git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 2/2] t/t7510-signed-commit.sh: add signing subkey to Eris Discordia key

From
Michał Górny <mgorny@gentoo.org>
Date
Nov 5, 2018, 04:09 UTC
Message-ID
<1541390965.763.2.camel@gentoo.org>
In-Reply-To
<xmqqo9b4l4a6.fsf@gitster-ct.c.googlers.com>
On Mon, 2018-11-05 at 10:08 +0900, Junio C Hamano wrote:
Show 26 quoted lines
> Michał Górny <mgorny@gentoo.org> writes:
> 
> > > It's my understanding that GnuPG will use the most recent subkey
> > > suitable for a particular purpose, and I think the test relies on that
> > > behavior.  However, I'm not sure that's documented.  Do we want to rely
> > > on that behavior or be more explicit?  (This is a question, not an
> > > opinion.)
> > 
> > To be honest, I don't recall which suitable subkey is used.  However, it
> > definitely will prefer a subkey with signing capabilities over
> > the primary key if one is present, and this is well-known and expected
> > behavior.
> > 
> > In fact, if you have a key with two signing subkeys A and B and it
> > considers A better, then even if you explicitly pass keyid of B, it will
> > use A.  To force another subkey you have to append '!' to keyid.
> > 
> > Therefore, I think this is a behavior we can rely on.
> 
> I didn't check how the signing key configuration is done in the test
> sript (which is outside the patch context), but do you mean that we
> create these signed objects by specifying which key to use with a
> keyid with "!"  appended?  If so I agree that would make sense,
> because we would then know which subkey should be used for signing
> and checking with %GF/%GP would be a good way to do so.
> 

No, we don't have duplicate subkeys to be required to use that. Some of the tests use explicit '-S<keyid>' to force using the other key; other seem to use a default key (I can't find a place where the default would be set, so I suppose it's GnuPG default).

-- 
Best regards,
Michał Górny
Previous: Junio C Hamano
Message 6 of 6 in “t/t7510-signed-commit.sh: Add %GP to custom format checks”
  1. 1/2 t/t7510-signed-commit.sh: Add %GP to custom format checksMichał Górny, Nov 4, 2018
  2. 2/2 t/t7510-signed-commit.sh: add signing subkey to Eris Discordia keyMichał Górny, Nov 4, 2018
  3. brian m. carlsonNov 4, 2018
  4. Michał GórnyNov 4, 2018
  5. Junio C HamanoNov 5, 2018
  6. Michał GórnyNov 5, 2018

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.