{"thread":{"id":"14356","subject":"[PATCH 2/4] git-imap-send: Add support for SSL.","startedAt":"2008-07-08T22:18:14Z","lastAt":"2008-07-10T06:39:41Z","messageCount":8,"participants":["Robert Shearman","Junio C Hamano","Abhijit Menon-Sen","Rob Shearman","Josh Triplett","Jeff King"],"isPatch":true,"patchVersion":1,"patchTotal":4},"messages":[{"id":"82640","messageId":"1215555496-21335-2-git-send-email-robertshearman@gmail.com","threadId":"14356","inReplyTo":null,"subject":"[PATCH 2/4] git-imap-send: Add support for SSL.","fromName":"Robert Shearman","fromEmail":"robertshearman@gmail.com","sentAt":"2008-07-08T22:18:14Z","receivedAt":"2008-07-08T22:18:14Z","isPatch":true,"sender":{"key":"robertshearman@gmail.com","avatar":null},"body":"Allow SSL to be used when a imaps:// URL is used for the host name.\n\nAlso, automatically use TLS when not using imaps:// by using the IMAP STARTTLS command, if the server supports it.\n\nTested with Courier and Gimap IMAP servers.\n---\n Documentation/git-imap-send.txt |    5 +-\n Makefile                        |    4 +-\n imap-send.c                     |  166 +++++++++++++++++++++++++++++++++++----\n 3 files changed, 157 insertions(+), 18 deletions(-)\n\ndiff --git a/Documentation/git-imap-send.txt b/Documentation/git-imap-send.txt\nindex b3d8da3..e4a5873 100644\n--- a/Documentation/git-imap-send.txt\n+++ b/Documentation/git-imap-send.txt\n@@ -37,10 +37,11 @@ configuration file (shown with examples):\n     Tunnel = \"ssh -q user@server.com /usr/bin/imapd ./Maildir 2> /dev/null\"\n \n [imap]\n-    Host = imap.server.com\n+    Host = imaps://imap.example.com\n     User = bob\n     Pass = pwd\n-    Port = 143\n+    Port = 993\n+    sslverify = false\n ..........................\n \n \ndiff --git a/Makefile b/Makefile\nindex bddd1a7..d9265f7 100644\n--- a/Makefile\n+++ b/Makefile\n@@ -1193,7 +1193,9 @@ endif\n git-%$X: %.o $(GITLIBS)\n \t$(QUIET_LINK)$(CC) $(ALL_CFLAGS) -o $@ $(ALL_LDFLAGS) $(filter %.o,$^) $(LIBS)\n \n-git-imap-send$X: imap-send.o $(LIB_FILE)\n+git-imap-send$X: imap-send.o $(GITLIBS)\n+\t$(QUIET_LINK)$(CC) $(ALL_CFLAGS) -o $@ $(ALL_LDFLAGS) $(filter %.o,$^) \\\n+\t\t$(LIBS) $(OPENSSL_LINK) $(OPENSSL_LIBSSL)\n \n http.o http-walker.o http-push.o transport.o: http.h\n \ndiff --git a/imap-send.c b/imap-send.c\nindex 89a1532..d138726 100644\n--- a/imap-send.c\n+++ b/imap-send.c\n@@ -23,6 +23,12 @@\n  */\n \n #include \"cache.h\"\n+#ifdef NO_OPENSSL\n+typedef void *SSL;\n+#else\n+# include <openssl/ssl.h>\n+# include <openssl/err.h>\n+#endif\n \n typedef struct store_conf {\n \tchar *name;\n@@ -129,6 +135,8 @@ typedef struct imap_server_conf {\n \tint port;\n \tchar *user;\n \tchar *pass;\n+\tint use_ssl;\n+\tint ssl_verify;\n } imap_server_conf_t;\n \n typedef struct imap_store_conf {\n@@ -148,6 +156,7 @@ typedef struct _list {\n \n typedef struct {\n \tint fd;\n+\tSSL *ssl;\n } Socket_t;\n \n typedef struct {\n@@ -201,6 +210,7 @@ enum CAPABILITY {\n \tUIDPLUS,\n \tLITERALPLUS,\n \tNAMESPACE,\n+\tSTARTTLS,\n };\n \n static const char *cap_list[] = {\n@@ -208,6 +218,7 @@ static const char *cap_list[] = {\n \t\"UIDPLUS\",\n \t\"LITERAL+\",\n \t\"NAMESPACE\",\n+\t\"STARTTLS\",\n };\n \n #define RESP_OK    0\n@@ -225,19 +236,101 @@ static const char *Flags[] = {\n \t\"Deleted\",\n };\n \n+#ifndef NO_OPENSSL\n+static void ssl_socket_perror(const char *func)\n+{\n+\tfprintf(stderr, \"%s: %s\\n\", func, ERR_error_string(ERR_get_error(), 0));\n+}\n+#endif\n+\n static void\n socket_perror( const char *func, Socket_t *sock, int ret )\n {\n-\tif (ret < 0)\n-\t\tperror( func );\n+#ifndef NO_OPENSSL\n+\tif (sock->ssl) {\n+\t\tint sslerr = SSL_get_error(sock->ssl, ret);\n+\t\tswitch (sslerr) {\n+\t\tcase SSL_ERROR_NONE:\n+\t\t\tbreak;\n+\t\tcase SSL_ERROR_SYSCALL:\n+\t\t\tperror(\"SSL_connect\");\n+\t\t\tbreak;\n+\t\tdefault:\n+\t\t\tssl_socket_perror(\"SSL_connect\");\n+\t\t\tbreak;\n+\t\t}\n+\t} else\n+#endif\n+\t{\n+\t\tif (ret < 0)\n+\t\t\tperror(func);\n+\t\telse\n+\t\t\tfprintf(stderr, \"%s: unexpected EOF\\n\", func);\n+\t}\n+}\n+\n+static int ssl_socket_connect(Socket_t *sock, int use_tls_only, int verify)\n+{\n+#ifdef NO_OPENSSL\n+\tfprintf(stderr, \"SSL requested but SSL support not compiled in\\n\");\n+\treturn -1;\n+#else\n+\tSSL_METHOD *meth;\n+\tSSL_CTX *ctx;\n+\tint ret;\n+\n+\tSSL_library_init();\n+\tSSL_load_error_strings();\n+\n+\tif (use_tls_only)\n+\t\tmeth = TLSv1_method();\n \telse\n-\t\tfprintf( stderr, \"%s: unexpected EOF\\n\", func );\n+\t\tmeth = SSLv23_method();\n+\n+\tif (!meth) {\n+\t\tssl_socket_perror(\"SSLv23_method\");\n+\t\treturn -1;\n+\t}\n+\n+\tctx = SSL_CTX_new(meth);\n+\n+\tif (verify)\n+\t\tSSL_CTX_set_verify(ctx, SSL_VERIFY_PEER, NULL);\n+\n+\tif (!SSL_CTX_set_default_verify_paths(ctx)) {\n+\t\tssl_socket_perror(\"SSL_CTX_set_default_verify_paths\");\n+\t\treturn -1;\n+\t}\n+\tsock->ssl = SSL_new(ctx);\n+\tif (!sock->ssl) {\n+\t\tssl_socket_perror(\"SSL_new\");\n+\t\treturn -1;\n+\t}\n+\tif (!SSL_set_fd(sock->ssl, sock->fd)) {\n+\t\tssl_socket_perror(\"SSL_set_fd\");\n+\t\treturn -1;\n+\t}\n+\n+\tret = SSL_connect(sock->ssl);\n+\tif (ret <= 0) {\n+\t\tsocket_perror(\"SSL_connect\", sock, ret);\n+\t\treturn -1;\n+\t}\n+\n+\treturn 0;\n+#endif\n }\n \n static int\n socket_read( Socket_t *sock, char *buf, int len )\n {\n-\tssize_t n = xread( sock->fd, buf, len );\n+\tssize_t n;\n+#ifndef NO_OPENSSL\n+\tif (sock->ssl)\n+\t\tn = SSL_read(sock->ssl, buf, len);\n+\telse\n+#endif\n+\t\tn = xread( sock->fd, buf, len );\n \tif (n <= 0) {\n \t\tsocket_perror( \"read\", sock, n );\n \t\tclose( sock->fd );\n@@ -249,7 +342,13 @@ socket_read( Socket_t *sock, char *buf, int len )\n static int\n socket_write( Socket_t *sock, const char *buf, int len )\n {\n-\tint n = write_in_full( sock->fd, buf, len );\n+\tint n;\n+#ifndef NO_OPENSSL\n+\tif (sock->ssl)\n+\t\tn = SSL_write(sock->ssl, buf, len);\n+\telse\n+#endif\n+\t\tn = write_in_full( sock->fd, buf, len );\n \tif (n != len) {\n \t\tsocket_perror( \"write\", sock, n );\n \t\tclose( sock->fd );\n@@ -258,6 +357,17 @@ socket_write( Socket_t *sock, const char *buf, int len )\n \treturn n;\n }\n \n+static void socket_shutdown(Socket_t *sock)\n+{\n+#ifndef NO_OPENSSL\n+\tif (sock->ssl) {\n+\t\tSSL_shutdown(sock->ssl);\n+\t\tSSL_free(sock->ssl);\n+\t}\n+#endif\n+\tclose(sock->fd);\n+}\n+\n /* simple line buffering */\n static int\n buffer_gets( buffer_t * b, char **s )\n@@ -875,7 +985,7 @@ imap_close_server( imap_store_t *ictx )\n \n \tif (imap->buf.sock.fd != -1) {\n \t\timap_exec( ictx, NULL, \"LOGOUT\" );\n-\t\tclose( imap->buf.sock.fd );\n+\t\tsocket_shutdown( &imap->buf.sock );\n \t}\n \tfree_list( imap->ns_personal );\n \tfree_list( imap->ns_other );\n@@ -906,6 +1016,7 @@ imap_open_store( imap_server_conf_t *srvc )\n \n \tctx->imap = imap = xcalloc( sizeof(*imap), 1 );\n \timap->buf.sock.fd = -1;\n+\timap->buf.sock.ssl = NULL;\n \timap->in_progress_append = &imap->in_progress;\n \n \t/* open connection to IMAP server */\n@@ -958,10 +1069,15 @@ imap_open_store( imap_server_conf_t *srvc )\n \t\t\tperror( \"connect\" );\n \t\t\tgoto bail;\n \t\t}\n-\t\timap_info( \"ok\\n\" );\n-\n+\t\t\n \t\timap->buf.sock.fd = s;\n \n+\t\tif (srvc->use_ssl &&\n+\t\t    ssl_socket_connect(&imap->buf.sock, 0, srvc->ssl_verify)) {\n+\t\t\tclose(s);\n+\t\t\tgoto bail;\n+\t\t}\n+\t\timap_info( \"ok\\n\" );\n \t}\n \n \t/* read the greeting string */\n@@ -986,7 +1102,18 @@ imap_open_store( imap_server_conf_t *srvc )\n \t\tgoto bail;\n \n \tif (!preauth) {\n-\n+#ifndef NO_OPENSSL\n+\t\tif (!srvc->use_ssl && CAP(STARTTLS)) {\n+\t\t\tif (imap_exec(ctx, 0, \"STARTTLS\") != RESP_OK)\n+\t\t\t\tgoto bail;\n+\t\t\tif (ssl_socket_connect(&imap->buf.sock, 1,\n+\t\t\t\t\t       srvc->ssl_verify))\n+\t\t\t\tgoto bail;\n+\t\t\t/* capabilities may have changed, so get the new capabilities */\n+\t\t\tif (imap_exec(ctx, 0, \"CAPABILITY\") != RESP_OK)\n+\t\t\t\tgoto bail;\n+\t\t}\n+#endif\n \t\timap_info (\"Logging in...\\n\");\n \t\tif (!srvc->user) {\n \t\t\tfprintf( stderr, \"Skipping server %s, no user\\n\", srvc->host );\n@@ -1014,7 +1141,9 @@ imap_open_store( imap_server_conf_t *srvc )\n \t\t\tfprintf( stderr, \"Skipping account %s@%s, server forbids LOGIN\\n\", srvc->user, srvc->host );\n \t\t\tgoto bail;\n \t\t}\n-\t\timap_warn( \"*** IMAP Warning *** Password is being sent in the clear\\n\" );\n+\t\tif (!imap->buf.sock.ssl)\n+\t\t\timap_warn( \"*** IMAP Warning *** Password is being \"\n+\t\t\t\t   \"sent in the clear\\n\" );\n \t\tif (imap_exec( ctx, NULL, \"LOGIN \\\"%s\\\" \\\"%s\\\"\", srvc->user, srvc->pass ) != RESP_OK) {\n \t\t\tfprintf( stderr, \"IMAP error: LOGIN failed\\n\" );\n \t\t\tgoto bail;\n@@ -1242,6 +1371,8 @@ static imap_server_conf_t server =\n \t0,\t/* port */\n \tNULL,\t/* user */\n \tNULL,\t/* pass */\n+\t0,   \t/* use_ssl */\n+\t1,   \t/* ssl_verify */\n };\n \n static char *imap_folder;\n@@ -1262,11 +1393,11 @@ git_imap_config(const char *key, const char *val, void *cb)\n \tif (!strcmp( \"folder\", key )) {\n \t\timap_folder = xstrdup( val );\n \t} else if (!strcmp( \"host\", key )) {\n-\t\t{\n-\t\t\tif (!prefixcmp(val, \"imap:\"))\n-\t\t\t\tval += 5;\n-\t\t\tif (!server.port)\n-\t\t\t\tserver.port = 143;\n+\t\tif (!prefixcmp(val, \"imap:\"))\n+\t\t\tval += 5;\n+\t\telse if (!prefixcmp(val, \"imaps:\")) {\n+\t\t\tval += 6;\n+\t\t\tserver.use_ssl = 1;\n \t\t}\n \t\tif (!prefixcmp(val, \"//\"))\n \t\t\tval += 2;\n@@ -1280,6 +1411,8 @@ git_imap_config(const char *key, const char *val, void *cb)\n \t\tserver.port = git_config_int( key, val );\n \telse if (!strcmp( \"tunnel\", key ))\n \t\tserver.tunnel = xstrdup( val );\n+\telse if (!strcmp( \"ssl_verify\", key ))\n+\t\tserver.ssl_verify = git_config_bool( key, val );\n \treturn 0;\n }\n \n@@ -1299,6 +1432,9 @@ main(int argc, char **argv)\n \tsetup_git_directory_gently( NULL );\n \tgit_config(git_imap_config, NULL);\n \n+\tif (!server.port)\n+\t\tserver.port = server.use_ssl ? 