{"thread":{"id":"64341","subject":"t7528-signed-commit-ssh.sh fails due to ssh-agent fails to start with ENAMETOOLONG","startedAt":"2025-10-17T01:52:43Z","lastAt":"2025-10-18T09:56:08Z","messageCount":9,"participants":["Xi Ruoyao","Collin Funk","Jeff King","Lauri Tirkkonen","Junio C Hamano","brian m. carlson"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"529034","messageId":"4e2952e512afc780b621d2c153b3e6e4eb7ed89a.camel@xry111.site","threadId":"64341","inReplyTo":null,"subject":"t7528-signed-commit-ssh.sh fails due to ssh-agent fails to start with ENAMETOOLONG","fromName":"Xi Ruoyao","fromEmail":"xry111@xry111.site","sentAt":"2025-10-17T01:52:32Z","receivedAt":"2025-10-17T01:52:43Z","isPatch":false,"sender":{"key":"xry111@xry111.site","avatar":null},"body":"Hi,\n\nWhen I test git-2.51.1 I hit a test failure in t7528-signed-commit-\nssh.sh.  Running it with -v reveals:\n\nunix_listener_tmp: path \"/home/xry111/sources/12.5/git-2.51.1/t/trash directory.t7528-signed-commit-ssh/.ssh/agent/s.fTyCxA5V6V.agent.dX2yNWQUX5\" too long for Unix domain socket\nmain: Couldn't prepare agent socket\n\nSo this seems an issue in the test harness.  Is it possible to fix it?\n\n-- \nXi Ruoyao <xry111@xry111.site>\n"},{"id":"529035","messageId":"87o6q6nux7.fsf@gmail.com","threadId":"64341","inReplyTo":"4e2952e512afc780b621d2c153b3e6e4eb7ed89a.camel@xry111.site","subject":"Re: t7528-signed-commit-ssh.sh fails due to ssh-agent fails to start with ENAMETOOLONG","fromName":"Collin Funk","fromEmail":"collin.funk1@gmail.com","sentAt":"2025-10-17T02:06:44Z","receivedAt":"2025-10-17T02:06:47Z","isPatch":false,"sender":{"key":"collin.funk1@gmail.com","avatar":"https://avatars.githubusercontent.com/u/65689063?v=4"},"body":"Hi Xi,\n\nXi Ruoyao <xry111@xry111.site> writes:\n\n> When I test git-2.51.1 I hit a test failure in t7528-signed-commit-\n> ssh.sh.  Running it with -v reveals:\n>\n> unix_listener_tmp: path \"/home/xry111/sources/12.5/git-2.51.1/t/trash directory.t7528-signed-commit-ssh/.ssh/agent/s.fTyCxA5V6V.agent.dX2yNWQUX5\" too long for Unix domain socket\n> main: Couldn't prepare agent socket\n>\n> So this seems an issue in the test harness.  Is it possible to fix it?\n\nUnix sockets have an unfortunate historical limit of ~100 characters on\nmost systems. All the derivatives of 4.4BSD have a limit of 104\ncharacters. Linux has a limit of 108 characters [1]. AIX is nice and\nsupports 1024 characters, but I assume you are not using that.\n\nI guess this test can check for that error. I'll have a look.\n\nCollin\n\n[1] https://github.com/torvalds/linux/blob/98ac9cc4b4452ed7e714eddc8c90ac4ae5da1a09/include/uapi/linux/un.h#L7\n"},{"id":"529042","messageId":"20251017070912.GA4068463@coredump.intra.peff.net","threadId":"64341","inReplyTo":"87o6q6nux7.fsf@gmail.com","subject":"Re: t7528-signed-commit-ssh.sh fails due to ssh-agent fails to start with ENAMETOOLONG","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2025-10-17T07:09:12Z","receivedAt":"2025-10-17T07:09:17Z","isPatch":false,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Thu, Oct 16, 2025 at 07:06:44PM -0700, Collin Funk wrote:\n\n> Xi Ruoyao <xry111@xry111.site> writes:\n> \n> > When I test git-2.51.1 I hit a test failure in t7528-signed-commit-\n> > ssh.sh.  Running it with -v reveals:\n> >\n> > unix_listener_tmp: path \"/home/xry111/sources/12.5/git-2.51.1/t/trash directory.t7528-signed-commit-ssh/.ssh/agent/s.fTyCxA5V6V.agent.dX2yNWQUX5\" too long for Unix domain socket\n> > main: Couldn't prepare agent socket\n> >\n> > So this seems an issue in the test harness.  Is it possible to fix it?\n> \n> Unix sockets have an unfortunate historical limit of ~100 characters on\n> most systems. All the derivatives of 4.4BSD have a limit of 104\n> characters. Linux has a limit of 108 characters [1]. AIX is nice and\n> supports 1024 characters, but I assume you are not using that.