{"thread":{"id":"43861","subject":"Credential helpers processing order","startedAt":"2016-08-16T15:14:01Z","lastAt":"2016-08-16T16:12:59Z","messageCount":3,"participants":["Dmitry Neverov","Jacob Keller","Jeff King"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"299463","messageId":"CAC+L6n0j0=6haBprM2ip75=orEi_5oBedHV1iPBTgi-N8Y6=4A@mail.gmail.com","threadId":"43861","inReplyTo":null,"subject":"Credential helpers processing order","fromName":"Dmitry Neverov","fromEmail":"dmitry.neverov@gmail.com","sentAt":"2016-08-16T15:13:55Z","receivedAt":"2016-08-16T15:14:01Z","isPatch":false,"sender":{"key":"dmitry.neverov@gmail.com","avatar":null},"body":"Hi,\n\nI wonder why credential helpers are called in the order: system,\nglobal, local, command-line and not in the reverse order? This make it\nimpossible to provide a custom helper and disable default ones via\ncommand-line parameter. My use-case is to clone a repository in a\nnon-interactive environment where a system-level GUI helper is\nconfigured: clone hangs since system-level helper called first and\nthere is no input from the user. Also if a system-level helper sets\nquit=true, then lower-level helpers won't be called at all. Is it by\ndesign?\n\n--\nDmitry\n"},{"id":"299468","messageId":"CA+P7+xpe2FeBjO0AEHTyuZPEOpCUmt=vUcs5RFYhE9KTZWLNhw@mail.gmail.com","threadId":"43861","inReplyTo":"CAC+L6n0j0=6haBprM2ip75=orEi_5oBedHV1iPBTgi-N8Y6=4A@mail.gmail.com","subject":"Re: Credential helpers processing order","fromName":"Jacob Keller","fromEmail":"jacob.keller@gmail.com","sentAt":"2016-08-16T15:58:11Z","receivedAt":"2016-08-16T15:58:36Z","isPatch":false,"sender":{"key":"jacob.keller@gmail.com","avatar":"https://avatars.githubusercontent.com/u/874719?v=4"},"body":"On Tue, Aug 16, 2016 at 8:13 AM, Dmitry Neverov\n<dmitry.neverov@gmail.com> wrote:\n> Hi,\n>\n> I wonder why credential helpers are called in the order: system,\n> global, local, command-line and not in the reverse order? This make it\n> impossible to provide a custom helper and disable default ones via\n> command-line parameter. My use-case is to clone a repository in a\n> non-interactive environment where a system-level GUI helper is\n> configured: clone hangs since system-level helper called first and\n> there is no input from the user. Also if a system-level helper sets\n> quit=true, then lower-level helpers won't be called at all. Is it by\n> design?\n>\n\nIf I understand correctly, the credential helpers aren't supposed to\nrequire input so it is assumed they can be tried in sequence if one\nfails? It might make sense to reverse the order though...\n\nThanks,\nJake\n\n> --\n> Dmitry\n> --\n> To unsubscribe from this list: send the line \"unsubscribe git\" in\n> the body of a message to majordomo@vger.kernel.org\n> More majordomo info at  http://vger.kernel.org/majordomo-info.html\n"},{"id":"299470","messageId":"20160816161216.xva2f2lp53u57bo4@sigill.intra.peff.net","threadId":"43861","inReplyTo":"CAC+L6n0j0=6haBprM2ip75=orEi_5oBedHV1iPBTgi-N8Y6=4A@mail.gmail.com","subject":"Re: Credential helpers processing order","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2016-08-16T16:12:17Z","receivedAt":"2016-08-16T16:12:59Z","isPatch":false,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Tue, Aug 16, 2016 at 05:13:55PM +0200, Dmitry Neverov wrote:\n\n> I wonder why credential helpers are called in the order: system,\n> global, local, command-line and not in the reverse order? This make it\n> impossible to provide a custom helper and disable default ones via\n> command-line parameter. My use-case is to clone a repository in a\n> non-interactive environment where a system-level GUI helper is\n> configured: clone hangs since system-level helper called first and\n> there is no input from the user. Also if a system-level helper sets\n> quit=true, then lower-level helpers won't be called at all. Is it by\n> design?\n\nI agree that it's not really a sensible order. But reversing them isn't\nquite right either. The problem is that the config code just gives the\ncredential code a sequence of items, with no indication which file they\ncame from, with what priority, etc.\n\nFor config keys with a single value, \"last one wins\" makes sense; we\njust keep overwriting the previous value.\n\nBut for lists (like credential.helper, but also other things like\nremote.*.fetch), we just build up the list. And we can't tell the\ndifference between two items next to each in the same file, or two in\ndifferent files with differing priorities.\n\nFixing that would be tricky. But I think for your case (and most similar\ncases), you'd be happy to just be able to \"reset\" the list to empty. As\nof git v2.9.0, you can do that, like so:\n\n  [credential]\n  helper = \"!echo >&2 should not run;:\"\n  helper =\n  helper = \"!echo >&2 should run;:\"\n\n-Peff\n"}]}