993 : 143;\n+\n \tif (!imap_folder) {\n \t\tfprintf( stderr, \"no imap store specified\\n\" );\n \t\treturn 1;\n-- \n1.5.6.GIT\n"},{"id":"82645","messageId":"7vbq18q7yk.fsf@gitster.siamese.dyndns.org","threadId":"14356","inReplyTo":"1215555496-21335-2-git-send-email-robertshearman@gmail.com","subject":"Re: [PATCH 2/4] git-imap-send: Add support for SSL.","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2008-07-08T23:20:19Z","receivedAt":"2008-07-08T23:20:19Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Robert Shearman <robertshearman@gmail.com> writes:\n\n> Allow SSL to be used when a imaps:// URL is used for the host name.\n>\n> Also, automatically use TLS when not using imaps:// by using the IMAP STARTTLS command, if the server supports it.\n>\n> Tested with Courier and Gimap IMAP servers.\n\nSign-off?\n\n> diff --git a/Documentation/git-imap-send.txt b/Documentation/git-imap-send.txt\n> index b3d8da3..e4a5873 100644\n> --- a/Documentation/git-imap-send.txt\n> +++ b/Documentation/git-imap-send.txt\n> @@ -37,10 +37,11 @@ configuration file (shown with examples):\n>      Tunnel = \"ssh -q user@server.com /usr/bin/imapd ./Maildir 2> /dev/null\"\n>  \n>  [imap]\n> -    Host = imap.server.com\n> +    Host = imaps://imap.example.com\n>      User = bob\n>      Pass = pwd\n> -    Port = 143\n> +    Port = 993\n> +    sslverify = false\n>  ..........................\n\nDon't we also want to keep a vanilla configuration in the example, or is\nimaps the norm and unencrypted imap is exception these days?\n\nDon't we need to support custom certificates, keys and CAs, just like our\ncode that supports https does, by honoring GIT_SSL_* environment variables\nand configuration file entries?  The patch itself looks fairly clean, and\nI'd like to queue this for wider testing, initially even without GIT_SSL_*\nsupport.  But I'd like to see any patch with substantial amount of changes\nproperly signed off.\n\nThanks.\n"},{"id":"82670","messageId":"20080709022839.GA4989@toroid.org","threadId":"14356","inReplyTo":"7vbq18q7yk.fsf@gitster.siamese.dyndns.org","subject":"Re: [PATCH 2/4] git-imap-send: Add support for SSL.","fromName":"Abhijit Menon-Sen","fromEmail":"ams@toroid.org","sentAt":"2008-07-09T02:28:39Z","receivedAt":"2008-07-09T02:28:39Z","isPatch":true,"sender":{"key":"ams@toroid.org","avatar":null},"body":"At 2008-07-08 16:20:19 -0700, gitster@pobox.com wrote:\n>\n> > -    Port = 143\n> > +    Port = 993\n> > +    sslverify = false\n> >  ..........................\n> \n> Don't we also want to keep a vanilla configuration in the example, or\n> is imaps the norm and unencrypted imap is exception these days?\n\nThe norm is IMAP+STARTTLS on port 143, not IMAPS on port 993. The latter\nis also widely deployed for compatibility with older clients, but it is\nnon-standard and its use isn't exactly encouraged.\n\n-- ams\n"},{"id":"82711","messageId":"1096648c0807090502x772fdaa4o59bf9932dc364de5@mail.gmail.com","threadId":"14356","inReplyTo":"7vbq18q7yk.fsf@gitster.siamese.dyndns.org","subject":"Re: [PATCH 2/4] git-imap-send: Add support for SSL.","fromName":"Rob Shearman","fromEmail":"robertshearman@gmail.com","sentAt":"2008-07-09T12:02:18Z","receivedAt":"2008-07-09T12:02:18Z","isPatch":true,"sender":{"key":"robertshearman@gmail.com","avatar":null},"body":"2008/7/9 Junio C Hamano <gitster@pobox.com>:\n> Robert Shearman <robertshearman@gmail.com> writes:\n>> diff --git a/Documentation/git-imap-send.txt b/Documentation/git-imap-send.txt\n>> index b3d8da3..e4a5873 100644\n>> --- a/Documentation/git-imap-send.txt\n>> +++ b/Documentation/git-imap-send.txt\n>> @@ -37,10 +37,11 @@ configuration file (shown with examples):\n>>      Tunnel = \"ssh -q user@server.com /usr/bin/imapd ./Maildir 2> /dev/null\"\n>>\n>>  [imap]\n>> -    Host = imap.server.com\n>> +    Host = imaps://imap.example.com\n>>      User = bob\n>>      Pass = pwd\n>> -    Port = 143\n>> +    Port = 993\n>> +    sslverify = false\n>>  ..........................