git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] t/lib-git.sh: fix ACL-related permissions failure

From
Fabian Stelzer <fs@gigacodes.de>
Date
Nov 4, 2021, 22:36 UTC
Message-ID
<20211104223633.5j556ggfga43myz5@fs>
In-Reply-To
<xmqqzgqj1yff.fsf@gitster.g>
On 04.11.2021 13:03, Junio C Hamano wrote:
Show 28 quoted lines
>Junio C Hamano <gitster@pobox.com> writes:
>
>>> This change is required in particular to avoid tests relating to SSH
>>> signing failing in Cygwin.
>>
>> ... I am not quite sure how this explains "tests relating to ssh
>> signing failing on Cygwin".  After all, this piece of code is
>> lazy_prereq, which means that ssh-keygen in this block that fails
>> (due to a less restrictive permissions) would merely mean that tests
>> that are protected with GPGSSH prerequisite will be skipped without
>> causing test failures.  After all that is the whole point of
>> computing prereq on the fly.
>
>The reason why I wondered about the above is that it can be an
>indication of another breakage, namely, that we may have tests that
>require a working ssh-keygen but are by mistake not protected with
>GPGSSH prerequisite.
>
>The test_lazy_prereq block you touched may refrain from setting the
>prerequisite on your system (due to the faulty test here that you
>touched), but if we had such unprotected tests, we still will run
>ssh signing tests and they would fail, due to the lack of the
>prerequisite.
>
>And fixing the prereq block alone will hide that other breakage, at
>least on your system.  Hence my question.
>
>Thanks.

The problem is that the ssh-keygen in the layz_prereq will succeed but might create a private key with world readable permissions. Only the remaining tests using this key will then fail with a "your private key permissions are too restrictive" like error. If we would like to make sure in the prereq that the keys actually work fine we would need to do a signing operation with them in it.

Something like the following call would be enough: echo "test" | ssh-keygen -Y sign -f $GPGSSHKEY_PRIMARY -n "git"

Not sure if we want to go that far though. The setfacl seems fine to me otherwise.

Previous: Junio C HamanoNext: Junio C Hamano
Message 4 of 28 in “t/lib-git.sh: fix ACL-related permissions failure”
  1. t/lib-git.sh: fix ACL-related permissions failureAdam Dinwoodie, Nov 4, 2021
  2. Junio C HamanoNov 4, 2021
  3. Junio C HamanoNov 4, 2021
  4. Fabian StelzerNov 4, 2021
  5. Junio C HamanoNov 5, 2021
  6. Adam DinwoodieNov 5, 2021
  7. Jeff KingNov 5, 2021
  8. Fabian StelzerNov 5, 2021
  9. Junio C HamanoNov 5, 2021
  10. Adam DinwoodieNov 5, 2021
  11. Junio C HamanoNov 5, 2021
  12. Adam DinwoodieNov 5, 2021
  13. Carlo ArenasNov 5, 2021
  14. lib-test: show failed prereq was Re: [PATCH] t/lib-git.sh: fix ACL-related permissions failureFabian Stelzer, Nov 12, 2021
  15. Junio C HamanoNov 13, 2021
  16. Fabian StelzerNov 13, 2021
  17. Jeff KingNov 5, 2021
  18. Jeff KingNov 5, 2021
  19. Junio C HamanoNov 5, 2021
  20. Ramsay JonesNov 4, 2021
  21. Adam DinwoodieNov 5, 2021
  22. Ramsay JonesNov 5, 2021
  23. t/lib-git.sh: fix ACL-related permissions failureAdam Dinwoodie, Nov 5, 2021
  24. Junio C HamanoNov 5, 2021
  25. Kerry, RichardNov 8, 2021
  26. Junio C HamanoNov 8, 2021
  27. Kerry, RichardNov 9, 2021
  28. Junio C HamanoNov 9, 2021

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.