{"thread":{"id":"38758","subject":"[PATCH] t7510: do not fail when gpg warns about insecure memory","startedAt":"2015-03-08T15:40:50Z","lastAt":"2015-03-10T09:10:13Z","messageCount":9,"participants":["Kyle J. McKay","Eric Sunshine","brian m. carlson","Michael J Gruber"],"isPatch":true,"patchVersion":1,"patchTotal":null},"messages":[{"id":"257329","messageId":"2652cb72a82d4ca4be3ea90bafd263e@74d39fa044aa309eaea14b9f57fe79c","threadId":"38758","inReplyTo":null,"subject":"[PATCH] t7510: do not fail when gpg warns about insecure memory","fromName":"Kyle J. McKay","fromEmail":"mackyle@gmail.com","sentAt":"2015-03-08T15:40:50Z","receivedAt":"2015-03-08T15:40:50Z","isPatch":true,"sender":{"key":"mackyle@gmail.com","avatar":"https://avatars.githubusercontent.com/u/813346?v=4"},"body":"Depending on how gpg was built, it may issue the following\nmessage to stderr when run:\n\n  Warning: using insecure memory!\n\nUnfortunately when running the test, that message gets\ncollected in the stdout result of git show -s --show-signature\nbut is collected in the stderr result of git verify-commit -v\ncausing both the stdout and stderr result comparisions to fail.\n\nSince checking for secure memory use by gpg is not the point of\nthis test, filter out such messages to allow the test to pass\neven when gpg is \"using insecure memory\".\n\nSigned-off-by: Kyle J. McKay <mackyle@gmail.com>\n---\n t/t7510-signed-commit.sh | 5 +++--\n 1 file changed, 3 insertions(+), 2 deletions(-)\n\ndiff --git a/t/t7510-signed-commit.sh b/t/t7510-signed-commit.sh\nindex 474dab38..e86923bc 100755\n--- a/t/t7510-signed-commit.sh\n+++ b/t/t7510-signed-commit.sh\n@@ -84,9 +84,10 @@ test_expect_success GPG 'verify and show signatures' '\n test_expect_success GPG 'show signed commit with signature' '\n \tgit show -s initial >commit &&\n \tgit show -s --show-signature initial >show &&\n-\tgit verify-commit -v initial >verify.1 2>verify.2 &&\n+\tgit verify-commit -v initial >verify.1 2>verify.2.out &&\n \tgit cat-file commit initial >cat &&\n-\tgrep -v \"gpg: \" show >show.commit &&\n+\tgrep -v -e \"gpg: \" -e \"insecure memory\" show >show.commit &&\n+\tgrep -v \"insecure memory\" verify.2.out >verify.2 &&\n \tgrep \"gpg: \" show >show.gpg &&\n \tgrep -v \"^ \" cat | grep -v \"^gpgsig \" >cat.commit &&\n \ttest_cmp show.commit commit &&\n---\n"},{"id":"257344","messageId":"CAPig+cQXJgZJAoyQVYg3CNNzd70eA=ttdL7=g6wabtBkWBijeQ@mail.gmail.com","threadId":"38758","inReplyTo":"2652cb72a82d4ca4be3ea90bafd263e@74d39fa044aa309eaea14b9f57fe79c","subject":"Re: [PATCH] t7510: do not fail when gpg warns about insecure memory","fromName":"Eric Sunshine","fromEmail":"sunshine@sunshineco.com","sentAt":"2015-03-08T21:43:41Z","receivedAt":"2015-03-08T21:43:41Z","isPatch":true,"sender":{"key":"sunshine@sunshineco.com","avatar":"https://avatars.githubusercontent.com/u/163641?v=4"},"body":"On Sun, Mar 8, 2015 at 11:40 AM, Kyle J. McKay <mackyle@gmail.com> wrote:\n> Depending on how gpg was built, it may issue the following\n> message to stderr when run:\n>\n>   Warning: using insecure memory!\n>\n> Unfortunately when running the test, that message gets\n> collected in the stdout result of git show -s --show-signature\n> but is collected in the stderr result of git verify-commit -v\n\nI'm having trouble parsing this. Is there a word missing?\n\n> causing both the stdout and stderr result comparisions to fail.\n\ns/comparisions/comparisons/\n\n> Since checking for secure memory use by gpg is not the point of\n> this test, filter out such messages to allow the test to pass\n> even when gpg is \"using insecure memory\".