git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v4 2/2] commit-tree: add missing --gpg-sign flag

From
MÅMartin Ågren <martin.agren@gmail.com>
Date
Jan 22, 2019, 21:43 UTC
Message-ID
<CAN0heSrSAupNkRHCsgsvMoOE7VE=yxv0MkaOi4WmZQm_2_Foaw@mail.gmail.com>
In-Reply-To
<xmqqzhrsfr4c.fsf@gitster-ct.c.googlers.com>
On Tue, 22 Jan 2019 at 20:07, Junio C Hamano <gitster@pobox.com> wrote:
Show 23 quoted lines
>
> Martin Ågren <martin.agren@gmail.com> writes:
>
> >> +       echo 11 | git commit-tree --gpg-sign HEAD^{tree} >oid &&
> >> +       test_line_count = 1 oid &&
> >> +       git tag eleventh-signed $(cat oid) &&
> >> +...
> > Let's see if there any opinions from others about this more verbose
> > construction, vs placing the oid in a variable and quoting it. We
> > obviously went several years without realizing that using $(...) as an
> > object id risked falling back to HEAD and that a completely broken `git
> > commit-tree -S` would pass the test. So being over-careful and extra
> > obvious might very well be the right thing.
>
> Sorry, but I am not sure what issue you are worried about.  If the
> "commit-tree" command failed in this construct:
>
>         oid=$(echo 11 | git commit-tree ...) &&
>         git tag eleventh-signed "$oid"
>
> wouldn't the &&-chain break after the assignment of an empty string
> to oid, skip "git tag" and make the whole test fail, with or without
> '$oid" fed to "git tag" quoted?
Yes.
> It is wrong not to quote "$oid" for
> the "git tag" command (the test should not rely on the fact that the
> object names given by "git commit-tree" have no $IFS in them), but
> that is a separate issue.

It'd also protect against a failure mode where we get no output and a zero exit code. (Maybe that's ridiculous, but we're testing `git commit-tree -S` here -- plus, I'm lazy, so I'd rather double-quote than think. ;-) )

But you asked me what issue I worried about... To recap, master has a test with a one-liner that doesn't bark if you completely drop the implementation of `git commit-tree -S`. I don't think that's the worrying that you're puzzled about.

I posted a three-line replacement that verified the exit code and quotes the output, but which also has a pretty paranoid middle step to verify that there was precisely one line of output. I then followed up with a less paranoid two-liner, which avoids some round-tripping, and which doesn't verify the line count, but which rather assumes that `git tag` will bark on a bad oid.

I think that last thing is a fair assumption, and that's why I referred to the three-line test as being over-careful and extra obvious. I'm not worrying about the quoting as such.

Martin
Previous: Junio C Hamano
Message 5 of 5 in “t7510: invoke git as part of &&-chain”
  1. 1/2 t7510: invoke git as part of &&-chainBrandon Richardson, Jan 19, 2019
  2. 2/2 commit-tree: add missing --gpg-sign flagBrandon Richardson, Jan 19, 2019
  3. Martin ÅgrenJan 20, 2019
  4. Junio C HamanoJan 22, 2019
  5. Martin ÅgrenJan 22, 2019

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.