git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] git-tag: don't use gpg's stdin, stdout when signing tags

From
Todd Zullinger <tmz@pobox.com>
Date
Feb 20, 2009, 13:46 UTC
Message-ID
<20090220134634.GJ4505@inocybe.teonanacatl.org>
In-Reply-To
<20090220113856.6612.qmail@0bbdb5719a4668.315fe32.mid.smarden.org>
Gerrit Pape wrote:
Show 8 quoted lines
> When using gpg with some console based gpg-agent, acquiring the
> passphrase through the agent fails if stdin and stdout of gpg are
> redirected.  With this commit, git-tag uses temporary files instead
> of standard input/output when signing a tag to support such
> gpg-agent usage.
>
> The problem was reported by Loïc Minier through
> http://bugs.debian.org/507642

I sign tags using gpg-agent with the curse pinentry often and it works here. Perhaps Loïc has not set GPG_TTY as the gpg-agent documentation suggests? If I unset GPG_TTY, I get the sort of failure indicated in the bug report. With it set tag signing works as expected.

Quoting the gpg-agent docs:
  You should always add the following lines to your `.bashrc' or
  whatever initialization file is used for all shell invocations:
     GPG_TTY=`tty`
     export GPG_TTY
  It is important that this environment variable always reflects the
  output of the `tty' command.  For W32 systems this option is not
  required.
Now, I'm not sure if that's a reason not to include this patch.  :)

I just wanted to mention that it can and does work if you have GPG_TTY set. This is often needed for other tools as well, e.g. with mutt, so users of the curses pinentry are best off setting it rather than hoping individual apps work around it.

-- 
Todd        OpenPGP -> KeyID: 0xBEAF0CE3 | URL: www.pobox.com/~tmz/pgp
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Some people are like Slinkies... not really good for anything, but you
still can't help but smile when you see one tumble down the stairs.
Previous: Gerrit PapeNext: Gerrit Pape
Message 2 of 4 in “git-tag: don't use gpg's stdin, stdout when signing tags”
  1. git-tag: don't use gpg's stdin, stdout when signing tagsGerrit Pape, Feb 20, 2009
  2. Todd ZullingerFeb 20, 2009
  3. Gerrit PapeFeb 23, 2009
  4. Johannes SixtFeb 20, 2009

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.