\n>\n> Signed-off-by: Kyle J. McKay <mackyle@gmail.com>\n"},{"id":"257347","messageId":"20150308220424.GD4245@vauxhall.crustytoothpaste.net","threadId":"38758","inReplyTo":"CAPig+cQXJgZJAoyQVYg3CNNzd70eA=ttdL7=g6wabtBkWBijeQ@mail.gmail.com","subject":"Re: [PATCH] t7510: do not fail when gpg warns about insecure memory","fromName":"brian m. carlson","fromEmail":"sandals@crustytoothpaste.net","sentAt":"2015-03-08T22:04:25Z","receivedAt":"2015-03-08T22:04:25Z","isPatch":true,"sender":{"key":"sandals@crustytoothpaste.net","avatar":"https://avatars.githubusercontent.com/u/497054?v=4"},"body":"On Sun, Mar 08, 2015 at 05:43:41PM -0400, Eric Sunshine wrote:\n>On Sun, Mar 8, 2015 at 11:40 AM, Kyle J. McKay <mackyle@gmail.com> wrote:\n>> Depending on how gpg was built, it may issue the following\n>> message to stderr when run:\n>>\n>>   Warning: using insecure memory!\n>>\n>> Unfortunately when running the test, that message gets\n>> collected in the stdout result of git show -s --show-signature\n>> but is collected in the stderr result of git verify-commit -v\n>\n>I'm having trouble parsing this. Is there a word missing?\n>\n>> causing both the stdout and stderr result comparisions to fail.\n\nPerhaps this is better?\n\n  Unfortunately when running the test, that message is found in the \n  standard output of git show -s --show-signature, but in the standard \n  error of git verify-commit -v causing the comparisons of both standard \n  output and standard error to fail.\n-- \nbrian m. carlson / brian with sandals: Houston, Texas, US\n+1 832 623 2791 | http://www.crustytoothpaste.net/~bmc | My opinion only\nOpenPGP: RSA v4 4096b: 88AC E9B2 9196 305B A994 7552 F1BA 225C 0223 B187\n"},{"id":"257348","messageId":"CAPig+cTj_z0xpDmnSvb-S_wEbwzdcFsGwUkFdGWgcJhwZpfMFQ@mail.gmail.com","threadId":"38758","inReplyTo":"20150308220424.GD4245@vauxhall.crustytoothpaste.net","subject":"Re: [PATCH] t7510: do not fail when gpg warns about insecure memory","fromName":"Eric Sunshine","fromEmail":"sunshine@sunshineco.com","sentAt":"2015-03-08T22:15:55Z","receivedAt":"2015-03-08T22:15:55Z","isPatch":true,"sender":{"key":"sunshine@sunshineco.com","avatar":"https://avatars.githubusercontent.com/u/163641?v=4"},"body":"On Sun, Mar 8, 2015 at 6:04 PM, brian m. carlson\n<sandals@crustytoothpaste.net> wrote:\n> On Sun, Mar 08, 2015 at 05:43:41PM -0400, Eric Sunshine wrote:\n>> On Sun, Mar 8, 2015 at 11:40 AM, Kyle J. McKay <mackyle@gmail.com> wrote:\n>>>   Warning: using insecure memory!\n>>>\n>>> Unfortunately when running the test, that message gets\n>>> collected in the stdout result of git show -s --show-signature\n>>> but is collected in the stderr result of git verify-commit -v\n>>\n>> I'm having trouble parsing this. Is there a word missing?\n> Perhaps this is better?\n>\n>  Unfortunately when running the test, that message is found in the  standard\n> output of git show -s --show-signature, but in the standard  error of git\n> verify-commit -v causing the comparisons of both standard  output and\n> standard error to fail.\n\nThat doesn't help me parse it any better.  It's the \"but\" without a\ncorresponding \"not\" which seems to be throwing me off. Typically, one\nwould write \"this but not that\" or \"not this but that\". I can't tell\nif there is a \"not\" missing or if the \"but\" is supposed to be an \"and\"\nor if something else was intended.