{"thread":{"id":"33181","subject":"[PATCH/RFC] http_init: only initialize SSL for https","startedAt":"2013-03-14T13:51:19Z","lastAt":"2013-03-18T12:14:15Z","messageCount":21,"participants":["Erik Faye-Lund","Johannes Schindelin","Junio C Hamano","Daniel Stenberg","Jeff King","Antoine Pelisse"],"isPatch":true,"patchVersion":1,"patchTotal":null},"messages":[{"id":"211295","messageId":"1363269079-6124-1-git-send-email-kusmabite@gmail.com","threadId":"33181","inReplyTo":null,"subject":"[PATCH/RFC] http_init: only initialize SSL for https","fromName":"Erik Faye-Lund","fromEmail":"kusmabite@gmail.com","sentAt":"2013-03-14T13:51:19Z","receivedAt":"2013-03-14T13:51:19Z","isPatch":true,"sender":{"key":"kusmabite@gmail.com","avatar":"https://avatars.githubusercontent.com/u/47073?v=4"},"body":"Since ancient times, we have been calling curl_global_init with the\nCURL_GLOBAL_ALL-flag, which initializes SSL (and the Win32 socket\nstack on Windows).\n\nInitializing SSL takes quite some time on Windows, so let's avoid\ndoing it when it's not needed.\n\ntiming of echo \"\" | ./git-remote-http.exe origin http://localhost\n\nbefore\n\nbest of 10 runs:\nreal    0m1.634s\nuser    0m0.015s\nsys     0m0.000s\n\nworst of 10 runs:\nreal    0m2.701s\nuser    0m0.000s\nsys     0m0.000s\n\nafter\n\nbest of 10 runs:\nreal    0m0.018s\nuser    0m0.000s\nsys     0m0.000s\n\nworst of 10 runs:\nreal    0m0.024s\nuser    0m0.000s\nsys     0m0.015s\n\nSigned-off-by: Erik Faye-Lund <erik.faye-lund@hue.no>\n---\n http.c | 3 ++-\n 1 file changed, 2 insertions(+), 1 deletion(-)\n\ndiff --git a/http.c b/http.c\nindex 3b312a8..528a736 100644\n--- a/http.c\n+++ b/http.c\n@@ -343,7 +343,8 @@ void http_init(struct remote *remote, const char *url, int proactive_auth)\n \n \tgit_config(http_options, NULL);\n \n-\tcurl_global_init(CURL_GLOBAL_ALL);\n+\tcurl_global_init(CURL_GLOBAL_WIN32 | (prefixcmp(url, \"https:\") ? 0 :\n+\t    CURL_GLOBAL_SSL));\n \n \thttp_proactive_auth = proactive_auth;\n \n-- \n1.8.0.msysgit.0.3.gd0186ec\n\n-- \n-- \n*** Please reply-to-all at all times ***\n*** (do not pretend to know who is subscribed and who is not) ***\n*** Please avoid top-posting. ***\nThe msysGit Wiki is here: https://github.com/msysgit/msysgit/wiki - Github accounts are free.\n\nYou received this message because you are subscribed to the Google\nGroups \"msysGit\" group.\nTo post to this group, send email to msysgit@googlegroups.com\nTo unsubscribe from this group, send email to\nmsysgit+unsubscribe@googlegroups.com\nFor more options, and view previous threads, visit this group at\nhttp://groups.google.com/group/msysgit?hl=en_US?hl=en\n\n--- \nYou received this message because you are subscribed to the Google Groups \"msysGit\" group.\nTo unsubscribe from this group and stop receiving emails from it, send an email to msysgit+unsubscribe@googlegroups.com.\nFor more options, visit https://groups.google.com/groups/opt_out.\n"},{"id":"211296","messageId":"CABPQNSZXAwQp-8M-6WQ_RdZMxwr_pm7EXOvrU3O8J4jaMWoegw@mail.gmail.com","threadId":"33181","inReplyTo":"1363269079-6124-1-git-send-email-kusmabite@gmail.com","subject":"Re: [PATCH/RFC] http_init: only initialize SSL for https","fromName":"Erik Faye-Lund","fromEmail":"kusmabite@gmail.com","sentAt":"2013-03-14T13:56:34Z","receivedAt":"2013-03-14T13:56:34Z","isPatch":true,"sender":{"key":"kusmabite@gmail.com","avatar":"https://avatars.githubusercontent.com/u/47073?v=4"},"body":"On Thu, Mar 14, 2013 at 2:51 PM, Erik Faye-Lund <kusmabite@gmail.com> wrote:\n> Since ancient times, we have been calling curl_global_init with the\n> CURL_GLOBAL_ALL-flag, which initializes SSL (and the Win32 socket\n> stack on Windows).\n>\n> Initializing SSL takes quite some time on Windows, so let's avoid\n> doing it when it's not needed.\n>\n> timing of echo \"\" | ./git-remote-http.exe origin http://localhost\n>\n> before\n>\n> best of 10 runs:\n> real    0m1.634s\n> user    0m0.015s\n> sys     0m0.000s\n>\n> worst of 10 runs:\n> real    0m2.701s\n> user    0m0.000s\n> sys     0m0.000s\n>\n> after\n>\n> best of 10 runs:\n> real    0m0.018s\n> user    0m0.000s\n> sys     0m0.000s\n>\n> worst of 10 runs:\n> real    0m0.024s\n> user    0m0.000s\n> sys     0m0.015s\n>\n> Signed-off-by: Erik Faye-Lund <erik.faye-lund@hue.no>\n\nSorry, that sign-off has my wrong e-mail address. Please replace it with this:\n\nSigned-off-by: Erik Faye-Lund <kusmabite@gmail.com>\n\n-- \n-- \n*** Please reply-to-all at all times ***\n*** (do not pretend to know who is subscribed and who is not) ***\n*** Please avoid top-posting. ***\nThe msysGit Wiki is here: https://github.com/msysgit/msysgit/wiki - Github accounts are free.\n\nYou received this message because you are subscribed to the Google\nGroups \"msysGit\" group.\nTo post to this group, send email to msysgit@googlegroups.com\nTo unsubscribe from this group, send email to\nmsysgit+unsubscribe@googlegroups.com\nFor more options, and view previous threads, visit this group at\nhttp://groups.google.com/group/msysgit?hl=en_US?hl=en\n\n--- \nYou received this message because you are subscribed to the Google Groups \"msysGit\" group.\nTo unsubscribe from this group and stop receiving emails from it, send an email to msysgit+unsubscribe@googlegroups.com.\nFor more options, visit https://groups.google.com/groups/opt_out.\n"},{"id":"211303","messageId":"alpine.DEB.1.00.1303141621340.3794@s15462909.onlinehome-server.info","threadId":"33181","inReplyTo":"1363269079-6124-1-git-send-email-kusmabite@gmail.com","subject":"Re: [PATCH/RFC] http_init: only initialize SSL for https","fromName":"Johannes Schindelin","fromEmail":"johannes.schindelin@gmx.de","sentAt":"2013-03-14T15:23:59Z","receivedAt":"2013-03-14T15:23:59Z","isPatch":true,"sender":{"key":"johannes.schindelin@gmx.de","avatar":"https://avatars.githubusercontent.com/u/127790?v=4"},"body":"Hi kusma,\n\nOn Thu, 14 Mar 2013, Erik Faye-Lund wrote:\n\n> Since ancient times, we have been calling curl_global_init with the\n> CURL_GLOBAL_ALL-flag, which initializes SSL (and the Win32 socket\n> stack on Windows).\n> \n> Initializing SSL takes quite some time on Windows, so let's avoid\n> doing it when it's not needed.