1
0
mirror of git://git.gnupg.org/gnupg.git synced 2025-01-03 12:11:33 +01:00

gpg: Emit FAILURE stati now in almost all cases.

* g10/cpr.c (write_status_failure): Make it print only once.
* g10/gpg.c (wrong_args): Bump error counter.
(g10_exit): Print a FAILURE status if we ever did a log_error etc.
(main): Use log_error instead of log_fatal at one place.  Print a
FAILURE status for a bad option.  Ditto for certain exit points so
that we can see different error locations.
--

This makes it easier to detect errors by tools which have no way to
get the exit code (e.g. due to double forking).

GnuPG-bug-id: 3872
Signed-off-by: Werner Koch <wk@gnupg.org>
This commit is contained in:
Werner Koch 2018-04-06 17:32:08 +02:00
parent cfd0779808
commit 0336e5d1a7
No known key found for this signature in database
GPG Key ID: E3FDFF218E45B72B
3 changed files with 65 additions and 11 deletions

View File

@ -245,9 +245,13 @@ write_status_errcode (const char *where, int errcode)
void void
write_status_failure (const char *where, gpg_error_t err) write_status_failure (const char *where, gpg_error_t err)
{ {
static int any_failure_printed;
if (!statusfp || !status_currently_allowed (STATUS_FAILURE)) if (!statusfp || !status_currently_allowed (STATUS_FAILURE))
return; /* Not enabled or allowed. */ return; /* Not enabled or allowed. */
if (any_failure_printed)
return;
any_failure_printed = 1;
es_fprintf (statusfp, "[GNUPG:] %s %s %u\n", es_fprintf (statusfp, "[GNUPG:] %s %s %u\n",
get_status_string (STATUS_FAILURE), where, err); get_status_string (STATUS_FAILURE), where, err);
if (es_fflush (statusfp) && opt.exit_on_status_write_error) if (es_fflush (statusfp) && opt.exit_on_status_write_error)