\n"},{"id":"257356","messageId":"20150309012214.GE4245@vauxhall.crustytoothpaste.net","threadId":"38758","inReplyTo":"CAPig+cTj_z0xpDmnSvb-S_wEbwzdcFsGwUkFdGWgcJhwZpfMFQ@mail.gmail.com","subject":"Re: [PATCH] t7510: do not fail when gpg warns about insecure memory","fromName":"brian m. carlson","fromEmail":"sandals@crustytoothpaste.net","sentAt":"2015-03-09T01:22:14Z","receivedAt":"2015-03-09T01:22:14Z","isPatch":true,"sender":{"key":"sandals@crustytoothpaste.net","avatar":"https://avatars.githubusercontent.com/u/497054?v=4"},"body":"On Sun, Mar 08, 2015 at 06:15:55PM -0400, Eric Sunshine wrote:\n>On Sun, Mar 8, 2015 at 6:04 PM, brian m. carlson\n><sandals@crustytoothpaste.net> wrote:\n>> Perhaps this is better?\n>>\n>>  Unfortunately when running the test, that message is found in the  standard\n>> output of git show -s --show-signature, but in the standard  error of git\n>> verify-commit -v causing the comparisons of both standard  output and\n>> standard error to fail.\n>\n>That doesn't help me parse it any better.  It's the \"but\" without a\n>corresponding \"not\" which seems to be throwing me off. Typically, one\n>would write \"this but not that\" or \"not this but that\". I can't tell\n>if there is a \"not\" missing or if the \"but\" is supposed to be an \"and\"\n>or if something else was intended.\n\nThe intended meaning is \"and\" with the additional sense of contrast. \nThe sentence, if read with verbal emphasis, is, \"…is found in the \nstandard *output* of git show -s --signature, but in the standard \n*error* of git verify-commit -v\", thus demonstrating why the test fails: \nthe pairs of output files don't match up.\n\nMaybe you can suggest a less confusing wording.\n-- \nbrian m. carlson / brian with sandals: Houston, Texas, US\n+1 832 623 2791 | http://www.crustytoothpaste.net/~bmc | My opinion only\nOpenPGP: RSA v4 4096b: 88AC E9B2 9196 305B A994 7552 F1BA 225C 0223 B187\n"},{"id":"257360","messageId":"E72F95BF-BE00-433E-9D05-0DDF1CACCCC1@gmail.com","threadId":"38758","inReplyTo":"20150309012214.GE4245@vauxhall.crustytoothpaste.net","subject":"Re: [PATCH] t7510: do not fail when gpg warns about insecure memory","fromName":"Kyle J. McKay","fromEmail":"mackyle@gmail.com","sentAt":"2015-03-09T05:32:34Z","receivedAt":"2015-03-09T05:32:34Z","isPatch":true,"sender":{"key":"mackyle@gmail.com","avatar":"https://avatars.githubusercontent.com/u/813346?v=4"},"body":"On Mar 8, 2015, at 18:22, brian m. carlson wrote:\n\n> On Sun, Mar 08, 2015 at 06:15:55PM -0400, Eric Sunshine wrote:\n>> On Sun, Mar 8, 2015 at 6:04 PM, brian m. carlson\n>> <sandals@crustytoothpaste.net> wrote:\n>>> Perhaps this is better?\n>>>\n>>> Unfortunately when running the test, that message is found in the   \n>>> standard\n>>> output of git show -s --show-signature, but in the standard  error  \n>>> of git\n>>> verify-commit -v causing the comparisons of both standard  output  \n>>> and\n>>> standard error to fail.\n>>\n>> That doesn't help me parse it any better.  It's the \"but\" without a\n>> corresponding \"not\" which seems to be throwing me off. Typically, one\n>> would write \"this but not that\" or \"not this but that\". I can't tell\n>> if there is a \"not\" missing or if the \"but\" is supposed to be an  \n>> \"and\"\n>> or if something else was intended.\n>\n> The intended meaning is \"and\" with the additional sense of contrast.  \n> The sentence, if read with verbal emphasis, is, \"…is found in the  \n> standard *output* of git show -s --signature, but in the standard  \n> *error* of git verify-commit -v\", thus demonstrating why the test  \n> fails: the pairs of output files don't match up.\n>\n> Maybe you can suggest a less confusing wording.