\n> \n> timing of echo \"\" | ./git-remote-http.exe origin http://localhost\n> \n> before\n> \n> best of 10 runs:\n> real    0m1.634s\n> user    0m0.015s\n> sys     0m0.000s\n> \n> worst of 10 runs:\n> real    0m2.701s\n> user    0m0.000s\n> sys     0m0.000s\n> \n> after\n> \n> best of 10 runs:\n> real    0m0.018s\n> user    0m0.000s\n> sys     0m0.000s\n> \n> worst of 10 runs:\n> real    0m0.024s\n> user    0m0.000s\n> sys     0m0.015s\n\nGood analysis!\n\n> diff --git a/http.c b/http.c\n> index 3b312a8..528a736 100644\n> --- a/http.c\n> +++ b/http.c\n> @@ -343,7 +343,8 @@ void http_init(struct remote *remote, const char *url, int proactive_auth)\n>  \n>  \tgit_config(http_options, NULL);\n>  \n> -\tcurl_global_init(CURL_GLOBAL_ALL);\n> +\tcurl_global_init(CURL_GLOBAL_WIN32 | (prefixcmp(url, \"https:\") ? 0 :\n> +\t    CURL_GLOBAL_SSL));\n>  \n>  \thttp_proactive_auth = proactive_auth;\n\nI wonder whether we want to have something like this instead:\n\n\tflags = CURL_GLOBAL_ALL;\n\tif (prefixcmp(url, \"https:\"))\n\t\tflags &= ^CURL_GLOBAL_SSL;\n\tcurl_global_init(flags);\n\nI do see that CURL_GLOBAL_ALL is #define'd as CURL_GLOBAL_WIN32 |\nCURL_GLOBAL_SSL in curl.h, but that might change in the future, no?\n\nCiao,\nDscho\n\n-- \n-- \n*** Please reply-to-all at all times ***\n*** (do not pretend to know who is subscribed and who is not) ***\n*** Please avoid top-posting. ***\nThe msysGit Wiki is here: https://github.com/msysgit/msysgit/wiki - Github accounts are free.\n\nYou received this message because you are subscribed to the Google\nGroups \"msysGit\" group.\nTo post to this group, send email to msysgit@googlegroups.com\nTo unsubscribe from this group, send email to\nmsysgit+unsubscribe@googlegroups.com\nFor more options, and view previous threads, visit this group at\nhttp://groups.google.com/group/msysgit?hl=en_US?hl=en\n\n--- \nYou received this message because you are subscribed to the Google Groups \"msysGit\" group.\nTo unsubscribe from this group and stop receiving emails from it, send an email to msysgit+unsubscribe@googlegroups.com.\nFor more options, visit https://groups.google.com/groups/opt_out.\n"},{"id":"211305","messageId":"CABPQNSZNdGea9Nn91emWhfRGAZjZXm755UKArNr3EUy9CrSKHg@mail.gmail.com","threadId":"33181","inReplyTo":"alpine.DEB.1.00.1303141621340.3794@s15462909.onlinehome-server.info","subject":"Re: [PATCH/RFC] http_init: only initialize SSL for https","fromName":"Erik Faye-Lund","fromEmail":"kusmabite@gmail.com","sentAt":"2013-03-14T15:36:26Z","receivedAt":"2013-03-14T15:36:26Z","isPatch":true,"sender":{"key":"kusmabite@gmail.com","avatar":"https://avatars.githubusercontent.com/u/47073?v=4"},"body":"On Thu, Mar 14, 2013 at 4:23 PM, Johannes Schindelin\n<Johannes.Schindelin@gmx.de> wrote:\n> Hi kusma,\n>\n> On Thu, 14 Mar 2013, Erik Faye-Lund wrote:\n>\n>> Since ancient times, we have been calling curl_global_init with the\n>> CURL_GLOBAL_ALL-flag, which initializes SSL (and the Win32 socket\n>> stack on Windows).\n>>\n>> Initializing SSL takes quite some time on Windows, so let's avoid\n>> doing it when it's not needed.\n>>\n>> timing of echo \"\" | ./git-remote-http.exe origin http://localhost\n>>\n>> before\n>>\n>> best of 10 runs:\n>> real    0m1.634s\n>> user    0m0.015s\n>> sys     0m0.000s\n>>\n>> worst of 10 runs:\n>> real    0m2.701s\n>> user    0m0.000s\n>> sys     0m0.000s\n>>\n>> after\n>>\n>> best of 10 runs:\n>> real    0m0.018s\n>> user    0m0.000s\n>> sys     0m0.000s\n>>\n>> worst of 10 runs:\n>> real    0m0.024s\n>> user    0m0.000s\n>> sys     0m0.015s\n>\n> Good analysis!\n>\n>> diff --git a/http.c b/http.c\n>> index 3b312a8..528a736 100644\n>> --- a/http.c\n>> +++ b/http.c\n>> @@ -343,7 +343,8 @@ void http_init(struct remote *remote, const char *url, int proactive_auth)\n>>\n>>       git_config(http_options, NULL);\n>>\n>> -     curl_global_init(CURL_GLOBAL_ALL);\n>> +     curl_global_init(CURL_GLOBAL_WIN32 | (prefixcmp(url, \"https:\") ? 0 :\n>> +         CURL_GLOBAL_SSL));\n>>\n>>       http_proactive_auth = proactive_auth;\n>\n> I wonder whether we want to have something like this instead:\n>\n>         flags = CURL_GLOBAL_ALL;\n>         if (prefixcmp(url, \"https:\"))\n>                 flags &= ^CURL_GLOBAL_SSL;\n>         curl_global_init(flags);\n>\n> I do see that CURL_GLOBAL_ALL is #define'd as CURL_GLOBAL_WIN32 |\n> CURL_GLOBAL_SSL in curl.h, but that might change in the future, no?\n>\n\nGood suggestion. But perhaps we'd want to use CURL_GLOBAL_DEFAULT\ninstead? I'm thinking that this define is probably what they'd include\nany essential flags, but not non-essential flags. CURL_GLOBAL_ALL\nmight be extended to include initialization bits for other transports,\nfor instance... but this feels a bit hand-wavy. Simply masking out the\nCURL_GLOBAL_SSL-flag would probably be the smallest logical change.\n\nI don't have any strong feeling on this, really. I'd like to hear what\nother people think, though.\n\n-- \n-- \n*** Please reply-to-all at all times ***\n*** (do not pretend to know who is subscribed and who is not) ***\n*** Please avoid top-posting. ***\nThe msysGit Wiki is here: https://github.com/msysgit/msysgit/wiki - Github accounts are free.\n\nYou received this message because you are subscribed to the Google\nGroups \"msysGit\" group.\nTo post to this group, send email to msysgit@googlegroups.com\nTo unsubscribe from this group, send email to\nmsysgit+unsubscribe@googlegroups.com\nFor more options, and view previous threads, visit this group at\nhttp://groups.google.com/group/msysgit?hl=en_US?hl=en\n\n--- \nYou received this message because you are subscribed to the Google Groups \"msysGit\" group.\nTo unsubscribe from this group and stop receiving emails from it, send an email to msysgit+unsubscribe@googlegroups.com.\nFor more options, visit https://groups.google.com/groups/opt_out.\n"},{"id":"211309","messageId":"7vy5dqx913.fsf@alter.siamese.dyndns.org","threadId":"33181","inReplyTo":"1363269079-6124-1-git-send-email-kusmabite@gmail.com","subject":"Re: [PATCH/RFC] http_init: only initialize SSL for https","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2013-03-14T16:04:24Z","receivedAt":"2013-03-14T16:04:24Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Erik Faye-Lund <kusmabite@gmail.com> writes:\n\n> diff --git a/http.c b/http.c\n> index 3b312a8..528a736 100644\n> --- a/http.c\n> +++ b/http.c\n> @@ -343,7 +343,8 @@ void http_init(struct remote *remote, const char *url, int proactive_auth)\n>  \n>  \tgit_config(http_options, NULL);\n>  \n> -\tcurl_global_init(CURL_GLOBAL_ALL);\n> +\tcurl_global_init(CURL_GLOBAL_WIN32 | (prefixcmp(url, \"https:\") ? 