{"thread":{"id":"49754","subject":"[PATCH 1/2] t/t7510-signed-commit.sh: Add %GP to custom format checks","startedAt":"2018-11-04T09:47:26Z","lastAt":"2018-11-05T04:09:33Z","messageCount":6,"participants":["Michał Górny","brian m. carlson","Junio C Hamano"],"isPatch":true,"patchVersion":1,"patchTotal":2},"messages":[{"id":"362391","messageId":"20181104094710.27859-1-mgorny@gentoo.org","threadId":"49754","inReplyTo":null,"subject":"[PATCH 1/2] t/t7510-signed-commit.sh: Add %GP to custom format checks","fromName":"Michał Górny","fromEmail":"mgorny@gentoo.org","sentAt":"2018-11-04T09:47:09Z","receivedAt":"2018-11-04T09:47:26Z","isPatch":true,"sender":{"key":"mgorny@gentoo.org","avatar":"https://avatars.githubusercontent.com/u/110765?v=4"},"body":"Test %GP in addition to %GF in custom format checks.  With current\nkeyring, both have the same value.\n\nSigned-off-by: Michał Górny <mgorny@gentoo.org>\n---\n t/t7510-signed-commit.sh | 18 ++++++++++++------\n 1 file changed, 12 insertions(+), 6 deletions(-)\n\ndiff --git a/t/t7510-signed-commit.sh b/t/t7510-signed-commit.sh\nindex 19ccae286..e8377286d 100755\n--- a/t/t7510-signed-commit.sh\n+++ b/t/t7510-signed-commit.sh\n@@ -176,8 +176,9 @@ test_expect_success GPG 'show good signature with custom format' '\n \t13B6F51ECDDE430D\n \tC O Mitter <committer@example.com>\n \t73D758744BE721698EC54E8713B6F51ECDDE430D\n+\t73D758744BE721698EC54E8713B6F51ECDDE430D\n \tEOF\n-\tgit log -1 --format=\"%G?%n%GK%n%GS%n%GF\" sixth-signed >actual &&\n+\tgit log -1 --format=\"%G?%n%GK%n%GS%n%GF%n%GP\" sixth-signed >actual &&\n \ttest_cmp expect actual\n '\n \n@@ -187,8 +188,9 @@ test_expect_success GPG 'show bad signature with custom format' '\n \t13B6F51ECDDE430D\n \tC O Mitter <committer@example.com>\n \n+\n \tEOF\n-\tgit log -1 --format=\"%G?%n%GK%n%GS%n%GF\" $(cat forged1.commit) >actual &&\n+\tgit log -1 --format=\"%G?%n%GK%n%GS%n%GF%n%GP\" $(cat forged1.commit) >actual &&\n \ttest_cmp expect actual\n '\n \n@@ -198,8 +200,9 @@ test_expect_success GPG 'show untrusted signature with custom format' '\n \t61092E85B7227189\n \tEris Discordia <discord@example.net>\n \tD4BE22311AD3131E5EDA29A461092E85B7227189\n+\tD4BE22311AD3131E5EDA29A461092E85B7227189\n \tEOF\n-\tgit log -1 --format=\"%G?%n%GK%n%GS%n%GF\" eighth-signed-alt >actual &&\n+\tgit log -1 --format=\"%G?%n%GK%n%GS%n%GF%n%GP\" eighth-signed-alt >actual &&\n \ttest_cmp expect actual\n '\n \n@@ -209,8 +212,9 @@ test_expect_success GPG 'show unknown signature with custom format' '\n \t61092E85B7227189\n \n \n+\n \tEOF\n-\tGNUPGHOME=\"$GNUPGHOME_NOT_USED\" git log -1 --format=\"%G?