\n> \n> I guess this test can check for that error. I'll have a look.\n\nGit's internal unix-domain socket code checks the name against\nsizeof(sa->sun_path) and will temporarily chdir into the surrounding\ndirectory and use a relative path if necessary.\n\nThe errors above aren't from Git, so presumably they're from ssh-agent\nitself, which is pulling the name from the $HOME we set in test-lib.sh.\nSo probably we could use the same trick like:\n\ndiff --git a/t/t7528-signed-commit-ssh.sh b/t/t7528-signed-commit-ssh.sh\nindex 0f887a3ebe..214908b2eb 100755\n--- a/t/t7528-signed-commit-ssh.sh\n+++ b/t/t7528-signed-commit-ssh.sh\n@@ -82,7 +82,7 @@ test_expect_success GPGSSH 'create signed commits' '\n test_expect_success GPGSSH 'sign commits using literal public keys with ssh-agent' '\n \ttest_when_finished \"test_unconfig commit.gpgsign\" &&\n \ttest_config gpg.format ssh &&\n-\teval $(ssh-agent) &&\n+\teval $(ssh-agent -a ./agent.sock) &&\n \ttest_when_finished \"kill ${SSH_AGENT_PID}\" &&\n \ttest_when_finished \"test_unconfig user.signingkey\" &&\n \tmkdir tmpdir &&\n\nBut that does mean that ssh-agent will produce:\n\n  SSH_AUTH_SOCK=./agent.sock\n\nwhich is only valid from that directory. If we wanted to protect\nourselves, we'd have to further set SSH_AUTH_SOCK to the full\n$PWD/agent.sock. But I'd guess that just pushes the error onto ssh-add\ntrying to connect later with the full pathname. Using the relative path\ndoes seem to work for me, at least insofar as:\n\n  ./t7528-signed-commit-ssh.sh --run=1-2 -v -x -i \\\n    --root=/tmp/holy-smokes-this-is-a-really-long-pathname\n\ntriggers the length issue before but not after.\n\nBut looking at this test, there's something even more funky going on.\nOur $HOME will always have a space in it, because no matter where you\nset the root, we will create \"trash directory.t7582...\" to work in. But\nAFAICT, ssh-agent does not quote the path in its output. So for example:\n\n  d='/tmp/has spaces'\n  mkdir \"$d\"\n  HOME=$d ssh-agent\n\nwill produce:\n\n  SSH_AUTH_SOCK=/tmp/has spaces/.ssh/agent/s.IcPuGe26YY.agent.6PtD3uhM4O; export SSH_AUTH_SOCK;\n\nwhich is nonsense to eval. And indeed, the \"working\" version of this\ntest (without a really long root path) produces:\n\n  ./t7528-signed-commit-ssh.sh: 1: eval: directory.t7528-signed-commit-ssh/.ssh/agent/s.IcPuGe26YY.agent.sOzoazWiDc: not found\n\nI expected that would cause ssh-add to fail, since our SSH_AUTH_SOCK\nwould point to truncated garbage, and we can't talk to the agent. But it\ndoesn't even do that. The extra space turns that line from a variable\nassignment into a one-shot variable attached to a command that fails to\nrun. And so we're left with the original SSH_AUTH_SOCK from the\nenvironment, the one in my real $HOME outside of the trash directory.\nYikes!\n\nIf I unset SSH_AUTH_SOCK in my environment, then the test consistently\nfails. But I'm somewhat amazed that nobody has complained about this\nbefore. Surely somebody somewhere (especially CI!) is running t7528\nwithout SSH_AUTH_SOCK set in the environment. Which makes wonder if I'm\nmissing something.\n\n-Peff\n"},{"id":"529052","messageId":"aPIR8fB4w5Jkeiq2@mail.hacktheplanet.fi","threadId":"64341","inReplyTo":"20251017070912.GA4068463@coredump.intra.peff.net","subject":"Re: t7528-signed-commit-ssh.sh fails due to ssh-agent fails to start with ENAMETOOLONG","fromName":"Lauri Tirkkonen","fromEmail":"lauri@hacktheplanet.fi","sentAt":"2025-10-17T09:52:49Z","receivedAt":"2025-10-17T09:53:01Z","isPatch":false,"sender":{"key":"lauri@hacktheplanet.fi","avatar":null},"body":"Hi Jeff,\n\nOn Fri, Oct 17 2025 03:09:12 -0400, Jeff King wrote:\n> But looking at this test, there's something even more funky going on.\n> Our $HOME will always have a space in it, because no matter where you\n> set the root, we will create \"trash directory.t7582...