0 :\n> +\t    CURL_GLOBAL_SSL));\n\nThe first and obvious question is what the symbol with a name\nspecific to one single platform doing in this generic codepath.\nIn order to get convinced that the patch does not regress, one\nsomehow need to know that bits in ALL other than WIN32 and SSL\ndo not matter (or there is no such bit).\n\nI'd understand if it were \"ALL & ~SSL\" though.\n\n-- \n-- \n*** Please reply-to-all at all times ***\n*** (do not pretend to know who is subscribed and who is not) ***\n*** Please avoid top-posting. ***\nThe msysGit Wiki is here: https://github.com/msysgit/msysgit/wiki - Github accounts are free.\n\nYou received this message because you are subscribed to the Google\nGroups \"msysGit\" group.\nTo post to this group, send email to msysgit@googlegroups.com\nTo unsubscribe from this group, send email to\nmsysgit+unsubscribe@googlegroups.com\nFor more options, and view previous threads, visit this group at\nhttp://groups.google.com/group/msysgit?hl=en_US?hl=en\n\n--- \nYou received this message because you are subscribed to the Google Groups \"msysGit\" group.\nTo unsubscribe from this group and stop receiving emails from it, send an email to msysgit+unsubscribe@googlegroups.com.\nFor more options, visit https://groups.google.com/groups/opt_out.\n"},{"id":"211310","messageId":"7vmwu6x72q.fsf@alter.siamese.dyndns.org","threadId":"33181","inReplyTo":"CABPQNSZNdGea9Nn91emWhfRGAZjZXm755UKArNr3EUy9CrSKHg@mail.gmail.com","subject":"Re: [PATCH/RFC] http_init: only initialize SSL for https","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2013-03-14T16:46:37Z","receivedAt":"2013-03-14T16:46:37Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Erik Faye-Lund <kusmabite@gmail.com> writes:\n\n>> I wonder whether we want to have something like this instead:\n>>\n>>         flags = CURL_GLOBAL_ALL;\n>>         if (prefixcmp(url, \"https:\"))\n>>                 flags &= ^CURL_GLOBAL_SSL;\n>>         curl_global_init(flags);\n>>\n>> I do see that CURL_GLOBAL_ALL is #define'd as CURL_GLOBAL_WIN32 |\n>> CURL_GLOBAL_SSL in curl.h, but that might change in the future, no?\n>\n> Good suggestion. But perhaps we'd want to use CURL_GLOBAL_DEFAULT\n> instead?\n\nThat as a follow-up suggestion may be fine but if you go that route,\nyou would need to explicitly flip SSL on when you know it is going\nto an SSL destination.\n\nThe way to determine SSL-ness has to be rock solid and that is much\nmore important than ALL vs DEFAULT.  Is prefixcmp(url, \"https://\")\nthe right way to do so?  Do we use this codepath only for HTTPS, or\ndoes anybody use other protocol cURL supports over SSL with this,\ntoo?\n\n-- \n-- \n*** Please reply-to-all at all times ***\n*** (do not pretend to know who is subscribed and who is not) ***\n*** Please avoid top-posting. ***\nThe msysGit Wiki is here: https://github.com/msysgit/msysgit/wiki - Github accounts are free.\n\nYou received this message because you are subscribed to the Google\nGroups \"msysGit\" group.\nTo post to this group, send email to msysgit@googlegroups.com\nTo unsubscribe from this group, send email to\nmsysgit+unsubscribe@googlegroups.com\nFor more options, and view previous threads, visit this group at\nhttp://groups.google.com/group/msysgit?hl=en_US?hl=en\n\n--- \nYou received this message because you are subscribed to the Google Groups \"msysGit\" group.\nTo unsubscribe from this group and stop receiving emails from it, send an email to msysgit+unsubscribe@googlegroups.com.\nFor more options, visit https://groups.google.com/groups/opt_out.\n"},{"id":"211311","messageId":"alpine.DEB.1.00.1303141756100.3794@s15462909.onlinehome-server.info","threadId":"33181","inReplyTo":"7vy5dqx913.fsf@alter.siamese.dyndns.org","subject":"Re: Re: [PATCH/RFC] http_init: only initialize SSL for https","fromName":"Johannes Schindelin","fromEmail":"johannes.schindelin@gmx.de","sentAt":"2013-03-14T16:57:43Z","receivedAt":"2013-03-14T16:57:43Z","isPatch":true,"sender":{"key":"johannes.schindelin@gmx.de","avatar":"https://avatars.githubusercontent.com/u/127790?v=4"},"body":"Hi Junio,\n\nOn Thu, 14 Mar 2013, Junio C Hamano wrote:\n\n> Erik Faye-Lund <kusmabite@gmail.com> writes:\n> \n> > diff --git a/http.c b/http.c\n> > index 3b312a8..528a736 100644\n> > --- a/http.c\n> > +++ b/http.c\n> > @@ -343,7 +343,8 @@ void http_init(struct remote *remote, const char *url, int proactive_auth)\n> >  \n> >  \tgit_config(http_options, NULL);\n> >  \n> > -\tcurl_global_init(CURL_GLOBAL_ALL);\n> > +\tcurl_global_init(CURL_GLOBAL_WIN32 | (prefixcmp(url, \"https:\") ? 0 :\n> > +\t    CURL_GLOBAL_SSL));\n> \n> The first and obvious question is what the symbol with a name\n> specific to one single platform doing in this generic codepath.\n> In order to get convinced that the patch does not regress, one\n> somehow need to know that bits in ALL other than WIN32 and SSL\n> do not matter (or there is no such bit).\n> \n> I'd understand if it were \"ALL & ~SSL\" though.\n\nHence my earlier suggestion (with the obvious tyop '^' instead of '~').\nYou will also find the information in my mail (unless you plonk my mails)\nthat CURL_GLOBAL_ALL is defined as CURL_GLOBAL_WIN32 | CURL_GLOBAL_SSL,\nand in kusma's response the suggestion to use DEFAULT & ~SSL instead.\n\nCiao,\nJohannes\n\n-- \n-- \n*** Please reply-to-all at all times ***\n*** (do not pretend to know who is subscribed and who is not) ***\n*** Please avoid top-posting. ***\nThe msysGit Wiki is here: https://github.com/msysgit/msysgit/wiki - Github accounts are free.\n\nYou received this message because you are subscribed to the Google\nGroups \"msysGit\" group.\nTo post to this group, send email to msysgit@googlegroups.com\nTo unsubscribe from this group, send email to\nmsysgit+unsubscribe@googlegroups.com\nFor more options, and view previous threads, visit this group at\nhttp://groups.google.com/group/msysgit?hl=en_US?hl=en\n\n--- \nYou received this message because you are subscribed to the Google Groups \"msysGit\" group.