{"thread":{"id":"58544","subject":"[PATCH] ssh signing: return an error when signature cannot be read","startedAt":"2022-10-03T09:24:50Z","lastAt":"2022-10-06T14:20:40Z","messageCount":6,"participants":["Phillip Wood via GitGitGadget","Junio C Hamano","Fabian Stelzer","Phillip Wood"],"isPatch":true,"patchVersion":1,"patchTotal":null},"messages":[{"id":"464066","messageId":"pull.1371.git.1664789075343.gitgitgadget@gmail.com","threadId":"58544","inReplyTo":null,"subject":"[PATCH] ssh signing: return an error when signature cannot be read","fromName":"Phillip Wood via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2022-10-03T09:24:35Z","receivedAt":"2022-10-03T09:24:50Z","isPatch":true,"sender":{"key":"phillip.wood@dunelm.org.uk","avatar":null},"body":"From: Phillip Wood <phillip.wood@dunelm.org.uk>\n\nIf the signature file cannot be read we print an error message but do\nnot return an error to the caller. In practice it seems unlikely that\nthe file would be unreadable if the call to ssh-keygen succeeds. If we\ncannot read the file it may be missing so ignore any errors from\nunlink() when we try to remove it.\n\nSigned-off-by: Phillip Wood <phillip.wood@dunelm.org.uk>\n---\n    ssh signing: return an error when signature cannot be read\n    \n    This patch is based on maint. In the longer term the code could be\n    simplified by using pipes rather than tempfiles as we do for gpg.\n    ssh-keygen has supported reading the data to be signed from stdin and\n    writing the signature to stdout since it introduced signing.\n\nPublished-As: https://github.com/gitgitgadget/git/releases/tag/pr-1371%2Fphillipwood%2Fssh-signing-return-error-on-missing-signature-v1\nFetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-1371/phillipwood/ssh-signing-return-error-on-missing-signature-v1\nPull-Request: https://github.com/gitgitgadget/git/pull/1371\n\n gpg-interface.c | 4 +++-\n 1 file changed, 3 insertions(+), 1 deletion(-)\n\ndiff --git a/gpg-interface.c b/gpg-interface.c\nindex 947b58ad4da..d352bc286b6 100644\n--- a/gpg-interface.c\n+++ b/gpg-interface.c\n@@ -1043,9 +1043,11 @@ static int sign_buffer_ssh(struct strbuf *buffer, struct strbuf *signature,\n \tstrbuf_addbuf(&ssh_signature_filename, &buffer_file->filename);\n \tstrbuf_addstr(&ssh_signature_filename, \".sig\");\n \tif (strbuf_read_file(signature, ssh_signature_filename.buf, 0) < 0) {\n-\t\terror_errno(\n+\t\tret = error_errno(\n \t\t\t_(\"failed reading ssh signing data buffer from '%s'\"),\n \t\t\tssh_signature_filename.buf);\n+\t\tunlink(ssh_signature_filename.buf);\n+\t\tgoto out;\n \t}\n \tunlink_or_warn(ssh_signature_filename.buf);\n \n\nbase-commit: a0feb8611d4c0b2b5d954efe4e98207f62223436\n-- \ngitgitgadget\n"},{"id":"464081","messageId":"xmqq1qroyjf3.fsf@gitster.g","threadId":"58544","inReplyTo":"pull.1371.git.1664789075343.gitgitgadget@gmail.com","subject":"Re: [PATCH] ssh signing: return an error when signature cannot be read","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2022-10-03T16:13:36Z","receivedAt":"2022-10-03T16:13:44Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"\"Phillip Wood via GitGitGadget\" <gitgitgadget@gmail.com> writes:\n\n> From: Phillip Wood <phillip.wood@dunelm.org.uk>\n>\n> If the signature file cannot be read we print an error message but do\n> not return an error to the caller. In practice it seems unlikely that\n> the file would be unreadable if the call to ssh-keygen succeeds. If we\n> cannot read the file it may be missing so ignore any errors from\n> unlink() when we try to remove it.