threads / patch / 38758

patcht7510: do not fail when gpg warns about insecure memory

Subject: [PATCH] t7510: do not fail when gpg warns about insecure memory

## tl;dr

9 messages between Mar 8, 2015 and Mar 10, 2015. Diffs are folded; open one to read it.

replies: 8people: 4as markdown or json

Kyle J. McKay· Mar 8, 2015, 15:40 UTC · lore

Depending on how gpg was built, it may issue the following message to stderr when run:

  Warning: using insecure memory!

Unfortunately when running the test, that message gets collected in the stdout result of git show -s --show-signature but is collected in the stderr result of git verify-commit -v causing both the stdout and stderr result comparisions to fail.

Since checking for secure memory use by gpg is not the point of this test, filter out such messages to allow the test to pass even when gpg is "using insecure memory".

Signed-off-by: Kyle J. McKay <mackyle@gmail.com>
---
 t/t7510-signed-commit.sh | 5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)
Show changes to t/t7510-signed-commit.sh +3 −2
diff --git a/t/t7510-signed-commit.sh b/t/t7510-signed-commit.sh
index 474dab38..e86923bc 100755
--- a/t/t7510-signed-commit.sh
+++ b/t/t7510-signed-commit.sh
@@ -84,9 +84,10 @@ test_expect_success GPG 'verify and show signatures' '
 test_expect_success GPG 'show signed commit with signature' '
 	git show -s initial >commit &&
 	git show -s --show-signature initial >show &&
-	git verify-commit -v initial >verify.1 2>verify.2 &&
+	git verify-commit -v initial >verify.1 2>verify.2.out &&
 	git cat-file commit initial >cat &&
-	grep -v "gpg: " show >show.commit &&
+	grep -v -e "gpg: " -e "insecure memory" show >show.commit &&
+	grep -v "insecure memory" verify.2.out >verify.2 &&
 	grep "gpg: " show >show.gpg &&
 	grep -v "^ " cat | grep -v "^gpgsig " >cat.commit &&
 	test_cmp show.commit commit &&
---
Eric Sunshine· Mar 8, 2015, 21:43 UTC · re: Kyle J. McKay · lore

Re: [PATCH] t7510: do not fail when gpg warns about insecure memory

On Sun, Mar 8, 2015 at 11:40 AM, Kyle J. McKay <mackyle@gmail.com> wrote:
Show 8 quoted lines
> Depending on how gpg was built, it may issue the following
> message to stderr when run:
>
>   Warning: using insecure memory!
>
> Unfortunately when running the test, that message gets
> collected in the stdout result of git show -s --show-signature
> but is collected in the stderr result of git verify-commit -v
I'm having trouble parsing this. Is there a word missing?
> causing both the stdout and stderr result comparisions to fail.
s/comparisions/comparisons/
Show 5 quoted lines
> Since checking for secure memory use by gpg is not the point of
> this test, filter out such messages to allow the test to pass
> even when gpg is "using insecure memory".
>
> Signed-off-by: Kyle J. McKay <mackyle@gmail.com>
brian m. carlson· Mar 8, 2015, 22:04 UTC · re: Eric Sunshine · lore

Re: [PATCH] t7510: do not fail when gpg warns about insecure memory

On Sun, Mar 08, 2015 at 05:43:41PM -0400, Eric Sunshine wrote:
Show 13 quoted lines
>On Sun, Mar 8, 2015 at 11:40 AM, Kyle J. McKay <mackyle@gmail.com> wrote:
>> Depending on how gpg was built, it may issue the following
>> message to stderr when run:
>>
>>   Warning: using insecure memory!
>>
>> Unfortunately when running the test, that message gets
>> collected in the stdout result of git show -s --show-signature
>> but is collected in the stderr result of git verify-commit -v
>
>I'm having trouble parsing this. Is there a word missing?
>
>> causing both the stdout and stderr result comparisions to fail.
Perhaps this is better?
  Unfortunately when running the test, that message is found in the 
  standard output of git show -s --show-signature, but in the standard 
  error of git verify-commit -v causing the comparisons of both standard 
  output and standard error to fail.
-- 
brian m. carlson / brian with sandals: Houston, Texas, US
+1 832 623 2791 | http://www.crustytoothpaste.net/~bmc | My opinion only
OpenPGP: RSA v4 4096b: 88AC E9B2 9196 305B A994 7552 F1BA 225C 0223 B187
Eric Sunshine· Mar 8, 2015, 22:15 UTC · re: brian m. carlson · lore

Re: [PATCH] t7510: do not fail when gpg warns about insecure memory

On Sun, Mar 8, 2015 at 6:04 PM, brian m. carlson <sandals@crustytoothpaste.net> wrote:

Show 15 quoted lines
> On Sun, Mar 08, 2015 at 05:43:41PM -0400, Eric Sunshine wrote:
>> On Sun, Mar 8, 2015 at 11:40 AM, Kyle J. McKay <mackyle@gmail.com> wrote:
>>>   Warning: using insecure memory!
>>>
>>> Unfortunately when running the test, that message gets
>>> collected in the stdout result of git show -s --show-signature
>>> but is collected in the stderr result of git verify-commit -v
>>
>> I'm having trouble parsing this. Is there a word missing?
> Perhaps this is better?
>
>  Unfortunately when running the test, that message is found in the  standard
> output of git show -s --show-signature, but in the standard  error of git
> verify-commit -v causing the comparisons of both standard  output and
> standard error to fail.

