_size,\n \targs_gpg[0] = gpg_program;\n \tfd = git_mkstemp(path, PATH_MAX, \".git_vtag_tmpXXXXXX\");\n \tif (fd < 0)\n-\t\treturn error(\"could not create temporary file '%s': %s\",\n+\t\treturn error(_(\"could not create temporary file '%s': %s\"),\n \t\t\t     path, strerror(errno));\n \tif (write_in_full(fd, signature, signature_size) < 0)\n-\t\treturn error(\"failed writing detached signature to '%s': %s\",\n+\t\treturn error(_(\"failed writing detached signature to '%s': %s\"),\n \t\t\t     path, strerror(errno));\n \tclose(fd);\n \n@@ -124,7 +124,7 @@ int verify_signed_buffer(const char *payload, size_t payload_size,\n \targs_gpg[2] = path;\n \tif (start_command(&gpg)) {\n \t\tunlink(path);\n-\t\treturn error(\"could not run gpg.\");\n+\t\treturn error(_(\"could not run gpg.\"));\n \t}\n \n \twrite_in_full(gpg.in, payload, payload_size);\n-- \nThe Qualcomm Innovation Center, Inc. is a member of the Code Aurora Forum,\nhosted by The Linux Foundation\n"},{"id":"208332","messageId":"20130131055053.GA11912@sigill.intra.peff.net","threadId":"32787","inReplyTo":"1359597666-10108-2-git-send-email-sboyd@codeaurora.org","subject":"Re: [PATCH 1/3] gpg: Close stderr once finished with it in verify_signed_buffer()","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2013-01-31T05:50:53Z","receivedAt":"2013-01-31T05:50:53Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Wed, Jan 30, 2013 at 06:01:04PM -0800, Stephen Boyd wrote:\n\n> Failing to close the stderr pipe in verify_signed_buffer() causes\n> git to run out of file descriptors if there are many calls to\n> verify_signed_buffer(). An easy way to trigger this is to run\n> \n>  git log --show-signature --merges | grep \"key\"\n> \n> on the linux kernel git repo. Eventually it will fail with\n> \n>  error: cannot create pipe for gpg: Too many open files\n>  error: could not run gpg.\n> \n> Close the stderr pipe so that this can't happen.\n\nI was able to easily reproduce the bug and verify your fix here.\n\n> diff --git a/gpg-interface.c b/gpg-interface.c\n> index 0863c61..2c0bed3 100644\n> --- a/gpg-interface.c\n> +++ b/gpg-interface.c\n> @@ -133,6 +133,8 @@ int verify_signed_buffer(const char *payload, size_t payload_size,\n>  \tif (gpg_output)\n>  \t\tstrbuf_read(gpg_output, gpg.err, 0);\n>  \tret = finish_command(&gpg);\n> +\tif (gpg_output)\n> +\t\tclose(gpg.err);\n\nThe strbuf_read above will read to EOF, so it should be equivalent (and\nIMHO slightly more readable) to do:\n\ndiff --git a/gpg-interface.c b/gpg-interface.c\nindex 0863c61..5f142f6 100644\n--- a/gpg-interface.c\n+++ b/gpg-interface.c\n@@ -130,8 +130,10 @@ int verify_signed_buffer(const char *payload, size_t payload_size,\n \twrite_in_full(gpg.in, payload, payload_size);\n \tclose(gpg.in);\n \n-\tif (gpg_output)\n+\tif (gpg_output) {\n \t\tstrbuf_read(gpg_output, gpg.err, 0);\n+\t\tclose(gpg.err);\n+\t}\n \tret = finish_command(&gpg);\n \n \tunlink_or_warn(path);\n\nBut that is a minor nit; either way, the patch looks good to me.\n\n-Peff\n"},{"id":"208362","messageId":"7vfw1hiami.fsf@alter.siamese.dyndns.org","threadId":"32787","inReplyTo":"1359597666-10108-3-git-send-email-sboyd@codeaurora.org","subject":"Re: [PATCH 2/3] run-command: Be more informative about what failed","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2013-01-31T16:24:21Z","receivedAt":"2013-01-31T16:24:21Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Stephen Boyd <sboyd@codeaurora.org> writes:\n\n> While debugging an error with verify_signed_buffer() the error\n> messages from run-command weren't very useful:\n>\n>  error: cannot create pipe for gpg: Too many open files\n>  error: could not run gpg.\n>\n> because they didn't indicate *which* pipe couldn't be created.\n\nFor the message emitted here with your update (or without for that\nmatter) to be useful, it has to hold that there is a single leaker,\nthat leaker fails in this codepath, and that there is nobody else\ninvolved.  