Skip to content

Commit aba9119

Browse files
jasamplergitster
authored andcommitted
git-tag -s must fail if gpg cannot sign the tag.
Most of this patch code and message was written by Shawn O. Pearce. I made some tests to know what the problem was, and then I changed the code related with the SIGPIPE signal. If the user has misconfigured `user.signingkey` in their .git/config or just doesn't have any secret keys on their keyring and they ask for a signed tag with `git tag -s` we better make sure the resulting tag was actually signed by gpg. Prior versions of builtin git-tag allowed this failure to slip by without error as they were not checking the return value of the finish_command() so they did not notice when gpg exited with an error exit status. They also did not fail if gpg produced an empty output or if read_in_full received an error from the read system call while trying to read the pipe back from gpg. Finally, we did not actually honor any return value from the do_sign function as it returns ssize_t but was being stored into an unsigned long. This caused the compiler to optimize out the die condition, allowing git-tag to continue along and create the tag object. However, when gpg gets a wrong username, it exits before any read was done and then the writing process receives SIGPIPE and program is terminated. By ignoring this signal, anyway, the function write_or_die gets EPIPE from write_in_full and exits returning 0 to the system without a message. Here we better call to write_in_full directly so we can fail printing a message and return safely to the caller. With these issues fixed `git-tag -s` will now fail to create the tag and will report a non-zero exit status to its caller, thereby allowing automated helper scripts to detect (and recover from) failure if gpg is not working properly. Proposed-by: Shawn O. Pearce <spearce@spearce.org> Signed-off-by: Carlos Rica <jasampler@gmail.com> Signed-off-by: Junio C Hamano <gitster@pobox.com>
1 parent 7b02b85 commit aba9119

File tree

2 files changed

+21
-4
lines changed

2 files changed

+21
-4
lines changed

builtin-tag.c

Lines changed: 14 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -200,6 +200,10 @@ static ssize_t do_sign(char *buffer, size_t size, size_t max)
200200
bracket[1] = '\0';
201201
}
202202

203+
/* When the username signingkey is bad, program could be terminated
204+
* because gpg exits without reading and then write gets SIGPIPE. */
205+
signal(SIGPIPE, SIG_IGN);
206+
203207
memset(&gpg, 0, sizeof(gpg));
204208
gpg.argv = args;
205209
gpg.in = -1;
@@ -212,12 +216,17 @@ static ssize_t do_sign(char *buffer, size_t size, size_t max)
212216
if (start_command(&gpg))
213217
return error("could not run gpg.");
214218

215-
write_or_die(gpg.in, buffer, size);
219+
if (write_in_full(gpg.in, buffer, size) != size) {
220+
close(gpg.in);
221+
finish_command(&gpg);
222+
return error("gpg did not accept the tag data");
223+
}
216224
close(gpg.in);
217225
gpg.close_in = 0;
218226
len = read_in_full(gpg.out, buffer + size, max - size);
219227

220-
finish_command(&gpg);
228+
if (finish_command(&gpg) || !len || len < 0)
229+
return error("gpg failed to sign the tag");
221230

222231
if (len == max - size)
223232
return error("could not read the entire signature from gpg.");
@@ -310,9 +319,10 @@ static void create_tag(const unsigned char *object, const char *tag,
310319
size += header_len;
311320

312321
if (sign) {
313-
size = do_sign(buffer, size, max_size);
314-
if (size < 0)
322+
ssize_t r = do_sign(buffer, size, max_size);
323+
if (r < 0)
315324
die("unable to sign the tag");
325+
size = r;
316326
}
317327

318328
if (write_sha1_file(buffer, size, tag_type, result) < 0)

t/t7004-tag.sh

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -990,6 +990,13 @@ test_expect_success \
990990
git diff expect actual
991991
'
992992

993+
# try to sign with bad user.signingkey
994+
git config user.signingkey BobTheMouse
995+
test_expect_failure \
996+
'git-tag -s fails if gpg is misconfigured' \
997+
'git tag -s -m tail tag-gpg-failure'
998+
git config --unset user.signingkey
999+
9931000
# try to verify without gpg:
9941001

9951002
rm -rf gpghome

0 commit comments

Comments
 (0)