git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v4 6/7] ssh signing: make fmt-merge-msg consider key lifetime

From
SZEDER Gábor <szeder.dev@gmail.com>
Date
Dec 5, 2021, 19:23 UTC
Message-ID
<20211205192344.GB624717@szeder.dev>
In-Reply-To
<20211130141112.78193-7-fs@gigacodes.de>
On Tue, Nov 30, 2021 at 03:11:11PM +0100, Fabian Stelzer wrote:
Show 42 quoted lines
> diff --git a/t/t6200-fmt-merge-msg.sh b/t/t6200-fmt-merge-msg.sh
> index 06c5fb5615..2dd2423643 100755
> --- a/t/t6200-fmt-merge-msg.sh
> +++ b/t/t6200-fmt-merge-msg.sh
> @@ -91,6 +91,26 @@ test_expect_success GPGSSH 'created ssh signed commit and tag' '
>  	git tag -s -u"${GPGSSH_KEY_UNTRUSTED}" -m signed-ssh-tag-msg-untrusted signed-untrusted-ssh-tag left
>  '
>  
> +test_expect_success GPGSSH,GPGSSH_VERIFYTIME 'create signed tags with keys having defined lifetimes' '
> +	test_when_finished "test_unconfig commit.gpgsign" &&
> +	test_config gpg.format ssh &&
> +	git checkout -b signed-expiry-ssh &&
> +	touch file &&
> +	git add file &&
> +
> +	echo expired >file && test_tick && git commit -a -m expired -S"${GPGSSH_KEY_EXPIRED}" &&
> +	git tag -s -u "${GPGSSH_KEY_EXPIRED}" -m expired-signed expired-signed &&
> +
> +	echo notyetvalid >file && test_tick && git commit -a -m notyetvalid -S"${GPGSSH_KEY_NOTYETVALID}" &&
> +	git tag -s -u "${GPGSSH_KEY_NOTYETVALID}" -m notyetvalid-signed notyetvalid-signed &&
> +
> +	echo timeboxedvalid >file && test_tick && git commit -a -m timeboxedvalid -S"${GPGSSH_KEY_TIMEBOXEDVALID}" &&
> +	git tag -s -u "${GPGSSH_KEY_TIMEBOXEDVALID}" -m timeboxedvalid-signed timeboxedvalid-signed &&
> +
> +	echo timeboxedinvalid >file && test_tick && git commit -a -m timeboxedinvalid -S"${GPGSSH_KEY_TIMEBOXEDINVALID}" &&
> +	git tag -s -u "${GPGSSH_KEY_TIMEBOXEDINVALID}" -m timeboxedinvalid-signed timeboxedinvalid-signed
> +'
> +
>  test_expect_success 'message for merging local branch' '
>  	echo "Merge branch ${apos}left${apos}" >expected &&
>  
> @@ -137,6 +157,40 @@ test_expect_success GPGSSH 'message for merging local tag signed by unknown ssh
>  	! grep "${GPGSSH_BAD_SIGNATURE}" actual &&
>  	grep "${GPGSSH_KEY_NOT_TRUSTED}" actual
>  '
> +
> +test_expect_success GPGSSH,GPGSSH_VERIFYTIME 'message for merging local tag signed by expired ssh key' '
> +	test_config gpg.ssh.allowedSignersFile "${GPGSSH_ALLOWED_SIGNERS}" &&
> +	git checkout main &&
> +	git fetch . expired-signed &&
> +	git fmt-merge-msg <.git/FETCH_HEAD >actual 2>&1 &&
> +	! grep "${GPGSSH_GOOD_SIGNATURE_TRUSTED}" actual

Are these messages supposed to go to standard output or error? If it's the former, then please drop the unnecessary (and confusing) '2>&1' redirection, but if it's the latter, then save and 'grep' only stderr.