Otherwise, you may be able to tell that one caller could\nnot create its stdin, but the reason it couldn't may be because\nsomebody else consumed all the available file descriptors.\n\nI am not opposed to this change per-se, but I am not sure that\nsaying \"stdin\" etc. makes the message more useful for the purpose of\ndebugging.\n\n> For example, the above error now prints:\n>\n>  error: cannot create stderr pipe for gpg: Too many open files\n>  error: could not run gpg.\n\nI'd prefer to see these names spelled out (e.g. \"standard error\")\nin any case.\n\nThanks.\n\n> Signed-off-by: Stephen Boyd <sboyd@codeaurora.org>\n> ---\n\n>  run-command.c | 8 ++++++--\n>  1 file changed, 6 insertions(+), 2 deletions(-)\n>\n> diff --git a/run-command.c b/run-command.c\n> index 12d4ddb..016dd05 100644\n> --- a/run-command.c\n> +++ b/run-command.c\n> @@ -274,6 +274,7 @@ int start_command(struct child_process *cmd)\n>  \tint need_in, need_out, need_err;\n>  \tint fdin[2], fdout[2], fderr[2];\n>  \tint failed_errno = failed_errno;\n> +\tchar *str;\n>  \n>  \t/*\n>  \t * In case of errors we must keep the promise to close FDs\n> @@ -286,6 +287,7 @@ int start_command(struct child_process *cmd)\n>  \t\t\tfailed_errno = errno;\n>  \t\t\tif (cmd->out > 0)\n>  \t\t\t\tclose(cmd->out);\n> +\t\t\tstr = \"stdin\";\n>  \t\t\tgoto fail_pipe;\n>  \t\t}\n>  \t\tcmd->in = fdin[1];\n> @@ -301,6 +303,7 @@ int start_command(struct child_process *cmd)\n>  \t\t\t\tclose_pair(fdin);\n>  \t\t\telse if (cmd->in)\n>  \t\t\t\tclose(cmd->in);\n> +\t\t\tstr = \"stdout\";\n>  \t\t\tgoto fail_pipe;\n>  \t\t}\n>  \t\tcmd->out = fdout[0];\n> @@ -318,9 +321,10 @@ int start_command(struct child_process *cmd)\n>  \t\t\t\tclose_pair(fdout);\n>  \t\t\telse if (cmd->out)\n>  \t\t\t\tclose(cmd->out);\n> +\t\t\tstr = \"stderr\";\n>  fail_pipe:\n> -\t\t\terror(\"cannot create pipe for %s: %s\",\n> -\t\t\t\tcmd->argv[0], strerror(failed_errno));\n> +\t\t\terror(\"cannot create %s pipe for %s: %s\",\n> +\t\t\t\tstr, cmd->argv[0], strerror(failed_errno));\n>  \t\t\terrno = failed_errno;\n>  \t\t\treturn -1;\n>  \t\t}\n"},{"id":"208374","messageId":"510AB255.40302@codeaurora.org","threadId":"32787","inReplyTo":"7vfw1hiami.fsf@alter.siamese.dyndns.org","subject":"Re: [PATCH 2/3] run-command: Be more informative about what failed","fromName":"Stephen Boyd","fromEmail":"sboyd@codeaurora.org","sentAt":"2013-01-31T18:05:09Z","receivedAt":"2013-01-31T18:05:09Z","isPatch":true,"sender":{"key":"bebarino@gmail.com","avatar":"https://avatars.githubusercontent.com/u/38832?v=4"},"body":"On 01/31/13 08:24, Junio C Hamano wrote:\n> Stephen Boyd <sboyd@codeaurora.org> writes:\n>\n>> While debugging an error with verify_signed_buffer() the error\n>> messages from run-command weren't very useful:\n>>\n>>  error: cannot create pipe for gpg: Too many open files\n>>  error: could not run gpg.\n>>\n>> because they didn't indicate *which* pipe couldn't be created.\n> For the message emitted here with your update (or without for that\n> matter) to be useful, it has to hold that there is a single leaker,\n> that leaker fails in this codepath, and that there is nobody else\n> involved.  Otherwise, you may be able to tell that one caller could\n> not create its stdin, but the reason it couldn't may be because\n> somebody else consumed all the available file descriptors.\n>\n> I am not opposed to this change per-se, but I am not sure that\n> saying \"stdin\" etc. makes the message more useful for the purpose of\n> debugging.\n\nIt helped me avoid firing up gdb, but if you don't see much use feel\nfree to ignore this patch.\n\n>\n>> For example, the above error now prints:\n>>\n>>  error: cannot create stderr pipe for gpg: Too many open files\n>>  error: could not run gpg.\n> I'd prefer to see these names spelled out (e.g. \"standard error\")\n> in any case.\n\nSure, I can do that.