{"thread":{"id":"46547","subject":"[PATCH 0/4] dropping support for older curl","startedAt":"2017-08-09T12:00:32Z","lastAt":"2021-09-13T17:41:25Z","messageCount":162,"participants":["Jeff King","Ævar Arnfjörð Bjarmason","Stefan Beller","Junio C Hamano","Nicolas Morey-Chaisemartin","Johannes Schindelin","Tom G. Christensen","Mischa POSLAWSKY","brian m. carlson","Bagas Sanjaya","Randall S. Becker","Daniel Stenberg","Konstantin Ryabitsev","Andrei Rybak"],"isPatch":true,"patchVersion":1,"patchTotal":4},"messages":[{"id":"325935","messageId":"20170809120024.7phdjzjv54uv5dpz@sigill.intra.peff.net","threadId":"46547","inReplyTo":null,"subject":"[PATCH 0/4] dropping support for older curl","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2017-08-09T12:00:25Z","receivedAt":"2017-08-09T12:00:32Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"This is a resurrection of the thread from April:\n\n  https://public-inbox.org/git/20170404025438.bgxz5sfmrawqswcj@sigill.intra.peff.net/\n\nThe general idea is that we should drop support for very old curl\nversions, which already fail to compile. I'm sympathetic to the case\nwhere people actually have systems with really old versions of curl. But\nat the same time, I think we may be better off informing them that Git\nisn't tested with these ancient versions at all (and I have a suspicion\nthat there are lurking bugs; see the commit messages or read that other\nthread).\n\nI've broken the changes into three patches. That helps a bit with\nreviewing the diffs, but it also means we don't have to apply them all\nat once (though I think we should; but it would likewise help if end up\nwanting to revert one of them later).\n\nThe first cutoff is based on having more compilation breakages than the\nother (and also just being incredibly old). The second is just a sweet\nspot of bang-for-the-buck and age. In the absence of other data, it's\nprobably what I would suggest. The third one uses the existing compile\nbreakage from v2.12.0 as a guide.\n\n  [1/4]: http: drop support for curl < 7.11.1\n  [2/4]: http: drop support for curl < 7.16.0\n  [3/4]: http: drop support for curl < 7.19.4\n  [4/4]: http: #error on too-old curl\n\n Documentation/config.txt |   3 +-\n http-push.c              |  23 -------\n http-walker.c            |  12 ----\n http.c                   | 153 +----------------------------------------------\n http.h                   |  35 +----------\n remote-curl.c            |   7 ---\n 6 files changed, 5 insertions(+), 228 deletions(-)\n\n-Peff\n"},{"id":"325937","messageId":"20170809120124.3i5xjmk7mfxzwmdq@sigill.intra.peff.net","threadId":"46547","inReplyTo":"20170809120024.7phdjzjv54uv5dpz@sigill.intra.peff.net","subject":"[PATCH 1/4] http: drop support for curl < 7.11.1","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2017-08-09T12:01:24Z","receivedAt":"2017-08-09T12:01:32Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"Recent versions of Git will not build with curl older than\n7.11.1 due to (at least) two issues:\n\n  - our use of CURLOPT_POSTFIELDSIZE in 37ee680d9b\n    (http.postbuffer: allow full range of ssize_t values,\n    2017-04-11). This field was introduced in curl 7.11.1.\n\n  - our use of CURLPROTO_* outside any #ifdef in aeae4db174\n    (http: create function to get curl allowed protocols,\n    2016-12-14). These were introduced in curl 7.19.4.\n\nWe could solve these compilation problems with more #ifdefs,\nbut it's not worth the trouble. Version 7.11.1 came out in\nMarch of 2004, over 13 years ago. Let's declare that too old\nand drop any existing ifdefs that go further back. One\nobvious benefit is that we'll have fewer conditional bits\ncluttering the code.\n\nBut more importantly, we're doing a disservice to users to\npretend that Git works with old versions. It's clear that\nnobody is testing modern Git with such old versions of curl\n(we've had 3 released versions with the CURLPROTO issue\nwithout a report of anyone seeing the breakage in the wild).\nAnd there are a lot of subtle ways we could be getting this\nwrong (for instance, curl prior to 7.17.0 did not copy\nstring arguments to curl_easy_setopt(), which means that\nusing an old copy of curl could produce use-after-free\nbugs that are not present with more recent versions).\n\nThis patch drops all #ifdefs that reference older versions\n(note that curl's preprocessor macros are in hex, so we're\nlooking for 070b01, not 071101).\n\nSigned-off-by: Jeff King <peff@peff.net>\n---\nThere may be other problems, too.  I couldn't actually get a version of\ncurl older than 7.12.2 to compile due to bison/yacc woes.\n\n http.c        | 51 ---------------------------------------------------\n http.h        | 11 -----------\n remote-curl.c |  3 ---\n 3 files changed, 65 deletions(-)\n\ndiff --git a/http.c b/http.c\nindex c6c010f881..a3675a0eaa 100644\n--- a/http.c\n+++ b/http.c\n@@ -13,19 +13,11 @@\n #include \"transport.h\"\n \n static struct trace_key trace_curl = TRACE_KEY_INIT(CURL);\n-#if LIBCURL_VERSION_NUM >= 0x070a08\n long int git_curl_ipresolve = CURL_IPRESOLVE_WHATEVER;\n-#else\n-long int git_curl_ipresolve;\n-#endif\n int active_requests;\n int http_is_verbose;\n ssize_t http_post_buffer = 16 * LARGE_PACKET_MAX;\n \n-#if LIBCURL_VERSION_NUM >= 0x070a06\n-#define LIBCURL_CAN_HANDLE_AUTH_ANY\n-#endif\n-\n static int min_curl_sessions = 1;\n static int curl_session_count;\n #ifdef USE_CURL_MULTI\n@@ -58,12 +50,8 @@ static struct {\n \t{ \"tlsv1.2\", CURL_SSLVERSION_TLSv1_2 },\n #endif\n };\n-#if LIBCURL_VERSION_NUM >= 0x070903\n static const char *ssl_key;\n-#endif\n-#if LIBCURL_VERSION_NUM >= 0x070908\n static const char *ssl_capath;\n-#endif\n #if LIBCURL_VERSION_NUM >= 0x072c00\n static const char *ssl_pinnedkey;\n #endif\n@@ -82,9 +70,7 @@ static struct {\n \t{ \"digest\", CURLAUTH_DIGEST },\n \t{ \"negotiate\", CURLAUTH_GSSNEGOTIATE },\n \t{ \"ntlm\", CURLAUTH_NTLM },\n-#ifdef LIBCURL_CAN_HANDLE_AUTH_ANY\n \t{ \"anyauth\", CURLAUTH_ANY },\n-#endif\n \t/*\n \t * CURLAUTH_DIGEST_IE has no corresponding command-line option in\n \t * curl(1) and is not included in CURLAUTH_ANY, so we leave it out\n@@ -124,7 +110,6 @@ enum http_follow_config http_follow_config = HTTP_FOLLOW_INITIAL;\n \n static struct credential cert_auth = CREDENTIAL_INIT;\n static int ssl_cert_password_required;\n-#ifdef LIBCURL_CAN_HANDLE_AUTH_ANY\n static unsigned long http_auth_methods = CURLAUTH_ANY;\n static int http_auth_methods_restricted;\n /* Modes for which empty_auth cannot actually help us. */\n@@ -134,7 +119,6 @@ static unsigned long empty_auth_useless =\n \t| CURLAUTH_DIGEST_IE\n #endif\n \t| CURLAUTH_DIGEST;\n-#endif\n \n static struct curl_slist *pragma_header;\n static struct curl_slist *no_pragma_header;\n@@ -208,12 +192,8 @@ static void finish_active_slot(struct active_request_slot *slot)\n \tif (slot->results != NULL) {\n \t\tslot->results->curl_result = slot->curl_result;\n \t\tslot->results->http_code = slot->http_code;\n-#if LIBCURL_VERSION_NUM >= 0x070a08\n \t\tcurl_easy_getinfo(slot->curl, CURLINFO_HTTPAUTH_AVAIL,\n \t\t\t\t  &slot->results->auth_avail);\n-#else\n-\t\tslot->results->auth_avail = 0;\n-#endif\n \n \t\tcurl_easy_getinfo(slot->curl, CURLINFO_HTTP_CONNECTCODE,\n \t\t\t&slot->results->http_connectcode);\n@@ -273,14 +253,10 @@ static int http_options(const char *var, const char *value, void *cb)\n \t\treturn git_config_string(&ssl_version, var, value);\n \tif (!strcmp(\"http.sslcert\", var))\n \t\treturn git_config_string(&ssl_cert, var, value);\n-#if LIBCURL_VERSION_NUM >= 0x070903\n \tif (!strcmp(\"http.sslkey\", var))\n \t\treturn git_config_string(&ssl_key, var, value);\n-#endif\n-#if LIBCURL_VERSION_NUM >= 0x070908\n \tif (!strcmp(\"http.sslcapath\", var))\n \t\treturn git_config_pathname(&ssl_capath, var, value);\n-#endif\n \tif (!strcmp(\"http.sslcainfo\", var))\n \t\treturn git_config_pathname(&ssl_cainfo, var, value);\n \tif (!strcmp(\"http.sslcertpasswordprotected\", var)) {\n@@ -401,12 +377,6 @@ static int curl_empty_auth_enabled(void)\n \tif (curl_empty_auth >= 0)\n \t\treturn curl_empty_auth;\n \n-#ifndef LIBCURL_CAN_HANDLE_AUTH_ANY\n-\t/*\n-\t * Our libcurl is too old to do AUTH_ANY in the first place;\n-\t * just default to turning the feature off.\n-\t */\n-#else\n \t/*\n \t * In the automatic case, kick in the empty-auth\n \t * hack as long as we would potentially try some\n@@ -419,7 +389,6 @@ static int curl_empty_auth_enabled(void)\n \tif (http_auth_methods_restricted &&\n \t    (http_auth_methods & ~empty_auth_useless))\n \t\treturn 1;\n-#endif\n \treturn 0;\n }\n \n@@ -490,7 +459,6 @@ static void init_curl_proxy_auth(CURL *result)\n \n \tvar_override(&http_proxy_authmethod, getenv(\"GIT_HTTP_PROXY_AUTHMETHOD\"));\n \n-#if LIBCURL_VERSION_NUM >= 0x070a07 /* CURLOPT_PROXYAUTH and CURLAUTH_ANY */\n \tif (http_proxy_authmethod) {\n \t\tint i;\n \t\tfor (i = 0; i < ARRAY_SIZE(proxy_authmethods); i++) {\n@@ -508,7 +476,6 @@ static void init_curl_proxy_auth(CURL *result)\n \t}\n \telse\n \t\tcurl_easy_setopt(result, CURLOPT_PROXYAUTH, CURLAUTH_ANY);\n-#endif\n }\n \n static int has_cert_password(void)\n@@ -710,12 +677,8 @@ static CURL *get_curl_handle(void)\n \t\tcurl_easy_setopt(result, CURLOPT_SSL_VERIFYHOST, 2);\n \t}\n \n-#if LIBCURL_VERSION_NUM >= 0x070907\n \tcurl_easy_setopt(result, CURLOPT_NETRC, CURL_NETRC_OPTIONAL);\n-#endif\n-#ifdef LIBCURL_CAN_HANDLE_AUTH_ANY\n \tcurl_easy_setopt(result, CURLOPT_HTTPAUTH, CURLAUTH_ANY);\n-#endif\n \n #if LIBCURL_VERSION_NUM >= 0x071600\n \tif (curl_deleg) {\n@@ -762,14 +725,10 @@ static CURL *get_curl_handle(void)\n \t\tcurl_easy_setopt(result, CURLOPT_SSLCERT, ssl_cert);\n \tif (has_cert_password())\n \t\tcurl_easy_setopt(result, CURLOPT_KEYPASSWD, cert_auth.password);\n-#if LIBCURL_VERSION_NUM >= 0x070903\n \tif (ssl_key != NULL)\n \t\tcurl_easy_setopt(result, CURLOPT_SSLKEY, ssl_key);\n-#endif\n-#if LIBCURL_VERSION_NUM >= 0x070908\n \tif (ssl_capath != NULL)\n \t\tcurl_easy_setopt(result, CURLOPT_CAPATH, ssl_capath);\n-#endif\n #if LIBCURL_VERSION_NUM >= 0x072c00\n \tif (ssl_pinnedkey != NULL)\n \t\tcurl_easy_setopt(result, CURLOPT_PINNEDPUBLICKEY, ssl_pinnedkey);\n@@ -945,12 +904,8 @@ void http_init(struct remote *remote, const char *url, int proactive_auth)\n \t\tcurl_ssl_verify = 0;\n \n \tset_from_env(&ssl_cert, \"GIT_SSL_CERT\");\n-#if LIBCURL_VERSION_NUM >= 0x070903\n \tset_from_env(&ssl_key, \"GIT_SSL_KEY\");\n-#endif\n-#if LIBCURL_VERSION_NUM >= 0x070908\n \tset_from_env(&ssl_capath, \"GIT_SSL_CAPATH\");\n-#endif\n \tset_from_env(&ssl_cainfo, \"GIT_SSL_CAINFO\");\n \n \tset_from_env(&user_agent, \"GIT_HTTP_USER_AGENT\");\n@@ -1120,12 +1075,8 @@ struct active_request_slot *get_active_slot(void)\n \telse\n \t\tcurl_easy_setopt(slot->curl, CURLOPT_FOLLOWLOCATION, 0);\n \n-#if LIBCURL_VERSION_NUM >= 0x070a08\n \tcurl_easy_setopt(slot->curl, CURLOPT_IPRESOLVE, git_curl_ipresolve);\n-#endif\n-#ifdef LIBCURL_CAN_HANDLE_AUTH_ANY\n \tcurl_easy_setopt(slot->curl, CURLOPT_HTTPAUTH, http_auth_methods);\n-#endif\n \tif (http_auth.password || curl_empty_auth_enabled())\n \t\tinit_curl_http_auth(slot->curl);\n \n@@ -1392,13 +1343,11 @@ static int handle_curl_result(struct slot_results *results)\n \t\t\tcredential_reject(&http_auth);\n \t\t\treturn HTTP_NOAUTH;\n \t\t} else {\n-#ifdef LIBCURL_CAN_HANDLE_AUTH_ANY\n \t\t\thttp_auth_methods &= ~CURLAUTH_GSSNEGOTIATE;\n \t\t\tif (results->auth_avail) {\n \t\t\t\thttp_auth_methods &= results->auth_avail;\n \t\t\t\thttp_auth_methods_restricted = 1;\n \t\t\t}\n-#endif\n \t\t\treturn HTTP_REAUTH;\n \t\t}\n \t} else {\ndiff --git a/http.h b/http.h\nindex f7bd3b26b0..90b20a711a 100644\n--- a/http.h\n+++ b/http.h\n@@ -22,21 +22,10 @@\n #define DEFAULT_MAX_REQUESTS 5\n #endif\n \n-#if LIBCURL_VERSION_NUM < 0x070704\n-#define curl_global_cleanup() do { /* nothing */ } while (0)\n-#endif\n-#if LIBCURL_VERSION_NUM < 0x070800\n-#define curl_global_init(a) do { /* nothing */ } while (0)\n-#endif\n-\n #if (LIBCURL_VERSION_NUM < 0x070c04) || (LIBCURL_VERSION_NUM == 0x071000)\n #define NO_CURL_EASY_DUPHANDLE\n #endif\n \n-#if LIBCURL_VERSION_NUM < 0x070a03\n-#define CURLE_HTTP_RETURNED_ERROR CURLE_HTTP_NOT_FOUND\n-#endif\n-\n #if LIBCURL_VERSION_NUM < 0x070c03\n #define NO_CURL_IOCTL\n #endif\ndiff --git a/remote-curl.c b/remote-curl.c\nindex 0053b09549..23e2a1f3ac 100644\n--- a/remote-curl.c\n+++ b/remote-curl.c\n@@ -144,8 +144,6 @@ static int set_option(const char *name, const char *value)\n \t} else if (!strcmp(name, \"push-option\")) {\n \t\tstring_list_append(&options.push_options, value);\n \t\treturn 0;\n-\n-#if LIBCURL_VERSION_NUM >= 0x070a08\n \t} else if (!strcmp(name, \"family\")) {\n \t\tif (!strcmp(value, \"ipv4\"))\n \t\t\tgit_curl_ipresolve = CURL_IPRESOLVE_V4;\n@@ -156,7 +154,6 @@ static int set_option(const char *name, const char *value)\n \t\telse\n \t\t\treturn -1;\n \t\treturn 0;\n-#endif /* LIBCURL_VERSION_NUM >= 0x070a08 */\n \t} else {\n \t\treturn 1 /* unsupported */;\n \t}\n-- \n2.14.0.609.gd2d1f7ddf\n\n"},{"id":"325938","messageId":"20170809120157.il4ktf75wscqoyic@sigill.intra.peff.net","threadId":"46547","inReplyTo":"20170809120024.7phdjzjv54uv5dpz@sigill.intra.peff.net","subject":"[PATCH 2/4] http: drop support for curl < 7.16.0","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2017-08-09T12:01:57Z","receivedAt":"2017-08-09T12:02:04Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"As discussed in the previous commit, Git is not well-tested\nwith old versions of curl (and in fact since v2.12.0 does\nnot even compile with versions older than 7.19.4). Let's\nstop pretending we support curl that old and drop any\nnow-obslete #ifdefs.\n\nChoosing 7.16.0 is a somewhat arbitrary cutoff, but:\n\n  1. it came out in October of 2006, over 10 years ago.\n     Besides being a nice round number, it's a common\n     end-of-life support period, even for conservative\n     distributions.\n\n  2. that version introduced the curl_multi interface, which\n     gives us a lot of bang for the buck in removing #ifdefs\n\nSigned-off-by: Jeff King <peff@peff.net>\n---\n Documentation/config.txt |  3 +--\n http-push.c              | 23 --------------------\n http-walker.c            | 12 -----------\n http.c                   | 56 +-----------------------------------------------\n http.h                   | 20 +----------------\n remote-curl.c            |  4 ----\n 6 files changed, 3 insertions(+), 115 deletions(-)\n\ndiff --git a/Documentation/config.txt b/Documentation/config.txt\nindex d5c9c4cab6..07e5fab98a 100644\n--- a/Documentation/config.txt\n+++ b/Documentation/config.txt\n@@ -1971,8 +1971,7 @@ http.maxRequests::\n http.minSessions::\n \tThe number of curl sessions (counted across slots) to be kept across\n \trequests. They will not be ended with curl_easy_cleanup() until\n-\thttp_cleanup() is invoked. If USE_CURL_MULTI is not defined, this\n-\tvalue will be capped at 1. Defaults to 1.\n+\thttp_cleanup() is invoked. Defaults to 1.\n \n http.postBuffer::\n \tMaximum size in bytes of the buffer used by smart HTTP\ndiff --git a/http-push.c b/http-push.c\nindex c91f40a610..366af210a9 100644\n--- a/http-push.c\n+++ b/http-push.c\n@@ -198,10 +198,8 @@ static void curl_setup_http(CURL *curl, const char *url,\n \tcurl_easy_setopt(curl, CURLOPT_INFILE, buffer);\n \tcurl_easy_setopt(curl, CURLOPT_INFILESIZE, buffer->buf.len);\n \tcurl_easy_setopt(curl, CURLOPT_READFUNCTION, fread_buffer);\n-#ifndef NO_CURL_IOCTL\n \tcurl_easy_setopt(curl, CURLOPT_IOCTLFUNCTION, ioctl_buffer);\n \tcurl_easy_setopt(curl, CURLOPT_IOCTLDATA, buffer);\n-#endif\n \tcurl_easy_setopt(curl, CURLOPT_WRITEFUNCTION, write_fn);\n \tcurl_easy_setopt(curl, CURLOPT_NOBODY, 0);\n \tcurl_easy_setopt(curl, CURLOPT_CUSTOMREQUEST, custom_req);\n@@ -244,8 +242,6 @@ static void process_response(void *callback_data)\n \tfinish_request(request);\n }\n \n-#ifdef USE_CURL_MULTI\n-\n static void start_fetch_loose(struct transfer_request *request)\n {\n \tstruct active_request_slot *slot;\n@@ -294,7 +290,6 @@ static void start_mkcol(struct transfer_request *request)\n \t\tFREE_AND_NULL(request->url);\n \t}\n }\n-#endif\n \n static void start_fetch_packed(struct transfer_request *request)\n {\n@@ -596,7 +591,6 @@ static void finish_request(struct transfer_request *request)\n \t}\n }\n \n-#ifdef USE_CURL_MULTI\n static int is_running_queue;\n static int fill_active_slot(void *unused)\n {\n@@ -620,7 +614,6 @@ static int fill_active_slot(void *unused)\n \t}\n \treturn 0;\n }\n-#endif\n \n static void get_remote_object_list(unsigned char parent);\n \n@@ -649,10 +642,8 @@ static void add_fetch_request(struct object *obj)\n \trequest->next = request_queue_head;\n \trequest_queue_head = request;\n \n-#ifdef USE_CURL_MULTI\n \tfill_active_slots();\n \tstep_active_slots();\n-#endif\n }\n \n static int add_send_request(struct object *obj, struct remote_lock *lock)\n@@ -687,10 +678,8 @@ static int add_send_request(struct object *obj, struct remote_lock *lock)\n \trequest->next = request_queue_head;\n \trequest_queue_head = request;\n \n-#ifdef USE_CURL_MULTI\n \tfill_active_slots();\n \tstep_active_slots();\n-#endif\n \n \treturn 1;\n }\n@@ -1666,21 +1655,15 @@ static int delete_remote_branch(const char *pattern, int force)\n \n static void run_request_queue(void)\n {\n-#ifdef USE_CURL_MULTI\n \tis_running_queue = 1;\n \tfill_active_slots();\n \tadd_fill_function(NULL, fill_active_slot);\n-#endif\n \tdo {\n \t\tfinish_all_active_slots();\n-#ifdef USE_CURL_MULTI\n \t\tfill_active_slots();\n-#endif\n \t} while (request_queue_head && !aborted);\n \n-#ifdef USE_CURL_MULTI\n \tis_running_queue = 0;\n-#endif\n }\n \n int cmd_main(int argc, const char **argv)\n@@ -1756,10 +1739,6 @@ int cmd_main(int argc, const char **argv)\n \t\tbreak;\n \t}\n \n-#ifndef USE_CURL_MULTI\n-\tdie(\"git-push is not available for http/https repository when not compiled with USE_CURL_MULTI\");\n-#endif\n-\n \tif (!repo->url)\n \t\tusage(http_push_usage);\n \n@@ -1772,9 +1751,7 @@ int cmd_main(int argc, const char **argv)\n \n \thttp_init(NULL, repo->url, 1);\n \n-#ifdef USE_CURL_MULTI\n \tis_running_queue = 0;\n-#endif\n \n \t/* Verify DAV compliance/lock support */\n \tif (!locking_available()) {\ndiff --git a/http-walker.c b/http-walker.c\nindex ee049cb13d..b5b8e03b0b 100644\n--- a/http-walker.c\n+++ b/http-walker.c\n@@ -119,7 +119,6 @@ static void release_object_request(struct object_request *obj_req)\n \tfree(obj_req);\n }\n \n-#ifdef USE_CURL_MULTI\n static int fill_active_slot(struct walker *walker)\n {\n \tstruct object_request *obj_req;\n@@ -138,7 +137,6 @@ static int fill_active_slot(struct walker *walker)\n \t}\n \treturn 0;\n }\n-#endif\n \n static void prefetch(struct walker *walker, unsigned char *sha1)\n {\n@@ -155,10 +153,8 @@ static void prefetch(struct walker *walker, unsigned char *sha1)\n \thttp_is_verbose = walker->get_verbosely;\n \tlist_add_tail(&newreq->node, &object_queue_head);\n \n-#ifdef USE_CURL_MULTI\n \tfill_active_slots();\n \tstep_active_slots();\n-#endif\n }\n \n static int is_alternate_allowed(const char *url)\n@@ -346,11 +342,9 @@ static void fetch_alternates(struct walker *walker, const char *base)\n \t * wait for them to arrive and return to processing this request's\n \t * curl message\n \t */\n-#ifdef USE_CURL_MULTI\n \twhile (cdata->got_alternates == 0) {\n \t\tstep_active_slots();\n \t}\n-#endif\n \n \t/* Nothing to do if they've already been fetched */\n \tif (cdata->got_alternates == 1)\n@@ -493,12 +487,8 @@ static int fetch_object(struct walker *walker, unsigned char *sha1)\n \t\treturn 0;\n \t}\n \n-#ifdef USE_CURL_MULTI\n \twhile (obj_req->state == WAITING)\n \t\tstep_active_slots();\n-#else\n-\tstart_object_request(walker, obj_req);\n-#endif\n \n \t/*\n \t * obj_req->req might change when fetching alternates in the callback\n@@ -618,9 +608,7 @@ struct walker *get_http_walker(const char *url)\n \twalker->cleanup = cleanup;\n \twalker->data = data;\n \n-#ifdef USE_CURL_MULTI\n \tadd_fill_function(walker, (int (*)(void *)) fill_active_slot);\n-#endif\n \n \treturn walker;\n }\ndiff --git a/http.c b/http.c\nindex a3675a0eaa..6e5f4ce5f9 100644\n--- a/http.c\n+++ b/http.c\n@@ -20,10 +20,8 @@ ssize_t http_post_buffer = 16 * LARGE_PACKET_MAX;\n \n static int min_curl_sessions = 1;\n static int curl_session_count;\n-#ifdef USE_CURL_MULTI\n static int max_requests = -1;\n static CURLM *curlm;\n-#endif\n #ifndef NO_CURL_EASY_DUPHANDLE\n static CURL *curl_default;\n #endif\n@@ -100,14 +98,6 @@ static int curl_empty_auth = -1;\n \n enum http_follow_config http_follow_config = HTTP_FOLLOW_INITIAL;\n \n-#if LIBCURL_VERSION_NUM >= 0x071700\n-/* Use CURLOPT_KEYPASSWD as is */\n-#elif LIBCURL_VERSION_NUM >= 0x070903\n-#define CURLOPT_KEYPASSWD CURLOPT_SSLKEYPASSWD\n-#else\n-#define CURLOPT_KEYPASSWD CURLOPT_SSLCERTPASSWD\n-#endif\n-\n static struct credential cert_auth = CREDENTIAL_INIT;\n static int ssl_cert_password_required;\n static unsigned long http_auth_methods = CURLAUTH_ANY;\n@@ -141,7 +131,6 @@ size_t fread_buffer(char *ptr, size_t eltsize, size_t nmemb, void *buffer_)\n \treturn size;\n }\n \n-#ifndef NO_CURL_IOCTL\n curlioerr ioctl_buffer(CURL *handle, int cmd, void *clientp)\n {\n \tstruct buffer *buffer = clientp;\n@@ -158,7 +147,6 @@ curlioerr ioctl_buffer(CURL *handle, int cmd, void *clientp)\n \t\treturn CURLIOE_UNKNOWNCMD;\n \t}\n }\n-#endif\n \n size_t fwrite_buffer(char *ptr, size_t eltsize, size_t nmemb, void *buffer_)\n {\n@@ -206,12 +194,9 @@ static void finish_active_slot(struct active_request_slot *slot)\n \n static void xmulti_remove_handle(struct active_request_slot *slot)\n {\n-#ifdef USE_CURL_MULTI\n \tcurl_multi_remove_handle(curlm, slot->curl);\n-#endif\n }\n \n-#ifdef USE_CURL_MULTI\n static void process_curl_messages(void)\n {\n \tint num_messages;\n@@ -239,7 +224,6 @@ static void process_curl_messages(void)\n \t\tcurl_message = curl_multi_info_read(curlm, &num_messages);\n \t}\n }\n-#endif\n \n static int http_options(const char *var, const char *value, void *cb)\n {\n@@ -269,18 +253,14 @@ static int http_options(const char *var, const char *value, void *cb)\n \t}\n \tif (!strcmp(\"http.minsessions\", var)) {\n \t\tmin_curl_sessions = git_config_int(var, value);\n-#ifndef USE_CURL_MULTI\n \t\tif (min_curl_sessions > 1)\n \t\t\tmin_curl_sessions = 1;\n-#endif\n \t\treturn 0;\n \t}\n-#ifdef USE_CURL_MULTI\n \tif (!strcmp(\"http.maxrequests\", var)) {\n \t\tmax_requests = git_config_int(var, value);\n \t\treturn 0;\n \t}\n-#endif\n \tif (!strcmp(\"http.lowspeedlimit\", var)) {\n \t\tcurl_low_speed_limit = (long)git_config_int(var, value);\n \t\treturn 0;\n@@ -497,7 +477,7 @@ static void set_curl_keepalive(CURL *c)\n \tcurl_easy_setopt(c, CURLOPT_TCP_KEEPALIVE, 1);\n }\n \n-#elif LIBCURL_VERSION_NUM >= 0x071000\n+#else\n static int sockopt_callback(void *client, curl_socket_t fd, curlsocktype type)\n {\n \tint ka = 1;\n@@ -518,12 +498,6 @@ static void set_curl_keepalive(CURL *c)\n {\n \tcurl_easy_setopt(c, CURLOPT_SOCKOPTFUNCTION, sockopt_callback);\n }\n-\n-#else\n-static void set_curl_keepalive(CURL *c)\n-{\n-\t/* not supported on older curl versions */\n-}\n #endif\n \n static void redact_sensitive_header(struct strbuf *header)\n@@ -888,7 +862,6 @@ void http_init(struct remote *remote, const char *url, int proactive_auth)\n \tno_pragma_header = curl_slist_append(http_copy_default_headers(),\n \t\t\"Pragma:\");\n \n-#ifdef USE_CURL_MULTI\n \t{\n \t\tchar *http_max_requests = getenv(\"GIT_HTTP_MAX_REQUESTS\");\n \t\tif (http_max_requests != NULL)\n@@ -898,7 +871,6 @@ void http_init(struct remote *remote, const char *url, int proactive_auth)\n \tcurlm = curl_multi_init();\n \tif (!curlm)\n \t\tdie(\"curl_multi_init failed\");\n-#endif\n \n \tif (getenv(\"GIT_SSL_NO_VERIFY\"))\n \t\tcurl_ssl_verify = 0;\n@@ -921,10 +893,8 @@ void http_init(struct remote *remote, const char *url, int proactive_auth)\n \t\tcurl_ssl_verify = 1;\n \n \tcurl_session_count = 0;\n-#ifdef USE_CURL_MULTI\n \tif (max_requests < 1)\n \t\tmax_requests = DEFAULT_MAX_REQUESTS;\n-#endif\n \n \tif (getenv(\"GIT_CURL_FTP_NO_EPSV\"))\n \t\tcurl_ftp_no_epsv = 1;\n@@ -961,9 +931,7 @@ void http_cleanup(void)\n \tcurl_easy_cleanup(curl_default);\n #endif\n \n-#ifdef USE_CURL_MULTI\n \tcurl_multi_cleanup(curlm);\n-#endif\n \tcurl_global_cleanup();\n \n \tcurl_slist_free_all(extra_http_headers);\n@@ -1005,7 +973,6 @@ struct active_request_slot *get_active_slot(void)\n \tstruct active_request_slot *slot = active_queue_head;\n \tstruct active_request_slot *newslot;\n \n-#ifdef USE_CURL_MULTI\n \tint num_transfers;\n \n \t/* Wait for a slot to open up if the queue is full */\n@@ -1014,7 +981,6 @@ struct active_request_slot *get_active_slot(void)\n \t\tif (num_transfers < active_requests)\n \t\t\tprocess_curl_messages();\n \t}\n-#endif\n \n \twhile (slot != NULL && slot->in_use)\n \t\tslot = slot->next;\n@@ -1085,7 +1051,6 @@ struct active_request_slot *get_active_slot(void)\n \n int start_active_slot(struct active_request_slot *slot)\n {\n-#ifdef USE_CURL_MULTI\n \tCURLMcode curlm_result = curl_multi_add_handle(curlm, slot->curl);\n \tint num_transfers;\n \n@@ -1103,11 +1068,9 @@ int start_active_slot(struct active_request_slot *slot)\n \t * something.\n \t */\n \tcurl_multi_perform(curlm, &num_transfers);\n-#endif\n \treturn 1;\n }\n \n-#ifdef USE_CURL_MULTI\n struct fill_chain {\n \tvoid *data;\n \tint (*fill)(void *);\n@@ -1166,11 +1129,9 @@ void step_active_slots(void)\n \t\tfill_active_slots();\n \t}\n }\n-#endif\n \n void run_active_slot(struct active_request_slot *slot)\n {\n-#ifdef USE_CURL_MULTI\n \tfd_set readfds;\n \tfd_set writefds;\n \tfd_set excfds;\n@@ -1183,7 +1144,6 @@ void run_active_slot(struct active_request_slot *slot)\n \t\tstep_active_slots();\n \n \t\tif (slot->in_use) {\n-#if LIBCURL_VERSION_NUM >= 0x070f04\n \t\t\tlong curl_timeout;\n \t\t\tcurl_multi_timeout(curlm, &curl_timeout);\n \t\t\tif (curl_timeout == 0) {\n@@ -1195,10 +1155,6 @@ void run_active_slot(struct active_request_slot *slot)\n \t\t\t\tselect_timeout.tv_sec  =  curl_timeout / 1000;\n \t\t\t\tselect_timeout.tv_usec = (curl_timeout % 1000) * 1000;\n \t\t\t}\n-#else\n-\t\t\tselect_timeout.tv_sec  = 0;\n-\t\t\tselect_timeout.tv_usec = 50000;\n-#endif\n \n \t\t\tmax_fd = -1;\n \t\t\tFD_ZERO(&readfds);\n@@ -1221,12 +1177,6 @@ void run_active_slot(struct active_request_slot *slot)\n \t\t\tselect(max_fd+1, &readfds, &writefds, &excfds, &select_timeout);\n \t\t}\n \t}\n-#else\n-\twhile (slot->in_use) {\n-\t\tslot->curl_result = curl_easy_perform(slot->curl);\n-\t\tfinish_active_slot(slot);\n-\t}\n-#endif\n }\n \n static void release_active_slot(struct active_request_slot *slot)\n@@ -1240,9 +1190,7 @@ static void release_active_slot(struct active_request_slot *slot)\n \t\t\tcurl_session_count--;\n \t\t}\n \t}\n-#ifdef USE_CURL_MULTI\n \tfill_active_slots();\n-#endif\n }\n \n void finish_all_active_slots(void)\n@@ -1353,12 +1301,10 @@ static int handle_curl_result(struct slot_results *results)\n \t} else {\n \t\tif (results->http_connectcode == 407)\n \t\t\tcredential_reject(&proxy_auth);\n-#if LIBCURL_VERSION_NUM >= 0x070c00\n \t\tif (!curl_errorstr[0])\n \t\t\tstrlcpy(curl_errorstr,\n \t\t\t\tcurl_easy_strerror(results->curl_result),\n \t\t\t\tsizeof(curl_errorstr));\n-#endif\n \t\treturn HTTP_ERROR;\n \t}\n }\ndiff --git a/http.h b/http.h\nindex 90b20a711a..57e97c128d 100644\n--- a/http.h\n+++ b/http.h\n@@ -10,26 +10,12 @@\n #include \"remote.h\"\n #include \"url.h\"\n \n-/*\n- * We detect based on the cURL version if multi-transfer is\n- * usable in this implementation and define this symbol accordingly.\n- * This shouldn't be set by the Makefile or by the user (e.g. via CFLAGS).\n- */\n-#undef USE_CURL_MULTI\n-\n-#if LIBCURL_VERSION_NUM >= 0x071000\n-#define USE_CURL_MULTI\n #define DEFAULT_MAX_REQUESTS 5\n-#endif\n \n-#if (LIBCURL_VERSION_NUM < 0x070c04) || (LIBCURL_VERSION_NUM == 0x071000)\n+#if LIBCURL_VERSION_NUM == 0x071000\n #define NO_CURL_EASY_DUPHANDLE\n #endif\n \n-#if LIBCURL_VERSION_NUM < 0x070c03\n-#define NO_CURL_IOCTL\n-#endif\n-\n /*\n  * CURLOPT_USE_SSL was known as CURLOPT_FTP_SSL up to 7.16.4,\n  * and the constants were known as CURLFTPSSL_*\n@@ -67,9 +53,7 @@ struct buffer {\n extern size_t fread_buffer(char *ptr, size_t eltsize, size_t nmemb, void *strbuf);\n extern size_t fwrite_buffer(char *ptr, size_t eltsize, size_t nmemb, void *strbuf);\n extern size_t fwrite_null(char *ptr, size_t eltsize, size_t nmemb, void *strbuf);\n-#ifndef NO_CURL_IOCTL\n extern curlioerr ioctl_buffer(CURL *handle, int cmd, void *clientp);\n-#endif\n \n /* Slot lifecycle functions */\n extern struct active_request_slot *get_active_slot(void);\n@@ -86,11 +70,9 @@ extern void finish_all_active_slots(void);\n int run_one_slot(struct active_request_slot *slot,\n \t\t struct slot_results *results);\n \n-#ifdef USE_CURL_MULTI\n extern void fill_active_slots(void);\n extern void add_fill_function(void *data, int (*fill)(void *));\n extern void step_active_slots(void);\n-#endif\n \n extern void http_init(struct remote *remote, const char *url,\n \t\t      int proactive_auth);\ndiff --git a/remote-curl.c b/remote-curl.c\nindex 23e2a1f3ac..333cca33b6 100644\n--- a/remote-curl.c\n+++ b/remote-curl.c\n@@ -435,7 +435,6 @@ static size_t rpc_out(void *ptr, size_t eltsize,\n \treturn avail;\n }\n \n-#ifndef NO_CURL_IOCTL\n static curlioerr rpc_ioctl(CURL *handle, int cmd, void *clientp)\n {\n \tstruct rpc_state *rpc = clientp;\n@@ -456,7 +455,6 @@ static curlioerr rpc_ioctl(CURL *handle, int cmd, void *clientp)\n \t\treturn CURLIOE_UNKNOWNCMD;\n \t}\n }\n-#endif\n \n static size_t rpc_in(char *ptr, size_t eltsize,\n \t\tsize_t nmemb, void *buffer_)\n@@ -602,10 +600,8 @@ static int post_rpc(struct rpc_state *rpc)\n \t\trpc->initial_buffer = 1;\n \t\tcurl_easy_setopt(slot->curl, CURLOPT_READFUNCTION, rpc_out);\n \t\tcurl_easy_setopt(slot->curl, CURLOPT_INFILE, rpc);\n-#ifndef NO_CURL_IOCTL\n \t\tcurl_easy_setopt(slot->curl, CURLOPT_IOCTLFUNCTION, rpc_ioctl);\n \t\tcurl_easy_setopt(slot->curl, CURLOPT_IOCTLDATA, rpc);\n-#endif\n \t\tif (options.verbosity > 1) {\n \t\t\tfprintf(stderr, \"POST %s (chunked)\\n\", rpc->service_name);\n \t\t\tfflush(stderr);\n-- \n2.14.0.609.gd2d1f7ddf\n\n"},{"id":"325939","messageId":"20170809120201.2eagzkljervqeusx@sigill.intra.peff.net","threadId":"46547","inReplyTo":"20170809120024.7phdjzjv54uv5dpz@sigill.intra.peff.net","subject":"[PATCH 3/4] http: drop support for curl < 7.19.4","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2017-08-09T12:02:01Z","receivedAt":"2017-08-09T12:02:08Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"Since v2.12.0, Git does not compile with versions of curl\nolder than 7.19.4. That version of curl is about 8 years\nold. This means it may still be used in some distributions\nwith long-running support periods. But the fact that we\nhaven't received a single bug report about the compile-time\nbreakage implies that nobody cares about building recent\nreleases on such platforms.\n\nAs discussed in the previous two commits, this cleans up the\ncode and gives a more realistic signal to users about which\nversions of Git are actually tested (in particular, this\nmoves us past the potential use-after-free issues with curl\nolder than 7.17.0).\n\nSigned-off-by: Jeff King <peff@peff.net>\n---\n http.c | 46 ----------------------------------------------\n http.h |  4 ----\n 2 files changed, 50 deletions(-)\n\ndiff --git a/http.c b/http.c\nindex 6e5f4ce5f9..5280511c74 100644\n--- a/http.c\n+++ b/http.c\n@@ -22,9 +22,7 @@ static int min_curl_sessions = 1;\n static int curl_session_count;\n static int max_requests = -1;\n static CURLM *curlm;\n-#ifndef NO_CURL_EASY_DUPHANDLE\n static CURL *curl_default;\n-#endif\n \n #define PREV_BUF_SIZE 4096\n \n@@ -382,24 +380,8 @@ static void init_curl_http_auth(CURL *result)\n \n \tcredential_fill(&http_auth);\n \n-#if LIBCURL_VERSION_NUM >= 0x071301\n \tcurl_easy_setopt(result, CURLOPT_USERNAME, http_auth.username);\n \tcurl_easy_setopt(result, CURLOPT_PASSWORD, http_auth.password);\n-#else\n-\t{\n-\t\tstatic struct strbuf up = STRBUF_INIT;\n-\t\t/*\n-\t\t * Note that we assume we only ever have a single set of\n-\t\t * credentials in a given program run, so we do not have\n-\t\t * to worry about updating this buffer, only setting its\n-\t\t * initial value.\n-\t\t */\n-\t\tif (!up.len)\n-\t\t\tstrbuf_addf(&up, \"%s:%s\",\n-\t\t\t\thttp_auth.username, http_auth.password);\n-\t\tcurl_easy_setopt(result, CURLOPT_USERPWD, up.buf);\n-\t}\n-#endif\n }\n \n /* *var must be free-able */\n@@ -413,20 +395,10 @@ static void var_override(const char **var, char *value)\n \n static void set_proxyauth_name_password(CURL *result)\n {\n-#if LIBCURL_VERSION_NUM >= 0x071301\n \t\tcurl_easy_setopt(result, CURLOPT_PROXYUSERNAME,\n \t\t\tproxy_auth.username);\n \t\tcurl_easy_setopt(result, CURLOPT_PROXYPASSWORD,\n \t\t\tproxy_auth.password);\n-#else\n-\t\tstruct strbuf s = STRBUF_INIT;\n-\n-\t\tstrbuf_addstr_urlencode(&s, proxy_auth.username, 1);\n-\t\tstrbuf_addch(&s, ':');\n-\t\tstrbuf_addstr_urlencode(&s, proxy_auth.password, 1);\n-\t\tcurl_proxyuserpwd = strbuf_detach(&s, NULL);\n-\t\tcurl_easy_setopt(result, CURLOPT_PROXYUSERPWD, curl_proxyuserpwd);\n-#endif\n }\n \n static void init_curl_proxy_auth(CURL *result)\n@@ -718,20 +690,12 @@ static CURL *get_curl_handle(void)\n \t}\n \n \tcurl_easy_setopt(result, CURLOPT_MAXREDIRS, 20);\n-#if LIBCURL_VERSION_NUM >= 0x071301\n \tcurl_easy_setopt(result, CURLOPT_POSTREDIR, CURL_REDIR_POST_ALL);\n-#elif LIBCURL_VERSION_NUM >= 0x071101\n \tcurl_easy_setopt(result, CURLOPT_POST301, 1);\n-#endif\n-#if LIBCURL_VERSION_NUM >= 0x071304\n \tcurl_easy_setopt(result, CURLOPT_REDIR_PROTOCOLS,\n \t\t\t get_curl_allowed_protocols(0));\n \tcurl_easy_setopt(result, CURLOPT_PROTOCOLS,\n \t\t\t get_curl_allowed_protocols(-1));\n-#else\n-\twarning(\"protocol restrictions not applied to curl redirects because\\n\"\n-\t\t\"your curl version is too old (>= 7.19.4)\");\n-#endif\n \tif (getenv(\"GIT_CURL_VERBOSE\"))\n \t\tcurl_easy_setopt(result, CURLOPT_VERBOSE, 1L);\n \tsetup_curl_trace(result);\n@@ -807,11 +771,9 @@ static CURL *get_curl_handle(void)\n \t\t\tdie(\"Invalid proxy URL '%s'\", curl_http_proxy);\n \n \t\tcurl_easy_setopt(result, CURLOPT_PROXY, proxy_auth.host);\n-#if LIBCURL_VERSION_NUM >= 0x071304\n \t\tvar_override(&curl_no_proxy, getenv(\"NO_PROXY\"));\n \t\tvar_override(&curl_no_proxy, getenv(\"no_proxy\"));\n \t\tcurl_easy_setopt(result, CURLOPT_NOPROXY, curl_no_proxy);\n-#endif\n \t}\n \tinit_curl_proxy_auth(result);\n \n@@ -907,9 +869,7 @@ void http_init(struct remote *remote, const char *url, int proactive_auth)\n \t\t\tssl_cert_password_required = 1;\n \t}\n \n-#ifndef NO_CURL_EASY_DUPHANDLE\n \tcurl_default = get_curl_handle();\n-#endif\n }\n \n void http_cleanup(void)\n@@ -927,9 +887,7 @@ void http_cleanup(void)\n \t}\n \tactive_queue_head = NULL;\n \n-#ifndef NO_CURL_EASY_DUPHANDLE\n \tcurl_easy_cleanup(curl_default);\n-#endif\n \n \tcurl_multi_cleanup(curlm);\n \tcurl_global_cleanup();\n@@ -1003,11 +961,7 @@ struct active_request_slot *get_active_slot(void)\n \t}\n \n \tif (slot->curl == NULL) {\n-#ifdef NO_CURL_EASY_DUPHANDLE\n-\t\tslot->curl = get_curl_handle();\n-#else\n \t\tslot->curl = curl_easy_duphandle(curl_default);\n-#endif\n \t\tcurl_session_count++;\n \t}\n \ndiff --git a/http.h b/http.h\nindex 57e97c128d..da4d8589d8 100644\n--- a/http.h\n+++ b/http.h\n@@ -12,10 +12,6 @@\n \n #define DEFAULT_MAX_REQUESTS 5\n \n-#if LIBCURL_VERSION_NUM == 0x071000\n-#define NO_CURL_EASY_DUPHANDLE\n-#endif\n-\n /*\n  * CURLOPT_USE_SSL was known as CURLOPT_FTP_SSL up to 7.16.4,\n  * and the constants were known as CURLFTPSSL_*\n-- \n2.14.0.609.gd2d1f7ddf\n\n"},{"id":"325940","messageId":"20170809120207.amjpwhxz3evjci6x@sigill.intra.peff.net","threadId":"46547","inReplyTo":"20170809120024.7phdjzjv54uv5dpz@sigill.intra.peff.net","subject":"[PATCH 4/4] http: #error on too-old curl","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2017-08-09T12:02:07Z","receivedAt":"2017-08-09T12:02:14Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"We already fail to build with versions of curl older than\n7.19.4. But doing an explicit check with an #error has two\nbenefits.\n\nOne is that it makes it clear to users that the build\nfailure is intentional, so they don't waste time trying to\ndebug it.\n\nAnd two is that it documents our current \"too old\"\nassumption, so that we know whether we need use an #ifdef\nwhen using newer curl features in future patches.\n\nSigned-off-by: Jeff King <peff@peff.net>\n---\n http.h | 4 ++++\n 1 file changed, 4 insertions(+)\n\ndiff --git a/http.h b/http.h\nindex da4d8589d8..29acfe8c55 100644\n--- a/http.h\n+++ b/http.h\n@@ -10,6 +10,10 @@\n #include \"remote.h\"\n #include \"url.h\"\n \n+#if LIBCURL_VERSION_NUM < 0x071304\n+#error \"your libcurl version is too old; Git requires curl >= 7.19.4\"\n+#endif\n+\n #define DEFAULT_MAX_REQUESTS 5\n \n /*\n-- \n2.14.0.609.gd2d1f7ddf\n"},{"id":"325949","messageId":"871sokhoi9.fsf@gmail.com","threadId":"46547","inReplyTo":"20170809120201.2eagzkljervqeusx@sigill.intra.peff.net","subject":"Re: [PATCH 3/4] http: drop support for curl < 7.19.4","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2017-08-09T13:14:22Z","receivedAt":"2017-08-09T13:14:32Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"\nOn Wed, Aug 09 2017, Jeff King jotted:\n\n> Since v2.12.0, Git does not compile with versions of curl\n> older than 7.19.4. That version of curl is about 8 years\n> old. This means it may still be used in some distributions\n> with long-running support periods. But the fact that we\n> haven't received a single bug report about the compile-time\n> breakage implies that nobody cares about building recent\n> releases on such platforms.\n\nThis whole series looks good to me. As I commented on in the thread you\nreferenced in 0/4 I think this is the right trade-off, and people like\nme who occasionally compile git on older systems can just easily package\na newer curl as well if we need it.\n\nMy reading of the curl history/docs is that you should squash this into\nthis last patch. It's code that's now dead since we require\n7.19.4.\n\nCURLAUTH_DIGEST_IE was added in 7.19.3, and as a comment this squash\nremoves indicates CURLOPT_USE_SSL hasn't been needed since 7.16.4:\nhttps://curl.haxx.se/libcurl/c/CURLOPT_USE_SSL.html\n\ndiff --git a/http.c b/http.c\nindex 5280511c74..527bc56dc2 100644\n--- a/http.c\n+++ b/http.c\n@@ -103,9 +103,7 @@ static int http_auth_methods_restricted;\n /* Modes for which empty_auth cannot actually help us. */\n static unsigned long empty_auth_useless =\n        CURLAUTH_BASIC\n-#ifdef CURLAUTH_DIGEST_IE\n        | CURLAUTH_DIGEST_IE\n-#endif\n        | CURLAUTH_DIGEST;\n\n static struct curl_slist *pragma_header;\n@@ -706,10 +704,8 @@ static CURL *get_curl_handle(void)\n        if (curl_ftp_no_epsv)\n                curl_easy_setopt(result, CURLOPT_FTP_USE_EPSV, 0);\n\n-#ifdef CURLOPT_USE_SSL\n        if (curl_ssl_try)\n                curl_easy_setopt(result, CURLOPT_USE_SSL, CURLUSESSL_TRY);\n-#endif\n\n        /*\n         * CURL also examines these variables as a fallback; but we need to query\ndiff --git a/http.h b/http.h\nindex 29acfe8c55..66d2d3c539 100644\n--- a/http.h\n+++ b/http.h\n@@ -16,15 +16,6 @@\n\n #define DEFAULT_MAX_REQUESTS 5\n\n-/*\n- * CURLOPT_USE_SSL was known as CURLOPT_FTP_SSL up to 7.16.4,\n- * and the constants were known as CURLFTPSSL_*\n-*/\n-#if !defined(CURLOPT_USE_SSL) && defined(CURLOPT_FTP_SSL)\n-#define CURLOPT_USE_SSL CURLOPT_FTP_SSL\n-#define CURLUSESSL_TRY CURLFTPSSL_TRY\n-#endif\n-\n struct slot_results {\n        CURLcode curl_result;\n        long http_code;\n"},{"id":"325950","messageId":"20170809133844.3h7plxm6nzoheckv@sigill.intra.peff.net","threadId":"46547","inReplyTo":"871sokhoi9.fsf@gmail.com","subject":"Re: [PATCH 3/4] http: drop support for curl < 7.19.4","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2017-08-09T13:38:44Z","receivedAt":"2017-08-09T13:38:51Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Wed, Aug 09, 2017 at 03:14:22PM +0200, Ævar Arnfjörð Bjarmason wrote:\n\n> This whole series looks good to me. As I commented on in the thread you\n> referenced in 0/4 I think this is the right trade-off, and people like\n> me who occasionally compile git on older systems can just easily package\n> a newer curl as well if we need it.\n> \n> My reading of the curl history/docs is that you should squash this into\n> this last patch. It's code that's now dead since we require\n> 7.19.4.\n> \n> CURLAUTH_DIGEST_IE was added in 7.19.3, and as a comment this squash\n> removes indicates CURLOPT_USE_SSL hasn't been needed since 7.16.4:\n> https://curl.haxx.se/libcurl/c/CURLOPT_USE_SSL.html\n\nThanks. Do you mind formatting this as a patch on top instead of a\nsquash? I think it's sufficiently subtle that it should be separate from\nthe main cleanup, which is just dropping our own internal #ifdefs.\n\nI guess that would make reverting harder, though.\n\n-Peff\n"},{"id":"325951","messageId":"20170809134937.10725-1-avarab@gmail.com","threadId":"46547","inReplyTo":"20170809133844.3h7plxm6nzoheckv@sigill.intra.peff.net","subject":"[PATCH 5/4] curl: remove ifdef'd code never used with curl >=7.19.4","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2017-08-09T13:49:37Z","receivedAt":"2017-08-09T13:49:53Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"As the LIBCURL_VERSION_NUM check at the top of http.h shows we require\ncurl >= 7.19.4. This means we can remove previously added ifdef's\nneeded to support older curl versions.\n\nThe CURLAUTH_DIGEST_IE macro conditionally used since [1] was added in\n7.19.3 (see CURLOPT_HTTPAUTH(3)).\n\nThe CURLOPT_USE_SSL macro used since [2] was added in 7.16.4 (see\nCURLOPT_USE_SSL(3)).\n\n1. 40a18fc77c (\"http: add an \"auto\" mode for http.emptyauth\",\n   2017-02-25)\n2. 4bc444eb64 (\"Support FTP-over-SSL/TLS for regular FTP\", 2013-04-07)\n\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n\nOn Wed, Aug 9, 2017 at 3:38 PM, Jeff King <peff@peff.net> wrote:\n> On Wed, Aug 09, 2017 at 03:14:22PM +0200, Ævar Arnfjörð Bjarmason wrote:\n>\n>> This whole series looks good to me. As I commented on in the thread you\n>> referenced in 0/4 I think this is the right trade-off, and people like\n>> me who occasionally compile git on older systems can just easily package\n>> a newer curl as well if we need it.\n>>\n>> My reading of the curl history/docs is that you should squash this into\n>> this last patch. It's code that's now dead since we require\n>> 7.19.4.\n>>\n>> CURLAUTH_DIGEST_IE was added in 7.19.3, and as a comment this squash\n>> removes indicates CURLOPT_USE_SSL hasn't been needed since 7.16.4:\n>> https://curl.haxx.se/libcurl/c/CURLOPT_USE_SSL.html\n>\n> Thanks. Do you mind formatting this as a patch on top instead of a\n> squash? I think it's sufficiently subtle that it should be separate from\n> the main cleanup, which is just dropping our own internal #ifdefs.\n\nNo problem. Here it is. Intended to be placed after your 4/4 since the\ncommit message references the new error message in http.h.\n\n http.c | 4 ----\n http.h | 9 ---------\n 2 files changed, 13 deletions(-)\n\ndiff --git a/http.c b/http.c\nindex 5280511c74..527bc56dc2 100644\n--- a/http.c\n+++ b/http.c\n@@ -103,9 +103,7 @@ static int http_auth_methods_restricted;\n /* Modes for which empty_auth cannot actually help us. */\n static unsigned long empty_auth_useless =\n \tCURLAUTH_BASIC\n-#ifdef CURLAUTH_DIGEST_IE\n \t| CURLAUTH_DIGEST_IE\n-#endif\n \t| CURLAUTH_DIGEST;\n \n static struct curl_slist *pragma_header;\n@@ -706,10 +704,8 @@ static CURL *get_curl_handle(void)\n \tif (curl_ftp_no_epsv)\n \t\tcurl_easy_setopt(result, CURLOPT_FTP_USE_EPSV, 0);\n \n-#ifdef CURLOPT_USE_SSL\n \tif (curl_ssl_try)\n \t\tcurl_easy_setopt(result, CURLOPT_USE_SSL, CURLUSESSL_TRY);\n-#endif\n \n \t/*\n \t * CURL also examines these variables as a fallback; but we need to query\ndiff --git a/http.h b/http.h\nindex 29acfe8c55..66d2d3c539 100644\n--- a/http.h\n+++ b/http.h\n@@ -16,15 +16,6 @@\n \n #define DEFAULT_MAX_REQUESTS 5\n \n-/*\n- * CURLOPT_USE_SSL was known as CURLOPT_FTP_SSL up to 7.16.4,\n- * and the constants were known as CURLFTPSSL_*\n-*/\n-#if !defined(CURLOPT_USE_SSL) && defined(CURLOPT_FTP_SSL)\n-#define CURLOPT_USE_SSL CURLOPT_FTP_SSL\n-#define CURLUSESSL_TRY CURLFTPSSL_TRY\n-#endif\n-\n struct slot_results {\n \tCURLcode curl_result;\n \tlong http_code;\n-- \n2.14.0.rc1.383.gd1ce394fe2\n\n"},{"id":"325968","messageId":"CAGZ79kYUn_V81pRHsAuOoqNOpjfnng2NqLu7jPK93GM=LuvywQ@mail.gmail.com","threadId":"46547","inReplyTo":"20170809120157.il4ktf75wscqoyic@sigill.intra.peff.net","subject":"Re: [PATCH 2/4] http: drop support for curl < 7.16.0","fromName":"Stefan Beller","fromEmail":"sbeller@google.com","sentAt":"2017-08-09T17:29:04Z","receivedAt":"2017-08-09T17:29:12Z","isPatch":true,"sender":{"key":"stefanbeller@gmail.com","avatar":"https://avatars.githubusercontent.com/u/455868?v=4"},"body":"On Wed, Aug 9, 2017 at 5:01 AM, Jeff King <peff@peff.net> wrote:\n> As discussed in the previous commit, Git is not well-tested\n> with old versions of curl (and in fact since v2.12.0 does\n> not even compile with versions older than 7.19.4). Let's\n> stop pretending we support curl that old and drop any\n> now-obslete #ifdefs.\n>\n> Choosing 7.16.0 is a somewhat arbitrary cutoff, but:\n>\n>   1. it came out in October of 2006, over 10 years ago.\n>      Besides being a nice round number, it's a common\n>      end-of-life support period, even for conservative\n>      distributions.\n>\n>   2. that version introduced the curl_multi interface, which\n>      gives us a lot of bang for the buck in removing #ifdefs\n>\n> Signed-off-by: Jeff King <peff@peff.net>\n> ---\n>  Documentation/config.txt |  3 +--\n>  http-push.c              | 23 --------------------\n>  http-walker.c            | 12 -----------\n>  http.c                   | 56 +-----------------------------------------------\n>  http.h                   | 20 +----------------\n>  remote-curl.c            |  4 ----\n>  6 files changed, 3 insertions(+), 115 deletions(-)\n\n`git grep USE_CURL_MULTI` also yields\nDocumentation/config.txt\nt/t5540-http-push-webdav.sh\n\nWould these also need adaption in this patch?\n"},{"id":"325969","messageId":"CAGZ79kZ-Ra6MCvvq-dqnsXowmykBt9ghqUgHgzSC_zt=Q1_=CA@mail.gmail.com","threadId":"46547","inReplyTo":"20170809120201.2eagzkljervqeusx@sigill.intra.peff.net","subject":"Re: [PATCH 3/4] http: drop support for curl < 7.19.4","fromName":"Stefan Beller","fromEmail":"sbeller@google.com","sentAt":"2017-08-09T17:34:09Z","receivedAt":"2017-08-09T17:34:17Z","isPatch":true,"sender":{"key":"stefanbeller@gmail.com","avatar":"https://avatars.githubusercontent.com/u/455868?v=4"},"body":"On Wed, Aug 9, 2017 at 5:02 AM, Jeff King <peff@peff.net> wrote:\n> Since v2.12.0, Git does not compile with versions of curl\n> older than 7.19.4. That version of curl is about 8 years\n> old. This means it may still be used in some distributions\n> with long-running support periods. But the fact that we\n> haven't received a single bug report about the compile-time\n> breakage implies that nobody cares about building recent\n> releases on such platforms.\n\nI would not state it as bland, see how\nhttps://public-inbox.org/git/20170806233850.14711-1-avarab@gmail.com/\ncame here to the mailing list.\n\n\n> As discussed in the previous two commits, this cleans up the\n> code and gives a more realistic signal to users about which\n> versions of Git are actually tested (in particular, this\n> moves us past the potential use-after-free issues with curl\n> older than 7.17.0).\n\nThis is a good reason for this patch, though, so maybe just elide\nthe \"nobody cares\" part?\n\nThanks for these cleanups!\n"},{"id":"325970","messageId":"CAGZ79kai_d4sU0D-oR=VpGQea6ZGVTsFd7P5Ch8VqQyc4h5obA@mail.gmail.com","threadId":"46547","inReplyTo":"20170809120207.amjpwhxz3evjci6x@sigill.intra.peff.net","subject":"Re: [PATCH 4/4] http: #error on too-old curl","fromName":"Stefan Beller","fromEmail":"sbeller@google.com","sentAt":"2017-08-09T17:37:45Z","receivedAt":"2017-08-09T17:37:52Z","isPatch":true,"sender":{"key":"stefanbeller@gmail.com","avatar":"https://avatars.githubusercontent.com/u/455868?v=4"},"body":"On Wed, Aug 9, 2017 at 5:02 AM, Jeff King <peff@peff.net> wrote:\n> We already fail to build with versions of curl older than\n> 7.19.4. But doing an explicit check with an #error has two\n> benefits.\n>\n> One is that it makes it clear to users that the build\n> failure is intentional, so they don't waste time trying to\n> debug it.\n>\n> And two is that it documents our current \"too old\"\n> assumption, so that we know whether we need use an #ifdef\n> when using newer curl features in future patches.\n>\n> Signed-off-by: Jeff King <peff@peff.net>\n> ---\n>  http.h | 4 ++++\n>  1 file changed, 4 insertions(+)\n>\n> diff --git a/http.h b/http.h\n> index da4d8589d8..29acfe8c55 100644\n> --- a/http.h\n> +++ b/http.h\n> @@ -10,6 +10,10 @@\n>  #include \"remote.h\"\n>  #include \"url.h\"\n>\n> +#if LIBCURL_VERSION_NUM < 0x071304\n\nOh, it's hex. 0x13 == 19. Makes sense.\n\nThanks,\nStefan\n"},{"id":"325971","messageId":"xmqq1sok7i82.fsf@gitster.mtv.corp.google.com","threadId":"46547","inReplyTo":"20170809120157.il4ktf75wscqoyic@sigill.intra.peff.net","subject":"Re: [PATCH 2/4] http: drop support for curl < 7.16.0","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2017-08-09T17:40:13Z","receivedAt":"2017-08-09T17:40:23Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Jeff King <peff@peff.net> writes:\n\n> -#if LIBCURL_VERSION_NUM >= 0x071700\n> -/* Use CURLOPT_KEYPASSWD as is */\n> -#elif LIBCURL_VERSION_NUM >= 0x070903\n> -#define CURLOPT_KEYPASSWD CURLOPT_SSLKEYPASSWD\n> -#else\n> -#define CURLOPT_KEYPASSWD CURLOPT_SSLCERTPASSWD\n> -#endif\n> -\n\nThis part I am not sure.  Don't we still need to substitute\nCURLOPT_KEYPASSWD with CURLOPT_SSLKEYPASSWD for versions below\n071700, e.g. 071000 which is 7.16.0?\n"},{"id":"325975","messageId":"38dfdc54-65ea-694a-4b72-fe0006a008cf@suse.de","threadId":"46547","inReplyTo":"xmqq1sok7i82.fsf@gitster.mtv.corp.google.com","subject":"Re: [PATCH 2/4] http: drop support for curl < 7.16.0","fromName":"Nicolas Morey-Chaisemartin","fromEmail":"nmoreychaisemartin@suse.de","sentAt":"2017-08-09T18:03:05Z","receivedAt":"2017-08-09T18:03:19Z","isPatch":true,"sender":{"key":"nmoreychaisemartin@suse.de","avatar":"https://gravatar.com/avatar/5546322ccb9067f56b6939d9d5c758a40cab5b978b1379fd6ec8ab9b8a6a12b1?d=mp&s=160"},"body":"\n\nLe 09/08/2017 à 19:40, Junio C Hamano a écrit :\n> Jeff King <peff@peff.net> writes:\n>\n>> -#if LIBCURL_VERSION_NUM >= 0x071700\n>> -/* Use CURLOPT_KEYPASSWD as is */\n>> -#elif LIBCURL_VERSION_NUM >= 0x070903\n>> -#define CURLOPT_KEYPASSWD CURLOPT_SSLKEYPASSWD\n>> -#else\n>> -#define CURLOPT_KEYPASSWD CURLOPT_SSLCERTPASSWD\n>> -#endif\n>> -\n> This part I am not sure.  Don't we still need to substitute\n> CURLOPT_KEYPASSWD with CURLOPT_SSLKEYPASSWD for versions below\n> 071700, e.g. 071000 which is 7.16.0?\nAccording to the documentation:\n\nhttps://curl.haxx.se/libcurl/c/CURLOPT_KEYPASSWD.html\nThis option was known as CURLOPT_SSLKEYPASSWD up to 7.16.4 and CURLOPT_SSLCERTPASSWD up to 7.9.2.\n\n\nSo the patch breaks things (broken for 7.16.[0-4]). But the series does not as the next patch ensure at least 7.19.4\n\n\n"},{"id":"325986","messageId":"20170809211317.5znle4vq4zxf56af@sigill.intra.peff.net","threadId":"46547","inReplyTo":"CAGZ79kYUn_V81pRHsAuOoqNOpjfnng2NqLu7jPK93GM=LuvywQ@mail.gmail.com","subject":"Re: [PATCH 2/4] http: drop support for curl < 7.16.0","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2017-08-09T21:13:18Z","receivedAt":"2017-08-09T21:13:25Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Wed, Aug 09, 2017 at 10:29:04AM -0700, Stefan Beller wrote:\n\n> >  Documentation/config.txt |  3 +--\n> >  http-push.c              | 23 --------------------\n> >  http-walker.c            | 12 -----------\n> >  http.c                   | 56 +-----------------------------------------------\n> >  http.h                   | 20 +----------------\n> >  remote-curl.c            |  4 ----\n> >  6 files changed, 3 insertions(+), 115 deletions(-)\n> \n> `git grep USE_CURL_MULTI` also yields\n> Documentation/config.txt\n> t/t5540-http-push-webdav.sh\n> \n> Would these also need adaption in this patch?\n\nThat one threw me off for a minute. How does a test even know about\nUSE_CURL_MULTI?\n\nBut it is just a bad error message. :) You cannot fix it by compiling\nwith \"make USE_CURL_MULTI=1\". The right message is more like \"skipping\nhttp-push tests, your curl is too old\".\n\nBut that does mean there's another problem: Makefile can drop its\nconditional curl_check for http-push.o. I'll add that to a re-roll.\n\n-Peff\n"},{"id":"325987","messageId":"20170809211520.djwrqds5b2yzmix5@sigill.intra.peff.net","threadId":"46547","inReplyTo":"xmqq1sok7i82.fsf@gitster.mtv.corp.google.com","subject":"Re: [PATCH 2/4] http: drop support for curl < 7.16.0","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2017-08-09T21:15:21Z","receivedAt":"2017-08-09T21:15:27Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Wed, Aug 09, 2017 at 10:40:13AM -0700, Junio C Hamano wrote:\n\n> Jeff King <peff@peff.net> writes:\n> \n> > -#if LIBCURL_VERSION_NUM >= 0x071700\n> > -/* Use CURLOPT_KEYPASSWD as is */\n> > -#elif LIBCURL_VERSION_NUM >= 0x070903\n> > -#define CURLOPT_KEYPASSWD CURLOPT_SSLKEYPASSWD\n> > -#else\n> > -#define CURLOPT_KEYPASSWD CURLOPT_SSLCERTPASSWD\n> > -#endif\n> > -\n> \n> This part I am not sure.  Don't we still need to substitute\n> CURLOPT_KEYPASSWD with CURLOPT_SSLKEYPASSWD for versions below\n> 071700, e.g. 071000 which is 7.16.0?\n\nYeah, you're right. I'm not sure how I botched that.\n\nThanks for reading carefully. I'll fix it in a re-roll.\n\n-Peff\n"},{"id":"325988","messageId":"20170809211734.dcyo2gppznzk6kng@sigill.intra.peff.net","threadId":"46547","inReplyTo":"38dfdc54-65ea-694a-4b72-fe0006a008cf@suse.de","subject":"Re: [PATCH 2/4] http: drop support for curl < 7.16.0","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2017-08-09T21:17:35Z","receivedAt":"2017-08-09T21:17:42Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Wed, Aug 09, 2017 at 08:03:05PM +0200, Nicolas Morey-Chaisemartin wrote:\n\n> >> -#if LIBCURL_VERSION_NUM >= 0x071700\n> >> -/* Use CURLOPT_KEYPASSWD as is */\n> >> -#elif LIBCURL_VERSION_NUM >= 0x070903\n> >> -#define CURLOPT_KEYPASSWD CURLOPT_SSLKEYPASSWD\n> >> -#else\n> >> -#define CURLOPT_KEYPASSWD CURLOPT_SSLCERTPASSWD\n> >> -#endif\n> >> -\n> > This part I am not sure.  Don't we still need to substitute\n> > CURLOPT_KEYPASSWD with CURLOPT_SSLKEYPASSWD for versions below\n> > 071700, e.g. 071000 which is 7.16.0?\n> According to the documentation:\n> \n> https://curl.haxx.se/libcurl/c/CURLOPT_KEYPASSWD.html\n> This option was known as CURLOPT_SSLKEYPASSWD up to 7.16.4 and\n> CURLOPT_SSLCERTPASSWD up to 7.9.2.\n> \n> \n> So the patch breaks things (broken for 7.16.[0-4]). But the series\n> does not as the next patch ensure at least 7.19.4\n\nBut the #ifdef above says 071700, which is 7.23.0. I wonder if we just\ngot it wrong back then (maybe hex confusion with 7.17.0?). I have a\nbuild setup for old versions of curl, so I'll double-check that 7.19.4\nbuilds with KEYPASSWD. And dig in the history to see if there's any\ncomment on this mismatch.\n\n-Peff\n"},{"id":"325989","messageId":"20170809211928.ubmhjuraguodcs7u@sigill.intra.peff.net","threadId":"46547","inReplyTo":"CAGZ79kZ-Ra6MCvvq-dqnsXowmykBt9ghqUgHgzSC_zt=Q1_=CA@mail.gmail.com","subject":"Re: [PATCH 3/4] http: drop support for curl < 7.19.4","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2017-08-09T21:19:29Z","receivedAt":"2017-08-09T21:19:35Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Wed, Aug 09, 2017 at 10:34:09AM -0700, Stefan Beller wrote:\n\n> On Wed, Aug 9, 2017 at 5:02 AM, Jeff King <peff@peff.net> wrote:\n> > Since v2.12.0, Git does not compile with versions of curl\n> > older than 7.19.4. That version of curl is about 8 years\n> > old. This means it may still be used in some distributions\n> > with long-running support periods. But the fact that we\n> > haven't received a single bug report about the compile-time\n> > breakage implies that nobody cares about building recent\n> > releases on such platforms.\n> \n> I would not state it as bland, see how\n> https://public-inbox.org/git/20170806233850.14711-1-avarab@gmail.com/\n> came here to the mailing list.\n\nHeh, I almost added \"Or they are happy patching Git themselves\". This\n_does_ make patching Git harder for them, because now there are a lot\nmore spots to patch.\n\n> > As discussed in the previous two commits, this cleans up the\n> > code and gives a more realistic signal to users about which\n> > versions of Git are actually tested (in particular, this\n> > moves us past the potential use-after-free issues with curl\n> > older than 7.17.0).\n> \n> This is a good reason for this patch, though, so maybe just elide\n> the \"nobody cares\" part?\n\nI think I'd rather elaborate than elide. One of the reasons to split\nthis into multiple patches is that it's a ready-made patch for a\ndistributor to apply (in reverse) if they really want to.\n\n-Peff\n"},{"id":"325991","messageId":"7468c434-88ca-48de-0bda-894baf8020f2@suse.de","threadId":"46547","inReplyTo":"20170809211734.dcyo2gppznzk6kng@sigill.intra.peff.net","subject":"Re: [PATCH 2/4] http: drop support for curl < 7.16.0","fromName":"Nicolas Morey-Chaisemartin","fromEmail":"nmoreychaisemartin@suse.de","sentAt":"2017-08-09T21:29:30Z","receivedAt":"2017-08-09T21:29:39Z","isPatch":true,"sender":{"key":"nmoreychaisemartin@suse.de","avatar":"https://gravatar.com/avatar/5546322ccb9067f56b6939d9d5c758a40cab5b978b1379fd6ec8ab9b8a6a12b1?d=mp&s=160"},"body":"\n\nLe 09/08/2017 à 23:17, Jeff King a écrit :\n> On Wed, Aug 09, 2017 at 08:03:05PM +0200, Nicolas Morey-Chaisemartin wrote:\n>\n>>>> -#if LIBCURL_VERSION_NUM >= 0x071700\n>>>> -/* Use CURLOPT_KEYPASSWD as is */\n>>>> -#elif LIBCURL_VERSION_NUM >= 0x070903\n>>>> -#define CURLOPT_KEYPASSWD CURLOPT_SSLKEYPASSWD\n>>>> -#else\n>>>> -#define CURLOPT_KEYPASSWD CURLOPT_SSLCERTPASSWD\n>>>> -#endif\n>>>> -\n>>> This part I am not sure.  Don't we still need to substitute\n>>> CURLOPT_KEYPASSWD with CURLOPT_SSLKEYPASSWD for versions below\n>>> 071700, e.g. 071000 which is 7.16.0?\n>> According to the documentation:\n>>\n>> https://curl.haxx.se/libcurl/c/CURLOPT_KEYPASSWD.html\n>> This option was known as CURLOPT_SSLKEYPASSWD up to 7.16.4 and\n>> CURLOPT_SSLCERTPASSWD up to 7.9.2.\n>>\n>>\n>> So the patch breaks things (broken for 7.16.[0-4]). But the series\n>> does not as the next patch ensure at least 7.19.4\n> But the #ifdef above says 071700, which is 7.23.0. I wonder if we just\n> got it wrong back then (maybe hex confusion with 7.17.0?). I have a\n> build setup for old versions of curl, so I'll double-check that 7.19.4\n> builds with KEYPASSWD. And dig in the history to see if there's any\n> comment on this mismatch.\n>\n> -Peff\nIt seems to be a decimal/hex issue:\ndocs/libcurl/symbols-in-versions:153:CURLOPT_KEYPASSWD               7.17.0\n\nI guess it should still work because it is now defined like this:\ncurl.h:#define CURLOPT_SSLKEYPASSWD CURLOPT_KEYPASSWD\n\nIf I'm not mistaken on cpp behaviour it means CURLOPT_KEYPASSWD is evaluated to CURLOPT_SSLKEYPASSWD (git define) which is evaluated into CURLOPT_KEYPASSWD (curl define).\nIt should stop here as CURLOPT_KEYPASSWD was not a defined macro when the curl one was evaluated.\nIt might be worth cleaning though, specially it wouldn't work anymore if the git macro is ever moved before the curl include.\n\nNicolas\n\n\n"},{"id":"325993","messageId":"alpine.DEB.2.21.1.1708092337350.11175@virtualbox","threadId":"46547","inReplyTo":"20170809120024.7phdjzjv54uv5dpz@sigill.intra.peff.net","subject":"Re: [PATCH 0/4] dropping support for older curl","fromName":"Johannes Schindelin","fromEmail":"johannes.schindelin@gmx.de","sentAt":"2017-08-09T21:42:12Z","receivedAt":"2017-08-09T21:42:22Z","isPatch":true,"sender":{"key":"johannes.schindelin@gmx.de","avatar":"https://avatars.githubusercontent.com/u/127790?v=4"},"body":"Hi Peff,\n\nOn Wed, 9 Aug 2017, Jeff King wrote:\n\n> This is a resurrection of the thread from April:\n> \n>   https://public-inbox.org/git/20170404025438.bgxz5sfmrawqswcj@sigill.intra.peff.net/\n\nAs before, I would like to point out that people running with older cURL\nare most likely not at liberty to change the system libraries.\n\nI know that I didn't when I was working on a very expensive microscope\nwhose only certified control computer ran a very old version of CentOS,\nand I really needed to install Git on it.\n\nIn such a case, it is often preferable to be able to build against an old\ncURL -- even if some of the fancier features might be broken, and even if\nsome minor compile errors need to be fixed.\n\nI know I was happy to compile Git against an ancient cURL back then.\n\nJust so you understand where I come from when I would like to caution\nagainst dropping support for older cURL unless it *really* adds an\n*enormous* amount of maintenance burden.\n\nI mean, if we even go out of our way to support the completely outdated\nand obsolete .git/branches/ for what is likely a single user, it may not\nbe the worst to keep those couple of #ifdef guards to keep at least\nnominal support for older cURLs?\n\nCiao,\nDscho\n"},{"id":"325994","messageId":"20170809214758.p77fqrwxanb4zn5a@sigill.intra.peff.net","threadId":"46547","inReplyTo":"alpine.DEB.2.21.1.1708092337350.11175@virtualbox","subject":"Re: [PATCH 0/4] dropping support for older curl","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2017-08-09T21:47:58Z","receivedAt":"2017-08-09T21:48:06Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Wed, Aug 09, 2017 at 11:42:12PM +0200, Johannes Schindelin wrote:\n\n> > This is a resurrection of the thread from April:\n> > \n> >   https://public-inbox.org/git/20170404025438.bgxz5sfmrawqswcj@sigill.intra.peff.net/\n> \n> As before, I would like to point out that people running with older cURL\n> are most likely not at liberty to change the system libraries.\n> \n> I know that I didn't when I was working on a very expensive microscope\n> whose only certified control computer ran a very old version of CentOS,\n> and I really needed to install Git on it.\n> \n> In such a case, it is often preferable to be able to build against an old\n> cURL -- even if some of the fancier features might be broken, and even if\n> some minor compile errors need to be fixed.\n> \n> I know I was happy to compile Git against an ancient cURL back then.\n> \n> Just so you understand where I come from when I would like to caution\n> against dropping support for older cURL unless it *really* adds an\n> *enormous* amount of maintenance burden.\n> \n> I mean, if we even go out of our way to support the completely outdated\n> and obsolete .git/branches/ for what is likely a single user, it may not\n> be the worst to keep those couple of #ifdef guards to keep at least\n> nominal support for older cURLs?\n\nYou've totally ignored the argument I made back then[1], and which I\nreiterated in this thread. So I'll say it one more time: the more\ncompelling reason is not the #ifdefs, but the fact that the older\nversions are totally untested.  In fact, they do not even compile, and\nyet I have not seen any patches to fix that.\n\nSo IMHO this is about being honest with users about which versions we\n_actually_ support.\n\n-Peff\n\n[1] https://public-inbox.org/git/20170410182215.figy7hm4sogwipyz@sigill.intra.peff.net/\n"},{"id":"325995","messageId":"20170809214945.jx2tqbs72g5hwsau@sigill.intra.peff.net","threadId":"46547","inReplyTo":"7468c434-88ca-48de-0bda-894baf8020f2@suse.de","subject":"Re: [PATCH 2/4] http: drop support for curl < 7.16.0","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2017-08-09T21:49:45Z","receivedAt":"2017-08-09T21:49:51Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Wed, Aug 09, 2017 at 11:29:30PM +0200, Nicolas Morey-Chaisemartin wrote:\n\n> > But the #ifdef above says 071700, which is 7.23.0. I wonder if we just\n> > got it wrong back then (maybe hex confusion with 7.17.0?). I have a\n> > build setup for old versions of curl, so I'll double-check that 7.19.4\n> > builds with KEYPASSWD. And dig in the history to see if there's any\n> > comment on this mismatch.\n>\n> It seems to be a decimal/hex issue:\n> docs/libcurl/symbols-in-versions:153:CURLOPT_KEYPASSWD               7.17.0\n> \n> I guess it should still work because it is now defined like this:\n> curl.h:#define CURLOPT_SSLKEYPASSWD CURLOPT_KEYPASSWD\n> \n> If I'm not mistaken on cpp behaviour it means CURLOPT_KEYPASSWD is\n> evaluated to CURLOPT_SSLKEYPASSWD (git define) which is evaluated into\n> CURLOPT_KEYPASSWD (curl define).