git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH v2] t/lib-git.sh: fix ACL-related permissions failure

From
Adam Dinwoodie <adam@dinwoodie.org>
Date
Nov 5, 2021, 19:31 UTC
Message-ID
<20211105193106.3195-1-adam@dinwoodie.org>
In-Reply-To
<20211104192533.2520-1-adam@dinwoodie.org>

As well as checking that the relevant functionality is available, the GPGSSH prerequisite check creates the SSH keys that are used by the test functions it gates. If these keys are created in a directory that has a default Access Control List, the key files can inherit those permissions.

This can result in a scenario where the private keys are created successfully, so the prerequisite check passes and the tests are run, but the key files have permissions that are too permissive, meaning OpenSSH will refuse to load them and the tests will fail.

To avoid this happening, before creating the keys, clear any default ACL set on the directory that will contain them. This step allowed to fail; if setfacl isn't present, that's a very likely indicator that the filesystem in question simply doesn't support default ACLs.

Helped-by: Fabian Stelzer <fs@gigacodes.de>
Signed-off-by: Adam Dinwoodie <adam@dinwoodie.org>
---
 t/lib-gpg.sh | 1 +
 1 file changed, 1 insertion(+)
diff --git a/t/lib-gpg.sh b/t/lib-gpg.sh
index f99ef3e859..1d8e5b5b7e 100644
--- a/t/lib-gpg.sh
+++ b/t/lib-gpg.sh
@@ -106,6 +106,7 @@ test_lazy_prereq GPGSSH '
 	test $? = 0 || exit 1;
 	mkdir -p "${GNUPGHOME}" &&
 	chmod 0700 "${GNUPGHOME}" &&
+	(setfacl -k "${GNUPGHOME}" 2>/dev/null || true) &&
 	ssh-keygen -t ed25519 -N "" -C "git ed25519 key" -f "${GPGSSH_KEY_PRIMARY}" >/dev/null &&
 	echo "\"principal with number 1\" $(cat "${GPGSSH_KEY_PRIMARY}.pub")" >> "${GPGSSH_ALLOWED_SIGNERS}" &&
 	ssh-keygen -t rsa -b 2048 -N "" -C "git rsa2048 key" -f "${GPGSSH_KEY_SECONDARY}" >/dev/null &&
-- 
2.33.0
Previous: Ramsay JonesNext: Junio C Hamano
Message 23 of 28 in “t/lib-git.sh: fix ACL-related permissions failure”
  1. t/lib-git.sh: fix ACL-related permissions failureAdam Dinwoodie, Nov 4, 2021
  2. Junio C HamanoNov 4, 2021
  3. Junio C HamanoNov 4, 2021
  4. Fabian StelzerNov 4, 2021
  5. Junio C HamanoNov 5, 2021
  6. Adam DinwoodieNov 5, 2021
  7. Jeff KingNov 5, 2021
  8. Fabian StelzerNov 5, 2021
  9. Junio C HamanoNov 5, 2021
  10. Adam DinwoodieNov 5, 2021
  11. Junio C HamanoNov 5, 2021
  12. Adam DinwoodieNov 5, 2021
  13. Carlo ArenasNov 5, 2021
  14. lib-test: show failed prereq was Re: [PATCH] t/lib-git.sh: fix ACL-related permissions failureFabian Stelzer, Nov 12, 2021
  15. Junio C HamanoNov 13, 2021
  16. Fabian StelzerNov 13, 2021
  17. Jeff KingNov 5, 2021
  18. Jeff KingNov 5, 2021
  19. Junio C HamanoNov 5, 2021
  20. Ramsay JonesNov 4, 2021
  21. Adam DinwoodieNov 5, 2021
  22. Ramsay JonesNov 5, 2021
  23. t/lib-git.sh: fix ACL-related permissions failureAdam Dinwoodie, Nov 5, 2021
  24. Junio C HamanoNov 5, 2021
  25. Kerry, RichardNov 8, 2021
  26. Junio C HamanoNov 8, 2021
  27. Kerry, RichardNov 9, 2021
  28. Junio C HamanoNov 9, 2021

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.