verify-tag: share code with verify-commit
verify-tag was executing an entirely different codepath than verify-commit, except for the underlying verify_signed_buffer. Move much of the code from check_commit_signature to a generic check_signature function and adjust both codepaths to call it. Update verify-tag to explicitly output the signature text, as we now call verify_signed_buffer with strbufs to catch the output, which prevents it from being printed automatically. Signed-off-by: brian m. carlson <sandals@crustytoothpaste.net> Signed-off-by: Junio C Hamano <gitster@pobox.com>
brian m. carlson committed
Jun 21, 2015 at 23:14 UTC
a4cc18f2934b8d2f00c7c3e11107acb6bfafe2c6
4 files changed
+34
-15
builtin/verify-tag.c
+8
-1
@@ -20,8 +20,11 @@ static const char * const verify_tag_usage[] = {
20
21
static int run_gpg_verify(const char *buf, unsigned long size, int verbose)
22
{
23
+ struct signature_check sigc;
24
int len;
25
26
+ memset(&sigc, 0, sizeof(sigc));
27
+
28
len = parse_signature(buf, size);
29
if (verbose)
30
write_in_full(1, buf, len);
@@ -29,7 +32,11 @@ static int run_gpg_verify(const char *buf, unsigned long size, int verbose)
32
if (size == len)
33
return error("no signature found");
34
32
- return verify_signed_buffer(buf, len, buf + len, size - len, NULL, NULL);
35
+ check_signature(buf, len, buf + len, size - len, &sigc);
36
+ fputs(sigc.gpg_output, stderr);
37
+
38
+ signature_check_clear(&sigc);
39
+ return sigc.result != 'G' && sigc.result != 'U';
40
}
41
42
static int verify_tag(const char *name, int verbose)
commit.c
+1
-14
@@ -1231,27 +1231,14 @@ void check_commit_signature(const struct commit *commit, struct signature_check
1231
{
1232
struct strbuf payload = STRBUF_INIT;
1233
struct strbuf signature = STRBUF_INIT;
1234
- struct strbuf gpg_output = STRBUF_INIT;
1235
- struct strbuf gpg_status = STRBUF_INIT;
1236
- int status;
1234
1235
sigc->result = 'N';
1236
1237
if (parse_signed_commit(commit, &payload, &signature) <= 0)
1238
goto out;
1242
- status = verify_signed_buffer(payload.buf, payload.len,
1243
- signature.buf, signature.len,
1244
- &gpg_output, &gpg_status);
1245
- if (status && !gpg_output.len)
1246
- goto out;
1247
- sigc->payload = strbuf_detach(&payload, NULL);
1248
- sigc->gpg_output = strbuf_detach(&gpg_output, NULL);
1249
- sigc->gpg_status = strbuf_detach(&gpg_status, NULL);
1250
- parse_gpg_output(sigc);
1239
+ check_signature(payload.buf, payload.len, signature.buf, signature.len, sigc);
1240
1241
out:
1253
- strbuf_release(&gpg_status);
1254
- strbuf_release(&gpg_output);
1242
strbuf_release(&payload);
1243
strbuf_release(&signature);
1244
}
gpg-interface.c
+23
@@ -60,6 +60,29 @@ void parse_gpg_output(struct signature_check *sigc)
60
}
61
}
62
63
+void check_signature(const char *payload, size_t plen, const char *signature,
64
+ size_t slen, struct signature_check *sigc)
65
+{
66
+ struct strbuf gpg_output = STRBUF_INIT;
67
+ struct strbuf gpg_status = STRBUF_INIT;
68
+ int status;
69
+
70
+ sigc->result = 'N';
71
+
72
+ status = verify_signed_buffer(payload, plen, signature, slen,
73
+ &gpg_output, &gpg_status);
74
+ if (status && !gpg_output.len)
75
+ goto out;
76
+ sigc->payload = xmemdupz(payload, plen);
77
+ sigc->gpg_output = strbuf_detach(&gpg_output, NULL);
78
+ sigc->gpg_status = strbuf_detach(&gpg_status, NULL);
79
+ parse_gpg_output(sigc);
80
+
81
+ out:
82
+ strbuf_release(&gpg_status);
83
+ strbuf_release(&gpg_output);
84
+}
85
+
86
/*
87
* Look at GPG signed content (e.g. a signed tag object), whose
88
* payload is followed by a detached signature on it. Return the
gpg-interface.h
+2
@@ -27,5 +27,7 @@ extern int verify_signed_buffer(const char *payload, size_t payload_size, const
27
extern int git_gpg_config(const char *, const char *, void *);
28
extern void set_signing_key(const char *);
29
extern const char *get_signing_key(void);
30
+extern void check_signature(const char *payload, size_t plen,
31
+ const char *signature, size_t slen, struct signature_check *sigc);
32
33
#endif