
In addition to the manual adjustment to let the `linux-gcc` CI job run the test suite with `master` and then with `main`, this patch makes sure that GIT_TEST_DEFAULT_INITIAL_BRANCH_NAME is set in all test scripts that currently rely on the initial branch name being `master by default. To determine which test scripts to mark up, the first step was to force-set the default branch name to `master` in - all test scripts that contain the keyword `master`, - t4211, which expects `t/t4211/history.export` with a hard-coded ref to initialize the default branch, - t5560 because it sources `t/t556x_common` which uses `master`, - t8002 and t8012 because both source `t/annotate-tests.sh` which also uses `master`) This trick was performed by this command: $ sed -i '/^ *\. \.\/\(test-lib\|lib-\(bash\|cvs\|git-svn\)\|gitweb-lib\)\.sh$/i\ GIT_TEST_DEFAULT_INITIAL_BRANCH_NAME=master\ export GIT_TEST_DEFAULT_INITIAL_BRANCH_NAME\ ' $(git grep -l master t/t[0-9]*.sh) \ t/t4211*.sh t/t5560*.sh t/t8002*.sh t/t8012*.sh After that, careful, manual inspection revealed that some of the test scripts containing the needle `master` do not actually rely on a specific default branch name: either they mention `master` only in a comment, or they initialize that branch specificially, or they do not actually refer to the current default branch. Therefore, the aforementioned modification was undone in those test scripts thusly: $ git checkout HEAD -- \ t/t0027-auto-crlf.sh t/t0060-path-utils.sh \ t/t1011-read-tree-sparse-checkout.sh \ t/t1305-config-include.sh t/t1309-early-config.sh \ t/t1402-check-ref-format.sh t/t1450-fsck.sh \ t/t2024-checkout-dwim.sh \ t/t2106-update-index-assume-unchanged.sh \ t/t3040-subprojects-basic.sh t/t3301-notes.sh \ t/t3308-notes-merge.sh t/t3423-rebase-reword.sh \ t/t3436-rebase-more-options.sh \ t/t4015-diff-whitespace.sh t/t4257-am-interactive.sh \ t/t5323-pack-redundant.sh t/t5401-update-hooks.sh \ t/t5511-refspec.sh t/t5526-fetch-submodules.sh \ t/t5529-push-errors.sh t/t5530-upload-pack-error.sh \ t/t5548-push-porcelain.sh \ t/t5552-skipping-fetch-negotiator.sh \ t/t5572-pull-submodule.sh t/t5608-clone-2gb.sh \ t/t5614-clone-submodules-shallow.sh \ t/t7508-status.sh t/t7606-merge-custom.sh \ t/t9302-fast-import-unpack-limit.sh We excluded one set of test scripts in these commands, though: the range of `git p4` tests. The reason? `git p4` stores the (foreign) remote branch in the branch called `p4/master`, which is obviously not the default branch. Manual analysis revealed that only five of these tests actually require a specific default branch name to pass; They were modified thusly: $ sed -i '/^ *\. \.\/lib-git-p4\.sh$/i\ GIT_TEST_DEFAULT_INITIAL_BRANCH_NAME=master\ export GIT_TEST_DEFAULT_INITIAL_BRANCH_NAME\ ' t/t980[0167]*.sh t/t9811*.sh Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de> Signed-off-by: Junio C Hamano <gitster@pobox.com>
203 lines
5.9 KiB
Bash
Executable File
203 lines
5.9 KiB
Bash
Executable File
#!/bin/sh
|
|
|
|
test_description='signed tag tests'
|
|
GIT_TEST_DEFAULT_INITIAL_BRANCH_NAME=master
|
|
export GIT_TEST_DEFAULT_INITIAL_BRANCH_NAME
|
|
|
|
. ./test-lib.sh
|
|
. "$TEST_DIRECTORY/lib-gpg.sh"
