Re: [PATCH v3 6/9] ssh signing: parse ssh-keygen output and verify signatures
- From
Fabian Stelzer <fs@gigacodes.de>
- Date
- Jul 16, 2021, 07:00 UTC
- Message-ID
- <3d8a3221-5d28-5707-0b80-5c8a58cc23bb@gigacodes.de>
- In-Reply-To
- <YPDN3Lkg9xm0WCSP@tilde.club>
On 16.07.21 02:07, Gwyneth Morgan wrote:
Show 15 quoted lines
> On 2021-07-14 12:10:10+0000, Fabian Stelzer via GitGitGadget wrote:
>> + for (line = ssh_keygen_out.buf; *line; line = strchrnul(line + 1, '\n')) {
>> + while (*line == '\n')
>> + line++;
>> + if (!*line)
>> + break;
>> +
>> + trust_size = strcspn(line, " \n");
>> + principal = xmemdupz(line, trust_size);
> This breaks on principals with spaces in them (principals in the allowed
> signers file can have spaces if surrounded by quotes). Looks like
> strcspn should reject "\n" instead of " \n".
>
> BTW, thanks for working on this feature. It seems much more convenient
> than GPG in my testing.Oh thanks. Very nice catch. Easily fixed here but i'll have to rewrite the verification output parsing to account for this as well. I will add a testcase too.