verify-tag: share code with verify-commit

verify-tag was executing an entirely different codepath than verify-commit, except for the underlying verify_signed_buffer. Move much of the code from check_commit_signature to a generic check_signature function and adjust both codepaths to call it. Update verify-tag to explicitly output the signature text, as we now call verify_signed_buffer with strbufs to catch the output, which prevents it from being printed automatically. Signed-off-by: brian m. carlson <sandals@crustytoothpaste.net> Signed-off-by: Junio C Hamano <gitster@pobox.com>

brian m. carlson committed Jun 21, 2015 at 23:14 UTC a4cc18f2934b8d2f00c7c3e11107acb6bfafe2c6
4 files changed +34 -15
builtin/verify-tag.c
+8 -1
@@ -20,8 +20,11 @@ static const char * const verify_tag_usage[] = {
20
21 static int run_gpg_verify(const char *buf, unsigned long size, int verbose)
22 {
23 + struct signature_check sigc;
24 int len;
25
26 + memset(&sigc, 0, sizeof(sigc));
27 +
28 len = parse_signature(buf, size);
29 if (verbose)
30 write_in_full(1, buf, len);
@@ -29,7 +32,11 @@ static int run_gpg_verify(const char *buf, unsigned long size, int verbose)
32 if (size == len)
33 return error("no signature found");
34
32 - return verify_signed_buffer(buf, len, buf + len, size - len, NULL, NULL);
35 + check_signature(buf, len, buf + len, size - len, &sigc);
36 + fputs(sigc.gpg_output, stderr);
37 +
38 + signature_check_clear(&sigc);
39 + return sigc.result != 'G' && sigc.result != 'U';
40 }
41
42 static int verify_tag(const char *name, int verbose)
commit.c
+1 -14
@@ -1231,27 +1231,14 @@ void check_commit_signature(const struct commit *commit, struct signature_check
1231 {
1232 struct strbuf payload = STRBUF_INIT;
1233 struct strbuf signature = STRBUF_INIT;
1234 - struct strbuf gpg_output = STRBUF_INIT;
1235 - struct strbuf gpg_status = STRBUF_INIT;
1236 - int status;
1234
1235 sigc->result = 'N';
1236
1237 if (parse_signed_commit(commit, &payload, &signature) <= 0)
1238 goto out;
1242 - status = verify_signed_buffer(payload.buf, payload.len,
1243 - signature.buf, signature.len,
1244 - &gpg_output, &gpg_status);
1245 - if (status && !gpg_output.len)
1246 - goto out;
1247 - sigc->payload = strbuf_detach(&payload, NULL);
1248 - sigc->gpg_output = strbuf_detach(&gpg_output, NULL);
1249 - sigc->gpg_status = strbuf_detach(&gpg_status, NULL);
1250 - parse_gpg_output(sigc);
1239 + check_signature(payload.buf, payload.len, signature.buf, signature.len, sigc);
1240
1241 out:
1253 - strbuf_release(&gpg_status);
1254 - strbuf_release(&gpg_output);
1242 strbuf_release(&payload);
1243 strbuf_release(&signature);
1244 }
gpg-interface.c
+23
@@ -60,6 +60,29 @@ void parse_gpg_output(struct signature_check *sigc)
60 }
61 }
62
63 +void check_signature(const char *payload, size_t plen, const char *signature,
64 + size_t slen, struct signature_check *sigc)
65 +{
66 + struct strbuf gpg_output = STRBUF_INIT;
67 + struct strbuf gpg_status = STRBUF_INIT;
68 + int status;
69 +
70 + sigc->result = 'N';
71 +
72 + status = verify_signed_buffer(payload, plen, signature, slen,
73 + &gpg_output, &gpg_status);
74 + if (status && !gpg_output.len)
75 + goto out;
76 + sigc->payload = xmemdupz(payload, plen);
77 + sigc->gpg_output = strbuf_detach(&gpg_output, NULL);
78 + sigc->gpg_status = strbuf_detach(&gpg_status, NULL);
79 + parse_gpg_output(sigc);
80 +
81 + out:
82 + strbuf_release(&gpg_status);
83 + strbuf_release(&gpg_output);
84 +}
85 +
86 /*
87 * Look at GPG signed content (e.g. a signed tag object), whose
88 * payload is followed by a detached signature on it. Return the
gpg-interface.h
+2
@@ -27,5 +27,7 @@ extern int verify_signed_buffer(const char *payload, size_t payload_size, const
27 extern int git_gpg_config(const char *, const char *, void *);
28 extern void set_signing_key(const char *);
29 extern const char *get_signing_key(void);
30 +extern void check_signature(const char *payload, size_t plen,
31 + const char *signature, size_t slen, struct signature_check *sigc);
32
33 #endif