# Git libsecret No Unlock Dialog Issue

8 messages from 2017-11-02 to 2017-11-06. Participants: Yaroslav Sapozhnyk, Stefan Beller, Dennis Kaarsemaker, Mantas Mikulėnas.
Thread: https://gitlist.dev/t/47100

## Yaroslav Sapozhnyk, 2017-11-02 16:00

Subject: Git libsecret No Unlock Dialog Issue
Message-ID: <CAOAxMp-vAM7mCWuanj69coM09zF-Sxe=G=-XMd_RmaAne8qFvw@mail.gmail.com>
URL: https://gitlist.dev/e/CAOAxMp-vAM7mCWuanj69coM09zF-Sxe%3DG%3D-XMd_RmaAne8qFvw%40mail.gmail.com

```
When using Git on Fedora with locked password store
credential-libsecret asks for username/password instead of displaying
the unlock dialog.

If the store is unlocked credential helper gets the credentials from
the store though.

-- 
Regards,
Yaroslav Sapozhnyk

```

## Stefan Beller, 2017-11-02 18:35

Subject: Re: Git libsecret No Unlock Dialog Issue
Message-ID: <CAGZ79kaDB+nnTZVw-7msVa12RQa3sHn_zFKQ2-5i2eosuHutxQ@mail.gmail.com>
URL: https://gitlist.dev/e/CAGZ79kaDB%2BnnTZVw-7msVa12RQa3sHn_zFKQ2-5i2eosuHutxQ%40mail.gmail.com
In-Reply-To: <CAOAxMp-vAM7mCWuanj69coM09zF-Sxe=G=-XMd_RmaAne8qFvw@mail.gmail.com>

```
On Thu, Nov 2, 2017 at 9:00 AM, Yaroslav Sapozhnyk
<yaroslav.sapozhnik@gmail.com> wrote:
> When using Git on Fedora with locked password store
> credential-libsecret asks for username/password instead of displaying
> the unlock dialog.

Git as packaged by Fedora or upstream Git (which version)?

> If the store is unlocked credential helper gets the credentials from
> the store though.
>
> --
> Regards,
> Yaroslav Sapozhnyk

```

## Yaroslav Sapozhnyk, 2017-11-02 18:50

Subject: Re: Git libsecret No Unlock Dialog Issue
Message-ID: <CAOAxMp9RGq-=QowPytsvE+Z5CgNW72FUhbtdCS35fBCMEvYYoA@mail.gmail.com>
URL: https://gitlist.dev/e/CAOAxMp9RGq-%3DQowPytsvE%2BZ5CgNW72FUhbtdCS35fBCMEvYYoA%40mail.gmail.com
In-Reply-To: <CAGZ79kaDB+nnTZVw-7msVa12RQa3sHn_zFKQ2-5i2eosuHutxQ@mail.gmail.com>

```
Sorry, should have mentioned that. It's packaged by Fedora - 2.13.6.

Yaroslav

On Thu, Nov 2, 2017 at 2:35 PM, Stefan Beller <sbeller@google.com> wrote:
> On Thu, Nov 2, 2017 at 9:00 AM, Yaroslav Sapozhnyk
> <yaroslav.sapozhnik@gmail.com> wrote:
>> When using Git on Fedora with locked password store
>> credential-libsecret asks for username/password instead of displaying
>> the unlock dialog.
>
> Git as packaged by Fedora or upstream Git (which version)?
>
>> If the store is unlocked credential helper gets the credentials from
>> the store though.
>>
>> --
>> Regards,
>> Yaroslav Sapozhnyk



-- 
Regards,
Yaroslav Sapozhnyk

```

## Dennis Kaarsemaker, 2017-11-02 18:55

Subject: Re: Git libsecret No Unlock Dialog Issue
Message-ID: <1509648929.1838.1.camel@kaarsemaker.net>
URL: https://gitlist.dev/e/1509648929.1838.1.camel%40kaarsemaker.net
In-Reply-To: <CAGZ79kaDB+nnTZVw-7msVa12RQa3sHn_zFKQ2-5i2eosuHutxQ@mail.gmail.com>

```
On Thu, 2017-11-02 at 11:35 -0700, Stefan Beller wrote:
> On Thu, Nov 2, 2017 at 9:00 AM, Yaroslav Sapozhnyk
> <yaroslav.sapozhnik@gmail.com> wrote:
> > When using Git on Fedora with locked password store
> > credential-libsecret asks for username/password instead of displaying
> > the unlock dialog.
> 
> Git as packaged by Fedora or upstream Git (which version)?

Looking at the code: current upstream git. Looking at the documentation
for libsecret, this should fix it. I've not been able to test it
though.

diff --git a/contrib/credential/libsecret/git-credential-libsecret.c b/contrib/credential/libsecret/git-credential-libsecret.c
index 4c56979d8a..b4750c9ee8 100644
--- a/contrib/credential/libsecret/git-credential-libsecret.c
+++ b/contrib/credential/libsecret/git-credential-libsecret.c
@@ -104,7 +104,7 @@ static int keyring_get(struct credential *c)
        items = secret_service_search_sync(service,
                                           SECRET_SCHEMA_COMPAT_NETWORK,
                                           attributes,
-                                          SECRET_SEARCH_LOAD_SECRETS,
+                                          SECRET_SEARCH_LOAD_SECRETS | SECRET_SEARCH_UNLOCK,
                                           NULL,
                                           &error);
        g_hash_table_unref(attributes);