\n\n-- \nQualcomm Innovation Center, Inc. is a member of Code Aurora Forum,\nhosted by The Linux Foundation\n"},{"id":"208375","messageId":"510AB2AA.4000400@codeaurora.org","threadId":"32787","inReplyTo":"20130131055053.GA11912@sigill.intra.peff.net","subject":"Re: [PATCH 1/3] gpg: Close stderr once finished with it in verify_signed_buffer()","fromName":"Stephen Boyd","fromEmail":"sboyd@codeaurora.org","sentAt":"2013-01-31T18:06:34Z","receivedAt":"2013-01-31T18:06:34Z","isPatch":true,"sender":{"key":"bebarino@gmail.com","avatar":"https://avatars.githubusercontent.com/u/38832?v=4"},"body":"On 01/30/13 21:50, Jeff King wrote:\n>\n> The strbuf_read above will read to EOF, so it should be equivalent (and\n> IMHO slightly more readable) to do:\n>\n> diff --git a/gpg-interface.c b/gpg-interface.c\n> index 0863c61..5f142f6 100644\n> --- a/gpg-interface.c\n> +++ b/gpg-interface.c\n> @@ -130,8 +130,10 @@ int verify_signed_buffer(const char *payload, size_t payload_size,\n>  \twrite_in_full(gpg.in, payload, payload_size);\n>  \tclose(gpg.in);\n>  \n> -\tif (gpg_output)\n> +\tif (gpg_output) {\n>  \t\tstrbuf_read(gpg_output, gpg.err, 0);\n> +\t\tclose(gpg.err);\n> +\t}\n>  \tret = finish_command(&gpg);\n>  \n>  \tunlink_or_warn(path);\n>\n> But that is a minor nit; either way, the patch looks good to me.\n\nLooks better. I'll resend with this.\n\n-- \nQualcomm Innovation Center, Inc. is a member of Code Aurora Forum,\nhosted by The Linux Foundation\n"},{"id":"208378","messageId":"1359656320-4434-1-git-send-email-sboyd@codeaurora.org","threadId":"32787","inReplyTo":"20130131055053.GA11912@sigill.intra.peff.net","subject":"[PATCHv2 1/3] gpg: Close stderr once finished with it in verify_signed_buffer()","fromName":"Stephen Boyd","fromEmail":"sboyd@codeaurora.org","sentAt":"2013-01-31T18:18:40Z","receivedAt":"2013-01-31T18:18:40Z","isPatch":false,"sender":{"key":"bebarino@gmail.com","avatar":"https://avatars.githubusercontent.com/u/38832?v=4"},"body":"Failing to close the stderr pipe in verify_signed_buffer() causes\ngit to run out of file descriptors if there are many calls to\nverify_signed_buffer(). An easy way to trigger this is to run\n\n git log --show-signature --merges | grep \"key\"\n\non the linux kernel git repo. Eventually it will fail with\n\n error: cannot create pipe for gpg: Too many open files\n error: could not run gpg.\n\nClose the stderr pipe so that this can't happen.\n\nSuggested-by: Jeff King <peff@peff.net>\nSigned-off-by: Stephen Boyd <sboyd@codeaurora.org>\n---\n gpg-interface.c | 4 +++-\n 1 file changed, 3 insertions(+), 1 deletion(-)\n\ndiff --git a/gpg-interface.c b/gpg-interface.c\nindex 0863c61..5f142f6 100644\n--- a/gpg-interface.c\n+++ b/gpg-interface.c\n@@ -130,8 +130,10 @@ int verify_signed_buffer(const char *payload, size_t payload_size,\n \twrite_in_full(gpg.in, payload, payload_size);\n \tclose(gpg.in);\n \n-\tif (gpg_output)\n+\tif (gpg_output) {\n \t\tstrbuf_read(gpg_output, gpg.err, 0);\n+\t\tclose(gpg.err);\n+\t}\n \tret = finish_command(&gpg);\n \n \tunlink_or_warn(path);\n-- \nThe Qualcomm Innovation Center, Inc. is a member of the Code Aurora Forum,\nhosted by The Linux Foundation\n"},{"id":"208379","messageId":"20130131182052.GA27340@google.com","threadId":"32787","inReplyTo":"1359597666-10108-4-git-send-email-sboyd@codeaurora.org","subject":"Re: [PATCH 3/3] gpg: Allow translation of more error messages","fromName":"Jonathan Nieder","fromEmail":"jrnieder@gmail.com","sentAt":"2013-01-31T18:20:52Z","receivedAt":"2013-01-31T18:20:52Z","isPatch":true,"sender":{"key":"jrnieder@gmail.com","avatar":"https://avatars.githubusercontent.com/u/281595?v=4"},"body":"Stephen Boyd wrote:\n\n> Mark these strings for translation so that error messages are\n> printed in the user's language of choice.\n\nYeah.  Other error messages in this file are already translated, so\nit's oddly inconsistent.