\n>\n> It should stop here as CURLOPT_KEYPASSWD was not a defined macro when\n> the curl one was evaluated.  It might be worth cleaning though,\n> specially it wouldn't work anymore if the git macro is ever moved\n> before the curl include.\n\nHmph. That makes me think the original should have just been using\nCURLOPT_SSLKEYPASSWD through the code, if curl was providing\na backwards-compatible macro. But it won't matter either way if we just\nget rid of it. :)\n\nThanks for digging up the curl history.\n\n-Peff\n"},{"id":"326004","messageId":"874ltg2tvo.fsf@gmail.com","threadId":"46547","inReplyTo":"alpine.DEB.2.21.1.1708092337350.11175@virtualbox","subject":"Re: [PATCH 0/4] dropping support for older curl","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2017-08-09T23:39:39Z","receivedAt":"2017-08-09T23:39:47Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"\nOn Wed, Aug 09 2017, Johannes Schindelin jotted:\n\n> Hi Peff,\n>\n> On Wed, 9 Aug 2017, Jeff King wrote:\n>\n>> This is a resurrection of the thread from April:\n>>\n>>   https://public-inbox.org/git/20170404025438.bgxz5sfmrawqswcj@sigill.intra.peff.net/\n>\n> As before, I would like to point out that people running with older cURL\n> are most likely not at liberty to change the system libraries.\n>\n> I know that I didn't when I was working on a very expensive microscope\n> whose only certified control computer ran a very old version of CentOS,\n> and I really needed to install Git on it.\n>\n> In such a case, it is often preferable to be able to build against an old\n> cURL -- even if some of the fancier features might be broken, and even if\n> some minor compile errors need to be fixed.\n>\n> I know I was happy to compile Git against an ancient cURL back then.\n>\n> Just so you understand where I come from when I would like to caution\n> against dropping support for older cURL unless it *really* adds an\n> *enormous* amount of maintenance burden.\n>\n> I mean, if we even go out of our way to support the completely outdated\n> and obsolete .git/branches/ for what is likely a single user, it may not\n> be the worst to keep those couple of #ifdef guards to keep at least\n> nominal support for older cURLs?\n\nI too compile against ancient CentOS crap often where I need a newer\nlibrary and upgrading the system library is not an option, and the\nproblem you're describing is easily solved.\n\nYou grab the source RPM for e.g. curl, search-replace both the package\nname and the installation paths to something else, e.g. name it\navar-curl and install it in /usr/local/avar-curl/{lib,bin,include}, then\nmake your new git package {Requires,BuildRequires}: avar-curl{,-dev}.\n\nYou then get a brand new curl on your system without touching anything\nthat needed the ancient system-library curl, because your new custom\ncurl lives under other paths, you then compile the package you actually\nwanted against those.\n\nIs it painless? No, of course it would be easier for me if I could just\n\"yum upgrade\" and every package tested all 10 year old versions of their\ndependencies, but it's often not realistic that they do that.\n\nIt usually takes no more than 10 minutes to give a package this\ntreatment, since I can usually grab a SRPM that already works for that\nOS version, I just need to change the name & installation paths.\n\nAt $WORK we have hundreds of RPMs that have been given this treatment\nfor one reason or another.\n\nSome of those are because upstream has decided to support the stuff\nfound on our systems. In some cases it's trivial to fix and they're\nwilling to take a patch, but in other cases it's reasonable of them to\nsay \"just upgrade\". I think looking at the diffstat of this series that\nthis is such a case, especially given Jeff's argument in\n20170809214758.p77fqrwxanb4zn5a@sigill.intra.peff.net\n"},{"id":"326020","messageId":"alpine.DEB.2.21.1.1708101111080.11175@virtualbox","threadId":"46547","inReplyTo":"20170809214758.p77fqrwxanb4zn5a@sigill.intra.peff.net","subject":"Re: [PATCH 0/4] dropping support for older curl","fromName":"Johannes Schindelin","fromEmail":"johannes.schindelin@gmx.de","sentAt":"2017-08-10T09:36:41Z","receivedAt":"2017-08-10T09:36:58Z","isPatch":true,"sender":{"key":"johannes.schindelin@gmx.de","avatar":"https://avatars.githubusercontent.com/u/127790?v=4"},"body":"Hi Peff,\n\nOn Wed, 9 Aug 2017, Jeff King wrote:\n\n> On Wed, Aug 09, 2017 at 11:42:12PM +0200, Johannes Schindelin wrote:\n> \n> > > This is a resurrection of the thread from April:\n> > > \n> > >   https://public-inbox.org/git/20170404025438.bgxz5sfmrawqswcj@sigill.intra.peff.net/\n> > \n> > As before, I would like to point out that people running with older cURL\n> > are most likely not at liberty to change the system libraries.\n> > \n> > I know that I didn't when I was working on a very expensive microscope\n> > whose only certified control computer ran a very old version of CentOS,\n> > and I really needed to install Git on it.\n> > \n> > In such a case, it is often preferable to be able to build against an old\n> > cURL -- even if some of the fancier features might be broken, and even if\n> > some minor compile errors need to be fixed.\n> > \n> > I know I was happy to compile Git against an ancient cURL back then.\n> > \n> > Just so you understand where I come from when I would like to caution\n> > against dropping support for older cURL unless it *really* adds an\n> > *enormous* amount of maintenance burden.\n> > \n> > I mean, if we even go out of our way to support the completely outdated\n> > and obsolete .git/branches/ for what is likely a single user, it may not\n> > be the worst to keep those couple of #ifdef guards to keep at least\n> > nominal support for older cURLs?\n> \n> You've totally ignored the argument I made back then[1], and which I\n> reiterated in this thread. So I'll say it one more time: the more\n> compelling reason is not the #ifdefs, but the fact that the older\n> versions are totally untested.  In fact, they do not even compile, and\n> yet I have not seen any patches to fix that.\n\nLet me re-quote from above:\n\n> > In such a case, it is often preferable to be able to build against an\n> > old cURL -- even if some of the fancier features might be broken, and\n> > even if some minor compile errors need to be fixed.\n\nAs far as I remember, I *did* have to fix a minor compile error.  Took\nsomething like 15 minutes from first compile error to fully running test\nsuite.\n\nCompare that effort to the effort of compiling a current cURL, possibly\nhaving to compile newer c-ares, spdylay, jansson, nghttp2, openssl,\nnettle, libunistring, libtasn1, libidn, libmetalink, rtmpdump and whatever\nelse.\n\n> So IMHO this is about being honest with users about which versions we\n> _actually_ support.\n\nWe will most likely never, ever have a fully 100% bug free system. That\ndoes not mean that we should rip out everything that is not totally,\ncompletely working.\n\nInstead, we try [*1*] to welcome patches.\n\nI can buy some argument like: this support is so invasive, so brittle, and\nnobody takes care of it, and if it breaks, it is hard to fix, and those\nwho could, won't, so let's remove it.\n\nThat argument is why Git for Windows dropped XP support.\n\nI cannot buy the argument: there are a dozen #ifdefs and I don't know\nwhether they still work. I don't know whether anybody (who most likely has\nbetter things to do than read the Git mailing list) is still using those.\nSo let's just remove them.\n\nThat argument was what let us go overboard, and actually go too far by\nremoving the fallback when REG_STARTEND is missing, even while fixing a\nvery real bug. And that overzealous action hurt users. It also cost *us*\ntime, having to deal with the ensuing conversation, but we deserved to be\npaying for this, the users didn't.\n\nI did not have time to look closely over your patches to remove cURL\nsupport for older versions. From a cursory look, I did not get the\nimpression that there is a lot of maintenance burden there, though.\nTherefore, I currently believe that the downsides of removing the support\noutweigh the benefits.\n\nMind, I agree that cURL should be upgrade to version 7.55.0 wherever\npossible. But it is a huge mistake to assume that everybody who wants to\nbuild, or just use, Git is at liberty to perform that upgrade in their\nsetup. To make that assumption is really harmful to users who are stuck in\na bad place out of no fault of their own. It is also not very nice.\n\nHopefully I had better luck expressing my concerns this time?\n\nCiao,\nDscho\n\nFootnote *1*: It is no secret that I find our patch submission less than\ninviting. Granted, *I* use it. *I* did not have problems entering the\nmailing list. But then, my mails were not swallowed silently, because my\nmail program does not send HTML by default. And prepared by the German\nschool system (I learned the term \"sugar coating\" only when exposed to\nsome US culture), I had little emotional problems with being criticized\nand not thanked for my contribution, I persisted nevertheless. The opinion\nthat the Git contribution process is a lot less inviting than it could be\nis not only my view, by the way. I hear this a lot. I give you that we are\nnot quite as textbook \"keep out from here unless you look like us, smell\nlike us, talk like us, have the same genital setup like us\" as the Linux\nkernel mailing list, but we are in a different universe compared to, say,\nthe Drupal community. And their universe is a lot nicer to live in.\n"},{"id":"326024","messageId":"69dba5a3-b9e5-15b2-ca7c-8720da6c3b62@jupiterrise.com","threadId":"46547","inReplyTo":"87zib8g8ub.fsf@gmail.com","subject":"Re: Dropping support for older perl","fromName":"Tom G. Christensen","fromEmail":"tgc@jupiterrise.com","sentAt":"2017-08-10T10:04:40Z","receivedAt":"2017-08-10T10:04:51Z","isPatch":false,"sender":{"key":"tgc@jupiterrise.com","avatar":"https://avatars.githubusercontent.com/u/912180?v=4"},"body":"On 09/08/17 15:38, Ævar Arnfjörð Bjarmason wrote:\n\n> RHEL/CentOS 5.x has perl 5.8.8, but it also has curl 7.15.5[1] which is\n> obseleted by these curl patches. Maybe we'd want to be more conservative\n> with perl for whatever reason, but I'd like to at least bump our\n> requirenment of 5.8.0 to 5.8.8. Those releases are 4 years apart, and a\n> lot of bugs were fixed[2], and some constructs / modules have newer APIs\n> we could use.\n> \n> But if we do the thing corresponding to these curl patches we should\n> bump the dependency to 5.10.1, that was released in August 2009 (and the\n> curl version JK is bumping us to in March 2009), and 5.10.1 is shipped\n> with RHEL/CentOS 6.\n> \n\nI agree with your thoughts.\nThough I'm a bit biased since I only really care about RHEL/CentOS in \nthe context of being able to use vendor provided versions of curl and perl.\n\n> The bump to 5.10.1 may be a bad idea, I know AIX/HPUX/Solaris and some\n> others have historically been more conservative about upgrading perl\n> than stuff like libcurl since it's in the base system.\n> \n\nAFAIK it used to be common to build updated versions at least on Solaris.\nI provide perl 5.16.x and a recent curl for Solaris 2.6-9 as part of \ntgcware(1) and Solaris 10/11 users can use OpenCSW which seems to have \n5.10.1 available.\n\n-tgc\n\n1) https://jupiterrise.com/tgcware/\n"},{"id":"326026","messageId":"20170810123641.GG2363@shiar.net","threadId":"46547","inReplyTo":"20170809120201.2eagzkljervqeusx@sigill.intra.peff.net","subject":"Re: [PATCH 3/4] http: drop support for curl < 7.19.4","fromName":"Mischa POSLAWSKY","fromEmail":"git@shiar.nl","sentAt":"2017-08-10T12:36:41Z","receivedAt":"2017-08-10T12:36:51Z","isPatch":true,"sender":{"key":"git@shiar.nl","avatar":null},"body":"Jeff King wrote:\n> -#if LIBCURL_VERSION_NUM >= 0x071301\n>  \tcurl_easy_setopt(result, CURLOPT_POSTREDIR, CURL_REDIR_POST_ALL);\n> -#elif LIBCURL_VERSION_NUM >= 0x071101\n>  \tcurl_easy_setopt(result, CURLOPT_POST301, 1);\n> -#endif\n\nThis seems to be an unintended behavioural change: the second condition\nwouldn't have applied previously and overrides the first option\n(equivalent to CURLOPT_POSTREDIR = CURL_REDIR_POST_301).\n\n-- \nMischa\n"},{"id":"326039","messageId":"20170810173405.pz6afvevatydkatg@sigill.intra.peff.net","threadId":"46547","inReplyTo":"20170810123641.GG2363@shiar.net","subject":"Re: [PATCH 3/4] http: drop support for curl < 7.19.4","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2017-08-10T17:34:05Z","receivedAt":"2017-08-10T17:34:11Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Thu, Aug 10, 2017 at 02:36:41PM +0200, Mischa POSLAWSKY wrote:\n\n> Jeff King wrote:\n> > -#if LIBCURL_VERSION_NUM >= 0x071301\n> >  \tcurl_easy_setopt(result, CURLOPT_POSTREDIR, CURL_REDIR_POST_ALL);\n> > -#elif LIBCURL_VERSION_NUM >= 0x071101\n> >  \tcurl_easy_setopt(result, CURLOPT_POST301, 1);\n> > -#endif\n> \n> This seems to be an unintended behavioural change: the second condition\n> wouldn't have applied previously and overrides the first option\n> (equivalent to CURLOPT_POSTREDIR = CURL_REDIR_POST_301).\n\nThanks, you're right. I'll fix it in my re-roll.\n\n-Peff\n"},{"id":"326091","messageId":"873e1f31-2a96-5b72-2f20-a5816cad1b51@jupiterrise.com","threadId":"46547","inReplyTo":"20170809214758.p77fqrwxanb4zn5a@sigill.intra.peff.net","subject":"Re: [PATCH 0/4] dropping support for older curl","fromName":"Tom G. Christensen","fromEmail":"tgc@jupiterrise.com","sentAt":"2017-08-10T20:33:18Z","receivedAt":"2017-08-10T20:33:27Z","isPatch":true,"sender":{"key":"tgc@jupiterrise.com","avatar":"https://avatars.githubusercontent.com/u/912180?v=4"},"body":"[I am resending this since the original does not seem to have made it to \nthe list, at least I cannot find it in any archives]\n\nOn 09/08/17 23:47, Jeff King wrote:\n> On Wed, Aug 09, 2017 at 11:42:12PM +0200, Johannes Schindelin wrote:\n>> I mean, if we even go out of our way to support the completely outdated\n>> and obsolete .git/branches/ for what is likely a single user, it may not\n>> be the worst to keep those couple of #ifdef guards to keep at least\n>> nominal support for older cURLs?\n> \n> You've totally ignored the argument I made back then[1], and which I\n> reiterated in this thread. So I'll say it one more time: the more\n> compelling reason is not the #ifdefs, but the fact that the older\n> versions are totally untested. \n\nPerhaps you forgot but I stated in the original thread that I build RPMS \nfor RHEL/CentOS 3, 4, 5, 6 and 7. I still do and I run the testsuite \nevery single time.\nI currently have 2.13.3 up for el4, el5, el6 and el7.\nOnly el4 requires any patches, the rest will build out of the box with \nthe vendor supplied version of curl.\n\nThe plan was to drop the el4 builds for 2.14.0 to get rid of the patches.\n\n> In fact, they do not even compile, and\n> yet I have not seen any patches to fix that.\n> \n\nI just built a pristine 2.14.0 on CentOS 5 with curl 7.15.5. No problems \nat all neither with building nor with running the testsuite.\n\n> So IMHO this is about being honest with users about which versions we\n> _actually_ support.\n> \n\nI have no problem with you wanting to drop support for older curl \nreleases (such as 7.15.5) but don't use the argument that it doesn't \ncurrently build and nobody cares.\n\nAlso FWIW Red Hat continues to support RHEL 5 with the Extended \nLife-cycle Support program until 2020-11-30.\n\n-tgc\n"},{"id":"326097","messageId":"171c1316-1f52-57e3-10ea-e0b0817967e8@jupiterrise.com","threadId":"46547","inReplyTo":"20170809214758.p77fqrwxanb4zn5a@sigill.intra.peff.net","subject":"Re: [PATCH 0/4] dropping support for older curl","fromName":"Tom G. Christensen","fromEmail":"tgc@jupiterrise.com","sentAt":"2017-08-10T09:01:12Z","receivedAt":"2017-08-10T21:05:39Z","isPatch":true,"sender":{"key":"tgc@jupiterrise.com","avatar":"https://avatars.githubusercontent.com/u/912180?v=4"},"body":"On 09/08/17 23:47, Jeff King wrote:\n> On Wed, Aug 09, 2017 at 11:42:12PM +0200, Johannes Schindelin wrote:\n>> I mean, if we even go out of our way to support the completely outdated\n>> and obsolete .git/branches/ for what is likely a single user, it may not\n>> be the worst to keep those couple of #ifdef guards to keep at least\n>> nominal support for older cURLs?\n> \n> You've totally ignored the argument I made back then[1], and which I\n> reiterated in this thread. So I'll say it one more time: the more\n> compelling reason is not the #ifdefs, but the fact that the older\n> versions are totally untested. \n\nPerhaps you forgot but I stated in the original thread that I build RPMS \nfor RHEL/CentOS 3, 4, 5, 6 and 7. I still do and I run the testsuite \nevery single time.\nI currently have 2.13.3 up for el4, el5, el6 and el7.\nOnly el4 requires any patches, the rest will build out of the box with \nthe vendor supplied version of curl.\n\nThe plan was to drop the el4 builds for 2.14.0 to get rid of the patches.\n\n> In fact, they do not even compile, and\n> yet I have not seen any patches to fix that.\n> \n\nI just built a pristine 2.14.0 on CentOS 5 with curl 7.15.5. No problems \nat all neither with building nor with running the testsuite.\n\n> So IMHO this is about being honest with users about which versions we\n> _actually_ support.\n> \n\nI have no problem with you wanting to drop support for older curl \nreleases (such as 7.15.5) but don't use the argument that it doesn't \ncurrently build and nobody cares.\n\nAlso FWIW Red Hat continues to support RHEL 5 with the Extended \nLife-cycle Support program until 2020-11-30.\n\n-tgc\n"},{"id":"326102","messageId":"20170810213236.dej4ibsag2lxf5w2@sigill.intra.peff.net","threadId":"46547","inReplyTo":"873e1f31-2a96-5b72-2f20-a5816cad1b51@jupiterrise.com","subject":"Re: [PATCH 0/4] dropping support for older curl","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2017-08-10T21:32:36Z","receivedAt":"2017-08-10T21:32:42Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Thu, Aug 10, 2017 at 10:33:18PM +0200, Tom G. Christensen wrote:\n\n> > You've totally ignored the argument I made back then[1], and which I\n> > reiterated in this thread. So I'll say it one more time: the more\n> > compelling reason is not the #ifdefs, but the fact that the older\n> > versions are totally untested.\n> \n> Perhaps you forgot but I stated in the original thread that I build RPMS for\n> RHEL/CentOS 3, 4, 5, 6 and 7. I still do and I run the testsuite every\n> single time.\n\nI didn't forget. I actually double-checked the patches you sent at the\ntime, but I didn't see one for the CURLPROTO issue. And indeed, it is\nstill broken for me:\n\n  $ cd /path/to/curl/repo\n  $ git checkout curl-7_15_5\n  $ ./buildconf && ./configure --prefix=/tmp/foo && make install\n  $ cd /path/to/git\n  $ git checkout v2.14.0\n  $ make CURLDIR=/tmp/foo V=1 http.o\n  gcc -o http.o -c -MF ./.depend/http.o.d -MQ http.o -MMD -MP   -g -O0 -Wall -Werror -Wdeclaration-after-statement -Wpointer-arith -Wstrict-prototypes -Wvla -Wold-style-declaration -Wold-style-definition -Wno-error -Wno-cpp -Wno-unused-value -Wno-strict-prototypes  -I. -DUSE_LIBPCRE1 -DHAVE_ALLOCA_H -I/tmp/foo/include -DUSE_CURL_FOR_IMAP_SEND -DNO_GETTEXT -DSHA1_DC -DSHA1DC_NO_STANDARD_INCLUDES -DSHA1DC_INIT_SAFE_HASH_DEFAULT=0 -DSHA1DC_CUSTOM_INCLUDE_SHA1_C=\"\\\"cache.h\\\"\" -DSHA1DC_CUSTOM_TRAILING_INCLUDE_SHA1_C=\"\\\"sha1dc_git.c\\\"\" -DSHA1DC_CUSTOM_TRAILING_INCLUDE_SHA1_H=\"\\\"sha1dc_git.h\\\"\" -DSHA1DC_CUSTOM_INCLUDE_UBC_CHECK_C=\"\\\"git-compat-util.h\\\"\"  -DHAVE_PATHS_H -DHAVE_DEV_TTY -DHAVE_CLOCK_GETTIME -DHAVE_CLOCK_MONOTONIC -DHAVE_GETDELIM  -DFREAD_READS_DIRECTORIES -DNO_STRLCPY -DSHELL_PATH='\"/bin/sh\"' -DPAGER_ENV='\"LESS=FRX LV=-c\"'  http.c\n  http.c: In function ‘get_curl_allowed_protocols’:\n  http.c:685:24: error: ‘CURLPROTO_HTTP’ undeclared (first use in this function); did you mean ‘CURLPROXY_HTTP’?\n     allowed_protocols |= CURLPROTO_HTTP;\n                          ^~~~~~~~~~~~~~\n                          CURLPROXY_HTTP\n  [and so on]\n\n> I just built a pristine 2.14.0 on CentOS 5 with curl 7.15.5. No problems at\n> all neither with building nor with running the testsuite.\n\nAs you can see, this does not compile for me. What's going on?\n\nI don't see how it could work, as CURLPROTO_HTTP is not defined at all\nin that version of curl.  Can you please double-check that you're\nbuilding against the correct version of curl, and that you are building\nthe HTTP parts of Git (which _are_ optional, and the test suite will\npass without them).\n\n> > So IMHO this is about being honest with users about which versions we\n> > _actually_ support.\n> \n> I have no problem with you wanting to drop support for older curl releases\n> (such as 7.15.5) but don't use the argument that it doesn't currently build\n> and nobody cares.\n\nMy argument isn't quite that nobody cares. It's that we do users a\ndisservice by shipping a version of the code that very well may have\nhidden problems like security holes (for instance, we do not handle\nredirects safely in old versions of curl). So if you can get it to build\nit may _seem_ fine, but it's a bit of a booby-trap waiting to spring.\n\nI also won't claim any absolutes. I think we all agree this is a\ncost/benefit tradeoff. But there are a lot of options for building on a\nvery old system. For instance, building without http if you don't need\nit. Or building a more recent libcurl (and even linking statically for\nsimplicity).\n\nI'd find arguments against the latter more compelling if recent curl\nwere hard to compile on old systems. I don't know whether that's the\ncase (certainly on a modern system, it's much easier to get newer\nversions of curl to compile than older ones).\n\n> Also FWIW Red Hat continues to support RHEL 5 with the Extended Life-cycle\n> Support program until 2020-11-30.\n\nI saw that, too. But as I understand it, they provide no code updates:\nno bugfixes and no security updates. They just promise to answer the\nphone and help you with troubleshooting. It's possible my perception is\nwrong, though; I'm certainly not one of their customers.\n\n-Peff\n"},{"id":"326103","messageId":"20170810213348.g4lue3j4uz6qapal@sigill.intra.peff.net","threadId":"46547","inReplyTo":"alpine.DEB.2.21.1.1708101111080.11175@virtualbox","subject":"Re: [PATCH 0/4] dropping support for older curl","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2017-08-10T21:33:49Z","receivedAt":"2017-08-10T21:33:54Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Thu, Aug 10, 2017 at 11:36:41AM +0200, Johannes Schindelin wrote:\n\n> Hopefully I had better luck expressing my concerns this time?\n\nI understand your argument much better now. I'm still not sure I agree.\n\n-Peff\n"},{"id":"326109","messageId":"xmqqshgz1319.fsf@gitster.mtv.corp.google.com","threadId":"46547","inReplyTo":"20170810213348.g4lue3j4uz6qapal@sigill.intra.peff.net","subject":"Re: [PATCH 0/4] dropping support for older curl","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2017-08-10T22:17:06Z","receivedAt":"2017-08-10T22:17:47Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Jeff King <peff@peff.net> writes:\n\n> On Thu, Aug 10, 2017 at 11:36:41AM +0200, Johannes Schindelin wrote:\n>\n>> Hopefully I had better luck expressing my concerns this time?\n>\n> I understand your argument much better now. I'm still not sure I agree.\n>\n> -Peff\n\nI do not think \"there are a dozen #ifdefs and I don't know whether\nthey still work. I don't know whether anybody (who most likely has\nbetter things to do than read the Git mailing list) is still using\nthose.  So let's just remove them.\" was why you were suggesting to\nclean up the (apparent) support of older curl in the code, though.\n\nIsn't the reason why your series simplifies these #ifdefs away\nbecause we by accident started using some features that require a\nversion that is even newer than any of these #ifdef's try to cater\nto and yet nobody complained?  That is a lot more similar to the\nremoval of rsync transport that happened in a not so distant past,\nwhere the reason for removal was \"We have been shipping code that\ncouldn't have possibly worked for some time and nobody complained\n---we know nobody is depending on it.\"\n\nOr \"We accidentally started shipping code with comma after the last\nelement of enum decl and nobody compalined---everybody's compiler\nmust be ready\" ;-)\n"},{"id":"326111","messageId":"fbd7e636-0087-9c2b-746f-e2413c6d2133@jupiterrise.com","threadId":"46547","inReplyTo":"20170810213236.dej4ibsag2lxf5w2@sigill.intra.peff.net","subject":"Re: [PATCH 0/4] dropping support for older curl","fromName":"Tom G. Christensen","fromEmail":"tgc@jupiterrise.com","sentAt":"2017-08-10T22:23:42Z","receivedAt":"2017-08-10T22:23:52Z","isPatch":true,"sender":{"key":"tgc@jupiterrise.com","avatar":"https://avatars.githubusercontent.com/u/912180?v=4"},"body":"On 10/08/17 23:32, Jeff King wrote:\n> On Thu, Aug 10, 2017 at 10:33:18PM +0200, Tom G. Christensen wrote:\n> \n>>> You've totally ignored the argument I made back then[1], and which I\n>>> reiterated in this thread. So I'll say it one more time: the more\n>>> compelling reason is not the #ifdefs, but the fact that the older\n>>> versions are totally untested.\n>>\n>> Perhaps you forgot but I stated in the original thread that I build RPMS for\n>> RHEL/CentOS 3, 4, 5, 6 and 7. I still do and I run the testsuite every\n>> single time.\n> \n> I didn't forget. I actually double-checked the patches you sent at the\n> time, but I didn't see one for the CURLPROTO issue. And indeed, it is\n> still broken for me:\n> \n>    $ cd /path/to/curl/repo\n>    $ git checkout curl-7_15_5\n>    $ ./buildconf && ./configure --prefix=/tmp/foo && make install\n>    $ cd /path/to/git\n>    $ git checkout v2.14.0\n>    $ make CURLDIR=/tmp/foo V=1 http.o\n>    gcc -o http.o -c -MF ./.depend/http.o.d -MQ http.o -MMD -MP   -g -O0 -Wall -Werror -Wdeclaration-after-statement -Wpointer-arith -Wstrict-prototypes -Wvla -Wold-style-declaration -Wold-style-definition -Wno-error -Wno-cpp -Wno-unused-value -Wno-strict-prototypes  -I. -DUSE_LIBPCRE1 -DHAVE_ALLOCA_H -I/tmp/foo/include -DUSE_CURL_FOR_IMAP_SEND -DNO_GETTEXT -DSHA1_DC -DSHA1DC_NO_STANDARD_INCLUDES -DSHA1DC_INIT_SAFE_HASH_DEFAULT=0 -DSHA1DC_CUSTOM_INCLUDE_SHA1_C=\"\\\"cache.h\\\"\" -DSHA1DC_CUSTOM_TRAILING_INCLUDE_SHA1_C=\"\\\"sha1dc_git.c\\\"\" -DSHA1DC_CUSTOM_TRAILING_INCLUDE_SHA1_H=\"\\\"sha1dc_git.h\\\"\" -DSHA1DC_CUSTOM_INCLUDE_UBC_CHECK_C=\"\\\"git-compat-util.h\\\"\"  -DHAVE_PATHS_H -DHAVE_DEV_TTY -DHAVE_CLOCK_GETTIME -DHAVE_CLOCK_MONOTONIC -DHAVE_GETDELIM  -DFREAD_READS_DIRECTORIES -DNO_STRLCPY -DSHELL_PATH='\n>   \"/bin/sh\"' -DPAGER_ENV='\"LESS=FRX LV=-c\"'  http.c\n>    http.c: In function ‘get_curl_allowed_protocols’:\n>    http.c:685:24: error: ‘CURLPROTO_HTTP’ undeclared (first use in this function); did you mean ‘CURLPROXY_HTTP’?\n>       allowed_protocols |= CURLPROTO_HTTP;\n>                            ^~~~~~~~~~~~~~\n>                            CURLPROXY_HTTP\n>    [and so on]\n> \n>> I just built a pristine 2.14.0 on CentOS 5 with curl 7.15.5. No problems at\n>> all neither with building nor with running the testsuite.\n> \n> As you can see, this does not compile for me. What's going on?\n>\nThe call site for get_curl_allowed_protocols() in http.c is still \nprotected by an #if:\n#if LIBCURL_VERSION_NUM >= 0x071304\n         curl_easy_setopt(result, CURLOPT_REDIR_PROTOCOLS,\n                          get_curl_allowed_protocols(0));\n         curl_easy_setopt(result, CURLOPT_PROTOCOLS,\n                          get_curl_allowed_protocols(-1));\n#else\n         warning(\"protocol restrictions not applied to curl redirects \nbecause\\n\"\n                 \"your curl version is too old (>= 7.19.4)\");\n#endif\n\n> I don't see how it could work, as CURLPROTO_HTTP is not defined at all\n> in that version of curl. \n\nIndeed but the #if will handle that.\n\n> Can you please double-check that you're\n> building against the correct version of curl, and that you are building\n> the HTTP parts of Git (which _are_ optional, and the test suite will\n> pass without them).\n> \n\nI use a mock buildroot and there is no other curl than the vendor \nsupplied 7.15.5 installed:\n# pwd\n/var/lib/mock/jrpms-el5-x86_64/root\n# find . -name 'curlver.h'\n./usr/include/curl/curlver.h\n# grep LIBCURL_VERSION_NUM ./usr/include/curl/curlver.h\n    parsing and comparions by programs. The LIBCURL_VERSION_NUM define will\n#define LIBCURL_VERSION_NUM 0x070f05\n#\n\n[root@c5-32bit-01 ~]# rpm -q git\ngit-2.14.1-1.el5.jr\n[root@c5-32bit-01 ~]# ldd /usr/libexec/git-core/git-http-fetch |grep libcurl\n         libcurl.so.3 => /usr/lib/libcurl.so.3 (0x001e7000)\n[root@c5-32bit-01 ~]# rpm -qf /usr/lib/libcurl.so.3\ncurl-7.15.5-17.el5_9\n[root@c5-32bit-01 ~]# git --version\ngit version 2.14.1\n[root@c5-32bit-01 ~]# git clone \nhttps://github.com/tgc/tgcware-for-solaris.git\nCloning into 'tgcware-for-solaris'...\nwarning: protocol restrictions not applied to curl redirects because\nyour curl version is too old (>= 7.19.4)\nremote: Counting objects: 2793, done.\nremote: Total 2793 (delta 0), reused 0 (delta 0), pack-reused 2793\nReceiving objects: 100% (2793/2793), 780.88 KiB | 639.00 KiB/s, done.\nResolving deltas: 100% (1233/1233), done.\n[root@c5-32bit-01 ~]#\n\n<snip>\n\n> I also won't claim any absolutes. I think we all agree this is a\n> cost/benefit tradeoff. But there are a lot of options for building on a\n> very old system. For instance, building without http if you don't need\n> it. Or building a more recent libcurl (and even linking statically for\n> simplicity).\n> \n\nOf course that is always an option but it does complicate things.\n\n> I'd find arguments against the latter more compelling if recent curl\n> were hard to compile on old systems. I don't know whether that's the\n> case (certainly on a modern system, it's much easier to get newer\n> versions of curl to compile than older ones).\n> \n\nI have no experience with building curl on older Linux systems. I know \nthat I can build it on old Solaris releases but that is not quite the \nsame since there I am also building against recent versions of curls \ndependecies (openssl etc.).\n\n>> Also FWIW Red Hat continues to support RHEL 5 with the Extended Life-cycle\n>> Support program until 2020-11-30.\n> \n> I saw that, too. But as I understand it, they provide no code updates:\n> no bugfixes and no security updates. They just promise to answer the\n> phone and help you with troubleshooting. It's possible my perception is\n> wrong, though; I'm certainly not one of their customers.\n> \n\nI am refering to the Extended Life-cycle Support product (ELS), which \npromises:\n\"the ELS Add-On delivers certain critical-impact security fixes and \nselected urgent priority bug fixes and troubleshooting for the last \nminor release\"\n\nThe full description is here:\nhttps://access.redhat.com/support/policy/updates/errata#Extended_Life_Cycle_Phase\n\n-tgc\n"},{"id":"326115","messageId":"20170810225428.jubkaistxz33ykco@sigill.intra.peff.net","threadId":"46547","inReplyTo":"fbd7e636-0087-9c2b-746f-e2413c6d2133@jupiterrise.com","subject":"Re: [PATCH 0/4] dropping support for older curl","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2017-08-10T22:54:28Z","receivedAt":"2017-08-10T22:54:40Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Fri, Aug 11, 2017 at 12:23:42AM +0200, Tom G. Christensen wrote:\n\n> > > I just built a pristine 2.14.0 on CentOS 5 with curl 7.15.5. No problems at\n> > > all neither with building nor with running the testsuite.\n> > \n> > As you can see, this does not compile for me. What's going on?\n> > \n> The call site for get_curl_allowed_protocols() in http.c is still protected\n> by an #if:\n> #if LIBCURL_VERSION_NUM >= 0x071304\n>         curl_easy_setopt(result, CURLOPT_REDIR_PROTOCOLS,\n>                          get_curl_allowed_protocols(0));\n>         curl_easy_setopt(result, CURLOPT_PROTOCOLS,\n>                          get_curl_allowed_protocols(-1));\n> #else\n>         warning(\"protocol restrictions not applied to curl redirects\n> because\\n\"\n>                 \"your curl version is too old (>= 7.19.4)\");\n> #endif\n> \n> > I don't see how it could work, as CURLPROTO_HTTP is not defined at all\n> > in that version of curl.\n> \n> Indeed but the #if will handle that.\n\nEr, sorry if I'm being dense, but how? Are you suggesting that by\nremoving the callsite of get_curl_allowed_protocols(), the compiler\nmight elide the now-dead code completely? I could certainly see it being\ndropped after the compilation, but I'm surprised that it wouldn't\ncomplain about the undeclared identifiers in the first place.\n\nAnd if that _is_ what is happening...that seems like a very fragile and\nunportable thing to be depending on.\n\n> > Can you please double-check that you're\n> > building against the correct version of curl, and that you are building\n> > the HTTP parts of Git (which _are_ optional, and the test suite will\n> > pass without them).\n> \n> I use a mock buildroot and there is no other curl than the vendor supplied\n> 7.15.5 installed:\n> [...]\n\nOK, thanks for double-checking. I'm still puzzled why your build\nsucceeds and mine does not.\n\n> > I saw that, too. But as I understand it, they provide no code updates:\n> > no bugfixes and no security updates. They just promise to answer the\n> > phone and help you with troubleshooting. It's possible my perception is\n> > wrong, though; I'm certainly not one of their customers.\n> \n> I am refering to the Extended Life-cycle Support product (ELS), which\n> promises:\n> \"the ELS Add-On delivers certain critical-impact security fixes and selected\n> urgent priority bug fixes and troubleshooting for the last minor release\"\n> \n> The full description is here:\n> https://access.redhat.com/support/policy/updates/errata#Extended_Life_Cycle_Phase\n\nThat was the same page I was looking at. The bit I read was:\n\n  For versions of products in the Extended Life Phase, Red Hat will\n  provide limited ongoing technical support. No bug fixes, security\n  fixes, hardware enablement or root-cause analysis will be available\n  during this phase, and support will be provided on existing\n  installations only.\n\nBut I missed the bit about the \"ELS add-on\" below there, which I guess\nis an extra thing. I do suspect that \"install arbitrary new versions of\nGit\" is outside of their scope of \"urgent priority bug fixes\". But in a\nsense it doesn't really matter. What is much more interesting is whether\nthere's a significant population that is running RHEL5 and has a strong\nneed for newer versions of Git. That I'm not sure about.\n\n-Peff\n"},{"id":"326117","messageId":"20170810230902.wnzoiaxdaus74a5i@sigill.intra.peff.net","threadId":"46547","inReplyTo":"xmqqshgz1319.fsf@gitster.mtv.corp.google.com","subject":"Re: [PATCH 0/4] dropping support for older curl","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2017-08-10T23:09:02Z","receivedAt":"2017-08-10T23:09:08Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Thu, Aug 10, 2017 at 03:17:06PM -0700, Junio C Hamano wrote:\n\n> Jeff King <peff@peff.net> writes:\n> \n> > On Thu, Aug 10, 2017 at 11:36:41AM +0200, Johannes Schindelin wrote:\n> >\n> >> Hopefully I had better luck expressing my concerns this time?\n> >\n> > I understand your argument much better now. I'm still not sure I agree.\n> >\n> > -Peff\n> \n> I do not think \"there are a dozen #ifdefs and I don't know whether\n> they still work. I don't know whether anybody (who most likely has\n> better things to do than read the Git mailing list) is still using\n> those.  So let's just remove them.\" was why you were suggesting to\n> clean up the (apparent) support of older curl in the code, though.\n> \n> Isn't the reason why your series simplifies these #ifdefs away\n> because we by accident started using some features that require a\n> version that is even newer than any of these #ifdef's try to cater\n> to and yet nobody complained?  That is a lot more similar to the\n> removal of rsync transport that happened in a not so distant past,\n> where the reason for removal was \"We have been shipping code that\n> couldn't have possibly worked for some time and nobody complained\n> ---we know nobody is depending on it.\"\n\nI think there are two questions to be asked, and their answers come from\ndifferent lines of reasoning.\n\nThe first is \"should we eventually drop support for antiquated versions\nof dependencies?\". And the argument in favor is the one I was making\nhere: besides lowering maintenance cost, it is more honest to our users\nabout what to expect[1].\n\nThe second is \"how far back should we keep support?\".\n\nAnd there are two lines of thought there.\n\nOne is to do it by date and what dependencies are in long-term OS\nreleases, and then compare that to the benefit. Requiring curl 7.11.1\nstill keeps us working back to rhel4, which was already end-of-lifed\ncompletely after a 12 year run. Bumping to 7.16.0 drops rhel4 and rhel5,\nthe latter of which is in its final \"barely supported\" phase after 10\nyears. But it gives us a bit more bang for our buck by making CURL_MULTI\nuconditional[2].  Requiring 7.19.4 actually doesn't drop any more rhel\nreleases. So by that metric, we might as well go there.\n\nAnd the second line of thought is: it was already broken and nobody\nreported it or offered up a fix. And that's where the \"similar to rsync\"\nthing comes in. Though in this case we do have some evidence that people\n(at least Tom) was patching and distributing behind the scenes. And our\nbreakage period was much shorter (since v2.12.0, but that's only months\nor so).\n\n-Peff\n"},{"id":"326120","messageId":"c8a2716d-76ac-735c-57f9-175ca3acbcb0@jupiterrise.com","threadId":"46547","inReplyTo":"20170810225428.jubkaistxz33ykco@sigill.intra.peff.net","subject":"Re: [PATCH 0/4] dropping support for older curl","fromName":"Tom G. Christensen","fromEmail":"tgc@jupiterrise.com","sentAt":"2017-08-10T23:17:51Z","receivedAt":"2017-08-10T23:17:59Z","isPatch":true,"sender":{"key":"tgc@jupiterrise.com","avatar":"https://avatars.githubusercontent.com/u/912180?v=4"},"body":"On 11/08/17 00:54, Jeff King wrote:\n> On Fri, Aug 11, 2017 at 12:23:42AM +0200, Tom G. Christensen wrote:\n\n> Er, sorry if I'm being dense, but how? Are you suggesting that by\n> removing the callsite of get_curl_allowed_protocols(), the compiler\n> might elide the now-dead code completely? I could certainly see it being\n> dropped after the compilation, but I'm surprised that it wouldn't\n> complain about the undeclared identifiers in the first place.\n>\nYou're right, that should not be able to handle it.\n\n>>> Can you please double-check that you're\n>>> building against the correct version of curl, and that you are building\n>>> the HTTP parts of Git (which _are_ optional, and the test suite will\n>>> pass without them).\n>>\n>> I use a mock buildroot and there is no other curl than the vendor supplied\n>> 7.15.5 installed:\n>> [...]\n> \n> OK, thanks for double-checking. I'm still puzzled why your build\n> succeeds and mine does not.\n> \n\nI know what's going on now and it's so simple.\nRed Hats version of curl 7.15.5 includes a number of patches including \none that backports support for CURLPROTO_* (as part of a fix for \nCVE-2009-0037).\nI haven't checked el6 but I would not be surprised if there where \nsimilar things going on there.\n\nSo in conclusion version based #ifdefs are misleading when used with \ncurl as shipped with RHEL.\n\n-tgc\n"},{"id":"326122","messageId":"20170810232315.twkrj32er552bryg@sigill.intra.peff.net","threadId":"46547","inReplyTo":"c8a2716d-76ac-735c-57f9-175ca3acbcb0@jupiterrise.com","subject":"Re: [PATCH 0/4] dropping support for older curl","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2017-08-10T23:23:15Z","receivedAt":"2017-08-10T23:23:21Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Fri, Aug 11, 2017 at 01:17:51AM +0200, Tom G. Christensen wrote:\n\n> > OK, thanks for double-checking. I'm still puzzled why your build\n> > succeeds and mine does not.\n> \n> I know what's going on now and it's so simple.\n> Red Hats version of curl 7.15.5 includes a number of patches including one\n> that backports support for CURLPROTO_* (as part of a fix for CVE-2009-0037).\n> I haven't checked el6 but I would not be surprised if there where similar\n> things going on there.\n\nel6 should have it already as part of 7.19.7, right?\n\n> So in conclusion version based #ifdefs are misleading when used with curl as\n> shipped with RHEL.\n\nYeah, that's certainly an interesting finding. In this case your builds\nare missing out on redirect protection that we _could_ be providing.\n\nIf we do keep the compat ifdefs around this feature, it may be worth\nconverting them to \"#ifdef CURLPROTO_HTTP\" to more directly check the\nfeature.\n\n-Peff\n"},{"id":"326123","messageId":"030356f8-0472-7400-c9f6-7492788dd2d0@jupiterrise.com","threadId":"46547","inReplyTo":"20170810232315.twkrj32er552bryg@sigill.intra.peff.net","subject":"Re: [PATCH 0/4] dropping support for older curl","fromName":"Tom G. Christensen","fromEmail":"tgc@jupiterrise.com","sentAt":"2017-08-10T23:36:09Z","receivedAt":"2017-08-10T23:36:17Z","isPatch":true,"sender":{"key":"tgc@jupiterrise.com","avatar":"https://avatars.githubusercontent.com/u/912180?v=4"},"body":"On 11/08/17 01:23, Jeff King wrote:\n> On Fri, Aug 11, 2017 at 01:17:51AM +0200, Tom G. Christensen wrote:\n> \n>>> OK, thanks for double-checking. I'm still puzzled why your build\n>>> succeeds and mine does not.\n>>\n>> I know what's going on now and it's so simple.\n>> Red Hats version of curl 7.15.5 includes a number of patches including one\n>> that backports support for CURLPROTO_* (as part of a fix for CVE-2009-0037).\n>> I haven't checked el6 but I would not be surprised if there where similar\n>> things going on there.\n> \n> el6 should have it already as part of 7.19.7, right?\n> \n\nYes of course.\n\n>> So in conclusion version based #ifdefs are misleading when used with curl as\n>> shipped with RHEL.\n> \n> Yeah, that's certainly an interesting finding. In this case your builds\n> are missing out on redirect protection that we _could_ be providing.\n> \n\nYes and I'm looking into that right now.\n\n> If we do keep the compat ifdefs around this feature, it may be worth\n> converting them to \"#ifdef CURLPROTO_HTTP\" to more directly check the\n> feature.\n> \n\nYes, a feature test would be better.\n\n-tgc\n"},{"id":"326126","messageId":"20170811001726.tmgascordtw4ksiz@sigill.intra.peff.net","threadId":"46547","inReplyTo":"20170810230902.wnzoiaxdaus74a5i@sigill.intra.peff.net","subject":"Re: [PATCH 0/4] dropping support for older curl","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2017-08-11T00:17:26Z","receivedAt":"2017-08-11T00:17:34Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Thu, Aug 10, 2017 at 07:09:02PM -0400, Jeff King wrote:\n\n> The first is \"should we eventually drop support for antiquated versions\n> of dependencies?\". And the argument in favor is the one I was making\n> here: besides lowering maintenance cost, it is more honest to our users\n> about what to expect[1].\n\nAs usual, I forgot all my footnotes.\n\n[1] When I've talked about keeping expectations reasonable, I'm a lot\n    less interested in \"oops, I built Git and this particular feature\n    didn't work\". It's easy to write that off as \"well, you have an old\n    version of curl, patches welcome\". I'm much more concerned about\n    security issues. Curl is network-facing. Leaving aside security\n    vulnerabilities in curl itself (which hopefully distros with 10-year\n    support periods would fix), I wouldn't be surprised if there are\n    bad interactions possible due to our tangle of ifdefs.\n\n    One way to address that would be more careful auditing. But then\n    that goes back to the cost/benefit thing.\n\n> One is to do it by date and what dependencies are in long-term OS\n> releases, and then compare that to the benefit. Requiring curl 7.11.1\n> still keeps us working back to rhel4, which was already end-of-lifed\n> completely after a 12 year run. Bumping to 7.16.0 drops rhel4 and rhel5,\n> the latter of which is in its final \"barely supported\" phase after 10\n> years. But it gives us a bit more bang for our buck by making CURL_MULTI\n> uconditional[2].  Requiring 7.19.4 actually doesn't drop any more rhel\n> releases. So by that metric, we might as well go there.\n\n[2] The line-count change from dropping CURL_MULTI isn't _too_ exciting.\n    But a lot of the tangled design of our http code revolves around\n    the abstractions we've introduced. I have a feeling that it will\n    enable further cleanups as we move forward (OTOH, a lot of the worst\n    parts of our design are because of _using_ curl_multi for dumb http,\n    which of course hardly anyone does these days. But I have a feeling\n    if I suggested removing that, people would really scream).\n\n-Peff\n"},{"id":"326321","messageId":"alpine.DEB.2.21.1.1708142302180.19382@virtualbox","threadId":"46547","inReplyTo":"CAHVLzcnnrABmkYNg31Aq99NgBbyuCKEM60pHGygyjXbjmaUEYQ@mail.gmail.com","subject":"Re: [PATCH 0/4] dropping support for older curl","fromName":"Johannes Schindelin","fromEmail":"johannes.schindelin@gmx.de","sentAt":"2017-08-14T21:50:09Z","receivedAt":"2017-08-14T21:50:22Z","isPatch":true,"sender":{"key":"johannes.schindelin@gmx.de","avatar":"https://avatars.githubusercontent.com/u/127790?v=4"},"body":"Hi Paolo,\n\nOn Thu, 10 Aug 2017, Paolo Ciarrocchi wrote:\n\n> Il 10 ago 2017 11:39 AM, \"Johannes Schindelin\" <Johannes.Schindelin@gmx.de>\n> ha scritto:\n> \n> \n> \n> Footnote *1*: It is no secret that I find our patch submission less than\n> inviting. Granted, *I* use it. *I* did not have problems entering the\n> mailing list. But then, my mails were not swallowed silently, because my\n> mail program does not send HTML by default. And prepared by the German\n> school system (I learned the term \"sugar coating\" only when exposed to\n> some US culture), I had little emotional problems with being criticized\n> and not thanked for my contribution, I persisted nevertheless. The opinion\n> that the Git contribution process is a lot less inviting than it could be\n> is not only my view, by the way. I hear this a lot. I give you that we are\n> not quite as textbook \"keep out from here unless you look like us, smell\n> like us, talk like us, have the same genital setup like us\" as the Linux\n> kernel mailing list, but we are in a different universe compared to, say,\n> the Drupal community. And their universe is a lot nicer to live in.\n> \n> \n> Isn't SumbitGit a possible answer to your doubts (I strongly agree with\n> you) about the current development process?\n\nNo. I hate to say that SubmitGit neither integrates well with GitHub Pull\nRequests (code comments on GitHub are approximately 1,523x easier to\nwrite, read, associate with the actual code, and see the current state of,\ncompared to the mailing list, and SubmitGit does not even hint at\nintegrating with that user experience).\n\nAlso, the barrier to start using SubmitGit is rather high. If you open a\nPull Request on github.com/git/git, you get *no* indication that SubmitGit\nis an option to *actually* get the code into Git. There are also concerns\nabout required permissions that Junio Hamano himself would not accept.\n\nNow, let's assume that you submitted the code via SubmitGit. The\nchallenges of the patch submission process do not end there, yet SubmitGit\ngoes home and has a beer. But the hard part, the discussions on the\nmailing list, the status updates in the completely separate What's cooking\nmails, the missing links back to the original source code (let alone the\ninformation in which worktree on your computer under which branch name\nthat topic was developed again?), the diverging mail threads, the\n\"rerolls\" that should not forget to Cc: all reviewers of previous rounds,\nall that jazz is still all very, very manual.\n\nAnd even if there was an easier path from having a local branch that works\nto finally getting it onto the list in the required form, your mail is an\neloquent example of one of the most preposterous hurdles along the way: we\npride ourselves with the openness we demonstrate by communicating via a\nmailing list, everybody has a mail address, amirite? But of course, HTML\nmails, like, about 130% of all mails on the internet (or so it feels),\nincluding yours, are dropped. Silently. Not so open anymore, are we.\n\nIt is all so frustrating, really. I work in a team (Visual Studio Team\nServices, you can think of it as kind of a Microsoft take on Git hosting\nplus a lot of other tooling) where we get really, really positive feedback\nregarding our user experience, in particular the frequent enhancements to\nPRs. It is really powerful to open, review and merge PRs, interact with\nother developers, see the state of PRs and their respective discussions,\nopen and resolve issues, automate workflows and build tasks [*1*]. And\nthen I try to convince people here on this mailing list that it really\nmakes a difference if you start using tools to lighten the load of\neverybody, and... little changes.\n\nAt least thanks to Lars Schneider's incredible efforts we have Continuous\nTesting (I know how much time he spent on this, it is another thing\ndeserving the label \"preposterous\", and I know how much time I spent on\ntop to add the Windows part which mostly works). If only we could push it\nfurther to true Continuous Integration. Or at least to accepting PRs from\nprofessionals who simply have no time to fight with our patch contribution\nprocess and whose expertise we lose as a consequence.\n\nCiao,\nJohannes\n\nFootnote *1*: The funniest part about this is that I do get mails about\nall of this all the time. When I am pulled in as a reviewer. When a build\nfailed. When a previously failing task was fixed by a new build. When\nsomebody responded to my comments. The difference to the mailing\nlist-centric approach is of course that those mails are only\nnotifications, and link back to the tool appropriately supporting what\nI, the user, want to get done.\n"},{"id":"430800","messageId":"cover-0.5-00000000000-20210721T220402Z-avarab@gmail.com","threadId":"46547","inReplyTo":"20170809120024.7phdjzjv54uv5dpz@sigill.intra.peff.net","subject":"[PATCH v2 0/5] drop support for ancient curl","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-07-21T22:22:11Z","receivedAt":"2021-07-21T22:22:24Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"This series simplifies the http code by dropping support for curl\nversions older than 7.19.4, released in March 2009.\n\nThis was last discussed on-list in 2017:\nhttp://lore.kernel.org/git/20170809120024.7phdjzjv54uv5dpz@sigill.intra.peff.net\n\nMy reading of why it didn't get integrated at the time was:\n\n - The original commit messages are opinionated about git not working\n   on these versions anyway, as noted in the original thread that's\n   only true of vanilla curl, but anyone impacted by these issues at\n   the time was probably using e.g. RHEL, which had backports that\n   confused the issue.\n\n - While in 2017 these versions were already ancient, RHEL 5 (released\n   in 2007) was still seeing some notable production use.\n\n   It finally got \"we really mean it now\" EOL'd in late 2020 when\n   extended life-cycle support ended (see\n   https://access.redhat.com/support/policy/updates/errata). RHEL 6\n   does not have a libcurl affected by these changes.\n\n - It ended with a patch to \"error on too-old curl\", i.e. to make\n   compiling on versions older than 7.19.4 an error. I've ejected that\n   per the discussion about backports confusing that issue.\n\nThis series is a re-roll of patches found in Peff's GitHub repo at\njk/no-ancient-curl, which were already-rebased versions of those\npatches. His original on-list version had his Signed-off-by, but the\nrange-diff is against that branch, hence the addition of\nSigned-off-by in the range-diff.\n\nPeff's original 3/4 had a subtle bug in keeping the \"CURLOPT_POST301\"\nbranch of an ifdef/elif, spotted by Mischa POSLAWSKY, a fix for that\nis squashed in here. See\nhttps://lore.kernel.org/git/20170810123641.GG2363@shiar.net/\n\nI then added a couple of patches on top, one is based on my comments\non the v1 http://lore.kernel.org/git/871sokhoi9.fsf@gmail.com,\ni.e. the CURLAUTH_DIGEST_IE and CURLOPT_USE_SSL flags are also\nversion-based, and we can drop support for curls that don't have them.\n\nI then renamed the ancient CURLOPT_FILE alias to\nCURLOPT_WRITEDATA. Incidentally that's how I remembered to dig up this\nseries, i.e. I tried to search for \"CURLOPT_FILE\" in API documentation\nwhile reading our HTTP code, but had a hard time finding it, turns out\nwe were using a very ancient synonym for the preferred name.\n\nJeff King (3):\n  http: drop support for curl < 7.11.1\n  http: drop support for curl < 7.16.0\n  http: drop support for curl < 7.19.4\n\nÆvar Arnfjörð Bjarmason (2):\n  http: drop support for curl < 7.19.3 and < 7.16.4 (again)\n  http: rename CURLOPT_FILE to CURLOPT_WRITEDATA\n\n http-push.c   |  29 +--------\n http-walker.c |  14 +----\n http.c        | 169 ++------------------------------------------------\n http.h        |  46 --------------\n imap-send.c   |   4 --\n remote-curl.c |  11 +---\n 6 files changed, 10 insertions(+), 263 deletions(-)\n\nRange-diff against v1:\n1:  8793735cc2c ! 1:  dcbb6f95652 http: drop support for curl < 7.11.1\n    @@ Metadata\n      ## Commit message ##\n         http: drop support for curl < 7.11.1\n     \n    -    Recent versions of Git will not build with curl older than\n    -    7.11.1 due to (at least) two issues:\n    +    Drop support for this ancient version of curl and simplify the code by\n    +    allowing us get rid of some \"#ifdef\"'s.\n    +\n    +    Git will not build with vanilla curl older than 7.11.1 due to (at\n    +    least) two issues:\n     \n           - our use of CURLOPT_POSTFIELDSIZE in 37ee680d9b\n             (http.postbuffer: allow full range of ssize_t values,\n    @@ Commit message\n         obvious benefit is that we'll have fewer conditional bits\n         cluttering the code.\n     \n    -    But more importantly, we're doing a disservice to users to\n    -    pretend that Git works with old versions. It's clear that\n    -    nobody is testing modern Git with such old versions of curl\n    -    (we've had 3 released versions with the CURLPROTO issue\n    -    without a report of anyone seeing the breakage in the wild).\n    -    And there are a lot of subtle ways we could be getting this\n    -    wrong (for instance, curl prior to 7.17.0 did not copy\n    -    string arguments to curl_easy_setopt(), which means that\n    -    using an old copy of curl could produce use-after-free\n    -    bugs that are not present with more recent versions).\n    -\n         This patch drops all #ifdefs that reference older versions\n         (note that curl's preprocessor macros are in hex, so we're\n         looking for 070b01, not 071101).\n     \n    +    Signed-off-by: Jeff King <peff@peff.net>\n    +    Signed-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n    +\n      ## http.c ##\n     @@\n      static struct trace_key trace_curl = TRACE_KEY_INIT(CURL);\n2:  15638cd1856 ! 2:  1c9f3bc031b http: drop support for curl < 7.16.0\n    @@ Metadata\n      ## Commit message ##\n         http: drop support for curl < 7.16.0\n     \n    -    As discussed in the previous commit, Git is not well-tested\n    -    with old versions of curl (and in fact since v2.12.0 does\n    -    not even compile with versions older than 7.19.4). Let's\n    -    stop pretending we support curl that old and drop any\n    -    now-obslete #ifdefs.\n    +    In the last commit we dropped support for curl < 7.11.1, let's\n    +    continue that and drop support for versions older than 7.16.0. This\n    +    allows us to get rid of some now-obsolete #ifdefs.\n     \n    -    Choosing 7.16.0 is a somewhat arbitrary cutoff, but:\n    +    Choosing 7.16.0 is a somewhat arbitrary cutoff:\n     \n    -      1. it came out in October of 2006, over 10 years ago.\n    -         Besides being a nice round number, it's a common\n    -         end-of-life support period, even for conservative\n    +      1. It came out in October of 2006, almost 15 years ago.\n    +         Besides being a nice round number, around 10 years is\n    +         a common end-of-life support period, even for conservative\n              distributions.\n     \n    -      2. that version introduced the curl_multi interface, which\n    +      2. That version introduced the curl_multi interface, which\n              gives us a lot of bang for the buck in removing #ifdefs\n     \n    +    RHEL 5 came with curl 7.15.5[1] (released in August 2006). RHEL 5's\n    +    extended life cycle program ended on 2020-11-30[1]. RHEL 6 comes with\n    +    curl 7.19.7 (released in November 2009), and RHEL 7 comes with\n    +    7.29.0 (released in February 2013).\n    +\n    +    1. http://lore.kernel.org/git/873e1f31-2a96-5b72-2f20-a5816cad1b51@jupiterrise.com\n    +\n    +    Signed-off-by: Jeff King <peff@peff.net>\n    +    Signed-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n    +\n      ## http-push.c ##\n     @@ http-push.c: static void curl_setup_http(CURL *curl, const char *url,\n      \tcurl_easy_setopt(curl, CURLOPT_INFILE, buffer);\n    @@ http.h: void finish_all_active_slots(void);\n      void http_init(struct remote *remote, const char *url,\n      \t       int proactive_auth);\n     \n    + ## imap-send.c ##\n    +@@ imap-send.c: static int curl_append_msgs_to_imap(struct imap_server_conf *server,\n    + \tif (cred.username) {\n    + \t\tif (res == CURLE_OK)\n    + \t\t\tcredential_approve(&cred);\n    +-#if LIBCURL_VERSION_NUM >= 0x070d01\n    + \t\telse if (res == CURLE_LOGIN_DENIED)\n    +-#else\n    +-\t\telse\n    +-#endif\n    + \t\t\tcredential_reject(&cred);\n    + \t}\n    + \n    +\n      ## remote-curl.c ##\n     @@ remote-curl.c: static size_t rpc_out(void *ptr, size_t eltsize,\n      \treturn avail;\n3:  335046de7bc ! 3:  faae88b7fec http: drop support for curl < 7.19.4\n    @@ Metadata\n      ## Commit message ##\n         http: drop support for curl < 7.19.4\n     \n    -    Since v2.12.0, Git does not compile with versions of curl\n    -    older than 7.19.4. That version of curl is about 8 years\n    -    old. This means it may still be used in some distributions\n    -    with long-running support periods. But the fact that we\n    -    haven't received a single bug report about the compile-time\n    -    breakage implies that nobody cares about building recent\n    -    releases on such platforms.\n    +    In the last commit we dropped support for curl < 7.16.0, let's\n    +    continue that and drop support for versions older than 7.19.4. This\n    +    allows us to simplify the code by getting rid of some \"#ifdef\"'s.\n     \n    -    As discussed in the previous two commits, this cleans up the\n    -    code and gives a more realistic signal to users about which\n    -    versions of Git are actually tested (in particular, this\n    -    moves us past the potential use-after-free issues with curl\n    -    older than 7.17.0).\n    +    Git was broken with vanilla curl < 7.19.4 from v2.12.0 until\n    +    v2.15.0. Compiling with it was broken by using CURLPROTO_* outside any\n    +    \"#ifdef\" in aeae4db174 (http: create function to get curl allowed\n    +    protocols, 2016-12-14), and fixed in v2.15.0 in f18777ba6ef (http: fix\n    +    handling of missing CURLPROTO_*, 2017-08-11).\n    +\n    +    It's unclear how much anyone was impacted by that in practice, since\n    +    as noted in [1] RHEL versions using curl older than that still\n    +    compiled, because RedHat backported some features. Perhaps other\n    +    vendors did the same.\n    +\n    +    Still, it's one datapoint indicating that it wasn't in active use at\n    +    the time. That (the v2.12.0 release) was in Feb 24, 2017, with v2.15.0\n    +    on Oct 30, 2017, it's now mid-2021.\n    +\n    +    1. http://lore.kernel.org/git/c8a2716d-76ac-735c-57f9-175ca3acbcb0@jupiterrise.com;\n    +       followed-up by f18777ba6ef (http: fix handling of missing CURLPROTO_*,\n    +       2017-08-11)\n    +\n    +    Signed-off-by: Jeff King <peff@peff.net>\n    +    Signed-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n     \n      ## http.c ##\n     @@ http.c: static int min_curl_sessions = 1;\n    @@ http.c: static void var_override(const char **var, char *value)\n      }\n      \n      static void init_curl_proxy_auth(CURL *result)\n    +@@ http.c: void setup_curl_trace(CURL *handle)\n    + \tcurl_easy_setopt(handle, CURLOPT_DEBUGDATA, NULL);\n    + }\n    + \n    +-#ifdef CURLPROTO_HTTP\n    + static long get_curl_allowed_protocols(int from_user)\n    + {\n    + \tlong allowed_protocols = 0;\n    +@@ http.c: static long get_curl_allowed_protocols(int from_user)\n    + \n    + \treturn allowed_protocols;\n    + }\n    +-#endif\n    + \n    + #if LIBCURL_VERSION_NUM >=0x072f00\n    + static int get_curl_http_version_opt(const char *version_string, long *opt)\n     @@ http.c: static CURL *get_curl_handle(void)\n      \t}\n      \n    @@ http.c: static CURL *get_curl_handle(void)\n     -#if LIBCURL_VERSION_NUM >= 0x071301\n      \tcurl_easy_setopt(result, CURLOPT_POSTREDIR, CURL_REDIR_POST_ALL);\n     -#elif LIBCURL_VERSION_NUM >= 0x071101\n    - \tcurl_easy_setopt(result, CURLOPT_POST301, 1);\n    +-\tcurl_easy_setopt(result, CURLOPT_POST301, 1);\n     -#endif\n     -#ifdef CURLPROTO_HTTP\n      \tcurl_easy_setopt(result, CURLOPT_REDIR_PROTOCOLS,\n4:  e049f37357a < -:  ----------- http: #error on too-old curl\n-:  ----------- > 4:  9a30e92520c http: drop support for curl < 7.19.3 and < 7.16.4 (again)\n-:  ----------- > 5:  64e510b4a6b http: rename CURLOPT_FILE to CURLOPT_WRITEDATA\n-- \n2.32.0.874.ge7a9d58bfcf\n\n"},{"id":"430801","messageId":"patch-1.5-dcbb6f95652-20210721T220402Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-0.5-00000000000-20210721T220402Z-avarab@gmail.com","subject":"[PATCH v2 1/5] http: drop support for curl < 7.11.1","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-07-21T22:22:12Z","receivedAt":"2021-07-21T22:22:27Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"From: Jeff King <peff@peff.net>\n\nDrop support for this ancient version of curl and simplify the code by\nallowing us get rid of some \"#ifdef\"'s.\n\nGit will not build with vanilla curl older than 7.11.1 due to (at\nleast) two issues:\n\n  - our use of CURLOPT_POSTFIELDSIZE in 37ee680d9b\n    (http.postbuffer: allow full range of ssize_t values,\n    2017-04-11). This field was introduced in curl 7.11.1.\n\n  - our use of CURLPROTO_* outside any #ifdef in aeae4db174\n    (http: create function to get curl allowed protocols,\n    2016-12-14). These were introduced in curl 7.19.4.\n\nWe could solve these compilation problems with more #ifdefs,\nbut it's not worth the trouble. Version 7.11.1 came out in\nMarch of 2004, over 13 years ago. Let's declare that too old\nand drop any existing ifdefs that go further back. One\nobvious benefit is that we'll have fewer conditional bits\ncluttering the code.\n\nThis patch drops all #ifdefs that reference older versions\n(note that curl's preprocessor macros are in hex, so we're\nlooking for 070b01, not 071101).