From: Junio C Hamano <gitster@pobox.com>
To: git@vger.kernel.org
Subject: [PATCH v5 23/23] t5541: test push --signed to smart HTTP server
Date: Mon, 15 Sep 2014 15:24:24 -0700 [thread overview]
Message-ID: <1410819864-22967-24-git-send-email-gitster@pobox.com> (raw)
In-Reply-To: <1410819864-22967-1-git-send-email-gitster@pobox.com>
Currently it seems that somewhere in the transport option setting
chain the "--signed" bit gets lost and this does not pass.
Signed-off-by: Junio C Hamano <gitster@pobox.com>
---
t/t5541-http-push-smart.sh | 39 +++++++++++++++++++++++++++++++++++++++
1 file changed, 39 insertions(+)
diff --git a/t/t5541-http-push-smart.sh b/t/t5541-http-push-smart.sh
index 73af16f..3915f67 100755
--- a/t/t5541-http-push-smart.sh
+++ b/t/t5541-http-push-smart.sh
@@ -14,6 +14,7 @@ fi
ROOT_PATH="$PWD"
. "$TEST_DIRECTORY"/lib-httpd.sh
. "$TEST_DIRECTORY"/lib-terminal.sh
+. "$TEST_DIRECTORY"/lib-gpg.sh
start_httpd
test_expect_success 'setup remote repository' '
@@ -323,5 +324,43 @@ test_expect_success 'push into half-auth-complete requires password' '
test_cmp expect actual
'
+test_expect_failure GPG 'push with post-receive to inspect certificate' '
+ (
+ cd "$HTTPD_DOCUMENT_ROOT_PATH"/test_repo.git &&
+ mkdir -p hooks &&
+ write_script hooks/post-receive <<-\EOF &&
+ # discard the update list
+ cat >/dev/null
+ # record the push certificate
+ if test -n "${GIT_PUSH_CERT-}"
+ then
+ git cat-file blob $GIT_PUSH_CERT >../push-cert
+ fi &&
+ env >../env &&
+ cat >../push-cert-status <<E_O_F
+ SIGNER=${GIT_PUSH_CERT_SIGNER-nobody}
+ KEY=${GIT_PUSH_CERT_KEY-nokey}
+ STATUS=${GIT_PUSH_CERT_STATUS-nostatus}
+ NONCE=${GIT_PUSH_CERT_NONCE-nononce}
+ E_O_F
+ EOF
+
+ git config receive.certnonceseed sekrit
+ ) &&
+ cd "$ROOT_PATH/test_repo_clone" &&
+ test_commit cert-test &&
+ git push --signed "$HTTPD_URL/smart/test_repo.git" &&
+ (
+ cd "$HTTPD_DOCUMENT_ROOT_PATH" &&
+ cat <<-\EOF &&
+ SIGNER=C O Mitter <committer@example.com>
+ KEY=13B6F51ECDDE430D
+ STATUS=G
+ EOF
+ sed -n -e "s/^nonce /NONCE=/p" -e "/^$/q" push-cert
+ ) >expect &&
+ test_cmp expect "$HTTPD_DOCUMENT_ROOT_PATH/push-cert-status"
+'
+
stop_httpd
test_done
--
2.1.0-410-gd72dacd
next prev parent reply other threads:[~2014-09-15 22:25 UTC|newest]
Thread overview: 27+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-09-15 22:24 [PATCH v5 00/23] Signed push Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 01/23] receive-pack: do not overallocate command structure Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 02/23] receive-pack: parse feature request a bit earlier Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 03/23] receive-pack: do not reuse old_sha1[] for other things Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 04/23] receive-pack: factor out queueing of command Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 05/23] send-pack: move REF_STATUS_REJECT_NODELETE logic a bit higher Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 06/23] send-pack: refactor decision to send update per ref Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 07/23] send-pack: always send capabilities Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 08/23] send-pack: factor out capability string generation Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 09/23] receive-pack: " Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 10/23] send-pack: rename "new_refs" to "need_pack_data" Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 11/23] send-pack: refactor inspecting and resetting status and sending commands Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 12/23] send-pack: clarify that cmds_sent is a boolean Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 13/23] gpg-interface: move parse_gpg_output() to where it should be Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 14/23] gpg-interface: move parse_signature() " Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 15/23] pack-protocol doc: typofix for PKT-LINE Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 16/23] push: the beginning of "git push --signed" Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 17/23] receive-pack: GPG-validate push certificates Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 18/23] send-pack: send feature request on push-cert packet Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 19/23] signed push: remove duplicated protocol info Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 20/23] signed push: add "pushee" header to push certificate Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 21/23] signed push: fortify against replay attacks Junio C Hamano
2014-09-15 22:24 ` [PATCH v5 22/23] signed push: allow stale nonce in stateless mode Junio C Hamano
2014-09-15 22:24 ` Junio C Hamano [this message]
2014-09-16 18:16 ` [PATCH v5 00/23] Signed push Jaime Soriano Pastor
2014-09-16 18:40 ` Junio C Hamano
2014-09-16 20:33 ` Eric Sunshine
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1410819864-22967-24-git-send-email-gitster@pobox.com \
--to=gitster@pobox.com \
--cc=git@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).