\nTo unsubscribe from this group and stop receiving emails from it, send an email to msysgit+unsubscribe@googlegroups.com.\nFor more options, visit https://groups.google.com/groups/opt_out.\n"},{"id":"211313","messageId":"7vip4tyjor.fsf@alter.siamese.dyndns.org","threadId":"33181","inReplyTo":"alpine.DEB.1.00.1303141756100.3794@s15462909.onlinehome-server.info","subject":"Re: [PATCH/RFC] http_init: only initialize SSL for https","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2013-03-14T17:28:52Z","receivedAt":"2013-03-14T17:28:52Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Johannes Schindelin <Johannes.Schindelin@gmx.de> writes:\n\n> Hence my earlier suggestion (with the obvious tyop '^' instead of '~').\n> You will also find the information in my mail (unless you plonk my mails)\n> that ...\n\nOur mails simply crossed.  Comparing the two messages I think we are\nin complete agreement.\n\n-- \n-- \n*** Please reply-to-all at all times ***\n*** (do not pretend to know who is subscribed and who is not) ***\n*** Please avoid top-posting. ***\nThe msysGit Wiki is here: https://github.com/msysgit/msysgit/wiki - Github accounts are free.\n\nYou received this message because you are subscribed to the Google\nGroups \"msysGit\" group.\nTo post to this group, send email to msysgit@googlegroups.com\nTo unsubscribe from this group, send email to\nmsysgit+unsubscribe@googlegroups.com\nFor more options, and view previous threads, visit this group at\nhttp://groups.google.com/group/msysgit?hl=en_US?hl=en\n\n--- \nYou received this message because you are subscribed to the Google Groups \"msysGit\" group.\nTo unsubscribe from this group and stop receiving emails from it, send an email to msysgit+unsubscribe@googlegroups.com.\nFor more options, visit https://groups.google.com/groups/opt_out.\n"},{"id":"211335","messageId":"alpine.DEB.1.00.1303142333170.3794@s15462909.onlinehome-server.info","threadId":"33181","inReplyTo":"7vmwu6x72q.fsf@alter.siamese.dyndns.org","subject":"Re: [PATCH/RFC] http_init: only initialize SSL for https","fromName":"Johannes Schindelin","fromEmail":"johannes.schindelin@gmx.de","sentAt":"2013-03-14T22:35:03Z","receivedAt":"2013-03-14T22:35:03Z","isPatch":true,"sender":{"key":"johannes.schindelin@gmx.de","avatar":"https://avatars.githubusercontent.com/u/127790?v=4"},"body":"Hi Junio,\n\nOn Thu, 14 Mar 2013, Junio C Hamano wrote:\n\n> Erik Faye-Lund <kusmabite@gmail.com> writes:\n> \n> >> I wonder whether we want to have something like this instead:\n> >>\n> >>         flags = CURL_GLOBAL_ALL;\n> >>         if (prefixcmp(url, \"https:\"))\n> >>                 flags &= ^CURL_GLOBAL_SSL;\n> >>         curl_global_init(flags);\n> >>\n> >> I do see that CURL_GLOBAL_ALL is #define'd as CURL_GLOBAL_WIN32 |\n> >> CURL_GLOBAL_SSL in curl.h, but that might change in the future, no?\n> >\n> > Good suggestion. But perhaps we'd want to use CURL_GLOBAL_DEFAULT\n> > instead?\n> \n> That as a follow-up suggestion may be fine but if you go that route,\n> you would need to explicitly flip SSL on when you know it is going\n> to an SSL destination.\n> \n> The way to determine SSL-ness has to be rock solid and that is much\n> more important than ALL vs DEFAULT.  Is prefixcmp(url, \"https://\")\n> the right way to do so?  Do we use this codepath only for HTTPS, or\n> does anybody use other protocol cURL supports over SSL with this,\n> too?\n\nApparently, ftps is also handled by cURL and most likely requires SSL.\n\nHow about optimizing for the common case and instead of prefixcmp(url,\n\"https:\")) ask for !prefixcmp(url, \"http:\")?\n\nCiao,\nDscho\n\n-- \n-- \n*** Please reply-to-all at all times ***\n*** (do not pretend to know who is subscribed and who is not) ***\n*** Please avoid top-posting. ***\nThe msysGit Wiki is here: https://github.com/msysgit/msysgit/wiki - Github accounts are free.\n\nYou received this message because you are subscribed to the Google\nGroups \"msysGit\" group.\nTo post to this group, send email to msysgit@googlegroups.com\nTo unsubscribe from this group, send email to\nmsysgit+unsubscribe@googlegroups.com\nFor more options, and view previous threads, visit this group at\nhttp://groups.google.com/group/msysgit?hl=en_US?hl=en\n\n--- \nYou received this message because you are subscribed to the Google Groups \"msysGit\" group.\nTo unsubscribe from this group and stop receiving emails from it, send an email to msysgit+unsubscribe@googlegroups.com.\nFor more options, visit https://groups.google.com/groups/opt_out.\n"},{"id":"211336","messageId":"7vk3p9wqh5.fsf@alter.siamese.dyndns.org","threadId":"33181","inReplyTo":"alpine.DEB.1.00.1303142333170.3794@s15462909.onlinehome-server.info","subject":"Re: [PATCH/RFC] http_init: only initialize SSL for https","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2013-03-14T22:45:10Z","receivedAt":"2013-03-14T22:45:10Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Johannes Schindelin <Johannes.Schindelin@gmx.de> writes:\n\n> Apparently, ftps is also handled by cURL and most likely requires SSL.\n>\n> How about optimizing for the common case and instead of prefixcmp(url,\n> \"https:\")) ask for !prefixcmp(url, \"http:\")?\n\nI think that is a very sensible way to go.\n\nAs to ALL vs DEFAULT, given that its manual page is riddled with a\nscary warning:\n\n    This function must be called at least once within a program (a\n    program is all the code that shares a memory space) before the\n    program calls any other function in libcurl. The environment it sets\n    up is constant for the life of the program and is the same for every\n    program, so multiple calls have the same effect as one call.  ... In\n    normal operation, you must specify CURL_GLOBAL_ALL. Don't use any\n    other value unless you are familiar with it and mean to control\n    internal operations of libcurl.\n\nI think we should stick to ALL.  So\n\n\tflags = CURL_GLOBAL_ALL;\n\tif (!prefixcmp(url, \"http:\"))\n\t\tflags &= ~CURL_GLOBAL_SSL;\n\nwould be the way to go.\n\nBut this is assuming that nobody feeds our client a http:// URL to\nthe server that redirects us to the https:// version (or we do not\nfollow such a redirect).  I offhand do not know if that is a valid\nassumption, though.