|
|
|
|
test_expect_success GPG 'create signed tags' '
|
|
echo 1 >file && git add file &&
|
|
test_tick && git commit -m initial &&
|
|
git tag -s -m initial initial &&
|
|
git branch side &&
|
|
|
|
echo 2 >file && test_tick && git commit -a -m second &&
|
|
git tag -s -m second second &&
|
|
|
|
git checkout side &&
|
|
echo 3 >elif && git add elif &&
|
|
test_tick && git commit -m "third on side" &&
|
|
|
|
git checkout master &&
|
|
test_tick && git merge -S side &&
|
|
git tag -s -m merge merge &&
|
|
|
|
echo 4 >file && test_tick && git commit -a -S -m "fourth unsigned" &&
|
|
git tag -a -m fourth-unsigned fourth-unsigned &&
|
|
|
|
test_tick && git commit --amend -S -m "fourth signed" &&
|
|
git tag -s -m fourth fourth-signed &&
|
|
|
|
echo 5 >file && test_tick && git commit -a -m "fifth" &&
|
|
git tag fifth-unsigned &&
|
|
|
|
git config commit.gpgsign true &&
|
|
echo 6 >file && test_tick && git commit -a -m "sixth" &&
|
|
git tag -a -m sixth sixth-unsigned &&
|
|
|
|
test_tick && git rebase -f HEAD^^ && git tag -s -m 6th sixth-signed HEAD^ &&
|
|
git tag -m seventh -s seventh-signed &&
|
|
|
|
echo 8 >file && test_tick && git commit -a -m eighth &&
|
|
git tag -uB7227189 -m eighth eighth-signed-alt
|
|
'
|
|
|
|
test_expect_success GPGSM 'create signed tags x509 ' '
|
|
test_config gpg.format x509 &&
|
|
test_config user.signingkey $GIT_COMMITTER_EMAIL &&
|
|
echo 9 >file && test_tick && git commit -a -m "ninth gpgsm-signed" &&
|
|
git tag -s -m ninth ninth-signed-x509
|
|
'
|
|
|
|
test_expect_success GPG 'verify and show signatures' '
|
|
(
|
|
for tag in initial second merge fourth-signed sixth-signed seventh-signed
|
|
do
|
|
git verify-tag $tag 2>actual &&
|
|
grep "Good signature from" actual &&
|
|
! grep "BAD signature from" actual &&
|
|
echo $tag OK || exit 1
|
|
done
|
|
) &&
|
|
(
|
|
for tag in fourth-unsigned fifth-unsigned sixth-unsigned
|
|
do
|
|
test_must_fail git verify-tag $tag 2>actual &&
|
|
! grep "Good signature from" actual &&
|
|
! grep "BAD signature from" actual &&
|
|
echo $tag OK || exit 1
|
|
done
|
|
) &&
|
|
(
|
|
for tag in eighth-signed-alt
|
|
do
|
|
git verify-tag $tag 2>actual &&
|
|
grep "Good signature from" actual &&
|
|
! grep "BAD signature from" actual &&
|
|
grep "not certified" actual &&
|
|
echo $tag OK || exit 1
|
|
done
|
|
)
|
|
'
|
|
|
|
test_expect_success GPGSM 'verify and show signatures x509' '
|
|
git verify-tag ninth-signed-x509 2>actual &&
|
|
grep "Good signature from" actual &&
|
|
! grep "BAD signature from" actual &&
|
|
echo ninth-signed-x509 OK
|
|
'
|
|
|
|
test_expect_success GPGSM 'verify and show signatures x509 with low minTrustLevel' '
|
|
test_config gpg.minTrustLevel undefined &&
|
|
git verify-tag ninth-signed-x509 2>actual &&
|
|
grep "Good signature from" actual &&
|
|
! grep "BAD signature from" actual &&
|
|
echo ninth-signed-x509 OK
|
|
'
|
|
|
|
test_expect_success GPGSM 'verify and show signatures x509 with matching minTrustLevel' '
|
|
test_config gpg.minTrustLevel fully &&
|
|
git verify-tag ninth-signed-x509 2>actual &&
|
|
grep "Good signature from" actual &&
|
|
! grep "BAD signature from" actual &&
|
|
echo ninth-signed-x509 OK