\n\nSigned-off-by: Jeff King <peff@peff.net>\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n http.c        | 53 ---------------------------------------------------\n http.h        | 12 +-----------\n remote-curl.c |  3 ---\n 3 files changed, 1 insertion(+), 67 deletions(-)\n\ndiff --git a/http.c b/http.c\nindex 8119247149a..56182a89e25 100644\n--- a/http.c\n+++ b/http.c\n@@ -19,19 +19,11 @@\n static struct trace_key trace_curl = TRACE_KEY_INIT(CURL);\n static int trace_curl_data = 1;\n static int trace_curl_redact = 1;\n-#if LIBCURL_VERSION_NUM >= 0x070a08\n long int git_curl_ipresolve = CURL_IPRESOLVE_WHATEVER;\n-#else\n-long int git_curl_ipresolve;\n-#endif\n int active_requests;\n int http_is_verbose;\n ssize_t http_post_buffer = 16 * LARGE_PACKET_MAX;\n \n-#if LIBCURL_VERSION_NUM >= 0x070a06\n-#define LIBCURL_CAN_HANDLE_AUTH_ANY\n-#endif\n-\n static int min_curl_sessions = 1;\n static int curl_session_count;\n #ifdef USE_CURL_MULTI\n@@ -68,15 +60,9 @@ static struct {\n \t{ \"tlsv1.3\", CURL_SSLVERSION_TLSv1_3 },\n #endif\n };\n-#if LIBCURL_VERSION_NUM >= 0x070903\n static const char *ssl_key;\n-#endif\n-#if LIBCURL_VERSION_NUM >= 0x070908\n static const char *ssl_capath;\n-#endif\n-#if LIBCURL_VERSION_NUM >= 0x071304\n static const char *curl_no_proxy;\n-#endif\n #if LIBCURL_VERSION_NUM >= 0x072c00\n static const char *ssl_pinnedkey;\n #endif\n@@ -101,9 +87,7 @@ static struct {\n \t{ \"digest\", CURLAUTH_DIGEST },\n \t{ \"negotiate\", CURLAUTH_GSSNEGOTIATE },\n \t{ \"ntlm\", CURLAUTH_NTLM },\n-#ifdef LIBCURL_CAN_HANDLE_AUTH_ANY\n \t{ \"anyauth\", CURLAUTH_ANY },\n-#endif\n \t/*\n \t * CURLAUTH_DIGEST_IE has no corresponding command-line option in\n \t * curl(1) and is not included in CURLAUTH_ANY, so we leave it out\n@@ -143,7 +127,6 @@ enum http_follow_config http_follow_config = HTTP_FOLLOW_INITIAL;\n \n static struct credential cert_auth = CREDENTIAL_INIT;\n static int ssl_cert_password_required;\n-#ifdef LIBCURL_CAN_HANDLE_AUTH_ANY\n static unsigned long http_auth_methods = CURLAUTH_ANY;\n static int http_auth_methods_restricted;\n /* Modes for which empty_auth cannot actually help us. */\n@@ -153,7 +136,6 @@ static unsigned long empty_auth_useless =\n \t| CURLAUTH_DIGEST_IE\n #endif\n \t| CURLAUTH_DIGEST;\n-#endif\n \n static struct curl_slist *pragma_header;\n static struct curl_slist *no_pragma_header;\n@@ -237,12 +219,8 @@ static void finish_active_slot(struct active_request_slot *slot)\n \tif (slot->results != NULL) {\n \t\tslot->results->curl_result = slot->curl_result;\n \t\tslot->results->http_code = slot->http_code;\n-#if LIBCURL_VERSION_NUM >= 0x070a08\n \t\tcurl_easy_getinfo(slot->curl, CURLINFO_HTTPAUTH_AVAIL,\n \t\t\t\t  &slot->results->auth_avail);\n-#else\n-\t\tslot->results->auth_avail = 0;\n-#endif\n \n \t\tcurl_easy_getinfo(slot->curl, CURLINFO_HTTP_CONNECTCODE,\n \t\t\t&slot->results->http_connectcode);\n@@ -305,14 +283,10 @@ static int http_options(const char *var, const char *value, void *cb)\n \t\treturn git_config_string(&ssl_version, var, value);\n \tif (!strcmp(\"http.sslcert\", var))\n \t\treturn git_config_pathname(&ssl_cert, var, value);\n-#if LIBCURL_VERSION_NUM >= 0x070903\n \tif (!strcmp(\"http.sslkey\", var))\n \t\treturn git_config_pathname(&ssl_key, var, value);\n-#endif\n-#if LIBCURL_VERSION_NUM >= 0x070908\n \tif (!strcmp(\"http.sslcapath\", var))\n \t\treturn git_config_pathname(&ssl_capath, var, value);\n-#endif\n \tif (!strcmp(\"http.sslcainfo\", var))\n \t\treturn git_config_pathname(&ssl_cainfo, var, value);\n \tif (!strcmp(\"http.sslcertpasswordprotected\", var)) {\n@@ -461,12 +435,6 @@ static int curl_empty_auth_enabled(void)\n \tif (curl_empty_auth >= 0)\n \t\treturn curl_empty_auth;\n \n-#ifndef LIBCURL_CAN_HANDLE_AUTH_ANY\n-\t/*\n-\t * Our libcurl is too old to do AUTH_ANY in the first place;\n-\t * just default to turning the feature off.\n-\t */\n-#else\n \t/*\n \t * In the automatic case, kick in the empty-auth\n \t * hack as long as we would potentially try some\n@@ -479,7 +447,6 @@ static int curl_empty_auth_enabled(void)\n \tif (http_auth_methods_restricted &&\n \t    (http_auth_methods & ~empty_auth_useless))\n \t\treturn 1;\n-#endif\n \treturn 0;\n }\n \n@@ -552,7 +519,6 @@ static void init_curl_proxy_auth(CURL *result)\n \n \tvar_override(&http_proxy_authmethod, getenv(\"GIT_HTTP_PROXY_AUTHMETHOD\"));\n \n-#if LIBCURL_VERSION_NUM >= 0x070a07 /* CURLOPT_PROXYAUTH and CURLAUTH_ANY */\n \tif (http_proxy_authmethod) {\n \t\tint i;\n \t\tfor (i = 0; i < ARRAY_SIZE(proxy_authmethods); i++) {\n@@ -570,7 +536,6 @@ static void init_curl_proxy_auth(CURL *result)\n \t}\n \telse\n \t\tcurl_easy_setopt(result, CURLOPT_PROXYAUTH, CURLAUTH_ANY);\n-#endif\n }\n \n static int has_cert_password(void)\n@@ -879,12 +844,8 @@ static CURL *get_curl_handle(void)\n     }\n #endif\n \n-#if LIBCURL_VERSION_NUM >= 0x070907\n \tcurl_easy_setopt(result, CURLOPT_NETRC, CURL_NETRC_OPTIONAL);\n-#endif\n-#ifdef LIBCURL_CAN_HANDLE_AUTH_ANY\n \tcurl_easy_setopt(result, CURLOPT_HTTPAUTH, CURLAUTH_ANY);\n-#endif\n \n #ifdef CURLGSSAPI_DELEGATION_FLAG\n \tif (curl_deleg) {\n@@ -940,14 +901,10 @@ static CURL *get_curl_handle(void)\n \t\tcurl_easy_setopt(result, CURLOPT_SSLCERT, ssl_cert);\n \tif (has_cert_password())\n \t\tcurl_easy_setopt(result, CURLOPT_KEYPASSWD, cert_auth.password);\n-#if LIBCURL_VERSION_NUM >= 0x070903\n \tif (ssl_key != NULL)\n \t\tcurl_easy_setopt(result, CURLOPT_SSLKEY, ssl_key);\n-#endif\n-#if LIBCURL_VERSION_NUM >= 0x070908\n \tif (ssl_capath != NULL)\n \t\tcurl_easy_setopt(result, CURLOPT_CAPATH, ssl_capath);\n-#endif\n #if LIBCURL_VERSION_NUM >= 0x072c00\n \tif (ssl_pinnedkey != NULL)\n \t\tcurl_easy_setopt(result, CURLOPT_PINNEDPUBLICKEY, ssl_pinnedkey);\n@@ -1180,12 +1137,8 @@ void http_init(struct remote *remote, const char *url, int proactive_auth)\n \t\tcurl_ssl_verify = 0;\n \n \tset_from_env(&ssl_cert, \"GIT_SSL_CERT\");\n-#if LIBCURL_VERSION_NUM >= 0x070903\n \tset_from_env(&ssl_key, \"GIT_SSL_KEY\");\n-#endif\n-#if LIBCURL_VERSION_NUM >= 0x070908\n \tset_from_env(&ssl_capath, \"GIT_SSL_CAPATH\");\n-#endif\n \tset_from_env(&ssl_cainfo, \"GIT_SSL_CAINFO\");\n \n \tset_from_env(&user_agent, \"GIT_HTTP_USER_AGENT\");\n@@ -1367,12 +1320,8 @@ struct active_request_slot *get_active_slot(void)\n \telse\n \t\tcurl_easy_setopt(slot->curl, CURLOPT_FOLLOWLOCATION, 0);\n \n-#if LIBCURL_VERSION_NUM >= 0x070a08\n \tcurl_easy_setopt(slot->curl, CURLOPT_IPRESOLVE, git_curl_ipresolve);\n-#endif\n-#ifdef LIBCURL_CAN_HANDLE_AUTH_ANY\n \tcurl_easy_setopt(slot->curl, CURLOPT_HTTPAUTH, http_auth_methods);\n-#endif\n \tif (http_auth.password || curl_empty_auth_enabled())\n \t\tinit_curl_http_auth(slot->curl);\n \n@@ -1654,13 +1603,11 @@ static int handle_curl_result(struct slot_results *results)\n \t\t\tcredential_reject(&http_auth);\n \t\t\treturn HTTP_NOAUTH;\n \t\t} else {\n-#ifdef LIBCURL_CAN_HANDLE_AUTH_ANY\n \t\t\thttp_auth_methods &= ~CURLAUTH_GSSNEGOTIATE;\n \t\t\tif (results->auth_avail) {\n \t\t\t\thttp_auth_methods &= results->auth_avail;\n \t\t\t\thttp_auth_methods_restricted = 1;\n \t\t\t}\n-#endif\n \t\t\treturn HTTP_REAUTH;\n \t\t}\n \t} else {\ndiff --git a/http.h b/http.h\nindex bf3d1270ad8..d2f8cc56617 100644\n--- a/http.h\n+++ b/http.h\n@@ -22,13 +22,7 @@\n #define DEFAULT_MAX_REQUESTS 5\n #endif\n \n-#if LIBCURL_VERSION_NUM < 0x070704\n-#define curl_global_cleanup() do { /* nothing */ } while (0)\n-#endif\n-\n-#if LIBCURL_VERSION_NUM < 0x070800\n-#define curl_global_init(a) do { /* nothing */ } while (0)\n-#elif LIBCURL_VERSION_NUM >= 0x070c00\n+#if LIBCURL_VERSION_NUM >= 0x070c00\n #define curl_global_init(a) curl_global_init_mem(a, xmalloc, free, \\\n \t\t\t\t\t\txrealloc, xstrdup, xcalloc)\n #endif\n@@ -37,10 +31,6 @@\n #define NO_CURL_EASY_DUPHANDLE\n #endif\n \n-#if LIBCURL_VERSION_NUM < 0x070a03\n-#define CURLE_HTTP_RETURNED_ERROR CURLE_HTTP_NOT_FOUND\n-#endif\n-\n #if LIBCURL_VERSION_NUM < 0x070c03\n #define NO_CURL_IOCTL\n #endif\ndiff --git a/remote-curl.c b/remote-curl.c\nindex 9d432c299a2..9e6918468e4 100644\n--- a/remote-curl.c\n+++ b/remote-curl.c\n@@ -185,8 +185,6 @@ static int set_option(const char *name, const char *value)\n \t\t\t\t\t\t strbuf_detach(&unquoted, NULL));\n \t\t}\n \t\treturn 0;\n-\n-#if LIBCURL_VERSION_NUM >= 0x070a08\n \t} else if (!strcmp(name, \"family\")) {\n \t\tif (!strcmp(value, \"ipv4\"))\n \t\t\tgit_curl_ipresolve = CURL_IPRESOLVE_V4;\n@@ -197,7 +195,6 @@ static int set_option(const char *name, const char *value)\n \t\telse\n \t\t\treturn -1;\n \t\treturn 0;\n-#endif /* LIBCURL_VERSION_NUM >= 0x070a08 */\n \t} else if (!strcmp(name, \"from-promisor\")) {\n \t\toptions.from_promisor = 1;\n \t\treturn 0;\n-- \n2.32.0.874.ge7a9d58bfcf\n\n"},{"id":"430802","messageId":"patch-2.5-1c9f3bc031b-20210721T220402Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-0.5-00000000000-20210721T220402Z-avarab@gmail.com","subject":"[PATCH v2 2/5] http: drop support for curl < 7.16.0","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-07-21T22:22:13Z","receivedAt":"2021-07-21T22:22:28Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"From: Jeff King <peff@peff.net>\n\nIn the last commit we dropped support for curl < 7.11.1, let's\ncontinue that and drop support for versions older than 7.16.0. This\nallows us to get rid of some now-obsolete #ifdefs.\n\nChoosing 7.16.0 is a somewhat arbitrary cutoff:\n\n  1. It came out in October of 2006, almost 15 years ago.\n     Besides being a nice round number, around 10 years is\n     a common end-of-life support period, even for conservative\n     distributions.\n\n  2. That version introduced the curl_multi interface, which\n     gives us a lot of bang for the buck in removing #ifdefs\n\nRHEL 5 came with curl 7.15.5[1] (released in August 2006). RHEL 5's\nextended life cycle program ended on 2020-11-30[1]. RHEL 6 comes with\ncurl 7.19.7 (released in November 2009), and RHEL 7 comes with\n7.29.0 (released in February 2013).\n\n1. http://lore.kernel.org/git/873e1f31-2a96-5b72-2f20-a5816cad1b51@jupiterrise.com\n\nSigned-off-by: Jeff King <peff@peff.net>\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n http-push.c   | 23 ---------------------\n http-walker.c | 12 -----------\n http.c        | 56 +--------------------------------------------------\n http.h        | 25 +----------------------\n imap-send.c   |  4 ----\n remote-curl.c |  4 ----\n 6 files changed, 2 insertions(+), 122 deletions(-)\n\ndiff --git a/http-push.c b/http-push.c\nindex d7cb1675a2d..aa3de7c1086 100644\n--- a/http-push.c\n+++ b/http-push.c\n@@ -203,10 +203,8 @@ static void curl_setup_http(CURL *curl, const char *url,\n \tcurl_easy_setopt(curl, CURLOPT_INFILE, buffer);\n \tcurl_easy_setopt(curl, CURLOPT_INFILESIZE, buffer->buf.len);\n \tcurl_easy_setopt(curl, CURLOPT_READFUNCTION, fread_buffer);\n-#ifndef NO_CURL_IOCTL\n \tcurl_easy_setopt(curl, CURLOPT_IOCTLFUNCTION, ioctl_buffer);\n \tcurl_easy_setopt(curl, CURLOPT_IOCTLDATA, buffer);\n-#endif\n \tcurl_easy_setopt(curl, CURLOPT_WRITEFUNCTION, write_fn);\n \tcurl_easy_setopt(curl, CURLOPT_NOBODY, 0);\n \tcurl_easy_setopt(curl, CURLOPT_CUSTOMREQUEST, custom_req);\n@@ -249,8 +247,6 @@ static void process_response(void *callback_data)\n \tfinish_request(request);\n }\n \n-#ifdef USE_CURL_MULTI\n-\n static void start_fetch_loose(struct transfer_request *request)\n {\n \tstruct active_request_slot *slot;\n@@ -299,7 +295,6 @@ static void start_mkcol(struct transfer_request *request)\n \t\tFREE_AND_NULL(request->url);\n \t}\n }\n-#endif\n \n static void start_fetch_packed(struct transfer_request *request)\n {\n@@ -605,7 +600,6 @@ static void finish_request(struct transfer_request *request)\n \t}\n }\n \n-#ifdef USE_CURL_MULTI\n static int is_running_queue;\n static int fill_active_slot(void *unused)\n {\n@@ -629,7 +623,6 @@ static int fill_active_slot(void *unused)\n \t}\n \treturn 0;\n }\n-#endif\n \n static void get_remote_object_list(unsigned char parent);\n \n@@ -658,10 +651,8 @@ static void add_fetch_request(struct object *obj)\n \trequest->next = request_queue_head;\n \trequest_queue_head = request;\n \n-#ifdef USE_CURL_MULTI\n \tfill_active_slots();\n \tstep_active_slots();\n-#endif\n }\n \n static int add_send_request(struct object *obj, struct remote_lock *lock)\n@@ -696,10 +687,8 @@ static int add_send_request(struct object *obj, struct remote_lock *lock)\n \trequest->next = request_queue_head;\n \trequest_queue_head = request;\n \n-#ifdef USE_CURL_MULTI\n \tfill_active_slots();\n \tstep_active_slots();\n-#endif\n \n \treturn 1;\n }\n@@ -1682,21 +1671,15 @@ static int delete_remote_branch(const char *pattern, int force)\n \n static void run_request_queue(void)\n {\n-#ifdef USE_CURL_MULTI\n \tis_running_queue = 1;\n \tfill_active_slots();\n \tadd_fill_function(NULL, fill_active_slot);\n-#endif\n \tdo {\n \t\tfinish_all_active_slots();\n-#ifdef USE_CURL_MULTI\n \t\tfill_active_slots();\n-#endif\n \t} while (request_queue_head && !aborted);\n \n-#ifdef USE_CURL_MULTI\n \tis_running_queue = 0;\n-#endif\n }\n \n int cmd_main(int argc, const char **argv)\n@@ -1770,10 +1753,6 @@ int cmd_main(int argc, const char **argv)\n \t\tbreak;\n \t}\n \n-#ifndef USE_CURL_MULTI\n-\tdie(\"git-push is not available for http/https repository when not compiled with USE_CURL_MULTI\");\n-#endif\n-\n \tif (!repo->url)\n \t\tusage(http_push_usage);\n \n@@ -1786,9 +1765,7 @@ int cmd_main(int argc, const char **argv)\n \n \thttp_init(NULL, repo->url, 1);\n \n-#ifdef USE_CURL_MULTI\n \tis_running_queue = 0;\n-#endif\n \n \t/* Verify DAV compliance/lock support */\n \tif (!locking_available()) {\ndiff --git a/http-walker.c b/http-walker.c\nindex 90d8ecb57ef..19e31623f04 100644\n--- a/http-walker.c\n+++ b/http-walker.c\n@@ -127,7 +127,6 @@ static void release_object_request(struct object_request *obj_req)\n \tfree(obj_req);\n }\n \n-#ifdef USE_CURL_MULTI\n static int fill_active_slot(struct walker *walker)\n {\n \tstruct object_request *obj_req;\n@@ -146,7 +145,6 @@ static int fill_active_slot(struct walker *walker)\n \t}\n \treturn 0;\n }\n-#endif\n \n static void prefetch(struct walker *walker, unsigned char *sha1)\n {\n@@ -163,10 +161,8 @@ static void prefetch(struct walker *walker, unsigned char *sha1)\n \thttp_is_verbose = walker->get_verbosely;\n \tlist_add_tail(&newreq->node, &object_queue_head);\n \n-#ifdef USE_CURL_MULTI\n \tfill_active_slots();\n \tstep_active_slots();\n-#endif\n }\n \n static int is_alternate_allowed(const char *url)\n@@ -357,11 +353,9 @@ static void fetch_alternates(struct walker *walker, const char *base)\n \t * wait for them to arrive and return to processing this request's\n \t * curl message\n \t */\n-#ifdef USE_CURL_MULTI\n \twhile (cdata->got_alternates == 0) {\n \t\tstep_active_slots();\n \t}\n-#endif\n \n \t/* Nothing to do if they've already been fetched */\n \tif (cdata->got_alternates == 1)\n@@ -505,12 +499,8 @@ static int fetch_object(struct walker *walker, unsigned char *hash)\n \t\treturn 0;\n \t}\n \n-#ifdef USE_CURL_MULTI\n \twhile (obj_req->state == WAITING)\n \t\tstep_active_slots();\n-#else\n-\tstart_object_request(walker, obj_req);\n-#endif\n \n \t/*\n \t * obj_req->req might change when fetching alternates in the callback\n@@ -623,9 +613,7 @@ struct walker *get_http_walker(const char *url)\n \twalker->cleanup = cleanup;\n \twalker->data = data;\n \n-#ifdef USE_CURL_MULTI\n \tadd_fill_function(walker, (int (*)(void *)) fill_active_slot);\n-#endif\n \n \treturn walker;\n }\ndiff --git a/http.c b/http.c\nindex 56182a89e25..ef00e930232 100644\n--- a/http.c\n+++ b/http.c\n@@ -26,10 +26,8 @@ ssize_t http_post_buffer = 16 * LARGE_PACKET_MAX;\n \n static int min_curl_sessions = 1;\n static int curl_session_count;\n-#ifdef USE_CURL_MULTI\n static int max_requests = -1;\n static CURLM *curlm;\n-#endif\n #ifndef NO_CURL_EASY_DUPHANDLE\n static CURL *curl_default;\n #endif\n@@ -117,14 +115,6 @@ static int curl_empty_auth = -1;\n \n enum http_follow_config http_follow_config = HTTP_FOLLOW_INITIAL;\n \n-#if LIBCURL_VERSION_NUM >= 0x071700\n-/* Use CURLOPT_KEYPASSWD as is */\n-#elif LIBCURL_VERSION_NUM >= 0x070903\n-#define CURLOPT_KEYPASSWD CURLOPT_SSLKEYPASSWD\n-#else\n-#define CURLOPT_KEYPASSWD CURLOPT_SSLCERTPASSWD\n-#endif\n-\n static struct credential cert_auth = CREDENTIAL_INIT;\n static int ssl_cert_password_required;\n static unsigned long http_auth_methods = CURLAUTH_ANY;\n@@ -168,7 +158,6 @@ size_t fread_buffer(char *ptr, size_t eltsize, size_t nmemb, void *buffer_)\n \treturn size / eltsize;\n }\n \n-#ifndef NO_CURL_IOCTL\n curlioerr ioctl_buffer(CURL *handle, int cmd, void *clientp)\n {\n \tstruct buffer *buffer = clientp;\n@@ -185,7 +174,6 @@ curlioerr ioctl_buffer(CURL *handle, int cmd, void *clientp)\n \t\treturn CURLIOE_UNKNOWNCMD;\n \t}\n }\n-#endif\n \n size_t fwrite_buffer(char *ptr, size_t eltsize, size_t nmemb, void *buffer_)\n {\n@@ -233,12 +221,9 @@ static void finish_active_slot(struct active_request_slot *slot)\n \n static void xmulti_remove_handle(struct active_request_slot *slot)\n {\n-#ifdef USE_CURL_MULTI\n \tcurl_multi_remove_handle(curlm, slot->curl);\n-#endif\n }\n \n-#ifdef USE_CURL_MULTI\n static void process_curl_messages(void)\n {\n \tint num_messages;\n@@ -266,7 +251,6 @@ static void process_curl_messages(void)\n \t\tcurl_message = curl_multi_info_read(curlm, &num_messages);\n \t}\n }\n-#endif\n \n static int http_options(const char *var, const char *value, void *cb)\n {\n@@ -315,18 +299,14 @@ static int http_options(const char *var, const char *value, void *cb)\n \n \tif (!strcmp(\"http.minsessions\", var)) {\n \t\tmin_curl_sessions = git_config_int(var, value);\n-#ifndef USE_CURL_MULTI\n \t\tif (min_curl_sessions > 1)\n \t\t\tmin_curl_sessions = 1;\n-#endif\n \t\treturn 0;\n \t}\n-#ifdef USE_CURL_MULTI\n \tif (!strcmp(\"http.maxrequests\", var)) {\n \t\tmax_requests = git_config_int(var, value);\n \t\treturn 0;\n \t}\n-#endif\n \tif (!strcmp(\"http.lowspeedlimit\", var)) {\n \t\tcurl_low_speed_limit = (long)git_config_int(var, value);\n \t\treturn 0;\n@@ -574,7 +554,7 @@ static void set_curl_keepalive(CURL *c)\n \tcurl_easy_setopt(c, CURLOPT_TCP_KEEPALIVE, 1);\n }\n \n-#elif LIBCURL_VERSION_NUM >= 0x071000\n+#else\n static int sockopt_callback(void *client, curl_socket_t fd, curlsocktype type)\n {\n \tint ka = 1;\n@@ -595,12 +575,6 @@ static void set_curl_keepalive(CURL *c)\n {\n \tcurl_easy_setopt(c, CURLOPT_SOCKOPTFUNCTION, sockopt_callback);\n }\n-\n-#else\n-static void set_curl_keepalive(CURL *c)\n-{\n-\t/* not supported on older curl versions */\n-}\n #endif\n \n static void redact_sensitive_header(struct strbuf *header)\n@@ -1121,7 +1095,6 @@ void http_init(struct remote *remote, const char *url, int proactive_auth)\n \tno_pragma_header = curl_slist_append(http_copy_default_headers(),\n \t\t\"Pragma:\");\n \n-#ifdef USE_CURL_MULTI\n \t{\n \t\tchar *http_max_requests = getenv(\"GIT_HTTP_MAX_REQUESTS\");\n \t\tif (http_max_requests != NULL)\n@@ -1131,7 +1104,6 @@ void http_init(struct remote *remote, const char *url, int proactive_auth)\n \tcurlm = curl_multi_init();\n \tif (!curlm)\n \t\tdie(\"curl_multi_init failed\");\n-#endif\n \n \tif (getenv(\"GIT_SSL_NO_VERIFY\"))\n \t\tcurl_ssl_verify = 0;\n@@ -1154,10 +1126,8 @@ void http_init(struct remote *remote, const char *url, int proactive_auth)\n \t\tcurl_ssl_verify = 1;\n \n \tcurl_session_count = 0;\n-#ifdef USE_CURL_MULTI\n \tif (max_requests < 1)\n \t\tmax_requests = DEFAULT_MAX_REQUESTS;\n-#endif\n \n \tset_from_env(&http_proxy_ssl_cert, \"GIT_PROXY_SSL_CERT\");\n \tset_from_env(&http_proxy_ssl_key, \"GIT_PROXY_SSL_KEY\");\n@@ -1201,9 +1171,7 @@ void http_cleanup(void)\n \tcurl_easy_cleanup(curl_default);\n #endif\n \n-#ifdef USE_CURL_MULTI\n \tcurl_multi_cleanup(curlm);\n-#endif\n \tcurl_global_cleanup();\n \n \tstring_list_clear(&extra_http_headers, 0);\n@@ -1250,7 +1218,6 @@ struct active_request_slot *get_active_slot(void)\n \tstruct active_request_slot *slot = active_queue_head;\n \tstruct active_request_slot *newslot;\n \n-#ifdef USE_CURL_MULTI\n \tint num_transfers;\n \n \t/* Wait for a slot to open up if the queue is full */\n@@ -1259,7 +1226,6 @@ struct active_request_slot *get_active_slot(void)\n \t\tif (num_transfers < active_requests)\n \t\t\tprocess_curl_messages();\n \t}\n-#endif\n \n \twhile (slot != NULL && slot->in_use)\n \t\tslot = slot->next;\n@@ -1330,7 +1296,6 @@ struct active_request_slot *get_active_slot(void)\n \n int start_active_slot(struct active_request_slot *slot)\n {\n-#ifdef USE_CURL_MULTI\n \tCURLMcode curlm_result = curl_multi_add_handle(curlm, slot->curl);\n \tint num_transfers;\n \n@@ -1348,11 +1313,9 @@ int start_active_slot(struct active_request_slot *slot)\n \t * something.\n \t */\n \tcurl_multi_perform(curlm, &num_transfers);\n-#endif\n \treturn 1;\n }\n \n-#ifdef USE_CURL_MULTI\n struct fill_chain {\n \tvoid *data;\n \tint (*fill)(void *);\n@@ -1411,11 +1374,9 @@ void step_active_slots(void)\n \t\tfill_active_slots();\n \t}\n }\n-#endif\n \n void run_active_slot(struct active_request_slot *slot)\n {\n-#ifdef USE_CURL_MULTI\n \tfd_set readfds;\n \tfd_set writefds;\n \tfd_set excfds;\n@@ -1428,7 +1389,6 @@ void run_active_slot(struct active_request_slot *slot)\n \t\tstep_active_slots();\n \n \t\tif (slot->in_use) {\n-#if LIBCURL_VERSION_NUM >= 0x070f04\n \t\t\tlong curl_timeout;\n \t\t\tcurl_multi_timeout(curlm, &curl_timeout);\n \t\t\tif (curl_timeout == 0) {\n@@ -1440,10 +1400,6 @@ void run_active_slot(struct active_request_slot *slot)\n \t\t\t\tselect_timeout.tv_sec  =  curl_timeout / 1000;\n \t\t\t\tselect_timeout.tv_usec = (curl_timeout % 1000) * 1000;\n \t\t\t}\n-#else\n-\t\t\tselect_timeout.tv_sec  = 0;\n-\t\t\tselect_timeout.tv_usec = 50000;\n-#endif\n \n \t\t\tmax_fd = -1;\n \t\t\tFD_ZERO(&readfds);\n@@ -1466,12 +1422,6 @@ void run_active_slot(struct active_request_slot *slot)\n \t\t\tselect(max_fd+1, &readfds, &writefds, &excfds, &select_timeout);\n \t\t}\n \t}\n-#else\n-\twhile (slot->in_use) {\n-\t\tslot->curl_result = curl_easy_perform(slot->curl);\n-\t\tfinish_active_slot(slot);\n-\t}\n-#endif\n }\n \n static void release_active_slot(struct active_request_slot *slot)\n@@ -1485,9 +1435,7 @@ static void release_active_slot(struct active_request_slot *slot)\n \t\t\tcurl_session_count--;\n \t\t}\n \t}\n-#ifdef USE_CURL_MULTI\n \tfill_active_slots();\n-#endif\n }\n \n void finish_all_active_slots(void)\n@@ -1613,12 +1561,10 @@ static int handle_curl_result(struct slot_results *results)\n \t} else {\n \t\tif (results->http_connectcode == 407)\n \t\t\tcredential_reject(&proxy_auth);\n-#if LIBCURL_VERSION_NUM >= 0x070c00\n \t\tif (!curl_errorstr[0])\n \t\t\tstrlcpy(curl_errorstr,\n \t\t\t\tcurl_easy_strerror(results->curl_result),\n \t\t\t\tsizeof(curl_errorstr));\n-#endif\n \t\treturn HTTP_ERROR;\n \t}\n }\ndiff --git a/http.h b/http.h\nindex d2f8cc56617..cb092622a73 100644\n--- a/http.h\n+++ b/http.h\n@@ -10,31 +10,12 @@\n #include \"remote.h\"\n #include \"url.h\"\n \n-/*\n- * We detect based on the cURL version if multi-transfer is\n- * usable in this implementation and define this symbol accordingly.\n- * This shouldn't be set by the Makefile or by the user (e.g. via CFLAGS).\n- */\n-#undef USE_CURL_MULTI\n-\n-#if LIBCURL_VERSION_NUM >= 0x071000\n-#define USE_CURL_MULTI\n #define DEFAULT_MAX_REQUESTS 5\n-#endif\n-\n-#if LIBCURL_VERSION_NUM >= 0x070c00\n-#define curl_global_init(a) curl_global_init_mem(a, xmalloc, free, \\\n-\t\t\t\t\t\txrealloc, xstrdup, xcalloc)\n-#endif\n \n-#if (LIBCURL_VERSION_NUM < 0x070c04) || (LIBCURL_VERSION_NUM == 0x071000)\n+#if LIBCURL_VERSION_NUM == 0x071000\n #define NO_CURL_EASY_DUPHANDLE\n #endif\n \n-#if LIBCURL_VERSION_NUM < 0x070c03\n-#define NO_CURL_IOCTL\n-#endif\n-\n /*\n  * CURLOPT_USE_SSL was known as CURLOPT_FTP_SSL up to 7.16.4,\n  * and the constants were known as CURLFTPSSL_*\n@@ -72,9 +53,7 @@ struct buffer {\n size_t fread_buffer(char *ptr, size_t eltsize, size_t nmemb, void *strbuf);\n size_t fwrite_buffer(char *ptr, size_t eltsize, size_t nmemb, void *strbuf);\n size_t fwrite_null(char *ptr, size_t eltsize, size_t nmemb, void *strbuf);\n-#ifndef NO_CURL_IOCTL\n curlioerr ioctl_buffer(CURL *handle, int cmd, void *clientp);\n-#endif\n \n /* Slot lifecycle functions */\n struct active_request_slot *get_active_slot(void);\n@@ -91,11 +70,9 @@ void finish_all_active_slots(void);\n int run_one_slot(struct active_request_slot *slot,\n \t\t struct slot_results *results);\n \n-#ifdef USE_CURL_MULTI\n void fill_active_slots(void);\n void add_fill_function(void *data, int (*fill)(void *));\n void step_active_slots(void);\n-#endif\n \n void http_init(struct remote *remote, const char *url,\n \t       int proactive_auth);\ndiff --git a/imap-send.c b/imap-send.c\nindex bb085d66d10..9844328b7b3 100644\n--- a/imap-send.c\n+++ b/imap-send.c\n@@ -1526,11 +1526,7 @@ static int curl_append_msgs_to_imap(struct imap_server_conf *server,\n \tif (cred.username) {\n \t\tif (res == CURLE_OK)\n \t\t\tcredential_approve(&cred);\n-#if LIBCURL_VERSION_NUM >= 0x070d01\n \t\telse if (res == CURLE_LOGIN_DENIED)\n-#else\n-\t\telse\n-#endif\n \t\t\tcredential_reject(&cred);\n \t}\n \ndiff --git a/remote-curl.c b/remote-curl.c\nindex 9e6918468e4..482d5a4656d 100644\n--- a/remote-curl.c\n+++ b/remote-curl.c\n@@ -706,7 +706,6 @@ static size_t rpc_out(void *ptr, size_t eltsize,\n \treturn avail;\n }\n \n-#ifndef NO_CURL_IOCTL\n static curlioerr rpc_ioctl(CURL *handle, int cmd, void *clientp)\n {\n \tstruct rpc_state *rpc = clientp;\n@@ -727,7 +726,6 @@ static curlioerr rpc_ioctl(CURL *handle, int cmd, void *clientp)\n \t\treturn CURLIOE_UNKNOWNCMD;\n \t}\n }\n-#endif\n \n struct check_pktline_state {\n \tchar len_buf[4];\n@@ -946,10 +944,8 @@ static int post_rpc(struct rpc_state *rpc, int stateless_connect, int flush_rece\n \t\trpc->initial_buffer = 1;\n \t\tcurl_easy_setopt(slot->curl, CURLOPT_READFUNCTION, rpc_out);\n \t\tcurl_easy_setopt(slot->curl, CURLOPT_INFILE, rpc);\n-#ifndef NO_CURL_IOCTL\n \t\tcurl_easy_setopt(slot->curl, CURLOPT_IOCTLFUNCTION, rpc_ioctl);\n \t\tcurl_easy_setopt(slot->curl, CURLOPT_IOCTLDATA, rpc);\n-#endif\n \t\tif (options.verbosity > 1) {\n \t\t\tfprintf(stderr, \"POST %s (chunked)\\n\", rpc->service_name);\n \t\t\tfflush(stderr);\n-- \n2.32.0.874.ge7a9d58bfcf\n\n"},{"id":"430803","messageId":"patch-3.5-faae88b7fec-20210721T220402Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-0.5-00000000000-20210721T220402Z-avarab@gmail.com","subject":"[PATCH v2 3/5] http: drop support for curl < 7.19.4","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-07-21T22:22:14Z","receivedAt":"2021-07-21T22:22:29Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"From: Jeff King <peff@peff.net>\n\nIn the last commit we dropped support for curl < 7.16.0, let's\ncontinue that and drop support for versions older than 7.19.4. This\nallows us to simplify the code by getting rid of some \"#ifdef\"'s.\n\nGit was broken with vanilla curl < 7.19.4 from v2.12.0 until\nv2.15.0. Compiling with it was broken by using CURLPROTO_* outside any\n\"#ifdef\" in aeae4db174 (http: create function to get curl allowed\nprotocols, 2016-12-14), and fixed in v2.15.0 in f18777ba6ef (http: fix\nhandling of missing CURLPROTO_*, 2017-08-11).\n\nIt's unclear how much anyone was impacted by that in practice, since\nas noted in [1] RHEL versions using curl older than that still\ncompiled, because RedHat backported some features. Perhaps other\nvendors did the same.\n\nStill, it's one datapoint indicating that it wasn't in active use at\nthe time. That (the v2.12.0 release) was in Feb 24, 2017, with v2.15.0\non Oct 30, 2017, it's now mid-2021.\n\n1. http://lore.kernel.org/git/c8a2716d-76ac-735c-57f9-175ca3acbcb0@jupiterrise.com;\n   followed-up by f18777ba6ef (http: fix handling of missing CURLPROTO_*,\n   2017-08-11)\n\nSigned-off-by: Jeff King <peff@peff.net>\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n http.c | 50 --------------------------------------------------\n http.h |  4 ----\n 2 files changed, 54 deletions(-)\n\ndiff --git a/http.c b/http.c\nindex ef00e930232..1f0d7664d35 100644\n--- a/http.c\n+++ b/http.c\n@@ -28,9 +28,7 @@ static int min_curl_sessions = 1;\n static int curl_session_count;\n static int max_requests = -1;\n static CURLM *curlm;\n-#ifndef NO_CURL_EASY_DUPHANDLE\n static CURL *curl_default;\n-#endif\n \n #define PREV_BUF_SIZE 4096\n \n@@ -440,24 +438,8 @@ static void init_curl_http_auth(CURL *result)\n \n \tcredential_fill(&http_auth);\n \n-#if LIBCURL_VERSION_NUM >= 0x071301\n \tcurl_easy_setopt(result, CURLOPT_USERNAME, http_auth.username);\n \tcurl_easy_setopt(result, CURLOPT_PASSWORD, http_auth.password);\n-#else\n-\t{\n-\t\tstatic struct strbuf up = STRBUF_INIT;\n-\t\t/*\n-\t\t * Note that we assume we only ever have a single set of\n-\t\t * credentials in a given program run, so we do not have\n-\t\t * to worry about updating this buffer, only setting its\n-\t\t * initial value.\n-\t\t */\n-\t\tif (!up.len)\n-\t\t\tstrbuf_addf(&up, \"%s:%s\",\n-\t\t\t\thttp_auth.username, http_auth.password);\n-\t\tcurl_easy_setopt(result, CURLOPT_USERPWD, up.buf);\n-\t}\n-#endif\n }\n \n /* *var must be free-able */\n@@ -471,22 +453,10 @@ static void var_override(const char **var, char *value)\n \n static void set_proxyauth_name_password(CURL *result)\n {\n-#if LIBCURL_VERSION_NUM >= 0x071301\n \t\tcurl_easy_setopt(result, CURLOPT_PROXYUSERNAME,\n \t\t\tproxy_auth.username);\n \t\tcurl_easy_setopt(result, CURLOPT_PROXYPASSWORD,\n \t\t\tproxy_auth.password);\n-#else\n-\t\tstruct strbuf s = STRBUF_INIT;\n-\n-\t\tstrbuf_addstr_urlencode(&s, proxy_auth.username,\n-\t\t\t\t\tis_rfc3986_unreserved);\n-\t\tstrbuf_addch(&s, ':');\n-\t\tstrbuf_addstr_urlencode(&s, proxy_auth.password,\n-\t\t\t\t\tis_rfc3986_unreserved);\n-\t\tcurl_proxyuserpwd = strbuf_detach(&s, NULL);\n-\t\tcurl_easy_setopt(result, CURLOPT_PROXYUSERPWD, curl_proxyuserpwd);\n-#endif\n }\n \n static void init_curl_proxy_auth(CURL *result)\n@@ -748,7 +718,6 @@ void setup_curl_trace(CURL *handle)\n \tcurl_easy_setopt(handle, CURLOPT_DEBUGDATA, NULL);\n }\n \n-#ifdef CURLPROTO_HTTP\n static long get_curl_allowed_protocols(int from_user)\n {\n \tlong allowed_protocols = 0;\n@@ -764,7 +733,6 @@ static long get_curl_allowed_protocols(int from_user)\n \n \treturn allowed_protocols;\n }\n-#endif\n \n #if LIBCURL_VERSION_NUM >=0x072f00\n static int get_curl_http_version_opt(const char *version_string, long *opt)\n@@ -906,19 +874,11 @@ static CURL *get_curl_handle(void)\n \t}\n \n \tcurl_easy_setopt(result, CURLOPT_MAXREDIRS, 20);\n-#if LIBCURL_VERSION_NUM >= 0x071301\n \tcurl_easy_setopt(result, CURLOPT_POSTREDIR, CURL_REDIR_POST_ALL);\n-#elif LIBCURL_VERSION_NUM >= 0x071101\n-\tcurl_easy_setopt(result, CURLOPT_POST301, 1);\n-#endif\n-#ifdef CURLPROTO_HTTP\n \tcurl_easy_setopt(result, CURLOPT_REDIR_PROTOCOLS,\n \t\t\t get_curl_allowed_protocols(0));\n \tcurl_easy_setopt(result, CURLOPT_PROTOCOLS,\n \t\t\t get_curl_allowed_protocols(-1));\n-#else\n-\twarning(_(\"Protocol restrictions not supported with cURL < 7.19.4\"));\n-#endif\n \tif (getenv(\"GIT_CURL_VERBOSE\"))\n \t\thttp_trace_curl_no_data();\n \tsetup_curl_trace(result);\n@@ -1012,11 +972,9 @@ static CURL *get_curl_handle(void)\n \t\t\tdie(\"Invalid proxy URL '%s'\", curl_http_proxy);\n \n \t\tcurl_easy_setopt(result, CURLOPT_PROXY, proxy_auth.host);\n-#if LIBCURL_VERSION_NUM >= 0x071304\n \t\tvar_override(&curl_no_proxy, getenv(\"NO_PROXY\"));\n \t\tvar_override(&curl_no_proxy, getenv(\"no_proxy\"));\n \t\tcurl_easy_setopt(result, CURLOPT_NOPROXY, curl_no_proxy);\n-#endif\n \t}\n \tinit_curl_proxy_auth(result);\n \n@@ -1147,9 +1105,7 @@ void http_init(struct remote *remote, const char *url, int proactive_auth)\n \t\t\tssl_cert_password_required = 1;\n \t}\n \n-#ifndef NO_CURL_EASY_DUPHANDLE\n \tcurl_default = get_curl_handle();\n-#endif\n }\n \n void http_cleanup(void)\n@@ -1167,9 +1123,7 @@ void http_cleanup(void)\n \t}\n \tactive_queue_head = NULL;\n \n-#ifndef NO_CURL_EASY_DUPHANDLE\n \tcurl_easy_cleanup(curl_default);\n-#endif\n \n \tcurl_multi_cleanup(curlm);\n \tcurl_global_cleanup();\n@@ -1248,11 +1202,7 @@ struct active_request_slot *get_active_slot(void)\n \t}\n \n \tif (slot->curl == NULL) {\n-#ifdef NO_CURL_EASY_DUPHANDLE\n-\t\tslot->curl = get_curl_handle();\n-#else\n \t\tslot->curl = curl_easy_duphandle(curl_default);\n-#endif\n \t\tcurl_session_count++;\n \t}\n \ndiff --git a/http.h b/http.h\nindex cb092622a73..19f19dbe74c 100644\n--- a/http.h\n+++ b/http.h\n@@ -12,10 +12,6 @@\n \n #define DEFAULT_MAX_REQUESTS 5\n \n-#if LIBCURL_VERSION_NUM == 0x071000\n-#define NO_CURL_EASY_DUPHANDLE\n-#endif\n-\n /*\n  * CURLOPT_USE_SSL was known as CURLOPT_FTP_SSL up to 7.16.4,\n  * and the constants were known as CURLFTPSSL_*\n-- \n2.32.0.874.ge7a9d58bfcf\n\n"},{"id":"430804","messageId":"patch-4.5-9a30e92520c-20210721T220402Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-0.5-00000000000-20210721T220402Z-avarab@gmail.com","subject":"[PATCH v2 4/5] http: drop support for curl < 7.19.3 and < 7.16.4 (again)","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-07-21T22:22:15Z","receivedAt":"2021-07-21T22:22:35Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"Remove the conditional use of CURLAUTH_DIGEST_IE and\nCURLOPT_USE_SSL. These two have been split from earlier simpler checks\nagainst LIBCURL_VERSION_NUM for ease of review.\n\nThe CURLAUTH_DIGEST_IE flag was added in n 7.19.3[1], and\nCURLOPT_USE_SSL in 7.16.4[2], as noted in [2] it was then renamed from\nthe older CURLOPT_FTP_SSL.\n\n1. https://curl.se/libcurl/c/CURLOPT_HTTPAUTH.html\n2. https://curl.se/libcurl/c/CURLOPT_USE_SSL.html\n\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n http.c | 4 ----\n http.h | 9 ---------\n 2 files changed, 13 deletions(-)\n\ndiff --git a/http.c b/http.c\nindex 1f0d7664d35..e9446850a62 100644\n--- a/http.c\n+++ b/http.c\n@@ -120,9 +120,7 @@ static int http_auth_methods_restricted;\n /* Modes for which empty_auth cannot actually help us. */\n static unsigned long empty_auth_useless =\n \tCURLAUTH_BASIC\n-#ifdef CURLAUTH_DIGEST_IE\n \t| CURLAUTH_DIGEST_IE\n-#endif\n \t| CURLAUTH_DIGEST;\n \n static struct curl_slist *pragma_header;\n@@ -893,10 +891,8 @@ static CURL *get_curl_handle(void)\n \tif (curl_ftp_no_epsv)\n \t\tcurl_easy_setopt(result, CURLOPT_FTP_USE_EPSV, 0);\n \n-#ifdef CURLOPT_USE_SSL\n \tif (curl_ssl_try)\n \t\tcurl_easy_setopt(result, CURLOPT_USE_SSL, CURLUSESSL_TRY);\n-#endif\n \n \t/*\n \t * CURL also examines these variables as a fallback; but we need to query\ndiff --git a/http.h b/http.h\nindex 19f19dbe74c..3db5a0cf320 100644\n--- a/http.h\n+++ b/http.h\n@@ -12,15 +12,6 @@\n \n #define DEFAULT_MAX_REQUESTS 5\n \n-/*\n- * CURLOPT_USE_SSL was known as CURLOPT_FTP_SSL up to 7.16.4,\n- * and the constants were known as CURLFTPSSL_*\n-*/\n-#if !defined(CURLOPT_USE_SSL) && defined(CURLOPT_FTP_SSL)\n-#define CURLOPT_USE_SSL CURLOPT_FTP_SSL\n-#define CURLUSESSL_TRY CURLFTPSSL_TRY\n-#endif\n-\n struct slot_results {\n \tCURLcode curl_result;\n \tlong http_code;\n-- \n2.32.0.874.ge7a9d58bfcf\n\n"},{"id":"430805","messageId":"patch-5.5-64e510b4a6b-20210721T220402Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-0.5-00000000000-20210721T220402Z-avarab@gmail.com","subject":"[PATCH v2 5/5] http: rename CURLOPT_FILE to CURLOPT_WRITEDATA","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-07-21T22:22:16Z","receivedAt":"2021-07-21T22:22:36Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"The CURLOPT_FILE name is an alias for CURLOPT_WRITEDATA, the\nCURLOPT_WRITEDATA name has been preferred since curl 7.9.7, released\nin May 2002[1].\n\n1. https://curl.se/libcurl/c/CURLOPT_WRITEDATA.html\n\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n http-push.c   | 6 +++---\n http-walker.c | 2 +-\n http.c        | 6 +++---\n remote-curl.c | 4 ++--\n 4 files changed, 9 insertions(+), 9 deletions(-)\n\ndiff --git a/http-push.c b/http-push.c\nindex aa3de7c1086..3309aaf004a 100644\n--- a/http-push.c\n+++ b/http-push.c\n@@ -883,7 +883,7 @@ static struct remote_lock *lock_remote(const char *path, long timeout)\n \tslot->results = &results;\n \tcurl_setup_http(slot->curl, url, DAV_LOCK, &out_buffer, fwrite_buffer);\n \tcurl_easy_setopt(slot->curl, CURLOPT_HTTPHEADER, dav_headers);\n-\tcurl_easy_setopt(slot->curl, CURLOPT_FILE, &in_buffer);\n+\tcurl_easy_setopt(slot->curl, CURLOPT_WRITEDATA, &in_buffer);\n \n \tCALLOC_ARRAY(lock, 1);\n \tlock->timeout = -1;\n@@ -1142,7 +1142,7 @@ static void remote_ls(const char *path, int flags,\n \tcurl_setup_http(slot->curl, url, DAV_PROPFIND,\n \t\t\t&out_buffer, fwrite_buffer);\n \tcurl_easy_setopt(slot->curl, CURLOPT_HTTPHEADER, dav_headers);\n-\tcurl_easy_setopt(slot->curl, CURLOPT_FILE, &in_buffer);\n+\tcurl_easy_setopt(slot->curl, CURLOPT_WRITEDATA, &in_buffer);\n \n \tif (start_active_slot(slot)) {\n \t\trun_active_slot(slot);\n@@ -1216,7 +1216,7 @@ static int locking_available(void)\n \tcurl_setup_http(slot->curl, repo->url, DAV_PROPFIND,\n \t\t\t&out_buffer, fwrite_buffer);\n \tcurl_easy_setopt(slot->curl, CURLOPT_HTTPHEADER, dav_headers);\n-\tcurl_easy_setopt(slot->curl, CURLOPT_FILE, &in_buffer);\n+\tcurl_easy_setopt(slot->curl, CURLOPT_WRITEDATA, &in_buffer);\n \n \tif (start_active_slot(slot)) {\n \t\trun_active_slot(slot);\ndiff --git a/http-walker.c b/http-walker.c\nindex 19e31623f04..910fae539b8 100644\n--- a/http-walker.c\n+++ b/http-walker.c\n@@ -378,7 +378,7 @@ static void fetch_alternates(struct walker *walker, const char *base)\n \talt_req.walker = walker;\n \tslot->callback_data = &alt_req;\n \n-\tcurl_easy_setopt(slot->curl, CURLOPT_FILE, &buffer);\n+\tcurl_easy_setopt(slot->curl, CURLOPT_WRITEDATA, &buffer);\n \tcurl_easy_setopt(slot->curl, CURLOPT_WRITEFUNCTION, fwrite_buffer);\n \tcurl_easy_setopt(slot->curl, CURLOPT_URL, url.buf);\n \ndiff --git a/http.c b/http.c\nindex e9446850a62..a0f169d2fe5 100644\n--- a/http.c\n+++ b/http.c\n@@ -1769,7 +1769,7 @@ static int http_request(const char *url,\n \t\tcurl_easy_setopt(slot->curl, CURLOPT_NOBODY, 1);\n \t} else {\n \t\tcurl_easy_setopt(slot->curl, CURLOPT_NOBODY, 0);\n-\t\tcurl_easy_setopt(slot->curl, CURLOPT_FILE, result);\n+\t\tcurl_easy_setopt(slot->curl, CURLOPT_WRITEDATA, result);\n \n \t\tif (target == HTTP_REQUEST_FILE) {\n \t\t\toff_t posn = ftello(result);\n@@ -2186,7 +2186,7 @@ struct http_pack_request *new_direct_http_pack_request(\n \t}\n \n \tpreq->slot = get_active_slot();\n-\tcurl_easy_setopt(preq->slot->curl, CURLOPT_FILE, preq->packfile);\n+\tcurl_easy_setopt(preq->slot->curl, CURLOPT_WRITEDATA, preq->packfile);\n \tcurl_easy_setopt(preq->slot->curl, CURLOPT_WRITEFUNCTION, fwrite);\n \tcurl_easy_setopt(preq->slot->curl, CURLOPT_URL, preq->url);\n \tcurl_easy_setopt(preq->slot->curl, CURLOPT_HTTPHEADER,\n@@ -2357,7 +2357,7 @@ struct http_object_request *new_http_object_request(const char *base_url,\n \n \tfreq->slot = get_active_slot();\n \n-\tcurl_easy_setopt(freq->slot->curl, CURLOPT_FILE, freq);\n+\tcurl_easy_setopt(freq->slot->curl, CURLOPT_WRITEDATA, freq);\n \tcurl_easy_setopt(freq->slot->curl, CURLOPT_FAILONERROR, 0);\n \tcurl_easy_setopt(freq->slot->curl, CURLOPT_WRITEFUNCTION, fwrite_sha1_file);\n \tcurl_easy_setopt(freq->slot->curl, CURLOPT_ERRORBUFFER, freq->errorstr);\ndiff --git a/remote-curl.c b/remote-curl.c\nindex 482d5a4656d..bf795f90c6e 100644\n--- a/remote-curl.c\n+++ b/remote-curl.c\n@@ -853,7 +853,7 @@ static int probe_rpc(struct rpc_state *rpc, struct slot_results *results)\n \tcurl_easy_setopt(slot->curl, CURLOPT_POSTFIELDSIZE, 4);\n \tcurl_easy_setopt(slot->curl, CURLOPT_HTTPHEADER, headers);\n \tcurl_easy_setopt(slot->curl, CURLOPT_WRITEFUNCTION, fwrite_buffer);\n-\tcurl_easy_setopt(slot->curl, CURLOPT_FILE, &buf);\n+\tcurl_easy_setopt(slot->curl, CURLOPT_WRITEDATA, &buf);\n \n \terr = run_slot(slot, results);\n \n@@ -1016,7 +1016,7 @@ static int post_rpc(struct rpc_state *rpc, int stateless_connect, int flush_rece\n \trpc_in_data.slot = slot;\n \trpc_in_data.check_pktline = stateless_connect;\n \tmemset(&rpc_in_data.pktline_state, 0, sizeof(rpc_in_data.pktline_state));\n-\tcurl_easy_setopt(slot->curl, CURLOPT_FILE, &rpc_in_data);\n+\tcurl_easy_setopt(slot->curl, CURLOPT_WRITEDATA, &rpc_in_data);\n \tcurl_easy_setopt(slot->curl, CURLOPT_FAILONERROR, 0);\n \n \n-- \n2.32.0.874.ge7a9d58bfcf\n\n"},{"id":"430806","messageId":"xmqq35s7cmvi.fsf@gitster.g","threadId":"46547","inReplyTo":"cover-0.5-00000000000-20210721T220402Z-avarab@gmail.com","subject":"Re: [PATCH v2 0/5] drop support for ancient curl","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2021-07-21T22:39:45Z","receivedAt":"2021-07-21T22:39:49Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Ævar Arnfjörð Bjarmason  <avarab@gmail.com> writes:\n\n> This series simplifies the http code by dropping support for curl\n> versions older than 7.19.4, released in March 2009.\n\nThanks.\n\nWill take a look and may have some comments, but I'd prefer to see\nan Ack from Peff as well.\n\n> Jeff King (3):\n>   http: drop support for curl < 7.11.1\n>   http: drop support for curl < 7.16.0\n>   http: drop support for curl < 7.19.4\n>\n> Ævar Arnfjörð Bjarmason (2):\n>   http: drop support for curl < 7.19.3 and < 7.16.4 (again)\n>   http: rename CURLOPT_FILE to CURLOPT_WRITEDATA\n>\n>  http-push.c   |  29 +--------\n>  http-walker.c |  14 +----\n>  http.c        | 169 ++------------------------------------------------\n>  http.h        |  46 --------------\n>  imap-send.c   |   4 --\n>  remote-curl.c |  11 +---\n>  6 files changed, 10 insertions(+), 263 deletions(-)\n>\n> Range-diff against v1:\n> 1:  8793735cc2c ! 1:  dcbb6f95652 http: drop support for curl < 7.11.1\n>     @@ Metadata\n>       ## Commit message ##\n>          http: drop support for curl < 7.11.1\n>      \n>     -    Recent versions of Git will not build with curl older than\n>     -    7.11.1 due to (at least) two issues:\n>     +    Drop support for this ancient version of curl and simplify the code by\n>     +    allowing us get rid of some \"#ifdef\"'s.\n>     +\n>     +    Git will not build with vanilla curl older than 7.11.1 due to (at\n>     +    least) two issues:\n>      \n>            - our use of CURLOPT_POSTFIELDSIZE in 37ee680d9b\n>              (http.postbuffer: allow full range of ssize_t values,\n>     @@ Commit message\n>          obvious benefit is that we'll have fewer conditional bits\n>          cluttering the code.\n>      \n>     -    But more importantly, we're doing a disservice to users to\n>     -    pretend that Git works with old versions. It's clear that\n>     -    nobody is testing modern Git with such old versions of curl\n>     -    (we've had 3 released versions with the CURLPROTO issue\n>     -    without a report of anyone seeing the breakage in the wild).\n>     -    And there are a lot of subtle ways we could be getting this\n>     -    wrong (for instance, curl prior to 7.17.0 did not copy\n>     -    string arguments to curl_easy_setopt(), which means that\n>     -    using an old copy of curl could produce use-after-free\n>     -    bugs that are not present with more recent versions).\n>     -\n>          This patch drops all #ifdefs that reference older versions\n>          (note that curl's preprocessor macros are in hex, so we're\n>          looking for 070b01, not 071101).\n>      \n>     +    Signed-off-by: Jeff King <peff@peff.net>\n>     +    Signed-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n>     +\n>       ## http.c ##\n>      @@\n>       static struct trace_key trace_curl = TRACE_KEY_INIT(CURL);\n> 2:  15638cd1856 ! 2:  1c9f3bc031b http: drop support for curl < 7.16.0\n>     @@ Metadata\n>       ## Commit message ##\n>          http: drop support for curl < 7.16.0\n>      \n>     -    As discussed in the previous commit, Git is not well-tested\n>     -    with old versions of curl (and in fact since v2.12.0 does\n>     -    not even compile with versions older than 7.19.4). Let's\n>     -    stop pretending we support curl that old and drop any\n>     -    now-obslete #ifdefs.\n>     +    In the last commit we dropped support for curl < 7.11.1, let's\n>     +    continue that and drop support for versions older than 7.16.0. This\n>     +    allows us to get rid of some now-obsolete #ifdefs.\n>      \n>     -    Choosing 7.16.0 is a somewhat arbitrary cutoff, but:\n>     +    Choosing 7.16.0 is a somewhat arbitrary cutoff:\n>      \n>     -      1. it came out in October of 2006, over 10 years ago.\n>     -         Besides being a nice round number, it's a common\n>     -         end-of-life support period, even for conservative\n>     +      1. It came out in October of 2006, almost 15 years ago.\n>     +         Besides being a nice round number, around 10 years is\n>     +         a common end-of-life support period, even for conservative\n>               distributions.\n>      \n>     -      2. that version introduced the curl_multi interface, which\n>     +      2. That version introduced the curl_multi interface, which\n>               gives us a lot of bang for the buck in removing #ifdefs\n>      \n>     +    RHEL 5 came with curl 7.15.5[1] (released in August 2006). RHEL 5's\n>     +    extended life cycle program ended on 2020-11-30[1]. RHEL 6 comes with\n>     +    curl 7.19.7 (released in November 2009), and RHEL 7 comes with\n>     +    7.29.0 (released in February 2013).\n>     +\n>     +    1. http://lore.kernel.org/git/873e1f31-2a96-5b72-2f20-a5816cad1b51@jupiterrise.com\n>     +\n>     +    Signed-off-by: Jeff King <peff@peff.net>\n>     +    Signed-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n>     +\n>       ## http-push.c ##\n>      @@ http-push.c: static void curl_setup_http(CURL *curl, const char *url,\n>       \tcurl_easy_setopt(curl, CURLOPT_INFILE, buffer);\n>     @@ http.h: void finish_all_active_slots(void);\n>       void http_init(struct remote *remote, const char *url,\n>       \t       int proactive_auth);\n>      \n>     + ## imap-send.c ##\n>     +@@ imap-send.c: static int curl_append_msgs_to_imap(struct imap_server_conf *server,\n>     + \tif (cred.username) {\n>     + \t\tif (res == CURLE_OK)\n>     + \t\t\tcredential_approve(&cred);\n>     +-#if LIBCURL_VERSION_NUM >= 0x070d01\n>     + \t\telse if (res == CURLE_LOGIN_DENIED)\n>     +-#else\n>     +-\t\telse\n>     +-#endif\n>     + \t\t\tcredential_reject(&cred);\n>     + \t}\n>     + \n>     +\n>       ## remote-curl.c ##\n>      @@ remote-curl.c: static size_t rpc_out(void *ptr, size_t eltsize,\n>       \treturn avail;\n> 3:  335046de7bc ! 3:  faae88b7fec http: drop support for curl < 7.19.4\n>     @@ Metadata\n>       ## Commit message ##\n>          http: drop support for curl < 7.19.4\n>      \n>     -    Since v2.12.0, Git does not compile with versions of curl\n>     -    older than 7.19.4. That version of curl is about 8 years\n>     -    old. This means it may still be used in some distributions\n>     -    with long-running support periods. But the fact that we\n>     -    haven't received a single bug report about the compile-time\n>     -    breakage implies that nobody cares about building recent\n>     -    releases on such platforms.\n>     +    In the last commit we dropped support for curl < 7.16.0, let's\n>     +    continue that and drop support for versions older than 7.19.4. This\n>     +    allows us to simplify the code by getting rid of some \"#ifdef\"'s.\n>      \n>     -    As discussed in the previous two commits, this cleans up the\n>     -    code and gives a more realistic signal to users about which\n>     -    versions of Git are actually tested (in particular, this\n>     -    moves us past the potential use-after-free issues with curl\n>     -    older than 7.17.0).\n>     +    Git was broken with vanilla curl < 7.19.4 from v2.12.0 until\n>     +    v2.15.0. Compiling with it was broken by using CURLPROTO_* outside any\n>     +    \"#ifdef\" in aeae4db174 (http: create function to get curl allowed\n>     +    protocols, 2016-12-14), and fixed in v2.15.0 in f18777ba6ef (http: fix\n>     +    handling of missing CURLPROTO_*, 2017-08-11).\n>     +\n>     +    It's unclear how much anyone was impacted by that in practice, since\n>     +    as noted in [1] RHEL versions using curl older than that still\n>     +    compiled, because RedHat backported some features. Perhaps other\n>     +    vendors did the same.\n>     +\n>     +    Still, it's one datapoint indicating that it wasn't in active use at\n>     +    the time. That (the v2.12.0 release) was in Feb 24, 2017, with v2.15.0\n>     +    on Oct 30, 2017, it's now mid-2021.\n>     +\n>     +    1. http://lore.kernel.org/git/c8a2716d-76ac-735c-57f9-175ca3acbcb0@jupiterrise.com;\n>     +       followed-up by f18777ba6ef (http: fix handling of missing CURLPROTO_*,\n>     +       2017-08-11)\n>     +\n>     +    Signed-off-by: Jeff King <peff@peff.net>\n>     +    Signed-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n>      \n>       ## http.c ##\n>      @@ http.c: static int min_curl_sessions = 1;\n>     @@ http.c: static void var_override(const char **var, char *value)\n>       }\n>       \n>       static void init_curl_proxy_auth(CURL *result)\n>     +@@ http.c: void setup_curl_trace(CURL *handle)\n>     + \tcurl_easy_setopt(handle, CURLOPT_DEBUGDATA, NULL);\n>     + }\n>     + \n>     +-#ifdef CURLPROTO_HTTP\n>     + static long get_curl_allowed_protocols(int from_user)\n>     + {\n>     + \tlong allowed_protocols = 0;\n>     +@@ http.c: static long get_curl_allowed_protocols(int from_user)\n>     + \n>     + \treturn allowed_protocols;\n>     + }\n>     +-#endif\n>     + \n>     + #if LIBCURL_VERSION_NUM >=0x072f00\n>     + static int get_curl_http_version_opt(const char *version_string, long *opt)\n>      @@ http.c: static CURL *get_curl_handle(void)\n>       \t}\n>       \n>     @@ http.c: static CURL *get_curl_handle(void)\n>      -#if LIBCURL_VERSION_NUM >= 0x071301\n>       \tcurl_easy_setopt(result, CURLOPT_POSTREDIR, CURL_REDIR_POST_ALL);\n>      -#elif LIBCURL_VERSION_NUM >= 0x071101\n>     - \tcurl_easy_setopt(result, CURLOPT_POST301, 1);\n>     +-\tcurl_easy_setopt(result, CURLOPT_POST301, 1);\n>      -#endif\n>      -#ifdef CURLPROTO_HTTP\n>       \tcurl_easy_setopt(result, CURLOPT_REDIR_PROTOCOLS,\n> 4:  e049f37357a < -:  ----------- http: #error on too-old curl\n> -:  ----------- > 4:  9a30e92520c http: drop support for curl < 7.19.3 and < 7.16.4 (again)\n> -:  ----------- > 5:  64e510b4a6b http: rename CURLOPT_FILE to CURLOPT_WRITEDATA\n"},{"id":"430809","messageId":"xmqqwnpjb7jg.fsf@gitster.g","threadId":"46547","inReplyTo":"patch-1.5-dcbb6f95652-20210721T220402Z-avarab@gmail.com","subject":"Re: [PATCH v2 1/5] http: drop support for curl < 7.11.1","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2021-07-21T22:56:19Z","receivedAt":"2021-07-21T22:56:22Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Ævar Arnfjörð Bjarmason  <avarab@gmail.com> writes:\n\n> From: Jeff King <peff@peff.net>\n>\n> Drop support for this ancient version of curl and simplify the code by\n> allowing us get rid of some \"#ifdef\"'s.\n>\n> Git will not build with vanilla curl older than 7.11.1 due to (at\n> least) two issues:\n>\n>   - our use of CURLOPT_POSTFIELDSIZE in 37ee680d9b\n>     (http.postbuffer: allow full range of ssize_t values,\n>     2017-04-11). This field was introduced in curl 7.11.1.\n>\n>   - our use of CURLPROTO_* outside any #ifdef in aeae4db174\n>     (http: create function to get curl allowed protocols,\n>     2016-12-14). These were introduced in curl 7.19.4.\n>\n> We could solve these compilation problems with more #ifdefs,\n> but it's not worth the trouble. Version 7.11.1 came out in\n> March of 2004, over 13 years ago. Let's declare that too old\n\n13+4=17; in 2/5 you say 2006 is 15 years ago, and I think this\nshould be updated, too.  Is 21-4=17 close enough?\n\n> and drop any existing ifdefs that go further back. One\n> obvious benefit is that we'll have fewer conditional bits\n> cluttering the code.\n>\n> This patch drops all #ifdefs that reference older versions\n> (note that curl's preprocessor macros are in hex, so we're\n> looking for 070b01, not 071101).\n\nYup.  I sense that we'd be dropping anything older than 7.19.4\nbecause nobody complained about our dependency on CURLPROTO_* for\nthe past 5 years?\n"},{"id":"430810","messageId":"YPimBp+TkaJ9ycuM@camp.crustytoothpaste.net","threadId":"46547","inReplyTo":"cover-0.5-00000000000-20210721T220402Z-avarab@gmail.com","subject":"Re: [PATCH v2 0/5] drop support for ancient curl","fromName":"brian m. carlson","fromEmail":"sandals@crustytoothpaste.net","sentAt":"2021-07-21T22:56:06Z","receivedAt":"2021-07-21T22:56:42Z","isPatch":true,"sender":{"key":"sandals@crustytoothpaste.net","avatar":"https://avatars.githubusercontent.com/u/497054?v=4"},"body":"On 2021-07-21 at 22:22:11, Ævar Arnfjörð Bjarmason wrote:\n> This series simplifies the http code by dropping support for curl\n> versions older than 7.19.4, released in March 2009.\n> \n> This was last discussed on-list in 2017:\n> http://lore.kernel.org/git/20170809120024.7phdjzjv54uv5dpz@sigill.intra.peff.net\n> \n> My reading of why it didn't get integrated at the time was:\n> \n>  - The original commit messages are opinionated about git not working\n>    on these versions anyway, as noted in the original thread that's\n>    only true of vanilla curl, but anyone impacted by these issues at\n>    the time was probably using e.g. RHEL, which had backports that\n>    confused the issue.\n> \n>  - While in 2017 these versions were already ancient, RHEL 5 (released\n>    in 2007) was still seeing some notable production use.\n> \n>    It finally got \"we really mean it now\" EOL'd in late 2020 when\n>    extended life-cycle support ended (see\n>    https://access.redhat.com/support/policy/updates/errata). RHEL 6\n>    does not have a libcurl affected by these changes.\n> \n>  - It ended with a patch to \"error on too-old curl\", i.e. to make\n>    compiling on versions older than 7.19.4 an error. I've ejected that\n>    per the discussion about backports confusing that issue.\n\nI'm in favor of this series.  I'm actually in favor of dropping support\nfor RHEL 6 as well, since there is nobody providing public security\nsupport for it, and therefore nobody but people paying Red Hat (that is,\nnot this project) can be expected to safely run it.  I also think ten\nyears is about the reasonable maximum lifetime of software.\n\nSo, with or without those changes, this seems like a good approach to\nme.\n-- \nbrian m. carlson (he/him or they/them)\nToronto, Ontario, CA\n"},{"id":"430822","messageId":"xmqqlf5zb73d.fsf@gitster.g","threadId":"46547","inReplyTo":"patch-3.5-faae88b7fec-20210721T220402Z-avarab@gmail.com","subject":"Re: [PATCH v2 3/5] http: drop support for curl < 7.19.4","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2021-07-21T23:05:58Z","receivedAt":"2021-07-21T23:06:07Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Ævar Arnfjörð Bjarmason  <avarab@gmail.com> writes:\n\n> From: Jeff King <peff@peff.net>\n>\n> In the last commit we dropped support for curl < 7.16.0, let's\n> continue that and drop support for versions older than 7.19.4. This\n> allows us to simplify the code by getting rid of some \"#ifdef\"'s.\n>\n> Git was broken with vanilla curl < 7.19.4 from v2.12.0 until\n> v2.15.0. Compiling with it was broken by using CURLPROTO_* outside any\n> \"#ifdef\" in aeae4db174 (http: create function to get curl allowed\n> protocols, 2016-12-14), and fixed in v2.15.0 in f18777ba6ef (http: fix\n> handling of missing CURLPROTO_*, 2017-08-11).\n\nHmph, doesn't the proposed log message of 1/5 need updating then?\nThe above says CURLPROTO_* breakage was only during a few months in\n2017 and hints that we've been OK for the past 4 years, but 1/5 says\nwe need further work to if we want to get stuff working with a\nversion of cURL without CURLPROTO_* stuff, which directly contradicts\nwith \"we fixed it at v2.15.0\" above.\n\n> It's unclear how much anyone was impacted by that in practice, since\n> as noted in [1] RHEL versions using curl older than that still\n> compiled, because RedHat backported some features. Perhaps other\n> vendors did the same.\n>\n> Still, it's one datapoint indicating that it wasn't in active use at\n> the time. That (the v2.12.0 release) was in Feb 24, 2017, with v2.15.0\n> on Oct 30, 2017, it's now mid-2021.\n\nYeah, with RHEL 6 at 7.19.7 (from the proposed log for 2/5), I agree\nthat we'd not be worried too much about pre 7.19.4 as we used to.\n"},{"id":"430823","messageId":"xmqqbl6vb6ji.fsf@gitster.g","threadId":"46547","inReplyTo":"patch-4.5-9a30e92520c-20210721T220402Z-avarab@gmail.com","subject":"Re: [PATCH v2 4/5] http: drop support for curl < 7.19.3 and < 7.16.4 (again)","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2021-07-21T23:17:53Z","receivedAt":"2021-07-21T23:17:56Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Ævar Arnfjörð Bjarmason  <avarab@gmail.com> writes:\n\n> Remove the conditional use of CURLAUTH_DIGEST_IE and\n> CURLOPT_USE_SSL. These two have been split from earlier simpler checks\n> against LIBCURL_VERSION_NUM for ease of review.\n>\n> The CURLAUTH_DIGEST_IE flag was added in n 7.19.3[1], and\n> CURLOPT_USE_SSL in 7.16.4[2], as noted in [2] it was then renamed from\n> the older CURLOPT_FTP_SSL.\n>\n> 1. https://curl.se/libcurl/c/CURLOPT_HTTPAUTH.html\n> 2. https://curl.se/libcurl/c/CURLOPT_USE_SSL.html\n\nMy go-to place for cURL version information is:\n\nhttps://github.com/curl/curl/blob/master/docs/libcurl/symbols-in-versions\n\nand it says CURLOPT_USE_SSL has been available since 7.17.0.  If\n7.16.4 was the last version in the 7.16.x series, then these two\nsources are consistent.\n\n[2] says that the feature was available under a different name in\nthe past and up to version 7.16.4, meaning with 7.16.4, USE_SSL was\nnot usable. You'd need to do \"<= 7.16.4\" on the title, but it is\nsimpler to follow the symbols-in-versions table and say \"< 7.17.0\",\nI would think.\n\nThe patch text looks OK.\n"},{"id":"430824","messageId":"xmqq7dhjb6hk.fsf@gitster.g","threadId":"46547","inReplyTo":"patch-5.5-64e510b4a6b-20210721T220402Z-avarab@gmail.com","subject":"Re: [PATCH v2 5/5] http: rename CURLOPT_FILE to CURLOPT_WRITEDATA","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2021-07-21T23:19:03Z","receivedAt":"2021-07-21T23:19:08Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Ævar Arnfjörð Bjarmason  <avarab@gmail.com> writes:\n\n> The CURLOPT_FILE name is an alias for CURLOPT_WRITEDATA, the\n> CURLOPT_WRITEDATA name has been preferred since curl 7.9.7, released\n> in May 2002[1].\n\nYes!  _FILE has been deprecated since that version so this is\ndefinitely the right thing to do.\n"},{"id":"430878","messageId":"3fb05d7e-fbce-5f13-406e-95218abe87f5@gmail.com","threadId":"46547","inReplyTo":"cover-0.5-00000000000-20210721T220402Z-avarab@gmail.com","subject":"Re: [PATCH v2 0/5] drop support for ancient curl","fromName":"Bagas Sanjaya","fromEmail":"bagasdotme@gmail.com","sentAt":"2021-07-22T06:27:29Z","receivedAt":"2021-07-22T06:27:37Z","isPatch":true,"sender":{"key":"bagasdotme@gmail.com","avatar":"https://avatars.githubusercontent.com/u/40219486?v=4"},"body":"On 22/07/21 05.22, Ævar Arnfjörð Bjarmason wrote:\n> This series simplifies the http code by dropping support for curl\n> versions older than 7.19.4, released in March 2009.\n\nBut INSTALL says:\n\n>         - \"libcurl\" library is used by git-http-fetch, git-fetch, and, if\n>           the curl version >= 7.34.0, for git-imap-send.  You might also\n>           want the \"curl\" executable for debugging purposes. If you do not\n>           use http:// or https:// repositories, and do not want to put\n>           patches into an IMAP mailbox, you do not have to have them\n>           (use NO_CURL).\n\nI think it's worth mentioning minimal required curl version (7.19.4) there.\n\n-- \nAn old man doll... just what I always wanted! - Clara\n"},{"id":"430880","messageId":"87czravm96.fsf@evledraar.gmail.com","threadId":"46547","inReplyTo":"YPimBp+TkaJ9ycuM@camp.crustytoothpaste.net","subject":"Re: [PATCH v2 0/5] drop support for ancient curl","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-07-22T07:09:59Z","receivedAt":"2021-07-22T07:30:16Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"\nOn Wed, Jul 21 2021, brian m. carlson wrote:\n\n> [[PGP Signed Part:Undecided]]\n> On 2021-07-21 at 22:22:11, Ævar Arnfjörð Bjarmason wrote:\n>> This series simplifies the http code by dropping support for curl\n>> versions older than 7.19.4, released in March 2009.\n>> \n>> This was last discussed on-list in 2017:\n>> http://lore.kernel.org/git/20170809120024.7phdjzjv54uv5dpz@sigill.intra.peff.net\n>> \n>> My reading of why it didn't get integrated at the time was:\n>> \n>>  - The original commit messages are opinionated about git not working\n>>    on these versions anyway, as noted in the original thread that's\n>>    only true of vanilla curl, but anyone impacted by these issues at\n>>    the time was probably using e.g. RHEL, which had backports that\n>>    confused the issue.\n>> \n>>  - While in 2017 these versions were already ancient, RHEL 5 (released\n>>    in 2007) was still seeing some notable production use.\n>> \n>>    It finally got \"we really mean it now\" EOL'd in late 2020 when\n>>    extended life-cycle support ended (see\n>>    https://access.redhat.com/support/policy/updates/errata). RHEL 6\n>>    does not have a libcurl affected by these changes.\n>> \n>>  - It ended with a patch to \"error on too-old curl\", i.e. to make\n>>    compiling on versions older than 7.19.4 an error. I've ejected that\n>>    per the discussion about backports confusing that issue.\n>\n> I'm in favor of this series.  I'm actually in favor of dropping support\n> for RHEL 6 as well, since there is nobody providing public security\n> support for it, and therefore nobody but people paying Red Hat (that is,\n> not this project) can be expected to safely run it.  I also think ten\n> years is about the reasonable maximum lifetime of software.\n>\n> So, with or without those changes, this seems like a good approach to\n> me.\n\nI'll clarify this along with other fixes in a re-roll, but I think our\npolicy shouldn't have anything to do with upstream promises of support,\nbut merely the trade-off of how easy it is for us to support old\nsoftware & how likely it is that people use it in practice along with\ngit.\n\nSo as an example we still say we support Perl 5.8, which is ridiculously\nancient as far as any notion of upstream security support goes (and as\nan aside, does have real DoS issues exposed by e.g. the gitweb we ship).\n\nBut while we could probably bump that to something more modern nowadays\nin practice we're not a mostly-Perl project, so I haven't found it to be\nworth it to bump it when working on the relevant code.\n\nI'm only using RHEL 5 as a shorthand for a system that's usually the\nmost ancient thing people want to build new gits with in practice.\n\nIt's just not the case that you can't run RHEL 5 or even RHEL 4 \"safely\"\neven today. Upstream has just abandoned it, but that doesn't mean users\nin the wild have. There's also CentOS, not everyone cares about IBM\ncorporate support policies.\n\nE.g. in practice at a past-job I've had to build git using system\nlibcurl in a mixed environment which (and I forget the details) included\nmostly today's equivalent of RHEL 8 and 7, but there was some system\nusing RHEL 5 in a closet somewhere still using puppet automation.\n\nWhy? Because (and I forget the details, but this example will do)\nbecause it needed to operate some proprietary dongle requiring a RHEL 5\nkernel driver that its vendor had since abandoned.\n\nThere were plans to move away from it, but that was maybe 1-2 years away\nat the time. Meanwhile I had to build a git across the fleet, and it\nwould be a hassle to need to ship my own libcurl just because this\nproject wanted to have paternalistic version dependency policies.\n\nI mean, if it's a matter of supporting that version being painful then\nfair enough. I had some comments in the 2017 thread (or something linked\nfrom it) about needing to package your dependencies not being *that* big\na deal.\n\nHence this series, I think on balance the improvement in maintainability\nof the http code makes it worth it.\n\nBut let's not justify it with a user not being able to run such software\nsecurely, in my example those ancient boxes were externally firewalled,\nand in any case any practical security issues were probably with some\nvendor's admin interface on them, not whatever ancient kernel they had.\n\nOn the other hand there's surely people who are running RHEL 5 today who\nare running insecure setup, but let's not make it our job to force them\nto move by virtue of being overly annoying about dependency version\nrequirements.\n\nWe should have the view that git's critical infrastructure and we should\nbe wary of breaking things. It would also just be counter-productive,\nthe result would probably be that the ancient box wouldn't get an\nupgraded git, and would still have preventable CVE's in git itself\npresent (e.g. the gitmodules RCE).\n"},{"id":"430974","messageId":"YPn3jP0n+ghomSkX@camp.crustytoothpaste.net","threadId":"46547","inReplyTo":"87czravm96.fsf@evledraar.gmail.com","subject":"Re: [PATCH v2 0/5] drop support for ancient curl","fromName":"brian m. carlson","fromEmail":"sandals@crustytoothpaste.net","sentAt":"2021-07-22T22:56:12Z","receivedAt":"2021-07-22T22:56:48Z","isPatch":true,"sender":{"key":"sandals@crustytoothpaste.net","avatar":"https://avatars.githubusercontent.com/u/497054?v=4"},"body":"On 2021-07-22 at 07:09:59, Ævar Arnfjörð Bjarmason wrote:\n> I'll clarify this along with other fixes in a re-roll, but I think our\n> policy shouldn't have anything to do with upstream promises of support,\n> but merely the trade-off of how easy it is for us to support old\n> software & how likely it is that people use it in practice along with\n> git.