\n\n-- \n-- \n*** Please reply-to-all at all times ***\n*** (do not pretend to know who is subscribed and who is not) ***\n*** Please avoid top-posting. ***\nThe msysGit Wiki is here: https://github.com/msysgit/msysgit/wiki - Github accounts are free.\n\nYou received this message because you are subscribed to the Google\nGroups \"msysGit\" group.\nTo post to this group, send email to msysgit@googlegroups.com\nTo unsubscribe from this group, send email to\nmsysgit+unsubscribe@googlegroups.com\nFor more options, and view previous threads, visit this group at\nhttp://groups.google.com/group/msysgit?hl=en_US?hl=en\n\n--- \nYou received this message because you are subscribed to the Google Groups \"msysGit\" group.\nTo unsubscribe from this group and stop receiving emails from it, send an email to msysgit+unsubscribe@googlegroups.com.\nFor more options, visit https://groups.google.com/groups/opt_out.\n"},{"id":"211338","messageId":"CABPQNSZO8q0LQJKj+xVcU=g3z-nSaGYGokN8tzrLfSfS4ypHCg@mail.gmail.com","threadId":"33181","inReplyTo":"7vk3p9wqh5.fsf@alter.siamese.dyndns.org","subject":"Re: [PATCH/RFC] http_init: only initialize SSL for https","fromName":"Erik Faye-Lund","fromEmail":"kusmabite@gmail.com","sentAt":"2013-03-14T23:00:58Z","receivedAt":"2013-03-14T23:00:58Z","isPatch":true,"sender":{"key":"kusmabite@gmail.com","avatar":"https://avatars.githubusercontent.com/u/47073?v=4"},"body":"On Thu, Mar 14, 2013 at 11:45 PM, Junio C Hamano <gitster@pobox.com> wrote:\n> Johannes Schindelin <Johannes.Schindelin@gmx.de> writes:\n>\n>> Apparently, ftps is also handled by cURL and most likely requires SSL.\n>>\n>> How about optimizing for the common case and instead of prefixcmp(url,\n>> \"https:\")) ask for !prefixcmp(url, \"http:\")?\n>\n> I think that is a very sensible way to go.\n>\n> As to ALL vs DEFAULT, given that its manual page is riddled with a\n> scary warning:\n>\n>     This function must be called at least once within a program (a\n>     program is all the code that shares a memory space) before the\n>     program calls any other function in libcurl. The environment it sets\n>     up is constant for the life of the program and is the same for every\n>     program, so multiple calls have the same effect as one call.  ... In\n>     normal operation, you must specify CURL_GLOBAL_ALL. Don't use any\n>     other value unless you are familiar with it and mean to control\n>     internal operations of libcurl.\n>\n> I think we should stick to ALL.  So\n>\n>         flags = CURL_GLOBAL_ALL;\n>         if (!prefixcmp(url, \"http:\"))\n>                 flags &= ~CURL_GLOBAL_SSL;\n>\n> would be the way to go.\n>\n> But this is assuming that nobody feeds our client a http:// URL to\n> the server that redirects us to the https:// version (or we do not\n> follow such a redirect).  I offhand do not know if that is a valid\n> assumption, though.\n>\n\nThanks, both. Very sensible points. I'll re-roll a new version\ntomorrow, but it could indeed be that the redirect-case can make this\na no-go.\n\n-- \n-- \n*** Please reply-to-all at all times ***\n*** (do not pretend to know who is subscribed and who is not) ***\n*** Please avoid top-posting. ***\nThe msysGit Wiki is here: https://github.com/msysgit/msysgit/wiki - Github accounts are free.\n\nYou received this message because you are subscribed to the Google\nGroups \"msysGit\" group.\nTo post to this group, send email to msysgit@googlegroups.com\nTo unsubscribe from this group, send email to\nmsysgit+unsubscribe@googlegroups.com\nFor more options, and view previous threads, visit this group at\nhttp://groups.google.com/group/msysgit?hl=en_US?hl=en\n\n--- \nYou received this message because you are subscribed to the Google Groups \"msysGit\" group.\nTo unsubscribe from this group and stop receiving emails from it, send an email to msysgit+unsubscribe@googlegroups.com.\nFor more options, visit https://groups.google.com/groups/opt_out.\n"},{"id":"211391","messageId":"alpine.DEB.2.00.1303151054130.32216@tvnag.unkk.fr","threadId":"33181","inReplyTo":"7vk3p9wqh5.fsf@alter.siamese.dyndns.org","subject":"Re: [PATCH/RFC] http_init: only initialize SSL for https","fromName":"Daniel Stenberg","fromEmail":"daniel@haxx.se","sentAt":"2013-03-15T10:08:17Z","receivedAt":"2013-03-15T10:08:17Z","isPatch":true,"sender":{"key":"daniel@haxx.se","avatar":"https://gravatar.com/avatar/69fdca87edd17cee21ca2e79fc2ff671d644603c3dc27167430f3cd3dbab7ba8?d=mp&s=160"},"body":"On Thu, 14 Mar 2013, Junio C Hamano wrote:\n\n> As to ALL vs DEFAULT, given that its manual page is riddled with a scary \n> warning:\n>\n>    This function must be called at least once within a program (a\n>    program is all the code that shares a memory space) before the\n>    program calls any other function in libcurl. The environment it sets\n>    up is constant for the life of the program and is the same for every\n>    program, so multiple calls have the same effect as one call.  ... In\n>    normal operation, you must specify CURL_GLOBAL_ALL. Don't use any\n>    other value unless you are familiar with it and mean to control\n>    internal operations of libcurl.\n\n(speaking from a libcurl perspective)\n\nThe \"warning\" is just there to scare people into actually consider what they \nwant and understand that removing bits will change behavior. I would say \nthat's exactly what you've done and I don't think people here need to be \nscared anymore! :-)\n\nAs for how ALL vs DEFAULT will act or differ in the future, I suspect that we \nwill end up having them being the same (even when we add bits) as we've \nencouraged \"ALL\" in the documentation like this for quite some time.\n\n-- \n\n  / daniel.haxx.se\n\n-- \n-- \n*** Please reply-to-all at all times ***\n*** (do not pretend to know who is subscribed and who is not) ***\n*** Please avoid top-posting. ***\nThe msysGit Wiki is here: https://github.com/msysgit/msysgit/wiki - Github accounts are free.\n\nYou received this message because you are subscribed to the Google\nGroups \"msysGit\" group.\nTo post to this group, send email to msysgit@googlegroups.com\nTo unsubscribe from this group, send email to\nmsysgit+unsubscribe@googlegroups.com\nFor more options, and view previous threads, visit this group at\nhttp://groups.google.com/group/msysgit?hl=en_US?hl=en\n\n--- \nYou received this message because you are subscribed to the Google Groups \"msysGit\" group.