%n%GK%n%GS%n%GF\" eighth-signed-alt >actual &&\n+\tGNUPGHOME=\"$GNUPGHOME_NOT_USED\" git log -1 --format=\"%G?%n%GK%n%GS%n%GF%n%GP\" eighth-signed-alt >actual &&\n \ttest_cmp expect actual\n '\n \n@@ -220,8 +224,9 @@ test_expect_success GPG 'show lack of signature with custom format' '\n \n \n \n+\n \tEOF\n-\tgit log -1 --format=\"%G?%n%GK%n%GS%n%GF\" seventh-unsigned >actual &&\n+\tgit log -1 --format=\"%G?%n%GK%n%GS%n%GF%n%GP\" seventh-unsigned >actual &&\n \ttest_cmp expect actual\n '\n \n@@ -261,8 +266,9 @@ test_expect_success GPG 'show double signature with custom format' '\n \n \n \n+\n \tEOF\n-\tgit log -1 --format=\"%G?%n%GK%n%GS%n%GF\" $(cat double-commit.commit) >actual &&\n+\tgit log -1 --format=\"%G?%n%GK%n%GS%n%GF%n%GP\" $(cat double-commit.commit) >actual &&\n \ttest_cmp expect actual\n '\n \n-- \n2.19.1\n\n"},{"id":"362392","messageId":"20181104094710.27859-2-mgorny@gentoo.org","threadId":"49754","inReplyTo":"20181104094710.27859-1-mgorny@gentoo.org","subject":"[PATCH 2/2] t/t7510-signed-commit.sh: add signing subkey to Eris Discordia key","fromName":"Michał Górny","fromEmail":"mgorny@gentoo.org","sentAt":"2018-11-04T09:47:10Z","receivedAt":"2018-11-04T09:48:08Z","isPatch":true,"sender":{"key":"mgorny@gentoo.org","avatar":"https://avatars.githubusercontent.com/u/110765?v=4"},"body":"Add a dedicated signing subkey to the key identified as 'Eris\nDiscordia', and update tests appropriately.  GnuPG will now sign commits\nusing the dedicated signing subkey, changing the value of %GK and %GF,\nand effectively creating a test case for %GF!=%GP.\n\nSigned-off-by: Michał Górny <mgorny@gentoo.org>\n---\n t/lib-gpg/keyring.gpg    | 62 ++++++++++++++++++++++++++++++++++++----\n t/t7510-signed-commit.sh |  6 ++--\n 2 files changed, 59 insertions(+), 9 deletions(-)\n\ndiff --git a/t/lib-gpg/keyring.gpg b/t/lib-gpg/keyring.gpg\nindex d4754a1f1..918dfce33 100644\n--- a/t/lib-gpg/keyring.gpg\n+++ b/t/lib-gpg/keyring.gpg\n@@ -30,7 +30,6 @@ Cezx4Q2khACcCs+/LtE8Lb9hC+2cvr3uH5p82AI=\n =aEiU\n -----END PGP PRIVATE KEY BLOCK-----\n -----BEGIN PGP PRIVATE KEY BLOCK-----\n-Version: GnuPG v1\n \n lQOYBFFMlkcBCADJi/xnAF8yI34PHilSCbM7VtOFO17oFMkpu4cgN2QpPuM5MVjy\n cvrzKSguZFvPCDLzeAFJW1uPxL4SHaHSkisCrFhijH7OJWcOPNPSFCwu+inAoAsv\n@@ -83,11 +82,43 @@ fn1sY/IG5atoKK+ypmV/TlBlMZqFQzuPIJQT8VLbmxtLlDhJG04LbI6c8axIZxOO\n ZKLy5nTTSy16ztqEeS7eifHLPZg1UFFyEEIQ1XW0CNDAeuWKh90ERjyl4Cg7PnWS\n Z9Ei+zj6JD5Pcdi3BJhQo9WOLOVEJ0NHmewTYqk9QVXH/0v1Hdl4LMJtgcbdbDWk\n 