Show 33 quoted lines
> +'
> +
> +test_expect_success GPGSSH,GPGSSH_VERIFYTIME 'message for merging local tag signed by not yet valid ssh key' '
> +	test_config gpg.ssh.allowedSignersFile "${GPGSSH_ALLOWED_SIGNERS}" &&
> +	git checkout main &&
> +	git fetch . notyetvalid-signed &&
> +	git fmt-merge-msg <.git/FETCH_HEAD >actual 2>&1 &&
> +	! grep "${GPGSSH_GOOD_SIGNATURE_TRUSTED}" actual
> +'
> +
> +test_expect_success GPGSSH,GPGSSH_VERIFYTIME 'message for merging local tag signed by valid timeboxed ssh key' '
> +	test_config gpg.ssh.allowedSignersFile "${GPGSSH_ALLOWED_SIGNERS}" &&
> +	git checkout main &&
> +	git fetch . timeboxedvalid-signed &&
> +	git fmt-merge-msg <.git/FETCH_HEAD >actual 2>&1 &&
> +	grep "${GPGSSH_GOOD_SIGNATURE_TRUSTED}" actual &&
> +	! grep "${GPGSSH_BAD_SIGNATURE}" actual
> +'
> +
> +test_expect_success GPGSSH,GPGSSH_VERIFYTIME 'message for merging local tag signed by invalid timeboxed ssh key' '
> +	test_config gpg.ssh.allowedSignersFile "${GPGSSH_ALLOWED_SIGNERS}" &&
> +	git checkout main &&
> +	git fetch . timeboxedinvalid-signed &&
> +	git fmt-merge-msg <.git/FETCH_HEAD >actual 2>&1 &&
> +	! grep "${GPGSSH_GOOD_SIGNATURE_TRUSTED}" actual
> +'
> +
>  test_expect_success 'message for merging external branch' '
>  	echo "Merge branch ${apos}left${apos} of $(pwd)" >expected &&
>  
> -- 
> 2.31.1
> 
Previous: Fabian StelzerNext: Fabian Stelzer
Message 23 of 60 in “ssh signing: verify key lifetime”
  1. 0/6 ssh signing: verify key lifetimeFabian Stelzer, Oct 27, 2021
  2. 1/6 ssh signing: use sigc struct to pass payloadFabian Stelzer, Oct 27, 2021
  3. 2/6 ssh signing: add key lifetime test prereqsFabian Stelzer, Oct 27, 2021
  4. 3/6 ssh signing: make verify-commit consider key lifetimeFabian Stelzer, Oct 27, 2021
  5. Junio C HamanoOct 27, 2021
  6. Fabian StelzerOct 28, 2021
  7. 0/7 ssh signing: verify key lifetimeFabian Stelzer, Nov 17, 2021
  8. 1/7 ssh signing: use sigc struct to pass payloadFabian Stelzer, Nov 17, 2021
  9. 2/7 ssh signing: add key lifetime test prereqsFabian Stelzer, Nov 17, 2021
  10. 3/7 ssh signing: make verify-commit consider key lifetimeFabian Stelzer, Nov 17, 2021
  11. 4/7 ssh signing: make git log verify key lifetimeFabian Stelzer, Nov 17, 2021
  12. 5/7 ssh signing: make verify-tag consider key lifetimeFabian Stelzer, Nov 17, 2021
  13. 6/7 ssh signing: make fmt-merge-msg consider key lifetimeFabian Stelzer, Nov 17, 2021
  14. 7/7 ssh signing: verify ssh-keygen in test prereqFabian Stelzer, Nov 17, 2021
  15. Junio C HamanoNov 19, 2021
  16. 0/7 ssh signing: verify key lifetimeFabian Stelzer, Nov 30, 2021
  17. 1/7 ssh signing: use sigc struct to pass payloadFabian Stelzer, Nov 30, 2021
  18. 2/7 ssh signing: add key lifetime test prereqsFabian Stelzer, Nov 30, 2021