\nTo unsubscribe from this group and stop receiving emails from it, send an email to msysgit+unsubscribe@googlegroups.com.\nFor more options, visit https://groups.google.com/groups/opt_out.\n"},{"id":"211403","messageId":"7v4ngcwt4w.fsf@alter.siamese.dyndns.org","threadId":"33181","inReplyTo":"alpine.DEB.2.00.1303151054130.32216@tvnag.unkk.fr","subject":"Re: [PATCH/RFC] http_init: only initialize SSL for https","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2013-03-15T15:59:59Z","receivedAt":"2013-03-15T15:59:59Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Daniel Stenberg <daniel@haxx.se> writes:\n\n> (speaking from a libcurl perspective)\n>\n> As for how ALL vs DEFAULT will act or differ in the future, I suspect\n> that we will end up having them being the same (even when we add bits)\n> as we've encouraged \"ALL\" in the documentation like this for quite\n> some time.\n\nThanks, then we should stick to starting from ALL like everybody\nelse who followed the suggestion in the documentation.  Do you have\nrecommendations on the conditional dropping of SSL?\n"},{"id":"211404","messageId":"alpine.DEB.2.00.1303151719170.32216@tvnag.unkk.fr","threadId":"33181","inReplyTo":"7v4ngcwt4w.fsf@alter.siamese.dyndns.org","subject":"Re: [PATCH/RFC] http_init: only initialize SSL for https","fromName":"Daniel Stenberg","fromEmail":"daniel@haxx.se","sentAt":"2013-03-15T16:23:27Z","receivedAt":"2013-03-15T16:23:27Z","isPatch":true,"sender":{"key":"daniel@haxx.se","avatar":"https://gravatar.com/avatar/69fdca87edd17cee21ca2e79fc2ff671d644603c3dc27167430f3cd3dbab7ba8?d=mp&s=160"},"body":"On Fri, 15 Mar 2013, Junio C Hamano wrote:\n\n>> As for how ALL vs DEFAULT will act or differ in the future, I suspect that \n>> we will end up having them being the same (even when we add bits) as we've \n>> encouraged \"ALL\" in the documentation like this for quite some time.\n>\n> Thanks, then we should stick to starting from ALL like everybody else who \n> followed the suggestion in the documentation.  Do you have recommendations \n> on the conditional dropping of SSL?\n\nNot really, no.\n\nSSL initing is as has been mentioned alredy only relevant with libcurl if an \nSSL powered protocol is gonna be used, so if checking the URL for the protocol \nis enough to figure this out then sure that should work fine.\n\n-- \n\n  / daniel.haxx.se\n\n-- \n-- \n*** Please reply-to-all at all times ***\n*** (do not pretend to know who is subscribed and who is not) ***\n*** Please avoid top-posting. ***\nThe msysGit Wiki is here: https://github.com/msysgit/msysgit/wiki - Github accounts are free.\n\nYou received this message because you are subscribed to the Google\nGroups \"msysGit\" group.\nTo post to this group, send email to msysgit@googlegroups.com\nTo unsubscribe from this group, send email to\nmsysgit+unsubscribe@googlegroups.com\nFor more options, and view previous threads, visit this group at\nhttp://groups.google.com/group/msysgit?hl=en_US?hl=en\n\n--- \nYou received this message because you are subscribed to the Google Groups \"msysGit\" group.\nTo unsubscribe from this group and stop receiving emails from it, send an email to msysgit+unsubscribe@googlegroups.com.\nFor more options, visit https://groups.google.com/groups/opt_out.\n"},{"id":"211454","messageId":"20130316120300.GA2626@sigill.intra.peff.net","threadId":"33181","inReplyTo":"alpine.DEB.2.00.1303151719170.32216@tvnag.unkk.fr","subject":"Re: [PATCH/RFC] http_init: only initialize SSL for https","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2013-03-16T12:03:00Z","receivedAt":"2013-03-16T12:03:00Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Fri, Mar 15, 2013 at 05:23:27PM +0100, Daniel Stenberg wrote:\n\n> >Thanks, then we should stick to starting from ALL like everybody\n> >else who followed the suggestion in the documentation.  Do you have\n> >recommendations on the conditional dropping of SSL?\n> \n> Not really, no.\n> \n> SSL initing is as has been mentioned alredy only relevant with\n> libcurl if an SSL powered protocol is gonna be used, so if checking\n> the URL for the protocol is enough to figure this out then sure that\n> should work fine.\n\nBut are we correct in assuming that curl will barf if it gets a redirect\nto an ssl-enabled protocol? My testing seems to say yes:\n\n  [in one terminal]\n  $ nc -lCp 5001 <<\\EOF\n  HTTP/1.1 301\n  Location: https://github.com/peff/git.git\n\n  EOF\n\n  [in another, git compiled with Erik's patch]\n  $ git ls-remote http://localhost:5001\n  error: SSL: couldn't create a context: error:140A90A1:lib(20):func(169):reason(161) while accessing http://localhost:5001/info/refs?service=git-upload-pack\n  fatal: HTTP request failed\n\n-Peff\n\n-- \n-- \n*** Please reply-to-all at all times ***\n*** (do not pretend to know who is subscribed and who is not) ***\n*** Please avoid top-posting. ***\nThe msysGit Wiki is here: https://github.com/msysgit/msysgit/wiki - Github accounts are free.\n\nYou received this message because you are subscribed to the Google\nGroups \"msysGit\" group.\nTo post to this group, send email to msysgit@googlegroups.com\nTo unsubscribe from this group, send email to\nmsysgit+unsubscribe@googlegroups.com\nFor more options, and view previous threads, visit this group at\nhttp://groups.google.com/group/msysgit?hl=en_US?hl=en\n\n--- \nYou received this message because you are subscribed to the Google Groups \"msysGit\" group.\nTo unsubscribe from this group and stop receiving emails from it, send an email to msysgit+unsubscribe@googlegroups.com.\nFor more options, visit https://groups.google.com/groups/opt_out.\n"},{"id":"211474","messageId":"alpine.DEB.2.00.1303162355120.21738@tvnag.unkk.fr","threadId":"33181","inReplyTo":"20130316120300.GA2626@sigill.intra.peff.net","subject":"Re: [PATCH/RFC] http_init: only initialize SSL for https","fromName":"Daniel Stenberg","fromEmail":"daniel@haxx.se","sentAt":"2013-03-16T22:58:55Z","receivedAt":"2013-03-16T22:58:55Z","isPatch":true,"sender":{"key":"daniel@haxx.se","avatar":"https://gravatar.com/avatar/69fdca87edd17cee21ca2e79fc2ff671d644603c3dc27167430f3cd3dbab7ba8?d=mp&s=160"},"body":"On Sat, 16 Mar 2013, Jeff King wrote:\n\n> But are we correct in assuming that curl will barf if it gets a redirect to \n> an ssl-enabled protocol? My testing seems to say yes:\n\nAh yes. If it switches over to an SSL-based protocol it will pretty much \nrequire that it had been initialized previously.