git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] ssh signing: return an error when signature cannot be read

From
Junio C Hamano <gitster@pobox.com>
Date
Oct 3, 2022, 16:13 UTC
Message-ID
<xmqq1qroyjf3.fsf@gitster.g>
In-Reply-To
<pull.1371.git.1664789075343.gitgitgadget@gmail.com>
"Phillip Wood via GitGitGadget" <gitgitgadget@gmail.com> writes:
Show 7 quoted lines
> From: Phillip Wood <phillip.wood@dunelm.org.uk>
>
> If the signature file cannot be read we print an error message but do
> not return an error to the caller. In practice it seems unlikely that
> the file would be unreadable if the call to ssh-keygen succeeds. If we
> cannot read the file it may be missing so ignore any errors from
> unlink() when we try to remove it.

OK. Not removing may help diagnose what the problem is, but going that route needs to add code to report what file is deliberately left for inspection. I do not know how valuable that would be to help human debuggers --- the user presumably have the original material (e.g. a signed tag object) anyway, and the human debugger probably needs to have access to both the original material and what is fed to the gpg-interface API. If they are chasing a reproducible bug, the latter should be recreatable by the human debugger from the former, so removing would not hurt the debuggability that much.

On the other hand, we can still report if the reason we cannot remove is not ENOENT, though.

Thanks.
Show 36 quoted lines
>
> Signed-off-by: Phillip Wood <phillip.wood@dunelm.org.uk>
> ---
>     ssh signing: return an error when signature cannot be read
>     
>     This patch is based on maint. In the longer term the code could be
>     simplified by using pipes rather than tempfiles as we do for gpg.
>     ssh-keygen has supported reading the data to be signed from stdin and
>     writing the signature to stdout since it introduced signing.
>
> Published-As: https://github.com/gitgitgadget/git/releases/tag/pr-1371%2Fphillipwood%2Fssh-signing-return-error-on-missing-signature-v1
> Fetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-1371/phillipwood/ssh-signing-return-error-on-missing-signature-v1
> Pull-Request: https://github.com/gitgitgadget/git/pull/1371
>
>  gpg-interface.c | 4 +++-
>  1 file changed, 3 insertions(+), 1 deletion(-)
>
> diff --git a/gpg-interface.c b/gpg-interface.c
> index 947b58ad4da..d352bc286b6 100644
> --- a/gpg-interface.c
> +++ b/gpg-interface.c
> @@ -1043,9 +1043,11 @@ static int sign_buffer_ssh(struct strbuf *buffer, struct strbuf *signature,
>  	strbuf_addbuf(&ssh_signature_filename, &buffer_file->filename);
>  	strbuf_addstr(&ssh_signature_filename, ".sig");
>  	if (strbuf_read_file(signature, ssh_signature_filename.buf, 0) < 0) {
> -		error_errno(
> +		ret = error_errno(
>  			_("failed reading ssh signing data buffer from '%s'"),
>  			ssh_signature_filename.buf);
> +		unlink(ssh_signature_filename.buf);
> +		goto out;
>  	}
>  	unlink_or_warn(ssh_signature_filename.buf);
>  
>
> base-commit: a0feb8611d4c0b2b5d954efe4e98207f62223436
Previous: Phillip Wood via GitGitGadgetNext: Phillip Wood via GitGitGadget
Message 2 of 6 in “ssh signing: return an error when signature cannot be read”
  1. ssh signing: return an error when signature cannot be readPhillip Wood via GitGitGadget, Oct 3, 2022
  2. Junio C HamanoOct 3, 2022
  3. ssh signing: return an error when signature cannot be readPhillip Wood via GitGitGadget, Oct 4, 2022
  4. Fabian StelzerOct 6, 2022
  5. Phillip WoodOct 6, 2022
  6. Fabian StelzerOct 6, 2022

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.