{"thread":{"id":"57217","subject":"git ssh signing changed broke tag merge message contents","startedAt":"2022-01-10T16:42:27Z","lastAt":"2022-01-11T15:42:15Z","messageCount":8,"participants":["Linus Torvalds","Taylor Blau","Junio C Hamano","Fabian Stelzer"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"445836","messageId":"CAHk-=whXPxWL7z3GiPkaDt+yygrRmagrYUnib7Lx=Vvrqx2ufg@mail.gmail.com","threadId":"57217","inReplyTo":null,"subject":"git ssh signing changed broke tag merge message contents","fromName":"Linus Torvalds","fromEmail":"torvalds@linux-foundation.org","sentAt":"2022-01-10T16:42:07Z","receivedAt":"2022-01-10T16:42:27Z","isPatch":false,"sender":{"key":"torvalds@linux-foundation.org","avatar":"https://avatars.githubusercontent.com/u/1024025?v=4"},"body":"So I made the mistake of updating my git tree as I started doing my\nmerge window for 5.17, and suddenly all the messages from signed tags\ndisappeared from the merge commits.\n\nI bisected it to commit 02769437e1 (\"ssh signing: use sigc struct to\npass payload\"), but haven't done any other analysis.\n\nI assume it's the change to fmt-merge-msg.c, but have no time to actually check.\n\nEasy enough to test:\n\n   echo \"Dummy file\" > dummy\n   git commit -m \"Dummy commit\" dummy\n   git tag -s -m \"Dummy tag\" dummy-tag\n   git reset --hard HEAD^\n   git merge --no-ff dummy-tag\n\nWith the above, you are *supposed* to get a merge message in your\neditor something like\n\n    Merge tag 'dummy-tag'\n\n    Dummy tag\n\n    * tag 'dummy-tag':\n      Dummy commit\n\n(ok, that last part you only get with merge.summary=true, of course)\n\nBut with the broken commit, that \"Dummy tag\" message from the tag\ncontents does not exist.\n\nHoller if there are questions, but I'm hoping the above explanation is\nclear enough since I'm about to be very busy..\n\n                Linus\n"},{"id":"445841","messageId":"YdxqshqXB/+ApOn2@nand.local","threadId":"57217","inReplyTo":"CAHk-=whXPxWL7z3GiPkaDt+yygrRmagrYUnib7Lx=Vvrqx2ufg@mail.gmail.com","subject":"Re: git ssh signing changed broke tag merge message contents","fromName":"Taylor Blau","fromEmail":"me@ttaylorr.com","sentAt":"2022-01-10T17:19:46Z","receivedAt":"2022-01-10T17:19:51Z","isPatch":false,"sender":{"key":"me@ttaylorr.com","avatar":"https://avatars.githubusercontent.com/u/301000140?v=4"},"body":"On Mon, Jan 10, 2022 at 08:42:07AM -0800, Linus Torvalds wrote:\n> So I made the mistake of updating my git tree as I started doing my\n> merge window for 5.17, and suddenly all the messages from signed tags\n> disappeared from the merge commits.\n>\n> I bisected it to commit 02769437e1 (\"ssh signing: use sigc struct to\n> pass payload\"), but haven't done any other analysis.\n\nThanks for the reproduction and bisection.\n\n> I assume it's the change to fmt-merge-msg.c, but have no time to actually check.\n\nYes, 02769437e1 appears to introduces an inadvertent use-after-free.