{"thread":{"id":"32806","subject":"[BUG] git-clone fails due to GnuTLS recv error (-9), then deletes entire local repo","startedAt":"2013-02-01T09:00:06Z","lastAt":"2013-04-15T15:58:54Z","messageCount":2,"participants":["TJ","Tay Ray Chuan"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"208457","messageId":"510B8416.7010802@iam.tj","threadId":"32806","inReplyTo":null,"subject":"[BUG] git-clone fails due to GnuTLS recv error (-9), then deletes entire local repo","fromName":"TJ","fromEmail":"git@iam.tj","sentAt":"2013-02-01T09:00:06Z","receivedAt":"2013-02-01T09:00:06Z","isPatch":false,"sender":{"key":"git@iam.tj","avatar":null},"body":"Using Ubuntu Precise 12.04 with git version (1.8.0.3) I discovered a bug whereby git-clone deletes the repository\nit has just created if there is a GnuTLS error after the final transfer.\n\nI switched to building and using the current git head (1.8.1.2.433.g070c57d.dirty) and found the same issue is still present.\n\nThere are two problems here:\n\n1. At the end of the transfer \"GnuTLS recv error (-9): A TLS packet with unexpected length was received\"\n2. git-clone goes on to resolve deltas *then* deletes the entire repository\n\nThis is reported as Ubuntu bug #1111882 at https://bugs.launchpad.net/ubuntu/+bug/1111882\n\nThe following transcript uses git built with one local patch on top of commit 070c57d which fixes the $(INSTALL) file mode\nissue as per my previous list posting \"PATCH 1/1] Introduce new build variables INSTALL_MODE_EXECUTABLE and INSTALL_MODE_DATA\".\n\nGIT_CURL_VERBOSE=1 git clone -v https://git01.codeplex.com/typescript\n\nthe operation fails after the final git pack-file has been received and the already-created repository is deleted from the file system.\n\n...\n> POST /typescript/git-upload-pack HTTP/1.1\nUser-Agent: git/1.8.1.2.433.g9808ce0.dirty\nHost: git01.codeplex.com\nAccept-Encoding: gzip\nContent-Type: application/x-git-upload-pack-request\nAccept: application/x-git-upload-pack-result\nContent-Length: 611\n\n* upload completely sent off: 611out of 611 bytes\n< HTTP/1.1 200 OK\n< Cache-Control: no-cache, max-age=0, must-revalidate\n< Pragma: no-cache\n< Content-Type: application/x-git-upload-pack-result\n< Expires: Fri, 01 Jan 1980 00:00:00 GMT\n< Server: Microsoft-IIS/7.5\n< X-Powered-By: ASP.NET\n< Date: Thu, 31 Jan 2013 21:43:55 GMT\n< Connection: close\n<\nremote: Counting objects: 149766, done.\nremote: Compressing objects: 100% (10580/10580), done.\n* GnuTLS recv error (-9): A TLS packet with unexpected length was received.\n* Closing connection #0\nremote: Total 149766 (delta 138201), reused 149559 (delta 138077)\nReceiving objects: 100% (149766/149766), 198.98 MiB | 361 KiB/s, done.\nerror: RPC failed; result=56, HTTP code = 200\nResolving deltas: 100% (138201/138201), done.\n\n\ngit exits at this point but it deletes the entire cloned ./typescript directory.\n\nSo far as I can tell from watching the ./typescript directory from another terminal and also the ethernet interface activity\nthe transfer is complete but GnuTLS is expecting something more from the HTTPS server which isn't forthcoming, leading to\nthe error.\n\nThe git bug - if this is accepted as a bug - is the deletion of the entire cloned repository.\n\n\nI tried building the git binary and including an additional debug option in \"http.c\" that allowed me to set the protocol version using an environment option:\n\nCURLOPT_SSLVERSION=1 git clone ...\n\nwhere 1 = TLSv1, 2 = SSLv2, 3 = SSLv3.\n\nI tried each protocol but the result was the same.\n\nI did some experimentation using gnutl-cli-debug but was unable to figure out a way to reproduce the SSL/TLS error without\nthis particular git-clone operation. However, that is a GnuTLS bug, not a git bug.