threads / discuss / 47100

Git libsecret No Unlock Dialog Issue

Subject: Git libsecret No Unlock Dialog Issue

## tl;dr

8 messages between Nov 2, 2017 and Nov 6, 2017.

replies: 7people: 4as markdown or json

Yaroslav Sapozhnyk· Nov 2, 2017, 16:00 UTC · lore

When using Git on Fedora with locked password store credential-libsecret asks for username/password instead of displaying the unlock dialog.

If the store is unlocked credential helper gets the credentials from the store though.

-- 
Regards,
Yaroslav Sapozhnyk
Stefan Beller· Nov 2, 2017, 18:35 UTC · re: Yaroslav Sapozhnyk · lore

Re: Git libsecret No Unlock Dialog Issue

On Thu, Nov 2, 2017 at 9:00 AM, Yaroslav Sapozhnyk <yaroslav.sapozhnik@gmail.com> wrote:

> When using Git on Fedora with locked password store
> credential-libsecret asks for username/password instead of displaying
> the unlock dialog.
Git as packaged by Fedora or upstream Git (which version)?
Show 6 quoted lines
> If the store is unlocked credential helper gets the credentials from
> the store though.
>
> --
> Regards,
> Yaroslav Sapozhnyk
Yaroslav Sapozhnyk· Nov 2, 2017, 18:50 UTC · re: Stefan Beller · lore

Re: Git libsecret No Unlock Dialog Issue

Sorry, should have mentioned that. It's packaged by Fedora - 2.13.6.
Yaroslav
On Thu, Nov 2, 2017 at 2:35 PM, Stefan Beller <sbeller@google.com> wrote:
Show 14 quoted lines
> On Thu, Nov 2, 2017 at 9:00 AM, Yaroslav Sapozhnyk
> <yaroslav.sapozhnik@gmail.com> wrote:
>> When using Git on Fedora with locked password store
>> credential-libsecret asks for username/password instead of displaying
>> the unlock dialog.
>
> Git as packaged by Fedora or upstream Git (which version)?
>
>> If the store is unlocked credential helper gets the credentials from
>> the store though.
>>
>> --
>> Regards,
>> Yaroslav Sapozhnyk
-- 
Regards,
Yaroslav Sapozhnyk
Dennis Kaarsemaker· Nov 2, 2017, 18:55 UTC · re: Stefan Beller · lore

Re: Git libsecret No Unlock Dialog Issue

On Thu, 2017-11-02 at 11:35 -0700, Stefan Beller wrote:
Show 7 quoted lines
> On Thu, Nov 2, 2017 at 9:00 AM, Yaroslav Sapozhnyk
> <yaroslav.sapozhnik@gmail.com> wrote:
> > When using Git on Fedora with locked password store
> > credential-libsecret asks for username/password instead of displaying
> > the unlock dialog.
> 
> Git as packaged by Fedora or upstream Git (which version)?

Looking at the code: current upstream git. Looking at the documentation for libsecret, this should fix it. I've not been able to test it though.

diff --git a/contrib/credential/libsecret/git-credential-libsecret.c b/contrib/credential/libsecret/git-credential-libsecret.c
index 4c56979d8a..b4750c9ee8 100644
--- a/contrib/credential/libsecret/git-credential-libsecret.c
+++ b/contrib/credential/libsecret/git-credential-libsecret.c
@@ -104,7 +104,7 @@ static int keyring_get(struct credential *c)
        items = secret_service_search_sync(service,
                                           SECRET_SCHEMA_COMPAT_NETWORK,
                                           attributes,
-                                          SECRET_SEARCH_LOAD_SECRETS,
+                                          SECRET_SEARCH_LOAD_SECRETS | SECRET_SEARCH_UNLOCK,
                                           NULL,
                                           &error);
        g_hash_table_unref(attributes);
Yaroslav Sapozhnyk· Nov 2, 2017, 19:48 UTC · re: Dennis Kaarsemaker · lore

Re: Git libsecret No Unlock Dialog Issue

I've tested the code change locally and seems like it fixes the issue.
Yaroslav

On Thu, Nov 2, 2017 at 2:55 PM, Dennis Kaarsemaker <dennis@kaarsemaker.net> wrote:

Show 26 quoted lines
> On Thu, 2017-11-02 at 11:35 -0700, Stefan Beller wrote:
>> On Thu, Nov 2, 2017 at 9:00 AM, Yaroslav Sapozhnyk
>> <yaroslav.sapozhnik@gmail.com> wrote:
>> > When using Git on Fedora with locked password store
>> > credential-libsecret asks for username/password instead of displaying
>> > the unlock dialog.
>>
>> Git as packaged by Fedora or upstream Git (which version)?
>
> Looking at the code: current upstream git. Looking at the documentation
> for libsecret, this should fix it. I've not been able to test it
> though.
>
> diff --git a/contrib/credential/libsecret/git-credential-libsecret.c b/contrib/credential/libsecret/git-credential-libsecret.c
> index 4c56979d8a..b4750c9ee8 100644
> --- a/contrib/credential/libsecret/git-credential-libsecret.c
> +++ b/contrib/credential/libsecret/git-credential-libsecret.c
> @@ -104,7 +104,7 @@ static int keyring_get(struct credential *c)
>         items = secret_service_search_sync(service,
>                                            SECRET_SCHEMA_COMPAT_NETWORK,
>                                            attributes,
> -                                          SECRET_SEARCH_LOAD_SECRETS,
> +                                          SECRET_SEARCH_LOAD_SECRETS | SECRET_SEARCH_UNLOCK,
>                                            NULL,
>                                            &error);
>         g_hash_table_unref(attributes);
-- 
Regards,
Yaroslav Sapozhnyk
Yaroslav Sapozhnyk· Nov 3, 2017, 18:01 UTC · re: Yaroslav Sapozhnyk · lore

Re: Git libsecret No Unlock Dialog Issue

What version should include this fix? Cannot find a pr for it.
Thanks for providing the fix!