\n\nOK.  Not removing may help diagnose what the problem is, but going\nthat route needs to add code to report what file is deliberately\nleft for inspection.  I do not know how valuable that would be to\nhelp human debuggers --- the user presumably have the original\nmaterial (e.g. a signed tag object) anyway, and the human debugger\nprobably needs to have access to both the original material and what\nis fed to the gpg-interface API.  If they are chasing a reproducible\nbug, the latter should be recreatable by the human debugger from the\nformer, so removing would not hurt the debuggability that much.\n\nOn the other hand, we can still report if the reason we cannot\nremove is not ENOENT, though.\n\nThanks.\n\n>\n> Signed-off-by: Phillip Wood <phillip.wood@dunelm.org.uk>\n> ---\n>     ssh signing: return an error when signature cannot be read\n>     \n>     This patch is based on maint. In the longer term the code could be\n>     simplified by using pipes rather than tempfiles as we do for gpg.\n>     ssh-keygen has supported reading the data to be signed from stdin and\n>     writing the signature to stdout since it introduced signing.\n>\n> Published-As: https://github.com/gitgitgadget/git/releases/tag/pr-1371%2Fphillipwood%2Fssh-signing-return-error-on-missing-signature-v1\n> Fetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-1371/phillipwood/ssh-signing-return-error-on-missing-signature-v1\n> Pull-Request: https://github.com/gitgitgadget/git/pull/1371\n>\n>  gpg-interface.c | 4 +++-\n>  1 file changed, 3 insertions(+), 1 deletion(-)\n>\n> diff --git a/gpg-interface.c b/gpg-interface.c\n> index 947b58ad4da..d352bc286b6 100644\n> --- a/gpg-interface.c\n> +++ b/gpg-interface.c\n> @@ -1043,9 +1043,11 @@ static int sign_buffer_ssh(struct strbuf *buffer, struct strbuf *signature,\n>  \tstrbuf_addbuf(&ssh_signature_filename, &buffer_file->filename);\n>  \tstrbuf_addstr(&ssh_signature_filename, \".sig\");\n>  \tif (strbuf_read_file(signature, ssh_signature_filename.buf, 0) < 0) {\n> -\t\terror_errno(\n> +\t\tret = error_errno(\n>  \t\t\t_(\"failed reading ssh signing data buffer from '%s'\"),\n>  \t\t\tssh_signature_filename.buf);\n> +\t\tunlink(ssh_signature_filename.buf);\n> +\t\tgoto out;\n>  \t}\n>  \tunlink_or_warn(ssh_signature_filename.buf);\n>  \n>\n> base-commit: a0feb8611d4c0b2b5d954efe4e98207f62223436\n"},{"id":"464116","messageId":"pull.1371.v2.git.1664877694430.gitgitgadget@gmail.com","threadId":"58544","inReplyTo":"pull.1371.git.1664789075343.gitgitgadget@gmail.com","subject":"[PATCH v2] ssh signing: return an error when signature cannot be read","fromName":"Phillip Wood via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2022-10-04T10:01:34Z","receivedAt":"2022-10-04T10:01:42Z","isPatch":true,"sender":{"key":"phillip.wood@dunelm.org.uk","avatar":null},"body":"From: Phillip Wood <phillip.wood@dunelm.org.uk>\n\nIf the signature file cannot be read we print an error message but do\nnot return an error to the caller. In practice it seems unlikely that\nthe file would be unreadable if the call to ssh-keygen succeeds.\n\nThe unlink_or_warn() call is moved to the end of the function so that\nwe always try and remove the signature file. This isn't strictly\nnecessary at the moment but it protects us against any extra code\nbeing added between trying to read the signature file and the cleanup\nat the end of the function in the future. unlink_or_warn() only prints\na warning if it exists and cannot be removed.