git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: gpg-related crash with custom formatter (BUG: gpg-interface.c:915: invalid trust level requested -1)

From
Junio C Hamano <gitster@pobox.com>
Date
Apr 18, 2023, 16:17 UTC
Message-ID
<xmqq354xf9m6.fsf@gitster.g>
In-Reply-To
<5926995.lOV4Wx5bFT@devpool47.emlix.com>
Rolf Eike Beer <eb@emlix.com> writes:
Show 9 quoted lines
> I use this one:
>
> [format]
>         pretty = %C(yellow)commit %H%C(auto)%d%Creset%nAuthor: %an <%ae> 
> %C(yellow)% GK %GS %C(auto)[%GT% G?]%Creset%nDate:   %ad%n%n%w(0,4,4)%s%n%w(0,
> 4,4)%+b
>
> When I now run "git log" in a repository that contains commits signed by 
> people not in my keyring (e.g. the Gentoo git) I get this backtrace:
Thanks for a clearly described report.  GPG reports something like
    [GNUPG:] NEWSIG
    [GNUPG:] ERRSIG B0B5E88696AFE6CB 1 8 00 1681831898 9 E1F036B1FEE7221FC778ECEFB0B5E88696AFE6CB
    [GNUPG:] NO_PUBKEY B0B5E88696AFE6CB

but parse_gpg_output() that is responsible for setting the trust_level member of sigc structure never responds to this report because none among NEWSIG, ERRSIG, and NO_PUBKEY begins with "TRUST_" that triggers a call to parse_gpg_trust_level() to set the member.

The caller of parse_gpg_output() initializes the member to -1 and that is left intact. Of course, it is not one of the values that gpg_trust_level_to_str() knows about.

The absolute minimum fix is to initialize the member to TRUST_NEVER which is one of the values gpg_trust_level_to_str() knows about. It seems that SSH based signature verification codepath uses the same approach.

 gpg-interface.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
diff --git c/gpg-interface.c w/gpg-interface.c
index aceeb08336..2044e00205 100644
--- c/gpg-interface.c
+++ w/gpg-interface.c
@@ -650,7 +650,7 @@ int check_signature(struct signature_check *sigc,
 	gpg_interface_lazy_init();
 
 	sigc->result = 'N';
-	sigc->trust_level = -1;
+	sigc->trust_level = TRUST_NEVER;
 
 	fmt = get_format_by_sig(signature);
 	if (!fmt)
Previous: Junio C Hamano
Message 9 of 9 in “gpg-related crash with custom formatter (BUG: gpg-interface.c:915: invalid trust level requested -1)”
  1. Rolf Eike BeerApr 18, 2023
  2. Jeff KingApr 18, 2023
  3. Jaydeep DasApr 18, 2023
  4. Junio C HamanoApr 18, 2023
  5. gpg-interface: set trust level of missing key to "undefined"Jeff King, Apr 19, 2023
  6. Junio C HamanoApr 19, 2023
  7. Jeff KingApr 22, 2023
  8. Junio C HamanoApr 24, 2023
  9. Junio C HamanoApr 18, 2023

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.