\n\nI don't think I agree.  We should try to support major operating systems\nwell provided we can adequately be expected to test on them, and that\nmeans that they should have publicly available security support.  In\nother words, a developer on the relevant operating system should be able\nto test on that OS without paying ongoing money for the privilege of doing\nso securely.\n\nOnce an operating system is no longer supported security-wise, we should\nno longer support it, either, since we can't be expected to test or\ndevelop on it securely.  Nobody could responsibly run such an image on\na CI system or test with it on an Internet-connected computer, so we\nshould no longer consider it worthy of our support.\n\n> So as an example we still say we support Perl 5.8, which is ridiculously\n> ancient as far as any notion of upstream security support goes (and as\n> an aside, does have real DoS issues exposed by e.g. the gitweb we ship).\n> \n> But while we could probably bump that to something more modern nowadays\n> in practice we're not a mostly-Perl project, so I haven't found it to be\n> worth it to bump it when working on the relevant code.\n\nI've actually argued in favor of bumping the version to 5.14 a long time\nago.  I can send a patch for that.  It has a bunch of nice new features\nwe could take advantage of.\n\n> I'm only using RHEL 5 as a shorthand for a system that's usually the\n> most ancient thing people want to build new gits with in practice.\n> \n> It's just not the case that you can't run RHEL 5 or even RHEL 4 \"safely\"\n> even today. Upstream has just abandoned it, but that doesn't mean users\n> in the wild have. There's also CentOS, not everyone cares about IBM\n> corporate support policies.\n\nYes, and CentOS has dropped support earlier than Red Hat has.\n\nJust because users want to run new versions of Git on systems that\nshould long ago have been abandoned[0] does not mean we should take the\nburden of maintaining that code for them.  Since they have the source\ncode, they can build and maintain Git on those old systems and apply\nany necessary patches.  If this becomes burdensome, then perhaps the\ncost of maintaining the system will be an incentive to replace it with a\nsecure system.\n\nI am unconvinced that we should make it easier for people to run\ninsecure operating systems because they pose a hazard to the Internet\nwhen connected to it.  Just because it is behind some firewall doesn't\nmean that it cannot be compromised, and once it is, it can then become\na source of spam and abuse.  This is not an idle thought experiment; it\ndoes practically happen with great frequency on the Internet today.  An\nunsupported system might be acceptable if it has no network connectivity\nat all, but then it would not need a newer version of Git.\n\nIt is not that I have not experienced such load-bearing obsolete systems\nbefore: I have, and I have done my best to support them.  But I've also\nbeen happy to be clear to management and/or customers about what that\nmeans in terms of costs and that we were taking a real, substantial\nrisk, and been clear what the consequences were.  In no situation,\nhowever, did I try to convince outside parties that my obsolete OS was\ndeserving of someone else's maintenance burden or argue that the system\nshould not be replaced as soon as possible.\n\n> We should have the view that git's critical infrastructure and we should\n> be wary of breaking things. It would also just be counter-productive,\n> the result would probably be that the ancient box wouldn't get an\n> upgraded git, and would still have preventable CVE's in git itself\n> present (e.g. the gitmodules RCE).\n\nConsidering that the machine already has multiple CVEs, probably\nincluding root code execution vulnerabilities, I'm not sure how much\nworse we could make it.  It's already trivial to compromise with or\nwithout a newer version of Git.\n\n[0] I should point out that ten years of support is already extremely\ngenerous.\n-- \nbrian m. carlson (he/him or they/them)\nToronto, Ontario, CA\n"},{"id":"430984","messageId":"87h7gltrst.fsf@evledraar.gmail.com","threadId":"46547","inReplyTo":"YPn3jP0n+ghomSkX@camp.crustytoothpaste.net","subject":"Re: [PATCH v2 0/5] drop support for ancient curl","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-07-23T07:17:58Z","receivedAt":"2021-07-23T07:25:38Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"\nOn Thu, Jul 22 2021, brian m. carlson wrote:\n\n> [[PGP Signed Part:Undecided]]\n> On 2021-07-22 at 07:09:59, Ævar Arnfjörð Bjarmason wrote:\n>> I'll clarify this along with other fixes in a re-roll, but I think our\n>> policy shouldn't have anything to do with upstream promises of support,\n>> but merely the trade-off of how easy it is for us to support old\n>> software & how likely it is that people use it in practice along with\n>> git.\n>\n> I don't think I agree.  We should try to support major operating systems\n> well provided we can adequately be expected to test on them, and that\n> means that they should have publicly available security support.  In\n> other words, a developer on the relevant operating system should be able\n> to test on that OS without paying ongoing money for the privilege of doing\n> so securely.\n\nDoesn't drawing that line in the sand for Linux distributions by\nimplication leave out support for Windows, OSX and any other proprietary\nsystem? You need to pay for security and other updates for those from\nday one.\n\n> Once an operating system is no longer supported security-wise, we should\n> no longer support it, either, since we can't be expected to test or\n> develop on it securely.  Nobody could responsibly run such an image on\n> a CI system or test with it on an Internet-connected computer, so we\n> should no longer consider it worthy of our support.\n\nYes, I do think we disagree. I just think we should focus narrowly on\nwhether it's a hassle for us to support older libcurl, whether some\nversion of it is packaged with an old OS that's known to be in wide use\nor not is ultimately just a useful heuristic.\n\n>> So as an example we still say we support Perl 5.8, which is ridiculously\n>> ancient as far as any notion of upstream security support goes (and as\n>> an aside, does have real DoS issues exposed by e.g. the gitweb we ship).\n>> \n>> But while we could probably bump that to something more modern nowadays\n>> in practice we're not a mostly-Perl project, so I haven't found it to be\n>> worth it to bump it when working on the relevant code.\n>\n> I've actually argued in favor of bumping the version to 5.14 a long time\n> ago.  I can send a patch for that.  It has a bunch of nice new features\n> we could take advantage of.\n\nSure, I'm not opposed. Just noting the in-tree nicer features for us\nv.s. more aggressive versioning policy for packagers and users (not that\nPerl 5.14 is aggressive).\n\n>> I'm only using RHEL 5 as a shorthand for a system that's usually the\n>> most ancient thing people want to build new gits with in practice.\n>> \n>> It's just not the case that you can't run RHEL 5 or even RHEL 4 \"safely\"\n>> even today. Upstream has just abandoned it, but that doesn't mean users\n>> in the wild have. There's also CentOS, not everyone cares about IBM\n>> corporate support policies.\n>\n> Yes, and CentOS has dropped support earlier than Red Hat has.\n>\n> Just because users want to run new versions of Git on systems that\n> should long ago have been abandoned[0] does not mean we should take the\n> burden of maintaining that code for them.  Since they have the source\n> code, they can build and maintain Git on those old systems and apply\n> any necessary patches.  If this becomes burdensome, then perhaps the\n> cost of maintaining the system will be an incentive to replace it with a\n> secure system.\n>\n> I am unconvinced that we should make it easier for people to run\n> insecure operating systems because they pose a hazard to the Internet\n> when connected to it.  Just because it is behind some firewall doesn't\n> mean that it cannot be compromised, and once it is, it can then become\n> a source of spam and abuse.  This is not an idle thought experiment; it\n> does practically happen with great frequency on the Internet today.  An\n> unsupported system might be acceptable if it has no network connectivity\n> at all, but then it would not need a newer version of Git.\n\nAren't you assuming that any network connectivity is equal to\nconnectivity to the open internet?\n\nIn any case, I think the notion that we should make git slightly more\npainful to use on these systems as a distant proxy variable to forcing\nOS upgrades is several levels away from where I think we should be\ndrawing the line, which is closer to \"is it painful in-tree?\" and \"is\nsomeone sending us patches to make it work?\" etc.\n"},{"id":"431018","messageId":"YPqW8lAcwno3j7Fq@coredump.intra.peff.net","threadId":"46547","inReplyTo":"cover-0.5-00000000000-20210721T220402Z-avarab@gmail.com","subject":"Re: [PATCH v2 0/5] drop support for ancient curl","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2021-07-23T10:16:18Z","receivedAt":"2021-07-23T10:16:21Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Thu, Jul 22, 2021 at 12:22:11AM +0200, Ævar Arnfjörð Bjarmason wrote:\n\n> This series is a re-roll of patches found in Peff's GitHub repo at\n> jk/no-ancient-curl, which were already-rebased versions of those\n> patches. His original on-list version had his Signed-off-by, but the\n> range-diff is against that branch, hence the addition of\n> Signed-off-by in the range-diff.\n\nHeh, OK. It's a little surprising to see random junk pulled out of my\nGitHub repo, but in this case I was holding onto them with the intent of\neventually resending after more time passed.\n\nSo I'm happy to see these cleaned up and posted. I think what's on that\nbranch should be good-ish, in the sense that I've been rebasing it\nforward as part of my daily routine, and it's part of the build that I\nuse day-to-day. Though apparently I never applied the CURLOPT_POST301\nfix. :-/\n\nI know my S-o-b was on the originals to the list, but just to make\nclear: I am fine with using them on the rebased versions you grabbed.\n\n> I then added a couple of patches on top, one is based on my comments\n> on the v1 http://lore.kernel.org/git/871sokhoi9.fsf@gmail.com,\n> i.e. the CURLAUTH_DIGEST_IE and CURLOPT_USE_SSL flags are also\n> version-based, and we can drop support for curls that don't have them.\n\nSeems reasonable.\n\n> I then renamed the ancient CURLOPT_FILE alias to\n> CURLOPT_WRITEDATA. Incidentally that's how I remembered to dig up this\n> series, i.e. I tried to search for \"CURLOPT_FILE\" in API documentation\n> while reading our HTTP code, but had a hard time finding it, turns out\n> we were using a very ancient synonym for the preferred name.\n\nThis seemed weirdly familiar. Looks like it was part of a series last\nyear, but the trickier parts built on top merited a re-roll that never\ncame:\n\n  https://lore.kernel.org/git/20201013191729.2524700-2-smcallis@google.com/\n\n> Jeff King (3):\n>   http: drop support for curl < 7.11.1\n>   http: drop support for curl < 7.16.0\n>   http: drop support for curl < 7.19.4\n> \n> Ævar Arnfjörð Bjarmason (2):\n>   http: drop support for curl < 7.19.3 and < 7.16.4 (again)\n>   http: rename CURLOPT_FILE to CURLOPT_WRITEDATA\n\nSo modulo the commit message tweaks that Junio suggested, this all looks\nfine. I actually think my original \"#error on too-old curl\" is still\nreasonable. Yes, people whose distro has backported all of these\nfeatures could possibly still use it. But in that case they likely know\nwhat's going on and can rip out the #error. It seems much more likely\nto me that it _won't_ work, and they'll get confused by obscure errors\nwhen they try to use an old curl.\n\nBut I don't feel too stronlgy about it either way.\n\n-Peff\n"},{"id":"431049","messageId":"xmqqo8atovbc.fsf@gitster.g","threadId":"46547","inReplyTo":"YPqW8lAcwno3j7Fq@coredump.intra.peff.net","subject":"Re: [PATCH v2 0/5] drop support for ancient curl","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2021-07-23T16:21:11Z","receivedAt":"2021-07-23T16:21:21Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Jeff King <peff@peff.net> writes:\n\n> On Thu, Jul 22, 2021 at 12:22:11AM +0200, Ævar Arnfjörð Bjarmason wrote:\n>\n>> This series is a re-roll of patches found in Peff's GitHub repo at\n>> jk/no-ancient-curl, which were already-rebased versions of those\n>> patches. His original on-list version had his Signed-off-by, but the\n>> range-diff is against that branch, hence the addition of\n>> Signed-off-by in the range-diff.\n>\n> Heh, OK. It's a little surprising to see random junk pulled out of my\n> GitHub repo, but in this case I was holding onto them with the intent of\n> eventually resending after more time passed.\n>\n> So I'm happy to see these cleaned up and posted. I think what's on that\n> branch should be good-ish, in the sense that I've been rebasing it\n> forward as part of my daily routine, and it's part of the build that I\n> use day-to-day. Though apparently I never applied the CURLOPT_POST301\n> fix. :-/\n\nThanks.\n\n> I know my S-o-b was on the originals to the list, but just to make\n> clear: I am fine with using them on the rebased versions you grabbed.\n\nGood.  S-o-b is merely \"I can let the project use it\" and does not\nsay \"I agree this is (still) relevant in the context of the code\nthis is being submitted to\", so the above note is very much\nappreciated.\n\n> So modulo the commit message tweaks that Junio suggested, this all looks\n> fine. I actually think my original \"#error on too-old curl\" is still\n> reasonable. Yes, people whose distro has backported all of these\n> features could possibly still use it. But in that case they likely know\n> what's going on and can rip out the #error. It seems much more likely\n> to me that it _won't_ work, and they'll get confused by obscure errors\n> when they try to use an old curl.\n>\n> But I don't feel too stronlgy about it either way.\n\nMe neither.  Those who are vanilla would not be helped by having it,\nas their build would fail if their cURL is too old anyway even\nwithout it.  Those who backported would have a build that may or may\nnot work, but diagnosing it is part of the job of backporting their\ncURL anyway.  So in practice, I think \"#error if you are older than\nX\" primarily would serve documentation purposes (which may be worth\ndoing, but requirements listed in INSTALL would probably be a better\nalternative anyway).\n\nThanks.\n"},{"id":"431053","messageId":"016801d77fe2$b7310ae0$259320a0$@nexbridge.com","threadId":"46547","inReplyTo":"xmqqo8atovbc.fsf@gitster.g","subject":"RE: [PATCH v2 0/5] drop support for ancient curl","fromName":"Randall S. Becker","fromEmail":"rsbecker@nexbridge.com","sentAt":"2021-07-23T16:49:27Z","receivedAt":"2021-07-23T16:49:38Z","isPatch":true,"sender":{"key":"randall.becker@nexbridge.ca","avatar":"https://avatars.githubusercontent.com/u/28956764?v=4"},"body":"On July 23, 2021 12:21 PM, Junio C Hamano wrote:\n>Jeff King <peff@peff.net> writes:\n>\n>> On Thu, Jul 22, 2021 at 12:22:11AM +0200, Ævar Arnfjörð Bjarmason wrote:\n>>\n>>> This series is a re-roll of patches found in Peff's GitHub repo at\n>>> jk/no-ancient-curl, which were already-rebased versions of those\n>>> patches. His original on-list version had his Signed-off-by, but the\n>>> range-diff is against that branch, hence the addition of\n>>> Signed-off-by in the range-diff.\n>>\n>> Heh, OK. It's a little surprising to see random junk pulled out of my\n>> GitHub repo, but in this case I was holding onto them with the intent\n>> of eventually resending after more time passed.\n>>\n>> So I'm happy to see these cleaned up and posted. I think what's on\n>> that branch should be good-ish, in the sense that I've been rebasing\n>> it forward as part of my daily routine, and it's part of the build\n>> that I use day-to-day. Though apparently I never applied the\n>> CURLOPT_POST301 fix. :-/\n>\n>Thanks.\n>\n>> I know my S-o-b was on the originals to the list, but just to make\n>> clear: I am fine with using them on the rebased versions you grabbed.\n>\n>Good.  S-o-b is merely \"I can let the project use it\" and does not say \"I agree this is (still) relevant in the context of the code this is being\n>submitted to\", so the above note is very much appreciated.\n>\n>> So modulo the commit message tweaks that Junio suggested, this all\n>> looks fine. I actually think my original \"#error on too-old curl\" is\n>> still reasonable. Yes, people whose distro has backported all of these\n>> features could possibly still use it. But in that case they likely\n>> know what's going on and can rip out the #error. It seems much more\n>> likely to me that it _won't_ work, and they'll get confused by obscure\n>> errors when they try to use an old curl.\n>>\n>> But I don't feel too stronlgy about it either way.\n>\n>Me neither.  Those who are vanilla would not be helped by having it, as their build would fail if their cURL is too old anyway even without\n>it.  Those who backported would have a build that may or may not work, but diagnosing it is part of the job of backporting their cURL\n>anyway.  So in practice, I think \"#error if you are older than X\" primarily would serve documentation purposes (which may be worth doing,\n>but requirements listed in INSTALL would probably be a better alternative anyway).\n\nThis is probably a red-herring, but from what I am observing, the curl 7.70 version is required for OpenSSL 3.0.0. Once we move there, which my team is working on, the near recent older version of curl could also be problematic and incompatible. This is rather unpleasant because the current standard libcurl on our platform is 7.65, which is too old to be compatible anyway, so we're going to have to put out a separate libcurl build. Curl seems to need to be closer to the bleeding edge to retain imminent compatibility.\n\n-Randall\n\n"},{"id":"431108","messageId":"YPtqlsnn/xYoS+7L@coredump.intra.peff.net","threadId":"46547","inReplyTo":"xmqqo8atovbc.fsf@gitster.g","subject":"Re: [PATCH v2 0/5] drop support for ancient curl","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2021-07-24T01:19:18Z","receivedAt":"2021-07-24T01:19:25Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Fri, Jul 23, 2021 at 09:21:11AM -0700, Junio C Hamano wrote:\n\n> > So modulo the commit message tweaks that Junio suggested, this all looks\n> > fine. I actually think my original \"#error on too-old curl\" is still\n> > reasonable. Yes, people whose distro has backported all of these\n> > features could possibly still use it. But in that case they likely know\n> > what's going on and can rip out the #error. It seems much more likely\n> > to me that it _won't_ work, and they'll get confused by obscure errors\n> > when they try to use an old curl.\n> >\n> > But I don't feel too stronlgy about it either way.\n> \n> Me neither.  Those who are vanilla would not be helped by having it,\n> as their build would fail if their cURL is too old anyway even\n> without it.  Those who backported would have a build that may or may\n> not work, but diagnosing it is part of the job of backporting their\n> cURL anyway.  So in practice, I think \"#error if you are older than\n> X\" primarily would serve documentation purposes (which may be worth\n> doing, but requirements listed in INSTALL would probably be a better\n> alternative anyway).\n\nYeah, it is purely for documentation to help people who are confused by\na broken build. But I agree that INSTALL is probably reasonable there\n(not to mention that the whole point is that these versions are so old\nhardly anybody should be using them anyway). So let's forget about the\n#error thing, then.\n\n-Peff\n"},{"id":"431544","messageId":"cover-v3-0.7-00000000000-20210730T092843Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-0.5-00000000000-20210721T220402Z-avarab@gmail.com","subject":"[PATCH v3 0/7] drop support for ancient curl, improve version checks","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-07-30T09:31:52Z","receivedAt":"2021-07-30T09:35:05Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"This should address the feedback on v2, except that I did not update\nthe INSTALL document as Bagas Sanjaya suggested. We did not have\nexisting discussion of the generally supported minimal support minimal\nversion there, that would make sense as a follow-up patch.\n\nThere's minor commit message changes here, and two new patches, one is\nanother missed ifdef we could remove because the version comparion was\nwrong, and the last commit entirely gets rid of LIBCURL_VERSION_NUM\nchecks in the codebase in favor of checking specific defined macros.\n\nJeff King (3):\n  http: drop support for curl < 7.11.1\n  http: drop support for curl < 7.16.0\n  http: drop support for curl < 7.19.4\n\nÆvar Arnfjörð Bjarmason (4):\n  http: drop support for curl < 7.19.3 and <= 7.16.4 (or <7.17.0)\n    (again)\n  http: drop support for curl < 7.18.0 (again)\n  http: rename CURLOPT_FILE to CURLOPT_WRITEDATA\n  http: centralize the accounting of libcurl dependencies\n\n git-curl-compat.h | 119 ++++++++++++++++++++++++++\n http-push.c       |  29 +------\n http-walker.c     |  14 +--\n http.c            | 212 ++++++----------------------------------------\n http.h            |  46 ----------\n imap-send.c       |  10 +--\n remote-curl.c     |  11 +--\n 7 files changed, 153 insertions(+), 288 deletions(-)\n create mode 100644 git-curl-compat.h\n\nRange-diff against v2:\n1:  dcbb6f95652 ! 1:  6bd41764a54 http: drop support for curl < 7.11.1\n    @@ Commit message\n         Drop support for this ancient version of curl and simplify the code by\n         allowing us get rid of some \"#ifdef\"'s.\n     \n    -    Git will not build with vanilla curl older than 7.11.1 due to (at\n    -    least) two issues:\n    -\n    -      - our use of CURLOPT_POSTFIELDSIZE in 37ee680d9b\n    -        (http.postbuffer: allow full range of ssize_t values,\n    -        2017-04-11). This field was introduced in curl 7.11.1.\n    -\n    -      - our use of CURLPROTO_* outside any #ifdef in aeae4db174\n    -        (http: create function to get curl allowed protocols,\n    -        2016-12-14). These were introduced in curl 7.19.4.\n    +    Git will not build with vanilla curl older than 7.11.1 due our use of\n    +    CURLOPT_POSTFIELDSIZE in 37ee680d9b\n    +    (http.postbuffer: allow full range of ssize_t values,\n    +    2017-04-11). This field was introduced in curl 7.11.1.\n     \n         We could solve these compilation problems with more #ifdefs,\n         but it's not worth the trouble. Version 7.11.1 came out in\n    -    March of 2004, over 13 years ago. Let's declare that too old\n    +    March of 2004, over 17 years ago. Let's declare that too old\n         and drop any existing ifdefs that go further back. One\n         obvious benefit is that we'll have fewer conditional bits\n         cluttering the code.\n2:  1c9f3bc031b = 2:  fb308258e2b http: drop support for curl < 7.16.0\n3:  faae88b7fec = 3:  9fcd3a3e486 http: drop support for curl < 7.19.4\n4:  9a30e92520c ! 4:  230b968382f http: drop support for curl < 7.19.3 and < 7.16.4 (again)\n    @@ Metadata\n     Author: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n     \n      ## Commit message ##\n    -    http: drop support for curl < 7.19.3 and < 7.16.4 (again)\n    +    http: drop support for curl < 7.19.3 and <= 7.16.4 (or <7.17.0) (again)\n     \n         Remove the conditional use of CURLAUTH_DIGEST_IE and\n         CURLOPT_USE_SSL. These two have been split from earlier simpler checks\n         against LIBCURL_VERSION_NUM for ease of review.\n     \n    -    The CURLAUTH_DIGEST_IE flag was added in n 7.19.3[1], and\n    -    CURLOPT_USE_SSL in 7.16.4[2], as noted in [2] it was then renamed from\n    -    the older CURLOPT_FTP_SSL.\n    +    The CURLAUTH_DIGEST_IE flag was added in 7.19.3[1], and\n    +    CURLOPT_USE_SSL in 7.16.4[2] or 7.17.0[3], depending on the source. As\n    +    noted in [2] it was then renamed around that time from the older\n    +    CURLOPT_FTP_SSL.\n     \n         1. https://curl.se/libcurl/c/CURLOPT_HTTPAUTH.html\n         2. https://curl.se/libcurl/c/CURLOPT_USE_SSL.html\n    +    3. https://github.com/curl/curl/blob/master/docs/libcurl/symbols-in-versions\n     \n         Signed-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n     \n-:  ----------- > 5:  b857a9ef7b1 http: drop support for curl < 7.18.0 (again)\n5:  64e510b4a6b = 6:  95e42b17ce8 http: rename CURLOPT_FILE to CURLOPT_WRITEDATA\n-:  ----------- > 7:  93a2775d0ee http: centralize the accounting of libcurl dependencies\n-- \n2.32.0.1069.g516d52f3d85\n\n"},{"id":"431545","messageId":"patch-v3-1.7-6bd41764a54-20210730T092843Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-v3-0.7-00000000000-20210730T092843Z-avarab@gmail.com","subject":"[PATCH v3 1/7] http: drop support for curl < 7.11.1","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-07-30T09:31:53Z","receivedAt":"2021-07-30T09:35:06Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"From: Jeff King <peff@peff.net>\n\nDrop support for this ancient version of curl and simplify the code by\nallowing us get rid of some \"#ifdef\"'s.\n\nGit will not build with vanilla curl older than 7.11.1 due our use of\nCURLOPT_POSTFIELDSIZE in 37ee680d9b\n(http.postbuffer: allow full range of ssize_t values,\n2017-04-11). This field was introduced in curl 7.11.1.\n\nWe could solve these compilation problems with more #ifdefs,\nbut it's not worth the trouble. Version 7.11.1 came out in\nMarch of 2004, over 17 years ago. Let's declare that too old\nand drop any existing ifdefs that go further back. One\nobvious benefit is that we'll have fewer conditional bits\ncluttering the code.\n\nThis patch drops all #ifdefs that reference older versions\n(note that curl's preprocessor macros are in hex, so we're\nlooking for 070b01, not 071101).\n\nSigned-off-by: Jeff King <peff@peff.net>\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n http.c        | 53 ---------------------------------------------------\n http.h        | 12 +-----------\n remote-curl.c |  3 ---\n 3 files changed, 1 insertion(+), 67 deletions(-)\n\ndiff --git a/http.c b/http.c\nindex 8119247149a..56182a89e25 100644\n--- a/http.c\n+++ b/http.c\n@@ -19,19 +19,11 @@\n static struct trace_key trace_curl = TRACE_KEY_INIT(CURL);\n static int trace_curl_data = 1;\n static int trace_curl_redact = 1;\n-#if LIBCURL_VERSION_NUM >= 0x070a08\n long int git_curl_ipresolve = CURL_IPRESOLVE_WHATEVER;\n-#else\n-long int git_curl_ipresolve;\n-#endif\n int active_requests;\n int http_is_verbose;\n ssize_t http_post_buffer = 16 * LARGE_PACKET_MAX;\n \n-#if LIBCURL_VERSION_NUM >= 0x070a06\n-#define LIBCURL_CAN_HANDLE_AUTH_ANY\n-#endif\n-\n static int min_curl_sessions = 1;\n static int curl_session_count;\n #ifdef USE_CURL_MULTI\n@@ -68,15 +60,9 @@ static struct {\n \t{ \"tlsv1.3\", CURL_SSLVERSION_TLSv1_3 },\n #endif\n };\n-#if LIBCURL_VERSION_NUM >= 0x070903\n static const char *ssl_key;\n-#endif\n-#if LIBCURL_VERSION_NUM >= 0x070908\n static const char *ssl_capath;\n-#endif\n-#if LIBCURL_VERSION_NUM >= 0x071304\n static const char *curl_no_proxy;\n-#endif\n #if LIBCURL_VERSION_NUM >= 0x072c00\n static const char *ssl_pinnedkey;\n #endif\n@@ -101,9 +87,7 @@ static struct {\n \t{ \"digest\", CURLAUTH_DIGEST },\n \t{ \"negotiate\", CURLAUTH_GSSNEGOTIATE },\n \t{ \"ntlm\", CURLAUTH_NTLM },\n-#ifdef LIBCURL_CAN_HANDLE_AUTH_ANY\n \t{ \"anyauth\", CURLAUTH_ANY },\n-#endif\n \t/*\n \t * CURLAUTH_DIGEST_IE has no corresponding command-line option in\n \t * curl(1) and is not included in CURLAUTH_ANY, so we leave it out\n@@ -143,7 +127,6 @@ enum http_follow_config http_follow_config = HTTP_FOLLOW_INITIAL;\n \n static struct credential cert_auth = CREDENTIAL_INIT;\n static int ssl_cert_password_required;\n-#ifdef LIBCURL_CAN_HANDLE_AUTH_ANY\n static unsigned long http_auth_methods = CURLAUTH_ANY;\n static int http_auth_methods_restricted;\n /* Modes for which empty_auth cannot actually help us. */\n@@ -153,7 +136,6 @@ static unsigned long empty_auth_useless =\n \t| CURLAUTH_DIGEST_IE\n #endif\n \t| CURLAUTH_DIGEST;\n-#endif\n \n static struct curl_slist *pragma_header;\n static struct curl_slist *no_pragma_header;\n@@ -237,12 +219,8 @@ static void finish_active_slot(struct active_request_slot *slot)\n \tif (slot->results != NULL) {\n \t\tslot->results->curl_result = slot->curl_result;\n \t\tslot->results->http_code = slot->http_code;\n-#if LIBCURL_VERSION_NUM >= 0x070a08\n \t\tcurl_easy_getinfo(slot->curl, CURLINFO_HTTPAUTH_AVAIL,\n \t\t\t\t  &slot->results->auth_avail);\n-#else\n-\t\tslot->results->auth_avail = 0;\n-#endif\n \n \t\tcurl_easy_getinfo(slot->curl, CURLINFO_HTTP_CONNECTCODE,\n \t\t\t&slot->results->http_connectcode);\n@@ -305,14 +283,10 @@ static int http_options(const char *var, const char *value, void *cb)\n \t\treturn git_config_string(&ssl_version, var, value);\n \tif (!strcmp(\"http.sslcert\", var))\n \t\treturn git_config_pathname(&ssl_cert, var, value);\n-#if LIBCURL_VERSION_NUM >= 0x070903\n \tif (!strcmp(\"http.sslkey\", var))\n \t\treturn git_config_pathname(&ssl_key, var, value);\n-#endif\n-#if LIBCURL_VERSION_NUM >= 0x070908\n \tif (!strcmp(\"http.sslcapath\", var))\n \t\treturn git_config_pathname(&ssl_capath, var, value);\n-#endif\n \tif (!strcmp(\"http.sslcainfo\", var))\n \t\treturn git_config_pathname(&ssl_cainfo, var, value);\n \tif (!strcmp(\"http.sslcertpasswordprotected\", var)) {\n@@ -461,12 +435,6 @@ static int curl_empty_auth_enabled(void)\n \tif (curl_empty_auth >= 0)\n \t\treturn curl_empty_auth;\n \n-#ifndef LIBCURL_CAN_HANDLE_AUTH_ANY\n-\t/*\n-\t * Our libcurl is too old to do AUTH_ANY in the first place;\n-\t * just default to turning the feature off.\n-\t */\n-#else\n \t/*\n \t * In the automatic case, kick in the empty-auth\n \t * hack as long as we would potentially try some\n@@ -479,7 +447,6 @@ static int curl_empty_auth_enabled(void)\n \tif (http_auth_methods_restricted &&\n \t    (http_auth_methods & ~empty_auth_useless))\n \t\treturn 1;\n-#endif\n \treturn 0;\n }\n \n@@ -552,7 +519,6 @@ static void init_curl_proxy_auth(CURL *result)\n \n \tvar_override(&http_proxy_authmethod, getenv(\"GIT_HTTP_PROXY_AUTHMETHOD\"));\n \n-#if LIBCURL_VERSION_NUM >= 0x070a07 /* CURLOPT_PROXYAUTH and CURLAUTH_ANY */\n \tif (http_proxy_authmethod) {\n \t\tint i;\n \t\tfor (i = 0; i < ARRAY_SIZE(proxy_authmethods); i++) {\n@@ -570,7 +536,6 @@ static void init_curl_proxy_auth(CURL *result)\n \t}\n \telse\n \t\tcurl_easy_setopt(result, CURLOPT_PROXYAUTH, CURLAUTH_ANY);\n-#endif\n }\n \n static int has_cert_password(void)\n@@ -879,12 +844,8 @@ static CURL *get_curl_handle(void)\n     }\n #endif\n \n-#if LIBCURL_VERSION_NUM >= 0x070907\n \tcurl_easy_setopt(result, CURLOPT_NETRC, CURL_NETRC_OPTIONAL);\n-#endif\n-#ifdef LIBCURL_CAN_HANDLE_AUTH_ANY\n \tcurl_easy_setopt(result, CURLOPT_HTTPAUTH, CURLAUTH_ANY);\n-#endif\n \n #ifdef CURLGSSAPI_DELEGATION_FLAG\n \tif (curl_deleg) {\n@@ -940,14 +901,10 @@ static CURL *get_curl_handle(void)\n \t\tcurl_easy_setopt(result, CURLOPT_SSLCERT, ssl_cert);\n \tif (has_cert_password())\n \t\tcurl_easy_setopt(result, CURLOPT_KEYPASSWD, cert_auth.password);\n-#if LIBCURL_VERSION_NUM >= 0x070903\n \tif (ssl_key != NULL)\n \t\tcurl_easy_setopt(result, CURLOPT_SSLKEY, ssl_key);\n-#endif\n-#if LIBCURL_VERSION_NUM >= 0x070908\n \tif (ssl_capath != NULL)\n \t\tcurl_easy_setopt(result, CURLOPT_CAPATH, ssl_capath);\n-#endif\n #if LIBCURL_VERSION_NUM >= 0x072c00\n \tif (ssl_pinnedkey != NULL)\n \t\tcurl_easy_setopt(result, CURLOPT_PINNEDPUBLICKEY, ssl_pinnedkey);\n@@ -1180,12 +1137,8 @@ void http_init(struct remote *remote, const char *url, int proactive_auth)\n \t\tcurl_ssl_verify = 0;\n \n \tset_from_env(&ssl_cert, \"GIT_SSL_CERT\");\n-#if LIBCURL_VERSION_NUM >= 0x070903\n \tset_from_env(&ssl_key, \"GIT_SSL_KEY\");\n-#endif\n-#if LIBCURL_VERSION_NUM >= 0x070908\n \tset_from_env(&ssl_capath, \"GIT_SSL_CAPATH\");\n-#endif\n \tset_from_env(&ssl_cainfo, \"GIT_SSL_CAINFO\");\n \n \tset_from_env(&user_agent, \"GIT_HTTP_USER_AGENT\");\n@@ -1367,12 +1320,8 @@ struct active_request_slot *get_active_slot(void)\n \telse\n \t\tcurl_easy_setopt(slot->curl, CURLOPT_FOLLOWLOCATION, 0);\n \n-#if LIBCURL_VERSION_NUM >= 0x070a08\n \tcurl_easy_setopt(slot->curl, CURLOPT_IPRESOLVE, git_curl_ipresolve);\n-#endif\n-#ifdef LIBCURL_CAN_HANDLE_AUTH_ANY\n \tcurl_easy_setopt(slot->curl, CURLOPT_HTTPAUTH, http_auth_methods);\n-#endif\n \tif (http_auth.password || curl_empty_auth_enabled())\n \t\tinit_curl_http_auth(slot->curl);\n \n@@ -1654,13 +1603,11 @@ static int handle_curl_result(struct slot_results *results)\n \t\t\tcredential_reject(&http_auth);\n \t\t\treturn HTTP_NOAUTH;\n \t\t} else {\n-#ifdef LIBCURL_CAN_HANDLE_AUTH_ANY\n \t\t\thttp_auth_methods &= ~CURLAUTH_GSSNEGOTIATE;\n \t\t\tif (results->auth_avail) {\n \t\t\t\thttp_auth_methods &= results->auth_avail;\n \t\t\t\thttp_auth_methods_restricted = 1;\n \t\t\t}\n-#endif\n \t\t\treturn HTTP_REAUTH;\n \t\t}\n \t} else {\ndiff --git a/http.h b/http.h\nindex bf3d1270ad8..d2f8cc56617 100644\n--- a/http.h\n+++ b/http.h\n@@ -22,13 +22,7 @@\n #define DEFAULT_MAX_REQUESTS 5\n #endif\n \n-#if LIBCURL_VERSION_NUM < 0x070704\n-#define curl_global_cleanup() do { /* nothing */ } while (0)\n-#endif\n-\n-#if LIBCURL_VERSION_NUM < 0x070800\n-#define curl_global_init(a) do { /* nothing */ } while (0)\n-#elif LIBCURL_VERSION_NUM >= 0x070c00\n+#if LIBCURL_VERSION_NUM >= 0x070c00\n #define curl_global_init(a) curl_global_init_mem(a, xmalloc, free, \\\n \t\t\t\t\t\txrealloc, xstrdup, xcalloc)\n #endif\n@@ -37,10 +31,6 @@\n #define NO_CURL_EASY_DUPHANDLE\n #endif\n \n-#if LIBCURL_VERSION_NUM < 0x070a03\n-#define CURLE_HTTP_RETURNED_ERROR CURLE_HTTP_NOT_FOUND\n-#endif\n-\n #if LIBCURL_VERSION_NUM < 0x070c03\n #define NO_CURL_IOCTL\n #endif\ndiff --git a/remote-curl.c b/remote-curl.c\nindex 6c320d57045..e738ae2c48a 100644\n--- a/remote-curl.c\n+++ b/remote-curl.c\n@@ -185,8 +185,6 @@ static int set_option(const char *name, const char *value)\n \t\t\t\t\t\t strbuf_detach(&unquoted, NULL));\n \t\t}\n \t\treturn 0;\n-\n-#if LIBCURL_VERSION_NUM >= 0x070a08\n \t} else if (!strcmp(name, \"family\")) {\n \t\tif (!strcmp(value, \"ipv4\"))\n \t\t\tgit_curl_ipresolve = CURL_IPRESOLVE_V4;\n@@ -197,7 +195,6 @@ static int set_option(const char *name, const char *value)\n \t\telse\n \t\t\treturn -1;\n \t\treturn 0;\n-#endif /* LIBCURL_VERSION_NUM >= 0x070a08 */\n \t} else if (!strcmp(name, \"from-promisor\")) {\n \t\toptions.from_promisor = 1;\n \t\treturn 0;\n-- \n2.32.0.1069.g516d52f3d85\n\n"},{"id":"431546","messageId":"patch-v3-2.7-fb308258e2b-20210730T092843Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-v3-0.7-00000000000-20210730T092843Z-avarab@gmail.com","subject":"[PATCH v3 2/7] http: drop support for curl < 7.16.0","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-07-30T09:31:54Z","receivedAt":"2021-07-30T09:35:09Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"From: Jeff King <peff@peff.net>\n\nIn the last commit we dropped support for curl < 7.11.1, let's\ncontinue that and drop support for versions older than 7.16.0. This\nallows us to get rid of some now-obsolete #ifdefs.\n\nChoosing 7.16.0 is a somewhat arbitrary cutoff:\n\n  1. It came out in October of 2006, almost 15 years ago.\n     Besides being a nice round number, around 10 years is\n     a common end-of-life support period, even for conservative\n     distributions.\n\n  2. That version introduced the curl_multi interface, which\n     gives us a lot of bang for the buck in removing #ifdefs\n\nRHEL 5 came with curl 7.15.5[1] (released in August 2006). RHEL 5's\nextended life cycle program ended on 2020-11-30[1]. RHEL 6 comes with\ncurl 7.19.7 (released in November 2009), and RHEL 7 comes with\n7.29.0 (released in February 2013).\n\n1. http://lore.kernel.org/git/873e1f31-2a96-5b72-2f20-a5816cad1b51@jupiterrise.com\n\nSigned-off-by: Jeff King <peff@peff.net>\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n http-push.c   | 23 ---------------------\n http-walker.c | 12 -----------\n http.c        | 56 +--------------------------------------------------\n http.h        | 25 +----------------------\n imap-send.c   |  4 ----\n remote-curl.c |  4 ----\n 6 files changed, 2 insertions(+), 122 deletions(-)\n\ndiff --git a/http-push.c b/http-push.c\nindex d7cb1675a2d..aa3de7c1086 100644\n--- a/http-push.c\n+++ b/http-push.c\n@@ -203,10 +203,8 @@ static void curl_setup_http(CURL *curl, const char *url,\n \tcurl_easy_setopt(curl, CURLOPT_INFILE, buffer);\n \tcurl_easy_setopt(curl, CURLOPT_INFILESIZE, buffer->buf.len);\n \tcurl_easy_setopt(curl, CURLOPT_READFUNCTION, fread_buffer);\n-#ifndef NO_CURL_IOCTL\n \tcurl_easy_setopt(curl, CURLOPT_IOCTLFUNCTION, ioctl_buffer);\n \tcurl_easy_setopt(curl, CURLOPT_IOCTLDATA, buffer);\n-#endif\n \tcurl_easy_setopt(curl, CURLOPT_WRITEFUNCTION, write_fn);\n \tcurl_easy_setopt(curl, CURLOPT_NOBODY, 0);\n \tcurl_easy_setopt(curl, CURLOPT_CUSTOMREQUEST, custom_req);\n@@ -249,8 +247,6 @@ static void process_response(void *callback_data)\n \tfinish_request(request);\n }\n \n-#ifdef USE_CURL_MULTI\n-\n static void start_fetch_loose(struct transfer_request *request)\n {\n \tstruct active_request_slot *slot;\n@@ -299,7 +295,6 @@ static void start_mkcol(struct transfer_request *request)\n \t\tFREE_AND_NULL(request->url);\n \t}\n }\n-#endif\n \n static void start_fetch_packed(struct transfer_request *request)\n {\n@@ -605,7 +600,6 @@ static void finish_request(struct transfer_request *request)\n \t}\n }\n \n-#ifdef USE_CURL_MULTI\n static int is_running_queue;\n static int fill_active_slot(void *unused)\n {\n@@ -629,7 +623,6 @@ static int fill_active_slot(void *unused)\n \t}\n \treturn 0;\n }\n-#endif\n \n static void get_remote_object_list(unsigned char parent);\n \n@@ -658,10 +651,8 @@ static void add_fetch_request(struct object *obj)\n \trequest->next = request_queue_head;\n \trequest_queue_head = request;\n \n-#ifdef USE_CURL_MULTI\n \tfill_active_slots();\n \tstep_active_slots();\n-#endif\n }\n \n static int add_send_request(struct object *obj, struct remote_lock *lock)\n@@ -696,10 +687,8 @@ static int add_send_request(struct object *obj, struct remote_lock *lock)\n \trequest->next = request_queue_head;\n \trequest_queue_head = request;\n \n-#ifdef USE_CURL_MULTI\n \tfill_active_slots();\n \tstep_active_slots();\n-#endif\n \n \treturn 1;\n }\n@@ -1682,21 +1671,15 @@ static int delete_remote_branch(const char *pattern, int force)\n \n static void run_request_queue(void)\n {\n-#ifdef USE_CURL_MULTI\n \tis_running_queue = 1;\n \tfill_active_slots();\n \tadd_fill_function(NULL, fill_active_slot);\n-#endif\n \tdo {\n \t\tfinish_all_active_slots();\n-#ifdef USE_CURL_MULTI\n \t\tfill_active_slots();\n-#endif\n \t} while (request_queue_head && !aborted);\n \n-#ifdef USE_CURL_MULTI\n \tis_running_queue = 0;\n-#endif\n }\n \n int cmd_main(int argc, const char **argv)\n@@ -1770,10 +1753,6 @@ int cmd_main(int argc, const char **argv)\n \t\tbreak;\n \t}\n \n-#ifndef USE_CURL_MULTI\n-\tdie(\"git-push is not available for http/https repository when not compiled with USE_CURL_MULTI\");\n-#endif\n-\n \tif (!repo->url)\n \t\tusage(http_push_usage);\n \n@@ -1786,9 +1765,7 @@ int cmd_main(int argc, const char **argv)\n \n \thttp_init(NULL, repo->url, 1);\n \n-#ifdef USE_CURL_MULTI\n \tis_running_queue = 0;\n-#endif\n \n \t/* Verify DAV compliance/lock support */\n \tif (!locking_available()) {\ndiff --git a/http-walker.c b/http-walker.c\nindex 90d8ecb57ef..19e31623f04 100644\n--- a/http-walker.c\n+++ b/http-walker.c\n@@ -127,7 +127,6 @@ static void release_object_request(struct object_request *obj_req)\n \tfree(obj_req);\n }\n \n-#ifdef USE_CURL_MULTI\n static int fill_active_slot(struct walker *walker)\n {\n \tstruct object_request *obj_req;\n@@ -146,7 +145,6 @@ static int fill_active_slot(struct walker *walker)\n \t}\n \treturn 0;\n }\n-#endif\n \n static void prefetch(struct walker *walker, unsigned char *sha1)\n {\n@@ -163,10 +161,8 @@ static void prefetch(struct walker *walker, unsigned char *sha1)\n \thttp_is_verbose = walker->get_verbosely;\n \tlist_add_tail(&newreq->node, &object_queue_head);\n \n-#ifdef USE_CURL_MULTI\n \tfill_active_slots();\n \tstep_active_slots();\n-#endif\n }\n \n static int is_alternate_allowed(const char *url)\n@@ -357,11 +353,9 @@ static void fetch_alternates(struct walker *walker, const char *base)\n \t * wait for them to arrive and return to processing this request's\n \t * curl message\n \t */\n-#ifdef USE_CURL_MULTI\n \twhile (cdata->got_alternates == 0) {\n \t\tstep_active_slots();\n \t}\n-#endif\n \n \t/* Nothing to do if they've already been fetched */\n \tif (cdata->got_alternates == 1)\n@@ -505,12 +499,8 @@ static int fetch_object(struct walker *walker, unsigned char *hash)\n \t\treturn 0;\n \t}\n \n-#ifdef USE_CURL_MULTI\n \twhile (obj_req->state == WAITING)\n \t\tstep_active_slots();\n-#else\n-\tstart_object_request(walker, obj_req);\n-#endif\n \n \t/*\n \t * obj_req->req might change when fetching alternates in the callback\n@@ -623,9 +613,7 @@ struct walker *get_http_walker(const char *url)\n \twalker->cleanup = cleanup;\n \twalker->data = data;\n \n-#ifdef USE_CURL_MULTI\n \tadd_fill_function(walker, (int (*)(void *)) fill_active_slot);\n-#endif\n \n \treturn walker;\n }\ndiff --git a/http.c b/http.c\nindex 56182a89e25..ef00e930232 100644\n--- a/http.c\n+++ b/http.c\n@@ -26,10 +26,8 @@ ssize_t http_post_buffer = 16 * LARGE_PACKET_MAX;\n \n static int min_curl_sessions = 1;\n static int curl_session_count;\n-#ifdef USE_CURL_MULTI\n static int max_requests = -1;\n static CURLM *curlm;\n-#endif\n #ifndef NO_CURL_EASY_DUPHANDLE\n static CURL *curl_default;\n #endif\n@@ -117,14 +115,6 @@ static int curl_empty_auth = -1;\n \n enum http_follow_config http_follow_config = HTTP_FOLLOW_INITIAL;\n \n-#if LIBCURL_VERSION_NUM >= 0x071700\n-/* Use CURLOPT_KEYPASSWD as is */\n-#elif LIBCURL_VERSION_NUM >= 0x070903\n-#define CURLOPT_KEYPASSWD CURLOPT_SSLKEYPASSWD\n-#else\n-#define CURLOPT_KEYPASSWD CURLOPT_SSLCERTPASSWD\n-#endif\n-\n static struct credential cert_auth = CREDENTIAL_INIT;\n static int ssl_cert_password_required;\n static unsigned long http_auth_methods = CURLAUTH_ANY;\n@@ -168,7 +158,6 @@ size_t fread_buffer(char *ptr, size_t eltsize, size_t nmemb, void *buffer_)\n \treturn size / eltsize;\n }\n \n-#ifndef NO_CURL_IOCTL\n curlioerr ioctl_buffer(CURL *handle, int cmd, void *clientp)\n {\n \tstruct buffer *buffer = clientp;\n@@ -185,7 +174,6 @@ curlioerr ioctl_buffer(CURL *handle, int cmd, void *clientp)\n \t\treturn CURLIOE_UNKNOWNCMD;\n \t}\n }\n-#endif\n \n size_t fwrite_buffer(char *ptr, size_t eltsize, size_t nmemb, void *buffer_)\n {\n@@ -233,12 +221,9 @@ static void finish_active_slot(struct active_request_slot *slot)\n \n static void xmulti_remove_handle(struct active_request_slot *slot)\n {\n-#ifdef USE_CURL_MULTI\n \tcurl_multi_remove_handle(curlm, slot->curl);\n-#endif\n }\n \n-#ifdef USE_CURL_MULTI\n static void process_curl_messages(void)\n {\n \tint num_messages;\n@@ -266,7 +251,6 @@ static void process_curl_messages(void)\n \t\tcurl_message = curl_multi_info_read(curlm, &num_messages);\n \t}\n }\n-#endif\n \n static int http_options(const char *var, const char *value, void *cb)\n {\n@@ -315,18 +299,14 @@ static int http_options(const char *var, const char *value, void *cb)\n \n \tif (!strcmp(\"http.minsessions\", var)) {\n \t\tmin_curl_sessions = git_config_int(var, value);\n-#ifndef USE_CURL_MULTI\n \t\tif (min_curl_sessions > 1)\n \t\t\tmin_curl_sessions = 1;\n-#endif\n \t\treturn 0;\n \t}\n-#ifdef USE_CURL_MULTI\n \tif (!strcmp(\"http.maxrequests\", var)) {\n \t\tmax_requests = git_config_int(var, value);\n \t\treturn 0;\n \t}\n-#endif\n \tif (!strcmp(\"http.lowspeedlimit\", var)) {\n \t\tcurl_low_speed_limit = (long)git_config_int(var, value);\n \t\treturn 0;\n@@ -574,7 +554,7 @@ static void set_curl_keepalive(CURL *c)\n \tcurl_easy_setopt(c, CURLOPT_TCP_KEEPALIVE, 1);\n }\n \n-#elif LIBCURL_VERSION_NUM >= 0x071000\n+#else\n static int sockopt_callback(void *client, curl_socket_t fd, curlsocktype type)\n {\n \tint ka = 1;\n@@ -595,12 +575,6 @@ static void set_curl_keepalive(CURL *c)\n {\n \tcurl_easy_setopt(c, CURLOPT_SOCKOPTFUNCTION, sockopt_callback);\n }\n-\n-#else\n-static void set_curl_keepalive(CURL *c)\n-{\n-\t/* not supported on older curl versions */\n-}\n #endif\n \n static void redact_sensitive_header(struct strbuf *header)\n@@ -1121,7 +1095,6 @@ void http_init(struct remote *remote, const char *url, int proactive_auth)\n \tno_pragma_header = curl_slist_append(http_copy_default_headers(),\n \t\t\"Pragma:\");\n \n-#ifdef USE_CURL_MULTI\n \t{\n \t\tchar *http_max_requests = getenv(\"GIT_HTTP_MAX_REQUESTS\");\n \t\tif (http_max_requests != NULL)\n@@ -1131,7 +1104,6 @@ void http_init(struct remote *remote, const char *url, int proactive_auth)\n \tcurlm = curl_multi_init();\n \tif (!curlm)\n \t\tdie(\"curl_multi_init failed\");\n-#endif\n \n \tif (getenv(\"GIT_SSL_NO_VERIFY\"))\n \t\tcurl_ssl_verify = 0;\n@@ -1154,10 +1126,8 @@ void http_init(struct remote *remote, const char *url, int proactive_auth)\n \t\tcurl_ssl_verify = 1;\n \n \tcurl_session_count = 0;\n-#ifdef USE_CURL_MULTI\n \tif (max_requests < 1)\n \t\tmax_requests = DEFAULT_MAX_REQUESTS;\n-#endif\n \n \tset_from_env(&http_proxy_ssl_cert, \"GIT_PROXY_SSL_CERT\");\n \tset_from_env(&http_proxy_ssl_key, \"GIT_PROXY_SSL_KEY\");\n@@ -1201,9 +1171,7 @@ void http_cleanup(void)\n \tcurl_easy_cleanup(curl_default);\n #endif\n \n-#ifdef USE_CURL_MULTI\n \tcurl_multi_cleanup(curlm);\n-#endif\n \tcurl_global_cleanup();\n \n \tstring_list_clear(&extra_http_headers, 0);\n@@ -1250,7 +1218,6 @@ struct active_request_slot *get_active_slot(void)\n \tstruct active_request_slot *slot = active_queue_head;\n \tstruct active_request_slot *newslot;\n \n-#ifdef USE_CURL_MULTI\n \tint num_transfers;\n \n \t/* Wait for a slot to open up if the queue is full */\n@@ -1259,7 +1226,6 @@ struct active_request_slot *get_active_slot(void)\n \t\tif (num_transfers < active_requests)\n \t\t\tprocess_curl_messages();\n \t}\n-#endif\n \n \twhile (slot != NULL && slot->in_use)\n \t\tslot = slot->next;\n@@ -1330,7 +1296,6 @@ struct active_request_slot *get_active_slot(void)\n \n int start_active_slot(struct active_request_slot *slot)\n {\n-#ifdef USE_CURL_MULTI\n \tCURLMcode curlm_result = curl_multi_add_handle(curlm, slot->curl);\n \tint num_transfers;\n \n@@ -1348,11 +1313,9 @@ int start_active_slot(struct active_request_slot *slot)\n \t * something.\n \t */\n \tcurl_multi_perform(curlm, &num_transfers);\n-#endif\n \treturn 1;\n }\n \n-#ifdef USE_CURL_MULTI\n struct fill_chain {\n \tvoid *data;\n \tint (*fill)(void *);\n@@ -1411,11 +1374,9 @@ void step_active_slots(void)\n \t\tfill_active_slots();\n \t}\n }\n-#endif\n \n void run_active_slot(struct active_request_slot *slot)\n {\n-#ifdef USE_CURL_MULTI\n \tfd_set readfds;\n \tfd_set writefds;\n \tfd_set excfds;\n@@ -1428,7 +1389,6 @@ void run_active_slot(struct active_request_slot *slot)\n \t\tstep_active_slots();\n \n \t\tif (slot->in_use) {\n-#if LIBCURL_VERSION_NUM >= 0x070f04\n \t\t\tlong curl_timeout;\n \t\t\tcurl_multi_timeout(curlm, &curl_timeout);\n \t\t\tif (curl_timeout == 0) {\n@@ -1440,10 +1400,6 @@ void run_active_slot(struct active_request_slot *slot)\n \t\t\t\tselect_timeout.tv_sec  =  curl_timeout / 1000;\n \t\t\t\tselect_timeout.tv_usec = (curl_timeout % 1000) * 1000;\n \t\t\t}\n-#else\n-\t\t\tselect_timeout.tv_sec  = 0;\n-\t\t\tselect_timeout.tv_usec = 50000;\n-#endif\n \n \t\t\tmax_fd = -1;\n \t\t\tFD_ZERO(&readfds);\n@@ -1466,12 +1422,6 @@ void run_active_slot(struct active_request_slot *slot)\n \t\t\tselect(max_fd+1, &readfds, &writefds, &excfds, &select_timeout);\n \t\t}\n \t}\n-#else\n-\twhile (slot->in_use) {\n-\t\tslot->curl_result = curl_easy_perform(slot->curl);\n-\t\tfinish_active_slot(slot);\n-\t}\n-#endif\n }\n \n static void release_active_slot(struct active_request_slot *slot)\n@@ -1485,9 +1435,7 @@ static void release_active_slot(struct active_request_slot *slot)\n \t\t\tcurl_session_count--;\n \t\t}\n \t}\n-#ifdef USE_CURL_MULTI\n \tfill_active_slots();\n-#endif\n }\n \n void finish_all_active_slots(void)\n@@ -1613,12 +1561,10 @@ static int handle_curl_result(struct slot_results *results)\n \t} else {\n \t\tif (results->http_connectcode == 407)\n \t\t\tcredential_reject(&proxy_auth);\n-#if LIBCURL_VERSION_NUM >= 0x070c00\n \t\tif (!curl_errorstr[0])\n \t\t\tstrlcpy(curl_errorstr,\n \t\t\t\tcurl_easy_strerror(results->curl_result),\n \t\t\t\tsizeof(curl_errorstr));\n-#endif\n \t\treturn HTTP_ERROR;\n \t}\n }\ndiff --git a/http.h b/http.h\nindex d2f8cc56617..cb092622a73 100644\n--- a/http.h\n+++ b/http.h\n@@ -10,31 +10,12 @@\n #include \"remote.h\"\n #include \"url.h\"\n \n-/*\n- * We detect based on the cURL version if multi-transfer is\n- * usable in this implementation and define this symbol accordingly.\n- * This shouldn't be set by the Makefile or by the user (e.g. via CFLAGS).\n- */\n-#undef USE_CURL_MULTI\n-\n-#if LIBCURL_VERSION_NUM >= 0x071000\n-#define USE_CURL_MULTI\n #define DEFAULT_MAX_REQUESTS 5\n-#endif\n-\n-#if LIBCURL_VERSION_NUM >= 0x070c00\n-#define curl_global_init(a) curl_global_init_mem(a, xmalloc, free, \\\n-\t\t\t\t\t\txrealloc, xstrdup, xcalloc)\n-#endif\n \n-#if (LIBCURL_VERSION_NUM < 0x070c04) || (LIBCURL_VERSION_NUM == 0x071000)\n+#if LIBCURL_VERSION_NUM == 0x071000\n #define NO_CURL_EASY_DUPHANDLE\n #endif\n \n-#if LIBCURL_VERSION_NUM < 0x070c03\n-#define NO_CURL_IOCTL\n-#endif\n-\n /*\n  * CURLOPT_USE_SSL was known as CURLOPT_FTP_SSL up to 7.16.4,\n  * and the constants were known as CURLFTPSSL_*\n@@ -72,9 +53,7 @@ struct buffer {\n size_t fread_buffer(char *ptr, size_t eltsize, size_t nmemb, void *strbuf);\n size_t fwrite_buffer(char *ptr, size_t eltsize, size_t nmemb, void *strbuf);\n size_t fwrite_null(char *ptr, size_t eltsize, size_t nmemb, void *strbuf);\n-#ifndef NO_CURL_IOCTL\n curlioerr ioctl_buffer(CURL *handle, int cmd, void *clientp);\n-#endif\n \n /* Slot lifecycle functions */\n struct active_request_slot *get_active_slot(void);\n@@ -91,11 +70,9 @@ void finish_all_active_slots(void);\n int run_one_slot(struct active_request_slot *slot,\n \t\t struct slot_results *results);\n \n-#ifdef USE_CURL_MULTI\n void fill_active_slots(void);\n void add_fill_function(void *data, int (*fill)(void *));\n void step_active_slots(void);\n-#endif\n \n void http_init(struct remote *remote, const char *url,\n \t       int proactive_auth);\ndiff --git a/imap-send.c b/imap-send.c\nindex a0540ba5cf4..49a5f8aa597 100644\n--- a/imap-send.c\n+++ b/imap-send.c\n@@ -1517,11 +1517,7 @@ static int curl_append_msgs_to_imap(struct imap_server_conf *server,\n \tif (cred.username) {\n \t\tif (res == CURLE_OK)\n \t\t\tcredential_approve(&cred);\n-#if LIBCURL_VERSION_NUM >= 0x070d01\n \t\telse if (res == CURLE_LOGIN_DENIED)\n-#else\n-\t\telse\n-#endif\n \t\t\tcredential_reject(&cred);\n \t}\n \ndiff --git a/remote-curl.c b/remote-curl.c\nindex e738ae2c48a..09f09aeece3 100644\n--- a/remote-curl.c\n+++ b/remote-curl.c\n@@ -706,7 +706,6 @@ static size_t rpc_out(void *ptr, size_t eltsize,\n \treturn avail;\n }\n \n-#ifndef NO_CURL_IOCTL\n static curlioerr rpc_ioctl(CURL *handle, int cmd, void *clientp)\n {\n \tstruct rpc_state *rpc = clientp;\n@@ -727,7 +726,6 @@ static curlioerr rpc_ioctl(CURL *handle, int cmd, void *clientp)\n \t\treturn CURLIOE_UNKNOWNCMD;\n \t}\n }\n-#endif\n \n struct check_pktline_state {\n \tchar len_buf[4];\n@@ -946,10 +944,8 @@ static int post_rpc(struct rpc_state *rpc, int stateless_connect, int flush_rece\n \t\trpc->initial_buffer = 1;\n \t\tcurl_easy_setopt(slot->curl, CURLOPT_READFUNCTION, rpc_out);\n \t\tcurl_easy_setopt(slot->curl, CURLOPT_INFILE, rpc);\n-#ifndef NO_CURL_IOCTL\n \t\tcurl_easy_setopt(slot->curl, CURLOPT_IOCTLFUNCTION, rpc_ioctl);\n \t\tcurl_easy_setopt(slot->curl, CURLOPT_IOCTLDATA, rpc);\n-#endif\n \t\tif (options.verbosity > 1) {\n \t\t\tfprintf(stderr, \"POST %s (chunked)\\n\", rpc->service_name);\n \t\t\tfflush(stderr);\n-- \n2.32.0.1069.g516d52f3d85\n\n"},{"id":"431547","messageId":"patch-v3-3.7-9fcd3a3e486-20210730T092843Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-v3-0.7-00000000000-20210730T092843Z-avarab@gmail.com","subject":"[PATCH v3 3/7] http: drop support for curl < 7.19.4","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-07-30T09:31:55Z","receivedAt":"2021-07-30T09:35:16Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"From: Jeff King <peff@peff.net>\n\nIn the last commit we dropped support for curl < 7.16.0, let's\ncontinue that and drop support for versions older than 7.19.4. This\nallows us to simplify the code by getting rid of some \"#ifdef\"'s.\n\nGit was broken with vanilla curl < 7.19.4 from v2.12.0 until\nv2.15.0. Compiling with it was broken by using CURLPROTO_* outside any\n\"#ifdef\" in aeae4db174 (http: create function to get curl allowed\nprotocols, 2016-12-14), and fixed in v2.15.0 in f18777ba6ef (http: fix\nhandling of missing CURLPROTO_*, 2017-08-11).\n\nIt's unclear how much anyone was impacted by that in practice, since\nas noted in [1] RHEL versions using curl older than that still\ncompiled, because RedHat backported some features. Perhaps other\nvendors did the same.\n\nStill, it's one datapoint indicating that it wasn't in active use at\nthe time. That (the v2.12.0 release) was in Feb 24, 2017, with v2.15.0\non Oct 30, 2017, it's now mid-2021.\n\n1. http://lore.kernel.org/git/c8a2716d-76ac-735c-57f9-175ca3acbcb0@jupiterrise.com;\n   followed-up by f18777ba6ef (http: fix handling of missing CURLPROTO_*,\n   2017-08-11)\n\nSigned-off-by: Jeff King <peff@peff.net>\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n http.c | 50 --------------------------------------------------\n http.h |  4 ----\n 2 files changed, 54 deletions(-)\n\ndiff --git a/http.c b/http.c\nindex ef00e930232..1f0d7664d35 100644\n--- a/http.c\n+++ b/http.c\n@@ -28,9 +28,7 @@ static int min_curl_sessions = 1;\n static int curl_session_count;\n static int max_requests = -1;\n static CURLM *curlm;\n-#ifndef NO_CURL_EASY_DUPHANDLE\n static CURL *curl_default;\n-#endif\n \n #define PREV_BUF_SIZE 4096\n \n@@ -440,24 +438,8 @@ static void init_curl_http_auth(CURL *result)\n \n \tcredential_fill(&http_auth);\n \n-#if LIBCURL_VERSION_NUM >= 0x071301\n \tcurl_easy_setopt(result, CURLOPT_USERNAME, http_auth.username);\n \tcurl_easy_setopt(result, CURLOPT_PASSWORD, http_auth.password);\n-#else\n-\t{\n-\t\tstatic struct strbuf up = STRBUF_INIT;\n-\t\t/*\n-\t\t * Note that we assume we only ever have a single set of\n-\t\t * credentials in a given program run, so we do not have\n-\t\t * to worry about updating this buffer, only setting its\n-\t\t * initial value.\n-\t\t */\n-\t\tif (!up.len)\n-\t\t\tstrbuf_addf(&up, \"%s:%s\",\n-\t\t\t\thttp_auth.username, http_auth.password);\n-\t\tcurl_easy_setopt(result, CURLOPT_USERPWD, up.buf);\n-\t}\n-#endif\n }\n \n /* *var must be free-able */\n@@ -471,22 +453,10 @@ static void var_override(const char **var, char *value)\n \n static void set_proxyauth_name_password(CURL *result)\n {\n-#if LIBCURL_VERSION_NUM >= 0x071301\n \t\tcurl_easy_setopt(result, CURLOPT_PROXYUSERNAME,\n \t\t\tproxy_auth.username);\n \t\tcurl_easy_setopt(result, CURLOPT_PROXYPASSWORD,\n \t\t\tproxy_auth.password);\n-#else\n-\t\tstruct strbuf s = STRBUF_INIT;\n-\n-\t\tstrbuf_addstr_urlencode(&s, proxy_auth.username,\n-\t\t\t\t\tis_rfc3986_unreserved);\n-\t\tstrbuf_addch(&s, ':');\n-\t\tstrbuf_addstr_urlencode(&s, proxy_auth.password,\n-\t\t\t\t\tis_rfc3986_unreserved);\n-\t\tcurl_proxyuserpwd = strbuf_detach(&s, NULL);\n-\t\tcurl_easy_setopt(result, CURLOPT_PROXYUSERPWD, curl_proxyuserpwd);\n-#endif\n }\n \n static void init_curl_proxy_auth(CURL *result)\n@@ -748,7 +718,6 @@ void setup_curl_trace(CURL *handle)\n \tcurl_easy_setopt(handle, CURLOPT_DEBUGDATA, NULL);\n }\n \n-#ifdef CURLPROTO_HTTP\n static long get_curl_allowed_protocols(int from_user)\n {\n \tlong allowed_protocols = 0;\n@@ -764,7 +733,6 @@ static long get_curl_allowed_protocols(int from_user)\n \n \treturn allowed_protocols;\n }\n-#endif\n \n #if LIBCURL_VERSION_NUM >=0x072f00\n static int get_curl_http_version_opt(const char *version_string, long *opt)\n@@ -906,19 +874,11 @@ static CURL *get_curl_handle(void)\n \t}\n \n \tcurl_easy_setopt(result, CURLOPT_MAXREDIRS, 20);\n-#if LIBCURL_VERSION_NUM >= 0x071301\n \tcurl_easy_setopt(result, CURLOPT_POSTREDIR, CURL_REDIR_POST_ALL);\n-#elif LIBCURL_VERSION_NUM >= 0x071101\n-\tcurl_easy_setopt(result, CURLOPT_POST301, 1);\n-#endif\n-#ifdef CURLPROTO_HTTP\n \tcurl_easy_setopt(result, CURLOPT_REDIR_PROTOCOLS,\n \t\t\t get_curl_allowed_protocols(0));\n \tcurl_easy_setopt(result, CURLOPT_PROTOCOLS,\n \t\t\t get_curl_allowed_protocols(-1));\n-#else\n-\twarning(_(\"Protocol restrictions not supported with cURL < 7.19.4\"));\n-#endif\n \tif (getenv(\"GIT_CURL_VERBOSE\"))\n \t\thttp_trace_curl_no_data();\n \tsetup_curl_trace(result);\n@@ -1012,11 +972,9 @@ static CURL *get_curl_handle(void)\n \t\t\tdie(\"Invalid proxy URL '%s'\", curl_http_proxy);\n \n \t\tcurl_easy_setopt(result, CURLOPT_PROXY, proxy_auth.host);\n-#if LIBCURL_VERSION_NUM >= 0x071304\n \t\tvar_override(&curl_no_proxy, getenv(\"NO_PROXY\"));\n \t\tvar_override(&curl_no_proxy, getenv(\"no_proxy\"));\n \t\tcurl_easy_setopt(result, CURLOPT_NOPROXY, curl_no_proxy);\n-#endif\n \t}\n \tinit_curl_proxy_auth(result);\n \n@@ -1147,9 +1105,7 @@ void http_init(struct remote *remote, const char *url, int proactive_auth)\n \t\t\tssl_cert_password_required = 1;\n \t}\n \n-#ifndef NO_CURL_EASY_DUPHANDLE\n \tcurl_default = get_curl_handle();\n-#endif\n }\n \n void http_cleanup(void)\n@@ -1167,9 +1123,7 @@ void http_cleanup(void)\n \t}\n \tactive_queue_head = NULL;\n \n-#ifndef NO_CURL_EASY_DUPHANDLE\n \tcurl_easy_cleanup(curl_default);\n-#endif\n \n \tcurl_multi_cleanup(curlm);\n \tcurl_global_cleanup();\n@@ -1248,11 +1202,7 @@ struct active_request_slot *get_active_slot(void)\n \t}\n \n \tif (slot->curl == NULL) {\n-#ifdef NO_CURL_EASY_DUPHANDLE\n-\t\tslot->curl = get_curl_handle();\n-#else\n \t\tslot->curl = curl_easy_duphandle(curl_default);\n-#endif\n \t\tcurl_session_count++;\n \t}\n \ndiff --git a/http.h b/http.h\nindex cb092622a73..19f19dbe74c 100644\n--- a/http.h\n+++ b/http.h\n@@ -12,10 +12,6 @@\n \n #define DEFAULT_MAX_REQUESTS 5\n \n-#if LIBCURL_VERSION_NUM == 0x071000\n-#define NO_CURL_EASY_DUPHANDLE\n-#endif\n-\n /*\n  * CURLOPT_USE_SSL was known as CURLOPT_FTP_SSL up to 7.16.4,\n  * and the constants were known as CURLFTPSSL_*\n-- \n2.32.0.1069.g516d52f3d85\n\n"},{"id":"431548","messageId":"patch-v3-5.7-b857a9ef7b1-20210730T092843Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-v3-0.7-00000000000-20210730T092843Z-avarab@gmail.com","subject":"[PATCH v3 5/7] http: drop support for curl < 7.18.0 (again)","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-07-30T09:31:57Z","receivedAt":"2021-07-30T09:35:18Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"In a preceding commit we dropped support for curl < 7.19.4, so we can\ndrop support for this non-obvious dependency on curl < 7.18.0.\n\nIt's non-obvious because in curl's hex version notation 0x071800 is\nversion 7.24.0, *not* 7.18.0, so at a glance this patch looks\nincorrect.\n\nBut it's correct, because the existing version check being removed\nhere is wrong. The check guards use of the following curl defines:\n\n    CURLPROXY_SOCKS4                7.10\n    CURLPROXY_SOCKS4A               7.18.0\n    CURLPROXY_SOCKS5                7.10\n    CURLPROXY_SOCKS5_HOSTNAME       7.18.0\n\nI.e. the oldest version that has these is in fact 7.18.0, not\n7.24.0. That we were checking 7.24.0 is just an mistake in\n6d7afe07f29 (remote-http(s): support SOCKS proxies, 2015-10-26),\ni.e. its author confusing base 10 and base 16.\n\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n http.c | 2 --\n 1 file changed, 2 deletions(-)\n\ndiff --git a/http.c b/http.c\nindex e9446850a62..477bf591141 100644\n--- a/http.c\n+++ b/http.c\n@@ -927,7 +927,6 @@ static CURL *get_curl_handle(void)\n \t\t */\n \t\tcurl_easy_setopt(result, CURLOPT_PROXY, \"\");\n \t} else if (curl_http_proxy) {\n-#if LIBCURL_VERSION_NUM >= 0x071800\n \t\tif (starts_with(curl_http_proxy, \"socks5h\"))\n \t\t\tcurl_easy_setopt(result,\n \t\t\t\tCURLOPT_PROXYTYPE, CURLPROXY_SOCKS5_HOSTNAME);\n@@ -940,7 +939,6 @@ static CURL *get_curl_handle(void)\n \t\telse if (starts_with(curl_http_proxy, \"socks\"))\n \t\t\tcurl_easy_setopt(result,\n \t\t\t\tCURLOPT_PROXYTYPE, CURLPROXY_SOCKS4);\n-#endif\n #if LIBCURL_VERSION_NUM >= 0x073400\n \t\telse if (starts_with(curl_http_proxy, \"https\")) {\n \t\t\tcurl_easy_setopt(result, CURLOPT_PROXYTYPE, CURLPROXY_HTTPS);\n-- \n2.32.0.1069.g516d52f3d85\n\n"},{"id":"431549","messageId":"patch-v3-4.7-230b968382f-20210730T092843Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-v3-0.7-00000000000-20210730T092843Z-avarab@gmail.com","subject":"[PATCH v3 4/7] http: drop support for curl < 7.19.3 and <= 7.16.4 (or <7.17.0) (again)","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-07-30T09:31:56Z","receivedAt":"2021-07-30T09:35:20Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"Remove the conditional use of CURLAUTH_DIGEST_IE and\nCURLOPT_USE_SSL. These two have been split from earlier simpler checks\nagainst LIBCURL_VERSION_NUM for ease of review.\n\nThe CURLAUTH_DIGEST_IE flag was added in 7.19.3[1], and\nCURLOPT_USE_SSL in 7.16.4[2] or 7.17.0[3], depending on the source. As\nnoted in [2] it was then renamed around that time from the older\nCURLOPT_FTP_SSL.\n\n1. https://curl.se/libcurl/c/CURLOPT_HTTPAUTH.html\n2. https://curl.se/libcurl/c/CURLOPT_USE_SSL.html\n3. https://github.com/curl/curl/blob/master/docs/libcurl/symbols-in-versions\n\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n http.c | 4 ----\n http.h | 9 ---------\n 2 files changed, 13 deletions(-)\n\ndiff --git a/http.c b/http.c\nindex 1f0d7664d35..e9446850a62 100644\n--- a/http.c\n+++ b/http.c\n@@ -120,9 +120,7 @@ static int http_auth_methods_restricted;\n /* Modes for which empty_auth cannot actually help us. */\n static unsigned long empty_auth_useless =\n \tCURLAUTH_BASIC\n-#ifdef CURLAUTH_DIGEST_IE\n \t| CURLAUTH_DIGEST_IE\n-#endif\n \t| CURLAUTH_DIGEST;\n \n static struct curl_slist *pragma_header;\n@@ -893,10 +891,8 @@ static CURL *get_curl_handle(void)\n \tif (curl_ftp_no_epsv)\n \t\tcurl_easy_setopt(result, CURLOPT_FTP_USE_EPSV, 0);\n \n-#ifdef CURLOPT_USE_SSL\n \tif (curl_ssl_try)\n \t\tcurl_easy_setopt(result, CURLOPT_USE_SSL, CURLUSESSL_TRY);\n-#endif\n \n \t/*\n \t * CURL also examines these variables as a fallback; but we need to query\ndiff --git a/http.h b/http.h\nindex 19f19dbe74c..3db5a0cf320 100644\n--- a/http.h\n+++ b/http.h\n@@ -12,15 +12,6 @@\n \n #define DEFAULT_MAX_REQUESTS 5\n \n-/*\n- * CURLOPT_USE_SSL was known as CURLOPT_FTP_SSL up to 7.16.4,\n- * and the constants were known as CURLFTPSSL_*\n-*/\n-#if !defined(CURLOPT_USE_SSL) && defined(CURLOPT_FTP_SSL)\n-#define CURLOPT_USE_SSL CURLOPT_FTP_SSL\n-#define CURLUSESSL_TRY CURLFTPSSL_TRY\n-#endif\n-\n struct slot_results {\n \tCURLcode curl_result;\n \tlong http_code;\n-- \n2.32.0.1069.g516d52f3d85\n\n"},{"id":"431550","messageId":"patch-v3-6.7-95e42b17ce8-20210730T092843Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-v3-0.7-00000000000-20210730T092843Z-avarab@gmail.com","subject":"[PATCH v3 6/7] http: rename CURLOPT_FILE to CURLOPT_WRITEDATA","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-07-30T09:31:58Z","receivedAt":"2021-07-30T09:35:21Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"The CURLOPT_FILE name is an alias for CURLOPT_WRITEDATA, the\nCURLOPT_WRITEDATA name has been preferred since curl 7.9.7, released\nin May 2002[1].