{"thread":{"id":"60141","subject":"[PATCH v2 1/1] t6300: fix match with insecure memory","startedAt":"2023-08-21T20:26:12Z","lastAt":"2023-08-23T16:14:42Z","messageCount":13,"participants":["Christian Hesse","Kousik Sanagavarapu","Junio C Hamano","Eric Sunshine"],"isPatch":true,"patchVersion":2,"patchTotal":1},"messages":[{"id":"480871","messageId":"20230821202606.49067-1-list@eworm.de","threadId":"60141","inReplyTo":"20230821222448.1524a5fc@leda.eworm.net","subject":"[PATCH v2 1/1] t6300: fix match with insecure memory","fromName":"Christian Hesse","fromEmail":"list@eworm.de","sentAt":"2023-08-21T20:25:36Z","receivedAt":"2023-08-21T20:26:12Z","isPatch":true,"sender":{"key":"list@eworm.de","avatar":"https://gravatar.com/avatar/ec9a78d63ae8bf8efdc06867449c0a3e763066c462c2c2f9f103ac4675109e14?d=mp&s=160"},"body":"From: Christian Hesse <mail@eworm.de>\n\nRunning the tests in a build environment makes gnupg print a warning:\n\ngpg: Warning: using insecure memory!\n\nThis warning breaks the match, as `head` misses one line. Let's strip\nthe line, make `head` return what is expected and fix the match.\n\nSigned-off-by: Christian Hesse <mail@eworm.de>\n---\n t/t6300-for-each-ref.sh | 5 +++--\n 1 file changed, 3 insertions(+), 2 deletions(-)\n\ndiff --git a/t/t6300-for-each-ref.sh b/t/t6300-for-each-ref.sh\nindex 5b434ab451..0f9981798e 100755\n--- a/t/t6300-for-each-ref.sh\n+++ b/t/t6300-for-each-ref.sh\n@@ -1764,12 +1764,13 @@ test_expect_success GPGSSH 'setup for signature atom using ssh' '\n \n test_expect_success GPG2 'bare signature atom' '\n \tgit verify-commit first-signed 2>out.raw &&\n-\tgrep -Ev \"checking the trustdb|PGP trust model\" out.raw >out &&\n+\tgrep -Ev \"checking the trustdb|PGP trust model|using insecure memory\" out.raw >out &&\n \thead -3 out >expect &&\n \ttail -1 out >>expect &&\n \techo  >>expect &&\n \tgit for-each-ref refs/tags/first-signed \\\n-\t\t--format=\"%(signature)\" >actual &&\n+\t\t--format=\"%(signature)\" >out.raw &&\n+\tgrep -Ev \"using insecure memory\" out.raw >actual &&\n \ttest_cmp expect actual\n '\n \n-- \n2.41.0\n\n"},{"id":"480873","messageId":"20230821222448.1524a5fc@leda.eworm.net","threadId":"60141","inReplyTo":"20230821200645.36796-1-list@eworm.de","subject":"Re: [PATCH 1/1] t6300: fix match with insecure memory","fromName":"Christian Hesse","fromEmail":"list@eworm.de","sentAt":"2023-08-21T20:24:48Z","receivedAt":"2023-08-21T20:33:59Z","isPatch":true,"sender":{"key":"list@eworm.de","avatar":"https://gravatar.com/avatar/ec9a78d63ae8bf8efdc06867449c0a3e763066c462c2c2f9f103ac4675109e14?d=mp&s=160"},"body":"Christian Hesse <list@eworm.de> on Mon, 2023/08/21 22:06:\n> From: Christian Hesse <mail@eworm.de>\n> \n> Running the tests in a build environment makes gnupg print a warning:\n> \n> gpg: Warning: using insecure memory!\n> \n> This warning breaks the match, as `head` misses one line. Let's strip\n> the line, make `head` return what is expected and fix the match.\n\nUps, my fingers are typing too fast... Of course this one was incomplete. See\nthe follow up...