\" to work in. But\n> AFAICT, ssh-agent does not quote the path in its output. So for example:\n> \n>   d='/tmp/has spaces'\n>   mkdir \"$d\"\n>   HOME=$d ssh-agent\n> \n> will produce:\n> \n>   SSH_AUTH_SOCK=/tmp/has spaces/.ssh/agent/s.IcPuGe26YY.agent.6PtD3uhM4O; export SSH_AUTH_SOCK;\n> \n> which is nonsense to eval. And indeed, the \"working\" version of this\n> test (without a really long root path) produces:\n> \n>   ./t7528-signed-commit-ssh.sh: 1: eval: directory.t7528-signed-commit-ssh/.ssh/agent/s.IcPuGe26YY.agent.sOzoazWiDc: not found\n> \n> I expected that would cause ssh-add to fail, since our SSH_AUTH_SOCK\n> would point to truncated garbage, and we can't talk to the agent. But it\n> doesn't even do that. The extra space turns that line from a variable\n> assignment into a one-shot variable attached to a command that fails to\n> run. And so we're left with the original SSH_AUTH_SOCK from the\n> environment, the one in my real $HOME outside of the trash directory.\n> Yikes!\n> \n> If I unset SSH_AUTH_SOCK in my environment, then the test consistently\n> fails. But I'm somewhat amazed that nobody has complained about this\n> before. Surely somebody somewhere (especially CI!) is running t7528\n> without SSH_AUTH_SOCK set in the environment. Which makes wonder if I'm\n> missing something.\n\nI believe the issue surfaced only now because prior to OpenSSH 10.1,\nssh-agent would put its socket in /tmp by default, not under $HOME. See\nhttps://www.openssh.com/txt/release-10.1\n\nWe saw this failure in CI on Alpine Linux and worked around by adding -T\nto the ssh-agent invocation in this test, but I suppose that won't work\nfor earlier releases of OpenSSH.\nhttps://gitlab.alpinelinux.org/alpine/aports/-/commit/81a159c8a371c871c1cd0f212881a757160632fb\n\n-- \nLauri Tirkkonen | lotheac @ IRCnet\n"},{"id":"529060","messageId":"20251017105400.GB1015973@coredump.intra.peff.net","threadId":"64341","inReplyTo":"aPIR8fB4w5Jkeiq2@mail.hacktheplanet.fi","subject":"Re: t7528-signed-commit-ssh.sh fails due to ssh-agent fails to start with ENAMETOOLONG","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2025-10-17T10:54:00Z","receivedAt":"2025-10-17T10:54:02Z","isPatch":false,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Fri, Oct 17, 2025 at 06:52:49PM +0900, Lauri Tirkkonen wrote:\n\n> > If I unset SSH_AUTH_SOCK in my environment, then the test consistently\n> > fails. But I'm somewhat amazed that nobody has complained about this\n> > before. Surely somebody somewhere (especially CI!) is running t7528\n> > without SSH_AUTH_SOCK set in the environment. Which makes wonder if I'm\n> > missing something.\n> \n> I believe the issue surfaced only now because prior to OpenSSH 10.1,\n> ssh-agent would put its socket in /tmp by default, not under $HOME. See\n> https://www.openssh.com/txt/release-10.1\n\nAh, of course. That explains it perfectly, thanks. So we're going to get\nlots more reports as people upgrade. :)\n\n> We saw this failure in CI on Alpine Linux and worked around by adding -T\n> to the ssh-agent invocation in this test, but I suppose that won't work\n> for earlier releases of OpenSSH.\n\nYeah. We could either do something like \"ssh-agent -T || ssh-agent\", or\nwe could go with \"ssh-agent -a\" (which has been around since 2002, but\ndoes raise the potential relative-path issue).\n\n-Peff\n"},{"id":"529085","messageId":"xmqqbjm51l3a.fsf@gitster.g","threadId":"64341","inReplyTo":"20251017070912.GA4068463@coredump.intra.peff.net","subject":"Re: t7528-signed-commit-ssh.sh fails due to ssh-agent fails to start with ENAMETOOLONG","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2025-10-17T17:42:17Z","receivedAt":"2025-10-17T17:42:20Z","isPatch":false,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Jeff King <peff@peff.net> writes:\n\n> AFAICT, ssh-agent does not quote the path in its output. So for example:\n>\n>   d='/tmp/has spaces'\n>   mkdir \"$d\"\n>   HOME=$d ssh-agent\n>\n> will produce:\n>\n>   SSH_AUTH_SOCK=/tmp/has spaces/.ssh/agent/s.IcPuGe26YY.agent.6PtD3uhM4O; export SSH_AUTH_SOCK;\n>\n> which is nonsense to eval.