{"thread":{"id":"45944","subject":"Git credential helper store flushes randomly","startedAt":"2017-05-12T18:44:27Z","lastAt":"2017-05-12T18:46:13Z","messageCount":5,"participants":["Райцин Антон","Jeff King","Matthieu Moy"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"319499","messageId":"cdedf063-5f53-04c9-5ac0-2acf7e26696e@smarthead.ru","threadId":"45944","inReplyTo":null,"subject":"Git credential helper store flushes randomly","fromName":"Райцин Антон","fromEmail":"anton@smarthead.ru","sentAt":"2017-05-12T08:05:19Z","receivedAt":"2017-05-12T18:44:27Z","isPatch":false,"sender":{"key":"anton@smarthead.ru","avatar":null},"body":"Hello.\n\nI have very strange git credentials store behavior on one of my servers.\nI Use Ubuntu 14.04 LTS and git  2.10.2. The server have multiple users \nwith multiple projects, so they have got many different git credentials \nto different repositories.\nI set git config --global credential.helper store, but the credential \nrecord strings from file ~/.git-credentials for one specific user \ndisappears randomly. Especially for one specific repository.\n\nI do not see any TTL for git credentials in credential.helper store on \ngit documentation, so I can't even imagine, what could cause such \nstrange behavior.\n\nIs this a known problem and is there any solution to fix this problem?\n\n\nBest regards,\nAnton.\n"},{"id":"319506","messageId":"20170512084513.duj7sesylo7jdd3w@sigill.intra.peff.net","threadId":"45944","inReplyTo":"vpq1srucwj1.fsf@anie.imag.fr","subject":"Re: Git credential helper store flushes randomly","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2017-05-12T08:45:14Z","receivedAt":"2017-05-12T18:44:44Z","isPatch":false,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Fri, May 12, 2017 at 10:24:50AM +0200, Matthieu Moy wrote:\n\n> Jeff King <peff@peff.net> writes:\n> \n> > The only time it should remove an entry is when Git asks it to. And the\n> > only time that happens is when Git sees the credential rejected by the\n> > server (e.g., an HTTP 401 even after we fed the stored credential). I\n> > don't know why that would happen unless there's some non-determinism on\n> > the server.\n> \n> I did see a case like this where the server was broken temporarily and\n> rejected one login attempt. In this case the credential store deletes\n> the entry for that user, and when the server is repaired, the store\n> still has the entry deleted.\n\nRight, that's inconvenient if your server is flaky, but is the expected\nbehavior. Git has to throw away the credential so it can stop trying it\nand actually prompt you on the next try (and save the result then if it\nworks).\n\n-Peff\n"},{"id":"319531","messageId":"vpq1srucwj1.fsf@anie.imag.fr","threadId":"45944","inReplyTo":"20170512082058.ivvsmzc44cildp7l@sigill.intra.peff.net","subject":"Re: Git credential helper store flushes randomly","fromName":"Matthieu Moy","fromEmail":"matthieu.moy@grenoble-inp.fr","sentAt":"2017-05-12T08:24:50Z","receivedAt":"2017-05-12T18:45:25Z","isPatch":false,"sender":{"key":"matthieu.moy@grenoble-inp.fr","avatar":"https://gravatar.com/avatar/72c8a2705971a25dfaff23cece15130d405685845d911aedd5667ace277f3fc5?d=mp&s=160"},"body":"Jeff King <peff@peff.net> writes:\n\n> The only time it should remove an entry is when Git asks it to. And the\n> only time that happens is when Git sees the credential rejected by the\n> server (e.g., an HTTP 401 even after we fed the stored credential). I\n> don't know why that would happen unless there's some non-determinism on\n> the server.\n\nI did see a case like this where the server was broken temporarily and\nrejected one login attempt. In this case the credential store deletes\nthe entry for that user, and when the server is repaired, the store\nstill has the entry deleted.\n\n-- \nMatthieu Moy\nhttp://www-verimag.imag.fr/~moy/\n"},{"id":"319555","messageId":"55d2b225-1f12-eb26-7333-131538b519fa@smarthead.ru","threadId":"45944","inReplyTo":"20170512084513.duj7sesylo7jdd3w@sigill.intra.peff.net","subject":"Re: Git credential helper store flushes randomly","fromName":"Райцин Антон","fromEmail":"anton@smarthead.ru","sentAt":"2017-05-12T10:05:41Z","receivedAt":"2017-05-12T18:46:12Z","isPatch":false,"sender":{"key":"anton@smarthead.ru","avatar":null},"body":"12.05.2017 11:45, Jeff King пишет:\n> On Fri, May 12, 2017 at 10:24:50AM +0200, Matthieu Moy wrote:\n>\n>> Jeff King <peff@peff.net> writes:\n>>\n>>> The only time it should remove an entry is when Git asks it to. And the\n>>> only time that happens is when Git sees the credential rejected by the\n>>> server (e.g., an HTTP 401 even after we fed the stored credential). I\n>>> don't know why that would happen unless there's some non-determinism on\n>>> the server.