\n>\n> Don't we also want to keep a vanilla configuration in the example, or is\n> imaps the norm and unencrypted imap is exception these days?\n\nGood point. I'll fix the documentation to use imap:// instead of\nimaps:// and not change the port number. However, I'm not sure the\nexamples should be telling the user what they should do, but rather\nwhat they can do.\n\n> Don't we need to support custom certificates, keys and CAs, just like our\n> code that supports https does, by honoring GIT_SSL_* environment variables\n> and configuration file entries?\n\nYes, eventually we will want that support in imap-send too. It should\nbe fairly trivial to do, although testing will be more difficult.\n\n>  The patch itself looks fairly clean, and\n> I'd like to queue this for wider testing, initially even without GIT_SSL_*\n> support.  But I'd like to see any patch with substantial amount of changes\n> properly signed off.\n\nGreat. I'll resend the series later with changes from the comments\nI've received and properly signed-off.\n\n-- \nRob Shearman\n"},{"id":"82725","messageId":"1215616484.3053.6.camel@josh-work.beaverton.ibm.com","threadId":"14356","inReplyTo":"1215555496-21335-2-git-send-email-robertshearman@gmail.com","subject":"Re: [PATCH 2/4] git-imap-send: Add support for SSL.","fromName":"Josh Triplett","fromEmail":"josht@linux.vnet.ibm.com","sentAt":"2008-07-09T15:14:44Z","receivedAt":"2008-07-09T15:14:44Z","isPatch":true,"sender":{"key":"josht@linux.vnet.ibm.com","avatar":null},"body":"On Tue, 2008-07-08 at 23:18 +0100, Robert Shearman wrote:\n> --- a/Documentation/git-imap-send.txt\n> +++ b/Documentation/git-imap-send.txt\n> @@ -37,10 +37,11 @@ configuration file (shown with examples):\n>      Tunnel = \"ssh -q user@server.com /usr/bin/imapd ./Maildir 2> /dev/null\"\n>  \n>  [imap]\n> -    Host = imap.server.com\n> +    Host = imaps://imap.example.com\n>      User = bob\n>      Pass = pwd\n> -    Port = 143\n> +    Port = 993\n> +    sslverify = false\n[...]\n> @@ -1280,6 +1411,8 @@ git_imap_config(const char *key, const char *val, void *cb)\n>  \t\tserver.port = git_config_int( key, val );\n>  \telse if (!strcmp( \"tunnel\", key ))\n>  \t\tserver.tunnel = xstrdup( val );\n> +\telse if (!strcmp( \"ssl_verify\", key ))\n> +\t\tserver.ssl_verify = git_config_bool( key, val );\n\nThe example and the code disagree on the name of the\nsslverify/ssl_verify option.  Also, ssl_verify needs explanation.\n\n- Josh Triplett\n"},{"id":"82742","messageId":"7vzloqkj38.fsf@gitster.siamese.dyndns.org","threadId":"14356","inReplyTo":"1096648c0807090502x772fdaa4o59bf9932dc364de5@mail.gmail.com","subject":"Re: [PATCH 2/4] git-imap-send: Add support for SSL.","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2008-07-09T18:28:43Z","receivedAt":"2008-07-09T18:28:43Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"\"Rob Shearman\" <robertshearman@gmail.com> writes:\n\n> 2008/7/9 Junio C Hamano <gitster@pobox.com>:\n> ...