{"thread":{"id":"1217","subject":"[PATCH] Support more http features: https no cert, .netrc -> auth","startedAt":"2005-07-13T02:12:40Z","lastAt":"2005-07-13T20:50:58Z","messageCount":3,"participants":["Darrin Thompson","Junio C Hamano"],"isPatch":true,"patchVersion":1,"patchTotal":null},"messages":[{"id":"6065","messageId":"20050713021240.88AAD63780@morimoto.progeny.com","threadId":"1217","inReplyTo":null,"subject":"[PATCH] Support more http features: https no cert, .netrc -> auth","fromName":"Darrin Thompson","fromEmail":"darrint@progeny.com","sentAt":"2005-07-13T02:12:40Z","receivedAt":"2005-07-13T02:12:40Z","isPatch":true,"sender":{"key":"darrint@progeny.com","avatar":null},"body":"Cause setting environment variable GIT_SSL_NO_VERIFY to turn off\ncurl's ssl peer verification.\n\nOnly use curl for http transfers, instead of curl and wget.\n\nMake curl check ~/.netrc for credentials.\n\n---\ncommit 229718f5723f81304c7c038c18d1e1bd630026ae\ntree 501594e7b424855f08d7bef6bd4f9721d40d4a3c\nparent e30e814dbfef7a6e89418863e5d7291a2d53b18f\nauthor Darrin Thompson <darrint@progeny.com> Tue, 12 Jul 2005 16:27:05 -0500\n\n git-fetch-script |    7 +++++--\n http-pull.c      |    6 ++++++\n 2 files changed, 11 insertions(+), 2 deletions(-)\n\ndiff --git a/git-fetch-script b/git-fetch-script\n--- a/git-fetch-script\n+++ b/git-fetch-script\n@@ -14,8 +14,11 @@ fi\n TMP_HEAD=\"$GIT_DIR/TMP_HEAD\"\n \n case \"$merge_repo\" in\n-http://*)\n-\thead=$(wget -q -O - \"$merge_repo/$merge_name\") || exit 1\n+http://*|https://*)\n+        if [ -n \"$GIT_SSL_NO_VERIFY\" ]; then\n+            curl_extra_args=\"-k\"\n+        fi\n+\thead=$(curl -ns $curl_extra_args \"$merge_repo/$merge_name\") || exit 1\n \techo Fetching $head using http\n \tgit-http-pull -v -a \"$head\" \"$merge_repo/\"\n \t;;\ndiff --git a/http-pull.c b/http-pull.c\n--- a/http-pull.c\n+++ b/http-pull.c\n@@ -16,6 +16,8 @@ static z_stream stream;\n static int local;\n static int zret;\n \n+static int curl_ssl_verify;\n+\n struct buffer\n {\n         size_t posn;\n@@ -173,6 +175,10 @@ int main(int argc, char **argv)\n \n \tcurl = curl_easy_init();\n \n+\tcurl_ssl_verify = gitenv(\"GIT_SSL_NO_VERIFY\") ? 0 : 1;\n+\tcurl_easy_setopt(curl, CURLOPT_SSL_VERIFYPEER, curl_ssl_verify);\n+\tcurl_easy_setopt(curl, CURLOPT_NETRC, CURL_NETRC_OPTIONAL);\n+\n \tbase = url;\n \n \tif (pull(commit_id))\n"},{"id":"6086","messageId":"7vk6juxy97.fsf@assigned-by-dhcp.cox.net","threadId":"1217","inReplyTo":"20050713021240.88AAD63780@morimoto.progeny.com","subject":"[PATCH (contingency)] Document \"curl\" requirements.","fromName":"Junio C Hamano","fromEmail":"junkio@cox.net","sentAt":"2005-07-13T20:11:00Z","receivedAt":"2005-07-13T20:11:00Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"darrint@progeny.com (Darrin Thompson) writes:\n\n> Cause setting environment variable GIT_SSL_NO_VERIFY to turn off\n> curl's ssl peer verification.\n>\n> Only use curl for http transfers, instead of curl and wget.\n\nI do not mind curl per se, since we already require libcurl for\nhttp-pull, but it would be nice if we document what external\nsoftware we depend on in one place.  Something like this on top\nof what you posted?\n\n------------\nNot just libcurl, but now we require curl executable as well.\n\nSigned-off-by: Junio C Hamano <junkio@cox.net>\n---\ndiff --git a/INSTALL b/INSTALL\n--- a/INSTALL\n+++ b/INSTALL\n@@ -41,8 +41,10 @@ Issues of note:\n \t  can avoid the bignum support by excising git-rev-list support\n \t  for \"--merge-order\" (by hand).\n \n-\t- \"libcurl\".  git-http-pull uses this.  You can disable building of\n-\t  that program if you just want to get started. \n+\t- \"libcurl\" and \"curl\" (executable).  git-http-pull and\n+\t  git-fetch-script use them.  If you do not use http\n+\t  transfer, you are probabaly OK if you do not have\n+\t  these two.\n \n \t- \"GNU diff\" to generate patches.  Of course, you don't _have_ to\n \t  generate patches if you don't want to, but let's face it, you'll\n"},{"id":"6094","messageId":"1121287859.3968.16.camel@localhost.localdomain","threadId":"1217","inReplyTo":"7vk6juxy97.fsf@assigned-by-dhcp.cox.net","subject":"Re: [PATCH (contingency)] Document \"curl\" requirements.","fromName":"Darrin Thompson","fromEmail":"darrint@progeny.com","sentAt":"2005-07-13T20:50:58Z","receivedAt":"2005-07-13T20:50:58Z","isPatch":true,"sender":{"key":"darrint@progeny.com","avatar":null},"body":"On Wed, 2005-07-13 at 13:11 -0700, Junio C Hamano wrote:\n> darrint@progeny.com (Darrin Thompson) writes:\n> \n> > Cause setting environment variable GIT_SSL_NO_VERIFY to turn off\n> > curl's ssl peer verification.\n> >\n> > Only use curl for http transfers, instead of curl and wget.\n> \n> I do not mind curl per se, since we already require libcurl for\n> http-pull, but it would be nice if we document what external\n> software we depend on in one place.  Something like this on top\n> of what you posted?\n\nI have no problem with it. Do I need to take some action?\n\n--\nDarrin\n"}]}