\nI'll write up the details and post the patch shortly, but an easy fix\nis:\n\n--- 8< ---\n\ndiff --git a/fmt-merge-msg.c b/fmt-merge-msg.c\nindex e5c0aff2bf..baca57d5b6 100644\n--- a/fmt-merge-msg.c\n+++ b/fmt-merge-msg.c\n@@ -541,7 +541,6 @@ static void fmt_merge_msg_sigs(struct strbuf *out)\n \t\t\telse\n \t\t\t\tstrbuf_addstr(&sig, sigc.output);\n \t\t}\n-\t\tsignature_check_clear(&sigc);\n\n \t\tif (!tag_number++) {\n \t\t\tfmt_tag_signature(&tagbuf, &sig, buf, len);\n@@ -565,6 +564,7 @@ static void fmt_merge_msg_sigs(struct strbuf *out)\n \t\t}\n \t\tstrbuf_release(&payload);\n \t\tstrbuf_release(&sig);\n+\t\tsignature_check_clear(&sigc);\n \tnext:\n \t\tfree(origbuf);\n \t}\n\n--- >8 ---\n\nOur coverage in t6200 (which should have ordinarily caught such a bug)\nis lacking and does not search for the tag message in fmt-merge-msg's\noutput.\n\nThanks,\nTaylor\n"},{"id":"445842","messageId":"CAHk-=wg8yGxwtv-Ggqbh7qqWGHbjiDCVARXdhOzxjCpMg=e0Rg@mail.gmail.com","threadId":"57217","inReplyTo":"YdxqshqXB/+ApOn2@nand.local","subject":"Re: git ssh signing changed broke tag merge message contents","fromName":"Linus Torvalds","fromEmail":"torvalds@linux-foundation.org","sentAt":"2022-01-10T17:22:57Z","receivedAt":"2022-01-10T17:23:18Z","isPatch":false,"sender":{"key":"torvalds@linux-foundation.org","avatar":"https://avatars.githubusercontent.com/u/1024025?v=4"},"body":"On Mon, Jan 10, 2022 at 9:19 AM Taylor Blau <me@ttaylorr.com> wrote:\n>\n> Yes, 02769437e1 appears to introduces an inadvertent use-after-free.\n> I'll write up the details and post the patch shortly, but an easy fix\n> is:\n\nAck, that seems to fix it here for me from a _very_ cursory test.\n\nThanks,\n               Linus\n"},{"id":"445843","messageId":"xmqqsftv1oqq.fsf@gitster.g","threadId":"57217","inReplyTo":"YdxqshqXB/+ApOn2@nand.local","subject":"Re: git ssh signing changed broke tag merge message contents","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2022-01-10T17:31:41Z","receivedAt":"2022-01-10T17:31:45Z","isPatch":false,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Taylor Blau <me@ttaylorr.com> writes:\n\n> I'll write up the details and post the patch shortly, but an easy fix\n> is:\n\nAh, I am glad that you beat me ;-)\n\n> --- 8< ---\n>\n> diff --git a/fmt-merge-msg.c b/fmt-merge-msg.c\n> index e5c0aff2bf..baca57d5b6 100644\n> --- a/fmt-merge-msg.c\n> +++ b/fmt-merge-msg.c\n> @@ -541,7 +541,6 @@ static void fmt_merge_msg_sigs(struct strbuf *out)\n>  \t\t\telse\n>  \t\t\t\tstrbuf_addstr(&sig, sigc.output);\n>  \t\t}\n> -\t\tsignature_check_clear(&sigc);\n>\n>  \t\tif (!tag_number++) {\n>  \t\t\tfmt_tag_signature(&tagbuf, &sig, buf, len);\n> @@ -565,6 +564,7 @@ static void fmt_merge_msg_sigs(struct strbuf *out)\n>  \t\t}\n>  \t\tstrbuf_release(&payload);\n>  \t\tstrbuf_release(&sig);\n> +\t\tsignature_check_clear(&sigc);\n>  \tnext:\n>  \t\tfree(origbuf);\n>  \t}\n>\n> --- >8 ---\n>\n> Our coverage in t6200 (which should have ordinarily caught such a bug)\n> is lacking and does not search for the tag message in fmt-merge-msg's\n> output.\n\nTrue.\n\nThanks, both.