\n\nSigned-off-by: Phillip Wood <phillip.wood@dunelm.org.uk>\n---\n    ssh signing: return an error when signature cannot be read\n    \n    Thanks to Junio for his comments. I've updated the patch to always use\n    unlink_or_warn() to remove the signature file as it does not warn on\n    missing files.\n    \n    V1 cover letter\n    \n    This patch is based on maint. In the longer term the code could be\n    simplified by using pipes rather than tempfiles as we do for gpg.\n    ssh-keygen has supported reading the data to be signed from stdin and\n    writing the signature to stdout since it introduced signing.\n\nPublished-As: https://github.com/gitgitgadget/git/releases/tag/pr-1371%2Fphillipwood%2Fssh-signing-return-error-on-missing-signature-v2\nFetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-1371/phillipwood/ssh-signing-return-error-on-missing-signature-v2\nPull-Request: https://github.com/gitgitgadget/git/pull/1371\n\nRange-diff vs v1:\n\n 1:  6f569ac0f48 ! 1:  1db8af68fce ssh signing: return an error when signature cannot be read\n     @@ Commit message\n      \n          If the signature file cannot be read we print an error message but do\n          not return an error to the caller. In practice it seems unlikely that\n     -    the file would be unreadable if the call to ssh-keygen succeeds. If we\n     -    cannot read the file it may be missing so ignore any errors from\n     -    unlink() when we try to remove it.\n     +    the file would be unreadable if the call to ssh-keygen succeeds.\n     +\n     +    The unlink_or_warn() call is moved to the end of the function so that\n     +    we always try and remove the signature file. This isn't strictly\n     +    necessary at the moment but it protects us against any extra code\n     +    being added between trying to read the signature file and the cleanup\n     +    at the end of the function in the future. unlink_or_warn() only prints\n     +    a warning if it exists and cannot be removed.\n      \n          Signed-off-by: Phillip Wood <phillip.wood@dunelm.org.uk>\n      \n     @@ gpg-interface.c: static int sign_buffer_ssh(struct strbuf *buffer, struct strbuf\n      +\t\tret = error_errno(\n       \t\t\t_(\"failed reading ssh signing data buffer from '%s'\"),\n       \t\t\tssh_signature_filename.buf);\n     -+\t\tunlink(ssh_signature_filename.buf);\n      +\t\tgoto out;\n       \t}\n     - \tunlink_or_warn(ssh_signature_filename.buf);\n     +-\tunlink_or_warn(ssh_signature_filename.buf);\n     +-\n     + \t/* Strip CR from the line endings, in case we are on Windows. */\n     + \tremove_cr_after(signature, bottom);\n       \n     +@@ gpg-interface.c: out:\n     + \t\tdelete_tempfile(&key_file);\n     + \tif (buffer_file)\n     + \t\tdelete_tempfile(&buffer_file);\n     ++\tif (ssh_signature_filename.len)\n     ++\t\tunlink_or_warn(ssh_signature_filename.buf);\n     + \tstrbuf_release(&signer_stderr);\n     + \tstrbuf_release(&ssh_signature_filename);\n     + \tFREE_AND_NULL(ssh_signing_key_file);\n\n\n gpg-interface.c | 7 ++++---\n 1 file changed, 4 insertions(+), 3 deletions(-)\n\ndiff --git a/gpg-interface.c b/gpg-interface.c\nindex 947b58ad4da..b5c2bbb3b91 100644\n--- a/gpg-interface.c\n+++ b/gpg-interface.c\n@@ -1043,12 +1043,11 @@ static int sign_buffer_ssh(struct strbuf *buffer, struct strbuf *signature,\n \tstrbuf_addbuf(&ssh_signature_filename, &buffer_file->filename);\n \tstrbuf_addstr(&ssh_signature_filename, \".sig\");\n \tif (strbuf_read_file(signature, ssh_signature_filename.buf, 0) < 0) {\n-\t\terror_errno(\n+\t\tret = error_errno(\n \t\t\t_(\"failed reading ssh signing data buffer from '%s'\"),\n \t\t\tssh_signature_filename.buf);\n+\t\tgoto out;\n \t}\n-\tunlink_or_warn(ssh_signature_filename.buf);\n-\n \t/* Strip CR from the line endings, in case we are on Windows. */\n \tremove_cr_after(signature, bottom);\n \n@@ -1057,6 +1056,8 @@ out:\n \t\tdelete_tempfile(&key_file);\n \tif (buffer_file)\n \t\tdelete_tempfile(&buffer_file);\n+\tif (ssh_signature_filename.len)\n+\t\tunlink_or_warn(ssh_signature_filename.buf);\n \tstrbuf_release(&signer_stderr);\n \tstrbuf_release(&ssh_signature_filename);\n \tFREE_AND_NULL(ssh_signing_key_file);\n\nbase-commit: a0feb8611d4c0b2b5d954efe4e98207f62223436\n-- \ngitgitgadget\n"},{"id":"464278","messageId":"20221006082817.4uxywfxjokfyml6y@fs","threadId":"58544","inReplyTo":"pull.1371.v2.git.1664877694430.gitgitgadget@gmail.com","subject":"Re: [PATCH v2] ssh signing: return an error when signature cannot be read","fromName":"Fabian Stelzer","fromEmail":"fs@gigacodes.de","sentAt":"2022-10-06T08:28:17Z","receivedAt":"2022-10-06T08:28:58Z","isPatch":true,"sender":{"key":"fs@gigacodes.de","avatar":"https://avatars.githubusercontent.com/u/564858?v=4"},"body":"On 04.10.2022 10:01, Phillip Wood via GitGitGadget wrote:\n>From: Phillip Wood <phillip.wood@dunelm.org.uk>\n>\n>If the signature file cannot be read we print an error message but do\n>not return an error to the caller. In practice it seems unlikely that\n>the file would be unreadable if the call to ssh-keygen succeeds.\n>\n>The unlink_or_warn() call is moved to the end of the function so that\n>we always try and remove the signature file. This isn't strictly\n>necessary at the moment but it protects us against any extra code\n>being added between trying to read the signature file and the cleanup\n>at the end of the function in the future. unlink_or_warn() only prints\n>a warning if it exists and cannot be removed.\n\nSounds sensible and the change looks good to me.\n\n>\n>Signed-off-by: Phillip Wood <phillip.wood@dunelm.org.uk>\n>---\n>    ssh signing: return an error when signature cannot be read\n>\n>    Thanks to Junio for his comments. I've updated the patch to always use\n>    unlink_or_warn() to remove the signature file as it does not warn on\n>    missing files.\n>\n>    V1 cover letter\n>\n>    This patch is based on maint. In the longer term the code could be\n>    simplified by using pipes rather than tempfiles as we do for gpg.\n>    ssh-keygen has supported reading the data to be signed from stdin and\n>    writing the signature to stdout since it introduced signing.\n\nThe ssh-keygen call is already using stdin for the content to sign or \nverify. The signature and the signing key need to be files passed as \nparameters to ssh-keygen. I'm not aware of any other option of providing \nthem to it.\n\nCheers,\nFabian\n\n"},{"id":"464285","messageId":"ce32d5c7-c62c-b27f-23fa-566cba65c383@dunelm.org.uk","threadId":"58544","inReplyTo":"20221006082817.4uxywfxjokfyml6y@fs","subject":"Re: [PATCH v2] ssh signing: return an error when signature cannot be read","fromName":"Phillip Wood","fromEmail":"phillip.wood123@gmail.com","sentAt":"2022-10-06T13:05:09Z","receivedAt":"2022-10-06T13:05:16Z","isPatch":true,"sender":{"key":"phillip.wood@dunelm.org.uk","avatar":null},"body":"Hi Fabian\n\nOn 06/10/2022 09:28, Fabian Stelzer wrote:\n> On 04.10.2022 10:01, Phillip Wood via GitGitGadget wrote:\n>> From: Phillip Wood <phillip.wood@dunelm.org.uk>\n>>    This patch is based on maint. In the longer term the code could be\n>>    simplified by using pipes rather than tempfiles as we do for gpg.