Regards, Yaroslav

On Thu, Nov 2, 2017 at 3:48 PM, Yaroslav Sapozhnyk <yaroslav.sapozhnik@gmail.com> wrote:

Show 38 quoted lines
> I've tested the code change locally and seems like it fixes the issue.
>
> Yaroslav
>
> On Thu, Nov 2, 2017 at 2:55 PM, Dennis Kaarsemaker
> <dennis@kaarsemaker.net> wrote:
>> On Thu, 2017-11-02 at 11:35 -0700, Stefan Beller wrote:
>>> On Thu, Nov 2, 2017 at 9:00 AM, Yaroslav Sapozhnyk
>>> <yaroslav.sapozhnik@gmail.com> wrote:
>>> > When using Git on Fedora with locked password store
>>> > credential-libsecret asks for username/password instead of displaying
>>> > the unlock dialog.
>>>
>>> Git as packaged by Fedora or upstream Git (which version)?
>>
>> Looking at the code: current upstream git. Looking at the documentation
>> for libsecret, this should fix it. I've not been able to test it
>> though.
>>
>> diff --git a/contrib/credential/libsecret/git-credential-libsecret.c b/contrib/credential/libsecret/git-credential-libsecret.c
>> index 4c56979d8a..b4750c9ee8 100644
>> --- a/contrib/credential/libsecret/git-credential-libsecret.c
>> +++ b/contrib/credential/libsecret/git-credential-libsecret.c
>> @@ -104,7 +104,7 @@ static int keyring_get(struct credential *c)
>>         items = secret_service_search_sync(service,
>>                                            SECRET_SCHEMA_COMPAT_NETWORK,
>>                                            attributes,
>> -                                          SECRET_SEARCH_LOAD_SECRETS,
>> +                                          SECRET_SEARCH_LOAD_SECRETS | SECRET_SEARCH_UNLOCK,
>>                                            NULL,
>>                                            &error);
>>         g_hash_table_unref(attributes);
>
>
>
> --
> Regards,
> Yaroslav Sapozhnyk
-- 
Regards,
Yaroslav Sapozhnyk
Dennis Kaarsemaker· Nov 3, 2017, 20:44 UTC · re: Yaroslav Sapozhnyk · lore

[PATCH] credential-libsecret: unlock locked secrets

Credentials exposed by the secret service DBUS interface may be locked. Setting the SECRET_SEARCH_UNLOCK flag will make the secret service unlock these secrets, possibly prompting the user for credentials to do so. Without this flag, the secret is simply not loaded.

Signed-off-by: Dennis Kaarsemaker <dennis@kaarsemaker.net>
---
 contrib/credential/libsecret/git-credential-libsecret.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/contrib/credential/libsecret/git-credential-libsecret.c b/contrib/credential/libsecret/git-credential-libsecret.c
index 4c56979d8a..b4750c9ee8 100644
--- a/contrib/credential/libsecret/git-credential-libsecret.c
+++ b/contrib/credential/libsecret/git-credential-libsecret.c
@@ -104,7 +104,7 @@ static int keyring_get(struct credential *c)
 	items = secret_service_search_sync(service,
 					   SECRET_SCHEMA_COMPAT_NETWORK,
 					   attributes,
-					   SECRET_SEARCH_LOAD_SECRETS,
+					   SECRET_SEARCH_LOAD_SECRETS | SECRET_SEARCH_UNLOCK,
 					   NULL,
 					   &error);
 	g_hash_table_unref(attributes);
-- 
2.15.0-rc2-464-gb5de734
Mantas Mikulėnas· Nov 6, 2017, 09:53 UTC · re: Dennis Kaarsemaker · lore

Re: [PATCH] credential-libsecret: unlock locked secrets

On Fri, Nov 3, 2017 at 10:44 PM, Dennis Kaarsemaker <dennis@kaarsemaker.net> wrote:

Show 26 quoted lines
> Credentials exposed by the secret service DBUS interface may be locked.
> Setting the SECRET_SEARCH_UNLOCK flag will make the secret service
> unlock these secrets, possibly prompting the user for credentials to do
> so. Without this flag, the secret is simply not loaded.
>
> Signed-off-by: Dennis Kaarsemaker <dennis@kaarsemaker.net>
> ---
>  contrib/credential/libsecret/git-credential-libsecret.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/contrib/credential/libsecret/git-credential-libsecret.c b/contrib/credential/libsecret/git-credential-libsecret.c
> index 4c56979d8a..b4750c9ee8 100644
> --- a/contrib/credential/libsecret/git-credential-libsecret.c
> +++ b/contrib/credential/libsecret/git-credential-libsecret.c
> @@ -104,7 +104,7 @@ static int keyring_get(struct credential *c)
>         items = secret_service_search_sync(service,
>                                            SECRET_SCHEMA_COMPAT_NETWORK,
>                                            attributes,
> -                                          SECRET_SEARCH_LOAD_SECRETS,
> +                                          SECRET_SEARCH_LOAD_SECRETS | SECRET_SEARCH_UNLOCK,
>                                            NULL,
>                                            &error);
>         g_hash_table_unref(attributes);
> --
> 2.15.0-rc2-464-gb5de734
>
Looks okay. (It seems that's what all other programs do, too...)
-- 
Mantas Mikulėnas <grawity@gmail.com>

← back to recent threads