\n\n1. https://curl.se/libcurl/c/CURLOPT_WRITEDATA.html\n\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n http-push.c   | 6 +++---\n http-walker.c | 2 +-\n http.c        | 6 +++---\n remote-curl.c | 4 ++--\n 4 files changed, 9 insertions(+), 9 deletions(-)\n\ndiff --git a/http-push.c b/http-push.c\nindex aa3de7c1086..3309aaf004a 100644\n--- a/http-push.c\n+++ b/http-push.c\n@@ -883,7 +883,7 @@ static struct remote_lock *lock_remote(const char *path, long timeout)\n \tslot->results = &results;\n \tcurl_setup_http(slot->curl, url, DAV_LOCK, &out_buffer, fwrite_buffer);\n \tcurl_easy_setopt(slot->curl, CURLOPT_HTTPHEADER, dav_headers);\n-\tcurl_easy_setopt(slot->curl, CURLOPT_FILE, &in_buffer);\n+\tcurl_easy_setopt(slot->curl, CURLOPT_WRITEDATA, &in_buffer);\n \n \tCALLOC_ARRAY(lock, 1);\n \tlock->timeout = -1;\n@@ -1142,7 +1142,7 @@ static void remote_ls(const char *path, int flags,\n \tcurl_setup_http(slot->curl, url, DAV_PROPFIND,\n \t\t\t&out_buffer, fwrite_buffer);\n \tcurl_easy_setopt(slot->curl, CURLOPT_HTTPHEADER, dav_headers);\n-\tcurl_easy_setopt(slot->curl, CURLOPT_FILE, &in_buffer);\n+\tcurl_easy_setopt(slot->curl, CURLOPT_WRITEDATA, &in_buffer);\n \n \tif (start_active_slot(slot)) {\n \t\trun_active_slot(slot);\n@@ -1216,7 +1216,7 @@ static int locking_available(void)\n \tcurl_setup_http(slot->curl, repo->url, DAV_PROPFIND,\n \t\t\t&out_buffer, fwrite_buffer);\n \tcurl_easy_setopt(slot->curl, CURLOPT_HTTPHEADER, dav_headers);\n-\tcurl_easy_setopt(slot->curl, CURLOPT_FILE, &in_buffer);\n+\tcurl_easy_setopt(slot->curl, CURLOPT_WRITEDATA, &in_buffer);\n \n \tif (start_active_slot(slot)) {\n \t\trun_active_slot(slot);\ndiff --git a/http-walker.c b/http-walker.c\nindex 19e31623f04..910fae539b8 100644\n--- a/http-walker.c\n+++ b/http-walker.c\n@@ -378,7 +378,7 @@ static void fetch_alternates(struct walker *walker, const char *base)\n \talt_req.walker = walker;\n \tslot->callback_data = &alt_req;\n \n-\tcurl_easy_setopt(slot->curl, CURLOPT_FILE, &buffer);\n+\tcurl_easy_setopt(slot->curl, CURLOPT_WRITEDATA, &buffer);\n \tcurl_easy_setopt(slot->curl, CURLOPT_WRITEFUNCTION, fwrite_buffer);\n \tcurl_easy_setopt(slot->curl, CURLOPT_URL, url.buf);\n \ndiff --git a/http.c b/http.c\nindex 477bf591141..56856178bfe 100644\n--- a/http.c\n+++ b/http.c\n@@ -1767,7 +1767,7 @@ static int http_request(const char *url,\n \t\tcurl_easy_setopt(slot->curl, CURLOPT_NOBODY, 1);\n \t} else {\n \t\tcurl_easy_setopt(slot->curl, CURLOPT_NOBODY, 0);\n-\t\tcurl_easy_setopt(slot->curl, CURLOPT_FILE, result);\n+\t\tcurl_easy_setopt(slot->curl, CURLOPT_WRITEDATA, result);\n \n \t\tif (target == HTTP_REQUEST_FILE) {\n \t\t\toff_t posn = ftello(result);\n@@ -2184,7 +2184,7 @@ struct http_pack_request *new_direct_http_pack_request(\n \t}\n \n \tpreq->slot = get_active_slot();\n-\tcurl_easy_setopt(preq->slot->curl, CURLOPT_FILE, preq->packfile);\n+\tcurl_easy_setopt(preq->slot->curl, CURLOPT_WRITEDATA, preq->packfile);\n \tcurl_easy_setopt(preq->slot->curl, CURLOPT_WRITEFUNCTION, fwrite);\n \tcurl_easy_setopt(preq->slot->curl, CURLOPT_URL, preq->url);\n \tcurl_easy_setopt(preq->slot->curl, CURLOPT_HTTPHEADER,\n@@ -2355,7 +2355,7 @@ struct http_object_request *new_http_object_request(const char *base_url,\n \n \tfreq->slot = get_active_slot();\n \n-\tcurl_easy_setopt(freq->slot->curl, CURLOPT_FILE, freq);\n+\tcurl_easy_setopt(freq->slot->curl, CURLOPT_WRITEDATA, freq);\n \tcurl_easy_setopt(freq->slot->curl, CURLOPT_FAILONERROR, 0);\n \tcurl_easy_setopt(freq->slot->curl, CURLOPT_WRITEFUNCTION, fwrite_sha1_file);\n \tcurl_easy_setopt(freq->slot->curl, CURLOPT_ERRORBUFFER, freq->errorstr);\ndiff --git a/remote-curl.c b/remote-curl.c\nindex 09f09aeece3..598cff7cde6 100644\n--- a/remote-curl.c\n+++ b/remote-curl.c\n@@ -853,7 +853,7 @@ static int probe_rpc(struct rpc_state *rpc, struct slot_results *results)\n \tcurl_easy_setopt(slot->curl, CURLOPT_POSTFIELDSIZE, 4);\n \tcurl_easy_setopt(slot->curl, CURLOPT_HTTPHEADER, headers);\n \tcurl_easy_setopt(slot->curl, CURLOPT_WRITEFUNCTION, fwrite_buffer);\n-\tcurl_easy_setopt(slot->curl, CURLOPT_FILE, &buf);\n+\tcurl_easy_setopt(slot->curl, CURLOPT_WRITEDATA, &buf);\n \n \terr = run_slot(slot, results);\n \n@@ -1016,7 +1016,7 @@ static int post_rpc(struct rpc_state *rpc, int stateless_connect, int flush_rece\n \trpc_in_data.slot = slot;\n \trpc_in_data.check_pktline = stateless_connect;\n \tmemset(&rpc_in_data.pktline_state, 0, sizeof(rpc_in_data.pktline_state));\n-\tcurl_easy_setopt(slot->curl, CURLOPT_FILE, &rpc_in_data);\n+\tcurl_easy_setopt(slot->curl, CURLOPT_WRITEDATA, &rpc_in_data);\n \tcurl_easy_setopt(slot->curl, CURLOPT_FAILONERROR, 0);\n \n \n-- \n2.32.0.1069.g516d52f3d85\n\n"},{"id":"431551","messageId":"patch-v3-7.7-93a2775d0ee-20210730T092843Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-v3-0.7-00000000000-20210730T092843Z-avarab@gmail.com","subject":"[PATCH v3 7/7] http: centralize the accounting of libcurl dependencies","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-07-30T09:31:59Z","receivedAt":"2021-07-30T09:35:29Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"As noted in preceding commits checking against LIBCURL_VERSION_NUM\nisn't as reliable as checking specific defines in curl, as some\ndistros have been known to backport features. Furthermore we had at\nleast one case of someone confusing base 10 for base 16 in comparing\nthe version.\n\nLet's add a git-curl-compat.h header that'll keep track of these\ndependencies, and make the next round of deprecations easier. This\npatch is mostly obvious, with the following exceptions:\n\n - In aeff8a61216 (http: implement public key pinning, 2016-02-15) a\n   dependency and warning() was added if curl older than 7.44.0 was\n   used, but the relevant code depended on CURLOPT_PINNEDPUBLICKEY,\n   introduced in 7.39.0.\n\n - We did not use CURL_SOCKOPT_OK and instead hardcoded its value in\n   a15d069a198 (http: enable keepalive on TCP sockets, 2013-10-12),\n   let's use it and guard its use by a new GITCURL_HAVE_* check.\n\n - We guarded the support for http.version with a check for curl\n   7.47.0, looking at the history of how that happen reveals that an\n   earlier on-list version of d73019feb44 (http: add support selecting\n   http version, 2018-11-08) depended on CURL_HTTP_VERSION_2TLS (which\n   was added in 7.47.0).\n\n   But the version this code depended on was in fact 7.43.0, since\n   that's when CURL_HTTP_VERSION_2_0 was added.\n\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n git-curl-compat.h | 119 ++++++++++++++++++++++++++++++++++++++++++++++\n http.c            |  41 ++++++++--------\n imap-send.c       |   6 +--\n 3 files changed, 143 insertions(+), 23 deletions(-)\n create mode 100644 git-curl-compat.h\n\ndiff --git a/git-curl-compat.h b/git-curl-compat.h\nnew file mode 100644\nindex 00000000000..554f244034e\n--- /dev/null\n+++ b/git-curl-compat.h\n@@ -0,0 +1,119 @@\n+#ifndef GIT_CURL_COMPAT_H\n+#define GIT_CURL_COMPAT_H\n+\n+/**\n+ * This header centralized the declaration of our libcurl dependencies\n+ * to make it easy to discover the oldest versions we support, and to\n+ * inform decisions about removing support for older libcurl in the\n+ * future.\n+ *\n+ * The source of truth for what versions have which symbols is\n+ * https://github.com/curl/curl/blob/master/docs/libcurl/symbols-in-versions;\n+ * the release dates are taken from curl.git (at\n+ * https://github.com/curl/curl/).\n+ *\n+ * For each X symbol we need from curl we check if it exists and\n+ * declare our own GIT_CURl_HAVE_X, or if it's for both X and Y\n+ * GIT_CURl_HAVE_X_and_Y, where the \"Y\" in \"X_and_Y\" is only the part\n+ * of the symbol name that \"X\" and \"Y\" don't have in common.\n+ *\n+ * We avoid comparisons against LIBCURL_VERSION_NUM, enterprise\n+ * distros have been known to backport symbols to their older curl\n+ * versions.\n+ *\n+ * Keep any symbols in date order of when their support was\n+ * introduced, oldest first.\n+ */\n+\n+/**\n+ * CURL_SOCKOPT_OK was added in 7.21.5, released in April 2011.\n+ */\n+#ifdef CURL_SOCKOPT_OK\n+#define GITCURL_HAVE_CURL_SOCKOPT_OK 1\n+#endif\n+\n+/**\n+ * CURLOPT_TCP_KEEPALIVE was added in 7.25.0, released in March 2012.\n+ */\n+#ifdef CURLOPT_TCP_KEEPALIVE\n+#define GITCURL_HAVE_CURLOPT_TCP_KEEPALIVE 1\n+#endif\n+\n+\n+/**\n+ * CURLOPT_LOGIN_OPTIONS was added in 7.34.0, released in December\n+ * 2013.\n+ */\n+#ifdef CURLOPT_LOGIN_OPTIONS\n+#define GIT_CURL_HAVE_CURLOPT_LOGIN_OPTIONS 1\n+#endif\n+\n+/**\n+ * CURL_SSLVERSION_TLSv1_[012] was added in 7.34.0, released in\n+ * December 2013.\n+ */\n+#if defined(CURL_SSLVERSION_TLSv1_0) && \\\n+    defined(CURL_SSLVERSION_TLSv1_1) && \\\n+    defined(CURL_SSLVERSION_TLSv1_2)\n+#define GIT_CURL_HAVE_CURL_SSLVERSION_TLSv1_0_and_1_and_2\n+#endif\n+\n+/**\n+ * CURLOPT_PINNEDPUBLICKEY was added in 7.39.0, released in November\n+ * 2014.\n+ */\n+#ifdef CURLOPT_PINNEDPUBLICKEY\n+#define GIT_CURL_HAVE_CURLOPT_PINNEDPUBLICKEY 1\n+#endif\n+\n+/**\n+ * CURL_HTTP_VERSION_2 was added in 7.43.0, released in June 2015.\n+ */\n+#ifdef CURL_HTTP_VERSION_2\n+#define GIT_CURL_HAVE_CURL_HTTP_VERSION_2 1\n+#endif\n+\n+/**\n+ * CURLSSLOPT_NO_REVOKE was added in 7.44.0, released in August 2015.\n+ */\n+#ifdef CURLSSLOPT_NO_REVOKE\n+#define GIT_CURL_HAVE_CURLSSLOPT_NO_REVOKE 1\n+#endif\n+\n+/**\n+ * CURLOPT_PROXY_CAINFO was added in 7.52.0, released in August 2017.\n+ */\n+#ifdef CURLOPT_PROXY_CAINFO\n+#define GIT_CURL_HAVE_CURLOPT_PROXY_CAINFO 1\n+#endif\n+\n+/**\n+ * CURLOPT_PROXY_{KEYPASSWD,SSLCERT,SSLKEY} was added in 7.52.0,\n+ * released in August 2017.\n+ */\n+#if defined(CURLOPT_PROXY_KEYPASSWD) && \\\n+    defined(CURLOPT_PROXY_SSLCERT) && \\\n+    defined(CURLOPT_PROXY_SSLKEY)\n+#define GIT_CURL_HAVE_CURLOPT_PROXY_KEYPASSWD_and_SSLCERT_and_SSLKEY 1\n+#endif\n+\n+/**\n+ * CURL_SSLVERSION_TLSv1_3 was added in 7.53.0, released in February\n+ * 2017.\n+ */\n+#ifdef CURL_SSLVERSION_TLSv1_3\n+#define GIT_CURL_HAVE_CURL_SSLVERSION_TLSv1_3 1\n+#endif\n+\n+/**\n+ * CURLSSLSET_{NO_BACKENDS,OK,TOO_LATE,UNKNOWN_BACKEND} were added in\n+ * 7.56.0, released in September 2017.\n+ */\n+#if defined(CURLSSLSET_NO_BACKENDS) && \\\n+    defined(CURLSSLSET_OK) && \\\n+    defined(CURLSSLSET_TOO_LATE) && \\\n+    defined(CURLSSLSET_UNKNOWN_BACKEND)\n+#define GIT_CURL_HAVE_CURLSSLSET_NO_BACKENDS_and_OK_and_TOO_LATE_and_UNKNOWN_BACKEND 1\n+#endif\n+\n+#endif\ndiff --git a/http.c b/http.c\nindex 56856178bfe..e8939a1ccf6 100644\n--- a/http.c\n+++ b/http.c\n@@ -1,4 +1,5 @@\n #include \"git-compat-util.h\"\n+#include \"git-curl-compat.h\"\n #include \"http.h\"\n #include \"config.h\"\n #include \"pack.h\"\n@@ -47,21 +48,19 @@ static struct {\n \t{ \"sslv2\", CURL_SSLVERSION_SSLv2 },\n \t{ \"sslv3\", CURL_SSLVERSION_SSLv3 },\n \t{ \"tlsv1\", CURL_SSLVERSION_TLSv1 },\n-#if LIBCURL_VERSION_NUM >= 0x072200\n+#if GIT_CURL_HAVE_CURL_SSLVERSION_TLSv1_0_AND_1_AND_2\n \t{ \"tlsv1.0\", CURL_SSLVERSION_TLSv1_0 },\n \t{ \"tlsv1.1\", CURL_SSLVERSION_TLSv1_1 },\n \t{ \"tlsv1.2\", CURL_SSLVERSION_TLSv1_2 },\n #endif\n-#if LIBCURL_VERSION_NUM >= 0x073400\n+#if GIT_CURL_HAVE_CURL_SSLVERSION_TLSv1_3\n \t{ \"tlsv1.3\", CURL_SSLVERSION_TLSv1_3 },\n #endif\n };\n static const char *ssl_key;\n static const char *ssl_capath;\n static const char *curl_no_proxy;\n-#if LIBCURL_VERSION_NUM >= 0x072c00\n static const char *ssl_pinnedkey;\n-#endif\n static const char *ssl_cainfo;\n static long curl_low_speed_limit = -1;\n static long curl_low_speed_time = -1;\n@@ -373,12 +372,10 @@ static int http_options(const char *var, const char *value, void *cb)\n \t}\n \n \tif (!strcmp(\"http.pinnedpubkey\", var)) {\n-#if LIBCURL_VERSION_NUM >= 0x072c00\n-\t\treturn git_config_pathname(&ssl_pinnedkey, var, value);\n-#else\n-\t\twarning(_(\"Public key pinning not supported with cURL < 7.44.0\"));\n-\t\treturn 0;\n+#ifndef GIT_CURL_HAVE_CURLOPT_PINNEDPUBLICKEY\n+\t\twarning(_(\"Public key pinning not supported with cURL < 7.39.0\"));\n #endif\n+\t\treturn git_config_pathname(&ssl_pinnedkey, var, value);\n \t}\n \n \tif (!strcmp(\"http.extraheader\", var)) {\n@@ -500,7 +497,7 @@ static int has_cert_password(void)\n \treturn 1;\n }\n \n-#if LIBCURL_VERSION_NUM >= 0x073400\n+#ifdef GIT_CURL_HAVE_CURLOPT_PROXY_KEYPASSWD_and_SSLCERT_and_SSLKEY\n static int has_proxy_cert_password(void)\n {\n \tif (http_proxy_ssl_cert == NULL || proxy_ssl_cert_password_required != 1)\n@@ -516,7 +513,7 @@ static int has_proxy_cert_password(void)\n }\n #endif\n \n-#if LIBCURL_VERSION_NUM >= 0x071900\n+#ifdef GITCURL_HAVE_CURLOPT_TCP_KEEPALIVE\n static void set_curl_keepalive(CURL *c)\n {\n \tcurl_easy_setopt(c, CURLOPT_TCP_KEEPALIVE, 1);\n@@ -536,7 +533,11 @@ static int sockopt_callback(void *client, curl_socket_t fd, curlsocktype type)\n \tif (rc < 0)\n \t\twarning_errno(\"unable to set SO_KEEPALIVE on socket\");\n \n-\treturn 0; /* CURL_SOCKOPT_OK only exists since curl 7.21.5 */\n+#ifdef GITCURL_HAVE_CURL_SOCKOPT_OK\n+\treturn CURL_SOCKOPT_OK;\n+#else\n+\treturn 0;\n+#endif\n }\n \n static void set_curl_keepalive(CURL *c)\n@@ -732,7 +733,7 @@ static long get_curl_allowed_protocols(int from_user)\n \treturn allowed_protocols;\n }\n \n-#if LIBCURL_VERSION_NUM >=0x072f00\n+#ifdef GIT_CURL_HAVE_CURL_HTTP_VERSION_2\n static int get_curl_http_version_opt(const char *version_string, long *opt)\n {\n \tint i;\n@@ -774,7 +775,7 @@ static CURL *get_curl_handle(void)\n \t\tcurl_easy_setopt(result, CURLOPT_SSL_VERIFYHOST, 2);\n \t}\n \n-#if LIBCURL_VERSION_NUM >= 0x072f00 // 7.47.0\n+#ifdef GIT_CURL_HAVE_CURL_HTTP_VERSION_2\n     if (curl_http_version) {\n \t\tlong opt;\n \t\tif (!get_curl_http_version_opt(curl_http_version, &opt)) {\n@@ -805,7 +806,7 @@ static CURL *get_curl_handle(void)\n \n \tif (http_ssl_backend && !strcmp(\"schannel\", http_ssl_backend) &&\n \t    !http_schannel_check_revoke) {\n-#if LIBCURL_VERSION_NUM >= 0x072c00\n+#ifdef GIT_CURL_HAVE_CURLSSLOPT_NO_REVOKE\n \t\tcurl_easy_setopt(result, CURLOPT_SSL_OPTIONS, CURLSSLOPT_NO_REVOKE);\n #else\n \t\twarning(_(\"CURLSSLOPT_NO_REVOKE not supported with cURL < 7.44.0\"));\n@@ -845,20 +846,20 @@ static CURL *get_curl_handle(void)\n \t\tcurl_easy_setopt(result, CURLOPT_SSLKEY, ssl_key);\n \tif (ssl_capath != NULL)\n \t\tcurl_easy_setopt(result, CURLOPT_CAPATH, ssl_capath);\n-#if LIBCURL_VERSION_NUM >= 0x072c00\n+#ifdef GIT_CURL_HAVE_CURLOPT_PINNEDPUBLICKEY\n \tif (ssl_pinnedkey != NULL)\n \t\tcurl_easy_setopt(result, CURLOPT_PINNEDPUBLICKEY, ssl_pinnedkey);\n #endif\n \tif (http_ssl_backend && !strcmp(\"schannel\", http_ssl_backend) &&\n \t    !http_schannel_use_ssl_cainfo) {\n \t\tcurl_easy_setopt(result, CURLOPT_CAINFO, NULL);\n-#if LIBCURL_VERSION_NUM >= 0x073400\n+#ifdef GIT_CURL_HAVE_CURLOPT_PROXY_CAINFO\n \t\tcurl_easy_setopt(result, CURLOPT_PROXY_CAINFO, NULL);\n #endif\n \t} else if (ssl_cainfo != NULL || http_proxy_ssl_ca_info != NULL) {\n \t\tif (ssl_cainfo != NULL)\n \t\t\tcurl_easy_setopt(result, CURLOPT_CAINFO, ssl_cainfo);\n-#if LIBCURL_VERSION_NUM >= 0x073400\n+#ifdef GIT_CURL_HAVE_CURLOPT_PROXY_CAINFO\n \t\tif (http_proxy_ssl_ca_info != NULL)\n \t\t\tcurl_easy_setopt(result, CURLOPT_PROXY_CAINFO, http_proxy_ssl_ca_info);\n #endif\n@@ -939,7 +940,7 @@ static CURL *get_curl_handle(void)\n \t\telse if (starts_with(curl_http_proxy, \"socks\"))\n \t\t\tcurl_easy_setopt(result,\n \t\t\t\tCURLOPT_PROXYTYPE, CURLPROXY_SOCKS4);\n-#if LIBCURL_VERSION_NUM >= 0x073400\n+#ifdef GIT_CURL_HAVE_CURLOPT_PROXY_KEYPASSWD_and_SSLCERT_and_SSLKEY\n \t\telse if (starts_with(curl_http_proxy, \"https\")) {\n \t\t\tcurl_easy_setopt(result, CURLOPT_PROXYTYPE, CURLPROXY_HTTPS);\n \n@@ -1004,7 +1005,7 @@ void http_init(struct remote *remote, const char *url, int proactive_auth)\n \tfree(normalized_url);\n \tstring_list_clear(&config.vars, 1);\n \n-#if LIBCURL_VERSION_NUM >= 0x073800\n+#ifdef GIT_CURL_HAVE_CURLSSLSET_NO_BACKENDS_and_OK_and_TOO_LATE_and_UNKNOWN_BACKEND\n \tif (http_ssl_backend) {\n \t\tconst curl_ssl_backend **backends;\n \t\tstruct strbuf buf = STRBUF_INIT;\ndiff --git a/imap-send.c b/imap-send.c\nindex 49a5f8aa597..2da96a9532f 100644\n--- a/imap-send.c\n+++ b/imap-send.c\n@@ -1441,14 +1441,14 @@ static CURL *setup_curl(struct imap_server_conf *srvc, struct credential *cred)\n \tcurl_easy_setopt(curl, CURLOPT_PORT, server.port);\n \n \tif (server.auth_method) {\n-#if LIBCURL_VERSION_NUM < 0x072200\n-\t\twarning(\"No LOGIN_OPTIONS support in this cURL version\");\n-#else\n+#ifdef GIT_CURL_HAVE_CURLOPT_LOGIN_OPTIONS\n \t\tstruct strbuf auth = STRBUF_INIT;\n \t\tstrbuf_addstr(&auth, \"AUTH=\");\n \t\tstrbuf_addstr(&auth, server.auth_method);\n \t\tcurl_easy_setopt(curl, CURLOPT_LOGIN_OPTIONS, auth.buf);\n \t\tstrbuf_release(&auth);\n+#else\n+\t\twarning(\"No LOGIN_OPTIONS support in this cURL version\");\n #endif\n \t}\n \n-- \n2.32.0.1069.g516d52f3d85\n\n"},{"id":"431583","messageId":"xmqq8s1n3hdk.fsf@gitster.g","threadId":"46547","inReplyTo":"patch-v3-4.7-230b968382f-20210730T092843Z-avarab@gmail.com","subject":"Re: [PATCH v3 4/7] http: drop support for curl < 7.19.3 and <= 7.16.4 (or <7.17.0) (again)","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2021-07-30T16:18:15Z","receivedAt":"2021-07-30T16:18:30Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Ævar Arnfjörð Bjarmason  <avarab@gmail.com> writes:\n\n> Remove the conditional use of CURLAUTH_DIGEST_IE and\n> CURLOPT_USE_SSL. These two have been split from earlier simpler checks\n> against LIBCURL_VERSION_NUM for ease of review.\n>\n> The CURLAUTH_DIGEST_IE flag was added in 7.19.3[1], and\n> CURLOPT_USE_SSL in 7.16.4[2] or 7.17.0[3], depending on the source. As\n> noted in [2] it was then renamed around that time from the older\n> CURLOPT_FTP_SSL.\n>\n> 1. https://curl.se/libcurl/c/CURLOPT_HTTPAUTH.html\n> 2. https://curl.se/libcurl/c/CURLOPT_USE_SSL.html\n> 3. https://github.com/curl/curl/blob/master/docs/libcurl/symbols-in-versions\n\nI still think \"depending on the source\" is wronge.  Let's read #2\n(whose copy we also have in our comment) again:\n\n    This option was known as CURLOPT_FTP_SSL up to 7.16.4, and the\n    constants were known as CURLFTPSSL_*\n\nA program that uses the CURLOPT_USE_SSL symbol would have failed to\ncompile with 7.16.4, as that version and older ones, even they had\nthe feature itself, did not use CUROPT_USE_SSL to invoke the\nfeature.  That is how I read the above sentence.\n\nPerhaps everything after the first paragraph can be like this instead?\n\n    The CURLAUTH_DIGEST_IE flag was added in 7.19.3 and\n    CURLOPT_USE_SSL in 7.17.0.\n    (cf. https://github.com/curl/curl/blob/master/docs/libcurl/symbols-in-versions)\n\nThe patch text looks good to me.\n\nThanks.\n"},{"id":"431584","messageId":"xmqq4kcb3h6n.fsf@gitster.g","threadId":"46547","inReplyTo":"patch-v3-5.7-b857a9ef7b1-20210730T092843Z-avarab@gmail.com","subject":"Re: [PATCH v3 5/7] http: drop support for curl < 7.18.0 (again)","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2021-07-30T16:22:24Z","receivedAt":"2021-07-30T16:22:28Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Ævar Arnfjörð Bjarmason  <avarab@gmail.com> writes:\n\n> In a preceding commit we dropped support for curl < 7.19.4, so we can\n> drop support for this non-obvious dependency on curl < 7.18.0.\n>\n> It's non-obvious because in curl's hex version notation 0x071800 is\n> version 7.24.0, *not* 7.18.0, so at a glance this patch looks\n> incorrect.\n>\n> But it's correct, because the existing version check being removed\n> here is wrong. The check guards use of the following curl defines:\n>\n>     CURLPROXY_SOCKS4                7.10\n>     CURLPROXY_SOCKS4A               7.18.0\n>     CURLPROXY_SOCKS5                7.10\n>     CURLPROXY_SOCKS5_HOSTNAME       7.18.0\n>\n> I.e. the oldest version that has these is in fact 7.18.0, not\n> 7.24.0. That we were checking 7.24.0 is just an mistake in\n> 6d7afe07f29 (remote-http(s): support SOCKS proxies, 2015-10-26),\n> i.e. its author confusing base 10 and base 16.\n\nHeh, not just the author but everybody who reviewed it may have been\nconfused that the version number string was binary coded decimal.\n\nNicely found.\n\n> Signed-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n> ---\n>  http.c | 2 --\n>  1 file changed, 2 deletions(-)\n>\n> diff --git a/http.c b/http.c\n> index e9446850a62..477bf591141 100644\n> --- a/http.c\n> +++ b/http.c\n> @@ -927,7 +927,6 @@ static CURL *get_curl_handle(void)\n>  \t\t */\n>  \t\tcurl_easy_setopt(result, CURLOPT_PROXY, \"\");\n>  \t} else if (curl_http_proxy) {\n> -#if LIBCURL_VERSION_NUM >= 0x071800\n>  \t\tif (starts_with(curl_http_proxy, \"socks5h\"))\n>  \t\t\tcurl_easy_setopt(result,\n>  \t\t\t\tCURLOPT_PROXYTYPE, CURLPROXY_SOCKS5_HOSTNAME);\n> @@ -940,7 +939,6 @@ static CURL *get_curl_handle(void)\n>  \t\telse if (starts_with(curl_http_proxy, \"socks\"))\n>  \t\t\tcurl_easy_setopt(result,\n>  \t\t\t\tCURLOPT_PROXYTYPE, CURLPROXY_SOCKS4);\n> -#endif\n>  #if LIBCURL_VERSION_NUM >= 0x073400\n>  \t\telse if (starts_with(curl_http_proxy, \"https\")) {\n>  \t\t\tcurl_easy_setopt(result, CURLOPT_PROXYTYPE, CURLPROXY_HTTPS);\n"},{"id":"431587","messageId":"xmqqwnp721gj.fsf@gitster.g","threadId":"46547","inReplyTo":"patch-v3-7.7-93a2775d0ee-20210730T092843Z-avarab@gmail.com","subject":"Re: [PATCH v3 7/7] http: centralize the accounting of libcurl dependencies","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2021-07-30T16:47:24Z","receivedAt":"2021-07-30T16:47:31Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Ævar Arnfjörð Bjarmason  <avarab@gmail.com> writes:\n\n> As noted in preceding commits checking against LIBCURL_VERSION_NUM\n> isn't as reliable as checking specific defines in curl, as some\n> distros have been known to backport features. Furthermore we had at\n> least one case of someone confusing base 10 for base 16 in comparing\n> the version.\n>\n> Let's add a git-curl-compat.h header that'll keep track of these\n> dependencies, and make the next round of deprecations easier. This\n> patch is mostly obvious, with the following exceptions:\n>\n>  - In aeff8a61216 (http: implement public key pinning, 2016-02-15) a\n>    dependency and warning() was added if curl older than 7.44.0 was\n>    used, but the relevant code depended on CURLOPT_PINNEDPUBLICKEY,\n>    introduced in 7.39.0.\n\nI'd feel safe with this change iff we positively know that the\nreason why the warning message and version guard back then said\n7.44.0 instead of 7.39.0 was not because the symbol was there but\nthe feature was broken between these two versions, and the feature\nbecame usable/reliable only after 7.44.0.  I do not recall the\nreview discussion around that commit offhand and somebody needs to\ndig the archive.\n\n>  - We did not use CURL_SOCKOPT_OK and instead hardcoded its value in\n>    a15d069a198 (http: enable keepalive on TCP sockets, 2013-10-12),\n>    let's use it and guard its use by a new GITCURL_HAVE_* check.\n\nI agree with the spirit, but find the execution iffy.  I may find it\ncleaner to hide all the version dependent details in curl-compat.h\nand to define CURL_SOCKOPT_OK to 0 there, iff the symbol is missing.\n\nThat way, the use sites can unconditionally use CURL_SOCKOPT_OK, no?\n\n>  - We guarded the support for http.version with a check for curl\n>    7.47.0, looking at the history of how that happen reveals that an\n>    earlier on-list version of d73019feb44 (http: add support selecting\n>    http version, 2018-11-08) depended on CURL_HTTP_VERSION_2TLS (which\n>    was added in 7.47.0).\n>\n>    But the version this code depended on was in fact 7.43.0, since\n>    that's when CURL_HTTP_VERSION_2_0 was added.\n\nOK.\n\n> +#ifndef GIT_CURL_COMPAT_H\n> +#define GIT_CURL_COMPAT_H\n> +\n> +/**\n> + * This header centralized the declaration of our libcurl dependencies\n\n-lizes, not -lized, no?\n\n> + * to make it easy to discover the oldest versions we support, and to\n> + * inform decisions about removing support for older libcurl in the\n> + * future.\n> + *\n> + * The source of truth for what versions have which symbols is\n> + * https://github.com/curl/curl/blob/master/docs/libcurl/symbols-in-versions;\n> + * the release dates are taken from curl.git (at\n> + * https://github.com/curl/curl/).\n> + *\n> + * For each X symbol we need from curl we check if it exists and\n> + * declare our own GIT_CURl_HAVE_X, or if it's for both X and Y\n> + * GIT_CURl_HAVE_X_and_Y, where the \"Y\" in \"X_and_Y\" is only the part\n\nGIT_CURL, not GIT_CURl, no?\n\n> + * of the symbol name that \"X\" and \"Y\" don't have in common.\n> + *\n> + * We avoid comparisons against LIBCURL_VERSION_NUM, enterprise\n> + * distros have been known to backport symbols to their older curl\n> + * versions.\n> + *\n> + * Keep any symbols in date order of when their support was\n> + * introduced, oldest first.\n\nThe above two paragraphs are somewhat at odds.  Perhaps with \"...,\noldest first, in the official version of cURL library\", it becomes a\nnon-issue, though.\n\n\nThe approach may mostly be sensible, but as I said, it is overkill\nfor things like this one:\n\n[in curl-compat.h]\n> +/**\n> + * CURL_SOCKOPT_OK was added in 7.21.5, released in April 2011.\n> + */\n> +#ifdef CURL_SOCKOPT_OK\n> +#define GITCURL_HAVE_CURL_SOCKOPT_OK 1\n> +#endif\n\n[in code]\n>  \tif (rc < 0)\n>  \t\twarning_errno(\"unable to set SO_KEEPALIVE on socket\");\n>  \n> -\treturn 0; /* CURL_SOCKOPT_OK only exists since curl 7.21.5 */\n> +#ifdef GITCURL_HAVE_CURL_SOCKOPT_OK\n> +\treturn CURL_SOCKOPT_OK;\n> +#else\n> +\treturn 0;\n> +#endif\n>  }\n\nIt would be far simpler and cleaner to do this instead only in\ncurl-compat.h, no?\n\n    #ifndef CURL_SOCKOPT_OK\n    #define CURL_SOCKOPT_OK 0\n    #endif\n\nWhen we drop support for versions that do not have symbol X, the\nheader must change (you'd probably remove the entry with the comment\nfor the symbol X), but there is no need to touch all the code that\nuses GITCURL_HAVE_X for a symbol like this one.\n\nAgain, of course, not all symbols and the way we conditionally\ncompile things are like this simple, and GITCURL_HAVE_* approach\nmay have merit at those places, but definitely not here.\n\nI really wish that you did not succumb to the temptation of feature\ncreep while going from v2 to v3.  With this close to the preview\nrelease, what we want is not a topic that covers more, but a topic\nthat corrects issues that have been identified in it and can be\nmerged down for the next release before -rc1.\n\nThanks.\n"},{"id":"431591","messageId":"cover-v4-0.5-00000000000-20210730T175650Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-v3-0.7-00000000000-20210730T092843Z-avarab@gmail.com","subject":"[PATCH v4 0/5] drop support for ancient curl","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-07-30T17:59:41Z","receivedAt":"2021-07-30T17:59:52Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"Per the feature creep feedback on v3 this v4 ejects the two new\nchanges new in v3. The below range-diff is against v2, not v3.\n\nI dug into the 7.16.4 v.s. 7.17.0 documentation issue and found that\nit's bug in curl's docs, for which I submitted a patch.\n\nI considered keeping\n<patch-v3-5.7-b857a9ef7b1-20210730T092843Z-avarab@gmail.com>, but\nsequencing it in made the range diff quite a bit larger, so per the\nfeature creep feedback I ejected it too. Junio: Perhaps you'd like to\ncherry-pick it on top too, or it can be dug up post-release.\n\nJeff King (3):\n  http: drop support for curl < 7.11.1\n  http: drop support for curl < 7.16.0\n  http: drop support for curl < 7.19.4\n\nÆvar Arnfjörð Bjarmason (2):\n  http: drop support for curl < 7.19.3 and < 7.17.0 (again)\n  http: rename CURLOPT_FILE to CURLOPT_WRITEDATA\n\n http-push.c   |  29 +--------\n http-walker.c |  14 +----\n http.c        | 169 ++------------------------------------------------\n http.h        |  46 --------------\n imap-send.c   |   4 --\n remote-curl.c |  11 +---\n 6 files changed, 10 insertions(+), 263 deletions(-)\n\nRange-diff against v1:\n1:  dcbb6f95652 ! 1:  6bd41764a54 http: drop support for curl < 7.11.1\n    @@ Commit message\n         Drop support for this ancient version of curl and simplify the code by\n         allowing us get rid of some \"#ifdef\"'s.\n     \n    -    Git will not build with vanilla curl older than 7.11.1 due to (at\n    -    least) two issues:\n    -\n    -      - our use of CURLOPT_POSTFIELDSIZE in 37ee680d9b\n    -        (http.postbuffer: allow full range of ssize_t values,\n    -        2017-04-11). This field was introduced in curl 7.11.1.\n    -\n    -      - our use of CURLPROTO_* outside any #ifdef in aeae4db174\n    -        (http: create function to get curl allowed protocols,\n    -        2016-12-14). These were introduced in curl 7.19.4.\n    +    Git will not build with vanilla curl older than 7.11.1 due our use of\n    +    CURLOPT_POSTFIELDSIZE in 37ee680d9b\n    +    (http.postbuffer: allow full range of ssize_t values,\n    +    2017-04-11). This field was introduced in curl 7.11.1.\n     \n         We could solve these compilation problems with more #ifdefs,\n         but it's not worth the trouble. Version 7.11.1 came out in\n    -    March of 2004, over 13 years ago. Let's declare that too old\n    +    March of 2004, over 17 years ago. Let's declare that too old\n         and drop any existing ifdefs that go further back. One\n         obvious benefit is that we'll have fewer conditional bits\n         cluttering the code.\n2:  1c9f3bc031b = 2:  fb308258e2b http: drop support for curl < 7.16.0\n3:  faae88b7fec ! 3:  fba5560a3ba http: drop support for curl < 7.19.4\n    @@ Commit message\n         http: drop support for curl < 7.19.4\n     \n         In the last commit we dropped support for curl < 7.16.0, let's\n    -    continue that and drop support for versions older than 7.19.4. This\n    +    continue that and drop support for versions older than 7.19.3. This\n         allows us to simplify the code by getting rid of some \"#ifdef\"'s.\n     \n         Git was broken with vanilla curl < 7.19.4 from v2.12.0 until\n4:  9a30e92520c ! 4:  42d1c72ff7e http: drop support for curl < 7.19.3 and < 7.16.4 (again)\n    @@ Metadata\n     Author: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n     \n      ## Commit message ##\n    -    http: drop support for curl < 7.19.3 and < 7.16.4 (again)\n    +    http: drop support for curl < 7.19.3 and < 7.17.0 (again)\n     \n         Remove the conditional use of CURLAUTH_DIGEST_IE and\n         CURLOPT_USE_SSL. These two have been split from earlier simpler checks\n         against LIBCURL_VERSION_NUM for ease of review.\n     \n         The CURLAUTH_DIGEST_IE flag was added in n 7.19.3[1], and\n    -    CURLOPT_USE_SSL in 7.16.4[2], as noted in [2] it was then renamed from\n    -    the older CURLOPT_FTP_SSL.\n    +    CURLOPT_USE_SSL in 7.17.0[2][3], as noted in [2] it was then renamed\n    +    from the older CURLOPT_FTP_SSL.\n    +\n    +    The documentation[2] currently claims that it was introduced in\n    +    7.16.4, but the symbols-in-versions file correctly states\n    +    7.17.0[3].\n    +\n    +    I've submitted an upstream\n    +    patch (<patch-1.1-953bab490-20210730T170510Z-avarab@gmail.com>) to the\n    +    curl-library mailing list fix the documentation.\n     \n         1. https://curl.se/libcurl/c/CURLOPT_HTTPAUTH.html\n         2. https://curl.se/libcurl/c/CURLOPT_USE_SSL.html\n    +    3. https://github.com/curl/curl/blob/master/docs/libcurl/symbols-in-versions\n     \n         Signed-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n     \n5:  64e510b4a6b = 5:  e34ab1d1f65 http: rename CURLOPT_FILE to CURLOPT_WRITEDATA\n-- \n2.32.0.1071.g36f34456314\n\n"},{"id":"431592","messageId":"patch-v4-1.5-6bd41764a54-20210730T175650Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-v4-0.5-00000000000-20210730T175650Z-avarab@gmail.com","subject":"[PATCH v4 1/5] http: drop support for curl < 7.11.1","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-07-30T17:59:42Z","receivedAt":"2021-07-30T17:59:58Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"From: Jeff King <peff@peff.net>\n\nDrop support for this ancient version of curl and simplify the code by\nallowing us get rid of some \"#ifdef\"'s.\n\nGit will not build with vanilla curl older than 7.11.1 due our use of\nCURLOPT_POSTFIELDSIZE in 37ee680d9b\n(http.postbuffer: allow full range of ssize_t values,\n2017-04-11). This field was introduced in curl 7.11.1.\n\nWe could solve these compilation problems with more #ifdefs,\nbut it's not worth the trouble. Version 7.11.1 came out in\nMarch of 2004, over 17 years ago. Let's declare that too old\nand drop any existing ifdefs that go further back. One\nobvious benefit is that we'll have fewer conditional bits\ncluttering the code.\n\nThis patch drops all #ifdefs that reference older versions\n(note that curl's preprocessor macros are in hex, so we're\nlooking for 070b01, not 071101).\n\nSigned-off-by: Jeff King <peff@peff.net>\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n http.c        | 53 ---------------------------------------------------\n http.h        | 12 +-----------\n remote-curl.c |  3 ---\n 3 files changed, 1 insertion(+), 67 deletions(-)\n\ndiff --git a/http.c b/http.c\nindex 8119247149a..56182a89e25 100644\n--- a/http.c\n+++ b/http.c\n@@ -19,19 +19,11 @@\n static struct trace_key trace_curl = TRACE_KEY_INIT(CURL);\n static int trace_curl_data = 1;\n static int trace_curl_redact = 1;\n-#if LIBCURL_VERSION_NUM >= 0x070a08\n long int git_curl_ipresolve = CURL_IPRESOLVE_WHATEVER;\n-#else\n-long int git_curl_ipresolve;\n-#endif\n int active_requests;\n int http_is_verbose;\n ssize_t http_post_buffer = 16 * LARGE_PACKET_MAX;\n \n-#if LIBCURL_VERSION_NUM >= 0x070a06\n-#define LIBCURL_CAN_HANDLE_AUTH_ANY\n-#endif\n-\n static int min_curl_sessions = 1;\n static int curl_session_count;\n #ifdef USE_CURL_MULTI\n@@ -68,15 +60,9 @@ static struct {\n \t{ \"tlsv1.3\", CURL_SSLVERSION_TLSv1_3 },\n #endif\n };\n-#if LIBCURL_VERSION_NUM >= 0x070903\n static const char *ssl_key;\n-#endif\n-#if LIBCURL_VERSION_NUM >= 0x070908\n static const char *ssl_capath;\n-#endif\n-#if LIBCURL_VERSION_NUM >= 0x071304\n static const char *curl_no_proxy;\n-#endif\n #if LIBCURL_VERSION_NUM >= 0x072c00\n static const char *ssl_pinnedkey;\n #endif\n@@ -101,9 +87,7 @@ static struct {\n \t{ \"digest\", CURLAUTH_DIGEST },\n \t{ \"negotiate\", CURLAUTH_GSSNEGOTIATE },\n \t{ \"ntlm\", CURLAUTH_NTLM },\n-#ifdef LIBCURL_CAN_HANDLE_AUTH_ANY\n \t{ \"anyauth\", CURLAUTH_ANY },\n-#endif\n \t/*\n \t * CURLAUTH_DIGEST_IE has no corresponding command-line option in\n \t * curl(1) and is not included in CURLAUTH_ANY, so we leave it out\n@@ -143,7 +127,6 @@ enum http_follow_config http_follow_config = HTTP_FOLLOW_INITIAL;\n \n static struct credential cert_auth = CREDENTIAL_INIT;\n static int ssl_cert_password_required;\n-#ifdef LIBCURL_CAN_HANDLE_AUTH_ANY\n static unsigned long http_auth_methods = CURLAUTH_ANY;\n static int http_auth_methods_restricted;\n /* Modes for which empty_auth cannot actually help us. */\n@@ -153,7 +136,6 @@ static unsigned long empty_auth_useless =\n \t| CURLAUTH_DIGEST_IE\n #endif\n \t| CURLAUTH_DIGEST;\n-#endif\n \n static struct curl_slist *pragma_header;\n static struct curl_slist *no_pragma_header;\n@@ -237,12 +219,8 @@ static void finish_active_slot(struct active_request_slot *slot)\n \tif (slot->results != NULL) {\n \t\tslot->results->curl_result = slot->curl_result;\n \t\tslot->results->http_code = slot->http_code;\n-#if LIBCURL_VERSION_NUM >= 0x070a08\n \t\tcurl_easy_getinfo(slot->curl, CURLINFO_HTTPAUTH_AVAIL,\n \t\t\t\t  &slot->results->auth_avail);\n-#else\n-\t\tslot->results->auth_avail = 0;\n-#endif\n \n \t\tcurl_easy_getinfo(slot->curl, CURLINFO_HTTP_CONNECTCODE,\n \t\t\t&slot->results->http_connectcode);\n@@ -305,14 +283,10 @@ static int http_options(const char *var, const char *value, void *cb)\n \t\treturn git_config_string(&ssl_version, var, value);\n \tif (!strcmp(\"http.sslcert\", var))\n \t\treturn git_config_pathname(&ssl_cert, var, value);\n-#if LIBCURL_VERSION_NUM >= 0x070903\n \tif (!strcmp(\"http.sslkey\", var))\n \t\treturn git_config_pathname(&ssl_key, var, value);\n-#endif\n-#if LIBCURL_VERSION_NUM >= 0x070908\n \tif (!strcmp(\"http.sslcapath\", var))\n \t\treturn git_config_pathname(&ssl_capath, var, value);\n-#endif\n \tif (!strcmp(\"http.sslcainfo\", var))\n \t\treturn git_config_pathname(&ssl_cainfo, var, value);\n \tif (!strcmp(\"http.sslcertpasswordprotected\", var)) {\n@@ -461,12 +435,6 @@ static int curl_empty_auth_enabled(void)\n \tif (curl_empty_auth >= 0)\n \t\treturn curl_empty_auth;\n \n-#ifndef LIBCURL_CAN_HANDLE_AUTH_ANY\n-\t/*\n-\t * Our libcurl is too old to do AUTH_ANY in the first place;\n-\t * just default to turning the feature off.\n-\t */\n-#else\n \t/*\n \t * In the automatic case, kick in the empty-auth\n \t * hack as long as we would potentially try some\n@@ -479,7 +447,6 @@ static int curl_empty_auth_enabled(void)\n \tif (http_auth_methods_restricted &&\n \t    (http_auth_methods & ~empty_auth_useless))\n \t\treturn 1;\n-#endif\n \treturn 0;\n }\n \n@@ -552,7 +519,6 @@ static void init_curl_proxy_auth(CURL *result)\n \n \tvar_override(&http_proxy_authmethod, getenv(\"GIT_HTTP_PROXY_AUTHMETHOD\"));\n \n-#if LIBCURL_VERSION_NUM >= 0x070a07 /* CURLOPT_PROXYAUTH and CURLAUTH_ANY */\n \tif (http_proxy_authmethod) {\n \t\tint i;\n \t\tfor (i = 0; i < ARRAY_SIZE(proxy_authmethods); i++) {\n@@ -570,7 +536,6 @@ static void init_curl_proxy_auth(CURL *result)\n \t}\n \telse\n \t\tcurl_easy_setopt(result, CURLOPT_PROXYAUTH, CURLAUTH_ANY);\n-#endif\n }\n \n static int has_cert_password(void)\n@@ -879,12 +844,8 @@ static CURL *get_curl_handle(void)\n     }\n #endif\n \n-#if LIBCURL_VERSION_NUM >= 0x070907\n \tcurl_easy_setopt(result, CURLOPT_NETRC, CURL_NETRC_OPTIONAL);\n-#endif\n-#ifdef LIBCURL_CAN_HANDLE_AUTH_ANY\n \tcurl_easy_setopt(result, CURLOPT_HTTPAUTH, CURLAUTH_ANY);\n-#endif\n \n #ifdef CURLGSSAPI_DELEGATION_FLAG\n \tif (curl_deleg) {\n@@ -940,14 +901,10 @@ static CURL *get_curl_handle(void)\n \t\tcurl_easy_setopt(result, CURLOPT_SSLCERT, ssl_cert);\n \tif (has_cert_password())\n \t\tcurl_easy_setopt(result, CURLOPT_KEYPASSWD, cert_auth.password);\n-#if LIBCURL_VERSION_NUM >= 0x070903\n \tif (ssl_key != NULL)\n \t\tcurl_easy_setopt(result, CURLOPT_SSLKEY, ssl_key);\n-#endif\n-#if LIBCURL_VERSION_NUM >= 0x070908\n \tif (ssl_capath != NULL)\n \t\tcurl_easy_setopt(result, CURLOPT_CAPATH, ssl_capath);\n-#endif\n #if LIBCURL_VERSION_NUM >= 0x072c00\n \tif (ssl_pinnedkey != NULL)\n \t\tcurl_easy_setopt(result, CURLOPT_PINNEDPUBLICKEY, ssl_pinnedkey);\n@@ -1180,12 +1137,8 @@ void http_init(struct remote *remote, const char *url, int proactive_auth)\n \t\tcurl_ssl_verify = 0;\n \n \tset_from_env(&ssl_cert, \"GIT_SSL_CERT\");\n-#if LIBCURL_VERSION_NUM >= 0x070903\n \tset_from_env(&ssl_key, \"GIT_SSL_KEY\");\n-#endif\n-#if LIBCURL_VERSION_NUM >= 0x070908\n \tset_from_env(&ssl_capath, \"GIT_SSL_CAPATH\");\n-#endif\n \tset_from_env(&ssl_cainfo, \"GIT_SSL_CAINFO\");\n \n \tset_from_env(&user_agent, \"GIT_HTTP_USER_AGENT\");\n@@ -1367,12 +1320,8 @@ struct active_request_slot *get_active_slot(void)\n \telse\n \t\tcurl_easy_setopt(slot->curl, CURLOPT_FOLLOWLOCATION, 0);\n \n-#if LIBCURL_VERSION_NUM >= 0x070a08\n \tcurl_easy_setopt(slot->curl, CURLOPT_IPRESOLVE, git_curl_ipresolve);\n-#endif\n-#ifdef LIBCURL_CAN_HANDLE_AUTH_ANY\n \tcurl_easy_setopt(slot->curl, CURLOPT_HTTPAUTH, http_auth_methods);\n-#endif\n \tif (http_auth.password || curl_empty_auth_enabled())\n \t\tinit_curl_http_auth(slot->curl);\n \n@@ -1654,13 +1603,11 @@ static int handle_curl_result(struct slot_results *results)\n \t\t\tcredential_reject(&http_auth);\n \t\t\treturn HTTP_NOAUTH;\n \t\t} else {\n-#ifdef LIBCURL_CAN_HANDLE_AUTH_ANY\n \t\t\thttp_auth_methods &= ~CURLAUTH_GSSNEGOTIATE;\n \t\t\tif (results->auth_avail) {\n \t\t\t\thttp_auth_methods &= results->auth_avail;\n \t\t\t\thttp_auth_methods_restricted = 1;\n \t\t\t}\n-#endif\n \t\t\treturn HTTP_REAUTH;\n \t\t}\n \t} else {\ndiff --git a/http.h b/http.h\nindex bf3d1270ad8..d2f8cc56617 100644\n--- a/http.h\n+++ b/http.h\n@@ -22,13 +22,7 @@\n #define DEFAULT_MAX_REQUESTS 5\n #endif\n \n-#if LIBCURL_VERSION_NUM < 0x070704\n-#define curl_global_cleanup() do { /* nothing */ } while (0)\n-#endif\n-\n-#if LIBCURL_VERSION_NUM < 0x070800\n-#define curl_global_init(a) do { /* nothing */ } while (0)\n-#elif LIBCURL_VERSION_NUM >= 0x070c00\n+#if LIBCURL_VERSION_NUM >= 0x070c00\n #define curl_global_init(a) curl_global_init_mem(a, xmalloc, free, \\\n \t\t\t\t\t\txrealloc, xstrdup, xcalloc)\n #endif\n@@ -37,10 +31,6 @@\n #define NO_CURL_EASY_DUPHANDLE\n #endif\n \n-#if LIBCURL_VERSION_NUM < 0x070a03\n-#define CURLE_HTTP_RETURNED_ERROR CURLE_HTTP_NOT_FOUND\n-#endif\n-\n #if LIBCURL_VERSION_NUM < 0x070c03\n #define NO_CURL_IOCTL\n #endif\ndiff --git a/remote-curl.c b/remote-curl.c\nindex 6c320d57045..e738ae2c48a 100644\n--- a/remote-curl.c\n+++ b/remote-curl.c\n@@ -185,8 +185,6 @@ static int set_option(const char *name, const char *value)\n \t\t\t\t\t\t strbuf_detach(&unquoted, NULL));\n \t\t}\n \t\treturn 0;\n-\n-#if LIBCURL_VERSION_NUM >= 0x070a08\n \t} else if (!strcmp(name, \"family\")) {\n \t\tif (!strcmp(value, \"ipv4\"))\n \t\t\tgit_curl_ipresolve = CURL_IPRESOLVE_V4;\n@@ -197,7 +195,6 @@ static int set_option(const char *name, const char *value)\n \t\telse\n \t\t\treturn -1;\n \t\treturn 0;\n-#endif /* LIBCURL_VERSION_NUM >= 0x070a08 */\n \t} else if (!strcmp(name, \"from-promisor\")) {\n \t\toptions.from_promisor = 1;\n \t\treturn 0;\n-- \n2.32.0.1071.g36f34456314\n\n"},{"id":"431593","messageId":"patch-v4-2.5-fb308258e2b-20210730T175650Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-v4-0.5-00000000000-20210730T175650Z-avarab@gmail.com","subject":"[PATCH v4 2/5] http: drop support for curl < 7.16.0","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-07-30T17:59:43Z","receivedAt":"2021-07-30T17:59:59Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"From: Jeff King <peff@peff.net>\n\nIn the last commit we dropped support for curl < 7.11.1, let's\ncontinue that and drop support for versions older than 7.16.0. This\nallows us to get rid of some now-obsolete #ifdefs.\n\nChoosing 7.16.0 is a somewhat arbitrary cutoff:\n\n  1. It came out in October of 2006, almost 15 years ago.\n     Besides being a nice round number, around 10 years is\n     a common end-of-life support period, even for conservative\n     distributions.\n\n  2. That version introduced the curl_multi interface, which\n     gives us a lot of bang for the buck in removing #ifdefs\n\nRHEL 5 came with curl 7.15.5[1] (released in August 2006). RHEL 5's\nextended life cycle program ended on 2020-11-30[1]. RHEL 6 comes with\ncurl 7.19.7 (released in November 2009), and RHEL 7 comes with\n7.29.0 (released in February 2013).\n\n1. http://lore.kernel.org/git/873e1f31-2a96-5b72-2f20-a5816cad1b51@jupiterrise.com\n\nSigned-off-by: Jeff King <peff@peff.net>\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n http-push.c   | 23 ---------------------\n http-walker.c | 12 -----------\n http.c        | 56 +--------------------------------------------------\n http.h        | 25 +----------------------\n imap-send.c   |  4 ----\n remote-curl.c |  4 ----\n 6 files changed, 2 insertions(+), 122 deletions(-)\n\ndiff --git a/http-push.c b/http-push.c\nindex d7cb1675a2d..aa3de7c1086 100644\n--- a/http-push.c\n+++ b/http-push.c\n@@ -203,10 +203,8 @@ static void curl_setup_http(CURL *curl, const char *url,\n \tcurl_easy_setopt(curl, CURLOPT_INFILE, buffer);\n \tcurl_easy_setopt(curl, CURLOPT_INFILESIZE, buffer->buf.len);\n \tcurl_easy_setopt(curl, CURLOPT_READFUNCTION, fread_buffer);\n-#ifndef NO_CURL_IOCTL\n \tcurl_easy_setopt(curl, CURLOPT_IOCTLFUNCTION, ioctl_buffer);\n \tcurl_easy_setopt(curl, CURLOPT_IOCTLDATA, buffer);\n-#endif\n \tcurl_easy_setopt(curl, CURLOPT_WRITEFUNCTION, write_fn);\n \tcurl_easy_setopt(curl, CURLOPT_NOBODY, 0);\n \tcurl_easy_setopt(curl, CURLOPT_CUSTOMREQUEST, custom_req);\n@@ -249,8 +247,6 @@ static void process_response(void *callback_data)\n \tfinish_request(request);\n }\n \n-#ifdef USE_CURL_MULTI\n-\n static void start_fetch_loose(struct transfer_request *request)\n {\n \tstruct active_request_slot *slot;\n@@ -299,7 +295,6 @@ static void start_mkcol(struct transfer_request *request)\n \t\tFREE_AND_NULL(request->url);\n \t}\n }\n-#endif\n \n static void start_fetch_packed(struct transfer_request *request)\n {\n@@ -605,7 +600,6 @@ static void finish_request(struct transfer_request *request)\n \t}\n }\n \n-#ifdef USE_CURL_MULTI\n static int is_running_queue;\n static int fill_active_slot(void *unused)\n {\n@@ -629,7 +623,6 @@ static int fill_active_slot(void *unused)\n \t}\n \treturn 0;\n }\n-#endif\n \n static void get_remote_object_list(unsigned char parent);\n \n@@ -658,10 +651,8 @@ static void add_fetch_request(struct object *obj)\n \trequest->next = request_queue_head;\n \trequest_queue_head = request;\n \n-#ifdef USE_CURL_MULTI\n \tfill_active_slots();\n \tstep_active_slots();\n-#endif\n }\n \n static int add_send_request(struct object *obj, struct remote_lock *lock)\n@@ -696,10 +687,8 @@ static int add_send_request(struct object *obj, struct remote_lock *lock)\n \trequest->next = request_queue_head;\n \trequest_queue_head = request;\n \n-#ifdef USE_CURL_MULTI\n \tfill_active_slots();\n \tstep_active_slots();\n-#endif\n \n \treturn 1;\n }\n@@ -1682,21 +1671,15 @@ static int delete_remote_branch(const char *pattern, int force)\n \n static void run_request_queue(void)\n {\n-#ifdef USE_CURL_MULTI\n \tis_running_queue = 1;\n \tfill_active_slots();\n \tadd_fill_function(NULL, fill_active_slot);\n-#endif\n \tdo {\n \t\tfinish_all_active_slots();\n-#ifdef USE_CURL_MULTI\n \t\tfill_active_slots();\n-#endif\n \t} while (request_queue_head && !aborted);\n \n-#ifdef USE_CURL_MULTI\n \tis_running_queue = 0;\n-#endif\n }\n \n int cmd_main(int argc, const char **argv)\n@@ -1770,10 +1753,6 @@ int cmd_main(int argc, const char **argv)\n \t\tbreak;\n \t}\n \n-#ifndef USE_CURL_MULTI\n-\tdie(\"git-push is not available for http/https repository when not compiled with USE_CURL_MULTI\");\n-#endif\n-\n \tif (!repo->url)\n \t\tusage(http_push_usage);\n \n@@ -1786,9 +1765,7 @@ int cmd_main(int argc, const char **argv)\n \n \thttp_init(NULL, repo->url, 1);\n \n-#ifdef USE_CURL_MULTI\n \tis_running_queue = 0;\n-#endif\n \n \t/* Verify DAV compliance/lock support */\n \tif (!locking_available()) {\ndiff --git a/http-walker.c b/http-walker.c\nindex 90d8ecb57ef..19e31623f04 100644\n--- a/http-walker.c\n+++ b/http-walker.c\n@@ -127,7 +127,6 @@ static void release_object_request(struct object_request *obj_req)\n \tfree(obj_req);\n }\n \n-#ifdef USE_CURL_MULTI\n static int fill_active_slot(struct walker *walker)\n {\n \tstruct object_request *obj_req;\n@@ -146,7 +145,6 @@ static int fill_active_slot(struct walker *walker)\n \t}\n \treturn 0;\n }\n-#endif\n \n static void prefetch(struct walker *walker, unsigned char *sha1)\n {\n@@ -163,10 +161,8 @@ static void prefetch(struct walker *walker, unsigned char *sha1)\n \thttp_is_verbose = walker->get_verbosely;\n \tlist_add_tail(&newreq->node, &object_queue_head);\n \n-#ifdef USE_CURL_MULTI\n \tfill_active_slots();\n \tstep_active_slots();\n-#endif\n }\n \n static int is_alternate_allowed(const char *url)\n@@ -357,11 +353,9 @@ static void fetch_alternates(struct walker *walker, const char *base)\n \t * wait for them to arrive and return to processing this request's\n \t * curl message\n \t */\n-#ifdef USE_CURL_MULTI\n \twhile (cdata->got_alternates == 0) {\n \t\tstep_active_slots();\n \t}\n-#endif\n \n \t/* Nothing to do if they've already been fetched */\n \tif (cdata->got_alternates == 1)\n@@ -505,12 +499,8 @@ static int fetch_object(struct walker *walker, unsigned char *hash)\n \t\treturn 0;\n \t}\n \n-#ifdef USE_CURL_MULTI\n \twhile (obj_req->state == WAITING)\n \t\tstep_active_slots();\n-#else\n-\tstart_object_request(walker, obj_req);\n-#endif\n \n \t/*\n \t * obj_req->req might change when fetching alternates in the callback\n@@ -623,9 +613,7 @@ struct walker *get_http_walker(const char *url)\n \twalker->cleanup = cleanup;\n \twalker->data = data;\n \n-#ifdef USE_CURL_MULTI\n \tadd_fill_function(walker, (int (*)(void *)) fill_active_slot);\n-#endif\n \n \treturn walker;\n }\ndiff --git a/http.c b/http.c\nindex 56182a89e25..ef00e930232 100644\n--- a/http.c\n+++ b/http.c\n@@ -26,10 +26,8 @@ ssize_t http_post_buffer = 16 * LARGE_PACKET_MAX;\n \n static int min_curl_sessions = 1;\n static int curl_session_count;\n-#ifdef USE_CURL_MULTI\n static int max_requests = -1;\n static CURLM *curlm;\n-#endif\n #ifndef NO_CURL_EASY_DUPHANDLE\n static CURL *curl_default;\n #endif\n@@ -117,14 +115,6 @@ static int curl_empty_auth = -1;\n \n enum http_follow_config http_follow_config = HTTP_FOLLOW_INITIAL;\n \n-#if LIBCURL_VERSION_NUM >= 0x071700\n-/* Use CURLOPT_KEYPASSWD as is */\n-#elif LIBCURL_VERSION_NUM >= 0x070903\n-#define CURLOPT_KEYPASSWD CURLOPT_SSLKEYPASSWD\n-#else\n-#define CURLOPT_KEYPASSWD CURLOPT_SSLCERTPASSWD\n-#endif\n-\n static struct credential cert_auth = CREDENTIAL_INIT;\n static int ssl_cert_password_required;\n static unsigned long http_auth_methods = CURLAUTH_ANY;\n@@ -168,7 +158,6 @@ size_t fread_buffer(char *ptr, size_t eltsize, size_t nmemb, void *buffer_)\n \treturn size / eltsize;\n }\n \n-#ifndef NO_CURL_IOCTL\n curlioerr ioctl_buffer(CURL *handle, int cmd, void *clientp)\n {\n \tstruct buffer *buffer = clientp;\n@@ -185,7 +174,6 @@ curlioerr ioctl_buffer(CURL *handle, int cmd, void *clientp)\n \t\treturn CURLIOE_UNKNOWNCMD;\n \t}\n }\n-#endif\n \n size_t fwrite_buffer(char *ptr, size_t eltsize, size_t nmemb, void *buffer_)\n {\n@@ -233,12 +221,9 @@ static void finish_active_slot(struct active_request_slot *slot)\n \n static void xmulti_remove_handle(struct active_request_slot *slot)\n {\n-#ifdef USE_CURL_MULTI\n \tcurl_multi_remove_handle(curlm, slot->curl);\n-#endif\n }\n \n-#ifdef USE_CURL_MULTI\n static void process_curl_messages(void)\n {\n \tint num_messages;\n@@ -266,7 +251,6 @@ static void process_curl_messages(void)\n \t\tcurl_message = curl_multi_info_read(curlm, &num_messages);\n \t}\n }\n-#endif\n \n static int http_options(const char *var, const char *value, void *cb)\n {\n@@ -315,18 +299,14 @@ static int http_options(const char *var, const char *value, void *cb)\n \n \tif (!strcmp(\"http.minsessions\", var)) {\n \t\tmin_curl_sessions = git_config_int(var, value);\n-#ifndef USE_CURL_MULTI\n \t\tif (min_curl_sessions > 1)\n \t\t\tmin_curl_sessions = 1;\n-#endif\n \t\treturn 0;\n \t}\n-#ifdef USE_CURL_MULTI\n \tif (!strcmp(\"http.maxrequests\", var)) {\n \t\tmax_requests = git_config_int(var, value);\n \t\treturn 0;\n \t}\n-#endif\n \tif (!strcmp(\"http.lowspeedlimit\", var)) {\n \t\tcurl_low_speed_limit = (long)git_config_int(var, value);\n \t\treturn 0;\n@@ -574,7 +554,7 @@ static void set_curl_keepalive(CURL *c)\n \tcurl_easy_setopt(c, CURLOPT_TCP_KEEPALIVE, 1);\n }\n \n-#elif LIBCURL_VERSION_NUM >= 0x071000\n+#else\n static int sockopt_callback(void *client, curl_socket_t fd, curlsocktype type)\n {\n \tint ka = 1;\n@@ -595,12 +575,6 @@ static void set_curl_keepalive(CURL *c)\n {\n \tcurl_easy_setopt(c, CURLOPT_SOCKOPTFUNCTION, sockopt_callback);\n }\n-\n-#else\n-static void set_curl_keepalive(CURL *c)\n-{\n-\t/* not supported on older curl versions */\n-}\n #endif\n \n static void redact_sensitive_header(struct strbuf *header)\n@@ -1121,7 +1095,6 @@ void http_init(struct remote *remote, const char *url, int proactive_auth)\n \tno_pragma_header = curl_slist_append(http_copy_default_headers(),\n \t\t\"Pragma:\");\n \n-#ifdef USE_CURL_MULTI\n \t{\n \t\tchar *http_max_requests = getenv(\"GIT_HTTP_MAX_REQUESTS\");\n \t\tif (http_max_requests != NULL)\n@@ -1131,7 +1104,6 @@ void http_init(struct remote *remote, const char *url, int proactive_auth)\n \tcurlm = curl_multi_init();\n \tif (!curlm)\n \t\tdie(\"curl_multi_init failed\");\n-#endif\n \n \tif (getenv(\"GIT_SSL_NO_VERIFY\"))\n \t\tcurl_ssl_verify = 0;\n@@ -1154,10 +1126,8 @@ void http_init(struct remote *remote, const char *url, int proactive_auth)\n \t\tcurl_ssl_verify = 1;\n \n \tcurl_session_count = 0;\n-#ifdef USE_CURL_MULTI\n \tif (max_requests < 1)\n \t\tmax_requests = DEFAULT_MAX_REQUESTS;\n-#endif\n \n \tset_from_env(&http_proxy_ssl_cert, \"GIT_PROXY_SSL_CERT\");\n \tset_from_env(&http_proxy_ssl_key, \"GIT_PROXY_SSL_KEY\");\n@@ -1201,9 +1171,7 @@ void http_cleanup(void)\n \tcurl_easy_cleanup(curl_default);\n #endif\n \n-#ifdef USE_CURL_MULTI\n \tcurl_multi_cleanup(curlm);\n-#endif\n \tcurl_global_cleanup();\n \n \tstring_list_clear(&extra_http_headers, 0);\n@@ -1250,7 +1218,6 @@ struct active_request_slot *get_active_slot(void)\n \tstruct active_request_slot *slot = active_queue_head;\n \tstruct active_request_slot *newslot;\n \n-#ifdef USE_CURL_MULTI\n \tint num_transfers;\n \n \t/* Wait for a slot to open up if the queue is full */\n@@ -1259,7 +1226,6 @@ struct active_request_slot *get_active_slot(void)\n \t\tif (num_transfers < active_requests)\n \t\t\tprocess_curl_messages();\n \t}\n-#endif\n \n \twhile (slot != NULL && slot->in_use)\n \t\tslot = slot->next;\n@@ -1330,7 +1296,6 @@ struct active_request_slot *get_active_slot(void)\n \n int start_active_slot(struct active_request_slot *slot)\n {\n-#ifdef USE_CURL_MULTI\n \tCURLMcode curlm_result = curl_multi_add_handle(curlm, slot->curl);\n \tint num_transfers;\n \n@@ -1348,11 +1313,9 @@ int start_active_slot(struct active_request_slot *slot)\n \t * something.\n \t */\n \tcurl_multi_perform(curlm, &num_transfers);\n-#endif\n \treturn 1;\n }\n \n-#ifdef USE_CURL_MULTI\n struct fill_chain {\n \tvoid *data;\n \tint (*fill)(void *);\n@@ -1411,11 +1374,9 @@ void step_active_slots(void)\n \t\tfill_active_slots();\n \t}\n }\n-#endif\n \n void run_active_slot(struct active_request_slot *slot)\n {\n-#ifdef USE_CURL_MULTI\n \tfd_set readfds;\n \tfd_set writefds;\n \tfd_set excfds;\n@@ -1428,7 +1389,6 @@ void run_active_slot(struct active_request_slot *slot)\n \t\tstep_active_slots();\n \n \t\tif (slot->in_use) {\n-#if LIBCURL_VERSION_NUM >= 0x070f04\n \t\t\tlong curl_timeout;\n \t\t\tcurl_multi_timeout(curlm, &curl_timeout);\n \t\t\tif (curl_timeout == 0) {\n@@ -1440,10 +1400,6 @@ void run_active_slot(struct active_request_slot *slot)\n \t\t\t\tselect_timeout.tv_sec  =  curl_timeout / 1000;\n \t\t\t\tselect_timeout.tv_usec = (curl_timeout % 1000) * 1000;\n \t\t\t}\n-#else\n-\t\t\tselect_timeout.tv_sec  = 0;\n-\t\t\tselect_timeout.tv_usec = 50000;\n-#endif\n \n \t\t\tmax_fd = -1;\n \t\t\tFD_ZERO(&readfds);\n@@ -1466,12 +1422,6 @@ void run_active_slot(struct active_request_slot *slot)\n \t\t\tselect(max_fd+1, &readfds, &writefds, &excfds, &select_timeout);\n \t\t}\n \t}\n-#else\n-\twhile (slot->in_use) {\n-\t\tslot->curl_result = curl_easy_perform(slot->curl);\n-\t\tfinish_active_slot(slot);\n-\t}\n-#endif\n }\n \n static void release_active_slot(struct active_request_slot *slot)\n@@ -1485,9 +1435,7 @@ static void release_active_slot(struct active_request_slot *slot)\n \t\t\tcurl_session_count--;\n \t\t}\n \t}\n-#ifdef USE_CURL_MULTI\n \tfill_active_slots();\n-#endif\n }\n \n void finish_all_active_slots(void)\n@@ -1613,12 +1561,10 @@ static int handle_curl_result(struct slot_results *results)\n \t} else {\n \t\tif (results->http_connectcode == 407)\n \t\t\tcredential_reject(&proxy_auth);\n-#if LIBCURL_VERSION_NUM >= 0x070c00\n \t\tif (!curl_errorstr[0])\n \t\t\tstrlcpy(curl_errorstr,\n \t\t\t\tcurl_easy_strerror(results->curl_result),\n \t\t\t\tsizeof(curl_errorstr));\n-#endif\n \t\treturn HTTP_ERROR;\n \t}\n }\ndiff --git a/http.h b/http.h\nindex d2f8cc56617..cb092622a73 100644\n--- a/http.h\n+++ b/http.h\n@@ -10,31 +10,12 @@\n #include \"remote.h\"\n #include \"url.h\"\n \n-/*\n- * We detect based on the cURL version if multi-transfer is\n- * usable in this implementation and define this symbol accordingly.\n- * This shouldn't be set by the Makefile or by the user (e.g. via CFLAGS).\n- */\n-#undef USE_CURL_MULTI\n-\n-#if LIBCURL_VERSION_NUM >= 0x071000\n-#define USE_CURL_MULTI\n #define DEFAULT_MAX_REQUESTS 5\n-#endif\n-\n-#if LIBCURL_VERSION_NUM >= 0x070c00\n-#define curl_global_init(a) curl_global_init_mem(a, xmalloc, free, \\\n-\t\t\t\t\t\txrealloc, xstrdup, xcalloc)\n-#endif\n \n-#if (LIBCURL_VERSION_NUM < 0x070c04) || (LIBCURL_VERSION_NUM == 0x071000)\n+#if LIBCURL_VERSION_NUM == 0x071000\n #define NO_CURL_EASY_DUPHANDLE\n #endif\n \n-#if LIBCURL_VERSION_NUM < 0x070c03\n-#define NO_CURL_IOCTL\n-#endif\n-\n /*\n  * CURLOPT_USE_SSL was known as CURLOPT_FTP_SSL up to 7.16.4,\n  * and the constants were known as CURLFTPSSL_*\n@@ -72,9 +53,7 @@ struct buffer {\n size_t fread_buffer(char *ptr, size_t eltsize, size_t nmemb, void *strbuf);\n size_t fwrite_buffer(char *ptr, size_t eltsize, size_t nmemb, void *strbuf);\n size_t fwrite_null(char *ptr, size_t eltsize, size_t nmemb, void *strbuf);\n-#ifndef NO_CURL_IOCTL\n curlioerr ioctl_buffer(CURL *handle, int cmd, void *clientp);\n-#endif\n \n /* Slot lifecycle functions */\n struct active_request_slot *get_active_slot(void);\n@@ -91,11 +70,9 @@ void finish_all_active_slots(void);\n int run_one_slot(struct active_request_slot *slot,\n \t\t struct slot_results *results);\n \n-#ifdef USE_CURL_MULTI\n void fill_active_slots(void);\n void add_fill_function(void *data, int (*fill)(void *));\n void step_active_slots(void);\n-#endif\n \n void http_init(struct remote *remote, const char *url,\n \t       int proactive_auth);\ndiff --git a/imap-send.c b/imap-send.c\nindex a0540ba5cf4..49a5f8aa597 100644\n--- a/imap-send.c\n+++ b/imap-send.c\n@@ -1517,11 +1517,7 @@ static int curl_append_msgs_to_imap(struct imap_server_conf *server,\n \tif (cred.username) {\n \t\tif (res == CURLE_OK)\n \t\t\tcredential_approve(&cred);\n-#if LIBCURL_VERSION_NUM >= 0x070d01\n \t\telse if (res == CURLE_LOGIN_DENIED)\n-#else\n-\t\telse\n-#endif\n \t\t\tcredential_reject(&cred);\n \t}\n \ndiff --git a/remote-curl.c b/remote-curl.c\nindex e738ae2c48a..09f09aeece3 100644\n--- a/remote-curl.c\n+++ b/remote-curl.c\n@@ -706,7 +706,6 @@ static size_t rpc_out(void *ptr, size_t eltsize,\n \treturn avail;\n }\n \n-#ifndef NO_CURL_IOCTL\n static curlioerr rpc_ioctl(CURL *handle, int cmd, void *clientp)\n {\n \tstruct rpc_state *rpc = clientp;\n@@ -727,7 +726,6 @@ static curlioerr rpc_ioctl(CURL *handle, int cmd, void *clientp)\n \t\treturn CURLIOE_UNKNOWNCMD;\n \t}\n }\n-#endif\n \n struct check_pktline_state {\n \tchar len_buf[4];\n@@ -946,10 +944,8 @@ static int post_rpc(struct rpc_state *rpc, int stateless_connect, int flush_rece\n \t\trpc->initial_buffer = 1;\n \t\tcurl_easy_setopt(slot->curl, CURLOPT_READFUNCTION, rpc_out);\n \t\tcurl_easy_setopt(slot->curl, CURLOPT_INFILE, rpc);\n-#ifndef NO_CURL_IOCTL\n \t\tcurl_easy_setopt(slot->curl, CURLOPT_IOCTLFUNCTION, rpc_ioctl);\n \t\tcurl_easy_setopt(slot->curl, CURLOPT_IOCTLDATA, rpc);\n-#endif\n \t\tif (options.verbosity > 1) {\n \t\t\tfprintf(stderr, \"POST %s (chunked)\\n\", rpc->service_name);\n \t\t\tfflush(stderr);\n-- \n2.32.0.1071.g36f34456314\n\n"},{"id":"431594","messageId":"patch-v4-3.5-fba5560a3ba-20210730T175650Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-v4-0.5-00000000000-20210730T175650Z-avarab@gmail.com","subject":"[PATCH v4 3/5] http: drop support for curl < 7.19.4","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-07-30T17:59:44Z","receivedAt":"2021-07-30T18:00:00Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"From: Jeff King <peff@peff.net>\n\nIn the last commit we dropped support for curl < 7.16.0, let's\ncontinue that and drop support for versions older than 7.19.3. This\nallows us to simplify the code by getting rid of some \"#ifdef\"'s.\n\nGit was broken with vanilla curl < 7.19.4 from v2.12.0 until\nv2.15.0. Compiling with it was broken by using CURLPROTO_* outside any\n\"#ifdef\" in aeae4db174 (http: create function to get curl allowed\nprotocols, 2016-12-14), and fixed in v2.15.0 in f18777ba6ef (http: fix\nhandling of missing CURLPROTO_*, 2017-08-11).\n\nIt's unclear how much anyone was impacted by that in practice, since\nas noted in [1] RHEL versions using curl older than that still\ncompiled, because RedHat backported some features. Perhaps other\nvendors did the same.\n\nStill, it's one datapoint indicating that it wasn't in active use at\nthe time. That (the v2.12.0 release) was in Feb 24, 2017, with v2.15.0\non Oct 30, 2017, it's now mid-2021.\n\n1. http://lore.kernel.org/git/c8a2716d-76ac-735c-57f9-175ca3acbcb0@jupiterrise.com;\n   followed-up by f18777ba6ef (http: fix handling of missing CURLPROTO_*,\n   2017-08-11)\n\nSigned-off-by: Jeff King <peff@peff.net>\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n http.c | 50 --------------------------------------------------\n http.h |  4 ----\n 2 files changed, 54 deletions(-)\n\ndiff --git a/http.c b/http.c\nindex ef00e930232..1f0d7664d35 100644\n--- a/http.c\n+++ b/http.c\n@@ -28,9 +28,7 @@ static int min_curl_sessions = 1;\n static int curl_session_count;\n static int max_requests = -1;\n static CURLM *curlm;\n-#ifndef NO_CURL_EASY_DUPHANDLE\n static CURL *curl_default;\n-#endif\n \n #define PREV_BUF_SIZE 4096\n \n@@ -440,24 +438,8 @@ static void init_curl_http_auth(CURL *result)\n \n \tcredential_fill(&http_auth);\n \n-#if LIBCURL_VERSION_NUM >= 0x071301\n \tcurl_easy_setopt(result, CURLOPT_USERNAME, http_auth.username);\n \tcurl_easy_setopt(result, CURLOPT_PASSWORD, http_auth.password);\n-#else\n-\t{\n-\t\tstatic struct strbuf up = STRBUF_INIT;\n-\t\t/*\n-\t\t * Note that we assume we only ever have a single set of\n-\t\t * credentials in a given program run, so we do not have\n-\t\t * to worry about updating this buffer, only setting its\n-\t\t * initial value.\n-\t\t */\n-\t\tif (!up.len)\n-\t\t\tstrbuf_addf(&up, \"%s:%s\",\n-\t\t\t\thttp_auth.username, http_auth.password);\n-\t\tcurl_easy_setopt(result, CURLOPT_USERPWD, up.buf);\n-\t}\n-#endif\n }\n \n /* *var must be free-able */\n@@ -471,22 +453,10 @@ static void var_override(const char **var, char *value)\n \n static void set_proxyauth_name_password(CURL *result)\n {\n-#if LIBCURL_VERSION_NUM >= 0x071301\n \t\tcurl_easy_setopt(result, CURLOPT_PROXYUSERNAME,\n \t\t\tproxy_auth.username);\n \t\tcurl_easy_setopt(result, CURLOPT_PROXYPASSWORD,\n \t\t\tproxy_auth.password);\n-#else\n-\t\tstruct strbuf s = STRBUF_INIT;\n-\n-\t\tstrbuf_addstr_urlencode(&s, proxy_auth.username,\n-\t\t\t\t\tis_rfc3986_unreserved);\n-\t\tstrbuf_addch(&s, ':');\n-\t\tstrbuf_addstr_urlencode(&s, proxy_auth.password,\n-\t\t\t\t\tis_rfc3986_unreserved);\n-\t\tcurl_proxyuserpwd = strbuf_detach(&s, NULL);\n-\t\tcurl_easy_setopt(result, CURLOPT_PROXYUSERPWD, curl_proxyuserpwd);\n-#endif\n }\n \n static void init_curl_proxy_auth(CURL *result)\n@@ -748,7 +718,6 @@ void setup_curl_trace(CURL *handle)\n \tcurl_easy_setopt(handle, CURLOPT_DEBUGDATA, NULL);\n }\n \n-#ifdef CURLPROTO_HTTP\n static long get_curl_allowed_protocols(int from_user)\n {\n \tlong allowed_protocols = 0;\n@@ -764,7 +733,6 @@ static long get_curl_allowed_protocols(int from_user)\n \n \treturn allowed_protocols;\n }\n-#endif\n \n #if LIBCURL_VERSION_NUM >=0x072f00\n static int get_curl_http_version_opt(const char *version_string, long *opt)\n@@ -906,19 +874,11 @@ static CURL *get_curl_handle(void)\n \t}\n \n \tcurl_easy_setopt(result, CURLOPT_MAXREDIRS, 20);\n-#if LIBCURL_VERSION_NUM >= 0x071301\n \tcurl_easy_setopt(result, CURLOPT_POSTREDIR, CURL_REDIR_POST_ALL);\n-#elif LIBCURL_VERSION_NUM >= 0x071101\n-\tcurl_easy_setopt(result, CURLOPT_POST301, 1);\n-#endif\n-#ifdef CURLPROTO_HTTP\n \tcurl_easy_setopt(result, CURLOPT_REDIR_PROTOCOLS,\n \t\t\t get_curl_allowed_protocols(0));\n \tcurl_easy_setopt(result, CURLOPT_PROTOCOLS,\n \t\t\t get_curl_allowed_protocols(-1));\n-#else\n-\twarning(_(\"Protocol restrictions not supported with cURL < 7.19.4\"));\n-#endif\n \tif (getenv(\"GIT_CURL_VERBOSE\"))\n \t\thttp_trace_curl_no_data();\n \tsetup_curl_trace(result);\n@@ -1012,11 +972,9 @@ static CURL *get_curl_handle(void)\n \t\t\tdie(\"Invalid proxy URL '%s'\", curl_http_proxy);\n \n \t\tcurl_easy_setopt(result, CURLOPT_PROXY, proxy_auth.host);\n-#if LIBCURL_VERSION_NUM >= 0x071304\n \t\tvar_override(&curl_no_proxy, getenv(\"NO_PROXY\"));\n \t\tvar_override(&curl_no_proxy, getenv(\"no_proxy\"));\n \t\tcurl_easy_setopt(result, CURLOPT_NOPROXY, curl_no_proxy);\n-#endif\n \t}\n \tinit_curl_proxy_auth(result);\n \n@@ -1147,9 +1105,7 @@ void http_init(struct remote *remote, const char *url, int proactive_auth)\n \t\t\tssl_cert_password_required = 1;\n \t}\n \n-#ifndef NO_CURL_EASY_DUPHANDLE\n \tcurl_default = get_curl_handle();\n-#endif\n }\n \n void http_cleanup(void)\n@@ -1167,9 +1123,7 @@ void http_cleanup(void)\n \t}\n \tactive_queue_head = NULL;\n \n-#ifndef NO_CURL_EASY_DUPHANDLE\n \tcurl_easy_cleanup(curl_default);\n-#endif\n \n \tcurl_multi_cleanup(curlm);\n \tcurl_global_cleanup();\n@@ -1248,11 +1202,7 @@ struct active_request_slot *get_active_slot(void)\n \t}\n \n \tif (slot->curl == NULL) {\n-#ifdef NO_CURL_EASY_DUPHANDLE\n-\t\tslot->curl = get_curl_handle();\n-#else\n \t\tslot->curl = curl_easy_duphandle(curl_default);\n-#endif\n \t\tcurl_session_count++;\n \t}\n \ndiff --git a/http.h b/http.h\nindex cb092622a73..19f19dbe74c 100644\n--- a/http.h\n+++ b/http.h\n@@ -12,10 +12,6 @@\n \n #define DEFAULT_MAX_REQUESTS 5\n \n-#if LIBCURL_VERSION_NUM == 0x071000\n-#define NO_CURL_EASY_DUPHANDLE\n-#endif\n-\n /*\n  * CURLOPT_USE_SSL was known as CURLOPT_FTP_SSL up to 7.16.4,\n  * and the constants were known as CURLFTPSSL_*\n-- \n2.32.0.1071.g36f34456314\n\n"},{"id":"431595","messageId":"patch-v4-4.5-42d1c72ff7e-20210730T175650Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-v4-0.5-00000000000-20210730T175650Z-avarab@gmail.com","subject":"[PATCH v4 4/5] http: drop support for curl < 7.19.3 and < 7.17.0 (again)","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-07-30T17:59:45Z","receivedAt":"2021-07-30T18:00:03Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"Remove the conditional use of CURLAUTH_DIGEST_IE and\nCURLOPT_USE_SSL. These two have been split from earlier simpler checks\nagainst LIBCURL_VERSION_NUM for ease of review.