4UTkXbg9pn3umCgkNJ3Vs8fWnIWO9Izdr2/wrFY2JvUT7Yvl+wsNIWatvOEzGy7n\n-BOW78WUxzhu0YJTLKy+iKCjg5HS5dx6OC+e4aEEgfhNPCMkbvDsJjtQ=\n-=hieJ\n+BOW78WUxzhu0YJTLKy+iKCjg5HS5dx6OC+e4aEEgfhNPCMkbvDsJjtSdA5gEW967\n+3AEIAKjseT0sTQjyN39fOn0fzxWp89REMUUKgLigb01MKuuNI3cedBZsz3hpFOKV\n+cii5rldw8uf3yS3Okht2DfHPSD4NrGzLGEzSTpQ10S8N2q0DUYwyLU6C0U8HnMZm\n+/n+lCGBbUoxvnruohAvKAjpHO3rmJ8D4De9hlWg/fwdAxQQ0Sve0kN8Vwk2p1GuO\n+OWQKV1SU9c+kBiou7dewQmbilPRanKmP5ZSU4emhpTOMlJFXF+kmYSODQk1cMvWW\n+Ob3ttll2llX0Gul7Sjf+haq/FcRyRk7Tw5MHwZjr5aWiCny0/0+byvfF6SBIfzyE\n+qlyWURQ2gHZUqSiG3QPMZiYr04cAEQEAAQAH/Am4rv/oQF6wodgz5y4zc6JJiTDA\n+4+nKdIuR7OKqUxk1oo7eZjJML/xvMumygNyUvJ9nodl1SlMKilOhdAswfkKj9gJY\n+BdDJLm1OufhW3pJwy6ahbjeqEgwJFVENtSPF0zkuyED9kElrpbD2ZTGfzwdM0e9D\n+10ZDFWtODCw8rzOFcijujgI8oilLtxSNrkkTKW+25WJFRNPSHgIkMIm8UlPAG+rj\n+3Yj9UqodeXTSvXwG2zceOxjFJadV77sOFJDgwWslN6J8El4+GcgwFVepJxoZEj7e\n+cKkmVr0Dc9/Q04D5dWATc1FYcIhZbTu3oImCAh45ep4u9WYLUV5PGyeMviEEAMwo\n+mJbYBxWuPjpNa722HQcbvMUiZWWDwHfLCib/SaP0AgfDahid8/PcZwxOPHPByBrm\n+GDi0z7ibn/pgJr07kpp1Cic9ntfc2FvkI0QMzG0EuiekzQyPEnzjoDHF+V4nJIj2\n+GWVjLYYqlZWEmhsfKt1CnlPXBunKoDJ30ABPcHJ/BADT0WxAIVKF4lO2HlrDVP44\n+bufBEG9Ct7dl/G08Qve4Ag3VEZpT82vEFp0LzX0mTCDIUKJUYAYLxAIPhP7IvIfc\n+EZXrwyDUxU7YSgKTHMKo9nFC6fIc1GeGPRalIF1gmTY32qlYJC6y5BTDhZNV5ydG\n+u8QL2P/orP7XuRrJyeyK+QP/XTekr/DS6Jkct826MPA52ciIkWVgYLatH5fO4HCq\n+ssDU8vz7FbbvGs0G1Xn7GA4m9dNYVOZtKwX++3nf2IEOpgPiZVTn/nP2u3HutpJb\n+/HMLlcfZGiGdxS6n/vdz6wsEobJoi6STkHkA+VFNOSZmdsw6eKl3X911tpCTYfOG\n+2U47/IkCbAQYAQgAIBYhBNS+IjEa0xMeXtoppGEJLoW3InGJBQJb3rvcAhsCAUAJ\n+EGEJLoW3InGJwHQgBBkBCAAdFiEE+DZKWeB//p9NYwBaZaDuoC4wytcFAlveu9wA\n+CgkQZaDuoC4wytcD9gf/WigtHl7lFyl8RaE/uqROFEelZyM00v1h55fd/IGRG88E\n+tN0Lr4FaqBqPkMZjU/LN9UMBaTd+748vHlHaweZqljXJu99CO9Id7Y4w7WzF3C3Y\n+yQsGZ92EGxthsPK0+rhHV0MbaINupI1oO9gATFglSxq17o83FJatGRjaXCZau8jr\n+57/By1MGtjk+Iq1NkzGkrX778LdRQGLKDw2Qa7lsdHY8d3lUPAH8mbb97ELmIc9t\n+PG2aM7ATJL7nBmFuTHo6hmEcIw32Ei9KK1zxM0ZylEYkjBjHAlklWmKb9MiayMC5\n+uHW7Iyhjl+NbgbIEr2JTamW/9tL6UrIIxiDEdqaHNfCaB/9D+V31Upcohc9azwB4\n+AF8diQwt5nfiVpnVeF/W8+eS1By2W6QrwLNthNRabYFnuSf9USHAY6atDWe+egId\n+MLIv4ce0i3ykoczSu0oMoUCMxdl9kQrsNHZCqWX/OiDDLSb05u/P/3he900y6tSB\n+15MbIPA6i5Bw/693nHguqxS1ASbBB/LiIu3vCXdFEs9RMvIJ+qkP3xQA96oImQiK\n+R3U6OGv593eONKijUINNqHRq6+UxIyJ+OCAi+L2QTidAhJLRCp6EZD96u02cthYq\n+8KA8j1+rx9BcbeacVVHepeG1JsgxsXX8BTJ7ZuS5VVndZOjag8URW/9nJMf01w/h\n+el64\n+=Iv7W\n -----END PGP PRIVATE KEY BLOCK-----\n -----BEGIN PGP PUBLIC KEY BLOCK-----\n-Version: GnuPG v1\n \n mQGiBEZnyykRBACzCPjIpTYNL7Y2tQqlEGTTDlvZcWNLjF5f7ZzuyOqNOidLUgFD\n 36qch1LZLSZkShdR3Gae+bsolyjxrlFuFP0eXRPMtqK20aLw7WZvPFpEV1ThMne+\n@@ -137,6 +168,25 @@ bGPyBuWraCivsqZlf05QZTGahUM7jyCUE/FS25sbS5Q4SRtOC2yOnPGsSGcTjmSi\n 8uZ000stes7ahHku3onxyz2YNVBRchBCENV1tAjQwHrliofdBEY8peAoOz51kmfR\n Ivs4+iQ+T3HYtwSYUKPVjizlRCdDR5nsE2KpPUFVx/9L9R3ZeCzCbYHG3Ww1pOFE\n 