\n"},{"id":"445878","messageId":"6e08b73d602853b3de71257117e85e32b96b5c19.1641849502.git.me@ttaylorr.com","threadId":"57217","inReplyTo":"YdxqshqXB/+ApOn2@nand.local","subject":"[PATCH] fmt-merge-msg: prevent use-after-free with signed tags","fromName":"Taylor Blau","fromEmail":"me@ttaylorr.com","sentAt":"2022-01-10T21:19:06Z","receivedAt":"2022-01-10T21:19:15Z","isPatch":true,"sender":{"key":"me@ttaylorr.com","avatar":"https://avatars.githubusercontent.com/u/301000140?v=4"},"body":"When merging a signed tag, fmt_merge_msg_sigs() is responsible for\npopulating the body of the merge message with the names of the signed\ntags, their signatures, and the validity of those signatures.\n\nIn 02769437e1 (ssh signing: use sigc struct to pass payload,\n2021-12-09), check_signature() was taught to pass the object payload via\nthe sigc struct instead of passing the payload buffer separately.\n\nIn effect, 02769437e1 causes buf, and sigc.payload to point at the same\nregion in memory. This causes a problem for fmt_tag_signature(), which\nwants to read from this location, since it is freed beforehand by\nsignature_check_clear() (which frees it via sigc's `payload` member).\n\nThat makes the subsequent use in fmt_tag_signature() a use-after-free.\n\nAs a result, merge messages did not contain the body of any signed tags.\nLuckily, they tend not to contain garbage, either, since the result of\nstrstr()-ing the object buffer in fmt_tag_signature() is guarded:\n\n    const char *tag_body = strstr(buf, \"\\n\\n\");\n    if (tag_body) {\n      tag_body += 2;\n      strbuf_add(tagbuf, tag_body, buf + len - tag_body);\n    }\n\nUnfortunately, the tests in t6200 did not catch this at the time because\nthey do not search for the body of signed tags in fmt-merge-msg's\noutput.\n\nResolve this by waiting to call signature_check_clear() until after its\ncontents can be safely discarded. Harden ourselves against any future\nregressions in this area by making sure we can find signed tag messages\nin the output of fmt-merge-msg, too.\n\nReported-by: Linus Torvalds <torvalds@linux-foundation.org>\nSigned-off-by: Taylor Blau <me@ttaylorr.com>\n---\n fmt-merge-msg.c          | 2 +-\n t/t6200-fmt-merge-msg.sh | 8 ++++++++\n 2 files changed, 9 insertions(+), 1 deletion(-)\n\ndiff --git a/fmt-merge-msg.c b/fmt-merge-msg.c\nindex e5c0aff2bf..baca57d5b6 100644\n--- a/fmt-merge-msg.c\n+++ b/fmt-merge-msg.c\n@@ -541,7 +541,6 @@ static void fmt_merge_msg_sigs(struct strbuf *out)\n \t\t\telse\n \t\t\t\tstrbuf_addstr(&sig, sigc.output);\n \t\t}\n-\t\tsignature_check_clear(&sigc);\n\n \t\tif (!tag_number++) {\n \t\t\tfmt_tag_signature(&tagbuf, &sig, buf, len);\n@@ -565,6 +564,7 @@ static void fmt_merge_msg_sigs(struct strbuf *out)\n \t\t}\n \t\tstrbuf_release(&payload);\n \t\tstrbuf_release(&sig);\n+\t\tsignature_check_clear(&sigc);\n \tnext:\n \t\tfree(origbuf);\n \t}\ndiff --git a/t/t6200-fmt-merge-msg.sh b/t/t6200-fmt-merge-msg.sh\nindex 7544245f90..5a221f8ef1 100755\n--- a/t/t6200-fmt-merge-msg.sh\n+++ b/t/t6200-fmt-merge-msg.sh\n@@ -126,6 +126,7 @@ test_expect_success GPG 'message for merging local tag signed by good key' '\n \tgit fetch . signed-good-tag &&\n \tgit fmt-merge-msg <.git/FETCH_HEAD >actual &&\n \tgrep \"^Merge tag ${apos}signed-good-tag${apos}\" actual &&\n+\tgrep \"^signed-tag-msg\" actual &&\n \tgrep \"^# gpg: Signature made\" actual &&\n \tgrep \"^# gpg: Good signature from\" actual\n '\n@@ -135,6 +136,7 @@ test_expect_success GPG 'message for merging local tag signed