From ef2bab7f59005c9e1215490d66faca6ea0fe0055 Mon Sep 17 00:00:00 2001 From: Todd Zullinger Date: Mon, 10 Jan 2022 17:49:49 -0500 Subject: [PATCH 1/9] update to 2.35.0-rc0 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Add openssh-clients BuildRequires, for ssh-add. Upstream 350a2518c8 (ssh signing: support non ssh-* keytypes, 2021-11-19), added `ssh-add` as a requirement of t7528-signed-commit-ssh's "sign commits using literal public keys with ssh-agent" test. Replace the openssh BR added in e8896ce (update to 2.34.0, 2021-11-15) with openssh-clients. The latter requires the former. Apply Taylor Blau's patch to fix a use-after-free bug in fmt-merge-msg¹. Add `missing !LONG_IS_64BIT,EXPENSIVE` to git.skip-test-patterns. It is used in t1051-large-conversion after upstream 596b5e77c9 (clean/smudge: allow clean filters to process extremely large files, 2021-11-02). Release notes: https://github.com/git/git/raw/v2.35.0-rc0/Documentation/RelNotes/2.35.0.txt ¹ https://lore.kernel.org/git/CAHk-=whXPxWL7z3GiPkaDt+yygrRmagrYUnib7Lx=Vvrqx2ufg@mail.gmail.com/ --- ...event-use-after-free-with-signed-tag.patch | 199 ++++++++++++++++++ git.skip-test-patterns | 2 +- git.spec | 15 +- sources | 4 +- 4 files changed, 213 insertions(+), 7 deletions(-) create mode 100644 0001-fmt-merge-msg-prevent-use-after-free-with-signed-tag.patch diff --git a/0001-fmt-merge-msg-prevent-use-after-free-with-signed-tag.patch b/0001-fmt-merge-msg-prevent-use-after-free-with-signed-tag.patch new file mode 100644 index 0000000..72cd990 --- /dev/null +++ b/0001-fmt-merge-msg-prevent-use-after-free-with-signed-tag.patch @@ -0,0 +1,199 @@ +From mboxrd@z Thu Jan 1 00:00:00 1970 +Return-Path: +X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on + aws-us-west-2-korg-lkml-1.web.codeaurora.org +Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) + by smtp.lore.kernel.org (Postfix) with ESMTP id 4EF60C433EF + for ; Mon, 10 Jan 2022 21:19:15 +0000 (UTC) +Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand + id S1343852AbiAJVTN (ORCPT ); + Mon, 10 Jan 2022 16:19:13 -0500 +Received: from lindbergh.monkeyblade.net ([23.128.96.19]:45246 "EHLO + lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org + with ESMTP id S240793AbiAJVTJ (ORCPT ); + Mon, 10 Jan 2022 16:19:09 -0500 +Received: from mail-io1-xd32.google.com (mail-io1-xd32.google.com [IPv6:2607:f8b0:4864:20::d32]) + by lindbergh.monkeyblade.net (Postfix) with ESMTPS id D57E9C06173F + for ; Mon, 10 Jan 2022 13:19:08 -0800 (PST) +Received: by mail-io1-xd32.google.com with SMTP id h23so19409080iol.11 + for ; Mon, 10 Jan 2022 13:19:08 -0800 (PST) +DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; + d=ttaylorr-com.20210112.gappssmtp.com; s=20210112; + h=date:from:to:cc:subject:message-id:references:mime-version + :content-disposition:in-reply-to; + bh=FTrKkNrsW7oFf2weWFjBUCeY4AzPYNFulnRyLyCVrk8=; + b=z+XM3REbAP5x9W9gK6pBjzm9BHigJ0mkHwdcjCN9VQSWk7aIMxsxwVauiC4+Y15Py4 + e4kEWLSahtCS62N2410rXTW5F4IiCjrtU+iZztr+gz2IfLpV70e3CO2WaIRGNPRJm2g0 + Gl1+Y32Gk2jkmZ7w/ue8yng54F8FHEvg5joJFj19bMoWF0kd16ny2U+SjCfurbJu7Qpm + 7qMJtWStXIt8SBVaYdqvMjIylr3zDEvOolaSUBxXZYmD51XjQJXFL4DaYTvT6RIRsBZF + gcdEfTKQ3MdH7Dr8AbiaERh3vNXQ9oKb1cHL7aodKSAS6/NpSSvKMxmW+7n4yICL7hsM + b8pQ== +X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; + d=1e100.net; s=20210112; + h=x-gm-message-state:date:from:to:cc:subject:message-id:references + :mime-version:content-disposition:in-reply-to; + bh=FTrKkNrsW7oFf2weWFjBUCeY4AzPYNFulnRyLyCVrk8=; + b=YyvJy1w+MELo/HMukbimTZO7p+9odhEtnD9F2+GB68WqNtHOSqLj+FNJKrl2cWUWPM + Oec5Mop17BPiDQ5du2gbK9mEJMae9wPoqUhJijzgbcfyH8nAHG8XgBD8PYhzcdaKiwZW + 1/rhWRpyqsAmRKRnXBk+qXOydG6sbeJqYIDiHxHV/MWXzXK8L1tw0TN6x+ovUHJ8tOuu + ZStLc+f7IV9gr3soTs3R4sloQluxitDfe4RReEpc0HDcPxG0V91aiT4MxULStqcCqUbz + I1S0PJMehkw5RIZvrW8GpPjBGFao6X30hvxBN1Skq/nq1rUbbIwat343WUGUC/LogIAV + Wd5A== +X-Gm-Message-State: AOAM533g0jVnFyUCJsyN7y07jhNAhfATafqgniWHcVni8kH1UQ43T/Cd + 76bWXlo05ji/88mEupUArvoHr60/63d4qA== +X-Google-Smtp-Source: ABdhPJwh3a+flp+ajvTa6YBvQY7iqlxqOUdkFKcfZ3ahJTw9JXb3F4kXsRKSfwjHXJ9SQm7cyHyn1Q== +X-Received: by 2002:a05:6638:3009:: with SMTP id r9mr861119jak.262.1641849548063; + Mon, 10 Jan 2022 13:19:08 -0800 (PST) +Received: from localhost (104-178-186-189.lightspeed.milwwi.sbcglobal.net. [104.178.186.189]) + by smtp.gmail.com with ESMTPSA id t6sm5035566iov.39.2022.01.10.13.19.07 + (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); + Mon, 10 Jan 2022 13:19:07 -0800 (PST) +Date: Mon, 10 Jan 2022 16:19:06 -0500 +From: Taylor Blau +To: git@vger.kernel.org +Cc: Junio C Hamano , + Linus Torvalds , + Fabian Stelzer +Subject: [PATCH] fmt-merge-msg: prevent use-after-free with signed tags +Message-ID: <6e08b73d602853b3de71257117e85e32b96b5c19.1641849502.git.me@ttaylorr.com> +References: +MIME-Version: 1.0 +Content-Type: text/plain; charset=utf-8 +Content-Disposition: inline +In-Reply-To: +Precedence: bulk +List-ID: +X-Mailing-List: git@vger.kernel.org + +When merging a signed tag, fmt_merge_msg_sigs() is responsible for +populating the body of the merge message with the names of the signed +tags, their signatures, and the validity of those signatures. + +In 02769437e1 (ssh signing: use sigc struct to pass payload, +2021-12-09), check_signature() was taught to pass the object payload via +the sigc struct instead of passing the payload buffer separately. + +In effect, 02769437e1 causes buf, and sigc.payload to point at the same +region in memory. This causes a problem for