git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: tests do not work with gpg 2.1

From
Michael J Gruber <git@drmicha.warpmail.net>
Date
Dec 2, 2014, 12:55 UTC
Message-ID
<547DB6C3.5010704@drmicha.warpmail.net>
In-Reply-To
<20141128165009.GA4728@peff.net>
Jeff King schrieb am 28.11.2014 um 17:50:
Show 16 quoted lines
> [updated subject, as this is not specific to the v2.2.0 release at all]
> 
> On Fri, Nov 28, 2014 at 10:48:51AM +0100, Michael J Gruber wrote:
> 
>> Are you running gnome_keyring_deamon by any chance? It think it runs by
>> default in Gnome, claims to offer gpg_agent functionality but does not
>> seem to do so fully. I.e., its presence may keep gpg2.1 from starting
>> its own gpg-agent. But gpg2.1 ("gnupg modern branch") needs a new
>> gpg-agent which knows how to handle secret keys for gpg2.1.
>>
>> (I may take a shot at trying, but I'm on Fedora - they're slow and
>> special in all things gpg/crypto. And compiling gpg2.1 means compiling
>> all the bits and pieces that monster consists of these days...)
> 
> I'm not running the gnome daemon (I do normally run gpg-agent, though),
> and I can reproduce.

You get the passphrase prompt, Steven didn't, if I understood correctly. You can continue successfully by hitting OK, Steven coudn't hit anything...

Show 23 quoted lines
> I wanted to try experimenting today with making sure GPG_AGENT_INFO was
> unset in the environment. But despite nothing changing (i.e., before I
> even cleared that variable), I'm getting totally different results.
> 
> Now when I run t4202, I get no agent prompt, and just:
> 
>     ok 40 - dotdot is a parent directory
>     
>     expecting success: 
>             test_when_finished "git reset --hard && git checkout master" &&
>             git checkout -b signed master &&
>             echo foo >foo &&
>             git add foo &&
>             git commit -S -m signed_commit &&
>             git log --graph --show-signature -n1 signed >actual &&
>             grep "^| gpg: Signature made" actual &&
>             grep "^| gpg: Good signature" actual
>     
>     Switched to a new branch 'signed'
>     gpg: skipped "C O Mitter <committer@example.com>": No secret key
>     gpg: signing failed: No secret key
>     error: gpg failed to sign the data
>     fatal: failed to write commit object
That is how things turned for Steven, afaik.
Show 19 quoted lines
> And then a subsequent run gives me:
> 
>     rm: cannot remove '/home/peff/compile/git/t/trash directory.t4202-log/gpghome/private-keys-v1.d/19D48118D24877F59C2AE86FEC8C3E90694B2631.key': Permission denied
>     rm: cannot remove '/home/peff/compile/git/t/trash directory.t4202-log/gpghome/private-keys-v1.d/E0C803F8BC3BCC4990E174E05936A7636E888899.key': Permission denied
>     rm: cannot remove '/home/peff/compile/git/t/trash directory.t4202-log/gpghome/private-keys-v1.d/FCFAC48BF12AC0FCC32B69AB90AA7B1891382C29.key': Permission denied
>     rm: cannot remove '/home/peff/compile/git/t/trash directory.t4202-log/gpghome/private-keys-v1.d/D50A866904B91C0C49A3F6059584F4A09807D330.key': Permission denied
>     FATAL: Cannot prepare test area
> 
> It seems that it creates the private-keys directory without the 'x' bit:
> 
>     $ ls -ld trash*/gpghome/private-keys-v1.d
>     drw------- 2 peff peff 4096 Nov 28 11:45 trash directory.t4202-log/gpghome/private-keys-v1.d/
> 
> So that's weird, and doubly so that it is behaving differently than it
> was last night. Obviously _something_ must have change. Maybe something
> related to the state of my running agent, I guess.
> 
> -Peff
> 

I think if you unset GPG_AGENT_INFO, gpg2.1 thinks there is no agent, starts it's own and talks to it via a socket directly (no env variable). Now that one seems come with different options (regarding pinentry) so that it can't even ask you for a passphrase.

That private-keys directory is from the first run of gpg2.1 on a pre-2.1 GPGHOME. It converts the old secring db to that new dir of entries and uses that instead.

Regarding the umask: That may actually be fallout from
e7f224f (t/lib-gpg: make gpghome files writable, 2014-10-24)

where I didn't expect directories to be present in gpghome. Maybe i should change

chmod 0700 gpghome chmod 0600 gpghome/*

to
chmod -R o+w gpghome/
though I felt somehow safer with the explicit permissions.
Michael
Previous: Jeff KingNext: Michael J Gruber
Message 6 of 15 in “[ANNOUNCE] Git v2.2.0”
  1. Junio C HamanoNov 26, 2014
  2. Steven NoonanNov 27, 2014
  3. Jeff KingNov 28, 2014
  4. Michael J GruberNov 28, 2014
  5. tests do not work with gpg 2.1Jeff King, Nov 28, 2014
  6. Michael J GruberDec 2, 2014
  7. t/lib-gpg: adjust permissions for gnupg 2.1Michael J Gruber, Dec 2, 2014
  8. Jeff KingDec 2, 2014
  9. Junio C HamanoDec 2, 2014
  10. Jeff KingDec 3, 2014
  11. Junio C HamanoDec 3, 2014
  12. Michael J GruberDec 3, 2014
  13. Junio C HamanoDec 3, 2014
  14. Jeff KingDec 2, 2014
  15. Jeff KingDec 2, 2014

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.