git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH 1/3] gpg-interface/gpgsm: fix for v2.3

From
Fabian Stelzer <fs@gigacodes.de>
Date
Feb 24, 2022, 10:06 UTC
Message-ID
<20220224100628.612789-1-fs@gigacodes.de>
In-Reply-To
<20220203123724.47529-1-fs@gigacodes.de>
gpgsm v2.3 changed some details about its output:
 - instead of displaying `fingerprint:` for keys it will print `sha1
   fpr:` and `sha2 fpr:`
 - some wording of errors has changed
 - signing will omit an extra debug output line before the [GNUPG]: tag

This change adjusts the gpgsm test prerequisite to work with v2.3 as well by accepting `sha1 fpr:` as well as `fingerprint:`. To make this parsing more robust switch to gpg's `--with-colons` output format. Also allow both variants of errors for unknown certs. Checking if signing was successful will now accept '[GNUPG]: SIG_CREATED' on any beginning of a line. Not just explictly the second one anymore.

Helped-By: Junio C Hamano <gitster@pobox.com>
Helped-By: Todd Zullinger <tmz@pobox.com>
---
 gpg-interface.c | 9 ++++++++-
 t/lib-gpg.sh    | 8 +++-----
 t/t4202-log.sh  | 2 +-
 3 files changed, 12 insertions(+), 7 deletions(-)
diff --git a/gpg-interface.c b/gpg-interface.c
index 17b1e44baa..94abb3090b 100644
--- a/gpg-interface.c
+++ b/gpg-interface.c
@@ -934,6 +934,7 @@ static int sign_buffer_gpg(struct strbuf *buffer, struct strbuf *signature,
 	struct child_process gpg = CHILD_PROCESS_INIT;
 	int ret;
 	size_t bottom;
+	const char *cp;
 	struct strbuf gpg_status = STRBUF_INIT;
 
 	strvec_pushl(&gpg.args,
@@ -953,7 +954,13 @@ static int sign_buffer_gpg(struct strbuf *buffer, struct strbuf *signature,
 			   signature, 1024, &gpg_status, 0);
 	sigchain_pop(SIGPIPE);
 
-	ret |= !strstr(gpg_status.buf, "\n[GNUPG:] SIG_CREATED ");
+	for (cp = gpg_status.buf;
+	     cp && (cp = strstr(cp, "[GNUPG:] SIG_CREATED "));
+	     cp++) {
+		if (cp == gpg_status.buf || cp[-1] == '\n')
+			break; /* found */
+	}
+	ret |= !cp;
 	strbuf_release(&gpg_status);
 	if (ret)
 		return error(_("gpg failed to sign the data"));
diff --git a/t/lib-gpg.sh b/t/lib-gpg.sh
index 3e7ee1386a..e997ce10ea 100644
--- a/t/lib-gpg.sh
+++ b/t/lib-gpg.sh
@@ -72,12 +72,10 @@ test_lazy_prereq GPGSM '
 		--passphrase-fd 0 --pinentry-mode loopback \
 		--import "$TEST_DIRECTORY"/lib-gpg/gpgsm_cert.p12 &&
 
-	gpgsm --homedir "${GNUPGHOME}" -K |
-	grep fingerprint: |
-	cut -d" " -f4 |
-	tr -d "\\n" >"${GNUPGHOME}/trustlist.txt" &&
+	gpgsm --homedir "${GNUPGHOME}" -K --with-colons |
+	awk -F ":" "/^(fpr|fingerprint):/ {printf \"%s S relax\\n\", \$10}" \
+		>"${GNUPGHOME}/trustlist.txt" &&
 
-	echo " S relax" >>"${GNUPGHOME}/trustlist.txt" &&
 	echo hello | gpgsm --homedir "${GNUPGHOME}" >/dev/null \
 	       -u committer@example.com -o /dev/null --sign -
 '
diff --git a/t/t4202-log.sh b/t/t4202-log.sh
index 544f0aa82e..493e376e73 100755
--- a/t/t4202-log.sh
+++ b/t/t4202-log.sh
@@ -2013,7 +2013,7 @@ test_expect_success GPGSM 'log --graph --show-signature for merged tag x509 miss
 	git merge --no-ff -m msg signed_tag_x509_nokey &&
 	GNUPGHOME=. git log --graph --show-signature -n1 plain-x509-nokey >actual &&
 	grep "^|\\\  merged tag" actual &&
-	grep "^| | gpgsm: certificate not found" actual
+	grep -Ei "^| | gpgsm:( failed to find the)? certificate:? not found" actual
 '
 
 test_expect_success GPGSM 'log --graph --show-signature for merged tag x509 bad signature' '
-- 
2.35.1
Previous: Fabian StelzerNext: Todd Zullinger
Message 15 of 24 in “gpg-interface: fix for gpgsm v2.3”
  1. gpg-interface: fix for gpgsm v2.3Fabian Stelzer, Feb 3, 2022
  2. Junio C HamanoFeb 3, 2022
  3. Todd ZullingerFeb 3, 2022
  4. Junio C HamanoFeb 3, 2022
  5. Todd ZullingerFeb 3, 2022
  6. Junio C HamanoFeb 3, 2022
  7. Fabian StelzerFeb 7, 2022
  8. Todd ZullingerFeb 7, 2022
  9. Fabian StelzerFeb 9, 2022
  10. Todd ZullingerFeb 9, 2022
  11. Fabian StelzerFeb 21, 2022
  12. Todd ZullingerFeb 23, 2022
  13. 2/3 t/lib-gpg: reload gpg components after updating trustlistFabian Stelzer, Feb 24, 2022
  14. 3/3 t/lib-gpg: kill all gpg components, not just gpg-agentFabian Stelzer, Feb 24, 2022
  15. 1/3 gpg-interface/gpgsm: fix for v2.3Fabian Stelzer, Feb 24, 2022
  16. Todd ZullingerFeb 28, 2022
  17. 1/3 gpg-interface/gpgsm: fix for v2.3Fabian Stelzer, Mar 2, 2022
  18. Junio C HamanoMar 2, 2022
  19. Fabian StelzerMar 3, 2022
  20. 1/3 gpg-interface/gpgsm: fix for v2.3Fabian Stelzer, Mar 4, 2022
  21. 3/3 t/lib-gpg: kill all gpg components, not just gpg-agentFabian Stelzer, Mar 4, 2022
  22. 2/3 t/lib-gpg: reload gpg components after updating trustlistFabian Stelzer, Mar 4, 2022
  23. 2/3 t/lib-gpg: reload gpg components after updating trustlistFabian Stelzer, Mar 2, 2022
  24. 3/3 t/lib-gpg: kill all gpg components, not just gpg-agentFabian Stelzer, Mar 2, 2022

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.