fmt_tag_signature(), which +wants to read from this location, since it is freed beforehand by +signature_check_clear() (which frees it via sigc's `payload` member). + +That makes the subsequent use in fmt_tag_signature() a use-after-free. + +As a result, merge messages did not contain the body of any signed tags. +Luckily, they tend not to contain garbage, either, since the result of +strstr()-ing the object buffer in fmt_tag_signature() is guarded: + + const char *tag_body = strstr(buf, "\n\n"); + if (tag_body) { + tag_body += 2; + strbuf_add(tagbuf, tag_body, buf + len - tag_body); + } + +Unfortunately, the tests in t6200 did not catch this at the time because +they do not search for the body of signed tags in fmt-merge-msg's +output. + +Resolve this by waiting to call signature_check_clear() until after its +contents can be safely discarded. Harden ourselves against any future +regressions in this area by making sure we can find signed tag messages +in the output of fmt-merge-msg, too. + +Reported-by: Linus Torvalds +Signed-off-by: Taylor Blau +--- + fmt-merge-msg.c | 2 +- + t/t6200-fmt-merge-msg.sh | 8 ++++++++ + 2 files changed, 9 insertions(+), 1 deletion(-) + +diff --git a/fmt-merge-msg.c b/fmt-merge-msg.c +index e5c0aff2bf..baca57d5b6 100644 +--- a/fmt-merge-msg.c ++++ b/fmt-merge-msg.c +@@ -541,7 +541,6 @@ static void fmt_merge_msg_sigs(struct strbuf *out) + else + strbuf_addstr(&sig, sigc.output); + } +- signature_check_clear(&sigc); + + if (!tag_number++) { + fmt_tag_signature(&tagbuf, &sig, buf, len); +@@ -565,6 +564,7 @@ static void fmt_merge_msg_sigs(struct strbuf *out) + } + strbuf_release(&payload); + strbuf_release(&sig); ++ signature_check_clear(&sigc); + next: + free(origbuf); + } +diff --git a/t/t6200-fmt-merge-msg.sh b/t/t6200-fmt-merge-msg.sh +index 7544245f90..5a221f8ef1 100755 +--- a/t/t6200-fmt-merge-msg.sh ++++ b/t/t6200-fmt-merge-msg.sh +@@ -126,6 +126,7 @@ test_expect_success GPG 'message for merging local tag signed by good key' ' + git fetch . signed-good-tag && + git fmt-merge-msg <.git/FETCH_HEAD >actual && + grep "^Merge tag ${apos}signed-good-tag${apos}" actual && ++ grep "^signed-tag-msg" actual && + grep "^# gpg: Signature made" actual && + grep "^# gpg: Good signature from" actual + ' +@@ -135,6 +136,7 @@ test_expect_success GPG 'message for merging local tag signed by unknown key' ' + git fetch . signed-good-tag && + GNUPGHOME=. git fmt-merge-msg <.git/FETCH_HEAD >actual && + grep "^Merge tag ${apos}signed-good-tag${apos}" actual && ++ grep "^signed-tag-msg" actual && + grep "^# gpg: Signature made" actual && + grep -E "^# gpg: Can${apos}t check signature: (public key not found|No public key)" actual + ' +@@ -145,6 +147,7 @@ test_expect_success GPGSSH 'message for merging local tag signed by good ssh key + git fetch . signed-good-ssh-tag && + git fmt-merge-msg <.git/FETCH_HEAD >actual && + grep "^Merge tag ${apos}signed-good-ssh-tag${apos}" actual && ++ grep "^signed-ssh-tag-msg" actual && + grep "${GPGSSH_GOOD_SIGNATURE_TRUSTED}" actual && + ! grep "${GPGSSH_BAD_SIGNATURE}" actual + ' +@@ -155,6 +158,7 @@ test_expect_success GPGSSH 'message for merging local tag signed by unknown ssh + git fetch . signed-untrusted-ssh-tag && + git fmt-merge-msg <.git/FETCH_HEAD >actual && + grep "^Merge tag ${apos}signed-untrusted-ssh-tag${apos}" actual && ++ grep "^signed-ssh-tag-msg-untrusted" actual && + grep "${GPGSSH_GOOD_SIGNATURE_UNTRUSTED}" actual && + ! grep "${GPGSSH_BAD_SIGNATURE}" actual && + grep "${GPGSSH_KEY_NOT_TRUSTED}" actual +@@ -166,6 +170,7 @@ test_expect_success GPGSSH,GPGSSH_VERIFYTIME 'message for merging local tag sign + git fetch . expired-signed && + git fmt-merge-msg <.git/FETCH_HEAD >actual && + grep "^Merge tag ${apos}expired-signed${apos}" actual && ++ grep "^expired-signed" actual && + ! grep "${GPGSSH_GOOD_SIGNATURE_TRUSTED}" actual + ' + +@@ -175,6 +180,7 @@ test_expect_success GPGSSH,GPGSSH_VERIFYTIME 'message for merging local tag sign + git fetch . notyetvalid-signed && + git fmt-merge-msg <.git/FETCH_HEAD >actual && + grep "^Merge tag ${apos}notyetvalid-signed${apos}" actual && ++ grep "^notyetvalid-signed" actual && + ! grep "${GPGSSH_GOOD_SIGNATURE_TRUSTED}" actual + ' + +@@ -184,6 +190,7 @@ test_expect_success GPGSSH,GPGSSH_VERIFYTIME 'message for merging local tag sign + git fetch . timeboxedvalid-signed && + git fmt-merge-msg <.git/FETCH_HEAD >actual && + grep "^Merge tag ${apos}timeboxedvalid-signed${apos}" actual && ++ grep "^timeboxedvalid-signed" actual && + grep "${GPGSSH_GOOD_SIGNATURE_TRUSTED}" actual && + ! grep "${GPGSSH_BAD_SIGNATURE}" actual + ' +@@ -194,6 +201,7 @@ test_expect_success GPGSSH,GPGSSH_VERIFYTIME 'message for merging local tag sign + git fetch . timeboxedinvalid-signed && + git fmt-merge-msg <.git/FETCH_HEAD >actual && + grep "^Merge tag ${apos}timeboxedinvalid-signed${apos}" actual && ++ grep "^timeboxedinvalid-signed" actual && + ! grep "${GPGSSH_GOOD_SIGNATURE_TRUSTED}" actual + ' + +-- +2.34.1.455.gd6eb6fd089 + diff --git a/git.skip-test-patterns b/git.skip-test-patterns index 1f1f8b1..bd44452 100644 --- a/git.skip-test-patterns +++ b/git.skip-test-patterns @@ -4,7 +4,7 @@ GIT_SKIP_TESTS missing AUTOIDENT missing CASE_INSENSITIVE_FS missing DONTHAVEIT -missing EXPENSIVE +missing ([!]LONG_IS_64BIT,)?EXPENSIVE missing JGIT missing !?LAZY_(TRUE|FALSE) missing MINGW diff --git a/git.spec b/git.spec index 6b12273..ea1b95b 100644 --- a/git.spec +++ b/git.spec @@ -76,11 +76,11 @@ %endif # Define for release candidates -#global rcrev .rc0 +%global rcrev .rc0 Name: git -Version: 2.34.1 -Release: 1%{?rcrev}%{?dist} +Version: 2.35.0 +Release: 0.0%{?rcrev}%{?dist} Summary: Fast Version Control System License: GPLv2 URL: https://git-scm.com/ @@ -119,6 +119,10 @@ Patch3: 0003-t-lib-gpg-kill-all-gpg-components-not-just-gpg-agent.patch Patch4: 0004-t4202-match-gpgsm-output-from-GnuPG-2.3.patch Patch5: 0005-gpg-interface-match-SIG_CREATED-if-it-s-the-first-li.patch +# Fix tag message contents +# https://lore.kernel.org/git/CAHk-=whXPxWL7z3GiPkaDt+yygrRmagrYUnib7Lx=Vvrqx2ufg@mail.gmail.com/ +Patch6: https://lore.kernel.org/git/6e08b73d602853b3de71257117e85e32b96b5c19.1641849502.git.me@ttaylorr.com/raw#/0001-fmt-merge-msg-prevent-use-after-free-with-signed-tag.patch + %if %{with docs} # pod2man is needed to build Git.3pm BuildRequires: %{_bindir}/pod2man @@ -218,7 +222,7 @@ BuildRequires: jgit %endif # endif fedora (except i386 and s390x) BuildRequires: mod_dav_svn -BuildRequires: openssh +BuildRequires: openssh-clients BuildRequires: perl(App::Prove) BuildRequires: perl(CGI) BuildRequires: perl(CGI::Carp) @@ -1008,6 +1012,9 @@ rmdir --ignore-fail-on-non-empty "$testdir" %{?with_docs:%{_pkgdocdir}/git-svn.html} %changelog +* Mon Jan 10 2022 Todd Zullinger - 2.35.0-0.0.rc0 +- update to 2.35.0-rc0 + * Thu Nov 25 2021 Todd Zullinger - 2.34.1-1 - update to 2.34.1 - fix gpgsm issues with gnupg-2.3 diff --git a/sources b/sources index 9c138f8..4e6eca9 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ -SHA512 (git-2.34.1.tar.xz) = a1a8e9e6f64b1da25508fbd2f783564dcdbe181fb5ff1ebab3bdac6db6094e18acc334479a1abf22ac17ce4f733cc3e10a664db9ab234cd523735a3f027b42db -SHA512 (git-2.34.1.tar.sign) = a1111276e18da1a7b360e3ed3b8460034ea413b116482b0b66342f8873a9dd02a90f3f5bc7ad1e4b3c7f39ed55926a8155064b849e6e6bdf9478cb85b93f10b5 +SHA512 (git-2.35.0.rc0.tar.xz) = 9aa5d89d7981c73d32e9023dfc61a62e63688c3172cba4bee145b2ff4f5f7bc497435d1b4b535089c698893feabc6057a6522676e52bd3355327dfc0b6b8ba56 +SHA512 (git-2.35.0.rc0.tar.sign) = fe4e74de26c0268d36f4fecfa2a2e014e4025c16c931366d1f6f70417661aa250e4ccb8d583c1060559e554e0f5eb770901f246f729f9a55ecbd08c11c6f1119 From 9d7a08be77521c05a65cdc450bc96e41f974f193 Mon Sep 17 00:00:00 2001 From: Todd Zullinger Date: Fri, 14 Jan 2022 20:04:04 -0500 Subject: [PATCH 2/9] update to 2.35.0-rc1 Release notes: https://github.com/git/git/raw/v2.35.0-rc1/Documentation/RelNotes/2.35.0.txt --- ...event-use-after-free-with-signed-tag.patch | 199 ------------------ git.spec | 11 +- sources | 4 +- 3 files changed, 7 insertions(+), 207 deletions(-) delete mode 100644 0001-fmt-merge-msg-prevent-use-after-free-with-signed-tag.patch diff --git a/0001-fmt-merge-msg-prevent-use-after-free-with-signed-tag.patch b/0001-fmt-merge-msg-prevent-use-after-free-with-signed-tag.patch deleted file mode 100644 index 72cd990..0000000 --- a/0001-fmt-merge-msg-prevent-use-after-free-with-signed-tag.patch +++ /dev/null @@ -1,199 +0,0 @@ -From mboxrd@z Thu Jan 1 00:00:00 1970 -Return-Path: -X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on - aws-us-west-2-korg-lkml-1.web.codeaurora.org -Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) - by smtp.lore.kernel.org (Postfix) with ESMTP id 4EF60C433EF - for ; Mon, 10 Jan 2022 21:19:15 +0000 (UTC) -Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand - id S1343852AbiAJVTN (ORCPT ); - Mon, 10 Jan 2022 16:19:13 -0500 -Received: from lindbergh.monkeyblade.net ([23.128.96.19]:45246 "EHLO - lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org - with ESMTP id S240793AbiAJVTJ (ORCPT ); - Mon, 10 Jan 2022 16:19:09 -0500 -Received: from mail-io1-xd32.google.com (mail-io1-xd32.google.com [IPv6:2607:f8b0:4864:20::d32]) - by lindbergh.monkeyblade.net (Postfix) with ESMTPS id D57E9C06173F - for ; Mon, 10 Jan 2022 13:19:08 -0800 (PST) -Received: by mail-io1-xd32.google.com with SMTP id h23so19409080iol.11 - for ; Mon, 10 Jan 2022 13:19:08 -0800 (PST) -DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; - d=ttaylorr-com.20210112.gappssmtp.com; s=20210112; - h=date:from:to:cc:subject:message-id:references:mime-version - :content-disposition:in-reply-to; - bh=FTrKkNrsW7oFf2weWFjBUCeY4AzPYNFulnRyLyCVrk8=; - b=z+XM3REbAP5x9W9gK6pBjzm9BHigJ0mkHwdcjCN9VQSWk7aIMxsxwVauiC4+Y15Py4 - e4kEWLSahtCS62N2410rXTW5F4IiCjrtU+iZztr+gz2IfLpV70e3CO2WaIRGNPRJm2g0 - Gl1+Y32Gk2jkmZ7w/ue8yng54F8FHEvg5joJFj19bMoWF0kd16ny2U+SjCfurbJu7Qpm - 7qMJtWStXIt8SBVaYdqvMjIylr3zDEvOolaSUBxXZYmD51XjQJXFL4DaYTvT6RIRsBZF - gcdEfTKQ3MdH7Dr8AbiaERh3vNXQ9oKb1cHL7aodKSAS6/NpSSvKMxmW+7n4yICL7hsM - b8pQ== -X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; - d=1e100.net; s=20210112; - h=x-gm-message-state:date:from:to:cc:subject:message-id:references - :mime-version:content-disposition:in-reply-to; - bh=FTrKkNrsW7oFf2weWFjBUCeY4AzPYNFulnRyLyCVrk8=; - b=YyvJy1w+MELo/HMukbimTZO7p+9odhEtnD9F2+GB68WqNtHOSqLj+FNJKrl2cWUWPM - Oec5Mop17BPiDQ5du2gbK9mEJMae9wPoqUhJijzgbcfyH8nAHG8XgBD8PYhzcdaKiwZW - 1/rhWRpyqsAmRKRnXBk+qXOydG6sbeJqYIDiHxHV/MWXzXK8L1tw0TN6x+ovUHJ8tOuu - ZStLc+f7IV9gr3soTs3R4sloQluxitDfe4RReEpc0HDcPxG0V91aiT4MxULStqcCqUbz - I1S0PJMehkw5RIZvrW8GpPjBGFao6X30hvxBN1Skq/nq1rUbbIwat343WUGUC/LogIAV - Wd5A== -X-Gm-Message-State: AOAM533g0jVnFyUCJsyN7y07jhNAhfATafqgniWHcVni8kH1UQ43T/Cd - 76bWXlo05ji/88mEupUArvoHr60/63d4qA== -X-Google-Smtp-Source: ABdhPJwh3a+flp+ajvTa6YBvQY7iqlxqOUdkFKcfZ3ahJTw9JXb3F4kXsRKSfwjHXJ9SQm7cyHyn1Q== -X-Received: by 2002:a05:6638:3009:: with SMTP id