|
|
'
|
|
|
|
test_expect_success GPGSM 'verify and show signatures x509 with high minTrustLevel' '
|
|
test_config gpg.minTrustLevel ultimate &&
|
|
test_must_fail git verify-tag ninth-signed-x509 2>actual &&
|
|
grep "Good signature from" actual &&
|
|
! grep "BAD signature from" actual &&
|
|
echo ninth-signed-x509 OK
|
|
'
|
|
|
|
test_expect_success GPG 'detect fudged signature' '
|
|
git cat-file tag seventh-signed >raw &&
|
|
sed -e "/^tag / s/seventh/7th forged/" raw >forged1 &&
|
|
git hash-object -w -t tag forged1 >forged1.tag &&
|
|
test_must_fail git verify-tag $(cat forged1.tag) 2>actual1 &&
|
|
grep "BAD signature from" actual1 &&
|
|
! grep "Good signature from" actual1
|
|
'
|
|
|
|
test_expect_success GPG 'verify signatures with --raw' '
|
|
(
|
|
for tag in initial second merge fourth-signed sixth-signed seventh-signed
|
|
do
|
|
git verify-tag --raw $tag 2>actual &&
|
|
grep "GOODSIG" actual &&
|
|
! grep "BADSIG" actual &&
|
|
echo $tag OK || exit 1
|
|
done
|
|
) &&
|
|
(
|
|
for tag in fourth-unsigned fifth-unsigned sixth-unsigned
|
|
do
|
|
test_must_fail git verify-tag --raw $tag 2>actual &&
|
|
! grep "GOODSIG" actual &&
|
|
! grep "BADSIG" actual &&
|
|
echo $tag OK || exit 1
|
|
done
|
|
) &&
|
|
(
|
|
for tag in eighth-signed-alt
|
|
do
|
|
git verify-tag --raw $tag 2>actual &&
|
|
grep "GOODSIG" actual &&
|
|
! grep "BADSIG" actual &&
|
|
grep "TRUST_UNDEFINED" actual &&
|
|
echo $tag OK || exit 1
|
|
done
|
|
)
|
|
'
|
|
|
|
test_expect_success GPGSM 'verify signatures with --raw x509' '
|
|
git verify-tag --raw ninth-signed-x509 2>actual &&
|
|
grep "GOODSIG" actual &&
|
|
! grep "BADSIG" actual &&
|
|
echo ninth-signed-x509 OK
|
|
'
|
|
|
|
test_expect_success GPG 'verify multiple tags' '
|
|
tags="fourth-signed sixth-signed seventh-signed" &&
|
|
for i in $tags
|
|
do
|
|
git verify-tag -v --raw $i || return 1
|
|
done >expect.stdout 2>expect.stderr.1 &&
|
|
grep "^.GNUPG:." <expect.stderr.1 >expect.stderr &&
|
|
git verify-tag -v --raw $tags >actual.stdout 2>actual.stderr.1 &&
|
|
grep "^.GNUPG:." <actual.stderr.1 >actual.stderr &&
|
|
test_cmp expect.stdout actual.stdout &&
|
|
test_cmp expect.stderr actual.stderr
|
|
'
|
|
|
|
test_expect_success GPGSM 'verify multiple tags x509' '
|
|
tags="seventh-signed ninth-signed-x509" &&
|
|
for i in $tags
|
|
do
|
|
git verify-tag -v --raw $i || return 1
|
|
done >expect.stdout 2>expect.stderr.1 &&
|
|
grep "^.GNUPG:." <expect.stderr.1 >expect.stderr &&
|
|
git verify-tag -v --raw $tags >actual.stdout 2>actual.stderr.1 &&
|
|
grep "^.GNUPG:." <actual.stderr.1 >actual.stderr &&
|
|
test_cmp expect.stdout actual.stdout &&
|
|
test_cmp expect.stderr actual.stderr
|
|
'
|
|
|
|
test_expect_success GPG 'verifying tag with --format' '
|
|
cat >expect <<-\EOF &&
|
|
tagname : fourth-signed
|
|
EOF
|
|
git verify-tag --format="tagname : %(tag)" "fourth-signed" >actual &&
|
|
test_cmp expect actual
|
|
'
|
|
|
|
test_expect_success GPG 'verifying a forged tag with --format should fail silently' '
|
|
test_must_fail git verify-tag --format="tagname : %(tag)" $(cat forged1.tag) >actual-forged &&
|
|
test_must_be_empty actual-forged
|
|
'
|
|
|
|
test_done
|