by unknown key' '\n \tgit fetch . signed-good-tag &&\n \tGNUPGHOME=. git fmt-merge-msg <.git/FETCH_HEAD >actual &&\n \tgrep \"^Merge tag ${apos}signed-good-tag${apos}\" actual &&\n+\tgrep \"^signed-tag-msg\" actual &&\n \tgrep \"^# gpg: Signature made\" actual &&\n \tgrep -E \"^# gpg: Can${apos}t check signature: (public key not found|No public key)\" actual\n '\n@@ -145,6 +147,7 @@ test_expect_success GPGSSH 'message for merging local tag signed by good ssh key\n \tgit fetch . signed-good-ssh-tag &&\n \tgit fmt-merge-msg <.git/FETCH_HEAD >actual &&\n \tgrep \"^Merge tag ${apos}signed-good-ssh-tag${apos}\" actual &&\n+\tgrep \"^signed-ssh-tag-msg\" actual &&\n \tgrep \"${GPGSSH_GOOD_SIGNATURE_TRUSTED}\" actual &&\n \t! grep \"${GPGSSH_BAD_SIGNATURE}\" actual\n '\n@@ -155,6 +158,7 @@ test_expect_success GPGSSH 'message for merging local tag signed by unknown ssh\n \tgit fetch . signed-untrusted-ssh-tag &&\n \tgit fmt-merge-msg <.git/FETCH_HEAD >actual &&\n \tgrep \"^Merge tag ${apos}signed-untrusted-ssh-tag${apos}\" actual &&\n+\tgrep \"^signed-ssh-tag-msg-untrusted\" actual &&\n \tgrep \"${GPGSSH_GOOD_SIGNATURE_UNTRUSTED}\" actual &&\n \t! grep \"${GPGSSH_BAD_SIGNATURE}\" actual &&\n \tgrep \"${GPGSSH_KEY_NOT_TRUSTED}\" actual\n@@ -166,6 +170,7 @@ test_expect_success GPGSSH,GPGSSH_VERIFYTIME 'message for merging local tag sign\n \tgit fetch . expired-signed &&\n \tgit fmt-merge-msg <.git/FETCH_HEAD >actual &&\n \tgrep \"^Merge tag ${apos}expired-signed${apos}\" actual &&\n+\tgrep \"^expired-signed\" actual &&\n \t! grep \"${GPGSSH_GOOD_SIGNATURE_TRUSTED}\" actual\n '\n\n@@ -175,6 +180,7 @@ test_expect_success GPGSSH,GPGSSH_VERIFYTIME 'message for merging local tag sign\n \tgit fetch . notyetvalid-signed &&\n \tgit fmt-merge-msg <.git/FETCH_HEAD >actual &&\n \tgrep \"^Merge tag ${apos}notyetvalid-signed${apos}\" actual &&\n+\tgrep \"^notyetvalid-signed\" actual &&\n \t! grep \"${GPGSSH_GOOD_SIGNATURE_TRUSTED}\" actual\n '\n\n@@ -184,6 +190,7 @@ test_expect_success GPGSSH,GPGSSH_VERIFYTIME 'message for merging local tag sign\n \tgit fetch . timeboxedvalid-signed &&\n \tgit fmt-merge-msg <.git/FETCH_HEAD >actual &&\n \tgrep \"^Merge tag ${apos}timeboxedvalid-signed${apos}\" actual &&\n+\tgrep \"^timeboxedvalid-signed\" actual &&\n \tgrep \"${GPGSSH_GOOD_SIGNATURE_TRUSTED}\" actual &&\n \t! grep \"${GPGSSH_BAD_SIGNATURE}\" actual\n '\n@@ -194,6 +201,7 @@ test_expect_success GPGSSH,GPGSSH_VERIFYTIME 'message for merging local tag sign\n \tgit fetch . timeboxedinvalid-signed &&\n \tgit fmt-merge-msg <.git/FETCH_HEAD >actual &&\n \tgrep \"^Merge tag ${apos}timeboxedinvalid-signed${apos}\" actual &&\n+\tgrep \"^timeboxedinvalid-signed\" actual &&\n \t! grep \"${GPGSSH_GOOD_SIGNATURE_TRUSTED}\" actual\n '\n\n--\n2.34.1.455.gd6eb6fd089\n"},{"id":"445879","messageId":"xmqqsftvxodf.fsf@gitster.g","threadId":"57217","inReplyTo":"6e08b73d602853b3de71257117e85e32b96b5c19.1641849502.git.me@ttaylorr.com","subject":"Re: [PATCH] fmt-merge-msg: prevent use-after-free with signed tags","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2022-01-10T21:38:36Z","receivedAt":"2022-01-10T21:38:41Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Taylor Blau <me@ttaylorr.com> writes:\n\n> When merging a signed tag, fmt_merge_msg_sigs() is responsible for\n> populating the body of the merge message with the names of the signed\n> tags, their signatures, and the validity of those signatures.