Skip to content

Fix: Thread safe GPGME tmp directory

What does this MR do?

Makes all Gitlab::Gpg operations thread safe.

Are there points in the code the reviewer needs to double check?

Why was this MR needed?

As GPGME stores the home directory on the class (or module) multiple threads using different temporary gpg directories unset the other's directory and end up using the wrong one. This leads to incorrect gpg operations, e.g. wrong signature validations.

The development of this MR is sponsored by @siemens (/cc @bufferoverflow).

Screenshots (if relevant)

Does this MR meet the acceptance criteria?

What are the relevant issue numbers?

Fixes https://gitlab.com/gitlab-org/gitlab-ce/issues/35986

Edited by username-removed-81730

Merge request reports