\n\nThe CURLAUTH_DIGEST_IE flag was added in n 7.19.3[1], and\nCURLOPT_USE_SSL in 7.17.0[2][3], as noted in [2] it was then renamed\nfrom the older CURLOPT_FTP_SSL.\n\nThe documentation[2] currently claims that it was introduced in\n7.16.4, but the symbols-in-versions file correctly states\n7.17.0[3].\n\nI've submitted an upstream\npatch (<patch-1.1-953bab490-20210730T170510Z-avarab@gmail.com>) to the\ncurl-library mailing list fix the documentation.\n\n1. https://curl.se/libcurl/c/CURLOPT_HTTPAUTH.html\n2. https://curl.se/libcurl/c/CURLOPT_USE_SSL.html\n3. https://github.com/curl/curl/blob/master/docs/libcurl/symbols-in-versions\n\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n http.c | 4 ----\n http.h | 9 ---------\n 2 files changed, 13 deletions(-)\n\ndiff --git a/http.c b/http.c\nindex 1f0d7664d35..e9446850a62 100644\n--- a/http.c\n+++ b/http.c\n@@ -120,9 +120,7 @@ static int http_auth_methods_restricted;\n /* Modes for which empty_auth cannot actually help us. */\n static unsigned long empty_auth_useless =\n \tCURLAUTH_BASIC\n-#ifdef CURLAUTH_DIGEST_IE\n \t| CURLAUTH_DIGEST_IE\n-#endif\n \t| CURLAUTH_DIGEST;\n \n static struct curl_slist *pragma_header;\n@@ -893,10 +891,8 @@ static CURL *get_curl_handle(void)\n \tif (curl_ftp_no_epsv)\n \t\tcurl_easy_setopt(result, CURLOPT_FTP_USE_EPSV, 0);\n \n-#ifdef CURLOPT_USE_SSL\n \tif (curl_ssl_try)\n \t\tcurl_easy_setopt(result, CURLOPT_USE_SSL, CURLUSESSL_TRY);\n-#endif\n \n \t/*\n \t * CURL also examines these variables as a fallback; but we need to query\ndiff --git a/http.h b/http.h\nindex 19f19dbe74c..3db5a0cf320 100644\n--- a/http.h\n+++ b/http.h\n@@ -12,15 +12,6 @@\n \n #define DEFAULT_MAX_REQUESTS 5\n \n-/*\n- * CURLOPT_USE_SSL was known as CURLOPT_FTP_SSL up to 7.16.4,\n- * and the constants were known as CURLFTPSSL_*\n-*/\n-#if !defined(CURLOPT_USE_SSL) && defined(CURLOPT_FTP_SSL)\n-#define CURLOPT_USE_SSL CURLOPT_FTP_SSL\n-#define CURLUSESSL_TRY CURLFTPSSL_TRY\n-#endif\n-\n struct slot_results {\n \tCURLcode curl_result;\n \tlong http_code;\n-- \n2.32.0.1071.g36f34456314\n\n"},{"id":"431596","messageId":"patch-v4-5.5-e34ab1d1f65-20210730T175650Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-v4-0.5-00000000000-20210730T175650Z-avarab@gmail.com","subject":"[PATCH v4 5/5] http: rename CURLOPT_FILE to CURLOPT_WRITEDATA","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-07-30T17:59:46Z","receivedAt":"2021-07-30T18:00:04Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"The CURLOPT_FILE name is an alias for CURLOPT_WRITEDATA, the\nCURLOPT_WRITEDATA name has been preferred since curl 7.9.7, released\nin May 2002[1].\n\n1. https://curl.se/libcurl/c/CURLOPT_WRITEDATA.html\n\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n http-push.c   | 6 +++---\n http-walker.c | 2 +-\n http.c        | 6 +++---\n remote-curl.c | 4 ++--\n 4 files changed, 9 insertions(+), 9 deletions(-)\n\ndiff --git a/http-push.c b/http-push.c\nindex aa3de7c1086..3309aaf004a 100644\n--- a/http-push.c\n+++ b/http-push.c\n@@ -883,7 +883,7 @@ static struct remote_lock *lock_remote(const char *path, long timeout)\n \tslot->results = &results;\n \tcurl_setup_http(slot->curl, url, DAV_LOCK, &out_buffer, fwrite_buffer);\n \tcurl_easy_setopt(slot->curl, CURLOPT_HTTPHEADER, dav_headers);\n-\tcurl_easy_setopt(slot->curl, CURLOPT_FILE, &in_buffer);\n+\tcurl_easy_setopt(slot->curl, CURLOPT_WRITEDATA, &in_buffer);\n \n \tCALLOC_ARRAY(lock, 1);\n \tlock->timeout = -1;\n@@ -1142,7 +1142,7 @@ static void remote_ls(const char *path, int flags,\n \tcurl_setup_http(slot->curl, url, DAV_PROPFIND,\n \t\t\t&out_buffer, fwrite_buffer);\n \tcurl_easy_setopt(slot->curl, CURLOPT_HTTPHEADER, dav_headers);\n-\tcurl_easy_setopt(slot->curl, CURLOPT_FILE, &in_buffer);\n+\tcurl_easy_setopt(slot->curl, CURLOPT_WRITEDATA, &in_buffer);\n \n \tif (start_active_slot(slot)) {\n \t\trun_active_slot(slot);\n@@ -1216,7 +1216,7 @@ static int locking_available(void)\n \tcurl_setup_http(slot->curl, repo->url, DAV_PROPFIND,\n \t\t\t&out_buffer, fwrite_buffer);\n \tcurl_easy_setopt(slot->curl, CURLOPT_HTTPHEADER, dav_headers);\n-\tcurl_easy_setopt(slot->curl, CURLOPT_FILE, &in_buffer);\n+\tcurl_easy_setopt(slot->curl, CURLOPT_WRITEDATA, &in_buffer);\n \n \tif (start_active_slot(slot)) {\n \t\trun_active_slot(slot);\ndiff --git a/http-walker.c b/http-walker.c\nindex 19e31623f04..910fae539b8 100644\n--- a/http-walker.c\n+++ b/http-walker.c\n@@ -378,7 +378,7 @@ static void fetch_alternates(struct walker *walker, const char *base)\n \talt_req.walker = walker;\n \tslot->callback_data = &alt_req;\n \n-\tcurl_easy_setopt(slot->curl, CURLOPT_FILE, &buffer);\n+\tcurl_easy_setopt(slot->curl, CURLOPT_WRITEDATA, &buffer);\n \tcurl_easy_setopt(slot->curl, CURLOPT_WRITEFUNCTION, fwrite_buffer);\n \tcurl_easy_setopt(slot->curl, CURLOPT_URL, url.buf);\n \ndiff --git a/http.c b/http.c\nindex e9446850a62..a0f169d2fe5 100644\n--- a/http.c\n+++ b/http.c\n@@ -1769,7 +1769,7 @@ static int http_request(const char *url,\n \t\tcurl_easy_setopt(slot->curl, CURLOPT_NOBODY, 1);\n \t} else {\n \t\tcurl_easy_setopt(slot->curl, CURLOPT_NOBODY, 0);\n-\t\tcurl_easy_setopt(slot->curl, CURLOPT_FILE, result);\n+\t\tcurl_easy_setopt(slot->curl, CURLOPT_WRITEDATA, result);\n \n \t\tif (target == HTTP_REQUEST_FILE) {\n \t\t\toff_t posn = ftello(result);\n@@ -2186,7 +2186,7 @@ struct http_pack_request *new_direct_http_pack_request(\n \t}\n \n \tpreq->slot = get_active_slot();\n-\tcurl_easy_setopt(preq->slot->curl, CURLOPT_FILE, preq->packfile);\n+\tcurl_easy_setopt(preq->slot->curl, CURLOPT_WRITEDATA, preq->packfile);\n \tcurl_easy_setopt(preq->slot->curl, CURLOPT_WRITEFUNCTION, fwrite);\n \tcurl_easy_setopt(preq->slot->curl, CURLOPT_URL, preq->url);\n \tcurl_easy_setopt(preq->slot->curl, CURLOPT_HTTPHEADER,\n@@ -2357,7 +2357,7 @@ struct http_object_request *new_http_object_request(const char *base_url,\n \n \tfreq->slot = get_active_slot();\n \n-\tcurl_easy_setopt(freq->slot->curl, CURLOPT_FILE, freq);\n+\tcurl_easy_setopt(freq->slot->curl, CURLOPT_WRITEDATA, freq);\n \tcurl_easy_setopt(freq->slot->curl, CURLOPT_FAILONERROR, 0);\n \tcurl_easy_setopt(freq->slot->curl, CURLOPT_WRITEFUNCTION, fwrite_sha1_file);\n \tcurl_easy_setopt(freq->slot->curl, CURLOPT_ERRORBUFFER, freq->errorstr);\ndiff --git a/remote-curl.c b/remote-curl.c\nindex 09f09aeece3..598cff7cde6 100644\n--- a/remote-curl.c\n+++ b/remote-curl.c\n@@ -853,7 +853,7 @@ static int probe_rpc(struct rpc_state *rpc, struct slot_results *results)\n \tcurl_easy_setopt(slot->curl, CURLOPT_POSTFIELDSIZE, 4);\n \tcurl_easy_setopt(slot->curl, CURLOPT_HTTPHEADER, headers);\n \tcurl_easy_setopt(slot->curl, CURLOPT_WRITEFUNCTION, fwrite_buffer);\n-\tcurl_easy_setopt(slot->curl, CURLOPT_FILE, &buf);\n+\tcurl_easy_setopt(slot->curl, CURLOPT_WRITEDATA, &buf);\n \n \terr = run_slot(slot, results);\n \n@@ -1016,7 +1016,7 @@ static int post_rpc(struct rpc_state *rpc, int stateless_connect, int flush_rece\n \trpc_in_data.slot = slot;\n \trpc_in_data.check_pktline = stateless_connect;\n \tmemset(&rpc_in_data.pktline_state, 0, sizeof(rpc_in_data.pktline_state));\n-\tcurl_easy_setopt(slot->curl, CURLOPT_FILE, &rpc_in_data);\n+\tcurl_easy_setopt(slot->curl, CURLOPT_WRITEDATA, &rpc_in_data);\n \tcurl_easy_setopt(slot->curl, CURLOPT_FAILONERROR, 0);\n \n \n-- \n2.32.0.1071.g36f34456314\n\n"},{"id":"431598","messageId":"xmqq7dh71v5g.fsf@gitster.g","threadId":"46547","inReplyTo":"cover-v4-0.5-00000000000-20210730T175650Z-avarab@gmail.com","subject":"Re: [PATCH v4 0/5] drop support for ancient curl","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2021-07-30T19:03:39Z","receivedAt":"2021-07-30T19:03:49Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Ævar Arnfjörð Bjarmason  <avarab@gmail.com> writes:\n\n> Per the feature creep feedback on v3 this v4 ejects the two new\n> changes new in v3. The below range-diff is against v2, not v3.\n>\n> I dug into the 7.16.4 v.s. 7.17.0 documentation issue and found that\n> it's bug in curl's docs, for which I submitted a patch.\n>\n> I considered keeping\n> <patch-v3-5.7-b857a9ef7b1-20210730T092843Z-avarab@gmail.com>, but\n> sequencing it in made the range diff quite a bit larger, so per the\n> feature creep feedback I ejected it too. Junio: Perhaps you'd like to\n> cherry-pick it on top too, or it can be dug up post-release.\n\nEither is fine; it is absolutely correct but \"who cares\" low impact\npatch in the shorter term.  We'd eventually want to have it (and\nsomething in the spirit of \"have a central place we know what the\ncurrent state of our cURL dependency is\", too) for the longer-term,\nbut they are not in urgent need anyway.\n\nThanks for working on it.\n\n>     +    The documentation[2] currently claims that it was introduced in\n>     +    7.16.4, but the symbols-in-versions file correctly states\n>     +    7.17.0[3].\n>     +\n>     +    I've submitted an upstream\n>     +    patch (<patch-1.1-953bab490-20210730T170510Z-avarab@gmail.com>) to the\n>     +    curl-library mailing list fix the documentation.\n\nI am not sure how to get to the patch, but I suspect you might be\nmisreading \"up to X\", which is different from \"before X\".  Once cURL\nmailing list confirms my suspicion, we would need to come back and\nupdate this patch again.\n\n>          1. https://curl.se/libcurl/c/CURLOPT_HTTPAUTH.html\n>          2. https://curl.se/libcurl/c/CURLOPT_USE_SSL.html\n>     +    3. https://github.com/curl/curl/blob/master/docs/libcurl/symbols-in-versions\n>      \n>          Signed-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n>      \n> 5:  64e510b4a6b = 5:  e34ab1d1f65 http: rename CURLOPT_FILE to CURLOPT_WRITEDATA\n"},{"id":"431601","messageId":"xmqqy29nzila.fsf@gitster.g","threadId":"46547","inReplyTo":"xmqq7dh71v5g.fsf@gitster.g","subject":"Re: [PATCH v4 0/5] drop support for ancient curl","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2021-07-30T19:50:57Z","receivedAt":"2021-07-30T19:51:01Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Junio C Hamano <gitster@pobox.com> writes:\n\n>>     +    The documentation[2] currently claims that it was introduced in\n>>     +    7.16.4, but the symbols-in-versions file correctly states\n>>     +    7.17.0[3].\n>>     +\n>>     +    I've submitted an upstream\n>>     +    patch (<patch-1.1-953bab490-20210730T170510Z-avarab@gmail.com>) to the\n>>     +    curl-library mailing list fix the documentation.\n>\n> I am not sure how to get to the patch, but I suspect you might be\n> misreading \"up to X\", which is different from \"before X\".  Once cURL\n> mailing list confirms my suspicion, we would need to come back and\n> update this patch again.\n\nAh, I found it at https://curl.se/mail/lib-2021-07/0058.html\n\nNobody seems to have responded yet, but I do think you are\nmisreading what \"X was known under a different name Y up to 7.16.4\"\nmeans.  These places do not say \"before 7.16.4\", which would have\nimplied that as of 7.16.4 you would be able to use X (not Y).\n\nBut because \"up to\" is \"less than or equal to but not more than\"\n(e.g https://dictionary.cambridge.org/us/dictionary/english/up-to),\nwhat applies to 7.16.3 also applies to 7.16.4, but not to 7.17.0.\nIOW, the feature X was known as Y when 7.16.4 was current, so our\nuse of X would not have worked with that exact version.  We would\nhave needed to wait until the next version (7.17.0).\n\n"},{"id":"431604","messageId":"xmqqa6m3zab3.fsf@gitster.g","threadId":"46547","inReplyTo":"xmqqy29nzila.fsf@gitster.g","subject":"Re: [PATCH v4 0/5] drop support for ancient curl","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2021-07-30T22:49:52Z","receivedAt":"2021-07-30T22:50:00Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Junio C Hamano <gitster@pobox.com> writes:\n\n> Junio C Hamano <gitster@pobox.com> writes:\n>\n>>>     +    The documentation[2] currently claims that it was introduced in\n>>>     +    7.16.4, but the symbols-in-versions file correctly states\n>>>     +    7.17.0[3].\n>>>     +\n>>>     +    I've submitted an upstream\n>>>     +    patch (<patch-1.1-953bab490-20210730T170510Z-avarab@gmail.com>) to the\n>>>     +    curl-library mailing list fix the documentation.\n>>\n>> I am not sure how to get to the patch, but I suspect you might be\n>> misreading \"up to X\", which is different from \"before X\".  Once cURL\n>> mailing list confirms my suspicion, we would need to come back and\n>> update this patch again.\n>\n> Ah, I found it at https://curl.se/mail/lib-2021-07/0058.html\n>\n> Nobody seems to have responded yet, but I do think you are\n> misreading what \"X was known under a different name Y up to 7.16.4\"\n> means.  These places do not say \"before 7.16.4\", which would have\n> implied that as of 7.16.4 you would be able to use X (not Y).\n>\n> But because \"up to\" is \"less than or equal to but not more than\"\n> (e.g https://dictionary.cambridge.org/us/dictionary/english/up-to),\n> what applies to 7.16.3 also applies to 7.16.4, but not to 7.17.0.\n> IOW, the feature X was known as Y when 7.16.4 was current, so our\n> use of X would not have worked with that exact version.  We would\n> have needed to wait until the next version (7.17.0).\n\nIt seems that Daniel has exactly the same reaction as I did.\n\n    https://curl.se/mail/lib-2021-07/0059.html\n\nSo, let's fix the log message for [4/5] on our end again.\n\n-- >8 --\nhttp: drop support for curl < 7.19.3 and < 7.17.0 (again)\n\nRemove the conditional use of CURLAUTH_DIGEST_IE and\nCURLOPT_USE_SSL. These two have been split from earlier simpler\nchecks against LIBCURL_VERSION_NUM for ease of review.\n\nAccording to\n\n  https://github.com/curl/curl/blob/master/docs/libcurl/symbols-in-versions\n\nthe CURLAUTH_DIGEST_IE flag became available in 7.19.3, and\nCURLOPT_USE_SSL in 7.17.0.\n\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\nSigned-off-by: Junio C Hamano <gitster@pobox.com>\n\ndiff --git a/http.c b/http.c\nindex 1f0d7664d3..e9446850a6 100644\n--- a/http.c\n+++ b/http.c\n@@ -120,9 +120,7 @@ static int http_auth_methods_restricted;\n /* Modes for which empty_auth cannot actually help us. */\n static unsigned long empty_auth_useless =\n \tCURLAUTH_BASIC\n-#ifdef CURLAUTH_DIGEST_IE\n \t| CURLAUTH_DIGEST_IE\n-#endif\n \t| CURLAUTH_DIGEST;\n \n static struct curl_slist *pragma_header;\n@@ -893,10 +891,8 @@ static CURL *get_curl_handle(void)\n \tif (curl_ftp_no_epsv)\n \t\tcurl_easy_setopt(result, CURLOPT_FTP_USE_EPSV, 0);\n \n-#ifdef CURLOPT_USE_SSL\n \tif (curl_ssl_try)\n \t\tcurl_easy_setopt(result, CURLOPT_USE_SSL, CURLUSESSL_TRY);\n-#endif\n \n \t/*\n \t * CURL also examines these variables as a fallback; but we need to query\ndiff --git a/http.h b/http.h\nindex 19f19dbe74..3db5a0cf32 100644\n--- a/http.h\n+++ b/http.h\n@@ -12,15 +12,6 @@\n \n #define DEFAULT_MAX_REQUESTS 5\n \n-/*\n- * CURLOPT_USE_SSL was known as CURLOPT_FTP_SSL up to 7.16.4,\n- * and the constants were known as CURLFTPSSL_*\n-*/\n-#if !defined(CURLOPT_USE_SSL) && defined(CURLOPT_FTP_SSL)\n-#define CURLOPT_USE_SSL CURLOPT_FTP_SSL\n-#define CURLUSESSL_TRY CURLFTPSSL_TRY\n-#endif\n-\n struct slot_results {\n \tCURLcode curl_result;\n \tlong http_code;\n"},{"id":"435103","messageId":"cover-0.5-00000000000-20210908T152807Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-v4-0.5-00000000000-20210730T175650Z-avarab@gmail.com","subject":"[PATCH 0/5] post-v2.33 \"drop support for ancient curl\" follow-up","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-09-08T15:31:51Z","receivedAt":"2021-09-08T15:32:15Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"This is a follow-up to the already-integrated topic for dropping\nsupport for older curl versions submitted before the v2.33 release[1].\n\nNo verions become unsupported in this topic, this is a mere clean-up.\n\nThere were a couple of cases where we either already dropped support\nfor something, but got the curl version wrong in a macro comparison,\nor just got the version wrong. That's now corrected.\n\nBut more importantly this introduces a git-curl-compat.h header which\ncentarlizes all our curl version dependencies, and any compatability\nshims we've got to deal with those versions. This makes the code much\neasier to read and maintain than inline LIBCURL_VERSION_NUM version\ncomparisons, and will make any future dropping of supported curl\nversions in the future easier to perform & review.\n\n1. https://lore.kernel.org/git/cover-v4-0.5-00000000000-20210730T175650Z-avarab@gmail.com/\n\nÆvar Arnfjörð Bjarmason (5):\n  http: drop support for curl < 7.18.0 (again)\n  http: correct curl version check for CURLOPT_PINNEDPUBLICKEY\n  http: correct version check for CURL_HTTP_VERSION_2_0\n  http: centralize the accounting of libcurl dependencies\n  http: don't hardcode the value of CURL_SOCKOPT_OK\n\n git-curl-compat.h | 123 ++++++++++++++++++++++++++++++++++++++++++++++\n http.c            |  39 +++++++--------\n imap-send.c       |   2 +-\n 3 files changed, 141 insertions(+), 23 deletions(-)\n create mode 100644 git-curl-compat.h\n\n-- \n2.33.0.825.g2bf60429931\n\n"},{"id":"435104","messageId":"patch-1.5-3ffa2f491dd-20210908T152807Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-0.5-00000000000-20210908T152807Z-avarab@gmail.com","subject":"[PATCH 1/5] http: drop support for curl < 7.18.0 (again)","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-09-08T15:31:52Z","receivedAt":"2021-09-08T15:32:25Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"In 644de29e220 (http: drop support for curl < 7.19.4, 2021-07-30) we\ndropped support for curl < 7.19.4, so we can drop support for this\nnon-obvious dependency on curl < 7.18.0.\n\nIt's non-obvious because in curl's hex version notation 0x071800 is\nversion 7.24.0, *not* 7.18.0, so at a glance this patch looks\nincorrect.\n\nBut it's correct, because the existing version check being removed\nhere is wrong. The check guards use of the following curl defines:\n\n    CURLPROXY_SOCKS4                7.10\n    CURLPROXY_SOCKS4A               7.18.0\n    CURLPROXY_SOCKS5                7.10\n    CURLPROXY_SOCKS5_HOSTNAME       7.18.0\n\nI.e. the oldest version that has these is in fact 7.18.0, not\n7.24.0. That we were checking 7.24.0 is just an mistake in\n6d7afe07f29 (remote-http(s): support SOCKS proxies, 2015-10-26),\ni.e. its author confusing base 10 and base 16.\n\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n http.c | 2 --\n 1 file changed, 2 deletions(-)\n\ndiff --git a/http.c b/http.c\nindex a0f169d2fe5..56856178bfe 100644\n--- a/http.c\n+++ b/http.c\n@@ -927,7 +927,6 @@ static CURL *get_curl_handle(void)\n \t\t */\n \t\tcurl_easy_setopt(result, CURLOPT_PROXY, \"\");\n \t} else if (curl_http_proxy) {\n-#if LIBCURL_VERSION_NUM >= 0x071800\n \t\tif (starts_with(curl_http_proxy, \"socks5h\"))\n \t\t\tcurl_easy_setopt(result,\n \t\t\t\tCURLOPT_PROXYTYPE, CURLPROXY_SOCKS5_HOSTNAME);\n@@ -940,7 +939,6 @@ static CURL *get_curl_handle(void)\n \t\telse if (starts_with(curl_http_proxy, \"socks\"))\n \t\t\tcurl_easy_setopt(result,\n \t\t\t\tCURLOPT_PROXYTYPE, CURLPROXY_SOCKS4);\n-#endif\n #if LIBCURL_VERSION_NUM >= 0x073400\n \t\telse if (starts_with(curl_http_proxy, \"https\")) {\n \t\t\tcurl_easy_setopt(result, CURLOPT_PROXYTYPE, CURLPROXY_HTTPS);\n-- \n2.33.0.825.g2bf60429931\n\n"},{"id":"435106","messageId":"patch-2.5-511534ce17a-20210908T152807Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-0.5-00000000000-20210908T152807Z-avarab@gmail.com","subject":"[PATCH 2/5] http: correct curl version check for CURLOPT_PINNEDPUBLICKEY","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-09-08T15:31:53Z","receivedAt":"2021-09-08T15:32:28Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"In aeff8a61216 (http: implement public key pinning, 2016-02-15) a\ndependency and warning() was added if curl older than 7.44.0 was used,\nbut the relevant code depended on CURLOPT_PINNEDPUBLICKEY, introduced\nin 7.39.0.\n\nLet's also remove the macro check before we declare the ssl_pinnedkey\nvariable, the pattern for other such variables is to declare the\nstatic variable unconditionally, we just may not use it on older\nversions. This reduces macro verbosity.\n\nThe reduction in verbosity comes at the small cost of issuing a\nwarning about the unused variable if this code is compiled with curl\nversions older than 7.39.0. I think that's an acceptable trade-off,\nanyone compiling a new git with a 2014-era toolchain likely has at\nleast other warning that'll have prompted them not to use -Werror, and\nif not maybe this'll prompt them to compile their new git with a more\nmodern libcurl.\n\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n http.c | 8 +++-----\n 1 file changed, 3 insertions(+), 5 deletions(-)\n\ndiff --git a/http.c b/http.c\nindex 56856178bfe..f7d5b6a0776 100644\n--- a/http.c\n+++ b/http.c\n@@ -59,9 +59,7 @@ static struct {\n static const char *ssl_key;\n static const char *ssl_capath;\n static const char *curl_no_proxy;\n-#if LIBCURL_VERSION_NUM >= 0x072c00\n static const char *ssl_pinnedkey;\n-#endif\n static const char *ssl_cainfo;\n static long curl_low_speed_limit = -1;\n static long curl_low_speed_time = -1;\n@@ -373,10 +371,10 @@ static int http_options(const char *var, const char *value, void *cb)\n \t}\n \n \tif (!strcmp(\"http.pinnedpubkey\", var)) {\n-#if LIBCURL_VERSION_NUM >= 0x072c00\n+#if LIBCURL_VERSION_NUM >= 0x072700\n \t\treturn git_config_pathname(&ssl_pinnedkey, var, value);\n #else\n-\t\twarning(_(\"Public key pinning not supported with cURL < 7.44.0\"));\n+\t\twarning(_(\"Public key pinning not supported with cURL < 7.39.0\"));\n \t\treturn 0;\n #endif\n \t}\n@@ -845,7 +843,7 @@ static CURL *get_curl_handle(void)\n \t\tcurl_easy_setopt(result, CURLOPT_SSLKEY, ssl_key);\n \tif (ssl_capath != NULL)\n \t\tcurl_easy_setopt(result, CURLOPT_CAPATH, ssl_capath);\n-#if LIBCURL_VERSION_NUM >= 0x072c00\n+#if LIBCURL_VERSION_NUM >= 0x072700\n \tif (ssl_pinnedkey != NULL)\n \t\tcurl_easy_setopt(result, CURLOPT_PINNEDPUBLICKEY, ssl_pinnedkey);\n #endif\n-- \n2.33.0.825.g2bf60429931\n\n"},{"id":"435107","messageId":"patch-3.5-d8192164937-20210908T152807Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-0.5-00000000000-20210908T152807Z-avarab@gmail.com","subject":"[PATCH 3/5] http: correct version check for CURL_HTTP_VERSION_2_0","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-09-08T15:31:54Z","receivedAt":"2021-09-08T15:32:30Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"In d73019feb44 (http: add support selecting http version, 2018-11-08)\na dependency was added on CURL_HTTP_VERSION_2_0, but this feature was\nintroduced in curl version 7.43.0, not 7.47.0, as the incorrect\nversion check led us to believe.\n\nAs looking through the history of that commit on the mailing list will\nreveal[1], the reason for this is that an earlier version of it\ndepended on CURL_HTTP_VERSION_2TLS, which was introduced in libcurl\n7.47.0.\n\nBut the version that made it in in d73019feb44 had dropped the\ndependency on CURL_HTTP_VERSION_2TLS, but the corresponding version\ncheck was not corrected.\n\n1. https://lore.kernel.org/git/pull.69.git.gitgitgadget@gmail.com/\n\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n http.c | 4 ++--\n 1 file changed, 2 insertions(+), 2 deletions(-)\n\ndiff --git a/http.c b/http.c\nindex f7d5b6a0776..b19d0a697d8 100644\n--- a/http.c\n+++ b/http.c\n@@ -730,7 +730,7 @@ static long get_curl_allowed_protocols(int from_user)\n \treturn allowed_protocols;\n }\n \n-#if LIBCURL_VERSION_NUM >=0x072f00\n+#if LIBCURL_VERSION_NUM >=0x072b00\n static int get_curl_http_version_opt(const char *version_string, long *opt)\n {\n \tint i;\n@@ -772,7 +772,7 @@ static CURL *get_curl_handle(void)\n \t\tcurl_easy_setopt(result, CURLOPT_SSL_VERIFYHOST, 2);\n \t}\n \n-#if LIBCURL_VERSION_NUM >= 0x072f00 // 7.47.0\n+#if LIBCURL_VERSION_NUM >= 0x072b00\n     if (curl_http_version) {\n \t\tlong opt;\n \t\tif (!get_curl_http_version_opt(curl_http_version, &opt)) {\n-- \n2.33.0.825.g2bf60429931\n\n"},{"id":"435108","messageId":"patch-4.5-47b513a261b-20210908T152807Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-0.5-00000000000-20210908T152807Z-avarab@gmail.com","subject":"[PATCH 4/5] http: centralize the accounting of libcurl dependencies","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-09-08T15:31:55Z","receivedAt":"2021-09-08T15:32:31Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"As discussed in 644de29e220 (http: drop support for curl < 7.19.4,\n2021-07-30) checking against LIBCURL_VERSION_NUM isn't as reliable as\nchecking specific defines in curl, as some distros have been known to\nbackport features. Furthermore as shown in the preceding commit doing\nthese version checks makes for hard to read and possibly buggy code,\nas shown by the bug fixed there where we were conflating base 10 for\nbase 16 when comparing the version.\n\nLet's instead add a new git-curl-compat.h header that'll keep track of\nthese dependencies. Following this pattern will also make it much\neasier to track when we should deprecate curl versions in the future,\nas we just did post-v2.33 e48a623dea0 (Merge branch\n'ab/http-drop-old-curl', 2021-08-24).\n\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n git-curl-compat.h | 112 ++++++++++++++++++++++++++++++++++++++++++++++\n http.c            |  31 +++++++------\n imap-send.c       |   2 +-\n 3 files changed, 128 insertions(+), 17 deletions(-)\n create mode 100644 git-curl-compat.h\n\ndiff --git a/git-curl-compat.h b/git-curl-compat.h\nnew file mode 100644\nindex 00000000000..2bba7adefa6\n--- /dev/null\n+++ b/git-curl-compat.h\n@@ -0,0 +1,112 @@\n+#ifndef GIT_CURL_COMPAT_H\n+#define GIT_CURL_COMPAT_H\n+\n+/**\n+ * This header centralizes the declaration of our libcurl dependencies\n+ * to make it easy to discover the oldest versions we support, and to\n+ * inform decisions about removing support for older libcurl in the\n+ * future.\n+ *\n+ * The source of truth for what versions have which symbols is\n+ * https://github.com/curl/curl/blob/master/docs/libcurl/symbols-in-versions;\n+ * the release dates are taken from curl.git (at\n+ * https://github.com/curl/curl/).\n+ *\n+ * For each X symbol we need from curl we check if it exists and\n+ * declare our own GIT_CURL_HAVE_X, or if it's for both X and Y\n+ * GIT_CURL_HAVE_X_and_Y, where the \"Y\" in \"X_and_Y\" is only the part\n+ * of the symbol name that \"X\" and \"Y\" don't have in common.\n+ *\n+ * We avoid comparisons against LIBCURL_VERSION_NUM, enterprise\n+ * distros have been known to backport symbols to their older curl\n+ * versions.\n+ *\n+ * Keep any symbols in date order of when their support was\n+ * introduced, oldest first, in the official version of cURL library.\n+ */\n+\n+/**\n+ * CURLOPT_TCP_KEEPALIVE was added in 7.25.0, released in March 2012.\n+ */\n+#ifdef CURLOPT_TCP_KEEPALIVE\n+#define GITCURL_HAVE_CURLOPT_TCP_KEEPALIVE 1\n+#endif\n+\n+\n+/**\n+ * CURLOPT_LOGIN_OPTIONS was added in 7.34.0, released in December\n+ * 2013.\n+ */\n+#ifdef CURLOPT_LOGIN_OPTIONS\n+#define GIT_CURL_HAVE_CURLOPT_LOGIN_OPTIONS 1\n+#endif\n+\n+/**\n+ * CURL_SSLVERSION_TLSv1_[012] was added in 7.34.0, released in\n+ * December 2013.\n+ */\n+#if defined(CURL_SSLVERSION_TLSv1_0) && \\\n+    defined(CURL_SSLVERSION_TLSv1_1) && \\\n+    defined(CURL_SSLVERSION_TLSv1_2)\n+#define GIT_CURL_HAVE_CURL_SSLVERSION_TLSv1_0_and_1_and_2\n+#endif\n+\n+/**\n+ * CURLOPT_PINNEDPUBLICKEY was added in 7.39.0, released in November\n+ * 2014.\n+ */\n+#ifdef CURLOPT_PINNEDPUBLICKEY\n+#define GIT_CURL_HAVE_CURLOPT_PINNEDPUBLICKEY 1\n+#endif\n+\n+/**\n+ * CURL_HTTP_VERSION_2 was added in 7.43.0, released in June 2015.\n+ */\n+#ifdef CURL_HTTP_VERSION_2\n+#define GIT_CURL_HAVE_CURL_HTTP_VERSION_2 1\n+#endif\n+\n+/**\n+ * CURLSSLOPT_NO_REVOKE was added in 7.44.0, released in August 2015.\n+ */\n+#ifdef CURLSSLOPT_NO_REVOKE\n+#define GIT_CURL_HAVE_CURLSSLOPT_NO_REVOKE 1\n+#endif\n+\n+/**\n+ * CURLOPT_PROXY_CAINFO was added in 7.52.0, released in August 2017.\n+ */\n+#ifdef CURLOPT_PROXY_CAINFO\n+#define GIT_CURL_HAVE_CURLOPT_PROXY_CAINFO 1\n+#endif\n+\n+/**\n+ * CURLOPT_PROXY_{KEYPASSWD,SSLCERT,SSLKEY} was added in 7.52.0,\n+ * released in August 2017.\n+ */\n+#if defined(CURLOPT_PROXY_KEYPASSWD) && \\\n+    defined(CURLOPT_PROXY_SSLCERT) && \\\n+    defined(CURLOPT_PROXY_SSLKEY)\n+#define GIT_CURL_HAVE_CURLOPT_PROXY_KEYPASSWD_and_SSLCERT_and_SSLKEY 1\n+#endif\n+\n+/**\n+ * CURL_SSLVERSION_TLSv1_3 was added in 7.53.0, released in February\n+ * 2017.\n+ */\n+#ifdef CURL_SSLVERSION_TLSv1_3\n+#define GIT_CURL_HAVE_CURL_SSLVERSION_TLSv1_3 1\n+#endif\n+\n+/**\n+ * CURLSSLSET_{NO_BACKENDS,OK,TOO_LATE,UNKNOWN_BACKEND} were added in\n+ * 7.56.0, released in September 2017.\n+ */\n+#if defined(CURLSSLSET_NO_BACKENDS) && \\\n+    defined(CURLSSLSET_OK) && \\\n+    defined(CURLSSLSET_TOO_LATE) && \\\n+    defined(CURLSSLSET_UNKNOWN_BACKEND)\n+#define GIT_CURL_HAVE_CURLSSLSET_NO_BACKENDS_and_OK_and_TOO_LATE_and_UNKNOWN_BACKEND 1\n+#endif\n+\n+#endif\ndiff --git a/http.c b/http.c\nindex b19d0a697d8..e38fcc34d64 100644\n--- a/http.c\n+++ b/http.c\n@@ -1,4 +1,5 @@\n #include \"git-compat-util.h\"\n+#include \"git-curl-compat.h\"\n #include \"http.h\"\n #include \"config.h\"\n #include \"pack.h\"\n@@ -47,12 +48,12 @@ static struct {\n \t{ \"sslv2\", CURL_SSLVERSION_SSLv2 },\n \t{ \"sslv3\", CURL_SSLVERSION_SSLv3 },\n \t{ \"tlsv1\", CURL_SSLVERSION_TLSv1 },\n-#if LIBCURL_VERSION_NUM >= 0x072200\n+#if GIT_CURL_HAVE_CURL_SSLVERSION_TLSv1_0_AND_1_AND_2\n \t{ \"tlsv1.0\", CURL_SSLVERSION_TLSv1_0 },\n \t{ \"tlsv1.1\", CURL_SSLVERSION_TLSv1_1 },\n \t{ \"tlsv1.2\", CURL_SSLVERSION_TLSv1_2 },\n #endif\n-#if LIBCURL_VERSION_NUM >= 0x073400\n+#if GIT_CURL_HAVE_CURL_SSLVERSION_TLSv1_3\n \t{ \"tlsv1.3\", CURL_SSLVERSION_TLSv1_3 },\n #endif\n };\n@@ -371,12 +372,10 @@ static int http_options(const char *var, const char *value, void *cb)\n \t}\n \n \tif (!strcmp(\"http.pinnedpubkey\", var)) {\n-#if LIBCURL_VERSION_NUM >= 0x072700\n-\t\treturn git_config_pathname(&ssl_pinnedkey, var, value);\n-#else\n+#ifndef GIT_CURL_HAVE_CURLOPT_PINNEDPUBLICKEY\n \t\twarning(_(\"Public key pinning not supported with cURL < 7.39.0\"));\n-\t\treturn 0;\n #endif\n+\t\treturn git_config_pathname(&ssl_pinnedkey, var, value);\n \t}\n \n \tif (!strcmp(\"http.extraheader\", var)) {\n@@ -498,7 +497,7 @@ static int has_cert_password(void)\n \treturn 1;\n }\n \n-#if LIBCURL_VERSION_NUM >= 0x073400\n+#ifdef GIT_CURL_HAVE_CURLOPT_PROXY_KEYPASSWD_and_SSLCERT_and_SSLKEY\n static int has_proxy_cert_password(void)\n {\n \tif (http_proxy_ssl_cert == NULL || proxy_ssl_cert_password_required != 1)\n@@ -514,7 +513,7 @@ static int has_proxy_cert_password(void)\n }\n #endif\n \n-#if LIBCURL_VERSION_NUM >= 0x071900\n+#ifdef GITCURL_HAVE_CURLOPT_TCP_KEEPALIVE\n static void set_curl_keepalive(CURL *c)\n {\n \tcurl_easy_setopt(c, CURLOPT_TCP_KEEPALIVE, 1);\n@@ -730,7 +729,7 @@ static long get_curl_allowed_protocols(int from_user)\n \treturn allowed_protocols;\n }\n \n-#if LIBCURL_VERSION_NUM >=0x072b00\n+#ifdef GIT_CURL_HAVE_CURL_HTTP_VERSION_2\n static int get_curl_http_version_opt(const char *version_string, long *opt)\n {\n \tint i;\n@@ -772,7 +771,7 @@ static CURL *get_curl_handle(void)\n \t\tcurl_easy_setopt(result, CURLOPT_SSL_VERIFYHOST, 2);\n \t}\n \n-#if LIBCURL_VERSION_NUM >= 0x072b00\n+#ifdef GIT_CURL_HAVE_CURL_HTTP_VERSION_2\n     if (curl_http_version) {\n \t\tlong opt;\n \t\tif (!get_curl_http_version_opt(curl_http_version, &opt)) {\n@@ -803,7 +802,7 @@ static CURL *get_curl_handle(void)\n \n \tif (http_ssl_backend && !strcmp(\"schannel\", http_ssl_backend) &&\n \t    !http_schannel_check_revoke) {\n-#if LIBCURL_VERSION_NUM >= 0x072c00\n+#ifdef GIT_CURL_HAVE_CURLSSLOPT_NO_REVOKE\n \t\tcurl_easy_setopt(result, CURLOPT_SSL_OPTIONS, CURLSSLOPT_NO_REVOKE);\n #else\n \t\twarning(_(\"CURLSSLOPT_NO_REVOKE not supported with cURL < 7.44.0\"));\n@@ -843,20 +842,20 @@ static CURL *get_curl_handle(void)\n \t\tcurl_easy_setopt(result, CURLOPT_SSLKEY, ssl_key);\n \tif (ssl_capath != NULL)\n \t\tcurl_easy_setopt(result, CURLOPT_CAPATH, ssl_capath);\n-#if LIBCURL_VERSION_NUM >= 0x072700\n+#ifdef GIT_CURL_HAVE_CURLOPT_PINNEDPUBLICKEY\n \tif (ssl_pinnedkey != NULL)\n \t\tcurl_easy_setopt(result, CURLOPT_PINNEDPUBLICKEY, ssl_pinnedkey);\n #endif\n \tif (http_ssl_backend && !strcmp(\"schannel\", http_ssl_backend) &&\n \t    !http_schannel_use_ssl_cainfo) {\n \t\tcurl_easy_setopt(result, CURLOPT_CAINFO, NULL);\n-#if LIBCURL_VERSION_NUM >= 0x073400\n+#ifdef GIT_CURL_HAVE_CURLOPT_PROXY_CAINFO\n \t\tcurl_easy_setopt(result, CURLOPT_PROXY_CAINFO, NULL);\n #endif\n \t} else if (ssl_cainfo != NULL || http_proxy_ssl_ca_info != NULL) {\n \t\tif (ssl_cainfo != NULL)\n \t\t\tcurl_easy_setopt(result, CURLOPT_CAINFO, ssl_cainfo);\n-#if LIBCURL_VERSION_NUM >= 0x073400\n+#ifdef GIT_CURL_HAVE_CURLOPT_PROXY_CAINFO\n \t\tif (http_proxy_ssl_ca_info != NULL)\n \t\t\tcurl_easy_setopt(result, CURLOPT_PROXY_CAINFO, http_proxy_ssl_ca_info);\n #endif\n@@ -937,7 +936,7 @@ static CURL *get_curl_handle(void)\n \t\telse if (starts_with(curl_http_proxy, \"socks\"))\n \t\t\tcurl_easy_setopt(result,\n \t\t\t\tCURLOPT_PROXYTYPE, CURLPROXY_SOCKS4);\n-#if LIBCURL_VERSION_NUM >= 0x073400\n+#ifdef GIT_CURL_HAVE_CURLOPT_PROXY_KEYPASSWD_and_SSLCERT_and_SSLKEY\n \t\telse if (starts_with(curl_http_proxy, \"https\")) {\n \t\t\tcurl_easy_setopt(result, CURLOPT_PROXYTYPE, CURLPROXY_HTTPS);\n \n@@ -1002,7 +1001,7 @@ void http_init(struct remote *remote, const char *url, int proactive_auth)\n \tfree(normalized_url);\n \tstring_list_clear(&config.vars, 1);\n \n-#if LIBCURL_VERSION_NUM >= 0x073800\n+#ifdef GIT_CURL_HAVE_CURLSSLSET_NO_BACKENDS_and_OK_and_TOO_LATE_and_UNKNOWN_BACKEND\n \tif (http_ssl_backend) {\n \t\tconst curl_ssl_backend **backends;\n \t\tstruct strbuf buf = STRBUF_INIT;\ndiff --git a/imap-send.c b/imap-send.c\nindex 49a5f8aa597..e6090a0346a 100644\n--- a/imap-send.c\n+++ b/imap-send.c\n@@ -1441,7 +1441,7 @@ static CURL *setup_curl(struct imap_server_conf *srvc, struct credential *cred)\n \tcurl_easy_setopt(curl, CURLOPT_PORT, server.port);\n \n \tif (server.auth_method) {\n-#if LIBCURL_VERSION_NUM < 0x072200\n+#ifndef GIT_CURL_HAVE_CURLOPT_LOGIN_OPTIONS\n \t\twarning(\"No LOGIN_OPTIONS support in this cURL version\");\n #else\n \t\tstruct strbuf auth = STRBUF_INIT;\n-- \n2.33.0.825.g2bf60429931\n\n"},{"id":"435109","messageId":"patch-5.5-4f42c0e48b0-20210908T152807Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-0.5-00000000000-20210908T152807Z-avarab@gmail.com","subject":"[PATCH 5/5] http: don't hardcode the value of CURL_SOCKOPT_OK","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-09-08T15:31:56Z","receivedAt":"2021-09-08T15:32:31Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"Use the new git-curl-compat.h header to define CURL_SOCKOPT_OK to its\nknown value if we're on an older curl version that doesn't have it. It\nwas hardcoded in http.c in a15d069a198 (http: enable keepalive on TCP\nsockets, 2013-10-12).\n\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n git-curl-compat.h | 11 +++++++++++\n http.c            |  2 +-\n 2 files changed, 12 insertions(+), 1 deletion(-)\n\ndiff --git a/git-curl-compat.h b/git-curl-compat.h\nindex 2bba7adefa6..bfa85711511 100644\n--- a/git-curl-compat.h\n+++ b/git-curl-compat.h\n@@ -17,6 +17,10 @@\n  * GIT_CURL_HAVE_X_and_Y, where the \"Y\" in \"X_and_Y\" is only the part\n  * of the symbol name that \"X\" and \"Y\" don't have in common.\n  *\n+ * We may also define a missing CURL_* symbol to its known value, if\n+ * doing so is sufficient to add support for it to older versions that\n+ * don't have it.\n+ *\n  * We avoid comparisons against LIBCURL_VERSION_NUM, enterprise\n  * distros have been known to backport symbols to their older curl\n  * versions.\n@@ -25,6 +29,13 @@\n  * introduced, oldest first, in the official version of cURL library.\n  */\n \n+/**\n+ * CURL_SOCKOPT_OK was added in 7.21.5, released in April 2011.\n+ */\n+#ifndef CURL_SOCKOPT_OK\n+#define CURL_SOCKOPT_OK 0\n+#endif\n+\n /**\n  * CURLOPT_TCP_KEEPALIVE was added in 7.25.0, released in March 2012.\n  */\ndiff --git a/http.c b/http.c\nindex e38fcc34d64..c40439d39ce 100644\n--- a/http.c\n+++ b/http.c\n@@ -533,7 +533,7 @@ static int sockopt_callback(void *client, curl_socket_t fd, curlsocktype type)\n \tif (rc < 0)\n \t\twarning_errno(\"unable to set SO_KEEPALIVE on socket\");\n \n-\treturn 0; /* CURL_SOCKOPT_OK only exists since curl 7.21.5 */\n+\treturn CURL_SOCKOPT_OK;\n }\n \n static void set_curl_keepalive(CURL *c)\n-- \n2.33.0.825.g2bf60429931\n\n"},{"id":"435148","messageId":"YTkNdGk28UJnSDVt@coredump.intra.peff.net","threadId":"46547","inReplyTo":"patch-2.5-511534ce17a-20210908T152807Z-avarab@gmail.com","subject":"Re: [PATCH 2/5] http: correct curl version check for CURLOPT_PINNEDPUBLICKEY","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2021-09-08T19:22:28Z","receivedAt":"2021-09-08T19:22:33Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Wed, Sep 08, 2021 at 05:31:53PM +0200, Ævar Arnfjörð Bjarmason wrote:\n\n> In aeff8a61216 (http: implement public key pinning, 2016-02-15) a\n> dependency and warning() was added if curl older than 7.44.0 was used,\n> but the relevant code depended on CURLOPT_PINNEDPUBLICKEY, introduced\n> in 7.39.0.\n\nAccording to the manpage for CURLOPT_PINNEDPUBLICKEY, it looks like\nsupport for various formats and implementations was phased in. In\nparticular, 7.44.0 picked up sha256 support (I guess for a fingerprint?\nI've never used this feature) for most major implementations.\n\nBut in terms of compiling, all we care about is that the constant is\nthere. So I think the cutoff point you found is what we want. Presumably\nwhen the file format isn't supported we'd get some error, though it's\nnot clear if that would come during the actual curl_*_perform(), or if\nwe should be checking the curl_easy_setopt() result.\n\n> Let's also remove the macro check before we declare the ssl_pinnedkey\n> variable, the pattern for other such variables is to declare the\n> static variable unconditionally, we just may not use it on older\n> versions. This reduces macro verbosity.\n> \n> The reduction in verbosity comes at the small cost of issuing a\n> warning about the unused variable if this code is compiled with curl\n> versions older than 7.39.0. I think that's an acceptable trade-off,\n> anyone compiling a new git with a 2014-era toolchain likely has at\n> least other warning that'll have prompted them not to use -Werror, and\n> if not maybe this'll prompt them to compile their new git with a more\n> modern libcurl.\n\nOK. That's a bit of a departure from how we've handled variables before,\nbut it does make the code a bit cleaner. And I am fine with the attitude\nof \"if you are using ancient tools, you may see some extra warnings\". We\nalready know this is true for older compilers, and it's not worth caring\ntoo much about.\n\n-Peff\n"},{"id":"435167","messageId":"YTkOlcfx8qwSBZ4A@coredump.intra.peff.net","threadId":"46547","inReplyTo":"patch-3.5-d8192164937-20210908T152807Z-avarab@gmail.com","subject":"Re: [PATCH 3/5] http: correct version check for CURL_HTTP_VERSION_2_0","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2021-09-08T19:27:17Z","receivedAt":"2021-09-08T19:27:19Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Wed, Sep 08, 2021 at 05:31:54PM +0200, Ævar Arnfjörð Bjarmason wrote:\n\n> In d73019feb44 (http: add support selecting http version, 2018-11-08)\n> a dependency was added on CURL_HTTP_VERSION_2_0, but this feature was\n> introduced in curl version 7.43.0, not 7.47.0, as the incorrect\n> version check led us to believe.\n> \n> As looking through the history of that commit on the mailing list will\n> reveal[1], the reason for this is that an earlier version of it\n> depended on CURL_HTTP_VERSION_2TLS, which was introduced in libcurl\n> 7.47.0.\n> \n> But the version that made it in in d73019feb44 had dropped the\n> dependency on CURL_HTTP_VERSION_2TLS, but the corresponding version\n> check was not corrected.\n\nAccording to the curl manpage, if we use CURL_HTTP_VERSION_2_0 instead,\nit goes all the way to 7.33.0. I don't have opinion on whether that's\nworth covering or not.\n\n-Peff\n"},{"id":"435168","messageId":"YTkPfyAYTU4ZgRgb@coredump.intra.peff.net","threadId":"46547","inReplyTo":"patch-4.5-47b513a261b-20210908T152807Z-avarab@gmail.com","subject":"Re: [PATCH 4/5] http: centralize the accounting of libcurl dependencies","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2021-09-08T19:31:11Z","receivedAt":"2021-09-08T19:31:14Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Wed, Sep 08, 2021 at 05:31:55PM +0200, Ævar Arnfjörð Bjarmason wrote:\n\n> As discussed in 644de29e220 (http: drop support for curl < 7.19.4,\n> 2021-07-30) checking against LIBCURL_VERSION_NUM isn't as reliable as\n> checking specific defines in curl, as some distros have been known to\n> backport features. Furthermore as shown in the preceding commit doing\n> these version checks makes for hard to read and possibly buggy code,\n> as shown by the bug fixed there where we were conflating base 10 for\n> base 16 when comparing the version.\n\nJust playing devil's advocate for a moment: we are making the assumption\nhere that curl will use preprocessor macros to implement these constants\n(as opposed to, say, enums). I think that has been historically true,\nbut it is an extra dependency we're adding on curl's internal-ish\ndetails.\n\n> +/**\n> + * CURLOPT_TCP_KEEPALIVE was added in 7.25.0, released in March 2012.\n> + */\n> +#ifdef CURLOPT_TCP_KEEPALIVE\n> +#define GITCURL_HAVE_CURLOPT_TCP_KEEPALIVE 1\n> +#endif\n>\n> [...]\n>\n> -#if LIBCURL_VERSION_NUM >= 0x071900\n> +#ifdef GITCURL_HAVE_CURLOPT_TCP_KEEPALIVE\n>  static void set_curl_keepalive(CURL *c)\n>  {\n>  \tcurl_easy_setopt(c, CURLOPT_TCP_KEEPALIVE, 1);\n\nPart of me is a little sad at the duplication this creates. We could\njust be checking\n\n  #ifdef CURLOPT_TCP_KEEPALIVE\n\nin the second hunk, without the first one at all. That does make it\nharder to see which ones are in use (and we'd still want a comment to\ntake note of the versions). I dunno. I guess having a central-ish\nregistry of these is worth the duplication.\n\n-Peff\n"},{"id":"435170","messageId":"YTkPvSzWKqEIVRDU@coredump.intra.peff.net","threadId":"46547","inReplyTo":"cover-0.5-00000000000-20210908T152807Z-avarab@gmail.com","subject":"Re: [PATCH 0/5] post-v2.33 \"drop support for ancient curl\" follow-up","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2021-09-08T19:32:13Z","receivedAt":"2021-09-08T19:32:15Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Wed, Sep 08, 2021 at 05:31:51PM +0200, Ævar Arnfjörð Bjarmason wrote:\n\n> This is a follow-up to the already-integrated topic for dropping\n> support for older curl versions submitted before the v2.33 release[1].\n> \n> No verions become unsupported in this topic, this is a mere clean-up.\n> \n> There were a couple of cases where we either already dropped support\n> for something, but got the curl version wrong in a macro comparison,\n> or just got the version wrong. That's now corrected.\n> \n> But more importantly this introduces a git-curl-compat.h header which\n> centarlizes all our curl version dependencies, and any compatability\n> shims we've got to deal with those versions. This makes the code much\n> easier to read and maintain than inline LIBCURL_VERSION_NUM version\n> comparisons, and will make any future dropping of supported curl\n> versions in the future easier to perform & review.\n\nThese all seem fine to me. I left a few comments that are mostly\nthinking out loud, not really asking for any changes.\n\n-Peff\n"},{"id":"435283","messageId":"xmqq5yv91wbn.fsf@gitster.g","threadId":"46547","inReplyTo":"YTkPfyAYTU4ZgRgb@coredump.intra.peff.net","subject":"Re: [PATCH 4/5] http: centralize the accounting of libcurl dependencies","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2021-09-09T17:40:44Z","receivedAt":"2021-09-09T17:40:47Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Jeff King <peff@peff.net> writes:\n\n>> +/**\n>> + * CURLOPT_TCP_KEEPALIVE was added in 7.25.0, released in March 2012.\n>> + */\n>> +#ifdef CURLOPT_TCP_KEEPALIVE\n>> +#define GITCURL_HAVE_CURLOPT_TCP_KEEPALIVE 1\n>> +#endif\n>>\n>> [...]\n>>\n>> -#if LIBCURL_VERSION_NUM >= 0x071900\n>> +#ifdef GITCURL_HAVE_CURLOPT_TCP_KEEPALIVE\n>>  static void set_curl_keepalive(CURL *c)\n>>  {\n>>  \tcurl_easy_setopt(c, CURLOPT_TCP_KEEPALIVE, 1);\n>\n> Part of me is a little sad at the duplication this creates. We could\n> just be checking\n>\n>   #ifdef CURLOPT_TCP_KEEPALIVE\n>\n> in the second hunk, without the first one at all.\n\nI recall having exactly the same reaction when the above pattern\nfirst was floated.  \n\nI still do not see how the GITCURL_* duplication is worth it.  What\ndo we want to gain from having a \"central registry\"?\n\nIf it is to see which ones we care about, would it be sufficient to\nuse the hits from \"git grep -e CURL\" with postprocessing?\n\nThanks.\n"},{"id":"435314","messageId":"YTpf7yC+32LYRC4Z@coredump.intra.peff.net","threadId":"46547","inReplyTo":"xmqq5yv91wbn.fsf@gitster.g","subject":"Re: [PATCH 4/5] http: centralize the accounting of libcurl dependencies","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2021-09-09T19:26:39Z","receivedAt":"2021-09-09T19:26:42Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Thu, Sep 09, 2021 at 10:40:44AM -0700, Junio C Hamano wrote:\n\n> > Part of me is a little sad at the duplication this creates. We could\n> > just be checking\n> >\n> >   #ifdef CURLOPT_TCP_KEEPALIVE\n> >\n> > in the second hunk, without the first one at all.\n> \n> I recall having exactly the same reaction when the above pattern\n> first was floated.  \n> \n> I still do not see how the GITCURL_* duplication is worth it.  What\n> do we want to gain from having a \"central registry\"?\n> \n> If it is to see which ones we care about, would it be sufficient to\n> use the hits from \"git grep -e CURL\" with postprocessing?\n\nJust brain-storming:\n\n  - It's probably a little easier to read, with the comments all\n    together with the definitions (keeping in mind that some of these\n    flags may need to be checked in several spots).\n\n  - Likewise a few of the checks are non-trivial, with multiple ANDs, so\n    it may be nicer to have a single registry (though the resulting\n    \"GIT_CURL_HAVE_X_and_Y_and_Z\" are pretty ugly to me).\n\n  - _Possibly_ it provides a knob for the user to say\n    \"-DGIT_CURL_HAVE_FOO=1\" by overriding our auto-detection. But since\n    most of these are \"do we have FOO defined? Because are about to\n    reference it in the code\", I don't see what that override would buy\n    you.\n\nI dunno. I admit that I do not overly care that much. Handling curl\nversion dependencies was neglected for many years. If Ævar wants to take\na more active role in handling these and this is convenient for him, I'm\nhappy enough however it works.\n\n-Peff\n"},{"id":"435342","messageId":"xmqq35qdxso0.fsf@gitster.g","threadId":"46547","inReplyTo":"patch-1.5-3ffa2f491dd-20210908T152807Z-avarab@gmail.com","subject":"Re: [PATCH 1/5] http: drop support for curl < 7.18.0 (again)","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2021-09-09T22:58:39Z","receivedAt":"2021-09-09T22:58:45Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Ævar Arnfjörð Bjarmason  <avarab@gmail.com> writes:\n\n> In 644de29e220 (http: drop support for curl < 7.19.4, 2021-07-30) we\n> dropped support for curl < 7.19.4, so we can drop support for this\n> non-obvious dependency on curl < 7.18.0.\n\nWill queue; this one is obviously correct.\n"},{"id":"435345","messageId":"xmqqv939wdgl.fsf@gitster.g","threadId":"46547","inReplyTo":"YTkNdGk28UJnSDVt@coredump.intra.peff.net","subject":"Re: [PATCH 2/5] http: correct curl version check for CURLOPT_PINNEDPUBLICKEY","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2021-09-09T23:12:26Z","receivedAt":"2021-09-09T23:12:31Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Jeff King <peff@peff.net> writes:\n\n> On Wed, Sep 08, 2021 at 05:31:53PM +0200, Ævar Arnfjörð Bjarmason wrote:\n>\n>> In aeff8a61216 (http: implement public key pinning, 2016-02-15) a\n>> dependency and warning() was added if curl older than 7.44.0 was used,\n>> but the relevant code depended on CURLOPT_PINNEDPUBLICKEY, introduced\n>> in 7.39.0.\n>\n> According to the manpage for CURLOPT_PINNEDPUBLICKEY, it looks like\n> support for various formats and implementations was phased in. In\n> particular, 7.44.0 picked up sha256 support (I guess for a fingerprint?\n> I've never used this feature) for most major implementations.\n>\n> But in terms of compiling, all we care about is that the constant is\n> there. So I think the cutoff point you found is what we want. Presumably\n> when the file format isn't supported we'd get some error, though it's\n> not clear if that would come during the actual curl_*_perform(), or if\n> we should be checking the curl_easy_setopt() result.\n\nIf we were evaluating a patch to add support for pinnedpublickey\nafresh back in, say, 2017, perhaps we cared enough about the\ndistinction between 7.39 and 7.44 (Nov 2014 and Aug 2015,\nrespectively), but I'd say cut-off at 7.44 for this, once it is\nwritten and committed in our codebase, is good enough for us.\n\nIf the code originally had cut-off at 7.39 and we were raising the\nfloor to 7.44 with \"sha256 weren't usable before that version\" as\nthe justification, it would be a totally different situation and it\nmay be worth the code change, but I am not sure if going backwards\nis worth it.\n\nSo, I dunno.\n\nThanks.\n"},{"id":"435346","messageId":"xmqqr1dxwdbu.fsf@gitster.g","threadId":"46547","inReplyTo":"patch-5.5-4f42c0e48b0-20210908T152807Z-avarab@gmail.com","subject":"Re: [PATCH 5/5] http: don't hardcode the value of CURL_SOCKOPT_OK","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2021-09-09T23:15:17Z","receivedAt":"2021-09-09T23:15:24Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Ævar Arnfjörð Bjarmason  <avarab@gmail.com> writes:\n\n> +/**\n> + * CURL_SOCKOPT_OK was added in 7.21.5, released in April 2011.\n> + */\n> +#ifndef CURL_SOCKOPT_OK\n> +#define CURL_SOCKOPT_OK 0\n> +#endif\n> +\n>  /**\n>   * CURLOPT_TCP_KEEPALIVE was added in 7.25.0, released in March 2012.\n>   */\n> diff --git a/http.c b/http.c\n> index e38fcc34d64..c40439d39ce 100644\n> --- a/http.c\n> +++ b/http.c\n> @@ -533,7 +533,7 @@ static int sockopt_callback(void *client, curl_socket_t fd, curlsocktype type)\n>  \tif (rc < 0)\n>  \t\twarning_errno(\"unable to set SO_KEEPALIVE on socket\");\n>  \n> -\treturn 0; /* CURL_SOCKOPT_OK only exists since curl 7.21.5 */\n> +\treturn CURL_SOCKOPT_OK;\n>  }\n\nThis is much better than the one in the previous round where an\nextra CPP macro with GIT_CURL_SOCKOPT_OK_AVAILABLE or some other\nname was used to conditionally return 0 or CURL_SOCKOPT_OK.\n"},{"id":"435347","messageId":"xmqqmtolwczv.fsf@gitster.g","threadId":"46547","inReplyTo":"xmqqr1dxwdbu.fsf@gitster.g","subject":"Re: [PATCH 5/5] http: don't hardcode the value of CURL_SOCKOPT_OK","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2021-09-09T23:22:28Z","receivedAt":"2021-09-09T23:22:34Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Junio C Hamano <gitster@pobox.com> writes:\n\n> Ævar Arnfjörð Bjarmason  <avarab@gmail.com> writes:\n>\n>> +/**\n>> + * CURL_SOCKOPT_OK was added in 7.21.5, released in April 2011.\n>> + */\n>> +#ifndef CURL_SOCKOPT_OK\n>> +#define CURL_SOCKOPT_OK 0\n>> +#endif\n>> +\n>>  /**\n>>   * CURLOPT_TCP_KEEPALIVE was added in 7.25.0, released in March 2012.\n>>   */\n>> diff --git a/http.c b/http.c\n>> index e38fcc34d64..c40439d39ce 100644\n>> --- a/http.c\n>> +++ b/http.c\n>> @@ -533,7 +533,7 @@ static int sockopt_callback(void *client, curl_socket_t fd, curlsocktype type)\n>>  \tif (rc < 0)\n>>  \t\twarning_errno(\"unable to set SO_KEEPALIVE on socket\");\n>>  \n>> -\treturn 0; /* CURL_SOCKOPT_OK only exists since curl 7.21.5 */\n>> +\treturn CURL_SOCKOPT_OK;\n>>  }\n>\n> This is much better than the one in the previous round where an\n> extra CPP macro with GIT_CURL_SOCKOPT_OK_AVAILABLE or some other\n> name was used to conditionally return 0 or CURL_SOCKOPT_OK.\n\nI hit <send> a bit too early.\n\nBecause the git-curl-compat.h header file is primarily to hold the\nGIT_CURL_HAVE_CURL_BLAH CPP macros, the fallback definition of\nCURL_SOCKOPT_OK added by this patch looks somewhat out of place.\nDoing so in http.c would be perfectly OK, though.\n\n"},{"id":"435384","messageId":"patch-v2-1.8-ac11cf8cfd1-20210910T105523Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-v2-0.8-00000000000-20210910T105523Z-avarab@gmail.com","subject":"[PATCH v2 1/8] INSTALL: don't mention the \"curl\" executable at all","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-09-10T11:04:26Z","receivedAt":"2021-09-10T11:04:41Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"In 1d53f90ed97 (The \"curl\" executable is no longer required,\n2008-06-15) the wording for requiring curl(1) was changed to the\ncurrent \"you might also want...\".\n\nMentioning the \"curl\" executable at all is just confusing, someone\nbuilding git might want to use it to debug things, but they might also\njust use wget(1) or some other http client. The \"curl\" executable has\nthe advantage that you might be able to e.g. reproduce a bug in git's\nusage of libcurl with it, but anyone going to those extents is\nunlikely to be aided by this note in INSTALL.\n\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n INSTALL | 10 +++++-----\n 1 file changed, 5 insertions(+), 5 deletions(-)\n\ndiff --git a/INSTALL b/INSTALL\nindex 66389ce0591..5c6ecf03c27 100644\n--- a/INSTALL\n+++ b/INSTALL\n@@ -139,11 +139,11 @@ Issues of note:\n \t  (PPC_SHA1).\n \n \t- \"libcurl\" library is used by git-http-fetch, git-fetch, and, if\n-\t  the curl version >= 7.34.0, for git-imap-send.  You might also\n-\t  want the \"curl\" executable for debugging purposes. If you do not\n-\t  use http:// or https:// repositories, and do not want to put\n-\t  patches into an IMAP mailbox, you do not have to have them\n-\t  (use NO_CURL).\n+\t  the curl version >= 7.34.0, for git-imap-send.\n+\n+\t  If you do not use http:// or https:// repositories, and do\n+\t  not want to put patches into an IMAP mailbox, you do not\n+\t  have to have them (use NO_CURL).\n \n \t- \"expat\" library; git-http-push uses it for remote lock\n \t  management over DAV.  Similar to \"curl\" above, this is optional\n-- \n2.33.0.873.g125ff7b9940\n\n"},{"id":"435385","messageId":"cover-v2-0.8-00000000000-20210910T105523Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-0.5-00000000000-20210908T152807Z-avarab@gmail.com","subject":"[PATCH v2 0/8] post-v2.33 \"drop support for ancient curl\" follow-up","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-09-10T11:04:25Z","receivedAt":"2021-09-10T11:04:42Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"This is a follow-up to the already-integrated topic for dropping\nsupport for older curl versions submitted before the v2.33 release[1].\n\nVersion 1 of this had a really bad bug where we'd effectively make all\nsupported curl versions act like 7.19.4, i.e. the oldest supported\nversion except for a couple of our supported features. This is because\nmost of the things checked with the \"ifdef\" checks are enum fields,\nnot macros. So basically the \"devil's advocate\" Jeff King pointed out\nin [2] was already the case. Oops!\n\nIn this v2 we're instead checking LIBCURL_VERSION_NUM consistently,\neven in those cases where we are checking things that are defined via\nmacros.\n\nThis means that anyone on an older distro with backported features\nwill need to -DGIT_CURL_HAVE_* if their version of curl supports some\nof these via a backport, not ideal, but an acceptable trade-off. If we\ncared about this we could have some \"detect-curl\" script similar to my\nproposed \"detect-compiler\"[3] (or another homegrown autoconf\nreplacement).\n\nThis also corrects commit messages, removes already-dead code from the\nMakefile that we'd missed, and mentions the oldest supported version\nin the INSTALL document.\n\nThe part where we left behind a potentially warning \"ssl_pinnedkey\"\nvariable is also gone, although due to another bug in v1 we'd\nunconditionally use it (for config) with the \"centralize the\naccounting\" change there.\n\n1. https://lore.kernel.org/git/cover-v4-0.5-00000000000-20210730T175650Z-avarab@gmail.com/ [1]\n2. http://lore.kernel.org/git/YTkPfyAYTU4ZgRgb@coredump.intra.peff.net\n3. https://lore.kernel.org/git/87bl6aypke.fsf@evledraar.gmail.com/\n\nÆvar Arnfjörð Bjarmason (8):\n  INSTALL: don't mention the \"curl\" executable at all\n  INSTALL: mention that we need libcurl 7.19.4 or newer to build\n  Makefile: drop support for curl < 7.9.8 (again)\n  http: drop support for curl < 7.18.0 (again)\n  http: correct version check for CURL_HTTP_VERSION_2\n  http: correct curl version check for CURLOPT_PINNEDPUBLICKEY\n  http: centralize the accounting of libcurl dependencies\n  http: don't hardcode the value of CURL_SOCKOPT_OK\n\n INSTALL           |  13 +++--\n Makefile          |  11 +---\n git-curl-compat.h | 133 ++++++++++++++++++++++++++++++++++++++++++++++\n http.c            |  35 ++++++------\n imap-send.c       |   2 +-\n 5 files changed, 161 insertions(+), 33 deletions(-)\n create mode 100644 git-curl-compat.h\n\nRange-diff against v1:\n-:  ----------- > 1:  ac11cf8cfd1 INSTALL: don't mention the \"curl\" executable at all\n-:  ----------- > 2:  4b653cee2d3 INSTALL: mention that we need libcurl 7.19.4 or newer to build\n-:  ----------- > 3:  76c2aa6e78d Makefile: drop support for curl < 7.9.8 (again)\n1:  3ffa2f491dd = 4:  e73a9ff1780 http: drop support for curl < 7.18.0 (again)\n3:  d8192164937 ! 5:  2567b888c3d http: correct version check for CURL_HTTP_VERSION_2_0\n    @@ Metadata\n     Author: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n     \n      ## Commit message ##\n    -    http: correct version check for CURL_HTTP_VERSION_2_0\n    +    http: correct version check for CURL_HTTP_VERSION_2\n     \n         In d73019feb44 (http: add support selecting http version, 2018-11-08)\n    -    a dependency was added on CURL_HTTP_VERSION_2_0, but this feature was\n    +    a dependency was added on CURL_HTTP_VERSION_2, but this feature was\n         introduced in curl version 7.43.0, not 7.47.0, as the incorrect\n         version check led us to believe.\n     \n    @@ Commit message\n         dependency on CURL_HTTP_VERSION_2TLS, but the corresponding version\n         check was not corrected.\n     \n    +    The newest symbol we depend on is CURL_HTTP_VERSION_2. It was added in\n    +    7.33.0, but the CURL_HTTP_VERSION_2 alias we used was added in\n    +    7.47.0. So we could support an even older version here, but let's just\n    +    correct the checked version.\n    +\n         1. https://lore.kernel.org/git/pull.69.git.gitgitgadget@gmail.com/\n     \n         Signed-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n2:  511534ce17a ! 6:  397d54a1352 http: correct curl version check for CURLOPT_PINNEDPUBLICKEY\n    @@ Commit message\n         but the relevant code depended on CURLOPT_PINNEDPUBLICKEY, introduced\n         in 7.39.0.\n     \n    -    Let's also remove the macro check before we declare the ssl_pinnedkey\n    -    variable, the pattern for other such variables is to declare the\n    -    static variable unconditionally, we just may not use it on older\n    -    versions. This reduces macro verbosity.\n    -\n    -    The reduction in verbosity comes at the small cost of issuing a\n    -    warning about the unused variable if this code is compiled with curl\n    -    versions older than 7.39.0. I think that's an acceptable trade-off,\n    -    anyone compiling a new git with a 2014-era toolchain likely has at\n    -    least other warning that'll have prompted them not to use -Werror, and\n    -    if not maybe this'll prompt them to compile their new git with a more\n    -    modern libcurl.\n    -\n         Signed-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n     \n      ## http.c ##\n    @@ http.c: static struct {\n      static const char *ssl_capath;\n      static const char *curl_no_proxy;\n     -#if LIBCURL_VERSION_NUM >= 0x072c00\n    ++#if LIBCURL_VERSION_NUM >= 0x072700\n      static const char *ssl_pinnedkey;\n    --#endif\n    + #endif\n      static const char *ssl_cainfo;\n    - static long curl_low_speed_limit = -1;\n    - static long curl_low_speed_time = -1;\n     @@ http.c: static int http_options(const char *var, const char *value, void *cb)\n      \t}\n      \n4:  47b513a261b ! 7:  8e57a8409c5 http: centralize the accounting of libcurl dependencies\n    @@ Commit message\n     \n         As discussed in 644de29e220 (http: drop support for curl < 7.19.4,\n         2021-07-30) checking against LIBCURL_VERSION_NUM isn't as reliable as\n    -    checking specific defines in curl, as some distros have been known to\n    -    backport features. Furthermore as shown in the preceding commit doing\n    -    these version checks makes for hard to read and possibly buggy code,\n    -    as shown by the bug fixed there where we were conflating base 10 for\n    -    base 16 when comparing the version.\n    +    checking specific symbols present in curl, as some distros have been\n    +    known to backport features.\n     \n    -    Let's instead add a new git-curl-compat.h header that'll keep track of\n    -    these dependencies. Following this pattern will also make it much\n    -    easier to track when we should deprecate curl versions in the future,\n    -    as we just did post-v2.33 e48a623dea0 (Merge branch\n    -    'ab/http-drop-old-curl', 2021-08-24).\n    +    However, while some of the curl_easy_setopt() arguments we rely on are\n    +    macros, others are enum, and we can't assume that those that are\n    +    macros won't change into enums in the future.\n    +\n    +    So we're still going to have to check LIBCURL_VERSION_NUM, but by\n    +    doing that in one central place and using a macro definition of our\n    +    own, anyone who's backporting features can define it themselves, and\n    +    thus have access to more modern curl features that they backported,\n    +    even if they didn't bump the LIBCURL_VERSION_NUM.\n    +\n    +    More importantly, as shown in a preceding commit doing these version\n    +    checks makes for hard to read and possibly buggy code, as shown by the\n    +    bug fixed there where we were conflating base 10 for base 16 when\n    +    comparing the version.\n    +\n    +    By doing them all in one place we'll hopefully reduce the chances of\n    +    such future mistakes, furthermore it now becomes easier to see at a\n    +    glance what the oldest supported version is, which makes it easier to\n    +    reason about any future deprecation similar to the recent\n    +    e48a623dea0 (Merge branch 'ab/http-drop-old-curl', 2021-08-24).\n     \n         Signed-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n     \n    @@ git-curl-compat.h (new)\n     @@\n     +#ifndef GIT_CURL_COMPAT_H\n     +#define GIT_CURL_COMPAT_H\n    ++#include <curl/curl.h>\n     +\n     +/**\n     + * This header centralizes the declaration of our libcurl dependencies\n    @@ git-curl-compat.h (new)\n     + * inform decisions about removing support for older libcurl in the\n     + * future.\n     + *\n    ++ * The oldest supported version of curl is documented in the \"INSTALL\"\n    ++ * document.\n    ++ *\n     + * The source of truth for what versions have which symbols is\n     + * https://github.com/curl/curl/blob/master/docs/libcurl/symbols-in-versions;\n     + * the release dates are taken from curl.git (at\n     + * https://github.com/curl/curl/).