diff options
| author | Ludovic Courtès <ludo@gnu.org> | 2025-12-19 09:34:47 +0100 |
|---|---|---|
| committer | Ludovic Courtès <ludo@gnu.org> | 2025-12-22 15:10:52 +0100 |
| commit | 0ac2a0fd1813fb5c04b22f6443d8f8a96d3c9645 (patch) | |
| tree | 045d39546054363d7376f4d44151cce005a35fd8 | |
| parent | 5d6dfd8981ac9ab65012de0e9a9ed26301e5b8fd (diff) | |
authenticate: Report failure to load keys to the daemon.
Previously, when failing to load a signing key, ‘guix authenticate’ would
print a backtrace and exit with a non-zero code. That, in turn, would lead
the guix-daemon child process to crash with:
nix/libutil/serialise.cc:15: virtual nix::BufferedSink::~BufferedSink(): Assertion `!bufPos' failed.
This patch fixes it by reporting the error to the daemon as was intended.
* guix/scripts/authenticate.scm (guix-authenticate): Arrange to call
‘load-key-pair’ from within ‘with-reply’.
* tests/guix-authenticate.sh: Test it.
Fixes: guix/guix#4928
Reported-by: Rutherther <rutherther@ditigal.xyz>
Change-Id: I8654ad6fdfbe18c55e1e85647d0c49f408d0574a
Signed-off-by: Ludovic Courtès <ludo@gnu.org>
Merges: #4961
| -rw-r--r-- | guix/scripts/authenticate.scm | 33 | ||||
| -rw-r--r-- | tests/guix-authenticate.sh | 7 |
2 files changed, 24 insertions, 16 deletions
diff --git a/guix/scripts/authenticate.scm b/guix/scripts/authenticate.scm index 48e76c61c8a..f90eeeec8de 100644 --- a/guix/scripts/authenticate.scm +++ b/guix/scripts/authenticate.scm | |||
| @@ -1,5 +1,5 @@ | |||
| 1 | ;;; GNU Guix --- Functional package management for GNU | 1 | ;;; GNU Guix --- Functional package management for GNU |
| 2 | ;;; Copyright © 2013, 2014, 2015, 2016, 2017, 2020 Ludovic Courtès <ludo@gnu.org> | 2 | ;;; Copyright © 2013-2017, 2020, 2025 Ludovic Courtès <ludo@gnu.org> |
| 3 | ;;; | 3 | ;;; |
| 4 | ;;; This file is part of GNU Guix. | 4 | ;;; This file is part of GNU Guix. |
| 5 | ;;; | 5 | ;;; |
| @@ -196,20 +196,23 @@ Sign data or verify signatures. This tool is meant to be used internally by | |||
| 196 | ;; Read a request on standard input and reply. | 196 | ;; Read a request on standard input and reply. |
| 197 | (match (read-command (current-input-port)) | 197 | (match (read-command (current-input-port)) |
| 198 | (("sign" signing-key (= base16-string->bytevector hash)) | 198 | (("sign" signing-key (= base16-string->bytevector hash)) |
| 199 | (let* ((key-pairs keys | 199 | (let ((cached-keys (match (vhash-assoc signing-key key-pairs) |
| 200 | (match (vhash-assoc signing-key key-pairs) | 200 | ((_ . keys) keys) |
| 201 | ((_ . keys) | 201 | (#f #f))) |
| 202 | (values key-pairs keys)) | 202 | (new-keys #f)) |
| 203 | (#f | 203 | (with-reply (begin |
| 204 | (let ((keys (load-key-pair signing-key))) | 204 | (unless cached-keys |
| 205 | (values (vhash-cons signing-key keys | 205 | ;; Delay 'load-key-pair' call so that failure |
| 206 | key-pairs) | 206 | ;; to load keys is reported via 'with-reply'. |
| 207 | keys)))))) | 207 | (set! new-keys (load-key-pair signing-key))) |
| 208 | (with-reply (canonical-sexp->string | 208 | (canonical-sexp->string |
| 209 | (match keys | 209 | (match (or cached-keys new-keys) |
| 210 | ((public . secret) | 210 | ((public . secret) |
| 211 | (sign-with-key public secret hash))))) | 211 | (sign-with-key public secret hash)))))) |
| 212 | (loop key-pairs))) | 212 | (loop (if new-keys |
| 213 | (vhash-cons signing-key new-keys | ||
| 214 | key-pairs) | ||
| 215 | key-pairs)))) | ||
| 213 | (("verify" signature) | 216 | (("verify" signature) |
| 214 | (with-reply (bytevector->base16-string | 217 | (with-reply (bytevector->base16-string |
| 215 | (validate-signature | 218 | (validate-signature |
diff --git a/tests/guix-authenticate.sh b/tests/guix-authenticate.sh index 0de6da18784..ddd39d09c44 100644 --- a/tests/guix-authenticate.sh +++ b/tests/guix-authenticate.sh | |||
| @@ -1,5 +1,5 @@ | |||
| 1 | # GNU Guix --- Functional package management for GNU | 1 | # GNU Guix --- Functional package management for GNU |
| 2 | # Copyright © 2013, 2014, 2020 Ludovic Courtès <ludo@gnu.org> | 2 | # Copyright © 2013, 2014, 2020, 2025 Ludovic Courtès <ludo@gnu.org> |
| 3 | # | 3 | # |
| 4 | # This file is part of GNU Guix. | 4 | # This file is part of GNU Guix. |
| 5 | # | 5 | # |
| @@ -85,3 +85,8 @@ sed -i "$sig" -e's/^0 //g' | |||
| 85 | echo "verify $(cat $sig)" | guix authenticate | 85 | echo "verify $(cat $sig)" | guix authenticate |
| 86 | hash2="$(echo "verify $(cat $sig)" | guix authenticate | cut -f2 -d ' ')" | 86 | hash2="$(echo "verify $(cat $sig)" | guix authenticate | cut -f2 -d ' ')" |
| 87 | test "$(echo $hash2 | cut -d : -f 2)" = "$hash" | 87 | test "$(echo $hash2 | cut -d : -f 2)" = "$hash" |
| 88 | |||
| 89 | # Make sure an error is properly reported for unreadable key pairs, with exit | ||
| 90 | # code zero (the process would keep running commands on standard input). | ||
| 91 | echo "sign 9:/dev/null $hash_len:$hash" | guix authenticate | ||
| 92 | test $(echo "sign 9:/dev/null $hash_len:$hash" | guix authenticate | cut -f1 -d ' ') = 500 | ||