That doesn't help me parse it any better. It's the "but" without a corresponding "not" which seems to be throwing me off. Typically, one would write "this but not that" or "not this but that". I can't tell if there is a "not" missing or if the "but" is supposed to be an "and" or if something else was intended.

brian m. carlson· Mar 9, 2015, 01:22 UTC · re: Eric Sunshine · lore

Re: [PATCH] t7510: do not fail when gpg warns about insecure memory

On Sun, Mar 08, 2015 at 06:15:55PM -0400, Eric Sunshine wrote:
Show 14 quoted lines
>On Sun, Mar 8, 2015 at 6:04 PM, brian m. carlson
><sandals@crustytoothpaste.net> wrote:
>> Perhaps this is better?
>>
>>  Unfortunately when running the test, that message is found in the  standard
>> output of git show -s --show-signature, but in the standard  error of git
>> verify-commit -v causing the comparisons of both standard  output and
>> standard error to fail.
>
>That doesn't help me parse it any better.  It's the "but" without a
>corresponding "not" which seems to be throwing me off. Typically, one
>would write "this but not that" or "not this but that". I can't tell
>if there is a "not" missing or if the "but" is supposed to be an "and"
>or if something else was intended.

The intended meaning is "and" with the additional sense of contrast. The sentence, if read with verbal emphasis, is, "…is found in the standard *output* of git show -s --signature, but in the standard *error* of git verify-commit -v", thus demonstrating why the test fails: the pairs of output files don't match up.

Maybe you can suggest a less confusing wording.
-- 
brian m. carlson / brian with sandals: Houston, Texas, US
+1 832 623 2791 | http://www.crustytoothpaste.net/~bmc | My opinion only
OpenPGP: RSA v4 4096b: 88AC E9B2 9196 305B A994 7552 F1BA 225C 0223 B187
Kyle J. McKay· Mar 9, 2015, 05:32 UTC · re: brian m. carlson · lore

Re: [PATCH] t7510: do not fail when gpg warns about insecure memory

On Mar 8, 2015, at 18:22, brian m. carlson wrote:
Show 27 quoted lines
> On Sun, Mar 08, 2015 at 06:15:55PM -0400, Eric Sunshine wrote:
>> On Sun, Mar 8, 2015 at 6:04 PM, brian m. carlson
>> <sandals@crustytoothpaste.net> wrote:
>>> Perhaps this is better?
>>>
>>> Unfortunately when running the test, that message is found in the   
>>> standard
>>> output of git show -s --show-signature, but in the standard  error  
>>> of git
>>> verify-commit -v causing the comparisons of both standard  output  
>>> and
>>> standard error to fail.
>>
>> That doesn't help me parse it any better.  It's the "but" without a
>> corresponding "not" which seems to be throwing me off. Typically, one
>> would write "this but not that" or "not this but that". I can't tell
>> if there is a "not" missing or if the "but" is supposed to be an  
>> "and"
>> or if something else was intended.
>
> The intended meaning is "and" with the additional sense of contrast.  
> The sentence, if read with verbal emphasis, is, "…is found in the  
> standard *output* of git show -s --signature, but in the standard  
> *error* of git verify-commit -v", thus demonstrating why the test  
> fails: the pairs of output files don't match up.
>
> Maybe you can suggest a less confusing wording.

I like Brian's wording, but how about this slight variation, does this parse any better for you?

Unfortunately when running the test, while that message is found in the standard output of git show -s --show-signature, it is found in the standard error of git verify-commit -v causing the comparisons of both standard output and standard error to fail.

-Kyle
Michael J Gruber· Mar 9, 2015, 09:47 UTC · re: Kyle J. McKay · lore

Re: [PATCH] t7510: do not fail when gpg warns about insecure memory

Kyle J. McKay venit, vidit, dixit 09.03.2015 06:32:
Show 40 quoted lines
> On Mar 8, 2015, at 18:22, brian m. carlson wrote:
> 
>> On Sun, Mar 08, 2015 at 06:15:55PM -0400, Eric Sunshine wrote:
>>> On Sun, Mar 8, 2015 at 6:04 PM, brian m. carlson
>>> <sandals@crustytoothpaste.net> wrote:
>>>> Perhaps this is better?
>>>>
>>>> Unfortunately when running the test, that message is found in the   
>>>> standard
>>>> output of git show -s --show-signature, but in the standard  error  
>>>> of git
>>>> verify-commit -v causing the comparisons of both standard  output  
>>>> and
>>>> standard error to fail.
>>>
>>> That doesn't help me parse it any better.  It's the "but" without a
>>> corresponding "not" which seems to be throwing me off. Typically, one
>>> would write "this but not that" or "not this but that". I can't tell
>>> if there is a "not" missing or if the "but" is supposed to be an  
>>> "and"
>>> or if something else was intended.
>>
>> The intended meaning is "and" with the additional sense of contrast.  
>> The sentence, if read with verbal emphasis, is, "…is found in the  
>> standard *output* of git show -s --signature, but in the standard  
>> *error* of git verify-commit -v", thus demonstrating why the test  
>> fails: the pairs of output files don't match up.
>>
>> Maybe you can suggest a less confusing wording.
> 
> I like Brian's wording, but how about this slight variation, does this  
> parse any better for you?
> 
> Unfortunately when running the test, while that message is found in
> the standard output of git show -s --show-signature, it is found in
> the standard error of git verify-commit -v causing the comparisons
> of both standard output and standard error to fail.
> 
> -Kyle
> 