\n\nSo if $d were\n\n    d='/tmp/has rm -rf in it'\n\nwould that produce some interesting side effect?\n\n> I expected that would cause ssh-add to fail, since our SSH_AUTH_SOCK\n> would point to truncated garbage, and we can't talk to the agent. But it\n> doesn't even do that. The extra space turns that line from a variable\n> assignment into a one-shot variable attached to a command that fails to\n> run. And so we're left with the original SSH_AUTH_SOCK from the\n> environment, the one in my real $HOME outside of the trash directory.\n> Yikes!\n>\n> If I unset SSH_AUTH_SOCK in my environment, then the test consistently\n> fails. But I'm somewhat amazed that nobody has complained about this\n> before. Surely somebody somewhere (especially CI!) is running t7528\n> without SSH_AUTH_SOCK set in the environment. Which makes wonder if I'm\n> missing something.\n>\n> -Peff\n"},{"id":"529092","messageId":"aPKZeqTK-tIcrfFB@fruit.crustytoothpaste.net","threadId":"64341","inReplyTo":"20251017105400.GB1015973@coredump.intra.peff.net","subject":"Re: t7528-signed-commit-ssh.sh fails due to ssh-agent fails to start with ENAMETOOLONG","fromName":"brian m. carlson","fromEmail":"sandals@crustytoothpaste.net","sentAt":"2025-10-17T19:31:06Z","receivedAt":"2025-10-17T19:31:08Z","isPatch":false,"sender":{"key":"sandals@crustytoothpaste.net","avatar":"https://avatars.githubusercontent.com/u/497054?v=4"},"body":"On 2025-10-17 at 10:54:00, Jeff King wrote:\n> On Fri, Oct 17, 2025 at 06:52:49PM +0900, Lauri Tirkkonen wrote:\n> \n> > > If I unset SSH_AUTH_SOCK in my environment, then the test consistently\n> > > fails. But I'm somewhat amazed that nobody has complained about this\n> > > before. Surely somebody somewhere (especially CI!) is running t7528\n> > > without SSH_AUTH_SOCK set in the environment. Which makes wonder if I'm\n> > > missing something.\n> > \n> > I believe the issue surfaced only now because prior to OpenSSH 10.1,\n> > ssh-agent would put its socket in /tmp by default, not under $HOME. See\n> > https://www.openssh.com/txt/release-10.1\n> \n> Ah, of course. That explains it perfectly, thanks. So we're going to get\n> lots more reports as people upgrade. :)\n\nI had not had time to properly analyze it in order to say something more\nthoughtful than \"this is broken\", but I can confirm it breaks for me on\nDebian unstable:\n\n  ERROR: ld.so: object 'libc_malloc_debug.so.0' from LD_PRELOAD cannot be preloaded (cannot open shared object file): ignored.\n  ./t7528-signed-commit-ssh.sh: 1: eval: directory.t7528-signed-commit-ssh/.ssh/agent/s.5w4CQ2109U.agent.5l0ixCaX1S: not found\n  Agent pid 1429798\n  Could not add identity \"/home/bmc/checkouts/git/t/trash directory.t7528-signed-commit-ssh/gpghome/ed25519_ssh_signing_key\": agent refused operation\n\nNote that OpenSSH in my case is broken because of the space in the\nhome directory.  I've reported that to Debian and we'll see if it gets\nfixed.  (I did mention it breaks the Git testsuite in the hopes that\nimproves the likelihood of getting it fixed.)\n\n> > We saw this failure in CI on Alpine Linux and worked around by adding -T\n> > to the ssh-agent invocation in this test, but I suppose that won't work\n> > for earlier releases of OpenSSH.\n> \n> Yeah. We could either do something like \"ssh-agent -T || ssh-agent\", or\n> we could go with \"ssh-agent -a\" (which has been around since 2002, but\n> does raise the potential relative-path issue).