\n\nWith redirects taken into account, I can't think of any really good way around \navoiding this init...\n\n-- \n\n  / daniel.haxx.se\n\n-- \n-- \n*** Please reply-to-all at all times ***\n*** (do not pretend to know who is subscribed and who is not) ***\n*** Please avoid top-posting. ***\nThe msysGit Wiki is here: https://github.com/msysgit/msysgit/wiki - Github accounts are free.\n\nYou received this message because you are subscribed to the Google\nGroups \"msysGit\" group.\nTo post to this group, send email to msysgit@googlegroups.com\nTo unsubscribe from this group, send email to\nmsysgit+unsubscribe@googlegroups.com\nFor more options, and view previous threads, visit this group at\nhttp://groups.google.com/group/msysgit?hl=en_US?hl=en\n\n--- \nYou received this message because you are subscribed to the Google Groups \"msysGit\" group.\nTo unsubscribe from this group and stop receiving emails from it, send an email to msysgit+unsubscribe@googlegroups.com.\nFor more options, visit https://groups.google.com/groups/opt_out.\n"},{"id":"211522","messageId":"CALWbr2wQNM=7vUcoragNmKGpSeXkOCsmsM5y1AMhj95i15A4bw@mail.gmail.com","threadId":"33181","inReplyTo":"alpine.DEB.2.00.1303162355120.21738@tvnag.unkk.fr","subject":"Re: [PATCH/RFC] http_init: only initialize SSL for https","fromName":"Antoine Pelisse","fromEmail":"apelisse@gmail.com","sentAt":"2013-03-17T17:41:23Z","receivedAt":"2013-03-17T17:41:23Z","isPatch":true,"sender":{"key":"apelisse@gmail.com","avatar":"https://avatars.githubusercontent.com/u/1929644?v=4"},"body":"> With redirects taken into account, I can't think of any really good way\n> around avoiding this init...\n\nIs there any way for curl to initialize SSL on-demand ?\n"},{"id":"211532","messageId":"alpine.DEB.2.00.1303172305230.21738@tvnag.unkk.fr","threadId":"33181","inReplyTo":"CALWbr2wQNM=7vUcoragNmKGpSeXkOCsmsM5y1AMhj95i15A4bw@mail.gmail.com","subject":"Re: [PATCH/RFC] http_init: only initialize SSL for https","fromName":"Daniel Stenberg","fromEmail":"daniel@haxx.se","sentAt":"2013-03-17T22:11:28Z","receivedAt":"2013-03-17T22:11:28Z","isPatch":true,"sender":{"key":"daniel@haxx.se","avatar":"https://gravatar.com/avatar/69fdca87edd17cee21ca2e79fc2ff671d644603c3dc27167430f3cd3dbab7ba8?d=mp&s=160"},"body":"On Sun, 17 Mar 2013, Antoine Pelisse wrote:\n\n>> With redirects taken into account, I can't think of any really good way\n>> around avoiding this init...\n>\n> Is there any way for curl to initialize SSL on-demand ?\n\nYes, but not without drawbacks.\n\nIf you don't call curl_global_init() at all, libcurl will notice that on first \nuse and then libcurl will call global_init by itself with a default bitmask.\n\nThat automatic call of course will prevent the application from being able to \nset its own bitmask choice, and also the global_init function is not \n(necessarily) thread safe while all other libcurl functions are so the \ninternal call to global_init from an otherwise thread-safe function is \nunfortunate.\n\n-- \n\n  / daniel.haxx.se\n\n-- \n-- \n*** Please reply-to-all at all times ***\n*** (do not pretend to know who is subscribed and who is not) ***\n*** Please avoid top-posting. ***\nThe msysGit Wiki is here: https://github.com/msysgit/msysgit/wiki - Github accounts are free.\n\nYou received this message because you are subscribed to the Google\nGroups \"msysGit\" group.\nTo post to this group, send email to msysgit@googlegroups.com\nTo unsubscribe from this group, send email to\nmsysgit+unsubscribe@googlegroups.com\nFor more options, and view previous threads, visit this group at\nhttp://groups.google.com/group/msysgit?hl=en_US?hl=en\n\n--- \nYou received this message because you are subscribed to the Google Groups \"msysGit\" group.\nTo unsubscribe from this group and stop receiving emails from it, send an email to msysgit+unsubscribe@googlegroups.com.\nFor more options, visit https://groups.google.com/groups/opt_out.\n"},{"id":"211535","messageId":"7vli9lpsqe.fsf@alter.siamese.dyndns.org","threadId":"33181","inReplyTo":"alpine.DEB.2.00.1303172305230.21738@tvnag.unkk.fr","subject":"Re: [PATCH/RFC] http_init: only initialize SSL for https","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2013-03-17T22:27:21Z","receivedAt":"2013-03-17T22:27:21Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Daniel Stenberg <daniel@haxx.se> writes:\n\n> On Sun, 17 Mar 2013, Antoine Pelisse wrote:\n>\n>>> With redirects taken into account, I can't think of any really good way\n>>> around avoiding this init...\n>>\n>> Is there any way for curl to initialize SSL on-demand ?\n>\n> Yes, but not without drawbacks.\n>\n> If you don't call curl_global_init() at all, libcurl will notice that\n> on first use and then libcurl will call global_init by itself with a\n> default bitmask.\n>\n> That automatic call of course will prevent the application from being\n> able to set its own bitmask choice, and also the global_init function\n> is not (necessarily) thread safe while all other libcurl functions are\n> so the internal call to global_init from an otherwise thread-safe\n> function is unfortunate.\n\nSo in short, unless you are writing a custom application to talk to\nservers that you know will never redirect you to HTTPS, passing\ncustom masks such as ALL&~SSL to global-init is not going to be a\nvalid optimization.\n\nI think that is a reasonable API; your custom application may want\nto go around your intranet servers all of which serve their status\nover plain HTTP, and it is a valid optimization to initialize the\nlibrary with ALL&~SSL.  It is just that such an optimization does\nnot apply to us---we let our users go to random hosts we have no\ncontrol over, and they may redirect us in ways we cannot anticipate.\n\n-- \n-- \n*** Please reply-to-all at all times ***\n*** (do not pretend to know who is subscribed and who is not) ***\n*** Please avoid top-posting. ***\nThe msysGit Wiki is here: https://github.com/msysgit/msysgit/wiki - Github accounts are free.\n\nYou received this message because you are subscribed to the Google\nGroups \"msysGit\" group.