That still makes it sound as if we'd rather fix "git show" than adjust the test to such surprising behavior.

But in fact, "git verify-commit" uses stdout and stderr to separate its output appropriately, whereas "git show" lumps everything together on stdout, so that the test has to split it up again.

Now, if I read it correctly, the patch suggests ignoring the insecure memory warning from both outputs rather than putting it on the correct side of the split.

I'd rather put it on the correct side (or silence gpg by setting its config).

Michael
Kyle J. McKay· Mar 9, 2015, 20:03 UTC · re: Michael J Gruber · lore

[PATCH v2] t7510: do not fail when gpg warns about insecure memory

Depending on how gpg was built, it may issue the following message to stderr when run:

  Warning: using insecure memory!

When the test is collecting gpg output it is therefore not enough to just match on a "gpg: " prefix it must also match on a "Warning: " prefix wherever it needs to match lines that have been produced by gpg.

Signed-off-by: Kyle J. McKay <mackyle@gmail.com>
---

How about this patch instead. It just treats "Warning:" lines as gpg output and the test still passes when "Warning: using insecure memory" shows up.

-Kyle
 t/t7510-signed-commit.sh | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)
Show changes to t/t7510-signed-commit.sh +2 −2
diff --git a/t/t7510-signed-commit.sh b/t/t7510-signed-commit.sh
index 474dab38..3cef18cf 100755
--- a/t/t7510-signed-commit.sh
+++ b/t/t7510-signed-commit.sh
@@ -86,8 +86,8 @@ test_expect_success GPG 'show signed commit with signature' '
 	git show -s --show-signature initial >show &&
 	git verify-commit -v initial >verify.1 2>verify.2 &&
 	git cat-file commit initial >cat &&
-	grep -v "gpg: " show >show.commit &&
-	grep "gpg: " show >show.gpg &&
+	grep -v -e "gpg: " -e "Warning: " show >show.commit &&
+	grep -e "gpg: " -e "Warning: " show >show.gpg &&
 	grep -v "^ " cat | grep -v "^gpgsig " >cat.commit &&
 	test_cmp show.commit commit &&
 	test_cmp show.gpg verify.2 &&
---
Michael J Gruber· Mar 10, 2015, 09:10 UTC · re: Kyle J. McKay · lore

Re: [PATCH v2] t7510: do not fail when gpg warns about insecure memory

Kyle J. McKay venit, vidit, dixit 09.03.2015 21:03:
Show 15 quoted lines
> Depending on how gpg was built, it may issue the following
> message to stderr when run:
> 
>   Warning: using insecure memory!
> 
> When the test is collecting gpg output it is therefore not
> enough to just match on a "gpg: " prefix it must also match
> on a "Warning: " prefix wherever it needs to match lines
> that have been produced by gpg.
> 
> Signed-off-by: Kyle J. McKay <mackyle@gmail.com>
> ---
> 
> How about this patch instead.  It just treats "Warning:" lines as gpg  
> output
(They are, but gpg fails tp prefix them.)
> and the test still passes when "Warning: using insecure memory"  
> shows up.
> 
> -Kyle
Perfect, thanks!
Show 20 quoted lines
>  t/t7510-signed-commit.sh | 4 ++--
>  1 file changed, 2 insertions(+), 2 deletions(-)
> 
> diff --git a/t/t7510-signed-commit.sh b/t/t7510-signed-commit.sh
> index 474dab38..3cef18cf 100755
> --- a/t/t7510-signed-commit.sh
> +++ b/t/t7510-signed-commit.sh
> @@ -86,8 +86,8 @@ test_expect_success GPG 'show signed commit with signature' '
>  	git show -s --show-signature initial >show &&
>  	git verify-commit -v initial >verify.1 2>verify.2 &&
>  	git cat-file commit initial >cat &&
> -	grep -v "gpg: " show >show.commit &&
> -	grep "gpg: " show >show.gpg &&
> +	grep -v -e "gpg: " -e "Warning: " show >show.commit &&
> +	grep -e "gpg: " -e "Warning: " show >show.gpg &&
>  	grep -v "^ " cat | grep -v "^gpgsig " >cat.commit &&
>  	test_cmp show.commit commit &&
>  	test_cmp show.gpg verify.2 &&
> ---
> 

← back to recent threads