\n\nI think like `ssh-agent -T || ssh-agent` would be better because we know\n$HOME can be very long in our case, whereas $TMPDIR should not be\nexcessive (since presumably it worked before and other services, such as\ntmux, place their sockets there).\n-- \nbrian m. carlson (they/them)\nToronto, Ontario, CA\n"},{"id":"529121","messageId":"20251018095125.GE1060824@coredump.intra.peff.net","threadId":"64341","inReplyTo":"xmqqbjm51l3a.fsf@gitster.g","subject":"Re: t7528-signed-commit-ssh.sh fails due to ssh-agent fails to start with ENAMETOOLONG","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2025-10-18T09:51:25Z","receivedAt":"2025-10-18T09:51:26Z","isPatch":false,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Fri, Oct 17, 2025 at 10:42:17AM -0700, Junio C Hamano wrote:\n\n> Jeff King <peff@peff.net> writes:\n> \n> > AFAICT, ssh-agent does not quote the path in its output. So for example:\n> >\n> >   d='/tmp/has spaces'\n> >   mkdir \"$d\"\n> >   HOME=$d ssh-agent\n> >\n> > will produce:\n> >\n> >   SSH_AUTH_SOCK=/tmp/has spaces/.ssh/agent/s.IcPuGe26YY.agent.6PtD3uhM4O; export SSH_AUTH_SOCK;\n> >\n> > which is nonsense to eval.\n> \n> So if $d were\n> \n>     d='/tmp/has rm -rf in it'\n> \n> would that produce some interesting side effect?\n\nYep. Somewhat terrifying, though I guess if an attacker controls your\n$HOME environment variable you probably have bigger worries.\n\n-Peff\n"},{"id":"529122","messageId":"20251018095606.GF1060824@coredump.intra.peff.net","threadId":"64341","inReplyTo":"aPKZeqTK-tIcrfFB@fruit.crustytoothpaste.net","subject":"Re: t7528-signed-commit-ssh.sh fails due to ssh-agent fails to start with ENAMETOOLONG","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2025-10-18T09:56:06Z","receivedAt":"2025-10-18T09:56:08Z","isPatch":false,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Fri, Oct 17, 2025 at 07:31:06PM +0000, brian m. carlson wrote:\n\n> I had not had time to properly analyze it in order to say something more\n> thoughtful than \"this is broken\", but I can confirm it breaks for me on\n> Debian unstable:\n> \n>   ERROR: ld.so: object 'libc_malloc_debug.so.0' from LD_PRELOAD cannot be preloaded (cannot open shared object file): ignored.\n>   ./t7528-signed-commit-ssh.sh: 1: eval: directory.t7528-signed-commit-ssh/.ssh/agent/s.5w4CQ2109U.agent.5l0ixCaX1S: not found\n>   Agent pid 1429798\n>   Could not add identity \"/home/bmc/checkouts/git/t/trash directory.t7528-signed-commit-ssh/gpghome/ed25519_ssh_signing_key\": agent refused operation\n> \n> Note that OpenSSH in my case is broken because of the space in the\n> home directory.  I've reported that to Debian and we'll see if it gets\n> fixed.  (I did mention it breaks the Git testsuite in the hopes that\n> improves the likelihood of getting it fixed.)\n\nThanks, I saw your report and had nothing to add. I agree it would be\nnice if ssh-agent shell-quoted the output. I don't think there should be\nportability issues.\n\n> > Yeah. We could either do something like \"ssh-agent -T || ssh-agent\", or\n> > we could go with \"ssh-agent -a\" (which has been around since 2002, but\n> > does raise the potential relative-path issue).\n> \n> I think like `ssh-agent -T || ssh-agent` would be better because we know\n> $HOME can be very long in our case, whereas $TMPDIR should not be\n> excessive (since presumably it worked before and other services, such as\n> tmux, place their sockets there).\n\nYeah, I think \"-T\" would work fine. I just find it a bit hacky to assume\nthat a failure of \"ssh-agent -T\" is because of the \"-T\" option. We also\ncould do better at detecting errors in general. If you did not have\nssh-agent at all, then:\n\n  eval $(ssh-agent) &&\n\nwill not fail the &&-chain since its exit code is eaten in the $()\nsubstitution, and we eval an empty string. So arguably we should pull\nthis into a prereq or something that makes sure we can actually run\nssh-agent in the first place.\n\n-Peff\n"}]}