\n\nI did try to build the latest gnutls but it needs a very recent version of libnettle which has the \"rsa_decrypt_tr\" function. I stopped at that point since I don't want to get into dependency and\nlibrary version issues.\n\nAdditional research seems to indicate this is a known intentional gnutls behaviour (that has been modified in very recent gnutls that makes use of a very recent libnettle - as mentioned above). The\nissue is, apparently, the random size padding of packets to prevent communications compromise for stream ciphers.\n\nI installed stunnel4 (which depends on openssl rather than gnutls) and created a reverse-proxy (client in stunnel terminology):\n\n$ cat /etc/stunnel/rp-codeplex.com.conf\nclient = yes\n\n[http]\naccept = 8888\nconnect = git01.codeplex.com:443\nTIMEOUTclose = 0\n\n$ sudo sed -i 's/\\(ENABLED\\).*/\\1=1/' /etc/default/stunnel4\n$ sudo service stunnel4 restart\n\n$ GIT_CURL_VERBOSE=1 git clone -v http://localhost:8888/typescript\n\n...\n> POST http://localhost:8888/typescript/git-upload-pack HTTP/1.1\nUser-Agent: git/1.8.1.2.433.g9808ce0.dirty\nHost: localhost:8888\nAccept-Encoding: gzip\nProxy-Connection: Keep-Alive\nContent-Type: application/x-git-upload-pack-request\nAccept: application/x-git-upload-pack-result\nContent-Length: 611\n\n* upload completely sent off: 611out of 611 bytes\n< HTTP/1.1 200 OK\n< Cache-Control: no-cache, max-age=0, must-revalidate\n< Pragma: no-cache\n< Content-Type: application/x-git-upload-pack-result\n< Expires: Fri, 01 Jan 1980 00:00:00 GMT\n< Server: Microsoft-IIS/7.5\n< X-Powered-By: ASP.NET\n< Date: Thu, 31 Jan 2013 23:38:19 GMT\n< Connection: close\n<\nremote: Counting objects: 149798, done.\nremote: Compressing objects: 100% (10612/10612), done.\nremote: Total 149798 (delta 138221), reused 149558 (delta 138077)\n* Closing connection #0\nReceiving objects: 100% (149798/149798), 198.99 MiB | 640 KiB/s, done.\nResolving deltas: 100% (138221/138221), done.\nChecking out files: 100% (2851/2851), done.\n"},{"id":"214314","messageId":"CALUzUxr5i6sRywbKB=eFEcrpHdVtduMQFKaXwMX-WdcWAa6g2A@mail.gmail.com","threadId":"32806","inReplyTo":"510B8416.7010802@iam.tj","subject":"Re: [BUG] git-clone fails due to GnuTLS recv error (-9), then deletes entire local repo","fromName":"Tay Ray Chuan","fromEmail":"rctay89@gmail.com","sentAt":"2013-04-15T15:58:54Z","receivedAt":"2013-04-15T15:58:54Z","isPatch":false,"sender":{"key":"rctay89@gmail.com","avatar":"https://avatars.githubusercontent.com/u/61553?v=4"},"body":"On Fri, Feb 1, 2013 at 5:00 PM, TJ <git@iam.tj> wrote:\n> Using Ubuntu Precise 12.04 with git version (1.8.0.3) I discovered a bug whereby git-clone deletes the repository\n> it has just created if there is a GnuTLS error after the final transfer.\n>\n> I switched to building and using the current git head (1.8.1.2.433.g070c57d.dirty) and found the same issue is still present.\n>\n> There are two problems here:\n>\n> 1. At the end of the transfer \"GnuTLS recv error (-9): A TLS packet with unexpected length was received\"\n> 2. git-clone goes on to resolve deltas *then* deletes the entire repository\n>\n> This is reported as Ubuntu bug #1111882 at https://bugs.launchpad.net/ubuntu/+bug/1111882\n\nI believe this is due to git not supporting resumable clones, and that\nthe repo is in an unusable state.\n\nIt's listed as a 2011 GSoC idea [1] but has since been taken off\nbecause it's considered a \"hard\" problem (can't come with a email\nthread right off the top of my head).\n\n[1] https://git.wiki.kernel.org/index.php/SoC2011Ideas#Resumable_clone\n\n--\nCheers,\nRay Chuan\n"}]}