\n>\n> In 02769437e1 (ssh signing: use sigc struct to pass payload,\n> 2021-12-09), check_signature() was taught to pass the object payload via\n> the sigc struct instead of passing the payload buffer separately.\n>\n> In effect, 02769437e1 causes buf, and sigc.payload to point at the same\n> region in memory. This causes a problem for fmt_tag_signature(), which\n> wants to read from this location, since it is freed beforehand by\n> signature_check_clear() (which frees it via sigc's `payload` member).\n>\n> That makes the subsequent use in fmt_tag_signature() a use-after-free.\n\nVery clearly described.\n\n> As a result, merge messages did not contain the body of any signed tags.\n> Luckily, they tend not to contain garbage, either, since the result of\n> strstr()-ing the object buffer in fmt_tag_signature() is guarded:\n>\n>     const char *tag_body = strstr(buf, \"\\n\\n\");\n>     if (tag_body) {\n>       tag_body += 2;\n>       strbuf_add(tagbuf, tag_body, buf + len - tag_body);\n>     }\n>\n> Unfortunately, the tests in t6200 did not catch this at the time because\n> they do not search for the body of signed tags in fmt-merge-msg's\n> output.\n>\n> Resolve this by waiting to call signature_check_clear() until after its\n> contents can be safely discarded. Harden ourselves against any future\n> regressions in this area by making sure we can find signed tag messages\n> in the output of fmt-merge-msg, too.\n>\n> Reported-by: Linus Torvalds <torvalds@linux-foundation.org>\n> Signed-off-by: Taylor Blau <me@ttaylorr.com>\n> ---\n\nWill fast-track.  Thanks.\n"},{"id":"445904","messageId":"20220111084115.esuyxeopdpaq7g7y@fs","threadId":"57217","inReplyTo":"6e08b73d602853b3de71257117e85e32b96b5c19.1641849502.git.me@ttaylorr.com","subject":"Re: [PATCH] fmt-merge-msg: prevent use-after-free with signed tags","fromName":"Fabian Stelzer","fromEmail":"fs@gigacodes.de","sentAt":"2022-01-11T08:41:15Z","receivedAt":"2022-01-11T08:41:21Z","isPatch":true,"sender":{"key":"fs@gigacodes.de","avatar":"https://avatars.githubusercontent.com/u/564858?v=4"},"body":"On 10.01.2022 16:19, Taylor Blau wrote:\n>When merging a signed tag, fmt_merge_msg_sigs() is responsible for\n>populating the body of the merge message with the names of the signed\n>tags, their signatures, and the validity of those signatures.\n>\n>In 02769437e1 (ssh signing: use sigc struct to pass payload,\n>2021-12-09), check_signature() was taught to pass the object payload via\n>the sigc struct instead of passing the payload buffer separately.\n>\n>In effect, 02769437e1 causes buf, and sigc.payload to point at the same\n>region in memory. This causes a problem for fmt_tag_signature(), which\n>wants to read from this location, since it is freed beforehand by\n>signature_check_clear() (which frees it via sigc's `payload` member).\n>\n>That makes the subsequent use in fmt_tag_signature() a use-after-free.\n>\n>As a result, merge messages did not contain the body of any signed tags.