\n-- \nmain(a){char*c=/*    Schoene Gruesse                         */\"B?IJj;MEH\"\n\"CX:;\",b;for(a/*    Best regards             my address:    */=0;b=c[a++];)\nputchar(b-1/(/*    Chris            cc -ox -xc - && ./x    */b/42*2-3)*42);}\n"},{"id":"480919","messageId":"ZORpucPcjzm-dhjP@five231003","threadId":"60141","inReplyTo":"20230821202606.49067-1-list@eworm.de","subject":"Re: [PATCH v2 1/1] t6300: fix match with insecure memory","fromName":"Kousik Sanagavarapu","fromEmail":"five231003@gmail.com","sentAt":"2023-08-22T07:54:33Z","receivedAt":"2023-08-22T07:54:51Z","isPatch":true,"sender":{"key":"five231003@gmail.com","avatar":"https://avatars.githubusercontent.com/u/75560439?v=4"},"body":"Christian Hesse <list@eworm.de> wrote:\n\n> From: Christian Hesse <mail@eworm.de>\n> \n> Running the tests in a build environment makes gnupg print a warning:\n> \n> gpg: Warning: using insecure memory!\n>\n> This warning breaks the match, as `head` misses one line. Let's strip\n> the line, make `head` return what is expected and fix the match.\n>\n> Signed-off-by: Christian Hesse <mail@eworm.de>\n\nI think a bit of an explanation about why this warning is showing up in the\ncommit message would be good.\n\n\"man gpg\" gives me\n\n\tOn older systems this program should be installed as setuid(root).\n\tThis is necessary to lock memory  pages.  Locking  memory\n\tpages prevents the operating system from writing memory pages (which\n\tmay contain passphrases or other sensitive material) to disk. If you\n\tget no warning message about insecure memory your operating system\n\tsupports locking  without  being  root.  The program drops root\n\tprivileges as soon as locked memory is allocated.\n\n\tNote  also  that  some systems (especially laptops) have the ability to\n\t``suspend to disk'' (also known as ``safe sleep'' or ``hibernate'').\n\tThis writes all memory to disk before going into a low power or even\n\tpowered off mode.  Unless measures are taken  in  the operating system\n\tto protect the saved memory, passphrases or other sensitive material\n\tmay be recoverable from it later.\n\nSo it seems that this warning will pop up if gpg is writing memory pages to disk\nwhich is bad because as stated above we don't want these pages written to disk\nwhich is a security risk.\n\n> ---\n>  t/t6300-for-each-ref.sh | 5 +++--\n>  1 file changed, 3 insertions(+), 2 deletions(-)\n> \n> diff --git a/t/t6300-for-each-ref.sh b/t/t6300-for-each-ref.sh\n> index 5b434ab451..0f9981798e 100755\n> --- a/t/t6300-for-each-ref.sh\n> +++ b/t/t6300-for-each-ref.sh\n> @@ -1764,12 +1764,13 @@ test_expect_success GPGSSH 'setup for signature atom using ssh' '\n>  \n>  test_expect_success GPG2 'bare signature atom' '\n>  \tgit verify-commit first-signed 2>out.raw &&\n> -\tgrep -Ev \"checking the trustdb|PGP trust model\" out.raw >out &&\n> +\tgrep -Ev \"checking the trustdb|PGP trust model|using insecure memory\" out.raw >out &&\n>  \thead -3 out >expect &&\n>  \ttail -1 out >>expect &&\n>  \techo  >>expect &&\n>  \tgit for-each-ref refs/tags/first-signed \\\n> -\t\t--format=\"%(signature)\" >actual &&\n> +\t\t--format=\"%(signature)\" >out.raw &&\n> +\tgrep -Ev \"using insecure memory\" out.raw >actual &&\n>  \ttest_cmp expect actual\n>  '\n>  \n> -- \n> 2.41.0\n\nWe skip \"checking the trustdb\" and \"PGP trust model\" lines (which are not\nwarnings) here because we don't really need those from the output that GPG\nproduces here but skipping a warning too seems kind of a question mark.