```

## Yaroslav Sapozhnyk, 2017-11-02 19:48

Subject: Re: Git libsecret No Unlock Dialog Issue
Message-ID: <CAOAxMp9H6M+t5RvYiem+kXrY920ZDYvyyYt4GZ7ZnkpXVA_c0g@mail.gmail.com>
URL: https://gitlist.dev/e/CAOAxMp9H6M%2Bt5RvYiem%2BkXrY920ZDYvyyYt4GZ7ZnkpXVA_c0g%40mail.gmail.com
In-Reply-To: <1509648929.1838.1.camel@kaarsemaker.net>

```
I've tested the code change locally and seems like it fixes the issue.

Yaroslav

On Thu, Nov 2, 2017 at 2:55 PM, Dennis Kaarsemaker
<dennis@kaarsemaker.net> wrote:
> On Thu, 2017-11-02 at 11:35 -0700, Stefan Beller wrote:
>> On Thu, Nov 2, 2017 at 9:00 AM, Yaroslav Sapozhnyk
>> <yaroslav.sapozhnik@gmail.com> wrote:
>> > When using Git on Fedora with locked password store
>> > credential-libsecret asks for username/password instead of displaying
>> > the unlock dialog.
>>
>> Git as packaged by Fedora or upstream Git (which version)?
>
> Looking at the code: current upstream git. Looking at the documentation
> for libsecret, this should fix it. I've not been able to test it
> though.
>
> diff --git a/contrib/credential/libsecret/git-credential-libsecret.c b/contrib/credential/libsecret/git-credential-libsecret.c
> index 4c56979d8a..b4750c9ee8 100644
> --- a/contrib/credential/libsecret/git-credential-libsecret.c
> +++ b/contrib/credential/libsecret/git-credential-libsecret.c
> @@ -104,7 +104,7 @@ static int keyring_get(struct credential *c)
>         items = secret_service_search_sync(service,
>                                            SECRET_SCHEMA_COMPAT_NETWORK,
>                                            attributes,
> -                                          SECRET_SEARCH_LOAD_SECRETS,
> +                                          SECRET_SEARCH_LOAD_SECRETS | SECRET_SEARCH_UNLOCK,
>                                            NULL,
>                                            &error);
>         g_hash_table_unref(attributes);



-- 
Regards,
Yaroslav Sapozhnyk

```

## Yaroslav Sapozhnyk, 2017-11-03 18:01

Subject: Re: Git libsecret No Unlock Dialog Issue
Message-ID: <CAOAxMp9fi3n=anfE_XCqDMtsr89pPANgCK1SL-RnOkwYjOM8hQ@mail.gmail.com>
URL: https://gitlist.dev/e/CAOAxMp9fi3n%3DanfE_XCqDMtsr89pPANgCK1SL-RnOkwYjOM8hQ%40mail.gmail.com
In-Reply-To: <CAOAxMp9H6M+t5RvYiem+kXrY920ZDYvyyYt4GZ7ZnkpXVA_c0g@mail.gmail.com>

```
What version should include this fix? Cannot find a pr for it.

Thanks for providing the fix!

Regards,
Yaroslav

On Thu, Nov 2, 2017 at 3:48 PM, Yaroslav Sapozhnyk
<yaroslav.sapozhnik@gmail.com> wrote:
> I've tested the code change locally and seems like it fixes the issue.
>
> Yaroslav
>
> On Thu, Nov 2, 2017 at 2:55 PM, Dennis Kaarsemaker
> <dennis@kaarsemaker.net> wrote:
>> On Thu, 2017-11-02 at 11:35 -0700, Stefan Beller wrote:
>>> On Thu, Nov 2, 2017 at 9:00 AM, Yaroslav Sapozhnyk
>>> <yaroslav.sapozhnik@gmail.com> wrote:
>>> > When using Git on Fedora with locked password store
>>> > credential-libsecret asks for username/password instead of displaying
>>> > the unlock dialog.
>>>
>>> Git as packaged by Fedora or upstream Git (which version)?
>>
>> Looking at the code: current upstream git. Looking at the documentation
>> for libsecret, this should fix it. I've not been able to test it
>> though.
>>
>> diff --git a/contrib/credential/libsecret/git-credential-libsecret.c b/contrib/credential/libsecret/git-credential-libsecret.c
>> index 4c56979d8a..b4750c9ee8 100644
>> --- a/contrib/credential/libsecret/git-credential-libsecret.c
>> +++ b/contrib/credential/libsecret/git-credential-libsecret.c
>> @@ -104,7 +104,7 @@ static int keyring_get(struct credential *c)
>>         items = secret_service_search_sync(service,
>>                                            SECRET_SCHEMA_COMPAT_NETWORK,
>>                                            attributes,
>> -                                          SECRET_SEARCH_LOAD_SECRETS,
>> +                                          SECRET_SEARCH_LOAD_SECRETS | SECRET_SEARCH_UNLOCK,
>>                                            NULL,
>>                                            &error);
>>         g_hash_table_unref(attributes);
>
>
>
> --
> Regards,
> Yaroslav Sapozhnyk



-- 
Regards,
Yaroslav Sapozhnyk

