git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 5/7] Add support for gnupg < 1.4

From
Ævar Arnfjörð Bjarmason <avarab@gmail.com>
Date
Apr 13, 2017, 15:17 UTC
Message-ID
<CACBZZX56Fx+niwwsiJeMwvaZkuR3h4zxytu+xx_sanobMPGobg@mail.gmail.com>
In-Reply-To
<CACBZZX6bYLRSUAy2GUYhBVet3tjzrBQ40L49KxetAvBdgx_x+w@mail.gmail.com>

On Wed, Apr 5, 2017 at 3:45 PM, Ævar Arnfjörð Bjarmason <avarab@gmail.com> wrote:

Show 19 quoted lines
> On Wed, Apr 5, 2017 at 3:04 PM, Tom G. Christensen <tgc@jupiterrise.com> wrote:
>> This adds an OLD_GNUPG define to the Makefile which when activated will
>> ensure git does not use the --keyid-format argument when calling the
>> 'gpg' program.
>> This is consistent with how 'gpg' was used in git < 2.10.0 and slightly
>> decreases security.
>
> This changes the code Linus Torvalds added in b624a3e67f to mitigate
> the evil32 project generating keys which looked the same for 32 bit
> signatures.
>
> I think this change makes sense, but the Makefile should have a
> slightly scarier warning, something like:
>
> "Define OLD_GNUPG if you need support for gnupg <1.4. Note that this
> will cause git to only show the first 32 bits of PGP keys instead of
> 64, and there's a wide variety of brute-forced 32 bit keys in the wild
> thanks to the evil32 project (https://evil32.com). Enabling this will
> make GPG work old versions, but you might be fooled into accepting
grammar fix: "work on older versions"....
Show 49 quoted lines
> malicious keys as a result".
>
>> Signed-off-by: Tom G. Christensen <tgc@jupiterrise.com>
>> ---
>>  Makefile        | 6 ++++++
>>  gpg-interface.c | 2 ++
>>  2 files changed, 8 insertions(+)
>>
>> diff --git a/Makefile b/Makefile
>> index ca9f16d19..f8f585d21 100644
>> --- a/Makefile
>> +++ b/Makefile
>> @@ -386,6 +386,8 @@ all::
>>  #
>>  # to say "export LESS=FRX (and LV=-c) if the environment variable
>>  # LESS (and LV) is not set, respectively".
>> +#
>> +# Define OLD_GNUPG if you need support for gnupg < 1.4.
>>
>>  GIT-VERSION-FILE: FORCE
>>         @$(SHELL_PATH) ./GIT-VERSION-GEN
>> @@ -1529,6 +1531,10 @@ ifndef PAGER_ENV
>>  PAGER_ENV = LESS=FRX LV=-c
>>  endif
>>
>> +ifdef OLD_GNUPG
>> +       BASIC_CFLAGS += -DOLD_GNUPG
>> +endif
>> +
>>  QUIET_SUBDIR0  = +$(MAKE) -C # space to separate -C and subdir
>>  QUIET_SUBDIR1  =
>>
>> diff --git a/gpg-interface.c b/gpg-interface.c
>> index e44cc27da..57f1ea792 100644
>> --- a/gpg-interface.c
>> +++ b/gpg-interface.c
>> @@ -224,7 +224,9 @@ int verify_signed_buffer(const char *payload, size_t payload_size,
>>         argv_array_pushl(&gpg.args,
>>                          gpg_program,
>>                          "--status-fd=1",
>> +#ifndef OLD_GNUPG
>>                          "--keyid-format=long",
>> +#endif
>>                          "--verify", temp.filename.buf, "-",
>>                          NULL);
>>
>> --
>> 2.12.2
>>
Previous: Junio C HamanoNext: Tom G. Christensen
Message 31 of 48 in “[RFC] dropping support for ancient versions of curl”
  1. Jeff KingApr 4, 2017
  2. Jeff KingApr 4, 2017
  3. Jessie HernandezApr 4, 2017
  4. Ævar Arnfjörð BjarmasonApr 4, 2017
  5. Jeff KingApr 4, 2017
  6. Ævar Arnfjörð BjarmasonApr 4, 2017
  7. Johannes SchindelinApr 4, 2017
  8. Ævar Arnfjörð BjarmasonApr 4, 2017
  9. Brandon WilliamsApr 4, 2017
  10. Johannes SchindelinApr 4, 2017
  11. Brandon WilliamsApr 4, 2017
  12. Stefan BellerApr 4, 2017
  13. Johannes SchindelinApr 5, 2017
  14. Jeff KingApr 5, 2017
  15. Jeff KingApr 4, 2017
  16. Frank GevaertsApr 4, 2017
  17. Tom G. ChristensenApr 5, 2017
  18. Ævar Arnfjörð BjarmasonApr 5, 2017
  19. 0/7 Patches to support older RHEL releasesTom G. Christensen, Apr 5, 2017
  20. 3/7 Allow svnrdump_sim.py to be used with Python 2.2Tom G. Christensen, Apr 5, 2017
  21. Ævar Arnfjörð BjarmasonApr 5, 2017
  22. Tom G. ChristensenApr 5, 2017
  23. 1/7 Make NO_PERL_MAKEMAKER behave more like ExtUtils::MakeMakerTom G. Christensen, Apr 5, 2017
  24. 4/7 Handle missing HTTP_CONNECTCODE in curl < 7.10.7Tom G. Christensen, Apr 5, 2017
  25. Ævar Arnfjörð BjarmasonApr 5, 2017
  26. Franke, KnutApr 5, 2017
  27. 2/7 Install man pages when NO_PERL_MAKEMAKER is usedTom G. Christensen, Apr 5, 2017
  28. 5/7 Add support for gnupg < 1.4Tom G. Christensen, Apr 5, 2017
  29. Ævar Arnfjörð BjarmasonApr 5, 2017
  30. Junio C HamanoApr 13, 2017
  31. Ævar Arnfjörð BjarmasonApr 13, 2017
  32. 6/7 Handle missing CURLINFO_SSL_DATA_{IN,OUT}Tom G. Christensen, Apr 5, 2017
  33. Ævar Arnfjörð BjarmasonApr 5, 2017
  34. 7/7 Do not use curl_easy_strerror with curl < 7.12.0Tom G. Christensen, Apr 5, 2017
  35. Ævar Arnfjörð BjarmasonApr 5, 2017
  36. Jeff KingApr 6, 2017
  37. Junio C HamanoApr 13, 2017
  38. Jacob KellerApr 13, 2017
  39. Tom G. ChristensenApr 5, 2017
  40. brian m. carlsonApr 6, 2017
  41. Todd ZullingerApr 6, 2017
  42. Jeff KingApr 6, 2017
  43. Johannes SchindelinApr 7, 2017
  44. Jeff KingApr 10, 2017
  45. Jeff KingApr 6, 2017
  46. Tom G. ChristensenApr 6, 2017
  47. Jeff KingApr 7, 2017
  48. Junio C HamanoApr 14, 2017

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.