git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 1/1] gpg(docs): use correct --verify syntax

From
Junio C Hamano <gitster@pobox.com>
Date
Jul 12, 2019, 16:47 UTC
Message-ID
<xmqqtvbrp5c5.fsf@gitster-ct.c.googlers.com>
In-Reply-To
<e2daf21f1f2574a79f83d4e66591f67b1c937efe.1562945635.git.gitgitgadget@gmail.com>
"Robert Morgan via GitGitGadget" <gitgitgadget@gmail.com> writes:
Show 13 quoted lines
> diff --git a/Documentation/config/gpg.txt b/Documentation/config/gpg.txt
> index f999f8ea49..cce2c89245 100644
> --- a/Documentation/config/gpg.txt
> +++ b/Documentation/config/gpg.txt
> @@ -2,7 +2,7 @@ gpg.program::
>  	Use this custom program instead of "`gpg`" found on `$PATH` when
>  	making or verifying a PGP signature. The program must support the
>  	same command-line interface as GPG, namely, to verify a detached
> -	signature, "`gpg --verify $file - <$signature`" is run, and the
> +	signature, "`gpg --verify $signature - <$file`" is run, and the
>  	program is expected to signal a good signature by exiting with
>  	code 0, and to generate an ASCII-armored detached signature, the
>  	standard input of "`gpg -bsau $key`" is fed with the contents to be
Wow.  Good find.

gpg-interface.c::verify_signed_buffer() takes a detached signature in core, writes it to a temporary file and runs

    gpg --status-fd=1 --verify $the_temporary_file

and the payload that is supposed to match the given signature is fed via the standard input, so the above documentation is the only thing that needs fixing, which is good ;-)

Thanks.
Previous: Robert Morgan via GitGitGadgetNext: Robert Morgan
Message 3 of 4 in “Update gpg.txt to correct gpg --verify syntax”
  1. 0/1 Update gpg.txt to correct gpg --verify syntaxRobert Morgan via GitGitGadget, Jul 12, 2019
  2. 1/1 gpg(docs): use correct --verify syntaxRobert Morgan via GitGitGadget, Jul 12, 2019
  3. Junio C HamanoJul 12, 2019
  4. Robert MorganJul 12, 2019

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.