```

## Dennis Kaarsemaker, 2017-11-03 20:44

Subject: [PATCH] credential-libsecret: unlock locked secrets
Message-ID: <20171103204449.5268-1-dennis@kaarsemaker.net>
URL: https://gitlist.dev/e/20171103204449.5268-1-dennis%40kaarsemaker.net
In-Reply-To: <CAOAxMp9H6M+t5RvYiem+kXrY920ZDYvyyYt4GZ7ZnkpXVA_c0g@mail.gmail.com>

```
Credentials exposed by the secret service DBUS interface may be locked.
Setting the SECRET_SEARCH_UNLOCK flag will make the secret service
unlock these secrets, possibly prompting the user for credentials to do
so. Without this flag, the secret is simply not loaded.

Signed-off-by: Dennis Kaarsemaker <dennis@kaarsemaker.net>
---
 contrib/credential/libsecret/git-credential-libsecret.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/contrib/credential/libsecret/git-credential-libsecret.c b/contrib/credential/libsecret/git-credential-libsecret.c
index 4c56979d8a..b4750c9ee8 100644
--- a/contrib/credential/libsecret/git-credential-libsecret.c
+++ b/contrib/credential/libsecret/git-credential-libsecret.c
@@ -104,7 +104,7 @@ static int keyring_get(struct credential *c)
 	items = secret_service_search_sync(service,
 					   SECRET_SCHEMA_COMPAT_NETWORK,
 					   attributes,
-					   SECRET_SEARCH_LOAD_SECRETS,
+					   SECRET_SEARCH_LOAD_SECRETS | SECRET_SEARCH_UNLOCK,
 					   NULL,
 					   &error);
 	g_hash_table_unref(attributes);
-- 
2.15.0-rc2-464-gb5de734


```

## Mantas Mikulėnas, 2017-11-06 09:53

Subject: Re: [PATCH] credential-libsecret: unlock locked secrets
Message-ID: <CAPWNY8WUo8n903AcUPQ-EsfmtjoKRJDGXp0Wy4KoBSbrOhrR0A@mail.gmail.com>
URL: https://gitlist.dev/e/CAPWNY8WUo8n903AcUPQ-EsfmtjoKRJDGXp0Wy4KoBSbrOhrR0A%40mail.gmail.com
In-Reply-To: <20171103204449.5268-1-dennis@kaarsemaker.net>

```
On Fri, Nov 3, 2017 at 10:44 PM, Dennis Kaarsemaker
<dennis@kaarsemaker.net> wrote:
> Credentials exposed by the secret service DBUS interface may be locked.
> Setting the SECRET_SEARCH_UNLOCK flag will make the secret service
> unlock these secrets, possibly prompting the user for credentials to do
> so. Without this flag, the secret is simply not loaded.
>
> Signed-off-by: Dennis Kaarsemaker <dennis@kaarsemaker.net>
> ---
>  contrib/credential/libsecret/git-credential-libsecret.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/contrib/credential/libsecret/git-credential-libsecret.c b/contrib/credential/libsecret/git-credential-libsecret.c
> index 4c56979d8a..b4750c9ee8 100644
> --- a/contrib/credential/libsecret/git-credential-libsecret.c
> +++ b/contrib/credential/libsecret/git-credential-libsecret.c
> @@ -104,7 +104,7 @@ static int keyring_get(struct credential *c)
>         items = secret_service_search_sync(service,
>                                            SECRET_SCHEMA_COMPAT_NETWORK,
>                                            attributes,
> -                                          SECRET_SEARCH_LOAD_SECRETS,
> +                                          SECRET_SEARCH_LOAD_SECRETS | SECRET_SEARCH_UNLOCK,
>                                            NULL,
>                                            &error);
>         g_hash_table_unref(attributes);
> --
> 2.15.0-rc2-464-gb5de734
>

Looks okay. (It seems that's what all other programs do, too...)

-- 
Mantas Mikulėnas <grawity@gmail.com>

```