5F24PaZ97pgoJDSd1bPH1pyFjvSM3a9v8KxWNib1E+2L5fsLDSFmrbzhMxsu5wTl\n-u/FlMc4btGCUyysvoigo4OR0uXcejgvnuGhBIH4TTwjJG7w7CY7U\n-=iYv/\n+u/FlMc4btGCUyysvoigo4OR0uXcejgvnuGhBIH4TTwjJG7w7CY7UuQENBFveu9wB\n+CACo7Hk9LE0I8jd/Xzp9H88VqfPURDFFCoC4oG9NTCrrjSN3HnQWbM94aRTilXIo\n+ua5XcPLn98ktzpIbdg3xz0g+DaxsyxhM0k6UNdEvDdqtA1GMMi1OgtFPB5zGZv5/\n+pQhgW1KMb567qIQLygI6Rzt65ifA+A3vYZVoP38HQMUENEr3tJDfFcJNqdRrjjlk\n+CldUlPXPpAYqLu3XsEJm4pT0Wpypj+WUlOHpoaUzjJSRVxfpJmEjg0JNXDL1ljm9\n+7bZZdpZV9Brpe0o3/oWqvxXEckZO08OTB8GY6+Wlogp8tP9Pm8r3xekgSH88hKpc\n+llEUNoB2VKkoht0DzGYmK9OHABEBAAGJAmwEGAEIACAWIQTUviIxGtMTHl7aKaRh\n+CS6FtyJxiQUCW9673AIbAgFACRBhCS6FtyJxicB0IAQZAQgAHRYhBPg2Slngf/6f\n+TWMAWmWg7qAuMMrXBQJb3rvcAAoJEGWg7qAuMMrXA/YH/1ooLR5e5RcpfEWhP7qk\n+ThRHpWcjNNL9YeeX3fyBkRvPBLTdC6+BWqgaj5DGY1PyzfVDAWk3fu+PLx5R2sHm\n+apY1ybvfQjvSHe2OMO1sxdwt2MkLBmfdhBsbYbDytPq4R1dDG2iDbqSNaDvYAExY\n+JUsate6PNxSWrRkY2lwmWrvI6+e/wctTBrY5PiKtTZMxpK1++/C3UUBiyg8NkGu5\n+bHR2PHd5VDwB/Jm2/exC5iHPbTxtmjOwEyS+5wZhbkx6OoZhHCMN9hIvSitc8TNG\n+cpRGJIwYxwJZJVpim/TImsjAubh1uyMoY5fjW4GyBK9iU2plv/bS+lKyCMYgxHam\n+hzXwmgf/Q/ld9VKXKIXPWs8AeABfHYkMLeZ34laZ1Xhf1vPnktQctlukK8CzbYTU\n+Wm2BZ7kn/VEhwGOmrQ1nvnoCHTCyL+HHtIt8pKHM0rtKDKFAjMXZfZEK7DR2Qqll\n+/zogwy0m9Obvz/94XvdNMurUgdeTGyDwOouQcP+vd5x4LqsUtQEmwQfy4iLt7wl3\n+RRLPUTLyCfqpD98UAPeqCJkIikd1Ojhr+fd3jjSoo1CDTah0auvlMSMifjggIvi9\n+kE4nQISS0QqehGQ/ertNnLYWKvCgPI9fq8fQXG3mnFVR3qXhtSbIMbF1/AUye2bk\n+uVVZ3WTo2oPFEVv/ZyTH9NcP4XpeuA==\n+=KRyT\n -----END PGP PUBLIC KEY BLOCK-----\ndiff --git a/t/t7510-signed-commit.sh b/t/t7510-signed-commit.sh\nindex e8377286d..86d3f93fa 100755\n--- a/t/t7510-signed-commit.sh\n+++ b/t/t7510-signed-commit.sh\n@@ -197,9 +197,9 @@ test_expect_success GPG 'show bad signature with custom format' '\n test_expect_success GPG 'show untrusted signature with custom format' '\n \tcat >expect <<-\\EOF &&\n \tU\n-\t61092E85B7227189\n+\t65A0EEA02E30CAD7\n \tEris Discordia <discord@example.net>\n-\tD4BE22311AD3131E5EDA29A461092E85B7227189\n+\tF8364A59E07FFE9F4D63005A65A0EEA02E30CAD7\n \tD4BE22311AD3131E5EDA29A461092E85B7227189\n \tEOF\n \tgit log -1 --format=\"%G?%n%GK%n%GS%n%GF%n%GP\" eighth-signed-alt >actual &&\n@@ -209,7 +209,7 @@ test_expect_success GPG 'show untrusted signature with custom format' '\n test_expect_success GPG 'show unknown signature with custom format' '\n \tcat >expect <<-\\EOF &&\n \tE\n-\t61092E85B7227189\n+\t65A0EEA02E30CAD7\n \n \n \n-- \n2.19.1\n\n"},{"id":"362393","messageId":"20181104151013.GH731755@genre.crustytoothpaste.net","threadId":"49754","inReplyTo":"20181104094710.27859-2-mgorny@gentoo.org","subject":"Re: [PATCH 2/2] t/t7510-signed-commit.sh: add signing subkey to Eris Discordia key","fromName":"brian