git.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: Junio C Hamano <gitster@pobox.com>
To: git@vger.kernel.org
Subject: [PATCH v5 00/23] Signed push
Date: Mon, 15 Sep 2014 15:24:01 -0700	[thread overview]
Message-ID: <1410819864-22967-1-git-send-email-gitster@pobox.com> (raw)

The first round is found at $gmane/255520.
The second round is found at $gmane/255701.
The third round is found at $gmane/256464.
The forth round is found at $gmane/256518.

Not much had to have changed since the last round, except for the
hooks used in the test that have been fixed to slurp all its input
in.

A failing test has been added at the end for smart HTTP.  It appears
that somewhere in the callchain "--signed" is forgotten and the
sending end not to send the certificate for some reason.  If
somebody with a fresh set of eyes can look into it, that would be
very much appreciated, as I do not expect I would have sufficient
concentration to dig it quickly for several days at least.

Junio C Hamano (23):
  receive-pack: do not overallocate command structure
  receive-pack: parse feature request a bit earlier
  receive-pack: do not reuse old_sha1[] for other things
  receive-pack: factor out queueing of command
  send-pack: move REF_STATUS_REJECT_NODELETE logic a bit higher
  send-pack: refactor decision to send update per ref
  send-pack: always send capabilities
  send-pack: factor out capability string generation
  receive-pack: factor out capability string generation
  send-pack: rename "new_refs" to "need_pack_data"
  send-pack: refactor inspecting and resetting status and sending
    commands
  send-pack: clarify that cmds_sent is a boolean
  gpg-interface: move parse_gpg_output() to where it should be
  gpg-interface: move parse_signature() to where it should be
  pack-protocol doc: typofix for PKT-LINE
  push: the beginning of "git push --signed"
  receive-pack: GPG-validate push certificates
  send-pack: send feature request on push-cert packet
  signed push: remove duplicated protocol info
  signed push: add "pushee" header to push certificate
  signed push: fortify against replay attacks
  signed push: allow stale nonce in stateless mode
  t5541: test push --signed to smart HTTP server

 Documentation/config.txt                          |   6 +
 Documentation/git-push.txt                        |   9 +-
 Documentation/git-receive-pack.txt                |  63 +++-
 Documentation/technical/pack-protocol.txt         |  49 ++-
 Documentation/technical/protocol-capabilities.txt |  13 +-
 builtin/push.c                                    |   1 +
 builtin/receive-pack.c                            | 354 +++++++++++++++++++---
 commit.c                                          |  36 ---
 gpg-interface.c                                   |  57 ++++
 gpg-interface.h                                   |  17 +-
 send-pack.c                                       | 201 +++++++++---
 send-pack.h                                       |   2 +
 t/t5534-push-signed.sh                            | 125 ++++++++
 t/t5541-http-push-smart.sh                        |  39 +++
 tag.c                                             |  20 --
 tag.h                                             |   1 -
 transport.c                                       |   5 +
 transport.h                                       |   5 +
 18 files changed, 847 insertions(+), 156 deletions(-)
 create mode 100755 t/t5534-push-signed.sh

-- 
2.1.0-410-gd72dacd

             reply	other threads:[~2014-09-15 22:24 UTC|newest]

Thread overview: 27+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2014-09-15 22:24 Junio C Hamano [this message]
2014-09-15 22:24 ` [PATCH v5 01/23] receive-pack: do not overallocate command structure Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 02/23] receive-pack: parse feature request a bit earlier Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 03/23] receive-pack: do not reuse old_sha1[] for other things Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 04/23] receive-pack: factor out queueing of command Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 05/23] send-pack: move REF_STATUS_REJECT_NODELETE logic a bit higher Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 06/23] send-pack: refactor decision to send update per ref Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 07/23] send-pack: always send capabilities Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 08/23] send-pack: factor out capability string generation Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 09/23] receive-pack: " Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 10/23] send-pack: rename "new_refs" to "need_pack_data" Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 11/23] send-pack: refactor inspecting and resetting status and sending commands Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 12/23] send-pack: clarify that cmds_sent is a boolean Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 13/23] gpg-interface: move parse_gpg_output() to where it should be Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 14/23] gpg-interface: move parse_signature() " Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 15/23] pack-protocol doc: typofix for PKT-LINE Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 16/23] push: the beginning of "git push --signed" Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 17/23] receive-pack: GPG-validate push certificates Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 18/23] send-pack: send feature request on push-cert packet Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 19/23] signed push: remove duplicated protocol info Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 20/23] signed push: add "pushee" header to push certificate Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 21/23] signed push: fortify against replay attacks Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 22/23] signed push: allow stale nonce in stateless mode Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 23/23] t5541: test push --signed to smart HTTP server Junio C Hamano
2014-09-16 18:16 ` [PATCH v5 00/23] Signed push Jaime Soriano Pastor
2014-09-16 18:40 ` Junio C Hamano
2014-09-16 20:33   ` Eric Sunshine

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1410819864-22967-1-git-send-email-gitster@pobox.com \
    --to=gitster@pobox.com \
    --cc=git@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).