View File

@ -1166,6 +1166,7 @@ static void
wrong_args( const char *text) wrong_args( const char *text)
{ {
es_fprintf (es_stderr, _("usage: %s [options] %s\n"), GPG_NAME, text); es_fprintf (es_stderr, _("usage: %s [options] %s\n"), GPG_NAME, text);
log_inc_errorcount ();
g10_exit(2); g10_exit(2);
} }
@ -3107,7 +3108,7 @@ main (int argc, char **argv)
case oCommandFD: case oCommandFD:
opt.command_fd = translate_sys2libc_fd_int (pargs.r.ret_int, 0); opt.command_fd = translate_sys2libc_fd_int (pargs.r.ret_int, 0);
if (! gnupg_fd_valid (opt.command_fd)) if (! gnupg_fd_valid (opt.command_fd))
log_fatal ("command-fd is invalid: %s\n", strerror (errno)); log_error ("command-fd is invalid: %s\n", strerror (errno));
break; break;
case oCommandFile: case oCommandFile:
opt.command_fd = open_info_file (pargs.r.ret_str, 0, 1); opt.command_fd = open_info_file (pargs.r.ret_str, 0, 1);
@ -3563,7 +3564,16 @@ main (int argc, char **argv)
case oNoop: break; case oNoop: break;
default: default:
pargs.err = configfp? ARGPARSE_PRINT_WARNING:ARGPARSE_PRINT_ERROR; if (configfp)
pargs.err = ARGPARSE_PRINT_WARNING;
else
{
pargs.err = ARGPARSE_PRINT_ERROR;
/* The argparse fucntion calls a plain exit and thus
* we need to print a status here. */
write_status_failure ("option-parser",
gpg_error(GPG_ERR_GENERAL));
}
break; break;
} }
} }
@ -3582,7 +3592,10 @@ main (int argc, char **argv)
} }
xfree(configname); configname = NULL; xfree(configname); configname = NULL;
if (log_get_errorcount (0)) if (log_get_errorcount (0))
g10_exit(2); {
write_status_failure ("option-parser", gpg_error(GPG_ERR_GENERAL));
g10_exit(2);
}
/* The command --gpgconf-list is pretty simple and may be called /* The command --gpgconf-list is pretty simple and may be called
directly after the option parsing. */ directly after the option parsing. */
@ -3603,7 +3616,10 @@ main (int argc, char **argv)
"--print-pks-records", "--print-pks-records",
"--export-options export-pka"); "--export-options export-pka");
if (log_get_errorcount (0)) if (log_get_errorcount (0))
g10_exit(2); {
write_status_failure ("option-checking", gpg_error(GPG_ERR_GENERAL));
g10_exit(2);
}
if( nogreeting ) if( nogreeting )
@ -3704,6 +3720,7 @@ main (int argc, char **argv)
{ {
log_info(_("will not run with insecure memory due to %s\n"), log_info(_("will not run with insecure memory due to %s\n"),
"--require-secmem"); "--require-secmem");
write_status_failure ("option-checking", gpg_error(GPG_ERR_GENERAL));
g10_exit(2); g10_exit(2);
} }
@ -3844,7 +3861,11 @@ main (int argc, char **argv)
} }
if( log_get_errorcount(0) ) if( log_get_errorcount(0) )
g10_exit(2); {
write_status_failure ("option-postprocessing",
gpg_error(GPG_ERR_GENERAL));
g10_exit (2);
}
if(opt.compress_level==0) if(opt.compress_level==0)
opt.compress_algo=COMPRESS_ALGO_NONE; opt.compress_algo=COMPRESS_ALGO_NONE;
@ -3945,7 +3966,10 @@ main (int argc, char **argv)
/* Fail hard. */ /* Fail hard. */
if (log_get_errorcount (0)) if (log_get_errorcount (0))
{
write_status_failure ("option-checking", gpg_error(GPG_ERR_GENERAL));
g10_exit (2); g10_exit (2);
}
/* Set the random seed file. */ /* Set the random seed file. */
if( use_random_seed ) { if( use_random_seed ) {
@ -4929,7 +4953,10 @@ main (int argc, char **argv)
hd = keydb_new (); hd = keydb_new ();
if (! hd) if (! hd)
g10_exit (1); {
write_status_failure ("tofu-driver", gpg_error(GPG_ERR_GENERAL));
g10_exit (1);
}
tofu_begin_batch_update (ctrl); tofu_begin_batch_update (ctrl);
@ -4943,6 +4970,7 @@ main (int argc, char **argv)
{ {
log_error (_("error parsing key specification '%s': %s\n"), log_error (_("error parsing key specification '%s': %s\n"),
argv[i], gpg_strerror (rc)); argv[i], gpg_strerror (rc));
write_status_failure ("tofu-driver", rc);
g10_exit (1); g10_exit (1);
} }
@ -4956,6 +4984,8 @@ main (int argc, char **argv)
log_error (_("'%s' does not appear to be a valid" log_error (_("'%s' does not appear to be a valid"
" key ID, fingerprint or keygrip\n"), " key ID, fingerprint or keygrip\n"),
argv[i]); argv[i]);
write_status_failure ("tofu-driver",
gpg_error(GPG_ERR_GENERAL));
g10_exit (1); g10_exit (1);
} }
@ -4966,6 +4996,7 @@ main (int argc, char **argv)
the string. */ the string. */
log_error ("keydb_search_reset failed: %s\n", log_error ("keydb_search_reset failed: %s\n",
gpg_strerror (rc)); gpg_strerror (rc));
write_status_failure ("tofu-driver", rc);
g10_exit (1); g10_exit (1);
} }
@ -4974,6 +5005,7 @@ main (int argc, char **argv)
{ {
log_error (_("key \"%s\" not found: %s\n"), argv[i], log_error (_("key \"%s\" not found: %s\n"), argv[i],
gpg_strerror (rc)); gpg_strerror (rc));
write_status_failure ("tofu-driver", rc);
g10_exit (1); g10_exit (1);
} }
@ -4982,12 +5014,16 @@ main (int argc, char **argv)
{ {
log_error (_("error reading keyblock: %s\n"), log_error (_("error reading keyblock: %s\n"),
gpg_strerror (rc)); gpg_strerror (rc));
write_status_failure ("tofu-driver", rc);
g10_exit (1); g10_exit (1);
} }
merge_keys_and_selfsig (ctrl, kb); merge_keys_and_selfsig (ctrl, kb);
if (tofu_set_policy (ctrl, kb, policy)) if (tofu_set_policy (ctrl, kb, policy))
g10_exit (1); {
write_status_failure ("tofu-driver", rc);
g10_exit (1);
}
release_kbnode (kb); release_kbnode (kb);
} }
@ -5069,6 +5105,12 @@ emergency_cleanup (void)
void void
g10_exit( int rc ) g10_exit( int rc )
{ {
/* If we had an error but not printed an error message, do it now.
* Note that write_status_failure will never print a second failure
* status line. */
if (log_get_errorcount (0))
write_status_failure ("gpg-exit", gpg_error (GPG_ERR_GENERAL));
gcry_control (GCRYCTL_UPDATE_RANDOM_SEED_FILE); gcry_control (GCRYCTL_UPDATE_RANDOM_SEED_FILE);
if (DBG_CLOCK) if (DBG_CLOCK)
log_clock ("stop"); log_clock ("stop");

View File

@ -1464,7 +1464,7 @@ main ( int argc, char **argv)
DIM (compliance_options), DIM (compliance_options),
opt.quiet); opt.quiet);
if (compliance < 0) if (compliance < 0)
gpgsm_exit (1); log_inc_errorcount (); /* Force later termination. */
opt.compliance = compliance; opt.compliance = compliance;
} }
break; break;
@ -1493,7 +1493,11 @@ main ( int argc, char **argv)
NULL); NULL);
if (log_get_errorcount(0)) if (log_get_errorcount(0))
gpgsm_exit(2); {
gpgsm_status_with_error (&ctrl, STATUS_FAILURE,
"option-parser", gpg_error (GPG_ERR_GENERAL));
gpgsm_exit(2);
}
if (pwfd != -1) /* Read the passphrase now. */ if (pwfd != -1) /* Read the passphrase now. */
read_passphrase_from_fd (pwfd); read_passphrase_from_fd (pwfd);
@ -1660,7 +1664,11 @@ main ( int argc, char **argv)
gnupg_compliance_option_string (opt.compliance)); gnupg_compliance_option_string (opt.compliance));
if (log_get_errorcount(0)) if (log_get_errorcount(0))
gpgsm_exit(2); {
gpgsm_status_with_error (&ctrl, STATUS_FAILURE, "option-postprocessing",
gpg_error (GPG_ERR_GENERAL));
gpgsm_exit (2);
}
/* Set the random seed file. */ /* Set the random seed file. */
if (use_random_seed) if (use_random_seed)