  19. 3/7 ssh signing: make verify-commit consider key lifetimeFabian Stelzer, Nov 30, 2021
  20. 4/7 ssh signing: make git log verify key lifetimeFabian Stelzer, Nov 30, 2021
  21. 5/7 ssh signing: make verify-tag consider key lifetimeFabian Stelzer, Nov 30, 2021
  22. 6/7 ssh signing: make fmt-merge-msg consider key lifetimeFabian Stelzer, Nov 30, 2021
  23. SZEDER GáborDec 5, 2021
  24. Fabian StelzerDec 8, 2021
  25. 7/7 ssh signing: verify ssh-keygen in test prereqFabian Stelzer, Nov 30, 2021
  26. Junio C HamanoDec 2, 2021
  27. Fabian StelzerDec 2, 2021
  28. Junio C HamanoDec 2, 2021
  29. Ævar Arnfjörð BjarmasonDec 3, 2021
  30. Fabian StelzerDec 3, 2021
  31. Junio C HamanoDec 3, 2021
  32. 0/8 ssh signing: verify key lifetimeFabian Stelzer, Dec 8, 2021
  33. 1/8 ssh signing: use sigc struct to pass payloadFabian Stelzer, Dec 8, 2021
  34. 2/8 ssh signing: add key lifetime test prereqsFabian Stelzer, Dec 8, 2021
  35. 3/8 ssh signing: make verify-commit consider key lifetimeFabian Stelzer, Dec 8, 2021
  36. 4/8 ssh signing: make git log verify key lifetimeFabian Stelzer, Dec 8, 2021
  37. 5/8 ssh signing: make verify-tag consider key lifetimeFabian Stelzer, Dec 8, 2021
  38. 6/8 ssh signing: make fmt-merge-msg consider key lifetimeFabian Stelzer, Dec 8, 2021
  39. 7/8 ssh signing: verify ssh-keygen in test prereqFabian Stelzer, Dec 8, 2021
  40. 8/8 t/fmt-merge-msg: make gpg/ssh tests more specificFabian Stelzer, Dec 8, 2021
  41. Junio C HamanoDec 8, 2021
  42. Fabian StelzerDec 9, 2021
  43. 0/9 ssh signing: verify key lifetimeFabian Stelzer, Dec 9, 2021
  44. 2/9 t/fmt-merge-msg: make gpgssh tests more specificFabian Stelzer, Dec 9, 2021
  45. 1/9 t/fmt-merge-msg: do not redirect stderrFabian Stelzer, Dec 9, 2021
  46. 3/9 ssh signing: use sigc struct to pass payloadFabian Stelzer, Dec 9, 2021
  47. 4/9 ssh signing: add key lifetime test prereqsFabian Stelzer, Dec 9, 2021
  48. 5/9 ssh signing: make verify-commit consider key lifetimeFabian Stelzer, Dec 9, 2021
  49. 6/9 ssh signing: make git log verify key lifetimeFabian Stelzer, Dec 9, 2021
  50. 7/9 ssh signing: make verify-tag consider key lifetimeFabian Stelzer, Dec 9, 2021
  51. 8/9 ssh signing: make fmt-merge-msg consider key lifetimeFabian Stelzer, Dec 9, 2021
  52. 9/9 ssh signing: verify ssh-keygen in test prereqFabian Stelzer, Dec 9, 2021
  53. 6/6 ssh signing: make fmt-merge-msg consider key lifetimeFabian Stelzer, Oct 27, 2021
  54. 4/6 ssh signing: make git log verify key lifetimeFabian Stelzer, Oct 27, 2021
  55. 5/6 ssh signing: make verify-tag consider key lifetimeFabian Stelzer, Oct 27, 2021
  56. Adam DinwoodieNov 3, 2021
  57. Fabian StelzerNov 3, 2021
  58. Adam DinwoodieNov 4, 2021
  59. Fabian StelzerNov 4, 2021
  60. Adam DinwoodieNov 4, 2021

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.