From: Gwyneth Morgan Date: Fri, 16 Jul 2021 00:07:56 GMT Subject: Re: [PATCH v3 6/9] ssh signing: parse ssh-keygen output and verify signatures Message-ID: In-Reply-To: <381a950a6e1708b3895bb9c9cb46e974e142ae64.1626264613.git.gitgitgadget@gmail.com> On 2021-07-14 12:10:10+0000, Fabian Stelzer via GitGitGadget wrote: > + for (line = ssh_keygen_out.buf; *line; line = strchrnul(line + 1, '\n')) { > + while (*line == '\n') > + line++; > + if (!*line) > + break; > + > + trust_size = strcspn(line, " \n"); > + principal = xmemdupz(line, trust_size); This breaks on principals with spaces in them (principals in the allowed signers file can have spaces if surrounded by quotes). Looks like strcspn should reject "\n" instead of " \n". BTW, thanks for working on this feature. It seems much more convenient than GPG in my testing.