From: Junio C Hamano <gitster@pobox.com>
To: git@vger.kernel.org
Subject: [PATCH v5 00/23] Signed push
Date: Mon, 15 Sep 2014 15:24:01 -0700 [thread overview]
Message-ID: <1410819864-22967-1-git-send-email-gitster@pobox.com> (raw)
The first round is found at $gmane/255520.
The second round is found at $gmane/255701.
The third round is found at $gmane/256464.
The forth round is found at $gmane/256518.
Not much had to have changed since the last round, except for the
hooks used in the test that have been fixed to slurp all its input
in.
A failing test has been added at the end for smart HTTP. It appears
that somewhere in the callchain "--signed" is forgotten and the
sending end not to send the certificate for some reason. If
somebody with a fresh set of eyes can look into it, that would be
very much appreciated, as I do not expect I would have sufficient
concentration to dig it quickly for several days at least.
Junio C Hamano (23):
receive-pack: do not overallocate command structure
receive-pack: parse feature request a bit earlier
receive-pack: do not reuse old_sha1[] for other things
receive-pack: factor out queueing of command
send-pack: move REF_STATUS_REJECT_NODELETE logic a bit higher
send-pack: refactor decision to send update per ref
send-pack: always send capabilities
send-pack: factor out capability string generation
receive-pack: factor out capability string generation
send-pack: rename "new_refs" to "need_pack_data"
send-pack: refactor inspecting and resetting status and sending
commands
send-pack: clarify that cmds_sent is a boolean
gpg-interface: move parse_gpg_output() to where it should be
gpg-interface: move parse_signature() to where it should be
pack-protocol doc: typofix for PKT-LINE
push: the beginning of "git push --signed"
receive-pack: GPG-validate push certificates
send-pack: send feature request on push-cert packet
signed push: remove duplicated protocol info
signed push: add "pushee" header to push certificate
signed push: fortify against replay attacks
signed push: allow stale nonce in stateless mode
t5541: test push --signed to smart HTTP server
Documentation/config.txt | 6 +
Documentation/git-push.txt | 9 +-
Documentation/git-receive-pack.txt | 63 +++-
Documentation/technical/pack-protocol.txt | 49 ++-
Documentation/technical/protocol-capabilities.txt | 13 +-
builtin/push.c | 1 +
builtin/receive-pack.c | 354 +++++++++++++++++++---
commit.c | 36 ---
gpg-interface.c | 57 ++++
gpg-interface.h | 17 +-
send-pack.c | 201 +++++++++---
send-pack.h | 2 +
t/t5534-push-signed.sh | 125 ++++++++
t/t5541-http-push-smart.sh | 39 +++
tag.c | 20 --
tag.h | 1 -
transport.c | 5 +
transport.h | 5 +
18 files changed, 847 insertions(+), 156 deletions(-)
create mode 100755 t/t5534-push-signed.sh
--
2.1.0-410-gd72dacd
next reply other threads:[~2014-09-15 22:24 UTC|newest]
Thread overview: 27+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-09-15 22:24 Junio C Hamano [this message]
2014-09-15 22:24 ` [PATCH v5 01/23] receive-pack: do not overallocate command structure Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 02/23] receive-pack: parse feature request a bit earlier Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 03/23] receive-pack: do not reuse old_sha1[] for other things Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 04/23] receive-pack: factor out queueing of command Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 05/23] send-pack: move REF_STATUS_REJECT_NODELETE logic a bit higher Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 06/23] send-pack: refactor decision to send update per ref Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 07/23] send-pack: always send capabilities Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 08/23] send-pack: factor out capability string generation Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 09/23] receive-pack: " Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 10/23] send-pack: rename "new_refs" to "need_pack_data" Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 11/23] send-pack: refactor inspecting and resetting status and sending commands Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 12/23] send-pack: clarify that cmds_sent is a boolean Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 13/23] gpg-interface: move parse_gpg_output() to where it should be Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 14/23] gpg-interface: move parse_signature() " Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 15/23] pack-protocol doc: typofix for PKT-LINE Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 16/23] push: the beginning of "git push --signed" Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 17/23] receive-pack: GPG-validate push certificates Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 18/23] send-pack: send feature request on push-cert packet Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 19/23] signed push: remove duplicated protocol info Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 20/23] signed push: add "pushee" header to push certificate Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 21/23] signed push: fortify against replay attacks Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 22/23] signed push: allow stale nonce in stateless mode Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 23/23] t5541: test push --signed to smart HTTP server Junio C Hamano
2014-09-16 18:16 ` [PATCH v5 00/23] Signed push Jaime Soriano Pastor
2014-09-16 18:40 ` Junio C Hamano
2014-09-16 20:33 ` Eric Sunshine
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1410819864-22967-1-git-send-email-gitster@pobox.com \
--to=gitster@pobox.com \
--cc=git@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).