gpg: centralize signature check
verify-commit and verify-tag both share a central codepath for verifying commits: check_signature. However, verify-tag exited successfully for untrusted signature, while verify-commit exited unsuccessfully. Centralize this signature check and make verify-commit adopt the older verify-tag behavior. This behavior is more logical anyway, as the signature is in fact valid, whether or not there's a path of trust to the author. Signed-off-by: brian m. carlson <sandals@crustytoothpaste.net> Signed-off-by: Junio C Hamano <gitster@pobox.com>
brian m. carlson committed
Jun 21, 2015 at 23:14 UTC
434060ec6d9bf50f095db901da3fb9b557e11df1
7 files changed
+18
-10
builtin/verify-commit.c
+3
-2
@@ -21,10 +21,11 @@ static const char * const verify_commit_usage[] = {
21
static int run_gpg_verify(const unsigned char *sha1, const char *buf, unsigned long size, int verbose)
22
{
23
struct signature_check signature_check;
24
+ int ret;
25
26
memset(&signature_check, 0, sizeof(signature_check));
27
27
- check_commit_signature(lookup_commit(sha1), &signature_check);
28
+ ret = check_commit_signature(lookup_commit(sha1), &signature_check);
29
30
if (verbose && signature_check.payload)
31
fputs(signature_check.payload, stdout);
@@ -33,7 +34,7 @@ static int run_gpg_verify(const unsigned char *sha1, const char *buf, unsigned l
34
fputs(signature_check.gpg_output, stderr);
35
36
signature_check_clear(&signature_check);
36
- return signature_check.result != 'G';
37
+ return ret;
38
}
39
40
static int verify_commit(const char *name, int verbose)
builtin/verify-tag.c
+3
-2
@@ -22,6 +22,7 @@ static int run_gpg_verify(const char *buf, unsigned long size, int verbose)
22
{
23
struct signature_check sigc;
24
int len;
25
+ int ret;
26
27
memset(&sigc, 0, sizeof(sigc));
28
@@ -32,11 +33,11 @@ static int run_gpg_verify(const char *buf, unsigned long size, int verbose)
33
if (size == len)
34
return error("no signature found");
35
35
- check_signature(buf, len, buf + len, size - len, &sigc);
36
+ ret = check_signature(buf, len, buf + len, size - len, &sigc);
37
fputs(sigc.gpg_output, stderr);
38
39
signature_check_clear(&sigc);
39
- return sigc.result != 'G' && sigc.result != 'U';
40
+ return ret;
41
}
42
43
static int verify_tag(const char *name, int verbose)
commit.c
+6
-2
@@ -1227,20 +1227,24 @@ free_return:
1227
free(buf);
1228
}
1229
1230
-void check_commit_signature(const struct commit *commit, struct signature_check *sigc)
1230
+int check_commit_signature(const struct commit *commit, struct signature_check *sigc)
1231
{
1232
struct strbuf payload = STRBUF_INIT;
1233
struct strbuf signature = STRBUF_INIT;
1234
+ int ret = 1;
1235
1236
sigc->result = 'N';
1237
1238
if (parse_signed_commit(commit, &payload, &signature) <= 0)
1239
goto out;
1239
- check_signature(payload.buf, payload.len, signature.buf, signature.len, sigc);
1240
+ ret = check_signature(payload.buf, payload.len, signature.buf,
1241
+ signature.len, sigc);
1242
1243
out:
1244
strbuf_release(&payload);
1245
strbuf_release(&signature);
1246
+
1247
+ return ret;
1248
}
1249
1250
commit.h
+1
-1
@@ -375,7 +375,7 @@ extern void print_commit_list(struct commit_list *list,
375
* at all. This may allocate memory for sig->gpg_output, sig->gpg_status,
376
* sig->signer and sig->key.
377
*/
378
-extern void check_commit_signature(const struct commit *commit, struct signature_check *sigc);
378
+extern int check_commit_signature(const struct commit *commit, struct signature_check *sigc);
379
380
int compare_commits_by_commit_date(const void *a_, const void *b_, void *unused);
381
gpg-interface.c
+3
-1
@@ -60,7 +60,7 @@ void parse_gpg_output(struct signature_check *sigc)
60
}
61
}
62
63
-void check_signature(const char *payload, size_t plen, const char *signature,
63
+int check_signature(const char *payload, size_t plen, const char *signature,
64
size_t slen, struct signature_check *sigc)
65
{
66
struct strbuf gpg_output = STRBUF_INIT;
@@ -81,6 +81,8 @@ void check_signature(const char *payload, size_t plen, const char *signature,
81
out:
82
strbuf_release(&gpg_status);
83
strbuf_release(&gpg_output);
84
+
85
+ return sigc->result != 'G' && sigc->result != 'U';
86
}
87
88
/*
gpg-interface.h
+1
-1
@@ -27,7 +27,7 @@ extern int verify_signed_buffer(const char *payload, size_t payload_size, const
27
extern int git_gpg_config(const char *, const char *, void *);
28
extern void set_signing_key(const char *);
29
extern const char *get_signing_key(void);
30
-extern void check_signature(const char *payload, size_t plen,
30
+extern int check_signature(const char *payload, size_t plen,
31
const char *signature, size_t slen, struct signature_check *sigc);
32
33
#endif
t/t7510-signed-commit.sh
+1
-1
@@ -81,7 +81,7 @@ test_expect_success GPG 'verify and show signatures' '
81
)
82
'
83
84
-test_expect_failure GPG 'verify-commit exits success on untrusted signature' '
84
+test_expect_success GPG 'verify-commit exits success on untrusted signature' '
85
git verify-commit eighth-signed-alt 2>actual &&
86
grep "Good signature from" actual &&
87
! grep "BAD signature from" actual &&