git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v2] ssh signing: return an error when signature cannot be read

From
Fabian Stelzer <fs@gigacodes.de>
Date
Oct 6, 2022, 14:19 UTC
Message-ID
<20221006141924.7rxj3ntq24hynj5t@fs>
In-Reply-To
<ce32d5c7-c62c-b27f-23fa-566cba65c383@dunelm.org.uk>
On 06.10.2022 14:05, Phillip Wood wrote:
Show 32 quoted lines
>Hi Fabian
>
>On 06/10/2022 09:28, Fabian Stelzer wrote:
>>On 04.10.2022 10:01, Phillip Wood via GitGitGadget wrote:
>>>From: Phillip Wood <phillip.wood@dunelm.org.uk>
>>>   This patch is based on maint. In the longer term the code could be
>>>   simplified by using pipes rather than tempfiles as we do for gpg.
>>>   ssh-keygen has supported reading the data to be signed from stdin and
>>>   writing the signature to stdout since it introduced signing.
>>
>>The ssh-keygen call is already using stdin for the content to sign 
>>or verify. The signature and the signing key need to be files passed 
>>as parameters to ssh-keygen. I'm not aware of any other option of 
>>providing them to it.
>
>We use stdin for the content when verifying but not when signing
>
>	strvec_pushl(&signer.args, use_format->program,
>		     "-Y", "sign",
>		     "-n", "git",
>		     "-f", ssh_signing_key_file,
>		     buffer_file->filename.buf,
>		     NULL);
>
>	sigchain_push(SIGPIPE, SIG_IGN);
>	ret = pipe_command(&signer, NULL, 0, NULL, 0, &signer_stderr, 0);
>	sigchain_pop(SIGPIPE);
>
>Note that when verifying with -Y check-novalidate there is a missing 
>call to sigchain_push(SIGPIPE, SIG_IGN) as we are passing data over 
>stdin so need to ignore SIGPIPE.
>

Hm, true. I was kinda sure it both used stdin/out. I'm short on time at the moment and can't really work on git stuff. But I hope i can at the end of the year. There's a few more todos on my list.

Cheers, Fabian

Previous: Phillip Wood
Message 6 of 6 in “ssh signing: return an error when signature cannot be read”
  1. ssh signing: return an error when signature cannot be readPhillip Wood via GitGitGadget, Oct 3, 2022
  2. Junio C HamanoOct 3, 2022
  3. ssh signing: return an error when signature cannot be readPhillip Wood via GitGitGadget, Oct 4, 2022
  4. Fabian StelzerOct 6, 2022
  5. Phillip WoodOct 6, 2022
  6. Fabian StelzerOct 6, 2022

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.