\n\nI like Brian's wording, but how about this slight variation, does this  \nparse any better for you?\n\nUnfortunately when running the test, while that message is found in\nthe standard output of git show -s --show-signature, it is found in\nthe standard error of git verify-commit -v causing the comparisons\nof both standard output and standard error to fail.\n\n-Kyle\n"},{"id":"257374","messageId":"54FD6C22.4020808@drmicha.warpmail.net","threadId":"38758","inReplyTo":"E72F95BF-BE00-433E-9D05-0DDF1CACCCC1@gmail.com","subject":"Re: [PATCH] t7510: do not fail when gpg warns about insecure memory","fromName":"Michael J Gruber","fromEmail":"git@drmicha.warpmail.net","sentAt":"2015-03-09T09:47:14Z","receivedAt":"2015-03-09T09:47:14Z","isPatch":true,"sender":{"key":"git@grubix.eu","avatar":"https://avatars.githubusercontent.com/u/233215?v=4"},"body":"Kyle J. McKay venit, vidit, dixit 09.03.2015 06:32:\n> On Mar 8, 2015, at 18:22, brian m. carlson wrote:\n> \n>> On Sun, Mar 08, 2015 at 06:15:55PM -0400, Eric Sunshine wrote:\n>>> On Sun, Mar 8, 2015 at 6:04 PM, brian m. carlson\n>>> <sandals@crustytoothpaste.net> wrote:\n>>>> Perhaps this is better?\n>>>>\n>>>> Unfortunately when running the test, that message is found in the   \n>>>> standard\n>>>> output of git show -s --show-signature, but in the standard  error  \n>>>> of git\n>>>> verify-commit -v causing the comparisons of both standard  output  \n>>>> and\n>>>> standard error to fail.\n>>>\n>>> That doesn't help me parse it any better.  It's the \"but\" without a\n>>> corresponding \"not\" which seems to be throwing me off. Typically, one\n>>> would write \"this but not that\" or \"not this but that\". I can't tell\n>>> if there is a \"not\" missing or if the \"but\" is supposed to be an  \n>>> \"and\"\n>>> or if something else was intended.\n>>\n>> The intended meaning is \"and\" with the additional sense of contrast.  \n>> The sentence, if read with verbal emphasis, is, \"…is found in the  \n>> standard *output* of git show -s --signature, but in the standard  \n>> *error* of git verify-commit -v\", thus demonstrating why the test  \n>> fails: the pairs of output files don't match up.\n>>\n>> Maybe you can suggest a less confusing wording.\n> \n> I like Brian's wording, but how about this slight variation, does this  \n> parse any better for you?\n> \n> Unfortunately when running the test, while that message is found in\n> the standard output of git show -s --show-signature, it is found in\n> the standard error of git verify-commit -v causing the comparisons\n> of both standard output and standard error to fail.\n> \n> -Kyle\n> \n\nThat still makes it sound as if we'd rather fix \"git show\" than adjust\nthe test to such surprising behavior.\n\nBut in fact, \"git verify-commit\" uses stdout and stderr to separate its\noutput appropriately, whereas \"git show\" lumps everything together on\nstdout, so that the test has to split it up again.\n\nNow, if I read it correctly, the patch suggests ignoring the insecure\nmemory warning from both outputs rather than putting it on the correct\nside of the split.\n\nI'd rather put it on the correct side (or silence gpg by setting its\nconfig).\n\nMichael\n"},{"id":"257425","messageId":"b822f2716d8bdfcb6576ad0dc502af5@74d39fa044aa309eaea14b9f57fe79c","threadId":"38758","inReplyTo":"54FD6C22.4020808@drmicha.warpmail.net","subject":"[PATCH v2] t7510: do not fail when gpg warns about insecure memory","fromName":"Kyle J. McKay","fromEmail":"mackyle@gmail.com","sentAt":"2015-03-09T20:03:01Z","receivedAt":"2015-03-09T20:03:01Z","isPatch":true,"sender":{"key":"mackyle@gmail.com","avatar":"https://avatars.githubusercontent.com/u/813346?v=4"},"body":"Depending on how gpg was built, it may issue the following\nmessage to stderr when run:\n\n  Warning: using insecure memory!