r9mr861119jak.262.1641849548063; - Mon, 10 Jan 2022 13:19:08 -0800 (PST) -Received: from localhost (104-178-186-189.lightspeed.milwwi.sbcglobal.net. [104.178.186.189]) - by smtp.gmail.com with ESMTPSA id t6sm5035566iov.39.2022.01.10.13.19.07 - (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); - Mon, 10 Jan 2022 13:19:07 -0800 (PST) -Date: Mon, 10 Jan 2022 16:19:06 -0500 -From: Taylor Blau -To: git@vger.kernel.org -Cc: Junio C Hamano , - Linus Torvalds , - Fabian Stelzer -Subject: [PATCH] fmt-merge-msg: prevent use-after-free with signed tags -Message-ID: <6e08b73d602853b3de71257117e85e32b96b5c19.1641849502.git.me@ttaylorr.com> -References: -MIME-Version: 1.0 -Content-Type: text/plain; charset=utf-8 -Content-Disposition: inline -In-Reply-To: -Precedence: bulk -List-ID: -X-Mailing-List: git@vger.kernel.org - -When merging a signed tag, fmt_merge_msg_sigs() is responsible for -populating the body of the merge message with the names of the signed -tags, their signatures, and the validity of those signatures. - -In 02769437e1 (ssh signing: use sigc struct to pass payload, -2021-12-09), check_signature() was taught to pass the object payload via -the sigc struct instead of passing the payload buffer separately. - -In effect, 02769437e1 causes buf, and sigc.payload to point at the same -region in memory. This causes a problem for fmt_tag_signature(), which -wants to read from this location, since it is freed beforehand by -signature_check_clear() (which frees it via sigc's `payload` member). - -That makes the subsequent use in fmt_tag_signature() a use-after-free. - -As a result, merge messages did not contain the body of any signed tags. -Luckily, they tend not to contain garbage, either, since the result of -strstr()-ing the object buffer in fmt_tag_signature() is guarded: - - const char *tag_body = strstr(buf, "\n\n"); - if (tag_body) { - tag_body += 2; - strbuf_add(tagbuf, tag_body, buf + len - tag_body); - } - -Unfortunately, the tests in t6200 did not catch this at the time because -they do not search for the body of signed tags in fmt-merge-msg's -output. - -Resolve this by waiting to call signature_check_clear() until after its -contents can be safely discarded. Harden ourselves against any future -regressions in this area by making sure we can find signed tag messages -in the output of fmt-merge-msg, too. - -Reported-by: Linus Torvalds -Signed-off-by: Taylor Blau ---- - fmt-merge-msg.c | 2 +- - t/t6200-fmt-merge-msg.sh | 8 ++++++++ - 2 files changed, 9 insertions(+), 1 deletion(-) - -diff --git a/fmt-merge-msg.c b/fmt-merge-msg.c -index e5c0aff2bf..baca57d5b6 100644 ---- a/fmt-merge-msg.c -+++ b/fmt-merge-msg.c -@@ -541,7 +541,6 @@ static void fmt_merge_msg_sigs(struct strbuf *out) - else - strbuf_addstr(&sig, sigc.output); - } -- signature_check_clear(&sigc); - - if (!tag_number++) { - fmt_tag_signature(&tagbuf, &sig, buf, len); -@@ -565,6 +564,7 @@ static void fmt_merge_msg_sigs(struct strbuf *out) - } - strbuf_release(&payload); - strbuf_release(&sig); -+ signature_check_clear(&sigc); - next: - free(origbuf); - } -diff --git a/t/t6200-fmt-merge-msg.sh b/t/t6200-fmt-merge-msg.sh -index 7544245f90..5a221f8ef1 100755 ---- a/t/t6200-fmt-merge-msg.sh -+++ b/t/t6200-fmt-merge-msg.sh -@@ -126,6 +126,7 @@ test_expect_success GPG 'message for merging local tag signed by good key' ' - git fetch . signed-good-tag && - git fmt-merge-msg <.git/FETCH_HEAD >actual && - grep "^Merge tag ${apos}signed-good-tag${apos}" actual && -+ grep "^signed-tag-msg" actual && - grep "^# gpg: Signature made" actual && - grep "^# gpg: Good signature from" actual - ' -@@ -135,6 +136,7 @@ test_expect_success GPG 'message for merging local tag signed by unknown key' ' - git fetch . signed-good-tag && - GNUPGHOME=. git fmt-merge-msg <.git/FETCH_HEAD >actual && - grep "^Merge tag ${apos}signed-good-tag${apos}" actual && -+ grep "^signed-tag-msg" actual && - grep "^# gpg: Signature made" actual && - grep -E "^# gpg: Can${apos}t check signature: (public key not found|No public key)" actual - ' -@@ -145,6 +147,7 @@ test_expect_success GPGSSH 'message for merging local tag signed by good ssh key - git fetch . signed-good-ssh-tag && - git fmt-merge-msg <.git/FETCH_HEAD >actual && - grep "^Merge tag ${apos}signed-good-ssh-tag${apos}" actual && -+ grep "^signed-ssh-tag-msg" actual && - grep "${GPGSSH_GOOD_SIGNATURE_TRUSTED}" actual && - ! grep "${GPGSSH_BAD_SIGNATURE}" actual - ' -@@ -155,6 +158,7 @@ test_expect_success GPGSSH 'message for merging local tag signed by unknown ssh - git fetch . signed-untrusted-ssh-tag && - git fmt-merge-msg <.git/FETCH_HEAD >actual && - grep "^Merge tag ${apos}signed-untrusted-ssh-tag${apos}" actual && -+ grep "^signed-ssh-tag-msg-untrusted" actual && - grep "${GPGSSH_GOOD_SIGNATURE_UNTRUSTED}" actual && - ! grep "${GPGSSH_BAD_SIGNATURE}" actual && - grep "${GPGSSH_KEY_NOT_TRUSTED}" actual -@@ -166,6 +170,7 @@ test_expect_success GPGSSH,GPGSSH_VERIFYTIME 'message for merging local tag sign - git fetch . expired-signed && - git fmt-merge-msg <.git/FETCH_HEAD >actual && - grep "^Merge tag ${apos}expired-signed${apos}" actual && -+ grep "^expired-signed" actual && - ! grep "${GPGSSH_GOOD_SIGNATURE_TRUSTED}" actual - ' - -@@ -175,6 +180,7 @@ test_expect_success GPGSSH,GPGSSH_VERIFYTIME 'message for merging local tag sign - git fetch . notyetvalid-signed && - git fmt-merge-msg <.git/FETCH_HEAD >actual && - grep "^Merge tag ${apos}notyetvalid-signed${apos}" actual && -+ grep "^notyetvalid-signed" actual && - ! grep "${GPGSSH_GOOD_SIGNATURE_TRUSTED}" actual - ' - -@@ -184,6 +190,7 @@ test_expect_success GPGSSH,GPGSSH_VERIFYTIME 'message for merging local tag sign - git fetch . timeboxedvalid-signed && - git fmt-merge-msg <.git/FETCH_HEAD >actual && - grep "^Merge tag ${apos}timeboxedvalid-signed${apos}" actual && -+ grep "^timeboxedvalid-signed" actual && - grep "${GPGSSH_GOOD_SIGNATURE_TRUSTED}" actual && - ! grep "${GPGSSH_BAD_SIGNATURE}" actual - ' -@@ -194,6 +201,7 @@ test_expect_success GPGSSH,GPGSSH_VERIFYTIME 'message for merging local tag sign - git fetch . timeboxedinvalid-signed && - git fmt-merge-msg <.git/FETCH_HEAD >actual && - grep "^Merge tag ${apos}timeboxedinvalid-signed${apos}" actual && -+ grep "^timeboxedinvalid-signed" actual && - ! grep "${GPGSSH_GOOD_SIGNATURE_TRUSTED}" actual - ' - --- -2.34.1.455.gd6eb6fd089 - diff --git a/git.spec b/git.spec index ea1b95b..fb6a98d 100644 --- a/git.spec +++ b/git.spec @@ -76,11 +76,11 @@ %endif # Define for release candidates -%global rcrev .rc0 +%global rcrev .rc1 Name: git Version: 2.35.0 -Release: 0.0%{?rcrev}%{?dist} +Release: 0.1%{?rcrev}%{?dist} Summary: Fast Version Control System License: GPLv2 URL: https://git-scm.com/ @@ -119,10 +119,6 @@ Patch3: 0003-t-lib-gpg-kill-all-gpg-components-not-just-gpg-agent.patch Patch4: 0004-t4202-match-gpgsm-output-from-GnuPG-2.3.patch Patch5: 0005-gpg-interface-match-SIG_CREATED-if-it-s-the-first-li.patch -# Fix tag message contents -# https://lore.kernel.org/git/CAHk-=whXPxWL7z3GiPkaDt+yygrRmagrYUnib7Lx=Vvrqx2ufg@mail.gmail.com/ -Patch6: https://lore.kernel.org/git/6e08b73d602853b3de71257117e85e32b96b5c19.1641849502.git.me@ttaylorr.com/raw#/0001-fmt-merge-msg-prevent-use-after-free-with-signed-tag.patch - %if %{with docs} # pod2man is needed to build Git.3pm BuildRequires: %{_bindir}/pod2man @@ -1012,6 +1008,9 @@ rmdir --ignore-fail-on-non-empty "$testdir" %{?with_docs:%{_pkgdocdir}/git-svn.html} %changelog +* Sat Jan 15 2022 Todd Zullinger - 2.35.0-0.1.rc1 +- update to 2.35.0-rc1 + * Mon Jan 10 2022 Todd Zullinger - 2.35.0-0.0.rc0 - update to 2.35.0-rc0 diff --git a/sources b/sources index 4e6eca9..84bfe82 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ -SHA512 (git-2.35.0.rc0.tar.xz) = 9aa5d89d7981c73d32e9023dfc61a62e63688c3172cba4bee145b2ff4f5f7bc497435d1b4b535089c698893feabc6057a6522676e52bd3355327dfc0b6b8ba56 -SHA512 (git-2.35.0.rc0.tar.sign) = fe4e74de26c0268d36f4fecfa2a2e014e4025c16c931366d1f6f70417661aa250e4ccb8d583c1060559e554e0f5eb770901f246f729f9a55ecbd08c11c6f1119 +SHA512 (git-2.35.0.rc1.tar.xz) = fe7fdf5dfa9f3c7ac89158fd73520335cb0c10ab992258dbb88ee1a90b03f4f8bfbe490dcf704770e91245e162014deb400f3b507dd6fda4f52b01c16081b2cd +SHA512 (git-2.35.0.rc1.tar.sign) = 0644ef1e80a3ef84edbe699c1fe50df451aa335b9a0881786e5dac73079e2b94111c9cfd140eb6bee1c2342e06d6c0a27e968fbd1bc5a2ca76892d6cbaa4bc83 From a8bfca0241b9008882609f05cbcc56466bd37856 Mon Sep 17 00:00:00 2001 From: Todd Zullinger Date: Wed, 19 Jan 2022 18:02:12 -0500 Subject: [PATCH 3/9] update to 2.35.0-rc2 Release notes: https://github.com/git/git/raw/v2.35.0-rc2/Documentation/RelNotes/2.35.0.txt --- git.spec | 7 +++++-- sources | 4 ++-- 2 files changed, 7 insertions(+), 4 deletions(-) diff --git a/git.spec b/git.spec index fb6a98d..6658bce 100644 --- a/git.spec +++ b/git.spec @@ -76,11 +76,11 @@ %endif # Define for release candidates -%global rcrev .rc1 +%global rcrev .rc2 Name: git Version: 2.35.0 -Release: 0.1%{?rcrev}%{?dist} +Release: 0.2%{?rcrev}%{?dist} Summary: Fast Version Control System License: GPLv2 URL: https://git-scm.com/ @@ -1008,6 +1008,9 @@ rmdir --ignore-fail-on-non-empty "$testdir" %{?with_docs:%{_pkgdocdir}/git-svn.html} %changelog +* Wed Jan 19 2022 Todd Zullinger - 2.35.0-0.2.rc2 +- update to 2.35.0-rc2 + * Sat Jan 15 2022 Todd Zullinger - 2.35.0-0.1.rc1 - update to 2.35.0-rc1 diff --git a/sources b/sources index 84bfe82..debc1e5 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ -SHA512 (git-2.35.0.rc1.tar.xz) = fe7fdf5dfa9f3c7ac89158fd73520335cb0c10ab992258dbb88ee1a90b03f4f8bfbe490dcf704770e91245e162014deb400f3b507dd6fda4f52b01c16081b2cd -SHA512 (git-2.35.0.rc1.tar.sign) = 0644ef1e80a3ef84edbe699c1fe50df451aa335b9a0881786e5dac73079e2b94111c9cfd140eb6bee1c2342e06d6c0a27e968fbd1bc5a2ca76892d6cbaa4bc83 +SHA512 (git-2.35.0.rc2.tar.xz) = 5eb758cbf37c632f89f03eca65bf36f7f2490fbfb3d54c396d906b45a7ab96735f928abe300d7bcacdfdd33b59b1901a4c92f27f30dfe82c4fb1e8d690568dc3 +SHA512 (git-2.35.0.rc2.tar.sign) = fc9d96ea3f58f3c34f121477597e4f5b4a9c50e0d3ee42d021a276f5f1ca9a524c437a3fee8c78b6f09095ff411ab2f919444c53152e9bb44e5211437c18f415 From ce97e98127806a33bcb42d1873af5aa11b77cdaa Mon Sep 17 00:00:00 2001 From: Todd Zullinger Date: Fri, 21 Jan 2022 15:07:05 -0500 Subject: [PATCH 4/9] checkout: avoid BUG() when hitting a broken repository (rhbz#2042920) The git checkout command crashes when run multiple times, if `.git/refs/remotes/origin/HEAD` is manually copied into `.git/refs/heads/$branch-name`. Strictly, this is repository corruption, but it has been silently tolerated until upstream 9081a421 (checkout: fix "branch info" memory leaks, 2021-11-16), which added some sanity checking of the data. Loosen the check via Junio's upstream commit 519947b69a (checkout: avoid BUG() when hitting a broken repository, 2022-01-21). --- ...BUG-when-hitting-a-broken-repository.patch | 74 +++++++++++++++++++ git.spec | 9 ++- 2 files changed, 82 insertions(+), 1 deletion(-) create mode 100644 