\n\nIt also seems that one could use \"--no-secmem-warning\" to suppress such a\nwarning. So a better place to make a change would not be in t/t6300 but in\nt/lib-gpg from where the prereq GPG2 comes from. Although I'm against this,\nbecause we don't really want to suppress any warnings.\n\nI think it is a good thing this test is breaking because it informs us about\nthe security risk. I have Cc'ed people who might have a thought on this. So\nit's better to wait for their response.\n\nThanks\n"},{"id":"480920","messageId":"20230822110404.1c002dcf@leda.eworm.net","threadId":"60141","inReplyTo":"ZORpucPcjzm-dhjP@five231003","subject":"Re: [PATCH v2 1/1] t6300: fix match with insecure memory","fromName":"Christian Hesse","fromEmail":"list@eworm.de","sentAt":"2023-08-22T09:04:04Z","receivedAt":"2023-08-22T09:04:17Z","isPatch":true,"sender":{"key":"list@eworm.de","avatar":"https://gravatar.com/avatar/ec9a78d63ae8bf8efdc06867449c0a3e763066c462c2c2f9f103ac4675109e14?d=mp&s=160"},"body":"Kousik Sanagavarapu <five231003@gmail.com> on Tue, 2023/08/22 13:24:\n> Christian Hesse <list@eworm.de> wrote:\n> \n> > From: Christian Hesse <mail@eworm.de>\n> > \n> > Running the tests in a build environment makes gnupg print a warning:\n> > \n> > gpg: Warning: using insecure memory!\n> >\n> > This warning breaks the match, as `head` misses one line. Let's strip\n> > the line, make `head` return what is expected and fix the match.\n> >\n> > Signed-off-by: Christian Hesse <mail@eworm.de>  \n> \n> I think a bit of an explanation about why this warning is showing up in the\n> commit message would be good.\n> \n> \"man gpg\" gives me <stripped>\n> \n> So it seems that this warning will pop up if gpg is writing memory pages to\n> disk which is bad because as stated above we don't want these pages written\n> to disk which is a security risk.\n\nThe Arch Linux packages are built inside a clean container, started via\nsystemd-nspawn. Within the container the system call @memlock is not allowed\nby default, for security reasons. There's an upstream systemd issue on this\ntopic:\n\nhttps://github.com/systemd/systemd/issues/9414\n\nNote this is only true at build time. If the packages are installed on the\nactual system the @memlock system call is available and things work as\nexpected without issues.\n\n> > ---\n> >  t/t6300-for-each-ref.sh | 5 +++--\n> >  1 file changed, 3 insertions(+), 2 deletions(-)\n> > \n> > diff --git a/t/t6300-for-each-ref.sh b/t/t6300-for-each-ref.sh\n> > index 5b434ab451..0f9981798e 100755\n> > --- a/t/t6300-for-each-ref.sh\n> > +++ b/t/t6300-for-each-ref.sh\n> > @@ -1764,12 +1764,13 @@ test_expect_success GPGSSH 'setup for signature\n> > atom using ssh' ' \n> >  test_expect_success GPG2 'bare signature atom' '\n> >  \tgit verify-commit first-signed 2>out.raw &&\n> > -\tgrep -Ev \"checking the trustdb|PGP trust model\" out.raw >out &&\n> > +\tgrep -Ev \"checking the trustdb|PGP trust model|using insecure\n> > memory\" out.raw >out && head -3 out >expect &&\n> >  \ttail -1 out >>expect &&\n> >  \techo  >>expect &&\n> >  \tgit for-each-ref refs/tags/first-signed \\\n> > -\t\t--format=\"%(signature)\" >actual &&\n> > +\t\t--format=\"%(signature)\" >out.raw &&\n> > +\tgrep -Ev \"using insecure memory\" out.raw >actual &&\n> >  \ttest_cmp expect actual\n> >  '\n> >  \n> > -- \n> > 2.41.0  \n> \n> We skip \"checking the trustdb\" and \"PGP trust model\" lines (which are not\n> warnings) here because we don't really need those from the output that GPG\n> produces here but skipping a warning too seems kind of a question mark.\n>\n> It also seems that one could use \"--no-secmem-warning\" to suppress such a\n> warning. So a better place to make a change would not be in t/t6300 but in\n> t/lib-gpg from where the prereq GPG2 comes from. Although I'm against this,\n> because we don't really want to suppress any warnings.\n>\n> I think it is a good thing this test is breaking because it informs us about\n> the security risk. I have Cc'ed people who might have a thought on this. So\n> it's better to wait for their response.\n\nWell, after all I just want to change the tests to succeed with our build\nenvironment, let's take a detailed look at the issue. All command below are\ninside the build environment, so including the warning about insecure memory.\n\nThe output of `git verify-commit first-signed` is:\n\n---- >8 ----\ngpg: Warning: using insecure memory!\ngpg: Signature made Tue Aug 22 08:46:43 2023 UTC\ngpg:                using DSA key 73D758744BE721698EC54E8713B6F51ECDDE430D\ngpg:                issuer \"committer@example.com\"\ngpg: checking the trustdb\ngpg: marginals needed: 3  completes needed: 1  trust model: pgp\ngpg: depth: 0  valid:   1  signed:   0  trust: 0-, 0q, 0n, 0m, 0f, 1u\ngpg: Good signature from \"C O Mitter <committer@example.com>\" [ultimate]\n---- >8 ----\n\nWhereas `git for-each-ref refs/tags/first-signed --format=\"%(signature)\"`\ngives:\n\n---- >8 ----\ngpg: Warning: using insecure memory!\ngpg: Signature made Tue Aug 22 08:46:43 2023 UTC\ngpg:                using DSA key 73D758744BE721698EC54E8713B6F51ECDDE430D\ngpg:                issuer \"committer@example.com\"\ngpg: Good signature from \"C O Mitter <committer@example.com>\" [ultimate]\n\n---- >8 ----\n\nRunning `head -3` on first output causes the warning to be included, but\nthe issuer line to be removed. That is what finally differs between `expect`\nand `actual`.\n\nJust changing the number of lines brings other issues I guess... As far as I\nknown the output on issuer was added recently with a gnupg release.\n\nSo we need a set of commands to bring the output of both command in line,\nwith or without warning on insecure memory.