\nTo post to this group, send email to msysgit@googlegroups.com\nTo unsubscribe from this group, send email to\nmsysgit+unsubscribe@googlegroups.com\nFor more options, and view previous threads, visit this group at\nhttp://groups.google.com/group/msysgit?hl=en_US?hl=en\n\n--- \nYou received this message because you are subscribed to the Google Groups \"msysGit\" group.\nTo unsubscribe from this group and stop receiving emails from it, send an email to msysgit+unsubscribe@googlegroups.com.\nFor more options, visit https://groups.google.com/groups/opt_out.\n"},{"id":"211556","messageId":"CABPQNSasFV-vZSMygu16xc-C2d3jTt7mtzFsYQyNUhS5jL-EoQ@mail.gmail.com","threadId":"33181","inReplyTo":"7vli9lpsqe.fsf@alter.siamese.dyndns.org","subject":"Re: [PATCH/RFC] http_init: only initialize SSL for https","fromName":"Erik Faye-Lund","fromEmail":"kusmabite@gmail.com","sentAt":"2013-03-18T10:38:48Z","receivedAt":"2013-03-18T10:38:48Z","isPatch":true,"sender":{"key":"kusmabite@gmail.com","avatar":"https://avatars.githubusercontent.com/u/47073?v=4"},"body":"On Sun, Mar 17, 2013 at 11:27 PM, Junio C Hamano <gitster@pobox.com> wrote:\n> Daniel Stenberg <daniel@haxx.se> writes:\n>\n>> On Sun, 17 Mar 2013, Antoine Pelisse wrote:\n>>\n>>>> With redirects taken into account, I can't think of any really good way\n>>>> around avoiding this init...\n>>>\n>>> Is there any way for curl to initialize SSL on-demand ?\n>>\n>> Yes, but not without drawbacks.\n>>\n>> If you don't call curl_global_init() at all, libcurl will notice that\n>> on first use and then libcurl will call global_init by itself with a\n>> default bitmask.\n>>\n>> That automatic call of course will prevent the application from being\n>> able to set its own bitmask choice, and also the global_init function\n>> is not (necessarily) thread safe while all other libcurl functions are\n>> so the internal call to global_init from an otherwise thread-safe\n>> function is unfortunate.\n>\n> So in short, unless you are writing a custom application to talk to\n> servers that you know will never redirect you to HTTPS, passing\n> custom masks such as ALL&~SSL to global-init is not going to be a\n> valid optimization.\n>\n> I think that is a reasonable API; your custom application may want\n> to go around your intranet servers all of which serve their status\n> over plain HTTP, and it is a valid optimization to initialize the\n> library with ALL&~SSL.  It is just that such an optimization does\n> not apply to us---we let our users go to random hosts we have no\n> control over, and they may redirect us in ways we cannot anticipate.\n>\n\nI wonder. Our libcurl is build with \"-winssl\" (USE_WINDOWS_SSPI=1), it\nseems. Perhaps switching to openssl (which we already have libraries\nfor) would make the init-time better?\n\n-- \n-- \n*** Please reply-to-all at all times ***\n*** (do not pretend to know who is subscribed and who is not) ***\n*** Please avoid top-posting. ***\nThe msysGit Wiki is here: https://github.com/msysgit/msysgit/wiki - Github accounts are free.\n\nYou received this message because you are subscribed to the Google\nGroups \"msysGit\" group.\nTo post to this group, send email to msysgit@googlegroups.com\nTo unsubscribe from this group, send email to\nmsysgit+unsubscribe@googlegroups.com\nFor more options, and view previous threads, visit this group at\nhttp://groups.google.com/group/msysgit?hl=en_US?hl=en\n\n--- \nYou received this message because you are subscribed to the Google Groups \"msysGit\" group.\nTo unsubscribe from this group and stop receiving emails from it, send an email to msysgit+unsubscribe@googlegroups.com.\nFor more options, visit https://groups.google.com/groups/opt_out.\n"},{"id":"211560","messageId":"CABPQNSZVptZ9RMQSe8ypgcBH1hmQ6Edg-27JT7-qp4H-46UfQA@mail.gmail.com","threadId":"33181","inReplyTo":"CABPQNSasFV-vZSMygu16xc-C2d3jTt7mtzFsYQyNUhS5jL-EoQ@mail.gmail.com","subject":"Re: [PATCH/RFC] http_init: only initialize SSL for https","fromName":"Erik Faye-Lund","fromEmail":"kusmabite@gmail.com","sentAt":"2013-03-18T12:14:15Z","receivedAt":"2013-03-18T12:14:15Z","isPatch":true,"sender":{"key":"kusmabite@gmail.com","avatar":"https://avatars.githubusercontent.com/u/47073?v=4"},"body":"On Mon, Mar 18, 2013 at 11:38 AM, Erik Faye-Lund <kusmabite@gmail.com> wrote:\n> On Sun, Mar 17, 2013 at 11:27 PM, Junio C Hamano <gitster@pobox.com> wrote:\n>> Daniel Stenberg <daniel@haxx.se> writes:\n>>\n>>> On Sun, 17 Mar 2013, Antoine Pelisse wrote:\n>>>\n>>>>> With redirects taken into account, I can't think of any really good way\n>>>>> around avoiding this init...\n>>>>\n>>>> Is there any way for curl to initialize SSL on-demand ?\n>>>\n>>> Yes, but not without drawbacks.\n>>>\n>>> If you don't call curl_global_init() at all, libcurl will notice that\n>>> on first use and then libcurl will call global_init by itself with a\n>>> default bitmask.\n>>>\n>>> That automatic call of course will prevent the application from being\n>>> able to set its own bitmask choice, and also the global_init function\n>>> is not (necessarily) thread safe while all other libcurl functions are\n>>> so the internal call to global_init from an otherwise thread-safe\n>>> function is unfortunate.\n>>\n>> So in short, unless you are writing a custom application to talk to\n>> servers that you know will never redirect you to HTTPS, passing\n>> custom masks such as ALL&~SSL to global-init is not going to be a\n>> valid optimization.\n>>\n>> I think that is a reasonable API; your custom application may want\n>> to go around your intranet servers all of which serve their status\n>> over plain HTTP, and it is a valid optimization to initialize the\n>> library with ALL&~SSL.  It is just that such an optimization does\n>> not apply to us---we let our users go to random hosts we have no\n>> control over, and they may redirect us in ways we cannot anticipate.\n>>\n>\n> I wonder. Our libcurl is build with \"-winssl\" (USE_WINDOWS_SSPI=1), it\n> seems. Perhaps switching to openssl (which we already have libraries\n> for) would make the init-time better?\n\nIt does indeed. So this is probably a better solution, and is\nsomething we're considering doing in Git for Windows anyway (for a\ndifferent reason). Thanks for all the feed-back!\n"}]}