0001-checkout-avoid-BUG-when-hitting-a-broken-repository.patch diff --git a/0001-checkout-avoid-BUG-when-hitting-a-broken-repository.patch b/0001-checkout-avoid-BUG-when-hitting-a-broken-repository.patch new file mode 100644 index 0000000..d04d487 --- /dev/null +++ b/0001-checkout-avoid-BUG-when-hitting-a-broken-repository.patch @@ -0,0 +1,74 @@ +From 519947b69a9ea1461d5f5afc762823835295b3b2 Mon Sep 17 00:00:00 2001 +From: Junio C Hamano +Date: Fri, 21 Jan 2022 16:58:30 -0800 +Subject: [PATCH] checkout: avoid BUG() when hitting a broken repository +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +When 9081a421 (checkout: fix "branch info" memory leaks, 2021-11-16) +cleaned up existing memory leaks, we added an unrelated sanity check +to ensure that a local branch is truly local and not a symref to +elsewhere that dies with BUG() otherwise. This was misguided in two +ways. First of all, such a tightening did not belong to a leak-fix +patch. And the condition it detected was *not* a bug in our program +but a problem in user data, where warning() or die() would have been +more appropriate. + +As the condition is not fatal (the result of computing the local +branch name in the code that is involved in the faulty check is only +used as a textual label for the commit), let's revert the code to +the original state, i.e. strip "refs/heads/" to compute the local +branch name if possible, and otherwise leave it NULL. The consumer +of the information in merge_working_tree() is prepared to see NULL +in there and act accordingly. + +cf. https://bugzilla.redhat.com/show_bug.cgi?id=2042920 + +Reported-by: Petr Šplíchal +Reported-by: Todd Zullinger +Helped-by: Ævar Arnfjörð Bjarmason +Signed-off-by: Junio C Hamano +--- + builtin/checkout.c | 3 --- + t/t2018-checkout-branch.sh | 13 +++++++++++++ + 2 files changed, 13 insertions(+), 3 deletions(-) + +diff --git a/builtin/checkout.c b/builtin/checkout.c +index 43d0275187fc8f..1fb34d537d9e91 100644 +--- a/builtin/checkout.c ++++ b/builtin/checkout.c +@@ -1094,9 +1094,6 @@ static int switch_branches(const struct checkout_opts *opts, + const char *p; + if (skip_prefix(old_branch_info.path, prefix, &p)) + old_branch_info.name = xstrdup(p); +- else +- BUG("should be able to skip past '%s' in '%s'!", +- prefix, old_branch_info.path); + } + + if (opts->new_orphan_branch && opts->orphan_from_empty_tree) { +diff --git a/t/t2018-checkout-branch.sh b/t/t2018-checkout-branch.sh +index 93be1c0eae5ead..5dda5ad4cbcb07 100755 +--- a/t/t2018-checkout-branch.sh ++++ b/t/t2018-checkout-branch.sh +@@ -85,6 +85,19 @@ test_expect_success 'setup' ' + git branch -m branch1 + ' + ++test_expect_success 'checkout a branch without refs/heads/* prefix' ' ++ git clone --no-tags . repo-odd-prefix && ++ ( ++ cd repo-odd-prefix && ++ ++ origin=$(git symbolic-ref refs/remotes/origin/HEAD) && ++ git symbolic-ref refs/heads/a-branch "$origin" && ++ ++ git checkout -f a-branch && ++ git checkout -f a-branch ++ ) ++' ++ + test_expect_success 'checkout -b to a new branch, set to HEAD' ' + test_when_finished " + git checkout branch1 && diff --git a/git.spec b/git.spec index 6658bce..7f280db 100644 --- a/git.spec +++ b/git.spec @@ -80,7 +80,7 @@ Name: git Version: 2.35.0 -Release: 0.2%{?rcrev}%{?dist} +Release: 0.2%{?rcrev}%{?dist}.1 Summary: Fast Version Control System License: GPLv2 URL: https://git-scm.com/ @@ -119,6 +119,10 @@ Patch3: 0003-t-lib-gpg-kill-all-gpg-components-not-just-gpg-agent.patch Patch4: 0004-t4202-match-gpgsm-output-from-GnuPG-2.3.patch Patch5: 0005-gpg-interface-match-SIG_CREATED-if-it-s-the-first-li.patch +# checkout: avoid BUG() when hitting a broken repository +# https://bugzilla.redhat.com/2042920 +Patch6: https://github.com/git/git/commit/519947b69a.patch#/0001-checkout-avoid-BUG-when-hitting-a-broken-repository.patch + %if %{with docs} # pod2man is needed to build Git.3pm BuildRequires: %{_bindir}/pod2man @@ -1008,6 +1012,9 @@ rmdir --ignore-fail-on-non-empty "$testdir" %{?with_docs:%{_pkgdocdir}/git-svn.html} %changelog +* Thu Jan 20 2022 Todd Zullinger - 2.35.0-0.2.rc2.1 +- checkout: avoid BUG() when hitting a broken repository (rhbz#2042920) + * Wed Jan 19 2022 Todd Zullinger - 2.35.0-0.2.rc2 - update to 2.35.0-rc2 From 601fe503aabd0aeb45589b153b8c23819966dfa6 Mon Sep 17 00:00:00 2001 From: Todd Zullinger Date: Thu, 20 Jan 2022 12:33:32 -0500 Subject: [PATCH 5/9] fix compilation on EL7 Git now requires C99 support and a zlib with uncompress2 by default. On EL7, gcc-4.8.5 requires a flag to enable C99 support. Compilation also fails without -fPIC on EL7, for reasons of which I am not entirely clear. (I do not like making a change I cannot justify or explain properly, but it is better than dropping EL7 support until I have time to learn the reason(s).) Update the %build_cflags macro when building on EL7 to enable C99 support and set -fPIC. Define NO_UNCOMPRESS2 to use compat/zlib-uncompress2.c. --- git.spec | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/git.spec b/git.spec index 7f280db..778e231 100644 --- a/git.spec +++ b/git.spec @@ -39,6 +39,7 @@ %else %bcond_without python2 %bcond_with python3 +%global build_cflags %{build_cflags} -fPIC -std=gnu99 %global gitweb_httpd_conf git.conf %global use_glibc_langpacks 0 %global use_perl_generators 0 @@ -80,7 +81,7 @@ Name: git Version: 2.35.0 -Release: 0.2%{?rcrev}%{?dist}.1 +Release: 0.2%{?rcrev}%{?dist}.2 Summary: Fast Version Control System License: GPLv2 URL: https://git-scm.com/ @@ -548,6 +549,9 @@ INSTALL_SYMLINKS = 1 GITWEB_PROJECTROOT = %{_localstatedir}/lib/git GNU_ROFF = 1 NO_PERL_CPAN_FALLBACKS = 1 +%if 0%{?rhel} && 0%{?rhel} < 8 +NO_UNCOMPRESS2 = 1 +%endif %if %{with python3} PYTHON_PATH = %{__python3} %else @@ -1012,6 +1016,9 @@ rmdir --ignore-fail-on-non-empty "$testdir" %{?with_docs:%{_pkgdocdir}/git-svn.html} %changelog +* Fri Jan 21 2022 Todd Zullinger - 2.35.0-0.2.rc2.2 +- fix compilation on EL7 + * Thu Jan 20 2022 Todd Zullinger - 2.35.0-0.2.rc2.1 - checkout: avoid BUG() when hitting a broken repository (rhbz#2042920) From 32a3ec7045053427f28f40500aad489b420325d4 Mon Sep 17 00:00:00 2001 From: Todd Zullinger Date: Sat, 22 Jan 2022 12:49:44 -0500 Subject: [PATCH 6/9] remove contrib/scalar to avoid cruft in git-core-doc The scalar command is being worked on incrementally upstream. As it matures, we may consider building and distributing it. Whether that will happen before it graduates from contrib or not is anyone's guess. For the moment, remove it to avoid cruft in git-core-doc. --- git.spec | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/git.spec b/git.spec index 778e231..75ca4f4 100644 --- a/git.spec +++ b/git.spec @@ -81,7 +81,7 @@ Name: git Version: 2.35.0 -Release: 0.2%{?rcrev}%{?dist}.2 +Release: 0.2%{?rcrev}%{?dist}.3 Summary: Fast Version Control System License: GPLv2 URL: https://git-scm.com/ @@ -675,6 +675,9 @@ install -Dpm 0755 contrib/diff-highlight/diff-highlight \ %{buildroot}%{_datadir}/git-core/contrib/diff-highlight rm -rf contrib/diff-highlight/{Makefile,diff-highlight,*.perl,t} +# Remove contrib/scalar to avoid cruft in the git-core-doc docdir +rm -rf contrib/scalar + # Clean up contrib/subtree to avoid cruft in the git-core-doc docdir rm -rf contrib/subtree/{INSTALL,Makefile,git-subtree*,t} @@ -1016,6 +1019,9 @@ rmdir --ignore-fail-on-non-empty "$testdir" %{?with_docs:%{_pkgdocdir}/git-svn.html} %changelog +* Sat Jan 22 2022 Todd Zullinger - 2.35.0-0.2.rc2.3 +- remove contrib/scalar to avoid cruft in git-core-doc + * Fri Jan 21 2022 Todd Zullinger - 2.35.0-0.2.rc2.2 - fix compilation on EL7 From 4eb061b2091db583f5b6d759e78d3aa6d32a75c4 Mon Sep 17 00:00:00 2001 From: Todd Zullinger Date: Mon, 24 Jan 2022 15:31:20 -0500 Subject: [PATCH 7/9] update to 2.35.0 Release notes: https://github.com/git/git/raw/v2.35.0/Documentation/RelNotes/2.35.0.txt --- ...BUG-when-hitting-a-broken-repository.patch | 74 ------------------- git.spec | 11 ++- sources | 4 +- 3 files changed, 7 insertions(+), 82 deletions(-) delete mode 100644 0001-checkout-avoid-BUG-when-hitting-a-broken-repository.patch diff --git a/0001-checkout-avoid-BUG-when-hitting-a-broken-repository.patch b/0001-checkout-avoid-BUG-when-hitting-a-broken-repository.patch deleted file mode 100644 index d04d487..0000000 --- a/0001-checkout-avoid-BUG-when-hitting-a-broken-repository.patch +++ /dev/null @@ -1,74 +0,0 @@ -From 519947b69a9ea1461d5f5afc762823835295b3b2 Mon Sep 17 00:00:00 2001 -From: Junio C Hamano -Date: Fri, 21 Jan 2022 16:58:30 -0800 -Subject: [PATCH] checkout: avoid BUG() when hitting a broken repository -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -When 9081a421 (checkout: fix "branch info" memory leaks, 2021-11-16) -cleaned up existing memory leaks, we added an unrelated sanity check -to ensure that a local branch is truly local and not a symref to -elsewhere that dies with BUG() otherwise. This was misguided in two -ways. First of all, such a tightening did not belong to a leak-fix -patch. And the condition it detected was *not* a bug in our program -but a problem in user data, where warning() or die() would have been -more appropriate. - -As the condition is not fatal (the result of computing the local -branch name in the code that is involved in the faulty check is only -used as a textual label for the commit), let's revert the code to -the original state, i.e. strip "refs/heads/" to compute the local -branch name if possible, and otherwise leave it NULL. The consumer -of the information in merge_working_tree() is prepared to see NULL -in there and act accordingly. - -cf. https://bugzilla.redhat.com/show_bug.cgi?id=2042920 - -Reported-by: Petr Šplíchal -Reported-by: Todd Zullinger -Helped-by: Ævar Arnfjörð Bjarmason -Signed-off-by: Junio C Hamano ---- - builtin/checkout.c | 3 --- - t/t2018-checkout-branch.sh | 13 +++++++++++++ - 2 files changed, 13 insertions(+), 3 deletions(-) - -diff --git a/builtin/checkout.c b/builtin/checkout.c -index 43d0275187fc8f..1fb34d537d9e91 100644 ---- a/builtin/checkout.c -+++ b/builtin/checkout.c -@@ -1094,9 +1094,6 @@ static int switch_branches(const struct checkout_opts *opts, - const char *p; - if (skip_prefix(old_branch_info.path, prefix, &p)) - old_branch_info.name = xstrdup(p); -- else -- BUG("should be able to skip past '%s' in '%s'!", -- prefix, old_branch_info.path); - } - - if (opts->new_orphan_branch && opts->orphan_from_empty_tree) { -diff --git a/t/t2018-checkout-branch.sh b/t/t2018-checkout-branch.sh -index 93be1c0eae5ead..5dda5ad4cbcb07 100755 ---- a/t/t2018-checkout-branch.sh -+++ b/t/t2018-checkout-branch.sh -@@ -85,6 +85,19 @@ test_expect_success 'setup' ' - git branch -m branch1 - ' - -+test_expect_success 'checkout a branch without refs/heads/* prefix' ' -+ git clone --no-tags . repo-odd-prefix && -+ ( -+ cd repo-odd-prefix && -+ -+ origin=$(git symbolic-ref refs/remotes/origin/HEAD) && -+ git symbolic-ref refs/heads/a-branch "$origin" && -+ -+ git checkout -f a-branch && -+ git checkout -f a-branch -+ ) -+' -+ - test_expect_success 'checkout -b to a new branch, set to HEAD' ' - test_when_finished " - git checkout branch1 && diff --git a/git.spec b/git.spec index 75ca4f4..14f4c3b 100644 --- a/git.spec +++ b/git.spec @@ -77,11 +77,11 @@ %endif # Define for release candidates -%global rcrev .rc2 +#global rcrev .rc0 Name: git Version: 2.35.0 -Release: 0.2%{?rcrev}%{?dist}.3 +Release: 1%{?rcrev}%{?dist} Summary: Fast Version Control System License: GPLv2 URL: https://git-scm.com/ @@ -120,10 +120,6 @@ Patch3: 0003-t-lib-gpg-kill-all-gpg-components-not-just-gpg-agent.patch Patch4: 0004-t4202-match-gpgsm-output-from-GnuPG-2.3.patch Patch5: 0005-gpg-interface-match-SIG_CREATED-if-it-s-the-first-li.patch -# checkout: avoid BUG() when hitting a broken repository -# https://bugzilla.redhat.com/2042920 -Patch6: https://github.com/git/git/commit/519947b69a.patch#/0001-checkout-avoid-BUG-when-hitting-a-broken-repository.patch - %if %{with docs} # pod2man is needed to build Git.3pm BuildRequires: %{_bindir}/pod2man @@ -1019,6 +1015,9 @@ rmdir --ignore-fail-on-non-empty "$testdir" %{?with_docs:%{_pkgdocdir}/git-svn.html} %changelog +* Mon Jan 24 2022 Todd Zullinger - 2.35.0-1 +- update to 2.35.0 + * Sat Jan 22 2022 Todd Zullinger - 2.35.0-0.2.rc2.3 - remove contrib/scalar to avoid cruft in git-core-doc diff --git a/sources b/sources index debc1e5..21febdd 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ -SHA512 (git-2.35.0.rc2.tar.xz) = 5eb758cbf37c632f89f03eca65bf36f7f2490fbfb3d54c396d906b45a7ab96735f928abe300d7bcacdfdd33b59b1901a4c92f27f30dfe82c4fb1e8d690568dc3 -SHA512 (git-2.35.0.rc2.tar.sign) = fc9d96ea3f58f3c34f121477597e4f5b4a9c50e0d3ee42d021a276f5f1ca9a524c437a3fee8c78b6f09095ff411ab2f919444c53152e9bb44e5211437c18f415 +SHA512 (git-2.35.0.tar.xz) = ae391e1cda7b4e7d49e09e7412cd2da8d643c71f20967fd7b600be00a13d3b126c2bc3a2deece935742084ecbbd1eb51455b10365e0d65423979241e9e7b94a9 +SHA512 (git-2.35.0.tar.sign) = 8aeb47662e51f2d64150101b2e0887c9f6bfe42b312d52cde3e9d0b2467febea7bd4e9ba2e2df2121728a574e3d02a42ef7f2220486211bde8f936e848da4510 From 1dc07e7d5daaacc47013f1a646d81f79379176b6 Mon Sep 17 00:00:00 2001 From: Todd Zullinger Date: Mon, 24 Jan 2022 15:33:49 -0500 Subject: [PATCH 8/9] set path to linker script in %_package_note_file MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The package-notes feature¹ creates a linker script in %{buildsubdir}. Unfortunately, %{buildsubdir} is not set in %prep, leaving us with an incorrect path to the linker script. The build then fails with: /usr/bin/ld: cannot open linker script file /builddir/build/BUILD/.package_note-git-2.35.0-0.2.rc2.fc36.3.x86_64.ld: No such file or directory Set the path to the linker script via %_package_note_file, per suggestion by Zbigniew Jędrzejewski-Szmek². References: ¹ https://fedoraproject.org/wiki/Changes/Package_information_on_ELF_objects ² https://bugzilla.redhat.com/2044028#c10 --- git.spec | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/git.spec b/git.spec index 14f4c3b..1baa4ef 100644 --- a/git.spec +++ b/git.spec @@ -76,6 +76,9 @@ %global _hardened_build 1 %endif +# Set path to the package-notes linker script +%global _package_note_file %{_builddir}/%{name}-%{version}/.package_note-%{name}-%{version}-%{release}.%{_arch}.ld + # Define for release candidates #global rcrev .rc0 @@ -1017,6 +1020,7 @@ rmdir --ignore-fail-on-non-empty "$testdir" %changelog * Mon Jan 24 2022 Todd Zullinger - 2.35.0-1 - update to 2.35.0 +- set path to linker script in %%_package_note_file * Sat Jan 22 2022 Todd Zullinger - 2.35.0-0.2.rc2.3 - remove contrib/scalar to avoid cruft in git-core-doc From 9e214cd4d018c3be1f38bd2b4aa949a8b7f0a3a4 Mon Sep 17 00:00:00 2001 From: Todd Zullinger Date: Sat, 29 Jan 2022 00:20:45 -0500 Subject: [PATCH 9/9] update to 2.35.1 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Per the upstream release notes¹: Git 2.35 shipped with a regression that broke use of "rebase" and "stash" in a secondary worktree. This maintenance release ought to fix it. ¹ https://github.com/git/git/raw/v2.35.1/Documentation/RelNotes/2.35.1.txt --- git.spec | 5 ++++- sources | 4 ++-- 2 files changed, 6 insertions(+), 3 deletions(-) diff --git a/git.spec b/git.spec index 1baa4ef..b8ea26b 100644 --- a/git.spec +++ b/git.spec @@ -83,7 +83,7 @@ #global rcrev .rc0 Name: git -Version: 2.35.0 +Version: 2.35.1 Release: 1%{?rcrev}%{?dist} Summary: Fast Version Control System License: GPLv2 @@ -1018,6 +1018,9 @@ rmdir --ignore-fail-on-non-empty "$testdir" %{?with_docs:%{_pkgdocdir}/git-svn.html} %changelog +* Sat Jan 29 2022 Todd Zullinger - 2.35.1-1 +- update to 2.35.1 + * Mon Jan 24 2022 Todd Zullinger - 2.35.0-1 - update to 2.35.0 - set path to linker script in %%_package_note_file diff --git a/sources b/sources index 21febdd..4095968 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ -SHA512 (git-2.35.0.tar.xz) = ae391e1cda7b4e7d49e09e7412cd2da8d643c71f20967fd7b600be00a13d3b126c2bc3a2deece935742084ecbbd1eb51455b10365e0d65423979241e9e7b94a9 -SHA512 (git-2.35.0.tar.sign) = 8aeb47662e51f2d64150101b2e0887c9f6bfe42b312d52cde3e9d0b2467febea7bd4e9ba2e2df2121728a574e3d02a42ef7f2220486211bde8f936e848da4510 +SHA512 (git-2.35.1.tar.xz) = 926c6813ef61931e1a1c43dfd7b15e20dc5878c1752876bd08f039249c9ed09f20f096b2f01947de9c9522c942e9fa8c1363d7d31a488bbe3f93c0cff31fcbcb +SHA512 (git-2.35.1.tar.sign) = 27adbb0628a18ae13ce76c2812c2f2a8a9da002105ca1f550a864ae769a27efa697ab7cbd8582e69be99d8731fe2f53895321c3a71990ffbcfe1e7f2064fd9b7