\n-- \nmain(a){char*c=/*    Schoene Gruesse                         */\"B?IJj;MEH\"\n\"CX:;\",b;for(a/*    Best regards             my address:    */=0;b=c[a++];)\nputchar(b-1/(/*    Chris            cc -ox -xc - && ./x    */b/42*2-3)*42);}\n"},{"id":"480922","messageId":"20230822150149.541ccb35@leda.eworm.net","threadId":"60141","inReplyTo":"20230822110404.1c002dcf@leda.eworm.net","subject":"Re: [PATCH v2 1/1] t6300: fix match with insecure memory","fromName":"Christian Hesse","fromEmail":"list@eworm.de","sentAt":"2023-08-22T13:01:49Z","receivedAt":"2023-08-22T13:01:59Z","isPatch":true,"sender":{"key":"list@eworm.de","avatar":"https://gravatar.com/avatar/ec9a78d63ae8bf8efdc06867449c0a3e763066c462c2c2f9f103ac4675109e14?d=mp&s=160"},"body":"Christian Hesse <list@eworm.de> on Tue, 2023/08/22 11:04:\n> So we need a set of commands to bring the output of both command in line,\n> with or without warning on insecure memory.\n\nI think I found a clean solution... Running a trustdb update earlier\nmakes the extra lines go away, and we do not need to filter them. See\nthe follow up...\n-- \nmain(a){char*c=/*    Schoene Gruesse                         */\"B?IJj;MEH\"\n\"CX:;\",b;for(a/*    Best regards             my address:    */=0;b=c[a++];)\nputchar(b-1/(/*    Chris            cc -ox -xc - && ./x    */b/42*2-3)*42);}\n"},{"id":"480923","messageId":"20230822130315.71259-1-list@eworm.de","threadId":"60141","inReplyTo":"20230822150149.541ccb35@leda.eworm.net","subject":"[PATCH 1/2] t/lib-gpg: forcibly run a trustdb update","fromName":"Christian Hesse","fromEmail":"list@eworm.de","sentAt":"2023-08-22T13:03:14Z","receivedAt":"2023-08-22T13:03:27Z","isPatch":true,"sender":{"key":"list@eworm.de","avatar":"https://gravatar.com/avatar/ec9a78d63ae8bf8efdc06867449c0a3e763066c462c2c2f9f103ac4675109e14?d=mp&s=160"},"body":"From: Christian Hesse <mail@eworm.de>\n\nWe want to compare output later, so randomly popping up 'gpg: checking\nthe trustdb' breaks the tests. Run the trustdb update forcibly.\n\nSigned-off-by: Christian Hesse <mail@eworm.de>\n---\n t/lib-gpg.sh | 1 +\n 1 file changed, 1 insertion(+)\n\ndiff --git a/t/lib-gpg.sh b/t/lib-gpg.sh\nindex 4eebd9c2b5..83b83c9abb 100644\n--- a/t/lib-gpg.sh\n+++ b/t/lib-gpg.sh\n@@ -45,6 +45,7 @@ test_lazy_prereq GPG '\n \t\t\t\"$TEST_DIRECTORY\"/lib-gpg/keyring.gpg &&\n \t\tgpg --homedir \"${GNUPGHOME}\" --import-ownertrust \\\n \t\t\t\"$TEST_DIRECTORY\"/lib-gpg/ownertrust &&\n+\t\tgpg --homedir \"${GNUPGHOME}\" --update-trustdb &&\n \t\tgpg --homedir \"${GNUPGHOME}\" </dev/null >/dev/null \\\n \t\t\t--sign -u committer@example.com\n \t\t;;\n-- \n2.42.0\n\n"},{"id":"480924","messageId":"20230822130315.71259-2-list@eworm.de","threadId":"60141","inReplyTo":"20230822130315.71259-1-list@eworm.de","subject":"[PATCH 2/2] t/t6300: drop magic filtering","fromName":"Christian Hesse","fromEmail":"list@eworm.de","sentAt":"2023-08-22T13:03:15Z","receivedAt":"2023-08-22T13:03:30Z","isPatch":true,"sender":{"key":"list@eworm.de","avatar":"https://gravatar.com/avatar/ec9a78d63ae8bf8efdc06867449c0a3e763066c462c2c2f9f103ac4675109e14?d=mp&s=160"},"body":"From: Christian Hesse <mail@eworm.de>\n\nNow that we ran a trustdb check forcibly it does no longer pullute the\noutput. Filtering is no longer required...