threads / patch / 51473

patchUpdate gpg.txt to correct gpg --verify syntax

Subject: [PATCH 0/1] Update gpg.txt to correct gpg --verify syntax

## tl;dr

4 messages between Jul 12, 2019 and Jul 12, 2019. Diffs are folded; open one to read it.

replies: 3people: 2as markdown or json

Robert Morgan via GitGitGadget· Jul 12, 2019, 15:33 UTC · lore

The gpg --verify usage example within the 'gpg.program' variable reference provides an incorrect example of the gpg --verify command arguments. The command argument order, when providing both a detached signature and data, should be signature first and data second: https://gnupg.org/documentation/manuals/gnupg/Operational-GPG-Commands.html#index-verify .

Signed-off-by: Robert T Morgan robert.thomas.morgan@gmail.com
[robert.thomas.morgan@gmail.com]
Robert Morgan (1):
  gpg(docs): use correct --verify syntax
 Documentation/config/gpg.txt | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
base-commit: 6d5b26420848ec3bc7eae46a7ffa54f20276249d
Published-As: https://github.com/gitgitgadget/git/releases/tag/pr-285%2Frtmorgan%2Fpatch-1-v1
Fetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-285/rtmorgan/patch-1-v1
Pull-Request: https://github.com/gitgitgadget/git/pull/285
-- 
gitgitgadget
Robert Morgan via GitGitGadget· Jul 12, 2019, 15:33 UTC · re: Robert Morgan via GitGitGadget · lore

[PATCH 1/1] gpg(docs): use correct --verify syntax

From: Robert Morgan <robert.thomas.morgan@gmail.com>

The gpg --verify usage example within the 'gpg.program' variable reference provides an incorrect example of the gpg --verify command arguments.

The command argument order, when providing both a detached signature and data, should be signature first and data second: https://gnupg.org/documentation/manuals/gnupg/Operational-GPG-Commands.html

Signed-off-by: Robert Morgan <robert.thomas.morgan@gmail.com>
---
 Documentation/config/gpg.txt | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
Show changes to Documentation/config/gpg.txt +1 −1
diff --git a/Documentation/config/gpg.txt b/Documentation/config/gpg.txt
index f999f8ea49..cce2c89245 100644
--- a/Documentation/config/gpg.txt
+++ b/Documentation/config/gpg.txt
@@ -2,7 +2,7 @@ gpg.program::
 	Use this custom program instead of "`gpg`" found on `$PATH` when
 	making or verifying a PGP signature. The program must support the
 	same command-line interface as GPG, namely, to verify a detached
-	signature, "`gpg --verify $file - <$signature`" is run, and the
+	signature, "`gpg --verify $signature - <$file`" is run, and the
 	program is expected to signal a good signature by exiting with
 	code 0, and to generate an ASCII-armored detached signature, the
 	standard input of "`gpg -bsau $key`" is fed with the contents to be
-- 
gitgitgadget
Junio C Hamano· Jul 12, 2019, 16:47 UTC · re: Robert Morgan via GitGitGadget · lore

Re: [PATCH 1/1] gpg(docs): use correct --verify syntax

"Robert Morgan via GitGitGadget" <gitgitgadget@gmail.com> writes:
Show 13 quoted lines
> diff --git a/Documentation/config/gpg.txt b/Documentation/config/gpg.txt
> index f999f8ea49..cce2c89245 100644
> --- a/Documentation/config/gpg.txt
> +++ b/Documentation/config/gpg.txt
> @@ -2,7 +2,7 @@ gpg.program::
>  	Use this custom program instead of "`gpg`" found on `$PATH` when
>  	making or verifying a PGP signature. The program must support the
>  	same command-line interface as GPG, namely, to verify a detached
> -	signature, "`gpg --verify $file - <$signature`" is run, and the
> +	signature, "`gpg --verify $signature - <$file`" is run, and the
>  	program is expected to signal a good signature by exiting with
>  	code 0, and to generate an ASCII-armored detached signature, the
>  	standard input of "`gpg -bsau $key`" is fed with the contents to be
Wow.  Good find.

gpg-interface.c::verify_signed_buffer() takes a detached signature in core, writes it to a temporary file and runs

    gpg --status-fd=1 --verify $the_temporary_file

and the payload that is supposed to match the given signature is fed via the standard input, so the above documentation is the only thing that needs fixing, which is good ;-)

Thanks.
Robert Morgan· Jul 12, 2019, 19:11 UTC · re: Junio C Hamano · lore

Re: [PATCH 1/1] gpg(docs): use correct --verify syntax

Thanks Junio.

I was looking at 'smimesign' and working to understand how, when set within 'gpg.program', it conformed with gpg's usage within git sign,verify etc. I happened to look at the docs for the 'gpg.program' config variable and noticed the discrepancy.

Thanks again, Robert

On Fri, Jul 12, 2019 at 11:47 AM Junio C Hamano <gitster@pobox.com> wrote:
Show 32 quoted lines
>
> "Robert Morgan via GitGitGadget" <gitgitgadget@gmail.com> writes:
>
> > diff --git a/Documentation/config/gpg.txt b/Documentation/config/gpg.txt
> > index f999f8ea49..cce2c89245 100644
> > --- a/Documentation/config/gpg.txt
> > +++ b/Documentation/config/gpg.txt
> > @@ -2,7 +2,7 @@ gpg.program::
> >       Use this custom program instead of "`gpg`" found on `$PATH` when
> >       making or verifying a PGP signature. The program must support the
> >       same command-line interface as GPG, namely, to verify a detached
> > -     signature, "`gpg --verify $file - <$signature`" is run, and the
> > +     signature, "`gpg --verify $signature - <$file`" is run, and the
> >       program is expected to signal a good signature by exiting with
> >       code 0, and to generate an ASCII-armored detached signature, the
> >       standard input of "`gpg -bsau $key`" is fed with the contents to be
>
> Wow.  Good find.
>
> gpg-interface.c::verify_signed_buffer() takes a detached signature
> in core, writes it to a temporary file and runs
>
>     gpg --status-fd=1 --verify $the_temporary_file
>
> and the payload that is supposed to match the given signature is fed
> via the standard input, so the above documentation is the only thing
> that needs fixing, which is good ;-)
>
> Thanks.
>
>
>

← back to recent threads