git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v2 1/1] t6300: fix match with insecure memory

From
Junio C Hamano <gitster@pobox.com>
Date
Aug 22, 2023, 15:50 UTC
Message-ID
<xmqqcyzfm5yp.fsf@gitster.g>
In-Reply-To
<20230822110404.1c002dcf@leda.eworm.net>
Christian Hesse <list@eworm.de> writes:
Show 26 quoted lines
> Kousik Sanagavarapu <five231003@gmail.com> on Tue, 2023/08/22 13:24:
>> Christian Hesse <list@eworm.de> wrote:
>> 
>> > From: Christian Hesse <mail@eworm.de>
>> > 
>> > Running the tests in a build environment makes gnupg print a warning:
>> > 
>> > gpg: Warning: using insecure memory!
>> >
>> > This warning breaks the match, as `head` misses one line. Let's strip
>> > the line, make `head` return what is expected and fix the match.
>> >
>> > Signed-off-by: Christian Hesse <mail@eworm.de>  
>> 
>> I think a bit of an explanation about why this warning is showing up in the
>> commit message would be good.
>> 
>> "man gpg" gives me <stripped>
>> 
>> So it seems that this warning will pop up if gpg is writing memory pages to
>> disk which is bad because as stated above we don't want these pages written
>> to disk which is a security risk.
>
> The Arch Linux packages are built inside a clean container, started via
> systemd-nspawn. Within the container the system call @memlock is not allowed
> by default, for security reasons.

Thanks for Kousik and Christian for discussing this. The phrase "in a build environment" in the proposed log message puzzled me, as the program does not seem to print such warning in my build environment.

And environments where memlock is disabled are probably not limited to containers used to build Arch's packages. "in a build environment" -> "in an enviornment where memlock is disabled" would have avoided puzzling readers.

Previous: Junio C Hamano
Message 13 of 13 in “Re: [PATCH 1/1] t6300: fix match with insecure memory”
  1. Christian HesseAug 21, 2023
  2. 1/1 t6300: fix match with insecure memoryChristian Hesse, Aug 21, 2023
  3. Kousik SanagavarapuAug 22, 2023
  4. Christian HesseAug 22, 2023
  5. Christian HesseAug 22, 2023
  6. 1/2 t/lib-gpg: forcibly run a trustdb updateChristian Hesse, Aug 22, 2023
  7. 2/2 t/t6300: drop magic filteringChristian Hesse, Aug 22, 2023
  8. Eric SunshineAug 22, 2023
  9. 2/2 t/t6300: drop magic filteringChristian Hesse, Aug 23, 2023
  10. Kousik SanagavarapuAug 23, 2023
  11. Junio C HamanoAug 23, 2023
  12. Junio C HamanoAug 23, 2023
  13. Junio C HamanoAug 22, 2023

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.