\n\nSigned-off-by: Christian Hesse <mail@eworm.de>\n---\n t/t6300-for-each-ref.sh | 5 +----\n 1 file changed, 1 insertion(+), 4 deletions(-)\n\ndiff --git a/t/t6300-for-each-ref.sh b/t/t6300-for-each-ref.sh\nindex 5b434ab451..aa3c7c03c4 100755\n--- a/t/t6300-for-each-ref.sh\n+++ b/t/t6300-for-each-ref.sh\n@@ -1763,10 +1763,7 @@ test_expect_success GPGSSH 'setup for signature atom using ssh' '\n '\n \n test_expect_success GPG2 'bare signature atom' '\n-\tgit verify-commit first-signed 2>out.raw &&\n-\tgrep -Ev \"checking the trustdb|PGP trust model\" out.raw >out &&\n-\thead -3 out >expect &&\n-\ttail -1 out >>expect &&\n+\tgit verify-commit first-signed 2>expect &&\n \techo  >>expect &&\n \tgit for-each-ref refs/tags/first-signed \\\n \t\t--format=\"%(signature)\" >actual &&\n-- \n2.42.0\n\n"},{"id":"480927","messageId":"xmqqcyzfm5yp.fsf@gitster.g","threadId":"60141","inReplyTo":"20230822110404.1c002dcf@leda.eworm.net","subject":"Re: [PATCH v2 1/1] t6300: fix match with insecure memory","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2023-08-22T15:50:38Z","receivedAt":"2023-08-22T15:51:10Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Christian Hesse <list@eworm.de> writes:\n\n> Kousik Sanagavarapu <five231003@gmail.com> on Tue, 2023/08/22 13:24:\n>> Christian Hesse <list@eworm.de> wrote:\n>> \n>> > From: Christian Hesse <mail@eworm.de>\n>> > \n>> > Running the tests in a build environment makes gnupg print a warning:\n>> > \n>> > gpg: Warning: using insecure memory!\n>> >\n>> > This warning breaks the match, as `head` misses one line. Let's strip\n>> > the line, make `head` return what is expected and fix the match.\n>> >\n>> > Signed-off-by: Christian Hesse <mail@eworm.de>  \n>> \n>> I think a bit of an explanation about why this warning is showing up in the\n>> commit message would be good.\n>> \n>> \"man gpg\" gives me <stripped>\n>> \n>> So it seems that this warning will pop up if gpg is writing memory pages to\n>> disk which is bad because as stated above we don't want these pages written\n>> to disk which is a security risk.\n>\n> The Arch Linux packages are built inside a clean container, started via\n> systemd-nspawn. Within the container the system call @memlock is not allowed\n> by default, for security reasons.\n\nThanks for Kousik and Christian for discussing this.  The phrase \"in\na build environment\" in the proposed log message puzzled me, as the\nprogram does not seem to print such warning in my build environment.\n\nAnd environments where memlock is disabled are probably not limited\nto containers used to build Arch's packages.  \"in a build\nenvironment\" -> \"in an enviornment where memlock is disabled\" would\nhave avoided puzzling readers.\n\n"},{"id":"480930","messageId":"CAPig+cTFrroZGo=KOXu0aCxeJvNz7eaHAK++HXELZ0ZheJhw9w@mail.gmail.com","threadId":"60141","inReplyTo":"20230822130315.71259-2-list@eworm.de","subject":"Re: [PATCH 2/2] t/t6300: drop magic filtering","fromName":"Eric Sunshine","fromEmail":"sunshine@sunshineco.com","sentAt":"2023-08-22T16:43:22Z","receivedAt":"2023-08-22T16:43:39Z","isPatch":true,"sender":{"key":"sunshine@sunshineco.com","avatar":"https://avatars.githubusercontent.com/u/163641?v=4"},"body":"On Tue, Aug 22, 2023 at 9:03 AM Christian Hesse <list@eworm.de> wrote:\n> Now that we ran a trustdb check forcibly it does no longer pullute the\n> output. Filtering is no longer required...