git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] gpg-interface: set trust level of missing key to "undefined"

From
Jeff King <peff@peff.net>
Date
Apr 22, 2023, 10:47 UTC
Message-ID
<20230422104758.GA2969939@coredump.intra.peff.net>
In-Reply-To
<xmqqy1mnanz8.fsf@gitster.g>
On Wed, Apr 19, 2023 at 08:30:35AM -0700, Junio C Hamano wrote:
Show 21 quoted lines
> Jeff King <peff@peff.net> writes:
> 
> > Here's the patch that I came up with, though it does not distinguish
> > between "we did not see any trust level" and "gpg told us the trust
> > level was undefined". I think that's OK. That level is still below
> > TRUST_NEVER. But if we really want to distinguish we can introduce a new
> > value for the enum.
> 
> Good.
> 
> In my zeroth draft, I added to the enum a new TRUST_FAILED = -1 to
> be used for the initialization assignment and get stringified in the
> gpg_trust_level_to_str() function, which gave us the distinction and
> made sure the enum is signed.  But in the end, I decided it was not
> worth risking upsetting the end-user scripts that assumed the
> current set of levels with a new "level" that is not known to them.
> 
> Initializing to undefined like this patch is with much less damage
> to the codebase, and existing end-user scripts are probably prepared
> to react to "undefined" already and treat it as even less trustworthy
> than the "never" ones.
One thing that I wondered about for using UNDEFINED is that we do this:
  static enum signature_trust_level configured_min_trust_level = TRUST_UNDEFINED;
which is then later compared with:
  status |= sigc->result != 'G';
  status |= sigc->trust_level < configured_min_trust_level;

So before my patch the uninitialized state is (supposedly) less than the min level, and after they are the same. For the reasons I gave in the commit message, I think that less-than comparison was already broken. And likewise, for the reasons I gave, it hopefully never matters since the result would never be 'G' in that case.

So I think it's fine, but I definitely had to stare at it for a while. This all comes from 54887b4689 (gpg-interface: add minTrustLevel as a configuration option, 2019-12-27), which does discuss some of the implications, but I think my patch is in line with the logic there.

-Peff
Previous: Junio C HamanoNext: Junio C Hamano
Message 7 of 9 in “gpg-related crash with custom formatter (BUG: gpg-interface.c:915: invalid trust level requested -1)”
  1. Rolf Eike BeerApr 18, 2023
  2. Jeff KingApr 18, 2023
  3. Jaydeep DasApr 18, 2023
  4. Junio C HamanoApr 18, 2023
  5. gpg-interface: set trust level of missing key to "undefined"Jeff King, Apr 19, 2023
  6. Junio C HamanoApr 19, 2023
  7. Jeff KingApr 22, 2023
  8. Junio C HamanoApr 24, 2023
  9. Junio C HamanoApr 18, 2023

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.