Re: [PATCH v3 6/9] ssh signing: parse ssh-keygen output and verify signatures
- From
Gwyneth Morgan <gwymor@tilde.club>
- Date
- Jul 16, 2021, 00:07 UTC
- Message-ID
- <YPDN3Lkg9xm0WCSP@tilde.club>
- In-Reply-To
- <381a950a6e1708b3895bb9c9cb46e974e142ae64.1626264613.git.gitgitgadget@gmail.com>
On 2021-07-14 12:10:10+0000, Fabian Stelzer via GitGitGadget wrote:
Show 8 quoted lines
> + for (line = ssh_keygen_out.buf; *line; line = strchrnul(line + 1, '\n')) {
> + while (*line == '\n')
> + line++;
> + if (!*line)
> + break;
> +
> + trust_size = strcspn(line, " \n");
> + principal = xmemdupz(line, trust_size);This breaks on principals with spaces in them (principals in the allowed signers file can have spaces if surrounded by quotes). Looks like strcspn should reject "\n" instead of " \n".
BTW, thanks for working on this feature. It seems much more convenient than GPG in my testing.