\n\ns/pullute/pollute/\n\n> Signed-off-by: Christian Hesse <mail@eworm.de>\n"},{"id":"480945","messageId":"20230823065300.21961-1-list@eworm.de","threadId":"60141","inReplyTo":"CAPig+cTFrroZGo=KOXu0aCxeJvNz7eaHAK++HXELZ0ZheJhw9w@mail.gmail.com","subject":"[PATCH v2 2/2] t/t6300: drop magic filtering","fromName":"Christian Hesse","fromEmail":"list@eworm.de","sentAt":"2023-08-23T06:52:17Z","receivedAt":"2023-08-23T06:53:07Z","isPatch":true,"sender":{"key":"list@eworm.de","avatar":"https://gravatar.com/avatar/ec9a78d63ae8bf8efdc06867449c0a3e763066c462c2c2f9f103ac4675109e14?d=mp&s=160"},"body":"From: Christian Hesse <mail@eworm.de>\n\nNow that we ran a trustdb check forcibly it does no longer pollute the\noutput. Filtering is no longer required...\n\nSigned-off-by: Christian Hesse <mail@eworm.de>\n---\n t/t6300-for-each-ref.sh | 5 +----\n 1 file changed, 1 insertion(+), 4 deletions(-)\n\ndiff --git a/t/t6300-for-each-ref.sh b/t/t6300-for-each-ref.sh\nindex 5b434ab451..aa3c7c03c4 100755\n--- a/t/t6300-for-each-ref.sh\n+++ b/t/t6300-for-each-ref.sh\n@@ -1763,10 +1763,7 @@ test_expect_success GPGSSH 'setup for signature atom using ssh' '\n '\n \n test_expect_success GPG2 'bare signature atom' '\n-\tgit verify-commit first-signed 2>out.raw &&\n-\tgrep -Ev \"checking the trustdb|PGP trust model\" out.raw >out &&\n-\thead -3 out >expect &&\n-\ttail -1 out >>expect &&\n+\tgit verify-commit first-signed 2>expect &&\n \techo  >>expect &&\n \tgit for-each-ref refs/tags/first-signed \\\n \t\t--format=\"%(signature)\" >actual &&\n-- \n2.42.0\n\n"},{"id":"480953","messageId":"ZOYHjwOFdFGjFm1W@five231003","threadId":"60141","inReplyTo":"20230823065300.21961-1-list@eworm.de","subject":"Re: [PATCH v2 2/2] t/t6300: drop magic filtering","fromName":"Kousik Sanagavarapu","fromEmail":"five231003@gmail.com","sentAt":"2023-08-23T13:20:15Z","receivedAt":"2023-08-23T13:22:05Z","isPatch":true,"sender":{"key":"five231003@gmail.com","avatar":"https://avatars.githubusercontent.com/u/75560439?v=4"},"body":"On Wed, Aug 23, 2023 at 08:52:17AM +0200, Christian Hesse wrote:\n> From: Christian Hesse <mail@eworm.de>\n> \n> Now that we ran a trustdb check forcibly it does no longer pollute the\n> output. Filtering is no longer required...\n\ns/forcibly/forcibly, \n\ns/it does no longer pollute/it no longer pollutes\n\nAlso, maybe instead of \"... the output.\",\n\n\t\"...the output when we encounter a signature check and hence filtering is no\n\tlonger required.\"\n\nor along similar lines.\n\n> Signed-off-by: Christian Hesse <mail@eworm.de>\n> ---\n>  t/t6300-for-each-ref.sh | 5 +----\n>  1 file changed, 1 insertion(+), 4 deletions(-)\n> \n> diff --git a/t/t6300-for-each-ref.sh b/t/t6300-for-each-ref.sh\n> index 5b434ab451..aa3c7c03c4 100755\n> --- a/t/t6300-for-each-ref.sh\n> +++ b/t/t6300-for-each-ref.sh\n> @@ -1763,10 +1763,7 @@ test_expect_success GPGSSH 'setup for signature atom using ssh' '\n>  '\n>  \n>  test_expect_success GPG2 'bare signature atom' '\n> -\tgit verify-commit first-signed 2>out.raw &&\n> -\tgrep -Ev \"checking the trustdb|PGP trust model\" out.raw >out &&\n> -\thead -3 out >expect &&\n> -\ttail -1 out >>expect &&\n> +\tgit verify-commit first-signed 2>expect &&\n>  \techo  >>expect &&\n>  \tgit for-each-ref refs/tags/first-signed \\\n>  \t\t--format=\"%(signature)\" >actual &&\n> -- \n> 2.42.0\n\nThe code looks really clean now, wow. Although I'm curious why both the changes\nweren't in a single commit. Is it because 1/2 is applicable generally and not\nonly to this specific test?