\n>>    ssh-keygen has supported reading the data to be signed from stdin and\n>>    writing the signature to stdout since it introduced signing.\n> \n> The ssh-keygen call is already using stdin for the content to sign or \n> verify. The signature and the signing key need to be files passed as \n> parameters to ssh-keygen. I'm not aware of any other option of providing \n> them to it.\n\nWe use stdin for the content when verifying but not when signing\n\n\tstrvec_pushl(&signer.args, use_format->program,\n\t\t     \"-Y\", \"sign\",\n\t\t     \"-n\", \"git\",\n\t\t     \"-f\", ssh_signing_key_file,\n\t\t     buffer_file->filename.buf,\n\t\t     NULL);\n\n\tsigchain_push(SIGPIPE, SIG_IGN);\n\tret = pipe_command(&signer, NULL, 0, NULL, 0, &signer_stderr, 0);\n\tsigchain_pop(SIGPIPE);\n\nNote that when verifying with -Y check-novalidate there is a missing \ncall to sigchain_push(SIGPIPE, SIG_IGN) as we are passing data over \nstdin so need to ignore SIGPIPE.\n\nBest Wishes\n\nPhillip\n\n\n> Cheers,\n> Fabian\n> \n"},{"id":"464292","messageId":"20221006141924.7rxj3ntq24hynj5t@fs","threadId":"58544","inReplyTo":"ce32d5c7-c62c-b27f-23fa-566cba65c383@dunelm.org.uk","subject":"Re: [PATCH v2] ssh signing: return an error when signature cannot be read","fromName":"Fabian Stelzer","fromEmail":"fs@gigacodes.de","sentAt":"2022-10-06T14:19:24Z","receivedAt":"2022-10-06T14:20:40Z","isPatch":true,"sender":{"key":"fs@gigacodes.de","avatar":"https://avatars.githubusercontent.com/u/564858?v=4"},"body":"On 06.10.2022 14:05, Phillip Wood wrote:\n>Hi Fabian\n>\n>On 06/10/2022 09:28, Fabian Stelzer wrote:\n>>On 04.10.2022 10:01, Phillip Wood via GitGitGadget wrote:\n>>>From: Phillip Wood <phillip.wood@dunelm.org.uk>\n>>>   This patch is based on maint. In the longer term the code could be\n>>>   simplified by using pipes rather than tempfiles as we do for gpg.\n>>>   ssh-keygen has supported reading the data to be signed from stdin and\n>>>   writing the signature to stdout since it introduced signing.\n>>\n>>The ssh-keygen call is already using stdin for the content to sign \n>>or verify. The signature and the signing key need to be files passed \n>>as parameters to ssh-keygen. I'm not aware of any other option of \n>>providing them to it.\n>\n>We use stdin for the content when verifying but not when signing\n>\n>\tstrvec_pushl(&signer.args, use_format->program,\n>\t\t     \"-Y\", \"sign\",\n>\t\t     \"-n\", \"git\",\n>\t\t     \"-f\", ssh_signing_key_file,\n>\t\t     buffer_file->filename.buf,\n>\t\t     NULL);\n>\n>\tsigchain_push(SIGPIPE, SIG_IGN);\n>\tret = pipe_command(&signer, NULL, 0, NULL, 0, &signer_stderr, 0);\n>\tsigchain_pop(SIGPIPE);\n>\n>Note that when verifying with -Y check-novalidate there is a missing \n>call to sigchain_push(SIGPIPE, SIG_IGN) as we are passing data over \n>stdin so need to ignore SIGPIPE.\n>\n\nHm, true. I was kinda sure it both used stdin/out. I'm short on time at the \nmoment and can't really work on git stuff. But I hope i can at the end of \nthe year. There's a few more todos on my list.\n\nCheers,\nFabian\n\n"}]}