\n>Luckily, they tend not to contain garbage, either, since the result of\n>strstr()-ing the object buffer in fmt_tag_signature() is guarded:\n>\n>    const char *tag_body = strstr(buf, \"\\n\\n\");\n>    if (tag_body) {\n>      tag_body += 2;\n>      strbuf_add(tagbuf, tag_body, buf + len - tag_body);\n>    }\n>\n>Unfortunately, the tests in t6200 did not catch this at the time because\n>they do not search for the body of signed tags in fmt-merge-msg's\n>output.\n>\n>Resolve this by waiting to call signature_check_clear() until after its\n>contents can be safely discarded. Harden ourselves against any future\n>regressions in this area by making sure we can find signed tag messages\n>in the output of fmt-merge-msg, too.\n\nSorry for breaking any workflows :/\nThanks Taylor for the quick fix and the additional test conditions.\n\nfmt_merge_msg_sigs() could probably use some additional refactoring to avoid \nthese multiple pointers to the same (detached) buffer. But thats for another \ntime.\n\nThanks\n\n>\n>Reported-by: Linus Torvalds <torvalds@linux-foundation.org>\n>Signed-off-by: Taylor Blau <me@ttaylorr.com>\n>---\n> fmt-merge-msg.c          | 2 +-\n> t/t6200-fmt-merge-msg.sh | 8 ++++++++\n> 2 files changed, 9 insertions(+), 1 deletion(-)\n>\n>diff --git a/fmt-merge-msg.c b/fmt-merge-msg.c\n>index e5c0aff2bf..baca57d5b6 100644\n>--- a/fmt-merge-msg.c\n>+++ b/fmt-merge-msg.c\n>@@ -541,7 +541,6 @@ static void fmt_merge_msg_sigs(struct strbuf *out)\n> \t\t\telse\n> \t\t\t\tstrbuf_addstr(&sig, sigc.output);\n> \t\t}\n>-\t\tsignature_check_clear(&sigc);\n>\n> \t\tif (!tag_number++) {\n> \t\t\tfmt_tag_signature(&tagbuf, &sig, buf, len);\n>@@ -565,6 +564,7 @@ static void fmt_merge_msg_sigs(struct strbuf *out)\n> \t\t}\n> \t\tstrbuf_release(&payload);\n> \t\tstrbuf_release(&sig);\n>+\t\tsignature_check_clear(&sigc);\n> \tnext:\n> \t\tfree(origbuf);\n> \t}\n>diff --git a/t/t6200-fmt-merge-msg.sh b/t/t6200-fmt-merge-msg.sh\n>index 7544245f90..5a221f8ef1 100755\n>--- a/t/t6200-fmt-merge-msg.sh\n>+++ b/t/t6200-fmt-merge-msg.sh\n>@@ -126,6 +126,7 @@ test_expect_success GPG 'message for merging local tag signed by good key' '\n> \tgit fetch . signed-good-tag &&\n> \tgit fmt-merge-msg <.git/FETCH_HEAD >actual &&\n> \tgrep \"^Merge tag ${apos}signed-good-tag${apos}\" actual &&\n>+\tgrep \"^signed-tag-msg\" actual &&\n> \tgrep \"^# gpg: Signature made\" actual &&\n> \tgrep \"^# gpg: Good signature from\" actual\n> '\n>@@ -135,6 +136,7 @@ test_expect_success GPG 'message for merging local tag signed by unknown key' '\n> \tgit fetch . signed-good-tag &&\n> \tGNUPGHOME=. git fmt-merge-msg <.git/FETCH_HEAD >actual &&\n> \tgrep \"^Merge tag ${apos}signed-good-tag${apos}\" actual &&\n>+\tgrep \"^signed-tag-msg\" actual &&\n> \tgrep \"^# gpg: Signature made\" actual &&\n> \tgrep -E \"^# gpg: Can${apos}t check signature: (public key not found|No public key)\" actual\n> '\n>@@ -145,6 +147,7 @@ test_expect_success GPGSSH 'message for merging local tag signed by good ssh key\n> \tgit fetch . signed-good-ssh-tag &&\n> \tgit fmt-merge-msg <.git/FETCH_HEAD >actual &&\n> \tgrep \"^Merge tag ${apos}signed-good-ssh-tag${apos}\" actual &&\n>+\tgrep \"^signed-ssh-tag-msg\" actual &&\n> \tgrep \"${GPGSSH_GOOD_SIGNATURE_TRUSTED}\" actual &&\n> \t! grep \"${GPGSSH_BAD_SIGNATURE}\" actual\n> '\n>@@ -155,6 +158,7 @@ test_expect_success GPGSSH 'message for merging local tag signed by unknown ssh\n> \tgit fetch . signed-untrusted-ssh-tag &&\n> \tgit fmt-merge-msg <.git/FETCH_HEAD >actual &&\n> \tgrep \"^Merge tag ${apos}signed-untrusted-ssh-tag${apos}\" actual &&\n>+\tgrep \"^signed-ssh-tag-msg-untrusted\" actual &&\n> \tgrep \"${GPGSSH_GOOD_SIGNATURE_UNTRUSTED}\" actual &&\n> \t! grep \"${GPGSSH_BAD_SIGNATURE}\" actual &&\n> \tgrep \"${GPGSSH_KEY_NOT_TRUSTED}\" actual\n>@@ -166,6 +170,7 @@ test_expect_success GPGSSH,GPGSSH_VERIFYTIME 'message for merging local tag sign\n> \tgit fetch . expired-signed &&\n> \tgit fmt-merge-msg <.git/FETCH_HEAD >actual &&\n> \tgrep \"^Merge tag ${apos}expired-signed${apos}\" actual &&\n>+\tgrep \"^expired-signed\" actual &&\n> \t! grep \"${GPGSSH_GOOD_SIGNATURE_TRUSTED}\" actual\n> '\n>\n>@@ -175,6 +180,7 @@ test_expect_success GPGSSH,GPGSSH_VERIFYTIME 'message for merging local tag sign\n> \tgit fetch . notyetvalid-signed &&\n> \tgit fmt-merge-msg <.git/FETCH_HEAD >actual &&\n> \tgrep \"^Merge tag ${apos}notyetvalid-signed${apos}\" actual &&\n>+\tgrep \"^notyetvalid-signed\" actual &&\n> \t! grep \"${GPGSSH_GOOD_SIGNATURE_TRUSTED}\" actual\n> '\n>\n>@@ -184,6 +190,7 @@ test_expect_success GPGSSH,GPGSSH_VERIFYTIME 'message for merging local tag sign\n> \tgit fetch . timeboxedvalid-signed &&\n> \tgit fmt-merge-msg <.git/FETCH_HEAD >actual &&\n> \tgrep \"^Merge tag ${apos}timeboxedvalid-signed${apos}\" actual &&\n>+\tgrep \"^timeboxedvalid-signed\" actual &&\n> \tgrep \"${GPGSSH_GOOD_SIGNATURE_TRUSTED}\" actual &&\n> \t! grep \"${GPGSSH_BAD_SIGNATURE}\" actual\n> '\n>@@ -194,6 +201,7 @@ test_expect_success GPGSSH,GPGSSH_VERIFYTIME 'message for merging local tag sign\n> \tgit fetch . timeboxedinvalid-signed &&\n> \tgit fmt-merge-msg <.git/FETCH_HEAD >actual &&\n> \tgrep \"^Merge tag ${apos}timeboxedinvalid-signed${apos}\" actual &&\n>+\tgrep \"^timeboxedinvalid-signed\" actual &&\n> \t! grep \"${GPGSSH_GOOD_SIGNATURE_TRUSTED}\" actual\n> '\n>\n>--\n>2.34.1.455.gd6eb6fd089\n"},{"id":"445924","messageId":"Yd2lU/ecNx1uIt7Q@nand.local","threadId":"57217","inReplyTo":"20220111084115.esuyxeopdpaq7g7y@fs","subject":"Re: [PATCH] fmt-merge-msg: prevent use-after-free with signed tags","fromName":"Taylor Blau","fromEmail":"me@ttaylorr.com","sentAt":"2022-01-11T15:42:11Z","receivedAt":"2022-01-11T15:42:15Z","isPatch":true,"sender":{"key":"me@ttaylorr.com","avatar":"https://avatars.githubusercontent.com/u/301000140?v=4"},"body":"On Tue, Jan 11, 2022 at 09:41:15AM +0100, Fabian Stelzer wrote:\n> fmt_merge_msg_sigs() could probably use some additional refactoring to avoid\n> these multiple pointers to the same (detached) buffer. But thats for another\n> time.\n\nI thought similarly when trying to looking at the original bisection.\nBut now that we're in the release candidate phase, I figure that any\nless-than-minimal fix was liable to cause more harm than good.\n\nIt is worth looking at in the future, though.\n\nThanks,\nTaylor\n"}]}