\n\nThanks\n"},{"id":"480955","messageId":"xmqq8ra1hhmv.fsf@gitster.g","threadId":"60141","inReplyTo":"CAPig+cTFrroZGo=KOXu0aCxeJvNz7eaHAK++HXELZ0ZheJhw9w@mail.gmail.com","subject":"Re: [PATCH 2/2] t/t6300: drop magic filtering","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2023-08-23T16:02:00Z","receivedAt":"2023-08-23T16:02:19Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Eric Sunshine <sunshine@sunshineco.com> writes:\n\n> On Tue, Aug 22, 2023 at 9:03 AM Christian Hesse <list@eworm.de> wrote:\n>> Now that we ran a trustdb check forcibly it does no longer pullute the\n>> output. Filtering is no longer required...\n>\n> s/pullute/pollute/\n>\n>> Signed-off-by: Christian Hesse <mail@eworm.de>\n\nThanks.  Applied the typofix (with removal of the extra double-dots)\nwhile queuing.\n"},{"id":"480958","messageId":"xmqqttspg2hh.fsf@gitster.g","threadId":"60141","inReplyTo":"ZOYHjwOFdFGjFm1W@five231003","subject":"Re: [PATCH v2 2/2] t/t6300: drop magic filtering","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2023-08-23T16:14:34Z","receivedAt":"2023-08-23T16:14:42Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Kousik Sanagavarapu <five231003@gmail.com> writes:\n\n> On Wed, Aug 23, 2023 at 08:52:17AM +0200, Christian Hesse wrote:\n>> From: Christian Hesse <mail@eworm.de>\n>> \n>> Now that we ran a trustdb check forcibly it does no longer pollute the\n>> output. Filtering is no longer required...\n>\n> s/forcibly/forcibly, \n>\n> s/it does no longer pollute/it no longer pollutes\n\nThanks.  I've updated the patch locally to read like so:\n\n----- >8 -----\nFrom: Christian Hesse <mail@eworm.de>\nDate: Tue, 22 Aug 2023 15:03:15 +0200\nSubject: [PATCH] t/t6300: drop magic filtering\n\nNow that we ran a trustdb check forcibly, it no longer pollutes the\noutput, and filtering is no longer required.\n\nSigned-off-by: Christian Hesse <mail@eworm.de>\nSigned-off-by: Junio C Hamano <gitster@pobox.com>\n---\n t/t6300-for-each-ref.sh | 5 +----\n 1 file changed, 1 insertion(+), 4 deletions(-)\n\ndiff --git a/t/t6300-for-each-ref.sh b/t/t6300-for-each-ref.sh\nindex 5b434ab451..aa3c7c03c4 100755\n--- a/t/t6300-for-each-ref.sh\n+++ b/t/t6300-for-each-ref.sh\n@@ -1763,10 +1763,7 @@ test_expect_success GPGSSH 'setup for signature atom using ssh' '\n '\n \n test_expect_success GPG2 'bare signature atom' '\n-\tgit verify-commit first-signed 2>out.raw &&\n-\tgrep -Ev \"checking the trustdb|PGP trust model\" out.raw >out &&\n-\thead -3 out >expect &&\n-\ttail -1 out >>expect &&\n+\tgit verify-commit first-signed 2>expect &&\n \techo  >>expect &&\n \tgit for-each-ref refs/tags/first-signed \\\n \t\t--format=\"%(signature)\" >actual &&\n-- \n2.42.0\n\n"}]}