git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v4] gpg-interface.c: detect and reject multiple signatures on commits

From
Duy Nguyen <pclouds@gmail.com>
Date
Nov 3, 2018, 15:17 UTC
Message-ID
<CACsJy8DKD3F3o74gTHW-WEL_hpB8x+oaWX8_SwN01Nmz3W9Z_w@mail.gmail.com>
In-Reply-To
<20181020193020.28517-1-mgorny@gentoo.org>
On Sat, Oct 20, 2018 at 9:31 PM Michał Górny <mgorny@gentoo.org> wrote:
Show 15 quoted lines
> +test_expect_success GPG 'detect fudged commit with double signature' '
> +       sed -e "/gpgsig/,/END PGP/d" forged1 >double-base &&
> +       sed -n -e "/gpgsig/,/END PGP/p" forged1 | \
> +               sed -e "s/^gpgsig//;s/^ //" | gpg --dearmor >double-sig1.sig &&
> +       gpg -o double-sig2.sig -u 29472784 --detach-sign double-base &&
> +       cat double-sig1.sig double-sig2.sig | gpg --enarmor >double-combined.asc &&
> +       sed -e "s/^\(-.*\)ARMORED FILE/\1SIGNATURE/;1s/^/gpgsig /;2,\$s/^/ /" \
> +               double-combined.asc > double-gpgsig &&
> +       sed -e "/committer/r double-gpgsig" double-base >double-commit &&
> +       git hash-object -w -t commit double-commit >double-commit.commit &&
> +       test_must_fail git verify-commit $(cat double-commit.commit) &&
> +       git show --pretty=short --show-signature $(cat double-commit.commit) >double-actual &&
> +       grep "BAD signature from" double-actual &&
> +       grep "Good signature from" double-actual
> +'
This test fails on 'master' today for me

gpg: WARNING: multiple signatures detected. Only the first will be checked. gpg: Signature made Sat Nov 3 15:13:28 2018 UTC gpg: using DSA key 13B6F51ECDDE430D gpg: issuer "committer@example.com" gpg: BAD signature from "C O Mitter <committer@example.com>" [ultimate] gpg: BAD signature from "C O Mitter <committer@example.com>" [ultimate] not ok 16 - detect fudged commit with double signature

Perhaps my gpg is too old?

$ gpg --version gpg (GnuPG) 2.1.15 libgcrypt 1.7.3 Copyright (C) 2016 Free Software Foundation, Inc. License GPLv3+: GNU GPL version 3 or later <https://gnu.org/licenses/gpl.html> This is free software: you are free to change and redistribute it. There is NO WARRANTY, to the extent permitted by law.

Home: /home/pclouds/.gnupg
Supported algorithms:
Pubkey: RSA, ELG, DSA, ECDH, ECDSA, EDDSA
Cipher: IDEA, 3DES, CAST5, BLOWFISH, AES, AES192, AES256, TWOFISH,
        CAMELLIA128, CAMELLIA192, CAMELLIA256
Hash: SHA1, RIPEMD160, SHA256, SHA384, SHA512, SHA224
Compression: Uncompressed, ZIP, ZLIB, BZIP2
-- 
Duy
Previous: Michał GórnyNext: Michał Górny
Message 7 of 11 in “gpg-interface.c: detect and reject multiple signatures on commits”
  1. gpg-interface.c: detect and reject multiple signatures on commitsMichał Górny, Oct 20, 2018
  2. Junio C HamanoOct 20, 2018
  3. Michał GórnyOct 21, 2018
  4. Junio C HamanoOct 22, 2018
  5. Michał GórnyOct 22, 2018
  6. Michał GórnyOct 22, 2018
  7. Duy NguyenNov 3, 2018
  8. Michał GórnyNov 3, 2018
  9. Duy NguyenNov 3, 2018
  10. Michał GórnyNov 3, 2018
  11. Duy NguyenNov 3, 2018

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.