\n>> I did see a case like this where the server was broken temporarily and\n>> rejected one login attempt. In this case the credential store deletes\n>> the entry for that user, and when the server is repaired, the store\n>> still has the entry deleted.\n> Right, that's inconvenient if your server is flaky, but is the expected\n> behavior. Git has to throw away the credential so it can stop trying it\n> and actually prompt you on the next try (and save the result then if it\n> works).\n>\n> -Peff\n>\n\nThank you all!\nI've found the reason and successfully fixed the problem. Here is a \ndescription.\n\nMost of repositories of this user were on one server EXAMPLE.COM. Some \norigins were configured like https://USER@EXAMPLE.COM. And they worked \nfine. Git just searched in ~/.git-credentials the \n\"USER:password@EXAMPLE.COM\" entry and everything was good. But some \nrepositories' origins were configured without username, just \nhttps://EXAMPLE.COM. So git tried to find just a EXAMPLE.COM in the \ncredentials store. Then git took the first entry and tried to connect to \nremote origin, got 401 unauthorized error and deleted first entry from \nhelper store. The randomness was manifested due to the fact that git \nrotates the records in .git-credentials every time it connects to remote \norigin, it moves the right account string to the top of the file.\n\nI think it will be good idea to add this information to \nhttps://git-scm.com/docs/git-credential-store, especially the info about \ndeletion behavior, when git gets 401 error.\n\nBest regards,\nAnton.\n"},{"id":"319556","messageId":"20170512082058.ivvsmzc44cildp7l@sigill.intra.peff.net","threadId":"45944","inReplyTo":"cdedf063-5f53-04c9-5ac0-2acf7e26696e@smarthead.ru","subject":"Re: Git credential helper store flushes randomly","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2017-05-12T08:20:58Z","receivedAt":"2017-05-12T18:46:13Z","isPatch":false,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Fri, May 12, 2017 at 11:05:19AM +0300, Райцин Антон wrote:\n\n> I have very strange git credentials store behavior on one of my servers.\n> I Use Ubuntu 14.04 LTS and git  2.10.2. The server have multiple users with\n> multiple projects, so they have got many different git credentials to\n> different repositories.\n> I set git config --global credential.helper store, but the credential record\n> strings from file ~/.git-credentials for one specific user disappears\n> randomly. Especially for one specific repository.\n> \n> I do not see any TTL for git credentials in credential.helper store on git\n> documentation, so I can't even imagine, what could cause such strange\n> behavior.\n> \n> Is this a known problem and is there any solution to fix this problem?\n\nI've never heard of a bug like this, and the credential-store code\nhasn't really changed in the 5+ years since it was introduced.\n\nThe only time it should remove an entry is when Git asks it to. And the\nonly time that happens is when Git sees the credential rejected by the\nserver (e.g., an HTTP 401 even after we fed the stored credential). I\ndon't know why that would happen unless there's some non-determinism on\nthe server.\n\nRunning with GIT_TRACE=/path/to/logfile in the environment would let you\nknow when Git invokes the helper with the \"erase\" argument. But the\ncredential data itself is sent over stdin, so it won't be logged. And if\nthis is something that happens occasionally and randomly, you might have\nto log for quite a while.\n\nLikewise, running with GIT_CURL_VERBOSE=1 might show what's going on,\nbut you'd have to actually catch the offending git command (in more\nrecent versions of curl there is GIT_TRACE_CURL, which you can point at\na specific logfile rather than just stderr). Do note if you try logging\nwith GIT_CURL_VERBOSE that it includes your password in the output, so\ntreat it appropriately.\n\n-Peff\n"}]}