m. carlson","fromEmail":"sandals@crustytoothpaste.net","sentAt":"2018-11-04T15:10:13Z","receivedAt":"2018-11-04T15:10:31Z","isPatch":true,"sender":{"key":"sandals@crustytoothpaste.net","avatar":"https://avatars.githubusercontent.com/u/497054?v=4"},"body":"On Sun, Nov 04, 2018 at 10:47:10AM +0100, Michał Górny wrote:\n> diff --git a/t/t7510-signed-commit.sh b/t/t7510-signed-commit.sh\n> index e8377286d..86d3f93fa 100755\n> --- a/t/t7510-signed-commit.sh\n> +++ b/t/t7510-signed-commit.sh\n> @@ -197,9 +197,9 @@ test_expect_success GPG 'show bad signature with custom format' '\n>  test_expect_success GPG 'show untrusted signature with custom format' '\n>  \tcat >expect <<-\\EOF &&\n>  \tU\n> -\t61092E85B7227189\n> +\t65A0EEA02E30CAD7\n>  \tEris Discordia <discord@example.net>\n> -\tD4BE22311AD3131E5EDA29A461092E85B7227189\n> +\tF8364A59E07FFE9F4D63005A65A0EEA02E30CAD7\n>  \tD4BE22311AD3131E5EDA29A461092E85B7227189\n>  \tEOF\n>  \tgit log -1 --format=\"%G?%n%GK%n%GS%n%GF%n%GP\" eighth-signed-alt >actual &&\n> @@ -209,7 +209,7 @@ test_expect_success GPG 'show untrusted signature with custom format' '\n>  test_expect_success GPG 'show unknown signature with custom format' '\n>  \tcat >expect <<-\\EOF &&\n>  \tE\n> -\t61092E85B7227189\n> +\t65A0EEA02E30CAD7\n\nIt's my understanding that GnuPG will use the most recent subkey\nsuitable for a particular purpose, and I think the test relies on that\nbehavior.  However, I'm not sure that's documented.  Do we want to rely\non that behavior or be more explicit?  (This is a question, not an\nopinion.)\n-- \nbrian m. carlson: Houston, Texas, US\nOpenPGP: https://keybase.io/bk2204\n"},{"id":"362401","messageId":"1541347654.22217.4.camel@gentoo.org","threadId":"49754","inReplyTo":"20181104151013.GH731755@genre.crustytoothpaste.net","subject":"Re: [PATCH 2/2] t/t7510-signed-commit.sh: add signing subkey to Eris Discordia key","fromName":"Michał Górny","fromEmail":"mgorny@gentoo.org","sentAt":"2018-11-04T16:07:34Z","receivedAt":"2018-11-04T16:07:42Z","isPatch":true,"sender":{"key":"mgorny@gentoo.org","avatar":"https://avatars.githubusercontent.com/u/110765?v=4"},"body":"On Sun, 2018-11-04 at 15:10 +0000, brian m. carlson wrote:\n> On Sun, Nov 04, 2018 at 10:47:10AM +0100, Michał Górny wrote:\n> > diff --git a/t/t7510-signed-commit.sh b/t/t7510-signed-commit.sh\n> > index e8377286d..86d3f93fa 100755\n> > --- a/t/t7510-signed-commit.sh\n> > +++ b/t/t7510-signed-commit.sh\n> > @@ -197,9 +197,9 @@ test_expect_success GPG 'show bad signature with custom format' '\n> >  test_expect_success GPG 'show untrusted signature with custom format' '\n> >  \tcat >expect <<-\\EOF &&\n> >  \tU\n> > -\t61092E85B7227189\n> > +\t65A0EEA02E30CAD7\n> >  \tEris Discordia <discord@example.net>\n> > -\tD4BE22311AD3131E5EDA29A461092E85B7227189\n> > +\tF8364A59E07FFE9F4D63005A65A0EEA02E30CAD7\n> >  \tD4BE22311AD3131E5EDA29A461092E85B7227189\n> >  \tEOF\n> >  \tgit log -1 --format=\"%G?