\n     + *\n    -+ * For each X symbol we need from curl we check if it exists and\n    -+ * declare our own GIT_CURL_HAVE_X, or if it's for both X and Y\n    -+ * GIT_CURL_HAVE_X_and_Y, where the \"Y\" in \"X_and_Y\" is only the part\n    -+ * of the symbol name that \"X\" and \"Y\" don't have in common.\n    -+ *\n    -+ * We avoid comparisons against LIBCURL_VERSION_NUM, enterprise\n    -+ * distros have been known to backport symbols to their older curl\n    -+ * versions.\n    ++ * For each X symbol we need from curl we define our own\n    ++ * GIT_CURL_HAVE_X. If multiple similar symbols with the same prefix\n    ++ * were defined in the same version we pick one and check for that name.\n     + *\n     + * Keep any symbols in date order of when their support was\n     + * introduced, oldest first, in the official version of cURL library.\n    @@ git-curl-compat.h (new)\n     +/**\n     + * CURLOPT_TCP_KEEPALIVE was added in 7.25.0, released in March 2012.\n     + */\n    -+#ifdef CURLOPT_TCP_KEEPALIVE\n    ++#if LIBCURL_VERSION_NUM >= 0x071900\n     +#define GITCURL_HAVE_CURLOPT_TCP_KEEPALIVE 1\n     +#endif\n     +\n    @@ git-curl-compat.h (new)\n     +/**\n     + * CURLOPT_LOGIN_OPTIONS was added in 7.34.0, released in December\n     + * 2013.\n    ++ *\n    ++ * If we start requiring 7.34.0 we might also be able to remove the\n    ++ * code conditional on USE_CURL_FOR_IMAP_SEND in imap-send.c, see\n    ++ * 1e16b255b95 (git-imap-send: use libcurl for implementation,\n    ++ * 2014-11-09) and the check it added for \"072200\" in the Makefile.\n    ++\n     + */\n    -+#ifdef CURLOPT_LOGIN_OPTIONS\n    ++#if LIBCURL_VERSION_NUM >= 0x072200\n     +#define GIT_CURL_HAVE_CURLOPT_LOGIN_OPTIONS 1\n     +#endif\n     +\n    @@ git-curl-compat.h (new)\n     + * CURL_SSLVERSION_TLSv1_[012] was added in 7.34.0, released in\n     + * December 2013.\n     + */\n    -+#if defined(CURL_SSLVERSION_TLSv1_0) && \\\n    -+    defined(CURL_SSLVERSION_TLSv1_1) && \\\n    -+    defined(CURL_SSLVERSION_TLSv1_2)\n    -+#define GIT_CURL_HAVE_CURL_SSLVERSION_TLSv1_0_and_1_and_2\n    ++#if LIBCURL_VERSION_NUM >= 0x072200\n    ++#define GIT_CURL_HAVE_CURL_SSLVERSION_TLSv1_0\n     +#endif\n     +\n     +/**\n     + * CURLOPT_PINNEDPUBLICKEY was added in 7.39.0, released in November\n     + * 2014.\n     + */\n    -+#ifdef CURLOPT_PINNEDPUBLICKEY\n    ++#if LIBCURL_VERSION_NUM >= 0x072c00\n     +#define GIT_CURL_HAVE_CURLOPT_PINNEDPUBLICKEY 1\n     +#endif\n     +\n     +/**\n     + * CURL_HTTP_VERSION_2 was added in 7.43.0, released in June 2015.\n    ++ *\n    ++ * The CURL_HTTP_VERSION_2 alias (but not CURL_HTTP_VERSION_2_0) has\n    ++ * always been a macro, not an enum field (checked on curl version\n    ++ * 7.78.0)\n     + */\n    -+#ifdef CURL_HTTP_VERSION_2\n    ++#if LIBCURL_VERSION_NUM >= 0x072b00\n     +#define GIT_CURL_HAVE_CURL_HTTP_VERSION_2 1\n     +#endif\n     +\n     +/**\n     + * CURLSSLOPT_NO_REVOKE was added in 7.44.0, released in August 2015.\n    ++ *\n    ++ * The CURLSSLOPT_NO_REVOKE is, has always been a macro, not an enum\n    ++ * field (checked on curl version 7.78.0)\n     + */\n    -+#ifdef CURLSSLOPT_NO_REVOKE\n    ++#if LIBCURL_VERSION_NUM >= 0x072c00\n     +#define GIT_CURL_HAVE_CURLSSLOPT_NO_REVOKE 1\n     +#endif\n     +\n     +/**\n     + * CURLOPT_PROXY_CAINFO was added in 7.52.0, released in August 2017.\n     + */\n    -+#ifdef CURLOPT_PROXY_CAINFO\n    ++#if LIBCURL_VERSION_NUM >= 0x073400\n     +#define GIT_CURL_HAVE_CURLOPT_PROXY_CAINFO 1\n     +#endif\n     +\n    @@ git-curl-compat.h (new)\n     + * CURLOPT_PROXY_{KEYPASSWD,SSLCERT,SSLKEY} was added in 7.52.0,\n     + * released in August 2017.\n     + */\n    -+#if defined(CURLOPT_PROXY_KEYPASSWD) && \\\n    -+    defined(CURLOPT_PROXY_SSLCERT) && \\\n    -+    defined(CURLOPT_PROXY_SSLKEY)\n    -+#define GIT_CURL_HAVE_CURLOPT_PROXY_KEYPASSWD_and_SSLCERT_and_SSLKEY 1\n    ++#if LIBCURL_VERSION_NUM >= 0x073400\n    ++#define GIT_CURL_HAVE_CURLOPT_PROXY_KEYPASSWD 1\n     +#endif\n     +\n     +/**\n     + * CURL_SSLVERSION_TLSv1_3 was added in 7.53.0, released in February\n     + * 2017.\n     + */\n    -+#ifdef CURL_SSLVERSION_TLSv1_3\n    ++#if LIBCURL_VERSION_NUM >= 0x073400\n     +#define GIT_CURL_HAVE_CURL_SSLVERSION_TLSv1_3 1\n     +#endif\n     +\n    @@ git-curl-compat.h (new)\n     + * CURLSSLSET_{NO_BACKENDS,OK,TOO_LATE,UNKNOWN_BACKEND} were added in\n     + * 7.56.0, released in September 2017.\n     + */\n    -+#if defined(CURLSSLSET_NO_BACKENDS) && \\\n    -+    defined(CURLSSLSET_OK) && \\\n    -+    defined(CURLSSLSET_TOO_LATE) && \\\n    -+    defined(CURLSSLSET_UNKNOWN_BACKEND)\n    -+#define GIT_CURL_HAVE_CURLSSLSET_NO_BACKENDS_and_OK_and_TOO_LATE_and_UNKNOWN_BACKEND 1\n    ++#if LIBCURL_VERSION_NUM >= 0x073800\n    ++#define GIT_CURL_HAVE_CURLSSLSET_NO_BACKENDS\n     +#endif\n     +\n     +#endif\n    @@ http.c: static struct {\n      \t{ \"sslv3\", CURL_SSLVERSION_SSLv3 },\n      \t{ \"tlsv1\", CURL_SSLVERSION_TLSv1 },\n     -#if LIBCURL_VERSION_NUM >= 0x072200\n    -+#if GIT_CURL_HAVE_CURL_SSLVERSION_TLSv1_0_AND_1_AND_2\n    ++#ifdef GIT_CURL_HAVE_CURL_SSLVERSION_TLSv1_0\n      \t{ \"tlsv1.0\", CURL_SSLVERSION_TLSv1_0 },\n      \t{ \"tlsv1.1\", CURL_SSLVERSION_TLSv1_1 },\n      \t{ \"tlsv1.2\", CURL_SSLVERSION_TLSv1_2 },\n      #endif\n     -#if LIBCURL_VERSION_NUM >= 0x073400\n    -+#if GIT_CURL_HAVE_CURL_SSLVERSION_TLSv1_3\n    ++#ifdef GIT_CURL_HAVE_CURL_SSLVERSION_TLSv1_3\n      \t{ \"tlsv1.3\", CURL_SSLVERSION_TLSv1_3 },\n      #endif\n      };\n    + static const char *ssl_key;\n    + static const char *ssl_capath;\n    + static const char *curl_no_proxy;\n    +-#if LIBCURL_VERSION_NUM >= 0x072700\n    ++#ifdef GIT_CURL_HAVE_CURLOPT_PINNEDPUBLICKEY\n    + static const char *ssl_pinnedkey;\n    + #endif\n    + static const char *ssl_cainfo;\n     @@ http.c: static int http_options(const char *var, const char *value, void *cb)\n      \t}\n      \n      \tif (!strcmp(\"http.pinnedpubkey\", var)) {\n     -#if LIBCURL_VERSION_NUM >= 0x072700\n    --\t\treturn git_config_pathname(&ssl_pinnedkey, var, value);\n    --#else\n    -+#ifndef GIT_CURL_HAVE_CURLOPT_PINNEDPUBLICKEY\n    ++#ifdef GIT_CURL_HAVE_CURLOPT_PINNEDPUBLICKEY\n    + \t\treturn git_config_pathname(&ssl_pinnedkey, var, value);\n    + #else\n      \t\twarning(_(\"Public key pinning not supported with cURL < 7.39.0\"));\n    --\t\treturn 0;\n    - #endif\n    -+\t\treturn git_config_pathname(&ssl_pinnedkey, var, value);\n    - \t}\n    - \n    - \tif (!strcmp(\"http.extraheader\", var)) {\n     @@ http.c: static int has_cert_password(void)\n      \treturn 1;\n      }\n      \n     -#if LIBCURL_VERSION_NUM >= 0x073400\n    -+#ifdef GIT_CURL_HAVE_CURLOPT_PROXY_KEYPASSWD_and_SSLCERT_and_SSLKEY\n    ++#ifdef GIT_CURL_HAVE_CURLOPT_PROXY_KEYPASSWD\n      static int has_proxy_cert_password(void)\n      {\n      \tif (http_proxy_ssl_cert == NULL || proxy_ssl_cert_password_required != 1)\n    @@ http.c: static CURL *get_curl_handle(void)\n      \t\t\tcurl_easy_setopt(result,\n      \t\t\t\tCURLOPT_PROXYTYPE, CURLPROXY_SOCKS4);\n     -#if LIBCURL_VERSION_NUM >= 0x073400\n    -+#ifdef GIT_CURL_HAVE_CURLOPT_PROXY_KEYPASSWD_and_SSLCERT_and_SSLKEY\n    ++#ifdef GIT_CURL_HAVE_CURLOPT_PROXY_KEYPASSWD\n      \t\telse if (starts_with(curl_http_proxy, \"https\")) {\n      \t\t\tcurl_easy_setopt(result, CURLOPT_PROXYTYPE, CURLPROXY_HTTPS);\n      \n    @@ http.c: void http_init(struct remote *remote, const char *url, int proactive_aut\n      \tstring_list_clear(&config.vars, 1);\n      \n     -#if LIBCURL_VERSION_NUM >= 0x073800\n    -+#ifdef GIT_CURL_HAVE_CURLSSLSET_NO_BACKENDS_and_OK_and_TOO_LATE_and_UNKNOWN_BACKEND\n    ++#ifdef GIT_CURL_HAVE_CURLSSLSET_NO_BACKENDS\n      \tif (http_ssl_backend) {\n      \t\tconst curl_ssl_backend **backends;\n      \t\tstruct strbuf buf = STRBUF_INIT;\n5:  4f42c0e48b0 ! 8:  465ab33ebda http: don't hardcode the value of CURL_SOCKOPT_OK\n    @@ Commit message\n     \n      ## git-curl-compat.h ##\n     @@\n    -  * GIT_CURL_HAVE_X_and_Y, where the \"Y\" in \"X_and_Y\" is only the part\n    -  * of the symbol name that \"X\" and \"Y\" don't have in common.\n    +  * GIT_CURL_HAVE_X. If multiple similar symbols with the same prefix\n    +  * were defined in the same version we pick one and check for that name.\n       *\n     + * We may also define a missing CURL_* symbol to its known value, if\n     + * doing so is sufficient to add support for it to older versions that\n     + * don't have it.\n     + *\n    -  * We avoid comparisons against LIBCURL_VERSION_NUM, enterprise\n    -  * distros have been known to backport symbols to their older curl\n    -  * versions.\n    -@@\n    +  * Keep any symbols in date order of when their support was\n       * introduced, oldest first, in the official version of cURL library.\n       */\n      \n     +/**\n     + * CURL_SOCKOPT_OK was added in 7.21.5, released in April 2011.\n    ++ *\n    ++ * This should be safe as CURL_SOCKOPT_OK has always been a macro, not\n    ++ * an enum field (checked on curl version 7.78.0, released on July 19,\n    ++ * 2021). Even if that were to change the value of \"0\" for \"OK\" is\n    ++ * unlikely to change.\n     + */\n     +#ifndef CURL_SOCKOPT_OK\n     +#define CURL_SOCKOPT_OK 0\n-- \n2.33.0.873.g125ff7b9940\n\n"},{"id":"435386","messageId":"patch-v2-2.8-4b653cee2d3-20210910T105523Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-v2-0.8-00000000000-20210910T105523Z-avarab@gmail.com","subject":"[PATCH v2 2/8] INSTALL: mention that we need libcurl 7.19.4 or newer to build","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-09-10T11:04:27Z","receivedAt":"2021-09-10T11:04:44Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"Without NO_CURL=Y we require at least version \"7.19.4\" of libcurl, see\n644de29e220 (http: drop support for curl < 7.19.4, 2021-07-30). Let's\ndocument this in the \"INSTALL\" document.\n\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n INSTALL | 3 +++\n 1 file changed, 3 insertions(+)\n\ndiff --git a/INSTALL b/INSTALL\nindex 5c6ecf03c27..81f3a6cf018 100644\n--- a/INSTALL\n+++ b/INSTALL\n@@ -141,6 +141,9 @@ Issues of note:\n \t- \"libcurl\" library is used by git-http-fetch, git-fetch, and, if\n \t  the curl version >= 7.34.0, for git-imap-send.\n \n+\t  Git version \"7.19.4\" of \"libcurl\" or later to build. This\n+\t  version requirement may be bumped in the future.\n+\n \t  If you do not use http:// or https:// repositories, and do\n \t  not want to put patches into an IMAP mailbox, you do not\n \t  have to have them (use NO_CURL).\n-- \n2.33.0.873.g125ff7b9940\n\n"},{"id":"435387","messageId":"patch-v2-3.8-76c2aa6e78d-20210910T105523Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-v2-0.8-00000000000-20210910T105523Z-avarab@gmail.com","subject":"[PATCH v2 3/8] Makefile: drop support for curl < 7.9.8 (again)","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-09-10T11:04:28Z","receivedAt":"2021-09-10T11:04:45Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"In 1119a15b5c8 (http: drop support for curl < 7.11.1, 2021-07-30)\nsupport for curl versions older than 7.11.1 was removed, and we\ncurrently require at least version 7.19.4, see 644de29e220 (http: drop\nsupport for curl < 7.19.4, 2021-07-30).\n\nIn those changes this Makefile-specific check added in\n0890098780f (Decide whether to build http-push in the Makefile,\n2005-11-18) was missed, now that we're never going to use such an\nancient curl version we don't need to check that we have at least\n7.9.8 here. I have no idea what in http-push.c broke on versions older\nthan that.\n\nThis does not impact \"NO_CURL\" setups, as this is in the \"else\" branch\nafter that check.\n\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n Makefile | 11 ++---------\n 1 file changed, 2 insertions(+), 9 deletions(-)\n\ndiff --git a/Makefile b/Makefile\nindex 429c276058d..378f58b950d 100644\n--- a/Makefile\n+++ b/Makefile\n@@ -1436,15 +1436,8 @@ else\n \tREMOTE_CURL_NAMES = $(REMOTE_CURL_PRIMARY) $(REMOTE_CURL_ALIASES)\n \tPROGRAM_OBJS += http-fetch.o\n \tPROGRAMS += $(REMOTE_CURL_NAMES)\n-\tcurl_check := $(shell (echo 070908; $(CURL_CONFIG) --vernum | sed -e '/^70[BC]/s/^/0/') 2>/dev/null | sort -r | sed -ne 2p)\n-\tifeq \"$(curl_check)\" \"070908\"\n-\t\tifndef NO_EXPAT\n-\t\t\tPROGRAM_OBJS += http-push.o\n-\t\telse\n-\t\t\tEXCLUDED_PROGRAMS += git-http-push\n-\t\tendif\n-\telse\n-\t\tEXCLUDED_PROGRAMS += git-http-push\n+\tifndef NO_EXPAT\n+\t\tPROGRAM_OBJS += http-push.o\n \tendif\n \tcurl_check := $(shell (echo 072200; $(CURL_CONFIG) --vernum | sed -e '/^70[BC]/s/^/0/') 2>/dev/null | sort -r | sed -ne 2p)\n \tifeq \"$(curl_check)\" \"072200\"\n-- \n2.33.0.873.g125ff7b9940\n\n"},{"id":"435388","messageId":"patch-v2-4.8-e73a9ff1780-20210910T105523Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-v2-0.8-00000000000-20210910T105523Z-avarab@gmail.com","subject":"[PATCH v2 4/8] http: drop support for curl < 7.18.0 (again)","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-09-10T11:04:29Z","receivedAt":"2021-09-10T11:04:48Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"In 644de29e220 (http: drop support for curl < 7.19.4, 2021-07-30) we\ndropped support for curl < 7.19.4, so we can drop support for this\nnon-obvious dependency on curl < 7.18.0.\n\nIt's non-obvious because in curl's hex version notation 0x071800 is\nversion 7.24.0, *not* 7.18.0, so at a glance this patch looks\nincorrect.\n\nBut it's correct, because the existing version check being removed\nhere is wrong. The check guards use of the following curl defines:\n\n    CURLPROXY_SOCKS4                7.10\n    CURLPROXY_SOCKS4A               7.18.0\n    CURLPROXY_SOCKS5                7.10\n    CURLPROXY_SOCKS5_HOSTNAME       7.18.0\n\nI.e. the oldest version that has these is in fact 7.18.0, not\n7.24.0. That we were checking 7.24.0 is just an mistake in\n6d7afe07f29 (remote-http(s): support SOCKS proxies, 2015-10-26),\ni.e. its author confusing base 10 and base 16.\n\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n http.c | 2 --\n 1 file changed, 2 deletions(-)\n\ndiff --git a/http.c b/http.c\nindex a0f169d2fe5..56856178bfe 100644\n--- a/http.c\n+++ b/http.c\n@@ -927,7 +927,6 @@ static CURL *get_curl_handle(void)\n \t\t */\n \t\tcurl_easy_setopt(result, CURLOPT_PROXY, \"\");\n \t} else if (curl_http_proxy) {\n-#if LIBCURL_VERSION_NUM >= 0x071800\n \t\tif (starts_with(curl_http_proxy, \"socks5h\"))\n \t\t\tcurl_easy_setopt(result,\n \t\t\t\tCURLOPT_PROXYTYPE, CURLPROXY_SOCKS5_HOSTNAME);\n@@ -940,7 +939,6 @@ static CURL *get_curl_handle(void)\n \t\telse if (starts_with(curl_http_proxy, \"socks\"))\n \t\t\tcurl_easy_setopt(result,\n \t\t\t\tCURLOPT_PROXYTYPE, CURLPROXY_SOCKS4);\n-#endif\n #if LIBCURL_VERSION_NUM >= 0x073400\n \t\telse if (starts_with(curl_http_proxy, \"https\")) {\n \t\t\tcurl_easy_setopt(result, CURLOPT_PROXYTYPE, CURLPROXY_HTTPS);\n-- \n2.33.0.873.g125ff7b9940\n\n"},{"id":"435389","messageId":"patch-v2-5.8-2567b888c3d-20210910T105523Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-v2-0.8-00000000000-20210910T105523Z-avarab@gmail.com","subject":"[PATCH v2 5/8] http: correct version check for CURL_HTTP_VERSION_2","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-09-10T11:04:30Z","receivedAt":"2021-09-10T11:04:49Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"In d73019feb44 (http: add support selecting http version, 2018-11-08)\na dependency was added on CURL_HTTP_VERSION_2, but this feature was\nintroduced in curl version 7.43.0, not 7.47.0, as the incorrect\nversion check led us to believe.\n\nAs looking through the history of that commit on the mailing list will\nreveal[1], the reason for this is that an earlier version of it\ndepended on CURL_HTTP_VERSION_2TLS, which was introduced in libcurl\n7.47.0.\n\nBut the version that made it in in d73019feb44 had dropped the\ndependency on CURL_HTTP_VERSION_2TLS, but the corresponding version\ncheck was not corrected.\n\nThe newest symbol we depend on is CURL_HTTP_VERSION_2. It was added in\n7.33.0, but the CURL_HTTP_VERSION_2 alias we used was added in\n7.47.0. So we could support an even older version here, but let's just\ncorrect the checked version.\n\n1. https://lore.kernel.org/git/pull.69.git.gitgitgadget@gmail.com/\n\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n http.c | 4 ++--\n 1 file changed, 2 insertions(+), 2 deletions(-)\n\ndiff --git a/http.c b/http.c\nindex 56856178bfe..b82b5b7a532 100644\n--- a/http.c\n+++ b/http.c\n@@ -732,7 +732,7 @@ static long get_curl_allowed_protocols(int from_user)\n \treturn allowed_protocols;\n }\n \n-#if LIBCURL_VERSION_NUM >=0x072f00\n+#if LIBCURL_VERSION_NUM >=0x072b00\n static int get_curl_http_version_opt(const char *version_string, long *opt)\n {\n \tint i;\n@@ -774,7 +774,7 @@ static CURL *get_curl_handle(void)\n \t\tcurl_easy_setopt(result, CURLOPT_SSL_VERIFYHOST, 2);\n \t}\n \n-#if LIBCURL_VERSION_NUM >= 0x072f00 // 7.47.0\n+#if LIBCURL_VERSION_NUM >= 0x072b00\n     if (curl_http_version) {\n \t\tlong opt;\n \t\tif (!get_curl_http_version_opt(curl_http_version, &opt)) {\n-- \n2.33.0.873.g125ff7b9940\n\n"},{"id":"435390","messageId":"patch-v2-6.8-397d54a1352-20210910T105523Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-v2-0.8-00000000000-20210910T105523Z-avarab@gmail.com","subject":"[PATCH v2 6/8] http: correct curl version check for CURLOPT_PINNEDPUBLICKEY","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-09-10T11:04:31Z","receivedAt":"2021-09-10T11:04:50Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"In aeff8a61216 (http: implement public key pinning, 2016-02-15) a\ndependency and warning() was added if curl older than 7.44.0 was used,\nbut the relevant code depended on CURLOPT_PINNEDPUBLICKEY, introduced\nin 7.39.0.\n\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n http.c | 8 ++++----\n 1 file changed, 4 insertions(+), 4 deletions(-)\n\ndiff --git a/http.c b/http.c\nindex b82b5b7a532..543faad9879 100644\n--- a/http.c\n+++ b/http.c\n@@ -59,7 +59,7 @@ static struct {\n static const char *ssl_key;\n static const char *ssl_capath;\n static const char *curl_no_proxy;\n-#if LIBCURL_VERSION_NUM >= 0x072c00\n+#if LIBCURL_VERSION_NUM >= 0x072700\n static const char *ssl_pinnedkey;\n #endif\n static const char *ssl_cainfo;\n@@ -373,10 +373,10 @@ static int http_options(const char *var, const char *value, void *cb)\n \t}\n \n \tif (!strcmp(\"http.pinnedpubkey\", var)) {\n-#if LIBCURL_VERSION_NUM >= 0x072c00\n+#if LIBCURL_VERSION_NUM >= 0x072700\n \t\treturn git_config_pathname(&ssl_pinnedkey, var, value);\n #else\n-\t\twarning(_(\"Public key pinning not supported with cURL < 7.44.0\"));\n+\t\twarning(_(\"Public key pinning not supported with cURL < 7.39.0\"));\n \t\treturn 0;\n #endif\n \t}\n@@ -845,7 +845,7 @@ static CURL *get_curl_handle(void)\n \t\tcurl_easy_setopt(result, CURLOPT_SSLKEY, ssl_key);\n \tif (ssl_capath != NULL)\n \t\tcurl_easy_setopt(result, CURLOPT_CAPATH, ssl_capath);\n-#if LIBCURL_VERSION_NUM >= 0x072c00\n+#if LIBCURL_VERSION_NUM >= 0x072700\n \tif (ssl_pinnedkey != NULL)\n \t\tcurl_easy_setopt(result, CURLOPT_PINNEDPUBLICKEY, ssl_pinnedkey);\n #endif\n-- \n2.33.0.873.g125ff7b9940\n\n"},{"id":"435391","messageId":"patch-v2-7.8-8e57a8409c5-20210910T105523Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-v2-0.8-00000000000-20210910T105523Z-avarab@gmail.com","subject":"[PATCH v2 7/8] http: centralize the accounting of libcurl dependencies","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-09-10T11:04:32Z","receivedAt":"2021-09-10T11:04:52Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"As discussed in 644de29e220 (http: drop support for curl < 7.19.4,\n2021-07-30) checking against LIBCURL_VERSION_NUM isn't as reliable as\nchecking specific symbols present in curl, as some distros have been\nknown to backport features.\n\nHowever, while some of the curl_easy_setopt() arguments we rely on are\nmacros, others are enum, and we can't assume that those that are\nmacros won't change into enums in the future.\n\nSo we're still going to have to check LIBCURL_VERSION_NUM, but by\ndoing that in one central place and using a macro definition of our\nown, anyone who's backporting features can define it themselves, and\nthus have access to more modern curl features that they backported,\neven if they didn't bump the LIBCURL_VERSION_NUM.\n\nMore importantly, as shown in a preceding commit doing these version\nchecks makes for hard to read and possibly buggy code, as shown by the\nbug fixed there where we were conflating base 10 for base 16 when\ncomparing the version.\n\nBy doing them all in one place we'll hopefully reduce the chances of\nsuch future mistakes, furthermore it now becomes easier to see at a\nglance what the oldest supported version is, which makes it easier to\nreason about any future deprecation similar to the recent\ne48a623dea0 (Merge branch 'ab/http-drop-old-curl', 2021-08-24).\n\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n git-curl-compat.h | 117 ++++++++++++++++++++++++++++++++++++++++++++++\n http.c            |  29 ++++++------\n imap-send.c       |   2 +-\n 3 files changed, 133 insertions(+), 15 deletions(-)\n create mode 100644 git-curl-compat.h\n\ndiff --git a/git-curl-compat.h b/git-curl-compat.h\nnew file mode 100644\nindex 00000000000..7ad87e89ed5\n--- /dev/null\n+++ b/git-curl-compat.h\n@@ -0,0 +1,117 @@\n+#ifndef GIT_CURL_COMPAT_H\n+#define GIT_CURL_COMPAT_H\n+#include <curl/curl.h>\n+\n+/**\n+ * This header centralizes the declaration of our libcurl dependencies\n+ * to make it easy to discover the oldest versions we support, and to\n+ * inform decisions about removing support for older libcurl in the\n+ * future.\n+ *\n+ * The oldest supported version of curl is documented in the \"INSTALL\"\n+ * document.\n+ *\n+ * The source of truth for what versions have which symbols is\n+ * https://github.com/curl/curl/blob/master/docs/libcurl/symbols-in-versions;\n+ * the release dates are taken from curl.git (at\n+ * https://github.com/curl/curl/).\n+ *\n+ * For each X symbol we need from curl we define our own\n+ * GIT_CURL_HAVE_X. If multiple similar symbols with the same prefix\n+ * were defined in the same version we pick one and check for that name.\n+ *\n+ * Keep any symbols in date order of when their support was\n+ * introduced, oldest first, in the official version of cURL library.\n+ */\n+\n+/**\n+ * CURLOPT_TCP_KEEPALIVE was added in 7.25.0, released in March 2012.\n+ */\n+#if LIBCURL_VERSION_NUM >= 0x071900\n+#define GITCURL_HAVE_CURLOPT_TCP_KEEPALIVE 1\n+#endif\n+\n+\n+/**\n+ * CURLOPT_LOGIN_OPTIONS was added in 7.34.0, released in December\n+ * 2013.\n+ *\n+ * If we start requiring 7.34.0 we might also be able to remove the\n+ * code conditional on USE_CURL_FOR_IMAP_SEND in imap-send.c, see\n+ * 1e16b255b95 (git-imap-send: use libcurl for implementation,\n+ * 2014-11-09) and the check it added for \"072200\" in the Makefile.\n+\n+ */\n+#if LIBCURL_VERSION_NUM >= 0x072200\n+#define GIT_CURL_HAVE_CURLOPT_LOGIN_OPTIONS 1\n+#endif\n+\n+/**\n+ * CURL_SSLVERSION_TLSv1_[012] was added in 7.34.0, released in\n+ * December 2013.\n+ */\n+#if LIBCURL_VERSION_NUM >= 0x072200\n+#define GIT_CURL_HAVE_CURL_SSLVERSION_TLSv1_0\n+#endif\n+\n+/**\n+ * CURLOPT_PINNEDPUBLICKEY was added in 7.39.0, released in November\n+ * 2014.\n+ */\n+#if LIBCURL_VERSION_NUM >= 0x072c00\n+#define GIT_CURL_HAVE_CURLOPT_PINNEDPUBLICKEY 1\n+#endif\n+\n+/**\n+ * CURL_HTTP_VERSION_2 was added in 7.43.0, released in June 2015.\n+ *\n+ * The CURL_HTTP_VERSION_2 alias (but not CURL_HTTP_VERSION_2_0) has\n+ * always been a macro, not an enum field (checked on curl version\n+ * 7.78.0)\n+ */\n+#if LIBCURL_VERSION_NUM >= 0x072b00\n+#define GIT_CURL_HAVE_CURL_HTTP_VERSION_2 1\n+#endif\n+\n+/**\n+ * CURLSSLOPT_NO_REVOKE was added in 7.44.0, released in August 2015.\n+ *\n+ * The CURLSSLOPT_NO_REVOKE is, has always been a macro, not an enum\n+ * field (checked on curl version 7.78.0)\n+ */\n+#if LIBCURL_VERSION_NUM >= 0x072c00\n+#define GIT_CURL_HAVE_CURLSSLOPT_NO_REVOKE 1\n+#endif\n+\n+/**\n+ * CURLOPT_PROXY_CAINFO was added in 7.52.0, released in August 2017.\n+ */\n+#if LIBCURL_VERSION_NUM >= 0x073400\n+#define GIT_CURL_HAVE_CURLOPT_PROXY_CAINFO 1\n+#endif\n+\n+/**\n+ * CURLOPT_PROXY_{KEYPASSWD,SSLCERT,SSLKEY} was added in 7.52.0,\n+ * released in August 2017.\n+ */\n+#if LIBCURL_VERSION_NUM >= 0x073400\n+#define GIT_CURL_HAVE_CURLOPT_PROXY_KEYPASSWD 1\n+#endif\n+\n+/**\n+ * CURL_SSLVERSION_TLSv1_3 was added in 7.53.0, released in February\n+ * 2017.\n+ */\n+#if LIBCURL_VERSION_NUM >= 0x073400\n+#define GIT_CURL_HAVE_CURL_SSLVERSION_TLSv1_3 1\n+#endif\n+\n+/**\n+ * CURLSSLSET_{NO_BACKENDS,OK,TOO_LATE,UNKNOWN_BACKEND} were added in\n+ * 7.56.0, released in September 2017.\n+ */\n+#if LIBCURL_VERSION_NUM >= 0x073800\n+#define GIT_CURL_HAVE_CURLSSLSET_NO_BACKENDS\n+#endif\n+\n+#endif\ndiff --git a/http.c b/http.c\nindex 543faad9879..94eefe97089 100644\n--- a/http.c\n+++ b/http.c\n@@ -1,4 +1,5 @@\n #include \"git-compat-util.h\"\n+#include \"git-curl-compat.h\"\n #include \"http.h\"\n #include \"config.h\"\n #include \"pack.h\"\n@@ -47,19 +48,19 @@ static struct {\n \t{ \"sslv2\", CURL_SSLVERSION_SSLv2 },\n \t{ \"sslv3\", CURL_SSLVERSION_SSLv3 },\n \t{ \"tlsv1\", CURL_SSLVERSION_TLSv1 },\n-#if LIBCURL_VERSION_NUM >= 0x072200\n+#ifdef GIT_CURL_HAVE_CURL_SSLVERSION_TLSv1_0\n \t{ \"tlsv1.0\", CURL_SSLVERSION_TLSv1_0 },\n \t{ \"tlsv1.1\", CURL_SSLVERSION_TLSv1_1 },\n \t{ \"tlsv1.2\", CURL_SSLVERSION_TLSv1_2 },\n #endif\n-#if LIBCURL_VERSION_NUM >= 0x073400\n+#ifdef GIT_CURL_HAVE_CURL_SSLVERSION_TLSv1_3\n \t{ \"tlsv1.3\", CURL_SSLVERSION_TLSv1_3 },\n #endif\n };\n static const char *ssl_key;\n static const char *ssl_capath;\n static const char *curl_no_proxy;\n-#if LIBCURL_VERSION_NUM >= 0x072700\n+#ifdef GIT_CURL_HAVE_CURLOPT_PINNEDPUBLICKEY\n static const char *ssl_pinnedkey;\n #endif\n static const char *ssl_cainfo;\n@@ -373,7 +374,7 @@ static int http_options(const char *var, const char *value, void *cb)\n \t}\n \n \tif (!strcmp(\"http.pinnedpubkey\", var)) {\n-#if LIBCURL_VERSION_NUM >= 0x072700\n+#ifdef GIT_CURL_HAVE_CURLOPT_PINNEDPUBLICKEY\n \t\treturn git_config_pathname(&ssl_pinnedkey, var, value);\n #else\n \t\twarning(_(\"Public key pinning not supported with cURL < 7.39.0\"));\n@@ -500,7 +501,7 @@ static int has_cert_password(void)\n \treturn 1;\n }\n \n-#if LIBCURL_VERSION_NUM >= 0x073400\n+#ifdef GIT_CURL_HAVE_CURLOPT_PROXY_KEYPASSWD\n static int has_proxy_cert_password(void)\n {\n \tif (http_proxy_ssl_cert == NULL || proxy_ssl_cert_password_required != 1)\n@@ -516,7 +517,7 @@ static int has_proxy_cert_password(void)\n }\n #endif\n \n-#if LIBCURL_VERSION_NUM >= 0x071900\n+#ifdef GITCURL_HAVE_CURLOPT_TCP_KEEPALIVE\n static void set_curl_keepalive(CURL *c)\n {\n \tcurl_easy_setopt(c, CURLOPT_TCP_KEEPALIVE, 1);\n@@ -732,7 +733,7 @@ static long get_curl_allowed_protocols(int from_user)\n \treturn allowed_protocols;\n }\n \n-#if LIBCURL_VERSION_NUM >=0x072b00\n+#ifdef GIT_CURL_HAVE_CURL_HTTP_VERSION_2\n static int get_curl_http_version_opt(const char *version_string, long *opt)\n {\n \tint i;\n@@ -774,7 +775,7 @@ static CURL *get_curl_handle(void)\n \t\tcurl_easy_setopt(result, CURLOPT_SSL_VERIFYHOST, 2);\n \t}\n \n-#if LIBCURL_VERSION_NUM >= 0x072b00\n+#ifdef GIT_CURL_HAVE_CURL_HTTP_VERSION_2\n     if (curl_http_version) {\n \t\tlong opt;\n \t\tif (!get_curl_http_version_opt(curl_http_version, &opt)) {\n@@ -805,7 +806,7 @@ static CURL *get_curl_handle(void)\n \n \tif (http_ssl_backend && !strcmp(\"schannel\", http_ssl_backend) &&\n \t    !http_schannel_check_revoke) {\n-#if LIBCURL_VERSION_NUM >= 0x072c00\n+#ifdef GIT_CURL_HAVE_CURLSSLOPT_NO_REVOKE\n \t\tcurl_easy_setopt(result, CURLOPT_SSL_OPTIONS, CURLSSLOPT_NO_REVOKE);\n #else\n \t\twarning(_(\"CURLSSLOPT_NO_REVOKE not supported with cURL < 7.44.0\"));\n@@ -845,20 +846,20 @@ static CURL *get_curl_handle(void)\n \t\tcurl_easy_setopt(result, CURLOPT_SSLKEY, ssl_key);\n \tif (ssl_capath != NULL)\n \t\tcurl_easy_setopt(result, CURLOPT_CAPATH, ssl_capath);\n-#if LIBCURL_VERSION_NUM >= 0x072700\n+#ifdef GIT_CURL_HAVE_CURLOPT_PINNEDPUBLICKEY\n \tif (ssl_pinnedkey != NULL)\n \t\tcurl_easy_setopt(result, CURLOPT_PINNEDPUBLICKEY, ssl_pinnedkey);\n #endif\n \tif (http_ssl_backend && !strcmp(\"schannel\", http_ssl_backend) &&\n \t    !http_schannel_use_ssl_cainfo) {\n \t\tcurl_easy_setopt(result, CURLOPT_CAINFO, NULL);\n-#if LIBCURL_VERSION_NUM >= 0x073400\n+#ifdef GIT_CURL_HAVE_CURLOPT_PROXY_CAINFO\n \t\tcurl_easy_setopt(result, CURLOPT_PROXY_CAINFO, NULL);\n #endif\n \t} else if (ssl_cainfo != NULL || http_proxy_ssl_ca_info != NULL) {\n \t\tif (ssl_cainfo != NULL)\n \t\t\tcurl_easy_setopt(result, CURLOPT_CAINFO, ssl_cainfo);\n-#if LIBCURL_VERSION_NUM >= 0x073400\n+#ifdef GIT_CURL_HAVE_CURLOPT_PROXY_CAINFO\n \t\tif (http_proxy_ssl_ca_info != NULL)\n \t\t\tcurl_easy_setopt(result, CURLOPT_PROXY_CAINFO, http_proxy_ssl_ca_info);\n #endif\n@@ -939,7 +940,7 @@ static CURL *get_curl_handle(void)\n \t\telse if (starts_with(curl_http_proxy, \"socks\"))\n \t\t\tcurl_easy_setopt(result,\n \t\t\t\tCURLOPT_PROXYTYPE, CURLPROXY_SOCKS4);\n-#if LIBCURL_VERSION_NUM >= 0x073400\n+#ifdef GIT_CURL_HAVE_CURLOPT_PROXY_KEYPASSWD\n \t\telse if (starts_with(curl_http_proxy, \"https\")) {\n \t\t\tcurl_easy_setopt(result, CURLOPT_PROXYTYPE, CURLPROXY_HTTPS);\n \n@@ -1004,7 +1005,7 @@ void http_init(struct remote *remote, const char *url, int proactive_auth)\n \tfree(normalized_url);\n \tstring_list_clear(&config.vars, 1);\n \n-#if LIBCURL_VERSION_NUM >= 0x073800\n+#ifdef GIT_CURL_HAVE_CURLSSLSET_NO_BACKENDS\n \tif (http_ssl_backend) {\n \t\tconst curl_ssl_backend **backends;\n \t\tstruct strbuf buf = STRBUF_INIT;\ndiff --git a/imap-send.c b/imap-send.c\nindex 49a5f8aa597..e6090a0346a 100644\n--- a/imap-send.c\n+++ b/imap-send.c\n@@ -1441,7 +1441,7 @@ static CURL *setup_curl(struct imap_server_conf *srvc, struct credential *cred)\n \tcurl_easy_setopt(curl, CURLOPT_PORT, server.port);\n \n \tif (server.auth_method) {\n-#if LIBCURL_VERSION_NUM < 0x072200\n+#ifndef GIT_CURL_HAVE_CURLOPT_LOGIN_OPTIONS\n \t\twarning(\"No LOGIN_OPTIONS support in this cURL version\");\n #else\n \t\tstruct strbuf auth = STRBUF_INIT;\n-- \n2.33.0.873.g125ff7b9940\n\n"},{"id":"435392","messageId":"patch-v2-8.8-465ab33ebda-20210910T105523Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-v2-0.8-00000000000-20210910T105523Z-avarab@gmail.com","subject":"[PATCH v2 8/8] http: don't hardcode the value of CURL_SOCKOPT_OK","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-09-10T11:04:33Z","receivedAt":"2021-09-10T11:04:53Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"Use the new git-curl-compat.h header to define CURL_SOCKOPT_OK to its\nknown value if we're on an older curl version that doesn't have it. It\nwas hardcoded in http.c in a15d069a198 (http: enable keepalive on TCP\nsockets, 2013-10-12).\n\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n git-curl-compat.h | 16 ++++++++++++++++\n http.c            |  2 +-\n 2 files changed, 17 insertions(+), 1 deletion(-)\n\ndiff --git a/git-curl-compat.h b/git-curl-compat.h\nindex 7ad87e89ed5..3d162730aaf 100644\n--- a/git-curl-compat.h\n+++ b/git-curl-compat.h\n@@ -20,10 +20,26 @@\n  * GIT_CURL_HAVE_X. If multiple similar symbols with the same prefix\n  * were defined in the same version we pick one and check for that name.\n  *\n+ * We may also define a missing CURL_* symbol to its known value, if\n+ * doing so is sufficient to add support for it to older versions that\n+ * don't have it.\n+ *\n  * Keep any symbols in date order of when their support was\n  * introduced, oldest first, in the official version of cURL library.\n  */\n \n+/**\n+ * CURL_SOCKOPT_OK was added in 7.21.5, released in April 2011.\n+ *\n+ * This should be safe as CURL_SOCKOPT_OK has always been a macro, not\n+ * an enum field (checked on curl version 7.78.0, released on July 19,\n+ * 2021). Even if that were to change the value of \"0\" for \"OK\" is\n+ * unlikely to change.\n+ */\n+#ifndef CURL_SOCKOPT_OK\n+#define CURL_SOCKOPT_OK 0\n+#endif\n+\n /**\n  * CURLOPT_TCP_KEEPALIVE was added in 7.25.0, released in March 2012.\n  */\ndiff --git a/http.c b/http.c\nindex 94eefe97089..d7c20493d7f 100644\n--- a/http.c\n+++ b/http.c\n@@ -537,7 +537,7 @@ static int sockopt_callback(void *client, curl_socket_t fd, curlsocktype type)\n \tif (rc < 0)\n \t\twarning_errno(\"unable to set SO_KEEPALIVE on socket\");\n \n-\treturn 0; /* CURL_SOCKOPT_OK only exists since curl 7.21.5 */\n+\treturn CURL_SOCKOPT_OK;\n }\n \n static void set_curl_keepalive(CURL *c)\n-- \n2.33.0.873.g125ff7b9940\n\n"},{"id":"435414","messageId":"YTtpWADzTJEAIvk+@coredump.intra.peff.net","threadId":"46547","inReplyTo":"xmqqv939wdgl.fsf@gitster.g","subject":"Re: [PATCH 2/5] http: correct curl version check for CURLOPT_PINNEDPUBLICKEY","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2021-09-10T14:19:04Z","receivedAt":"2021-09-10T14:19:09Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Thu, Sep 09, 2021 at 04:12:26PM -0700, Junio C Hamano wrote:\n\n> > But in terms of compiling, all we care about is that the constant is\n> > there. So I think the cutoff point you found is what we want. Presumably\n> > when the file format isn't supported we'd get some error, though it's\n> > not clear if that would come during the actual curl_*_perform(), or if\n> > we should be checking the curl_easy_setopt() result.\n> \n> If we were evaluating a patch to add support for pinnedpublickey\n> afresh back in, say, 2017, perhaps we cared enough about the\n> distinction between 7.39 and 7.44 (Nov 2014 and Aug 2015,\n> respectively), but I'd say cut-off at 7.44 for this, once it is\n> written and committed in our codebase, is good enough for us.\n> \n> If the code originally had cut-off at 7.39 and we were raising the\n> floor to 7.44 with \"sha256 weren't usable before that version\" as\n> the justification, it would be a totally different situation and it\n> may be worth the code change, but I am not sure if going backwards\n> is worth it.\n> \n> So, I dunno.\n\nI don't have a sense of whether the functionality difference between\n7.39 and 7.44 actually matters.\n\nI just saw it as: if you have 7.39 then before it would not work because\nwe didn't bother to compile it, and after it _might_ work depending on\nhow you use it. So it's a strict increase in functionality. Likewise, if\nyou compile Git against 7.39 and then later upgrade the shared library,\nyou'd get the increased functionality.\n\nBut I admit I don't really care that much, either. This is an\nobscure-ish feature in a 7 year old version of libcurl we are talking\nabout.\n\nBut there is one thing that does get weird if we don't do this patch. If\nwe later take the approach of checking:\n\n  #ifdef CURLOPT_PINNEDPUBLICKEY\n\nthen that will subtly shift the cutoff point from 7.44 to 7.39 anyway.\n_If_ we are going to do that conversion in a later patch (as this series\ndoes), I think it makes sense to shift the version number explicitly in\na commit with an explanation, as this commit does.\n\n-Peff\n"},{"id":"435416","messageId":"YTtsDGs7j2lM+hh+@coredump.intra.peff.net","threadId":"46547","inReplyTo":"YTtpWADzTJEAIvk+@coredump.intra.peff.net","subject":"Re: [PATCH 2/5] http: correct curl version check for CURLOPT_PINNEDPUBLICKEY","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2021-09-10T14:30:36Z","receivedAt":"2021-09-10T14:30:41Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Fri, Sep 10, 2021 at 10:19:04AM -0400, Jeff King wrote:\n\n> But there is one thing that does get weird if we don't do this patch. If\n> we later take the approach of checking:\n> \n>   #ifdef CURLOPT_PINNEDPUBLICKEY\n> \n> then that will subtly shift the cutoff point from 7.44 to 7.39 anyway.\n> _If_ we are going to do that conversion in a later patch (as this series\n> does), I think it makes sense to shift the version number explicitly in\n> a commit with an explanation, as this commit does.\n\nAh, nevermind. I just saw Ævar's re-roll where that strategy turns out\nto be a bad idea anyway. So that is no longer a compelling argument. :)\n\n-Peff\n"},{"id":"435417","messageId":"YTtttIuur0JvcPub@coredump.intra.peff.net","threadId":"46547","inReplyTo":"cover-v2-0.8-00000000000-20210910T105523Z-avarab@gmail.com","subject":"Re: [PATCH v2 0/8] post-v2.33 \"drop support for ancient curl\" follow-up","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2021-09-10T14:37:40Z","receivedAt":"2021-09-10T14:37:43Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Fri, Sep 10, 2021 at 01:04:25PM +0200, Ævar Arnfjörð Bjarmason wrote:\n\n> Version 1 of this had a really bad bug where we'd effectively make all\n> supported curl versions act like 7.19.4, i.e. the oldest supported\n> version except for a couple of our supported features. This is because\n> most of the things checked with the \"ifdef\" checks are enum fields,\n> not macros. So basically the \"devil's advocate\" Jeff King pointed out\n> in [2] was already the case. Oops!\n\nOops. :)\n\nWell, I'm glad I mentioned it, then (I really was just playing devil's\nadvocate). It does seem a little scary that we'd compile without all of\nthese features and not even notice it.\n\nI guess it's hard to test for those features when we don't know for sure\nthat our libcurl supports them. We could perhaps make the tests\noptional, but how do we set up the prereqs?\n\nVersion checks based on \"curl --version\" or even \"pkg-config\n--modversion libcurl\" seems error-prone. The curl binary might not match\nthe library we used, or the user might have given us a specific libcurl\nto use rather than the pkg-config version. We could teach Git to tell us\nwhich features it thinks curl supports, but that's depending on the very\nthing we're trying to test. We could have Git output the\nLIBCURL_VERSION_NUM it saw at build time, but then we're just\nimplementing the same \"if version > X, we have this feature\" logic now\nin the test suite.\n\nSo I dunno. I do not have any clever solution that would have caught\nthis automatically without creating an even bigger maintenance headache.\n\n(Though for other reasons, it might be nice to report the curl version\nfrom \"git version --build-options\". This is a bit tricky because we\navoid linking at libcurl at all in the main binary. Definitely\northogonal to your series, anyway).\n\n> This means that anyone on an older distro with backported features\n> will need to -DGIT_CURL_HAVE_* if their version of curl supports some\n> of these via a backport, not ideal, but an acceptable trade-off. If we\n> cared about this we could have some \"detect-curl\" script similar to my\n> proposed \"detect-compiler\"[3] (or another homegrown autoconf\n> replacement).\n\nI think that's acceptable. This should be rare, and they can always set\nCFLAGS appropriately.\n\n-Peff\n"},{"id":"435418","messageId":"87tuiscwso.fsf@evledraar.gmail.com","threadId":"46547","inReplyTo":"YTtpWADzTJEAIvk+@coredump.intra.peff.net","subject":"Re: [PATCH 2/5] http: correct curl version check for CURLOPT_PINNEDPUBLICKEY","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-09-10T14:37:48Z","receivedAt":"2021-09-10T14:47:26Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"\nOn Fri, Sep 10 2021, Jeff King wrote:\n\n> On Thu, Sep 09, 2021 at 04:12:26PM -0700, Junio C Hamano wrote:\n>\n>> > But in terms of compiling, all we care about is that the constant is\n>> > there. So I think the cutoff point you found is what we want. Presumably\n>> > when the file format isn't supported we'd get some error, though it's\n>> > not clear if that would come during the actual curl_*_perform(), or if\n>> > we should be checking the curl_easy_setopt() result.\n>> \n>> If we were evaluating a patch to add support for pinnedpublickey\n>> afresh back in, say, 2017, perhaps we cared enough about the\n>> distinction between 7.39 and 7.44 (Nov 2014 and Aug 2015,\n>> respectively), but I'd say cut-off at 7.44 for this, once it is\n>> written and committed in our codebase, is good enough for us.\n>> \n>> If the code originally had cut-off at 7.39 and we were raising the\n>> floor to 7.44 with \"sha256 weren't usable before that version\" as\n>> the justification, it would be a totally different situation and it\n>> may be worth the code change, but I am not sure if going backwards\n>> is worth it.\n>> \n>> So, I dunno.\n>\n> I don't have a sense of whether the functionality difference between\n> 7.39 and 7.44 actually matters.\n\nFor what it's worth I tested this as part of re-rolling, i.e. I grabbed\nthe tarball for 7.39[1].\n\nBy using the correct version number of 7.39 we'll support pinned public\nkeys there, but if you supply e.g. the \"sha256/[...]\" format we'll\ninstead of printing a warning about this version not supporting pinned\nkeys, we'll die with an error from curl itself.\n\nI think whatever happens with 7.39..7.44 doesn't matter much, but this\ndoes seem like more useful behavior, and we avoid the oddity of\nhardcoding the \"wrong\" version (until you start looking more into it,\nthat is...).\n\nAside from 7.39..7.44 though it does seem like a really bad thing to do\nto just warn that we don't support pinned public keys, but proceed with\nthe request anyway (which could also be a push).\n\nI don't think it's worth changing that s/warning/die/g now, since the\ntarget audience for a new git release with such an ancient curl version\nis probably zero, or near enough to be zero.\n\nI mean, we do have new git + old OS, but it tends to be *specific* old\nversions, namely for releases of this age the one released with RHEL. I\nthink pretty nobody else does that (the rest are probably all\nRHEL-derived). Per 013c7e2b070 (http: drop support for curl < 7.16.0,\n2021-07-30) none of the RHEL out there have a curl in the 7.39..7.44\nrange.\n\nThe commit doesn't note the RHEL 8 version (which b.t.w., is something I\nadded to it, not you), but it seems to be 7.61.1[2]. So at least as far\nas RHEL goes we'll never be stuck in the 7.39..7.44 range..\n\n1. protip: curl.git git tags are rather useless, since (at least for old\n   versions) the embedded version number is bumped sometime *after* the\n   release).\n\n   I also ran \"diff -ru\" on at least one old tag/tarball (I forget\n   which) and there were a lot of changes (and not just some \"make dist\"\n   stuff like autoconf files, version numbers or whatever).\n\n   So in testing this I stopped using curl.git for anything but \"git log\n   -G<str>\" searching and the like, and just tested with archived\n   release tarballs.\n\n2. https://access.redhat.com/solutions/4174711\n"},{"id":"435419","messageId":"YTtxcBdF2VQdWp5C@coredump.intra.peff.net","threadId":"46547","inReplyTo":"patch-v2-1.8-ac11cf8cfd1-20210910T105523Z-avarab@gmail.com","subject":"Re: [PATCH v2 1/8] INSTALL: don't mention the \"curl\" executable at all","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2021-09-10T14:53:36Z","receivedAt":"2021-09-10T14:53:39Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Fri, Sep 10, 2021 at 01:04:26PM +0200, Ævar Arnfjörð Bjarmason wrote:\n\n> In 1d53f90ed97 (The \"curl\" executable is no longer required,\n> 2008-06-15) the wording for requiring curl(1) was changed to the\n> current \"you might also want...\".\n> \n> Mentioning the \"curl\" executable at all is just confusing, someone\n> building git might want to use it to debug things, but they might also\n> just use wget(1) or some other http client. The \"curl\" executable has\n> the advantage that you might be able to e.g. reproduce a bug in git's\n> usage of libcurl with it, but anyone going to those extents is\n> unlikely to be aided by this note in INSTALL.\n\nI think that's reasonable. Keeping the INSTALL document short and clear\nis much more important than preemptively giving debugging hints of\nquestionable value.\n\n> diff --git a/INSTALL b/INSTALL\n> index 66389ce0591..5c6ecf03c27 100644\n> --- a/INSTALL\n> +++ b/INSTALL\n> @@ -139,11 +139,11 @@ Issues of note:\n>  \t  (PPC_SHA1).\n>  \n>  \t- \"libcurl\" library is used by git-http-fetch, git-fetch, and, if\n> -\t  the curl version >= 7.34.0, for git-imap-send.  You might also\n> -\t  want the \"curl\" executable for debugging purposes. If you do not\n> -\t  use http:// or https:// repositories, and do not want to put\n> -\t  patches into an IMAP mailbox, you do not have to have them\n> -\t  (use NO_CURL).\n> +\t  the curl version >= 7.34.0, for git-imap-send.\n> +\n> +\t  If you do not use http:// or https:// repositories, and do\n> +\t  not want to put patches into an IMAP mailbox, you do not\n> +\t  have to have them (use NO_CURL).\n\nI was confused by \"them\" here, which you kept in the post-image. In the\noriginal I thought it mean \"libcurl and curl\". And now that you are just\nsaying \"libcurl\", it ought to be \"it\".\n\nBut perhaps it means \"git-http-fetch, git-fetch, etc\". In which case\nit's still correct.\n\nBut maybe it would be simpler to say:\n\n  If you do not use ..., you do not need libcurl (use NO_CURL to build\n  without it).\n\nSort of orthogonal, but maybe worth touching while we're here: that list\nof commands is kind of outdated. Nobody even knows what git-http-fetch\nis these days, and most people would not use it (it is only for dumb\nfetching). And certainly git-push can use http.\n\nSo maybe something like:\n\n  \"libcurl\" library is used for fetching and pushing repositories over\n  http:// or https://, as well as by git-imap-send if the curl version\n  is >= 7.34.0.\n\n-Peff\n"},{"id":"435420","messageId":"YTtxo/HKYDTOJBvh@coredump.intra.peff.net","threadId":"46547","inReplyTo":"patch-v2-2.8-4b653cee2d3-20210910T105523Z-avarab@gmail.com","subject":"Re: [PATCH v2 2/8] INSTALL: mention that we need libcurl 7.19.4 or newer to build","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2021-09-10T14:54:27Z","receivedAt":"2021-09-10T14:54:29Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Fri, Sep 10, 2021 at 01:04:27PM +0200, Ævar Arnfjörð Bjarmason wrote:\n\n> Without NO_CURL=Y we require at least version \"7.19.4\" of libcurl, see\n> 644de29e220 (http: drop support for curl < 7.19.4, 2021-07-30). Let's\n> document this in the \"INSTALL\" document.\n\nMakes sense.\n\n> diff --git a/INSTALL b/INSTALL\n> index 5c6ecf03c27..81f3a6cf018 100644\n> --- a/INSTALL\n> +++ b/INSTALL\n> @@ -141,6 +141,9 @@ Issues of note:\n>  \t- \"libcurl\" library is used by git-http-fetch, git-fetch, and, if\n>  \t  the curl version >= 7.34.0, for git-imap-send.\n>  \n> +\t  Git version \"7.19.4\" of \"libcurl\" or later to build. This\n> +\t  version requirement may be bumped in the future.\n> +\n\ns/to build/is needed &/ or similar?\n\n-Peff\n"},{"id":"435422","messageId":"YTt0EpbdmYVlu1zR@coredump.intra.peff.net","threadId":"46547","inReplyTo":"patch-v2-3.8-76c2aa6e78d-20210910T105523Z-avarab@gmail.com","subject":"Re: [PATCH v2 3/8] Makefile: drop support for curl < 7.9.8 (again)","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2021-09-10T15:04:50Z","receivedAt":"2021-09-10T15:04:52Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Fri, Sep 10, 2021 at 01:04:28PM +0200, Ævar Arnfjörð Bjarmason wrote:\n\n> In 1119a15b5c8 (http: drop support for curl < 7.11.1, 2021-07-30)\n> support for curl versions older than 7.11.1 was removed, and we\n> currently require at least version 7.19.4, see 644de29e220 (http: drop\n> support for curl < 7.19.4, 2021-07-30).\n> \n> In those changes this Makefile-specific check added in\n> 0890098780f (Decide whether to build http-push in the Makefile,\n> 2005-11-18) was missed, now that we're never going to use such an\n> ancient curl version we don't need to check that we have at least\n> 7.9.8 here. I have no idea what in http-push.c broke on versions older\n> than that.\n\nNice catch. I was curious, and I think the issue was just that older\nversions did not have the curl_multi_* interface.\n\n> @@ -1436,15 +1436,8 @@ else\n>  \tREMOTE_CURL_NAMES = $(REMOTE_CURL_PRIMARY) $(REMOTE_CURL_ALIASES)\n>  \tPROGRAM_OBJS += http-fetch.o\n>  \tPROGRAMS += $(REMOTE_CURL_NAMES)\n> -\tcurl_check := $(shell (echo 070908; $(CURL_CONFIG) --vernum | sed -e '/^70[BC]/s/^/0/') 2>/dev/null | sort -r | sed -ne 2p)\n> -\tifeq \"$(curl_check)\" \"070908\"\n> -\t\tifndef NO_EXPAT\n> -\t\t\tPROGRAM_OBJS += http-push.o\n> -\t\telse\n> -\t\t\tEXCLUDED_PROGRAMS += git-http-push\n> -\t\tendif\n> -\telse\n> -\t\tEXCLUDED_PROGRAMS += git-http-push\n> +\tifndef NO_EXPAT\n> +\t\tPROGRAM_OBJS += http-push.o\n>  \tendif\n\nI wonder if this $(CURL_CONFIG) check could have been be problematic for\nsome obscure platforms, if they set up CURL_{CFLAGS,LDFLAGS,LIBCURL}\nmanually (rather than relying on curl-config). We do have one more\nsimilar check:\n\n>  \tcurl_check := $(shell (echo 072200; $(CURL_CONFIG) --vernum | sed -e '/^70[BC]/s/^/0/') 2>/dev/null | sort -r | sed -ne 2p)\n\n...and nobody has complained either way, so perhaps it doesn't matter\nmuch. Anyway, I'm happy to see this now-useless code go away. :)\n\n-Peff\n"},{"id":"435423","messageId":"YTt1RLty0KDEAio1@coredump.intra.peff.net","threadId":"46547","inReplyTo":"patch-v2-5.8-2567b888c3d-20210910T105523Z-avarab@gmail.com","subject":"Re: [PATCH v2 5/8] http: correct version check for CURL_HTTP_VERSION_2","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2021-09-10T15:09:56Z","receivedAt":"2021-09-10T15:09:59Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Fri, Sep 10, 2021 at 01:04:30PM +0200, Ævar Arnfjörð Bjarmason wrote:\n\n> In d73019feb44 (http: add support selecting http version, 2018-11-08)\n> a dependency was added on CURL_HTTP_VERSION_2, but this feature was\n> introduced in curl version 7.43.0, not 7.47.0, as the incorrect\n> version check led us to believe.\n> \n> As looking through the history of that commit on the mailing list will\n> reveal[1], the reason for this is that an earlier version of it\n> depended on CURL_HTTP_VERSION_2TLS, which was introduced in libcurl\n> 7.47.0.\n> \n> But the version that made it in in d73019feb44 had dropped the\n> dependency on CURL_HTTP_VERSION_2TLS, but the corresponding version\n> check was not corrected.\n> \n> The newest symbol we depend on is CURL_HTTP_VERSION_2. It was added in\n> 7.33.0, but the CURL_HTTP_VERSION_2 alias we used was added in\n> 7.47.0. So we could support an even older version here, but let's just\n> correct the checked version.\n\nThanks for expanding on the history here. I agree it probably doesn't\nmatter much between the two versions, as they're both 6+ years old (and\nonly about 6 months apart). If somebody has a case where it really\nmatters, they can submit a patch.\n\n-Peff\n"},{"id":"435424","messageId":"87lf44cvkp.fsf@evledraar.gmail.com","threadId":"46547","inReplyTo":"YTtttIuur0JvcPub@coredump.intra.peff.net","subject":"Re: [PATCH v2 0/8] post-v2.33 \"drop support for ancient curl\" follow-up","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-09-10T15:08:32Z","receivedAt":"2021-09-10T15:13:46Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"\nOn Fri, Sep 10 2021, Jeff King wrote:\n\n> On Fri, Sep 10, 2021 at 01:04:25PM +0200, Ævar Arnfjörð Bjarmason wrote:\n>\n>> Version 1 of this had a really bad bug where we'd effectively make all\n>> supported curl versions act like 7.19.4, i.e. the oldest supported\n>> version except for a couple of our supported features. This is because\n>> most of the things checked with the \"ifdef\" checks are enum fields,\n>> not macros. So basically the \"devil's advocate\" Jeff King pointed out\n>> in [2] was already the case. Oops!\n>\n> Oops. :)\n>\n> Well, I'm glad I mentioned it, then (I really was just playing devil's\n> advocate). It does seem a little scary that we'd compile without all of\n> these features and not even notice it.\n>\n> I guess it's hard to test for those features when we don't know for sure\n> that our libcurl supports them. We could perhaps make the tests\n> optional, but how do we set up the prereqs?\n>\n> Version checks based on \"curl --version\" or even \"pkg-config\n> --modversion libcurl\" seems error-prone. The curl binary might not match\n> the library we used, or the user might have given us a specific libcurl\n> to use rather than the pkg-config version. We could teach Git to tell us\n> which features it thinks curl supports, but that's depending on the very\n> thing we're trying to test. We could have Git output the\n> LIBCURL_VERSION_NUM it saw at build time, but then we're just\n> implementing the same \"if version > X, we have this feature\" logic now\n> in the test suite.\n>\n> So I dunno. I do not have any clever solution that would have caught\n> this automatically without creating an even bigger maintenance headache.\n\nYeah, ideally we'd have tests for these optional features, and we'd then\njust add them to GIT-BUILD-OPTIONS and skip dedicated tests\nappropriately, then it would be more visible to see those tests\nskipped. Presumably someone testing this would run \"make test\" against a\nglob that includes *curl*.\n\nBut that's not easy to do in practice since the flags are either not\nvisible from the outside in terms of behavior, or if they are it's all\nsomething that requires proxies, SSL etc, which we don't test currently.\n\nWe can and should test that, but requires e.g. extending lib-httpd.sh to\nstart apache with ssl support, or maybe we could do it more easily with\nan optional stunnel or something...\n\n> (Though for other reasons, it might be nice to report the curl version\n> from \"git version --build-options\". This is a bit tricky because we\n> avoid linking at libcurl at all in the main binary. Definitely\n> orthogonal to your series, anyway).\n\nWe could always ship a git-version-curl and shell out to it, or embed\nthe version curl-config --vernum gave us at compile time via Makefile ->\n-DGIT_CURL_VERSION.\n\nThat version could be changed at runtime. We could call that a\nfeature. It's --build-options, not --runtime-libraries :)\n"},{"id":"435425","messageId":"YTt2nHMXAkyfol9v@coredump.intra.peff.net","threadId":"46547","inReplyTo":"patch-v2-7.8-8e57a8409c5-20210910T105523Z-avarab@gmail.com","subject":"Re: [PATCH v2 7/8] http: centralize the accounting of libcurl dependencies","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2021-09-10T15:15:40Z","receivedAt":"2021-09-10T15:15:43Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Fri, Sep 10, 2021 at 01:04:32PM +0200, Ævar Arnfjörð Bjarmason wrote:\n\n> As discussed in 644de29e220 (http: drop support for curl < 7.19.4,\n> 2021-07-30) checking against LIBCURL_VERSION_NUM isn't as reliable as\n> checking specific symbols present in curl, as some distros have been\n> known to backport features.\n> \n> However, while some of the curl_easy_setopt() arguments we rely on are\n> macros, others are enum, and we can't assume that those that are\n> macros won't change into enums in the future.\n> \n> So we're still going to have to check LIBCURL_VERSION_NUM, but by\n> doing that in one central place and using a macro definition of our\n> own, anyone who's backporting features can define it themselves, and\n> thus have access to more modern curl features that they backported,\n> even if they didn't bump the LIBCURL_VERSION_NUM.\n\nI think this lays out a nicer argument for this centralized registry\nthan the previous round.\n\nI looked over the changes themselves and didn't notice any problems. I\ndidn't cross-check every moved-version field, since that seemed like an\nunlikely mistake to make. I did check for easy mistakes at the\nuse-sites, like making sure to use #ifndef for \"version < X\" and #ifdef\nfor \"version >= X\".\n\n> -#if LIBCURL_VERSION_NUM >=0x072b00\n> +#ifdef GIT_CURL_HAVE_CURL_HTTP_VERSION_2\n\nGood, I was going to complain about the whitespace in this one when you\ntouched it earlier, but now it goes away. :)\n\n-Peff\n"},{"id":"435426","messageId":"YTt3E6/klkL55kY8@coredump.intra.peff.net","threadId":"46547","inReplyTo":"patch-v2-8.8-465ab33ebda-20210910T105523Z-avarab@gmail.com","subject":"Re: [PATCH v2 8/8] http: don't hardcode the value of CURL_SOCKOPT_OK","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2021-09-10T15:17:39Z","receivedAt":"2021-09-10T15:17:42Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Fri, Sep 10, 2021 at 01:04:33PM +0200, Ævar Arnfjörð Bjarmason wrote:\n\n> Use the new git-curl-compat.h header to define CURL_SOCKOPT_OK to its\n> known value if we're on an older curl version that doesn't have it. It\n> was hardcoded in http.c in a15d069a198 (http: enable keepalive on TCP\n> sockets, 2013-10-12).\n\nThanks for splitting this one out. I agree it's unlike the rest.\n\n> +/**\n> + * CURL_SOCKOPT_OK was added in 7.21.5, released in April 2011.\n> + *\n> + * This should be safe as CURL_SOCKOPT_OK has always been a macro, not\n> + * an enum field (checked on curl version 7.78.0, released on July 19,\n> + * 2021). Even if that were to change the value of \"0\" for \"OK\" is\n> + * unlikely to change.\n> + */\n> +#ifndef CURL_SOCKOPT_OK\n> +#define CURL_SOCKOPT_OK 0\n> +#endif\n\nI agree this is probably fine if it later becomes an enum. But it would\nbe easy enough to just do the version-number check here, wouldn't it?\nThat would be even safer, and using the #ifndef doesn't really buy us\nmuch. We still have to annotate the version and date in a comment as you\ndid, because we want to know when it is time to drop support.\n\n-Peff\n"},{"id":"435427","messageId":"YTt3qwVPXEkgh6LP@coredump.intra.peff.net","threadId":"46547","inReplyTo":"87lf44cvkp.fsf@evledraar.gmail.com","subject":"Re: [PATCH v2 0/8] post-v2.33 \"drop support for ancient curl\" follow-up","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2021-09-10T15:20:11Z","receivedAt":"2021-09-10T15:20:14Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Fri, Sep 10, 2021 at 05:08:32PM +0200, Ævar Arnfjörð Bjarmason wrote:\n\n> > So I dunno. I do not have any clever solution that would have caught\n> > this automatically without creating an even bigger maintenance headache.\n> \n> Yeah, ideally we'd have tests for these optional features, and we'd then\n> just add them to GIT-BUILD-OPTIONS and skip dedicated tests\n> appropriately, then it would be more visible to see those tests\n> skipped. Presumably someone testing this would run \"make test\" against a\n> glob that includes *curl*.\n> \n> But that's not easy to do in practice since the flags are either not\n> visible from the outside in terms of behavior, or if they are it's all\n> something that requires proxies, SSL etc, which we don't test currently.\n> \n> We can and should test that, but requires e.g. extending lib-httpd.sh to\n> start apache with ssl support, or maybe we could do it more easily with\n> an optional stunnel or something...\n\nYeah, even after we get the right version/feature flags into the test\nsuite, most of these are pretty obscure and hard to test.\n\nI definitely think that's not something we should worry about for this\nseries.\n\n> > (Though for other reasons, it might be nice to report the curl version\n> > from \"git version --build-options\". This is a bit tricky because we\n> > avoid linking at libcurl at all in the main binary. Definitely\n> > orthogonal to your series, anyway).\n> \n> We could always ship a git-version-curl and shell out to it, or embed\n> the version curl-config --vernum gave us at compile time via Makefile ->\n> -DGIT_CURL_VERSION.\n\nYeah, I was thinking \"git remote-curl --curl-version\" or something.\nLet's punt on it for now, though. I think this series is getting close\nto ready, and this is all only semi-related.\n\n-Peff\n"},{"id":"435429","messageId":"nycvar.QRO.7.76.2109101713110.2614@fvyyl","threadId":"46547","inReplyTo":"YTt1RLty0KDEAio1@coredump.intra.peff.net","subject":"Re: [PATCH v2 5/8] http: correct version check for CURL_HTTP_VERSION_2","fromName":"Daniel Stenberg","fromEmail":"daniel@haxx.se","sentAt":"2021-09-10T15:20:24Z","receivedAt":"2021-09-10T15:26:56Z","isPatch":true,"sender":{"key":"daniel@haxx.se","avatar":"https://gravatar.com/avatar/69fdca87edd17cee21ca2e79fc2ff671d644603c3dc27167430f3cd3dbab7ba8?d=mp&s=160"},"body":"On Fri, 10 Sep 2021, Jeff King wrote:\n\n>> The newest symbol we depend on is CURL_HTTP_VERSION_2. It was added in \n>> 7.33.0, but the CURL_HTTP_VERSION_2 alias we used was added in 7.47.0. So \n>> we could support an even older version here, but let's just correct the \n>> checked version.\n>\n> Thanks for expanding on the history here. I agree it probably doesn't matter \n> much between the two versions, as they're both 6+ years old (and only about \n> 6 months apart). If somebody has a case where it really matters, they can \n> submit a patch.\n\nForgive me for digressing a bit here but wow, I *so* appreciate your digging \ninto the details of the curl history and the symbols that were introduced when \netc. I know of no other libcurl-using project with this eye and sense for \nhistoric details and as the lead maintainer of libcurl I learn a lot here. It \nalso keeps me motivated to provide this documentation and work on keeping in \naccurate.\n\nKeep it up! <3\n\n-- \n\n  / daniel.haxx.se\n"},{"id":"435430","messageId":"YTt5nhXfZ8CRYayk@coredump.intra.peff.net","threadId":"46547","inReplyTo":"87tuiscwso.fsf@evledraar.gmail.com","subject":"Re: [PATCH 2/5] http: correct curl version check for CURLOPT_PINNEDPUBLICKEY","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2021-09-10T15:28:30Z","receivedAt":"2021-09-10T15:28:33Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Fri, Sep 10, 2021 at 04:37:48PM +0200, Ævar Arnfjörð Bjarmason wrote:\n\n> > I don't have a sense of whether the functionality difference between\n> > 7.39 and 7.44 actually matters.\n> \n> For what it's worth I tested this as part of re-rolling, i.e. I grabbed\n> the tarball for 7.39[1].\n> \n> By using the correct version number of 7.39 we'll support pinned public\n> keys there, but if you supply e.g. the \"sha256/[...]\" format we'll\n> instead of printing a warning about this version not supporting pinned\n> keys, we'll die with an error from curl itself.\n\nThanks for testing that. That was really my one concern: that by not\nissuing our own error for the semi-functional version, we might fail to\nnotice it entirely, putting people on that older version in a worse\nspot. But it sounds like we (and curl) do the right thing.\n\n> Aside from 7.39..7.44 though it does seem like a really bad thing to do\n> to just warn that we don't support pinned public keys, but proceed with\n> the request anyway (which could also be a push).\n> \n> I don't think it's worth changing that s/warning/die/g now, since the\n> target audience for a new git release with such an ancient curl version\n> is probably zero, or near enough to be zero.\n\nYeah, agreed. When we introduce optional features we should try to make\nsure that they fail in the safest direction (assuming the user has\nexplicitly asked to use them, as in this case). But given the age and\nhistory here, I'm not sure it matters that much at this point. On the\nother hand, if it really is s/warning/die/, that's easy enough to do. I\ncould go either way.\n\n> I mean, we do have new git + old OS, but it tends to be *specific* old\n> versions, namely for releases of this age the one released with RHEL. I\n> think pretty nobody else does that (the rest are probably all\n> RHEL-derived). Per 013c7e2b070 (http: drop support for curl < 7.16.0,\n> 2021-07-30) none of the RHEL out there have a curl in the 7.39..7.44\n> range.\n\nI don't think the specific version range matters here. If I had curl\n7.19.4 (for example) and tried to use the pinning feature I'd get a\nwarning but we'd continue without using the pinned key, which is\ndangerous. That's true both before and after your patches.\n\n> The commit doesn't note the RHEL 8 version (which b.t.w., is something I\n> added to it, not you), but it seems to be 7.61.1[2]. So at least as far\n> as RHEL goes we'll never be stuck in the 7.39..7.44 range..\n> \n> 1. protip: curl.git git tags are rather useless, since (at least for old\n>    versions) the embedded version number is bumped sometime *after* the\n>    release).\n> \n>    I also ran \"diff -ru\" on at least one old tag/tarball (I forget\n>    which) and there were a lot of changes (and not just some \"make dist\"\n>    stuff like autoconf files, version numbers or whatever).\n> \n>    So in testing this I stopped using curl.git for anything but \"git log\n>    -G<str>\" searching and the like, and just tested with archived\n>    release tarballs.\n\nInteresting to note. I'd always looked at curl.git in the past.