\n>> Don't we also want to keep a vanilla configuration in the example, or is\n>> imaps the norm and unencrypted imap is exception these days?\n>\n> Good point. I'll fix the documentation to use imap:// instead of\n> imaps:// and not change the port number. However, I'm not sure the\n> examples should be telling the user what they should do, but rather\n> what they can do.\n\nMy comment was purely about losing the basic example by replacing it with\nsomething more advanced.  Nobody prevents you from having _more_ examples.\n\"You can do this, you can do that, also here is an example of how to use\nSSL\".\n"},{"id":"82753","messageId":"1096648c0807091424g1e10d0ccrae0be929ec428b89@mail.gmail.com","threadId":"14356","inReplyTo":"1215616484.3053.6.camel@josh-work.beaverton.ibm.com","subject":"Re: [PATCH 2/4] git-imap-send: Add support for SSL.","fromName":"Rob Shearman","fromEmail":"robertshearman@gmail.com","sentAt":"2008-07-09T21:24:27Z","receivedAt":"2008-07-09T21:24:27Z","isPatch":true,"sender":{"key":"robertshearman@gmail.com","avatar":null},"body":"2008/7/9 Josh Triplett <josht@linux.vnet.ibm.com>:\n> On Tue, 2008-07-08 at 23:18 +0100, Robert Shearman wrote:\n>> --- a/Documentation/git-imap-send.txt\n>> +++ b/Documentation/git-imap-send.txt\n>> @@ -37,10 +37,11 @@ configuration file (shown with examples):\n>>      Tunnel = \"ssh -q user@server.com /usr/bin/imapd ./Maildir 2> /dev/null\"\n>>\n>>  [imap]\n>> -    Host = imap.server.com\n>> +    Host = imaps://imap.example.com\n>>      User = bob\n>>      Pass = pwd\n>> -    Port = 143\n>> +    Port = 993\n>> +    sslverify = false\n> [...]\n>> @@ -1280,6 +1411,8 @@ git_imap_config(const char *key, const char *val, void *cb)\n>>               server.port = git_config_int( key, val );\n>>       else if (!strcmp( \"tunnel\", key ))\n>>               server.tunnel = xstrdup( val );\n>> +     else if (!strcmp( \"ssl_verify\", key ))\n>> +             server.ssl_verify = git_config_bool( key, val );\n>\n> The example and the code disagree on the name of the\n> sslverify/ssl_verify option.\n\nI wouldn't exactly call it \"disagree\". The config variable is limited\nby not allowing underscores, whereas the C language does allow them.\n\n> Also, ssl_verify needs explanation.\n\nSee patch 4/4.\n\n-- \nRob Shearman\n"},{"id":"82785","messageId":"20080710063941.GC3195@sigill.intra.peff.net","threadId":"14356","inReplyTo":"1096648c0807091424g1e10d0ccrae0be929ec428b89@mail.gmail.com","subject":"Re: [PATCH 2/4] git-imap-send: Add support for SSL.","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2008-07-10T06:39:41Z","receivedAt":"2008-07-10T06:39:41Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Wed, Jul 09, 2008 at 10:24:27PM +0100, Rob Shearman wrote:\n\n> >>  [imap]\n> >> +    sslverify = false\n> > [...]\n> >> +     else if (!strcmp( \"ssl_verify\", key ))\n> >\n> > The example and the code disagree on the name of the\n> > sslverify/ssl_verify option.\n> \n> I wouldn't exactly call it \"disagree\". The config variable is limited\n> by not allowing underscores, whereas the C language does allow them.\n\nI think his point is that the example says \"sslverify\" but the code is\nlooking for the config variable \"ssl_verify\". So that config won't work.\n\nHowever as you mention, underscore isn't allowed, so your strcmp line is\ntotally bogus anyway, but you silently fix it in your 3/4 \"style\" fix.\n\n-Peff\n"}]}