%n%GK%n%GS%n%GF%n%GP\" eighth-signed-alt >actual &&\n> > @@ -209,7 +209,7 @@ test_expect_success GPG 'show untrusted signature with custom format' '\n> >  test_expect_success GPG 'show unknown signature with custom format' '\n> >  \tcat >expect <<-\\EOF &&\n> >  \tE\n> > -\t61092E85B7227189\n> > +\t65A0EEA02E30CAD7\n> \n> It's my understanding that GnuPG will use the most recent subkey\n> suitable for a particular purpose, and I think the test relies on that\n> behavior.  However, I'm not sure that's documented.  Do we want to rely\n> on that behavior or be more explicit?  (This is a question, not an\n> opinion.)\n\nTo be honest, I don't recall which suitable subkey is used.  However, it\ndefinitely will prefer a subkey with signing capabilities over\nthe primary key if one is present, and this is well-known and expected\nbehavior.\n\nIn fact, if you have a key with two signing subkeys A and B and it\nconsiders A better, then even if you explicitly pass keyid of B, it will\nuse A.  To force another subkey you have to append '!' to keyid.\n\nTherefore, I think this is a behavior we can rely on.\n\n-- \nBest regards,\nMichał Górny\n"},{"id":"362436","messageId":"xmqqo9b4l4a6.fsf@gitster-ct.c.googlers.com","threadId":"49754","inReplyTo":"1541347654.22217.4.camel@gentoo.org","subject":"Re: [PATCH 2/2] t/t7510-signed-commit.sh: add signing subkey to Eris Discordia key","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2018-11-05T01:08:33Z","receivedAt":"2018-11-05T01:08:40Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Michał Górny <mgorny@gentoo.org> writes:\n\n>> It's my understanding that GnuPG will use the most recent subkey\n>> suitable for a particular purpose, and I think the test relies on that\n>> behavior.  However, I'm not sure that's documented.  Do we want to rely\n>> on that behavior or be more explicit?  (This is a question, not an\n>> opinion.)\n>\n> To be honest, I don't recall which suitable subkey is used.  However, it\n> definitely will prefer a subkey with signing capabilities over\n> the primary key if one is present, and this is well-known and expected\n> behavior.\n>\n> In fact, if you have a key with two signing subkeys A and B and it\n> considers A better, then even if you explicitly pass keyid of B, it will\n> use A.  To force another subkey you have to append '!' to keyid.