{"thread":{"id":"51473","subject":"[PATCH 0/1] Update gpg.txt to correct gpg --verify syntax","startedAt":"2019-07-12T15:34:00Z","lastAt":"2019-07-12T19:12:09Z","messageCount":4,"participants":["Robert Morgan via GitGitGadget","Junio C Hamano","Robert Morgan"],"isPatch":true,"patchVersion":1,"patchTotal":1},"messages":[{"id":"378887","messageId":"pull.285.git.gitgitgadget@gmail.com","threadId":"51473","inReplyTo":null,"subject":"[PATCH 0/1] Update gpg.txt to correct gpg --verify syntax","fromName":"Robert Morgan via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2019-07-12T15:33:56Z","receivedAt":"2019-07-12T15:34:00Z","isPatch":true,"sender":{"key":"robert.thomas.morgan@gmail.com","avatar":"https://avatars.githubusercontent.com/u/7585796?v=4"},"body":"The gpg --verify usage example within the 'gpg.program' variable reference\nprovides an incorrect example of the gpg --verify command arguments. The\ncommand argument order, when providing both a detached signature and data,\nshould be signature first and data second: \nhttps://gnupg.org/documentation/manuals/gnupg/Operational-GPG-Commands.html#index-verify\n.\n\nSigned-off-by: Robert T Morgan robert.thomas.morgan@gmail.com\n[robert.thomas.morgan@gmail.com]\n\nRobert Morgan (1):\n  gpg(docs): use correct --verify syntax\n\n Documentation/config/gpg.txt | 2 +-\n 1 file changed, 1 insertion(+), 1 deletion(-)\n\n\nbase-commit: 6d5b26420848ec3bc7eae46a7ffa54f20276249d\nPublished-As: https://github.com/gitgitgadget/git/releases/tag/pr-285%2Frtmorgan%2Fpatch-1-v1\nFetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-285/rtmorgan/patch-1-v1\nPull-Request: https://github.com/gitgitgadget/git/pull/285\n-- \ngitgitgadget\n"},{"id":"378888","messageId":"e2daf21f1f2574a79f83d4e66591f67b1c937efe.1562945635.git.gitgitgadget@gmail.com","threadId":"51473","inReplyTo":"pull.285.git.gitgitgadget@gmail.com","subject":"[PATCH 1/1] gpg(docs): use correct --verify syntax","fromName":"Robert Morgan via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2019-07-12T15:33:57Z","receivedAt":"2019-07-12T15:34:01Z","isPatch":true,"sender":{"key":"robert.thomas.morgan@gmail.com","avatar":"https://avatars.githubusercontent.com/u/7585796?v=4"},"body":"From: Robert Morgan <robert.thomas.morgan@gmail.com>\n\nThe gpg --verify usage example within the 'gpg.program' variable\nreference provides an incorrect example of the gpg --verify command\narguments.\n\nThe command argument order, when providing both a detached signature\nand data, should be signature first and data second:\nhttps://gnupg.org/documentation/manuals/gnupg/Operational-GPG-Commands.html\n\nSigned-off-by: Robert Morgan <robert.thomas.morgan@gmail.com>\n---\n Documentation/config/gpg.txt | 2 +-\n 1 file changed, 1 insertion(+), 1 deletion(-)\n\ndiff --git a/Documentation/config/gpg.txt b/Documentation/config/gpg.txt\nindex f999f8ea49..cce2c89245 100644\n--- a/Documentation/config/gpg.txt\n+++ b/Documentation/config/gpg.txt\n@@ -2,7 +2,7 @@ gpg.program::\n \tUse this custom program instead of \"`gpg`\" found on `$PATH` when\n \tmaking or verifying a PGP signature. The program must support the\n \tsame command-line interface as GPG, namely, to verify a detached\n-\tsignature, \"`gpg --verify $file - <$signature`\" is run, and the\n+\tsignature, \"`gpg --verify $signature - <$file`\" is run, and the\n \tprogram is expected to signal a good signature by exiting with\n \tcode 0, and to generate an ASCII-armored detached signature, the\n \tstandard input of \"`gpg -bsau $key`\" is fed with the contents to be\n-- \ngitgitgadget\n"},{"id":"378896","messageId":"xmqqtvbrp5c5.fsf@gitster-ct.c.googlers.com","threadId":"51473","inReplyTo":"e2daf21f1f2574a79f83d4e66591f67b1c937efe.1562945635.git.gitgitgadget@gmail.com","subject":"Re: [PATCH 1/1] gpg(docs): use correct --verify syntax","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2019-07-12T16:47:54Z","receivedAt":"2019-07-12T16:47:59Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"\"Robert Morgan via GitGitGadget\" <gitgitgadget@gmail.com> writes:\n\n> diff --git a/Documentation/config/gpg.txt b/Documentation/config/gpg.txt\n> index f999f8ea49..cce2c89245 100644\n> --- a/Documentation/config/gpg.txt\n> +++ b/Documentation/config/gpg.txt\n> @@ -2,7 +2,7 @@ gpg.program::\n>  \tUse this custom program instead of \"`gpg`\" found on `$PATH` when\n>  \tmaking or verifying a PGP signature. The program must support the\n>  \tsame command-line interface as GPG, namely, to verify a detached\n> -\tsignature, \"`gpg --verify $file - <$signature`\" is run, and the\n> +\tsignature, \"`gpg --verify $signature - <$file`\" is run, and the\n>  \tprogram is expected to signal a good signature by exiting with\n>  \tcode 0, and to generate an ASCII-armored detached signature, the\n>  \tstandard input of \"`gpg -bsau $key`\" is fed with the contents to be\n\nWow.  Good find.\n\ngpg-interface.c::verify_signed_buffer() takes a detached signature\nin core, writes it to a temporary file and runs \n\n    gpg --status-fd=1 --verify $the_temporary_file\n\nand the payload that is supposed to match the given signature is fed\nvia the standard input, so the above documentation is the only thing\nthat needs fixing, which is good ;-)\n\nThanks.\n\n\n\n"},{"id":"378906","messageId":"CAMgm5nNX5qF18MBQKBkkctqvFMwfd5q8XvymSdTfEncKXeiKVA@mail.gmail.com","threadId":"51473","inReplyTo":"xmqqtvbrp5c5.fsf@gitster-ct.c.googlers.com","subject":"Re: [PATCH 1/1] gpg(docs): use correct --verify syntax","fromName":"Robert Morgan","fromEmail":"robert.thomas.morgan@gmail.com","sentAt":"2019-07-12T19:11:56Z","receivedAt":"2019-07-12T19:12:09Z","isPatch":true,"sender":{"key":"robert.thomas.morgan@gmail.com","avatar":"https://avatars.githubusercontent.com/u/7585796?v=4"},"body":"Thanks Junio.\n\nI was looking at 'smimesign' and working to understand how, when set\nwithin 'gpg.program', it conformed with gpg's usage within git\nsign,verify etc.  I happened to look at the docs for the 'gpg.program'\nconfig variable and noticed the discrepancy.\n\nThanks again,\nRobert\n\nOn Fri, Jul 12, 2019 at 11:47 AM Junio C Hamano <gitster@pobox.com> wrote:\n>\n> \"Robert Morgan via GitGitGadget\" <gitgitgadget@gmail.com> writes:\n>\n> > diff --git a/Documentation/config/gpg.txt b/Documentation/config/gpg.txt\n> > index f999f8ea49..cce2c89245 100644\n> > --- a/Documentation/config/gpg.txt\n> > +++ b/Documentation/config/gpg.txt\n> > @@ -2,7 +2,7 @@ gpg.program::\n> >       Use this custom program instead of \"`gpg`\" found on `$PATH` when\n> >       making or verifying a PGP signature. The program must support the\n> >       same command-line interface as GPG, namely, to verify a detached\n> > -     signature, \"`gpg --verify $file - <$signature`\" is run, and the\n> > +     signature, \"`gpg --verify $signature - <$file`\" is run, and the\n> >       program is expected to signal a good signature by exiting with\n> >       code 0, and to generate an ASCII-armored detached signature, the\n> >       standard input of \"`gpg -bsau $key`\" is fed with the contents to be\n>\n> Wow.  Good find.\n>\n> gpg-interface.c::verify_signed_buffer() takes a detached signature\n> in core, writes it to a temporary file and runs\n>\n>     gpg --status-fd=1 --verify $the_temporary_file\n>\n> and the payload that is supposed to match the given signature is fed\n> via the standard input, so the above documentation is the only thing\n> that needs fixing, which is good ;-)\n>\n> Thanks.\n>\n>\n>\n"}]}