\n\nAssuming this passes tests with GETTEXT_POISON=YesPlease,\nReviewed-by: Jonathan Nieder <jrnieder@gmail.com>\n"},{"id":"208418","messageId":"20130131223559.GC21729@sigill.intra.peff.net","threadId":"32787","inReplyTo":"7vfw1hiami.fsf@alter.siamese.dyndns.org","subject":"Re: [PATCH 2/3] run-command: Be more informative about what failed","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2013-01-31T22:35:59Z","receivedAt":"2013-01-31T22:35:59Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Thu, Jan 31, 2013 at 08:24:21AM -0800, Junio C Hamano wrote:\n\n> Stephen Boyd <sboyd@codeaurora.org> writes:\n> \n> > While debugging an error with verify_signed_buffer() the error\n> > messages from run-command weren't very useful:\n> >\n> >  error: cannot create pipe for gpg: Too many open files\n> >  error: could not run gpg.\n> >\n> > because they didn't indicate *which* pipe couldn't be created.\n> \n> For the message emitted here with your update (or without for that\n> matter) to be useful, it has to hold that there is a single leaker,\n> that leaker fails in this codepath, and that there is nobody else\n> involved.  Otherwise, you may be able to tell that one caller could\n> not create its stdin, but the reason it couldn't may be because\n> somebody else consumed all the available file descriptors.\n> \n> I am not opposed to this change per-se, but I am not sure that\n> saying \"stdin\" etc. makes the message more useful for the purpose of\n> debugging.\n\nYeah, I had the same feeling. All that failed is pipe(), which does not\nhave anything to do with what we are going to use the pipe for. So it\ngives some context, perhaps, but does not necessarily tell us anything\nuseful.\n\nBut it is not much code, and sometimes it is surprising what information\ncan be helpful when debugging, so like you, I am not opposed, just\ndoubtful.\n\n-Peff\n"},{"id":"208420","messageId":"20130131223710.GD21729@sigill.intra.peff.net","threadId":"32787","inReplyTo":"1359656320-4434-1-git-send-email-sboyd@codeaurora.org","subject":"Re: [PATCHv2 1/3] gpg: Close stderr once finished with it in verify_signed_buffer()","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2013-01-31T22:37:10Z","receivedAt":"2013-01-31T22:37:10Z","isPatch":false,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Thu, Jan 31, 2013 at 10:18:40AM -0800, Stephen Boyd wrote:\n\n> Failing to close the stderr pipe in verify_signed_buffer() causes\n> git to run out of file descriptors if there are many calls to\n> verify_signed_buffer(). An easy way to trigger this is to run\n> \n>  git log --show-signature --merges | grep \"key\"\n> \n> on the linux kernel git repo. Eventually it will fail with\n> \n>  error: cannot create pipe for gpg: Too many open files\n>  error: could not run gpg.\n> \n> Close the stderr pipe so that this can't happen.\n> \n> Suggested-by: Jeff King <peff@peff.net>\n> Signed-off-by: Stephen Boyd <sboyd@codeaurora.org>\n\nThanks, looks good to me (obviously :) ). The rest of the series looks\nfine, too, with the caveat I mentioned on 2/3. Thanks for fixing this.\n\n-Peff\n"},{"id":"208429","messageId":"7v8v78ewhx.fsf@alter.siamese.dyndns.org","threadId":"32787","inReplyTo":"20130131223559.GC21729@sigill.intra.peff.net","subject":"Re: [PATCH 2/3] run-command: Be more informative about what failed","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2013-01-31T23:57:46Z","receivedAt":"2013-01-31T23:57:46Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Jeff King <peff@peff.net> writes:\n\n> But it is not much code, and sometimes it is surprising what information\n> can be helpful when debugging, so like you, I am not opposed, just\n> doubtful.\n\nYes, exactly my feeling.\n\nPerhaps I should just amend the 'stdin' and friends away without\nasking Stephen to reroll.  In the other two I did not see any\nissues.  I've queued all three of them including this one but as\nseparate topics.\n\nThanks.\n"}]}