\n>\n> Therefore, I think this is a behavior we can rely on.\n\nI didn't check how the signing key configuration is done in the test\nsript (which is outside the patch context), but do you mean that we\ncreate these signed objects by specifying which key to use with a\nkeyid with \"!\"  appended?  If so I agree that would make sense,\nbecause we would then know which subkey should be used for signing\nand checking with %GF/%GP would be a good way to do so.\n\nThanks.\n"},{"id":"362451","messageId":"1541390965.763.2.camel@gentoo.org","threadId":"49754","inReplyTo":"xmqqo9b4l4a6.fsf@gitster-ct.c.googlers.com","subject":"Re: [PATCH 2/2] t/t7510-signed-commit.sh: add signing subkey to Eris Discordia key","fromName":"Michał Górny","fromEmail":"mgorny@gentoo.org","sentAt":"2018-11-05T04:09:25Z","receivedAt":"2018-11-05T04:09:33Z","isPatch":true,"sender":{"key":"mgorny@gentoo.org","avatar":"https://avatars.githubusercontent.com/u/110765?v=4"},"body":"On Mon, 2018-11-05 at 10:08 +0900, Junio C Hamano wrote:\n> Michał Górny <mgorny@gentoo.org> writes:\n> \n> > > It's my understanding that GnuPG will use the most recent subkey\n> > > suitable for a particular purpose, and I think the test relies on that\n> > > behavior.  However, I'm not sure that's documented.  Do we want to rely\n> > > on that behavior or be more explicit?  (This is a question, not an\n> > > opinion.)\n> > \n> > To be honest, I don't recall which suitable subkey is used.  However, it\n> > definitely will prefer a subkey with signing capabilities over\n> > the primary key if one is present, and this is well-known and expected\n> > behavior.\n> > \n> > In fact, if you have a key with two signing subkeys A and B and it\n> > considers A better, then even if you explicitly pass keyid of B, it will\n> > use A.  To force another subkey you have to append '!' to keyid.\n> > \n> > Therefore, I think this is a behavior we can rely on.\n> \n> I didn't check how the signing key configuration is done in the test\n> sript (which is outside the patch context), but do you mean that we\n> create these signed objects by specifying which key to use with a\n> keyid with \"!\"  appended?  If so I agree that would make sense,\n> because we would then know which subkey should be used for signing\n> and checking with %GF/%GP would be a good way to do so.\n> \n\nNo, we don't have duplicate subkeys to be required to use that.  Some of\nthe tests use explicit '-S<keyid>' to force using the other key; other\nseem to use a default key (I can't find a place where the default would\nbe set, so I suppose it's GnuPG default).\n\n-- \nBest regards,\nMichał Górny\n"}]}