git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v2] gpg-interface.c: detect and reject multiple signatures on commits

From
Tacitus Aedifex <aedifex@sdf.org>
Date
Oct 4, 2018, 22:52 UTC
Message-ID
<20181004225229.GA15236@SDF.ORG>
In-Reply-To
<20180817073441.5247-1-mgorny@gentoo.org>

I think that there is a more simple way to catch multiple signatures see below. Other than that, I like this patch.

Signed-off-by: Tacitus Aedifex <aedifex@sdf.org>
---
 gpg-interface.c | 18 ++++++++++++++++++
 1 file changed, 18 insertions(+)
diff --git a/gpg-interface.c b/gpg-interface.c
index db17d65f8..a4dba3361 100644
--- a/gpg-interface.c
+++ b/gpg-interface.c
@@ -93,6 +93,7 @@ static void parse_gpg_output(struct signature_check *sigc)
 {
 	const char *buf = sigc->gpg_status;
 	int i;
+	int multi_sig = 0;
 
 	/* Iterate over all search strings */
 	for (i = 0; i < ARRAY_SIZE(sigcheck_gpg_status); i++) {
@@ -115,6 +116,23 @@ static void parse_gpg_output(struct signature_check *sigc)
 				next = strchrnul(found, '\n');
 				sigc->signer = xmemdupz(found, next - found);
 			}
+		} else 
+			multi_sig++;
+
+		/*
+		 * GOODSIG, BADSIG, etc. can occure only once for each signature.
+		 * Therefore, if we had more than one then we're dealing with
+		 * multiple signatures. We don't support them currently and they are
+		 * rather hard to create, so something is likely probably not right
+		 * and we should reject them altogether.
+		 */
+		if (multi_sig > 1) {
+			sigc->result = 'E';
+			/* clear partial data to avoid confusion */
+			if (sigc->signer)
+				FREE_AND_NULL(sigc->signer);
+			if (sigc->key)
+				FREE_AND_NULL(sigc->key);
 		}
 	}
 }
--
2.18.0.129.ge333175
Previous: Junio C Hamano
Message 5 of 5 in “gpg-interface.c: detect and reject multiple signatures on commits”
  1. gpg-interface.c: detect and reject multiple signatures on commitsMichał Górny, Aug 17, 2018
  2. Michał GórnyOct 3, 2018
  3. Stefan BellerOct 3, 2018
  4. Junio C HamanoOct 5, 2018
  5. Tacitus AedifexOct 4, 2018

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.