\n\nWhen the test is collecting gpg output it is therefore not\nenough to just match on a \"gpg: \" prefix it must also match\non a \"Warning: \" prefix wherever it needs to match lines\nthat have been produced by gpg.\n\nSigned-off-by: Kyle J. McKay <mackyle@gmail.com>\n---\n\nHow about this patch instead.  It just treats \"Warning:\" lines as gpg  \noutput and the test still passes when \"Warning: using insecure memory\"  \nshows up.\n\n-Kyle\n\n t/t7510-signed-commit.sh | 4 ++--\n 1 file changed, 2 insertions(+), 2 deletions(-)\n\ndiff --git a/t/t7510-signed-commit.sh b/t/t7510-signed-commit.sh\nindex 474dab38..3cef18cf 100755\n--- a/t/t7510-signed-commit.sh\n+++ b/t/t7510-signed-commit.sh\n@@ -86,8 +86,8 @@ test_expect_success GPG 'show signed commit with signature' '\n \tgit show -s --show-signature initial >show &&\n \tgit verify-commit -v initial >verify.1 2>verify.2 &&\n \tgit cat-file commit initial >cat &&\n-\tgrep -v \"gpg: \" show >show.commit &&\n-\tgrep \"gpg: \" show >show.gpg &&\n+\tgrep -v -e \"gpg: \" -e \"Warning: \" show >show.commit &&\n+\tgrep -e \"gpg: \" -e \"Warning: \" show >show.gpg &&\n \tgrep -v \"^ \" cat | grep -v \"^gpgsig \" >cat.commit &&\n \ttest_cmp show.commit commit &&\n \ttest_cmp show.gpg verify.2 &&\n---\n"},{"id":"257454","messageId":"54FEB4F5.4060602@drmicha.warpmail.net","threadId":"38758","inReplyTo":"b822f2716d8bdfcb6576ad0dc502af5@74d39fa044aa309eaea14b9f57fe79c","subject":"Re: [PATCH v2] t7510: do not fail when gpg warns about insecure memory","fromName":"Michael J Gruber","fromEmail":"git@drmicha.warpmail.net","sentAt":"2015-03-10T09:10:13Z","receivedAt":"2015-03-10T09:10:13Z","isPatch":true,"sender":{"key":"git@grubix.eu","avatar":"https://avatars.githubusercontent.com/u/233215?v=4"},"body":"Kyle J. McKay venit, vidit, dixit 09.03.2015 21:03:\n> Depending on how gpg was built, it may issue the following\n> message to stderr when run:\n> \n>   Warning: using insecure memory!\n> \n> When the test is collecting gpg output it is therefore not\n> enough to just match on a \"gpg: \" prefix it must also match\n> on a \"Warning: \" prefix wherever it needs to match lines\n> that have been produced by gpg.\n> \n> Signed-off-by: Kyle J. McKay <mackyle@gmail.com>\n> ---\n> \n> How about this patch instead.  It just treats \"Warning:\" lines as gpg  \n> output\n\n(They are, but gpg fails tp prefix them.)\n\n> and the test still passes when \"Warning: using insecure memory\"  \n> shows up.\n> \n> -Kyle\n\nPerfect, thanks!\n\n>  t/t7510-signed-commit.sh | 4 ++--\n>  1 file changed, 2 insertions(+), 2 deletions(-)\n> \n> diff --git a/t/t7510-signed-commit.sh b/t/t7510-signed-commit.sh\n> index 474dab38..3cef18cf 100755\n> --- a/t/t7510-signed-commit.sh\n> +++ b/t/t7510-signed-commit.sh\n> @@ -86,8 +86,8 @@ test_expect_success GPG 'show signed commit with signature' '\n>  \tgit show -s --show-signature initial >show &&\n>  \tgit verify-commit -v initial >verify.1 2>verify.2 &&\n>  \tgit cat-file commit initial >cat &&\n> -\tgrep -v \"gpg: \" show >show.commit &&\n> -\tgrep \"gpg: \" show >show.gpg &&\n> +\tgrep -v -e \"gpg: \" -e \"Warning: \" show >show.commit &&\n> +\tgrep -e \"gpg: \" -e \"Warning: \" show >show.gpg &&\n>  \tgrep -v \"^ \" cat | grep -v \"^gpgsig \" >cat.commit &&\n>  \ttest_cmp show.commit commit &&\n>  \ttest_cmp show.gpg verify.2 &&\n> ---\n> \n"}]}