Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 298605

Summary: repoman commit should test if gpg is ready to sign manifest
Product: Portage Development Reporter: Diego Elio Pettenò (RETIRED) <flameeyes>
Component: RepomanAssignee: Portage team <dev-portage>
Status: RESOLVED OBSOLETE    
Severity: normal CC: pesa, vapier, xmw
Priority: High    
Version: unspecified   
Hardware: All   
OS: Linux   
See Also: https://bugs.gentoo.org/show_bug.cgi?id=360459
https://bugs.gentoo.org/show_bug.cgi?id=473926
Whiteboard:
Package list:
Runtime testing required: ---

Description Diego Elio Pettenò (RETIRED) gentoo-dev 2009-12-28 00:49:16 UTC
Right now it's very well possible that a broken gpg-agent, an expired signing key, or a password forgotten to be typed in due time will make the FEATURES=sign moot, since the commit is completed _before_ the signing take place.

To avoid this, it should probably be better to sign something _before_ commit, and fail if it didn't work properly.
Comment 1 Zac Medico gentoo-dev 2013-06-23 20:59:12 UTC
It seems that we can start a gpg process with our PORTAGE_GPG_SIGNING_COMMAND and omit the ${FILE} argument. The process will load the key into memory, and wait for us to feed it the Manifest on stdin. So, if the gpg process doesn't exit before we are ready to commit, then that should be enough to validate that it's safe to commit. When ready to sign, we just feed the Manifest to stdin and read the signed Manifest from stdout. Thanks for the suggestion from here:

  http://article.gmane.org/gmane.linux.gentoo.devel/86418
Comment 2 Jan Matějka (RETIRED) gentoo-dev 2013-06-27 19:06:08 UTC
*** Bug 360459 has been marked as a duplicate of this bug. ***
Comment 3 Brian Dolbec (RETIRED) gentoo-dev 2017-03-15 22:49:11 UTC
Since this is a CVS specific commit problem and we have moved on to a git based repository...

I am going to close this