\n\n-Peff\n"},{"id":"435440","messageId":"YTt8ppkt/PloRn4D@coredump.intra.peff.net","threadId":"46547","inReplyTo":"nycvar.QRO.7.76.2109101713110.2614@fvyyl","subject":"Re: [PATCH v2 5/8] http: correct version check for CURL_HTTP_VERSION_2","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2021-09-10T15:41:26Z","receivedAt":"2021-09-10T15:41:29Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Fri, Sep 10, 2021 at 05:20:24PM +0200, Daniel Stenberg wrote:\n\n> On Fri, 10 Sep 2021, Jeff King wrote:\n> \n> > > The newest symbol we depend on is CURL_HTTP_VERSION_2. It was added\n> > > in 7.33.0, but the CURL_HTTP_VERSION_2 alias we used was added in\n> > > 7.47.0. So we could support an even older version here, but let's\n> > > just correct the checked version.\n> > \n> > Thanks for expanding on the history here. I agree it probably doesn't\n> > matter much between the two versions, as they're both 6+ years old (and\n> > only about 6 months apart). If somebody has a case where it really\n> > matters, they can submit a patch.\n> \n> Forgive me for digressing a bit here but wow, I *so* appreciate your digging\n> into the details of the curl history and the symbols that were introduced\n> when etc. I know of no other libcurl-using project with this eye and sense\n> for historic details and as the lead maintainer of libcurl I learn a lot\n> here. It also keeps me motivated to provide this documentation and work on\n> keeping in accurate.\n\nThis documentation is most definitely appreciated. As is your continued\nsupport and attention to our issues, not to mention just having libcurl\nin general. :)\n\nThere are two related things that came up in this discussion that might\nbe of interest to you:\n\n  - it would be convenient if libcurl provided preprocessor macros\n    indicating a feature was present. E.g., if we could say:\n\n      #ifdef CURL_HAVE_FOO\n\n    rather than checking that \"FOO\" showed up in version 7.60.0 or\n    whatever. That has two advantages. One, it's just less work and\n    harder to get wrong. But two, it could help for cases where distros\n    backport features (i.e., the version-to-feature mapping is not\n    always 100% correct).\n\n    Obviously that can't help historical versions, but maybe something\n    to think about as new features are added.\n\n  - Ævar mentioned at the end of:\n\n      https://lore.kernel.org/git/87tuiscwso.fsf@evledraar.gmail.com/\n\n    that the tags in the curl repo sometime seem to differ from the\n    releases.\n\n-Peff\n"},{"id":"435442","messageId":"nycvar.QRO.7.76.2109101740380.2614@fvyyl","threadId":"46547","inReplyTo":"YTt5nhXfZ8CRYayk@coredump.intra.peff.net","subject":"Re: [PATCH 2/5] http: correct curl version check for CURLOPT_PINNEDPUBLICKEY","fromName":"Daniel Stenberg","fromEmail":"daniel@haxx.se","sentAt":"2021-09-10T15:45:56Z","receivedAt":"2021-09-10T15:45:59Z","isPatch":true,"sender":{"key":"daniel@haxx.se","avatar":"https://gravatar.com/avatar/69fdca87edd17cee21ca2e79fc2ff671d644603c3dc27167430f3cd3dbab7ba8?d=mp&s=160"},"body":"On Fri, 10 Sep 2021, Jeff King wrote:\n\n>> 1. protip: curl.git git tags are rather useless, since (at least for old\n>>    versions) the embedded version number is bumped sometime *after* the\n>>    release).\n\n(double-level quote since I miseed the original email saying this)\n\nThis is simply not true and it makes me really curious why you would think \nthis.\n\nWe (in the curl project) tag the git repository exactly at the point we \ngenerate the release from. The release is however the generated tarball, and \nthe tag is the moment in the git history where the release was done. That's \nwhy the release number at the time of the tag will always say \"blabla-DEV\" \nsomething.\n\nI know this, becasue I've done every single curl release personally, since the \ndawn of time. Of course we've only used git since about 2010 but I can't \nremember that we ever did it differently.\n\nThe exact step-by-step to do a release is also documented since years back:\n   https://curl.se/dev/release-procedure.html\n\n-- \n\n  / daniel.haxx.se\n"},{"id":"435443","messageId":"xmqqr1dwtlt1.fsf@gitster.g","threadId":"46547","inReplyTo":"cover-v2-0.8-00000000000-20210910T105523Z-avarab@gmail.com","subject":"Re: [PATCH v2 0/8] post-v2.33 \"drop support for ancient curl\" follow-up","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2021-09-10T16:52:42Z","receivedAt":"2021-09-10T16:52:46Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Ævar Arnfjörð Bjarmason  <avarab@gmail.com> writes:\n\n> Version 1 of this had a really bad bug where we'd effectively make all\n> supported curl versions act like 7.19.4, i.e. the oldest supported\n> version except for a couple of our supported features. This is because\n> most of the things checked with the \"ifdef\" checks are enum fields,\n> not macros. So basically the \"devil's advocate\" Jeff King pointed out\n> in [2] was already the case. Oops!\n\nWow.  Thanks for bothering to actually test ;-)\n\nBecause we learned that \"#ifdef CURL_SOME_FEATURE_WE_WANT\" is not a\ngenerally applicable way to conditionally build for various features\nand we'd need to switch on the version numbers, it is now clear (at\nleast to me) that the central registry approach would be a direction\nto go.\n\n> In this v2 we're instead checking LIBCURL_VERSION_NUM consistently,\n> even in those cases where we are checking things that are defined via\n> macros.\n\nNice.\n\n>     ++ * For each X symbol we need from curl we define our own\n>     ++ * GIT_CURL_HAVE_X. If multiple similar symbols with the same prefix\n>     ++ * were defined in the same version we pick one and check for that name.\n>      + *\n>      + * Keep any symbols in date order of when their support was\n>      + * introduced, oldest first, in the official version of cURL library.\n>     @@ git-curl-compat.h (new)\n>      +/**\n>      + * CURLOPT_TCP_KEEPALIVE was added in 7.25.0, released in March 2012.\n>      + */\n>     -+#ifdef CURLOPT_TCP_KEEPALIVE\n>     ++#if LIBCURL_VERSION_NUM >= 0x071900\n>      +#define GITCURL_HAVE_CURLOPT_TCP_KEEPALIVE 1\n>      +#endif\n\nWhat we have in the posted patch is perfectly OK and serviceable,\nbut this organization somewhat surprised me.  \n\nInstead of one #if...#endif block per a feature macro, I expected to\nsee a sequence of\n\n\t/* 7.34.0 (0x072200) - Dec 2013 */\n\t#if 0x072200 < VERSION\n\t#define HAVE_FOO 1\n\t#define HAVE_BAR 1\n\t...\n\t#endif\n\n\t/* 7.25.0 (0x071900) - March 2012 */\n\t#if 0x071900 < VERSION\n\t#define HAVE_BAZ 1\n\t#define HAVE_QUX 1\n\t...\n        #endif\n\n\nbecause it would make it more clear which features can now be\nunconditionally used when we raise the cut-off point for the oldest\nsupported version if we group these entries along the versions.\n\nThanks.\n"},{"id":"435444","messageId":"xmqqmtoktln0.fsf@gitster.g","threadId":"46547","inReplyTo":"YTtxo/HKYDTOJBvh@coredump.intra.peff.net","subject":"Re: [PATCH v2 2/8] INSTALL: mention that we need libcurl 7.19.4 or newer to build","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2021-09-10T16:56:19Z","receivedAt":"2021-09-10T16:56:25Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Jeff King <peff@peff.net> writes:\n\n> On Fri, Sep 10, 2021 at 01:04:27PM +0200, Ævar Arnfjörð Bjarmason wrote:\n>\n>> Without NO_CURL=Y we require at least version \"7.19.4\" of libcurl, see\n>> 644de29e220 (http: drop support for curl < 7.19.4, 2021-07-30). Let's\n>> document this in the \"INSTALL\" document.\n>\n> Makes sense.\n>\n>> diff --git a/INSTALL b/INSTALL\n>> index 5c6ecf03c27..81f3a6cf018 100644\n>> --- a/INSTALL\n>> +++ b/INSTALL\n>> @@ -141,6 +141,9 @@ Issues of note:\n>>  \t- \"libcurl\" library is used by git-http-fetch, git-fetch, and, if\n>>  \t  the curl version >= 7.34.0, for git-imap-send.\n>>  \n>> +\t  Git version \"7.19.4\" of \"libcurl\" or later to build. This\n>> +\t  version requirement may be bumped in the future.\n>> +\n>\n> s/to build/is needed &/ or similar?\n\n\"Get version X of \"libcurl\" or later to build.\" probably.\n"},{"id":"435445","messageId":"xmqqfsuctlfm.fsf@gitster.g","threadId":"46547","inReplyTo":"patch-v2-6.8-397d54a1352-20210910T105523Z-avarab@gmail.com","subject":"Re: [PATCH v2 6/8] http: correct curl version check for CURLOPT_PINNEDPUBLICKEY","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2021-09-10T17:00:45Z","receivedAt":"2021-09-10T17:00:48Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Ævar Arnfjörð Bjarmason  <avarab@gmail.com> writes:\n\n> In aeff8a61216 (http: implement public key pinning, 2016-02-15) a\n> dependency and warning() was added if curl older than 7.44.0 was used,\n> but the relevant code depended on CURLOPT_PINNEDPUBLICKEY, introduced\n> in 7.39.0.\n\n[PATCH 7/8] should make the difference irrelevant, but OK ;-)\n\n>\n> Signed-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n> ---\n>  http.c | 8 ++++----\n>  1 file changed, 4 insertions(+), 4 deletions(-)\n>\n> diff --git a/http.c b/http.c\n> index b82b5b7a532..543faad9879 100644\n> --- a/http.c\n> +++ b/http.c\n> @@ -59,7 +59,7 @@ static struct {\n>  static const char *ssl_key;\n>  static const char *ssl_capath;\n>  static const char *curl_no_proxy;\n> -#if LIBCURL_VERSION_NUM >= 0x072c00\n> +#if LIBCURL_VERSION_NUM >= 0x072700\n>  static const char *ssl_pinnedkey;\n>  #endif\n>  static const char *ssl_cainfo;\n> @@ -373,10 +373,10 @@ static int http_options(const char *var, const char *value, void *cb)\n>  \t}\n>  \n>  \tif (!strcmp(\"http.pinnedpubkey\", var)) {\n> -#if LIBCURL_VERSION_NUM >= 0x072c00\n> +#if LIBCURL_VERSION_NUM >= 0x072700\n>  \t\treturn git_config_pathname(&ssl_pinnedkey, var, value);\n>  #else\n> -\t\twarning(_(\"Public key pinning not supported with cURL < 7.44.0\"));\n> +\t\twarning(_(\"Public key pinning not supported with cURL < 7.39.0\"));\n>  \t\treturn 0;\n>  #endif\n>  \t}\n> @@ -845,7 +845,7 @@ static CURL *get_curl_handle(void)\n>  \t\tcurl_easy_setopt(result, CURLOPT_SSLKEY, ssl_key);\n>  \tif (ssl_capath != NULL)\n>  \t\tcurl_easy_setopt(result, CURLOPT_CAPATH, ssl_capath);\n> -#if LIBCURL_VERSION_NUM >= 0x072c00\n> +#if LIBCURL_VERSION_NUM >= 0x072700\n>  \tif (ssl_pinnedkey != NULL)\n>  \t\tcurl_easy_setopt(result, CURLOPT_PINNEDPUBLICKEY, ssl_pinnedkey);\n>  #endif\n"},{"id":"435446","messageId":"024f01d7a666$4338a620$c9a9f260$@nexbridge.com","threadId":"46547","inReplyTo":"xmqqr1dwtlt1.fsf@gitster.g","subject":"RE: [PATCH v2 0/8] post-v2.33 \"drop support for ancient curl\" follow-up","fromName":"Randall S. Becker","fromEmail":"rsbecker@nexbridge.com","sentAt":"2021-09-10T17:06:52Z","receivedAt":"2021-09-10T17:07:28Z","isPatch":true,"sender":{"key":"randall.becker@nexbridge.ca","avatar":"https://avatars.githubusercontent.com/u/28956764?v=4"},"body":"On September 10, 2021 12:53 PM, Junio C Hamano wrote:\n>To: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n>Cc: git@vger.kernel.org; Jeff King <peff@peff.net>; brian m . carlson <sandals@crustytoothpaste.net>; Bagas Sanjaya\n><bagasdotme@gmail.com>\n>Subject: Re: [PATCH v2 0/8] post-v2.33 \"drop support for ancient curl\" follow-up\n>\n>Ævar Arnfjörð Bjarmason  <avarab@gmail.com> writes:\n>\n>> Version 1 of this had a really bad bug where we'd effectively make all\n>> supported curl versions act like 7.19.4, i.e. the oldest supported\n>> version except for a couple of our supported features. This is because\n>> most of the things checked with the \"ifdef\" checks are enum fields,\n>> not macros. So basically the \"devil's advocate\" Jeff King pointed out\n>> in [2] was already the case. Oops!\n>\n>Wow.  Thanks for bothering to actually test ;-)\n>\n>Because we learned that \"#ifdef CURL_SOME_FEATURE_WE_WANT\" is not a generally applicable way to conditionally build for various\n>features and we'd need to switch on the version numbers, it is now clear (at least to me) that the central registry approach would be a\n>direction to go.\n>\n>> In this v2 we're instead checking LIBCURL_VERSION_NUM consistently,\n>> even in those cases where we are checking things that are defined via\n>> macros.\n>\n>Nice.\n>\n>>     ++ * For each X symbol we need from curl we define our own\n>>     ++ * GIT_CURL_HAVE_X. If multiple similar symbols with the same prefix\n>>     ++ * were defined in the same version we pick one and check for that name.\n>>      + *\n>>      + * Keep any symbols in date order of when their support was\n>>      + * introduced, oldest first, in the official version of cURL library.\n>>     @@ git-curl-compat.h (new)\n>>      +/**\n>>      + * CURLOPT_TCP_KEEPALIVE was added in 7.25.0, released in March 2012.\n>>      + */\n>>     -+#ifdef CURLOPT_TCP_KEEPALIVE\n>>     ++#if LIBCURL_VERSION_NUM >= 0x071900\n>>      +#define GITCURL_HAVE_CURLOPT_TCP_KEEPALIVE 1\n>>      +#endif\n>\n>What we have in the posted patch is perfectly OK and serviceable, but this organization somewhat surprised me.\n>\n>Instead of one #if...#endif block per a feature macro, I expected to see a sequence of\n>\n>\t/* 7.34.0 (0x072200) - Dec 2013 */\n>\t#if 0x072200 < VERSION\n>\t#define HAVE_FOO 1\n>\t#define HAVE_BAR 1\n>\t...\n>\t#endif\n>\n>\t/* 7.25.0 (0x071900) - March 2012 */\n>\t#if 0x071900 < VERSION\n>\t#define HAVE_BAZ 1\n>\t#define HAVE_QUX 1\n>\t...\n>        #endif\n>\n>\n>because it would make it more clear which features can now be unconditionally used when we raise the cut-off point for the oldest\n>supported version if we group these entries along the versions.\n>\n>Thanks.\n\nNot that it might matter much, but both NonStop platforms are now on curl 7.78.0 and we are deploying git under OpenSSL 3 this week or next. So any objections I might previously have had are now fortunately really moot.\nCheers,\n-Randall\n\n"},{"id":"435447","messageId":"xmqqbl50tkte.fsf@gitster.g","threadId":"46547","inReplyTo":"cover-v2-0.8-00000000000-20210910T105523Z-avarab@gmail.com","subject":"Re: [PATCH v2 0/8] post-v2.33 \"drop support for ancient curl\" follow-up","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2021-09-10T17:14:05Z","receivedAt":"2021-09-10T17:14:11Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Ævar Arnfjörð Bjarmason  <avarab@gmail.com> writes:\n\n> This is a follow-up to the already-integrated topic for dropping\n> support for older curl versions submitted before the v2.33 release[1].\n\nTo which commit are these expected to apply?  I am having trouble\nwiggling 5 and 7 in.\n\nThanks.\n"},{"id":"435450","messageId":"xmqq7dfotjy3.fsf@gitster.g","threadId":"46547","inReplyTo":"xmqqbl50tkte.fsf@gitster.g","subject":"Re: [PATCH v2 0/8] post-v2.33 \"drop support for ancient curl\" follow-up","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2021-09-10T17:32:52Z","receivedAt":"2021-09-10T17:33:01Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Junio C Hamano <gitster@pobox.com> writes:\n\n> Ævar Arnfjörð Bjarmason  <avarab@gmail.com> writes:\n>\n>> This is a follow-up to the already-integrated topic for dropping\n>> support for older curl versions submitted before the v2.33 release[1].\n>\n> To which commit are these expected to apply?  I am having trouble\n> wiggling 5 and 7 in.\n\nNevermind.  I seem to be getting garbage from \"b4 am\", possibly an\noperator error.  I've seen \"b4 am\" getting confused on a thread with\nmultiple versions (like the config-based-hook thing where the\nmixture of Emily's v9 and your v5 for base in the same huge thread\nseem to confuse it).\n\n"},{"id":"435451","messageId":"8735qccop0.fsf@evledraar.gmail.com","threadId":"46547","inReplyTo":"nycvar.QRO.7.76.2109101713110.2614@fvyyl","subject":"Re: [PATCH v2 5/8] http: correct version check for CURL_HTTP_VERSION_2","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-09-10T17:19:29Z","receivedAt":"2021-09-10T17:42:23Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"\nOn Fri, Sep 10 2021, Daniel Stenberg wrote:\n\n> On Fri, 10 Sep 2021, Jeff King wrote:\n>\n>>> The newest symbol we depend on is CURL_HTTP_VERSION_2. It was added\n>>> in 7.33.0, but the CURL_HTTP_VERSION_2 alias we used was added in\n>>> 7.47.0. So we could support an even older version here, but let's\n>>> just correct the checked version.\n>>\n>> Thanks for expanding on the history here. I agree it probably\n>> doesn't matter much between the two versions, as they're both 6+\n>> years old (and only about 6 months apart). If somebody has a case\n>> where it really matters, they can submit a patch.\n>\n> Forgive me for digressing a bit here but wow, I *so* appreciate your\n> digging into the details of the curl history and the symbols that were\n> introduced when etc. I know of no other libcurl-using project with\n> this eye and sense for historic details and as the lead maintainer of\n> libcurl I learn a lot here. It also keeps me motivated to provide this\n> documentation and work on keeping in accurate.\n>\n> Keep it up! <3\n\nThanks! And thanks for curl.\n\nFor what it's worth I found myself looking for some bidirectional API\nmapping between these option IDs and their names, we tend to prefer that\nsort of pattern in git.git to macros, since we can test that something\ncompiles everywhere, run tests without the feature without recompiling\netc.\n\nI found that curl didn't have anything like that & started writing up a\nfeature request for it, only to find that my curl.git checkout had been\non an older commit, and that you'd added that API last year in curl.git\n6ebe63fac (options: API for meta-data about easy options, 2020-08-26):\n\n    https://curl.se/libcurl/c/curl_easy_option_by_name.html\n\nIt's probably not something we can use in the next 10 years, but if\nwhatever the most ancient OS we support upgrades past it it should make\ndealing with the version-specific code in http.c even easier.\n"},{"id":"435452","messageId":"YTuZ7LKQu2u2133e@coredump.intra.peff.net","threadId":"46547","inReplyTo":"xmqqmtoktln0.fsf@gitster.g","subject":"Re: [PATCH v2 2/8] INSTALL: mention that we need libcurl 7.19.4 or newer to build","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2021-09-10T17:46:20Z","receivedAt":"2021-09-10T17:46:23Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Fri, Sep 10, 2021 at 09:56:19AM -0700, Junio C Hamano wrote:\n\n> Jeff King <peff@peff.net> writes:\n> \n> > On Fri, Sep 10, 2021 at 01:04:27PM +0200, Ævar Arnfjörð Bjarmason wrote:\n> >\n> >> Without NO_CURL=Y we require at least version \"7.19.4\" of libcurl, see\n> >> 644de29e220 (http: drop support for curl < 7.19.4, 2021-07-30). Let's\n> >> document this in the \"INSTALL\" document.\n> >\n> > Makes sense.\n> >\n> >> diff --git a/INSTALL b/INSTALL\n> >> index 5c6ecf03c27..81f3a6cf018 100644\n> >> --- a/INSTALL\n> >> +++ b/INSTALL\n> >> @@ -141,6 +141,9 @@ Issues of note:\n> >>  \t- \"libcurl\" library is used by git-http-fetch, git-fetch, and, if\n> >>  \t  the curl version >= 7.34.0, for git-imap-send.\n> >>  \n> >> +\t  Git version \"7.19.4\" of \"libcurl\" or later to build. This\n> >> +\t  version requirement may be bumped in the future.\n> >> +\n> >\n> > s/to build/is needed &/ or similar?\n> \n> \"Get version X of \"libcurl\" or later to build.\" probably.\n\nOh, heh. I do not even see s/Git/Get/ anymore. My mind has been\nirrecoverably polluted.\n\n-Peff\n"},{"id":"435453","messageId":"87y284b9xn.fsf@evledraar.gmail.com","threadId":"46547","inReplyTo":"xmqqr1dwtlt1.fsf@gitster.g","subject":"Re: [PATCH v2 0/8] post-v2.33 \"drop support for ancient curl\" follow-up","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-09-10T17:42:45Z","receivedAt":"2021-09-10T17:46:34Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"\nOn Fri, Sep 10 2021, Junio C Hamano wrote:\n\n> Ævar Arnfjörð Bjarmason  <avarab@gmail.com> writes:\n>\n>> Version 1 of this had a really bad bug where we'd effectively make all\n>> supported curl versions act like 7.19.4, i.e. the oldest supported\n>> version except for a couple of our supported features. This is because\n>> most of the things checked with the \"ifdef\" checks are enum fields,\n>> not macros. So basically the \"devil's advocate\" Jeff King pointed out\n>> in [2] was already the case. Oops!\n>\n> Wow.  Thanks for bothering to actually test ;-)\n\nFWIW I'd tested that this worked for CURL_SOCKOPT_OK for v1, but there I\nhappened to pick one that *is* a macro.\n\nThen I also tested GIT_CURL_HAVE_CURLOPT_PINNEDPUBLICKEY, which isn't,\nbut the way I wrote the code would have thrown a warning/error about the\nunused variable, except in v1 I managed to scew that up in the last\npatch, so we unconditionally used the relevant variable either way...\n"},{"id":"435454","messageId":"87tuisb9qu.fsf@evledraar.gmail.com","threadId":"46547","inReplyTo":"xmqqbl50tkte.fsf@gitster.g","subject":"Re: [PATCH v2 0/8] post-v2.33 \"drop support for ancient curl\" follow-up","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-09-10T17:47:55Z","receivedAt":"2021-09-10T17:50:37Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"\nOn Fri, Sep 10 2021, Junio C Hamano wrote:\n\n> Ævar Arnfjörð Bjarmason  <avarab@gmail.com> writes:\n>\n>> This is a follow-up to the already-integrated topic for dropping\n>> support for older curl versions submitted before the v2.33 release[1].\n>\n> To which commit are these expected to apply?  I am having trouble\n> wiggling 5 and 7 in.\n\nI based this on top of the current master (8463beaeb69) and these apply\ncleanly to me on top of that:\n    \n    vm git (master $>) 0 $ git reset --hard @{u}\n    HEAD is now at 8463beaeb69 The fourth batch\n    vm git (master $=) 0 $ git am 000*patch\n    Applying: INSTALL: don't mention the \"curl\" executable at all\n    Applying: INSTALL: mention that we need libcurl 7.19.4 or newer to build\n    Applying: Makefile: drop support for curl < 7.9.8 (again)\n    Applying: http: drop support for curl < 7.18.0 (again)\n    Applying: http: correct version check for CURL_HTTP_VERSION_2\n    Applying: http: correct curl version check for CURLOPT_PINNEDPUBLICKEY\n    Applying: http: centralize the accounting of libcurl dependencies\n    Applying: http: don't hardcode the value of CURL_SOCKOPT_OK\n\nSo, weird, I can't imagine why they wouldn't apply...\n"},{"id":"435460","messageId":"20210910190507.k6gxpsdnwtqyog5c@meerkat.local","threadId":"46547","inReplyTo":"xmqq7dfotjy3.fsf@gitster.g","subject":"Re: [PATCH v2 0/8] post-v2.33 \"drop support for ancient curl\" follow-up","fromName":"Konstantin Ryabitsev","fromEmail":"konstantin@linuxfoundation.org","sentAt":"2021-09-10T19:05:07Z","receivedAt":"2021-09-10T19:05:13Z","isPatch":true,"sender":{"key":"konstantin@linuxfoundation.org","avatar":"https://gravatar.com/avatar/7cb8827c6de56e1bd2dea16508c6708aa43feed3bf3813bcdacecdf96ceadd79?d=mp&s=160"},"body":"On Fri, Sep 10, 2021 at 10:32:52AM -0700, Junio C Hamano wrote:\n> >> This is a follow-up to the already-integrated topic for dropping\n> >> support for older curl versions submitted before the v2.33 release[1].\n> >\n> > To which commit are these expected to apply?  I am having trouble\n> > wiggling 5 and 7 in.\n> \n> Nevermind.  I seem to be getting garbage from \"b4 am\", possibly an\n> operator error.  I've seen \"b4 am\" getting confused on a thread with\n> multiple versions (like the config-based-hook thing where the\n> mixture of Emily's v9 and your v5 for base in the same huge thread\n> seem to confuse it).\n\nYeah, sorry, the thread is not great for figuring out which patch goes where\n(there are two v2 versions, one from July and one from today, and a v4 from\nJuly that b4 considers the latest). \n\nThe only solution I can offer is doing \"b4 mbox\" first, then deleting\neverything you don't want, and then doing \"b4 am -m that.mbox\".\n\nI could add extra heuristics that also looks at series age, but I'm worried\nthat the \"what you get is what you (probably) meant\" logic will just get more\nand more tortured.\n\n-K\n"},{"id":"435462","messageId":"87lf44b4e0.fsf@evledraar.gmail.com","threadId":"46547","inReplyTo":"nycvar.QRO.7.76.2109101740380.2614@fvyyl","subject":"Re: [PATCH 2/5] http: correct curl version check for CURLOPT_PINNEDPUBLICKEY","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-09-10T19:41:41Z","receivedAt":"2021-09-10T19:46:22Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"\nOn Fri, Sep 10 2021, Daniel Stenberg wrote:\n\n> On Fri, 10 Sep 2021, Jeff King wrote:\n>\n>>> 1. protip: curl.git git tags are rather useless, since (at least for old\n>>>    versions) the embedded version number is bumped sometime *after* the\n>>>    release).\n>\n> (double-level quote since I miseed the original email saying this)\n>\n> This is simply not true and it makes me really curious why you would\n> think this.\n>\n> We (in the curl project) tag the git repository exactly at the point\n> we generate the release from. The release is however the generated\n> tarball, and the tag is the moment in the git history where the\n> release was done. That's why the release number at the time of the tag\n> will always say \"blabla-DEV\" something.\n>\n> I know this, becasue I've done every single curl release personally,\n> since the dawn of time. Of course we've only used git since about 2010\n> but I can't remember that we ever did it differently.\n>\n> The exact step-by-step to do a release is also documented since years back:\n>   https://curl.se/dev/release-procedure.html\n\nI take that back, sorry.\n\nIt turns out to just have been a stupid mistake of mine. I don't know\nwhere exactly but somewhere in the checking out of verions, building &\ninstalling them I had a LIBCURL_VERSION_NUM that didn't match. But\nlooking back at the tarballs I unpacked (which I didn't remove in the\ninterim) it does match.\n\nSo it was just a mistake of mine, sorry to soil curl's good reputation\non a public ML, my bad.\n\nFor what it's worth I'm rather prejudiced to the knee-jerk reaction of\njust giving up on source control pretty early on for this sort of thing.\nI.e. seeing what state some some ancient software version from 10-15-20\nyears back was in.\n\nIt is really common for the two to mismatch (e.g. because there was\nnever a version for that release, the maintainer grabbed some version,\ndid \"make dist\", adjusted files manually etc.). But apparently curl was\nrather early on bandwagon of good SCM practices.\n\n"},{"id":"435463","messageId":"xmqqo890rz2k.fsf@gitster.g","threadId":"46547","inReplyTo":"20210910190507.k6gxpsdnwtqyog5c@meerkat.local","subject":"Re: [PATCH v2 0/8] post-v2.33 \"drop support for ancient curl\" follow-up","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2021-09-10T19:49:07Z","receivedAt":"2021-09-10T19:49:16Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Konstantin Ryabitsev <konstantin@linuxfoundation.org> writes:\n\n> The only solution I can offer is doing \"b4 mbox\" first, then deleting\n> everything you don't want, and then doing \"b4 am -m that.mbox\".\n\nThanks.  Marking the articles I want in GNUS (I read via\nnntp://lore) and downloading works just fine ;-)\n"},{"id":"435483","messageId":"nycvar.QRO.7.76.2109102350460.2614@fvyyl","threadId":"46547","inReplyTo":"87lf44b4e0.fsf@evledraar.gmail.com","subject":"Re: [PATCH 2/5] http: correct curl version check for CURLOPT_PINNEDPUBLICKEY","fromName":"Daniel Stenberg","fromEmail":"daniel@haxx.se","sentAt":"2021-09-10T21:57:04Z","receivedAt":"2021-09-10T21:57:08Z","isPatch":true,"sender":{"key":"daniel@haxx.se","avatar":"https://gravatar.com/avatar/69fdca87edd17cee21ca2e79fc2ff671d644603c3dc27167430f3cd3dbab7ba8?d=mp&s=160"},"body":"On Fri, 10 Sep 2021, Ævar Arnfjörð Bjarmason wrote:\n\n> So it was just a mistake of mine, sorry to soil curl's good reputation on a \n> public ML, my bad.\n\nAh, no worries. I'm just glad things are good!\n\n> It is really common for the two to mismatch (e.g. because there was never a \n> version for that release, the maintainer grabbed some version, did \"make \n> dist\", adjusted files manually etc.). But apparently curl was rather early \n> on bandwagon of good SCM practices.\n\nI'd like to think that we've had that part pretty well nailed since a very \nlong time back, partly thanks to us sticking to simple and straight-forward \neven for version control. And of course thanks to git for making it easy to do \nit right!\n\n-- \n\n  / daniel.haxx.se"},{"id":"435487","messageId":"1b18309a-93e8-60cc-1bd3-61857b1da819@gmail.com","threadId":"46547","inReplyTo":"patch-v4-2.5-fb308258e2b-20210730T175650Z-avarab@gmail.com","subject":"Re: [PATCH v4 2/5] http: drop support for curl < 7.16.0","fromName":"Andrei Rybak","fromEmail":"rybak.a.v@gmail.com","sentAt":"2021-09-10T22:28:25Z","receivedAt":"2021-09-10T22:28:31Z","isPatch":true,"sender":{"key":"rybak.a.v@gmail.com","avatar":"https://avatars.githubusercontent.com/u/624072?v=4"},"body":"On 30/07/2021 19:59, Ævar Arnfjörð Bjarmason wrote:\n> From: Jeff King <peff@peff.net>\n> \n> In the last commit we dropped support for curl < 7.11.1, let's\n> continue that and drop support for versions older than 7.16.0. This\n> allows us to get rid of some now-obsolete #ifdefs.\n> \n> Choosing 7.16.0 is a somewhat arbitrary cutoff:\n> \n>    1. It came out in October of 2006, almost 15 years ago.\n>       Besides being a nice round number, around 10 years is\n>       a common end-of-life support period, even for conservative\n>       distributions.\n> \n>    2. That version introduced the curl_multi interface, which\n>       gives us a lot of bang for the buck in removing #ifdefs\n> \n> RHEL 5 came with curl 7.15.5[1] (released in August 2006). RHEL 5's\n> extended life cycle program ended on 2020-11-30[1]. RHEL 6 comes with\n> curl 7.19.7 (released in November 2009), and RHEL 7 comes with\n> 7.29.0 (released in February 2013).\n> \n> 1. http://lore.kernel.org/git/873e1f31-2a96-5b72-2f20-a5816cad1b51@jupiterrise.com\n> \n> Signed-off-by: Jeff King <peff@peff.net>\n> Signed-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n> ---\n\n[...]\n\n> diff --git a/http.c b/http.c\n> index 56182a89e25..ef00e930232 100644\n> --- a/http.c\n> +++ b/http.c\n> @@ -26,10 +26,8 @@ ssize_t http_post_buffer = 16 * LARGE_PACKET_MAX;\n>   \n>   static int min_curl_sessions = 1;\n>   static int curl_session_count;\n> -#ifdef USE_CURL_MULTI\n>   static int max_requests = -1;\n>   static CURLM *curlm;\n> -#endif\n>   #ifndef NO_CURL_EASY_DUPHANDLE\n>   static CURL *curl_default;\n>   #endif\n> @@ -117,14 +115,6 @@ static int curl_empty_auth = -1;\n>   \n>   enum http_follow_config http_follow_config = HTTP_FOLLOW_INITIAL;\n>   \n> -#if LIBCURL_VERSION_NUM >= 0x071700\n> -/* Use CURLOPT_KEYPASSWD as is */\n> -#elif LIBCURL_VERSION_NUM >= 0x070903\n> -#define CURLOPT_KEYPASSWD CURLOPT_SSLKEYPASSWD\n> -#else\n> -#define CURLOPT_KEYPASSWD CURLOPT_SSLCERTPASSWD\n> -#endif\n\nIn 0x071700, 0x17 == 23, so it seems that this chain of `#if`s\ndistinguishes between three categories of curl versions:\n\n   1. version < 7.9.3\n   2. 7.9.3 <= version < 7.23.0\n   3. 7.23.0 <= version\n\nSo it seems that this patch [1] drops support for curl < 7.23.0, while\nthe subject line claims \"drop support for curl < 7.16.0\".\n\n[1]: already in branch master as commit 013c7e2b07 (http: drop support\n      for curl < 7.16.0, 2021-07-30)\n\n> -\n>   static struct credential cert_auth = CREDENTIAL_INIT;\n>   static int ssl_cert_password_required;\n>   static unsigned long http_auth_methods = CURLAUTH_ANY;\n> @@ -168,7 +158,6 @@ size_t fread_buffer(char *ptr, size_t eltsize, size_t nmemb, void *buffer_)\n>   \treturn size / eltsize;\n>   }\n>   \n> -#ifndef NO_CURL_IOCTL\n>   curlioerr ioctl_buffer(CURL *handle, int cmd, void *clientp)\n>   {\n>   \tstruct buffer *buffer = clientp;\n> @@ -185,7 +174,6 @@ curlioerr ioctl_buffer(CURL *handle, int cmd, void *clientp)\n>   \t\treturn CURLIOE_UNKNOWNCMD;\n>   \t}\n>   }\n> -#endif\n>   \n>   size_t fwrite_buffer(char *ptr, size_t eltsize, size_t nmemb, void *buffer_)\n>   {\n> @@ -233,12 +221,9 @@ static void finish_active_slot(struct active_request_slot *slot)\n>   \n>   static void xmulti_remove_handle(struct active_request_slot *slot)\n>   {\n> -#ifdef USE_CURL_MULTI\n>   \tcurl_multi_remove_handle(curlm, slot->curl);\n> -#endif\n>   }\n>   \n> -#ifdef USE_CURL_MULTI\n>   static void process_curl_messages(void)\n>   {\n>   \tint num_messages;\n> @@ -266,7 +251,6 @@ static void process_curl_messages(void)\n>   \t\tcurl_message = curl_multi_info_read(curlm, &num_messages);\n>   \t}\n>   }\n> -#endif\n>   \n>   static int http_options(const char *var, const char *value, void *cb)\n>   {\n> @@ -315,18 +299,14 @@ static int http_options(const char *var, const char *value, void *cb)\n>   \n>   \tif (!strcmp(\"http.minsessions\", var)) {\n>   \t\tmin_curl_sessions = git_config_int(var, value);\n> -#ifndef USE_CURL_MULTI\n>   \t\tif (min_curl_sessions > 1)\n>   \t\t\tmin_curl_sessions = 1;\n> -#endif\n>   \t\treturn 0;\n>   \t}\n> -#ifdef USE_CURL_MULTI\n>   \tif (!strcmp(\"http.maxrequests\", var)) {\n>   \t\tmax_requests = git_config_int(var, value);\n>   \t\treturn 0;\n>   \t}\n> -#endif\n>   \tif (!strcmp(\"http.lowspeedlimit\", var)) {\n>   \t\tcurl_low_speed_limit = (long)git_config_int(var, value);\n>   \t\treturn 0;\n> @@ -574,7 +554,7 @@ static void set_curl_keepalive(CURL *c)\n>   \tcurl_easy_setopt(c, CURLOPT_TCP_KEEPALIVE, 1);\n>   }\n>   \n> -#elif LIBCURL_VERSION_NUM >= 0x071000\n> +#else\n>   static int sockopt_callback(void *client, curl_socket_t fd, curlsocktype type)\n>   {\n>   \tint ka = 1;\n> @@ -595,12 +575,6 @@ static void set_curl_keepalive(CURL *c)\n>   {\n>   \tcurl_easy_setopt(c, CURLOPT_SOCKOPTFUNCTION, sockopt_callback);\n>   }\n> -\n> -#else\n> -static void set_curl_keepalive(CURL *c)\n> -{\n> -\t/* not supported on older curl versions */\n> -}\n>   #endif\n>   \n>   static void redact_sensitive_header(struct strbuf *header)\n> @@ -1121,7 +1095,6 @@ void http_init(struct remote *remote, const char *url, int proactive_auth)\n>   \tno_pragma_header = curl_slist_append(http_copy_default_headers(),\n>   \t\t\"Pragma:\");\n>   \n> -#ifdef USE_CURL_MULTI\n>   \t{\n>   \t\tchar *http_max_requests = getenv(\"GIT_HTTP_MAX_REQUESTS\");\n>   \t\tif (http_max_requests != NULL)\n> @@ -1131,7 +1104,6 @@ void http_init(struct remote *remote, const char *url, int proactive_auth)\n>   \tcurlm = curl_multi_init();\n>   \tif (!curlm)\n>   \t\tdie(\"curl_multi_init failed\");\n> -#endif\n>   \n>   \tif (getenv(\"GIT_SSL_NO_VERIFY\"))\n>   \t\tcurl_ssl_verify = 0;\n> @@ -1154,10 +1126,8 @@ void http_init(struct remote *remote, const char *url, int proactive_auth)\n>   \t\tcurl_ssl_verify = 1;\n>   \n>   \tcurl_session_count = 0;\n> -#ifdef USE_CURL_MULTI\n>   \tif (max_requests < 1)\n>   \t\tmax_requests = DEFAULT_MAX_REQUESTS;\n> -#endif\n>   \n>   \tset_from_env(&http_proxy_ssl_cert, \"GIT_PROXY_SSL_CERT\");\n>   \tset_from_env(&http_proxy_ssl_key, \"GIT_PROXY_SSL_KEY\");\n> @@ -1201,9 +1171,7 @@ void http_cleanup(void)\n>   \tcurl_easy_cleanup(curl_default);\n>   #endif\n>   \n> -#ifdef USE_CURL_MULTI\n>   \tcurl_multi_cleanup(curlm);\n> -#endif\n>   \tcurl_global_cleanup();\n>   \n>   \tstring_list_clear(&extra_http_headers, 0);\n> @@ -1250,7 +1218,6 @@ struct active_request_slot *get_active_slot(void)\n>   \tstruct active_request_slot *slot = active_queue_head;\n>   \tstruct active_request_slot *newslot;\n>   \n> -#ifdef USE_CURL_MULTI\n>   \tint num_transfers;\n>   \n>   \t/* Wait for a slot to open up if the queue is full */\n> @@ -1259,7 +1226,6 @@ struct active_request_slot *get_active_slot(void)\n>   \t\tif (num_transfers < active_requests)\n>   \t\t\tprocess_curl_messages();\n>   \t}\n> -#endif\n>   \n>   \twhile (slot != NULL && slot->in_use)\n>   \t\tslot = slot->next;\n> @@ -1330,7 +1296,6 @@ struct active_request_slot *get_active_slot(void)\n>   \n>   int start_active_slot(struct active_request_slot *slot)\n>   {\n> -#ifdef USE_CURL_MULTI\n>   \tCURLMcode curlm_result = curl_multi_add_handle(curlm, slot->curl);\n>   \tint num_transfers;\n>   \n> @@ -1348,11 +1313,9 @@ int start_active_slot(struct active_request_slot *slot)\n>   \t * something.\n>   \t */\n>   \tcurl_multi_perform(curlm, &num_transfers);\n> -#endif\n>   \treturn 1;\n>   }\n>   \n> -#ifdef USE_CURL_MULTI\n>   struct fill_chain {\n>   \tvoid *data;\n>   \tint (*fill)(void *);\n> @@ -1411,11 +1374,9 @@ void step_active_slots(void)\n>   \t\tfill_active_slots();\n>   \t}\n>   }\n> -#endif\n>   \n>   void run_active_slot(struct active_request_slot *slot)\n>   {\n> -#ifdef USE_CURL_MULTI\n>   \tfd_set readfds;\n>   \tfd_set writefds;\n>   \tfd_set excfds;\n> @@ -1428,7 +1389,6 @@ void run_active_slot(struct active_request_slot *slot)\n>   \t\tstep_active_slots();\n>   \n>   \t\tif (slot->in_use) {\n> -#if LIBCURL_VERSION_NUM >= 0x070f04\n>   \t\t\tlong curl_timeout;\n>   \t\t\tcurl_multi_timeout(curlm, &curl_timeout);\n>   \t\t\tif (curl_timeout == 0) {\n> @@ -1440,10 +1400,6 @@ void run_active_slot(struct active_request_slot *slot)\n>   \t\t\t\tselect_timeout.tv_sec  =  curl_timeout / 1000;\n>   \t\t\t\tselect_timeout.tv_usec = (curl_timeout % 1000) * 1000;\n>   \t\t\t}\n> -#else\n> -\t\t\tselect_timeout.tv_sec  = 0;\n> -\t\t\tselect_timeout.tv_usec = 50000;\n> -#endif\n>   \n>   \t\t\tmax_fd = -1;\n>   \t\t\tFD_ZERO(&readfds);\n> @@ -1466,12 +1422,6 @@ void run_active_slot(struct active_request_slot *slot)\n>   \t\t\tselect(max_fd+1, &readfds, &writefds, &excfds, &select_timeout);\n>   \t\t}\n>   \t}\n> -#else\n> -\twhile (slot->in_use) {\n> -\t\tslot->curl_result = curl_easy_perform(slot->curl);\n> -\t\tfinish_active_slot(slot);\n> -\t}\n> -#endif\n>   }\n>   \n>   static void release_active_slot(struct active_request_slot *slot)\n> @@ -1485,9 +1435,7 @@ static void release_active_slot(struct active_request_slot *slot)\n>   \t\t\tcurl_session_count--;\n>   \t\t}\n>   \t}\n> -#ifdef USE_CURL_MULTI\n>   \tfill_active_slots();\n> -#endif\n>   }\n>   \n>   void finish_all_active_slots(void)\n> @@ -1613,12 +1561,10 @@ static int handle_curl_result(struct slot_results *results)\n>   \t} else {\n>   \t\tif (results->http_connectcode == 407)\n>   \t\t\tcredential_reject(&proxy_auth);\n> -#if LIBCURL_VERSION_NUM >= 0x070c00\n>   \t\tif (!curl_errorstr[0])\n>   \t\t\tstrlcpy(curl_errorstr,\n>   \t\t\t\tcurl_easy_strerror(results->curl_result),\n>   \t\t\t\tsizeof(curl_errorstr));\n> -#endif\n>   \t\treturn HTTP_ERROR;\n>   \t}\n>   }\n> diff --git a/http.h b/http.h\n> index d2f8cc56617..cb092622a73 100644\n> --- a/http.h\n> +++ b/http.h\n> @@ -10,31 +10,12 @@\n>   #include \"remote.h\"\n>   #include \"url.h\"\n>   \n> -/*\n> - * We detect based on the cURL version if multi-transfer is\n> - * usable in this implementation and define this symbol accordingly.\n> - * This shouldn't be set by the Makefile or by the user (e.g. via CFLAGS).\n> - */\n> -#undef USE_CURL_MULTI\n> -\n> -#if LIBCURL_VERSION_NUM >= 0x071000\n> -#define USE_CURL_MULTI\n>   #define DEFAULT_MAX_REQUESTS 5\n> -#endif\n> -\n> -#if LIBCURL_VERSION_NUM >= 0x070c00\n> -#define curl_global_init(a) curl_global_init_mem(a, xmalloc, free, \\\n> -\t\t\t\t\t\txrealloc, xstrdup, xcalloc)\n> -#endif\n>   \n> -#if (LIBCURL_VERSION_NUM < 0x070c04) || (LIBCURL_VERSION_NUM == 0x071000)\n> +#if LIBCURL_VERSION_NUM == 0x071000\n>   #define NO_CURL_EASY_DUPHANDLE\n>   #endif\n>   \n> -#if LIBCURL_VERSION_NUM < 0x070c03\n> -#define NO_CURL_IOCTL\n> -#endif\n> -\n>   /*\n>    * CURLOPT_USE_SSL was known as CURLOPT_FTP_SSL up to 7.16.4,\n>    * and the constants were known as CURLFTPSSL_*\n> @@ -72,9 +53,7 @@ struct buffer {\n>   size_t fread_buffer(char *ptr, size_t eltsize, size_t nmemb, void *strbuf);\n>   size_t fwrite_buffer(char *ptr, size_t eltsize, size_t nmemb, void *strbuf);\n>   size_t fwrite_null(char *ptr, size_t eltsize, size_t nmemb, void *strbuf);\n> -#ifndef NO_CURL_IOCTL\n>   curlioerr ioctl_buffer(CURL *handle, int cmd, void *clientp);\n> -#endif\n>   \n>   /* Slot lifecycle functions */\n>   struct active_request_slot *get_active_slot(void);\n> @@ -91,11 +70,9 @@ void finish_all_active_slots(void);\n>   int run_one_slot(struct active_request_slot *slot,\n>   \t\t struct slot_results *results);\n>   \n> -#ifdef USE_CURL_MULTI\n>   void fill_active_slots(void);\n>   void add_fill_function(void *data, int (*fill)(void *));\n>   void step_active_slots(void);\n> -#endif\n>   \n>   void http_init(struct remote *remote, const char *url,\n>   \t       int proactive_auth);\n> diff --git a/imap-send.c b/imap-send.c\n> index a0540ba5cf4..49a5f8aa597 100644\n> --- a/imap-send.c\n> +++ b/imap-send.c\n> @@ -1517,11 +1517,7 @@ static int curl_append_msgs_to_imap(struct imap_server_conf *server,\n>   \tif (cred.username) {\n>   \t\tif (res == CURLE_OK)\n>   \t\t\tcredential_approve(&cred);\n> -#if LIBCURL_VERSION_NUM >= 0x070d01\n>   \t\telse if (res == CURLE_LOGIN_DENIED)\n> -#else\n> -\t\telse\n> -#endif\n>   \t\t\tcredential_reject(&cred);\n>   \t}\n>   \n> diff --git a/remote-curl.c b/remote-curl.c\n> index e738ae2c48a..09f09aeece3 100644\n> --- a/remote-curl.c\n> +++ b/remote-curl.c\n> @@ -706,7 +706,6 @@ static size_t rpc_out(void *ptr, size_t eltsize,\n>   \treturn avail;\n>   }\n>   \n> -#ifndef NO_CURL_IOCTL\n>   static curlioerr rpc_ioctl(CURL *handle, int cmd, void *clientp)\n>   {\n>   \tstruct rpc_state *rpc = clientp;\n> @@ -727,7 +726,6 @@ static curlioerr rpc_ioctl(CURL *handle, int cmd, void *clientp)\n>   \t\treturn CURLIOE_UNKNOWNCMD;\n>   \t}\n>   }\n> -#endif\n>   \n>   struct check_pktline_state {\n>   \tchar len_buf[4];\n> @@ -946,10 +944,8 @@ static int post_rpc(struct rpc_state *rpc, int stateless_connect, int flush_rece\n>   \t\trpc->initial_buffer = 1;\n>   \t\tcurl_easy_setopt(slot->curl, CURLOPT_READFUNCTION, rpc_out);\n>   \t\tcurl_easy_setopt(slot->curl, CURLOPT_INFILE, rpc);\n> -#ifndef NO_CURL_IOCTL\n>   \t\tcurl_easy_setopt(slot->curl, CURLOPT_IOCTLFUNCTION, rpc_ioctl);\n>   \t\tcurl_easy_setopt(slot->curl, CURLOPT_IOCTLDATA, rpc);\n> -#endif\n>   \t\tif (options.verbosity > 1) {\n>   \t\t\tfprintf(stderr, \"POST %s (chunked)\\n\", rpc->service_name);\n>   \t\t\tfflush(stderr);\n> \n\n"},{"id":"435528","messageId":"cover-v3-0.9-00000000000-20210911T092751Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-v2-0.8-00000000000-20210910T105523Z-avarab@gmail.com","subject":"[PATCH v3 0/9] post-v2.33 \"drop support for ancient curl\" follow-up","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-09-11T09:34:14Z","receivedAt":"2021-09-11T09:34:28Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"This is a follow-up to the already-integrated topic for dropping\nsupport for older curl versions submitted before the v2.33 release[1].\n\nSee\nhttps://lore.kernel.org/git/cover-v2-0.8-00000000000-20210910T105523Z-avarab@gmail.com/\nfor v2.\n\nThis has relatively minor changes against v2. This addresses Jeff\nKing's comments about the INSTALL phrasing, I split up the more\ngeneral improvements into another commit.\n\nThe CURL_SOCKOPT_OK is now defined in terms of LIBCURL_VERSION_NUM\nlike everything else.\n\nI did not re-arrange the macros as suggested by Junio in\nhttp://lore.kernel.org/git/xmqqr1dwtlt1.fsf@gitster.g\n\nÆvar Arnfjörð Bjarmason (9):\n  INSTALL: don't mention the \"curl\" executable at all\n  INSTALL: reword and copy-edit the \"libcurl\" section\n  INSTALL: mention that we need libcurl 7.19.4 or newer to build\n  Makefile: drop support for curl < 7.9.8 (again)\n  http: drop support for curl < 7.18.0 (again)\n  http: correct version check for CURL_HTTP_VERSION_2\n  http: correct curl version check for CURLOPT_PINNEDPUBLICKEY\n  http: centralize the accounting of libcurl dependencies\n  http: don't hardcode the value of CURL_SOCKOPT_OK\n\n INSTALL           |  15 +++---\n Makefile          |  11 +---\n git-curl-compat.h | 128 ++++++++++++++++++++++++++++++++++++++++++++++\n http.c            |  35 ++++++-------\n imap-send.c       |   2 +-\n 5 files changed, 157 insertions(+), 34 deletions(-)\n create mode 100644 git-curl-compat.h\n\nRange-diff against v2:\n 1:  ac11cf8cfd1 !  1:  7b771aa70ef INSTALL: don't mention the \"curl\" executable at all\n    @@ INSTALL: Issues of note:\n      \t- \"libcurl\" library is used by git-http-fetch, git-fetch, and, if\n     -\t  the curl version >= 7.34.0, for git-imap-send.  You might also\n     -\t  want the \"curl\" executable for debugging purposes. If you do not\n    --\t  use http:// or https:// repositories, and do not want to put\n    --\t  patches into an IMAP mailbox, you do not have to have them\n    --\t  (use NO_CURL).\n    -+\t  the curl version >= 7.34.0, for git-imap-send.\n    -+\n    -+\t  If you do not use http:// or https:// repositories, and do\n    -+\t  not want to put patches into an IMAP mailbox, you do not\n    -+\t  have to have them (use NO_CURL).\n    - \n    - \t- \"expat\" library; git-http-push uses it for remote lock\n    - \t  management over DAV.  Similar to \"curl\" above, this is optional\n    ++\t  the curl version >= 7.34.0, for git-imap-send. If you do not\n    + \t  use http:// or https:// repositories, and do not want to put\n    + \t  patches into an IMAP mailbox, you do not have to have them\n    + \t  (use NO_CURL).\n -:  ----------- >  2:  3b0119958a3 INSTALL: reword and copy-edit the \"libcurl\" section\n 2:  4b653cee2d3 !  3:  dce6520a5c9 INSTALL: mention that we need libcurl 7.19.4 or newer to build\n    @@ Commit message\n     \n      ## INSTALL ##\n     @@ INSTALL: Issues of note:\n    - \t- \"libcurl\" library is used by git-http-fetch, git-fetch, and, if\n    - \t  the curl version >= 7.34.0, for git-imap-send.\n    + \t  not need that functionality, use NO_CURL to build without\n    + \t  it.\n      \n    -+\t  Git version \"7.19.4\" of \"libcurl\" or later to build. This\n    -+\t  version requirement may be bumped in the future.\n    ++\t  Git requires version \"7.19.4\" or later of \"libcurl\", to\n    ++\t  build (without NO_CURL). This version requirement may be\n    ++\t  bumped in the future.\n     +\n    - \t  If you do not use http:// or https:// repositories, and do\n    - \t  not want to put patches into an IMAP mailbox, you do not\n    - \t  have to have them (use NO_CURL).\n    + \t- \"expat\" library; git-http-push uses it for remote lock\n    + \t  management over DAV.  Similar to \"curl\" above, this is optional\n    + \t  (with NO_EXPAT).\n 3:  76c2aa6e78d =  4:  98cdb7c35a9 Makefile: drop support for curl < 7.9.8 (again)\n 4:  e73a9ff1780 =  5:  7919debfd89 http: drop support for curl < 7.18.0 (again)\n 5:  2567b888c3d =  6:  67bc1992762 http: correct version check for CURL_HTTP_VERSION_2\n 6:  397d54a1352 =  7:  db7d6029dda http: correct curl version check for CURLOPT_PINNEDPUBLICKEY\n 7:  8e57a8409c5 =  8:  e2e53cbfba1 http: centralize the accounting of libcurl dependencies\n 8:  465ab33ebda !  9:  4bdec34a545 http: don't hardcode the value of CURL_SOCKOPT_OK\n    @@ git-curl-compat.h\n      \n     +/**\n     + * CURL_SOCKOPT_OK was added in 7.21.5, released in April 2011.\n    -+ *\n    -+ * This should be safe as CURL_SOCKOPT_OK has always been a macro, not\n    -+ * an enum field (checked on curl version 7.78.0, released on July 19,\n    -+ * 2021). Even if that were to change the value of \"0\" for \"OK\" is\n    -+ * unlikely to change.\n     + */\n    -+#ifndef CURL_SOCKOPT_OK\n    ++#if LIBCURL_VERSION_NUM < 0x071505\n     +#define CURL_SOCKOPT_OK 0\n     +#endif\n     +\n-- \n2.33.0.984.gea2c3555113\n\n"},{"id":"435529","messageId":"patch-v3-1.9-7b771aa70ef-20210911T092751Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-v3-0.9-00000000000-20210911T092751Z-avarab@gmail.com","subject":"[PATCH v3 1/9] INSTALL: don't mention the \"curl\" executable at all","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-09-11T09:34:15Z","receivedAt":"2021-09-11T09:34:33Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"In 1d53f90ed97 (The \"curl\" executable is no longer required,\n2008-06-15) the wording for requiring curl(1) was changed to the\ncurrent \"you might also want...\".\n\nMentioning the \"curl\" executable at all is just confusing, someone\nbuilding git might want to use it to debug things, but they might also\njust use wget(1) or some other http client. The \"curl\" executable has\nthe advantage that you might be able to e.g. reproduce a bug in git's\nusage of libcurl with it, but anyone going to those extents is\nunlikely to be aided by this note in INSTALL.\n\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n INSTALL | 3 +--\n 1 file changed, 1 insertion(+), 2 deletions(-)\n\ndiff --git a/INSTALL b/INSTALL\nindex 66389ce0591..5b8bd5ccce1 100644\n--- a/INSTALL\n+++ b/INSTALL\n@@ -139,8 +139,7 @@ Issues of note:\n \t  (PPC_SHA1).\n \n \t- \"libcurl\" library is used by git-http-fetch, git-fetch, and, if\n-\t  the curl version >= 7.34.0, for git-imap-send.  You might also\n-\t  want the \"curl\" executable for debugging purposes. If you do not\n+\t  the curl version >= 7.34.0, for git-imap-send. If you do not\n \t  use http:// or https:// repositories, and do not want to put\n \t  patches into an IMAP mailbox, you do not have to have them\n \t  (use NO_CURL).\n-- \n2.33.0.984.gea2c3555113\n\n"},{"id":"435530","messageId":"patch-v3-2.9-3b0119958a3-20210911T092751Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-v3-0.9-00000000000-20210911T092751Z-avarab@gmail.com","subject":"[PATCH v3 2/9] INSTALL: reword and copy-edit the \"libcurl\" section","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-09-11T09:34:16Z","receivedAt":"2021-09-11T09:34:33Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"Make the \"libcurl\" section shorter and more to the point, this is\nmostly based on suggestions from [1].\n\n1. https://lore.kernel.org/git/YTtxcBdF2VQdWp5C@coredump.intra.peff.net/\n\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n INSTALL | 10 +++++-----\n 1 file changed, 5 insertions(+), 5 deletions(-)\n\ndiff --git a/INSTALL b/INSTALL\nindex 5b8bd5ccce1..d593f628749 100644\n--- a/INSTALL\n+++ b/INSTALL\n@@ -138,11 +138,11 @@ Issues of note:\n \t  BLK_SHA1.  Also included is a version optimized for PowerPC\n \t  (PPC_SHA1).\n \n-\t- \"libcurl\" library is used by git-http-fetch, git-fetch, and, if\n-\t  the curl version >= 7.34.0, for git-imap-send. If you do not\n-\t  use http:// or https:// repositories, and do not want to put\n-\t  patches into an IMAP mailbox, you do not have to have them\n-\t  (use NO_CURL).\n+\t- \"libcurl\" library is used for fetching and pushing\n+\t  repositories over http:// or https://, as well as by\n+\t  git-imap-send if the curl version is >= 7.34.0. If you do\n+\t  not need that functionality, use NO_CURL to build without\n+\t  it.\n \n \t- \"expat\" library; git-http-push uses it for remote lock\n \t  management over DAV.  Similar to \"curl\" above, this is optional\n-- \n2.33.0.984.gea2c3555113\n\n"},{"id":"435531","messageId":"patch-v3-3.9-dce6520a5c9-20210911T092751Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-v3-0.9-00000000000-20210911T092751Z-avarab@gmail.com","subject":"[PATCH v3 3/9] INSTALL: mention that we need libcurl 7.19.4 or newer to build","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-09-11T09:34:17Z","receivedAt":"2021-09-11T09:34:33Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"Without NO_CURL=Y we require at least version \"7.19.4\" of libcurl, see\n644de29e220 (http: drop support for curl < 7.19.4, 2021-07-30). Let's\ndocument this in the \"INSTALL\" document.\n\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n INSTALL | 4 ++++\n 1 file changed, 4 insertions(+)\n\ndiff --git a/INSTALL b/INSTALL\nindex d593f628749..795b02b6f96 100644\n--- a/INSTALL\n+++ b/INSTALL\n@@ -144,6 +144,10 @@ Issues of note:\n \t  not need that functionality, use NO_CURL to build without\n \t  it.\n \n+\t  Git requires version \"7.19.4\" or later of \"libcurl\", to\n+\t  build (without NO_CURL). This version requirement may be\n+\t  bumped in the future.\n+\n \t- \"expat\" library; git-http-push uses it for remote lock\n \t  management over DAV.  Similar to \"curl\" above, this is optional\n \t  (with NO_EXPAT).\n-- \n2.33.0.984.gea2c3555113\n\n"},{"id":"435532","messageId":"patch-v3-4.9-98cdb7c35a9-20210911T092751Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-v3-0.9-00000000000-20210911T092751Z-avarab@gmail.com","subject":"[PATCH v3 4/9] Makefile: drop support for curl < 7.9.8 (again)","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-09-11T09:34:18Z","receivedAt":"2021-09-11T09:34:35Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"In 1119a15b5c8 (http: drop support for curl < 7.11.1, 2021-07-30)\nsupport for curl versions older than 7.11.1 was removed, and we\ncurrently require at least version 7.19.4, see 644de29e220 (http: drop\nsupport for curl < 7.19.4, 2021-07-30).\n\nIn those changes this Makefile-specific check added in\n0890098780f (Decide whether to build http-push in the Makefile,\n2005-11-18) was missed, now that we're never going to use such an\nancient curl version we don't need to check that we have at least\n7.9.8 here. I have no idea what in http-push.c broke on versions older\nthan that.\n\nThis does not impact \"NO_CURL\" setups, as this is in the \"else\" branch\nafter that check.\n\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n Makefile | 11 ++---------\n 1 file changed, 2 insertions(+), 9 deletions(-)\n\ndiff --git a/Makefile b/Makefile\nindex 429c276058d..378f58b950d 100644\n--- a/Makefile\n+++ b/Makefile\n@@ -1436,15 +1436,8 @@ else\n \tREMOTE_CURL_NAMES = $(REMOTE_CURL_PRIMARY) $(REMOTE_CURL_ALIASES)\n \tPROGRAM_OBJS += http-fetch.o\n \tPROGRAMS += $(REMOTE_CURL_NAMES)\n-\tcurl_check := $(shell (echo 070908; $(CURL_CONFIG) --vernum | sed -e '/^70[BC]/s/^/0/') 2>/dev/null | sort -r | sed -ne 2p)\n-\tifeq \"$(curl_check)\" \"070908\"\n-\t\tifndef NO_EXPAT\n-\t\t\tPROGRAM_OBJS += http-push.o\n-\t\telse\n-\t\t\tEXCLUDED_PROGRAMS += git-http-push\n-\t\tendif\n-\telse\n-\t\tEXCLUDED_PROGRAMS += git-http-push\n+\tifndef NO_EXPAT\n+\t\tPROGRAM_OBJS += http-push.o\n \tendif\n \tcurl_check := $(shell (echo 072200; $(CURL_CONFIG) --vernum | sed -e '/^70[BC]/s/^/0/') 2>/dev/null | sort -r | sed -ne 2p)\n \tifeq \"$(curl_check)\" \"072200\"\n-- \n2.33.0.984.gea2c3555113\n\n"},{"id":"435533","messageId":"patch-v3-5.9-7919debfd89-20210911T092751Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-v3-0.9-00000000000-20210911T092751Z-avarab@gmail.com","subject":"[PATCH v3 5/9] http: drop support for curl < 7.18.0 (again)","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-09-11T09:34:19Z","receivedAt":"2021-09-11T09:34:35Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"In 644de29e220 (http: drop support for curl < 7.19.4, 2021-07-30) we\ndropped support for curl < 7.19.4, so we can drop support for this\nnon-obvious dependency on curl < 7.18.0.\n\nIt's non-obvious because in curl's hex version notation 0x071800 is\nversion 7.24.0, *not* 7.18.0, so at a glance this patch looks\nincorrect.\n\nBut it's correct, because the existing version check being removed\nhere is wrong. The check guards use of the following curl defines:\n\n    CURLPROXY_SOCKS4                7.10\n    CURLPROXY_SOCKS4A               7.18.0\n    CURLPROXY_SOCKS5                7.10\n    CURLPROXY_SOCKS5_HOSTNAME       7.18.0\n\nI.e. the oldest version that has these is in fact 7.18.0, not\n7.24.0. That we were checking 7.24.0 is just an mistake in\n6d7afe07f29 (remote-http(s): support SOCKS proxies, 2015-10-26),\ni.e. its author confusing base 10 and base 16.\n\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n http.c | 2 --\n 1 file changed, 2 deletions(-)\n\ndiff --git a/http.c b/http.c\nindex a0f169d2fe5..56856178bfe 100644\n--- a/http.c\n+++ b/http.c\n@@ -927,7 +927,6 @@ static CURL *get_curl_handle(void)\n \t\t */\n \t\tcurl_easy_setopt(result, CURLOPT_PROXY, \"\");\n \t} else if (curl_http_proxy) {\n-#if LIBCURL_VERSION_NUM >= 0x071800\n \t\tif (starts_with(curl_http_proxy, \"socks5h\"))\n \t\t\tcurl_easy_setopt(result,\n \t\t\t\tCURLOPT_PROXYTYPE, CURLPROXY_SOCKS5_HOSTNAME);\n@@ -940,7 +939,6 @@ static CURL *get_curl_handle(void)\n \t\telse if (starts_with(curl_http_proxy, \"socks\"))\n \t\t\tcurl_easy_setopt(result,\n \t\t\t\tCURLOPT_PROXYTYPE, CURLPROXY_SOCKS4);\n-#endif\n #if LIBCURL_VERSION_NUM >= 0x073400\n \t\telse if (starts_with(curl_http_proxy, \"https\")) {\n \t\t\tcurl_easy_setopt(result, CURLOPT_PROXYTYPE, CURLPROXY_HTTPS);\n-- \n2.33.0.984.gea2c3555113\n\n"},{"id":"435534","messageId":"patch-v3-6.9-67bc1992762-20210911T092751Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-v3-0.9-00000000000-20210911T092751Z-avarab@gmail.com","subject":"[PATCH v3 6/9] http: correct version check for CURL_HTTP_VERSION_2","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-09-11T09:34:20Z","receivedAt":"2021-09-11T09:34:37Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"In d73019feb44 (http: add support selecting http version, 2018-11-08)\na dependency was added on CURL_HTTP_VERSION_2, but this feature was\nintroduced in curl version 7.43.0, not 7.47.0, as the incorrect\nversion check led us to believe.\n\nAs looking through the history of that commit on the mailing list will\nreveal[1], the reason for this is that an earlier version of it\ndepended on CURL_HTTP_VERSION_2TLS, which was introduced in libcurl\n7.47.0.\n\nBut the version that made it in in d73019feb44 had dropped the\ndependency on CURL_HTTP_VERSION_2TLS, but the corresponding version\ncheck was not corrected.\n\nThe newest symbol we depend on is CURL_HTTP_VERSION_2. It was added in\n7.33.0, but the CURL_HTTP_VERSION_2 alias we used was added in\n7.47.0. So we could support an even older version here, but let's just\ncorrect the checked version.\n\n1. https://lore.kernel.org/git/pull.69.git.gitgitgadget@gmail.com/\n\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n http.c | 4 ++--\n 1 file changed, 2 insertions(+), 2 deletions(-)\n\ndiff --git a/http.c b/http.c\nindex 56856178bfe..b82b5b7a532 100644\n--- a/http.c\n+++ b/http.c\n@@ -732,7 +732,7 @@ static long get_curl_allowed_protocols(int from_user)\n \treturn allowed_protocols;\n }\n \n-#if LIBCURL_VERSION_NUM >=0x072f00\n+#if LIBCURL_VERSION_NUM >=0x072b00\n static int get_curl_http_version_opt(const char *version_string, long *opt)\n {\n \tint i;\n@@ -774,7 +774,7 @@ static CURL *get_curl_handle(void)\n \t\tcurl_easy_setopt(result, CURLOPT_SSL_VERIFYHOST, 2);\n \t}\n \n-#if LIBCURL_VERSION_NUM >= 0x072f00 // 7.47.0\n+#if LIBCURL_VERSION_NUM >= 0x072b00\n     if (curl_http_version) {\n \t\tlong opt;\n \t\tif (!get_curl_http_version_opt(curl_http_version, &opt)) {\n-- \n2.33.0.984.gea2c3555113\n\n"},{"id":"435535","messageId":"patch-v3-7.9-db7d6029dda-20210911T092751Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-v3-0.9-00000000000-20210911T092751Z-avarab@gmail.com","subject":"[PATCH v3 7/9] http: correct curl version check for CURLOPT_PINNEDPUBLICKEY","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-09-11T09:34:21Z","receivedAt":"2021-09-11T09:34:38Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"In aeff8a61216 (http: implement public key pinning, 2016-02-15) a\ndependency and warning() was added if curl older than 7.44.0 was used,\nbut the relevant code depended on CURLOPT_PINNEDPUBLICKEY, introduced\nin 7.39.0.\n\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n http.c | 8 ++++----\n 1 file changed, 4 insertions(+), 4 deletions(-)\n\ndiff --git a/http.c b/http.c\nindex b82b5b7a532..543faad9879 100644\n--- a/http.c\n+++ b/http.c\n@@ -59,7 +59,7 @@ static struct {\n static const char *ssl_key;\n static const char *ssl_capath;\n static const char *curl_no_proxy;\n-#if LIBCURL_VERSION_NUM >= 0x072c00\n+#if LIBCURL_VERSION_NUM >= 0x072700\n static const char *ssl_pinnedkey;\n #endif\n static const char *ssl_cainfo;\n@@ -373,10 +373,10 @@ static int http_options(const char *var, const char *value, void *cb)\n \t}\n \n \tif (!strcmp(\"http.pinnedpubkey\", var)) {\n-#if LIBCURL_VERSION_NUM >= 0x072c00\n+#if LIBCURL_VERSION_NUM >= 0x072700\n \t\treturn git_config_pathname(&ssl_pinnedkey, var, value);\n #else\n-\t\twarning(_(\"Public key pinning not supported with cURL < 7.44.0\"));\n+\t\twarning(_(\"Public key pinning not supported with cURL < 7.39.0\"));\n \t\treturn 0;\n #endif\n \t}\n@@ -845,7 +845,7 @@ static CURL *get_curl_handle(void)\n \t\tcurl_easy_setopt(result, CURLOPT_SSLKEY, ssl_key);\n \tif (ssl_capath != NULL)\n \t\tcurl_easy_setopt(result, CURLOPT_CAPATH, ssl_capath);\n-#if LIBCURL_VERSION_NUM >= 0x072c00\n+#if LIBCURL_VERSION_NUM >= 0x072700\n \tif (ssl_pinnedkey != NULL)\n \t\tcurl_easy_setopt(result, CURLOPT_PINNEDPUBLICKEY, ssl_pinnedkey);\n #endif\n-- \n2.33.0.984.gea2c3555113\n\n"},{"id":"435536","messageId":"patch-v3-8.9-e2e53cbfba1-20210911T092751Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-v3-0.9-00000000000-20210911T092751Z-avarab@gmail.com","subject":"[PATCH v3 8/9] http: centralize the accounting of libcurl dependencies","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-09-11T09:34:22Z","receivedAt":"2021-09-11T09:34:40Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"As discussed in 644de29e220 (http: drop support for curl < 7.19.4,\n2021-07-30) checking against LIBCURL_VERSION_NUM isn't as reliable as\nchecking specific symbols present in curl, as some distros have been\nknown to backport features.\n\nHowever, while some of the curl_easy_setopt() arguments we rely on are\nmacros, others are enum, and we can't assume that those that are\nmacros won't change into enums in the future.\n\nSo we're still going to have to check LIBCURL_VERSION_NUM, but by\ndoing that in one central place and using a macro definition of our\nown, anyone who's backporting features can define it themselves, and\nthus have access to more modern curl features that they backported,\neven if they didn't bump the LIBCURL_VERSION_NUM.\n\nMore importantly, as shown in a preceding commit doing these version\nchecks makes for hard to read and possibly buggy code, as shown by the\nbug fixed there where we were conflating base 10 for base 16 when\ncomparing the version.\n\nBy doing them all in one place we'll hopefully reduce the chances of\nsuch future mistakes, furthermore it now becomes easier to see at a\nglance what the oldest supported version is, which makes it easier to\nreason about any future deprecation similar to the recent\ne48a623dea0 (Merge branch 'ab/http-drop-old-curl', 2021-08-24).\n\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n git-curl-compat.h | 117 ++++++++++++++++++++++++++++++++++++++++++++++\n http.c            |  29 ++++++------\n imap-send.c       |   2 +-\n 3 files changed, 133 insertions(+), 15 deletions(-)\n create mode 100644 git-curl-compat.h\n\ndiff --git a/git-curl-compat.h b/git-curl-compat.h\nnew file mode 100644\nindex 00000000000..7ad87e89ed5\n--- /dev/null\n+++ b/git-curl-compat.h\n@@ -0,0 +1,117 @@\n+#ifndef GIT_CURL_COMPAT_H\n+#define GIT_CURL_COMPAT_H\n+#include <curl/curl.h>\n+\n+/**\n+ * This header centralizes the declaration of our libcurl dependencies\n+ * to make it easy to discover the oldest versions we support, and to\n+ * inform decisions about removing support for older libcurl in the\n+ * future.\n+ *\n+ * The oldest supported version of curl is documented in the \"INSTALL\"\n+ * document.\n+ *\n+ * The source of truth for what versions have which symbols is\n+ * https://github.com/curl/curl/blob/master/docs/libcurl/symbols-in-versions;\n+ * the release dates are taken from curl.git (at\n+ * https://github.com/curl/curl/).\n+ *\n+ * For each X symbol we need from curl we define our own\n+ * GIT_CURL_HAVE_X. If multiple similar symbols with the same prefix\n+ * were defined in the same version we pick one and check for that name.\n+ *\n+ * Keep any symbols in date order of when their support was\n+ * introduced, oldest first, in the official version of cURL library.\n+ */\n+\n+/**\n+ * CURLOPT_TCP_KEEPALIVE was added in 7.25.0, released in March 2012.\n+ */\n+#if LIBCURL_VERSION_NUM >= 0x071900\n+#define GITCURL_HAVE_CURLOPT_TCP_KEEPALIVE 1\n+#endif\n+\n+\n+/**\n+ * CURLOPT_LOGIN_OPTIONS was added in 7.34.0, released in December\n+ * 2013.\n+ *\n+ * If we start requiring 7.34.0 we might also be able to remove the\n+ * code conditional on USE_CURL_FOR_IMAP_SEND in imap-send.c, see\n+ * 1e16b255b95 (git-imap-send: use libcurl for implementation,\n+ * 2014-11-09) and the check it added for \"072200\" in the Makefile.\n+\n+ */\n+#if LIBCURL_VERSION_NUM >= 0x072200\n+#define GIT_CURL_HAVE_CURLOPT_LOGIN_OPTIONS 1\n+#endif\n+\n+/**\n+ * CURL_SSLVERSION_TLSv1_[012] was added in 7.34.0, released in\n+ * December 2013.\n+ */\n+#if LIBCURL_VERSION_NUM >= 0x072200\n+#define GIT_CURL_HAVE_CURL_SSLVERSION_TLSv1_0\n+#endif\n+\n+/**\n+ * CURLOPT_PINNEDPUBLICKEY was added in 7.39.0, released in November\n+ * 2014.\n+ */\n+#if LIBCURL_VERSION_NUM >= 0x072c00\n+#define GIT_CURL_HAVE_CURLOPT_PINNEDPUBLICKEY 1\n+#endif\n+\n+/**\n+ * CURL_HTTP_VERSION_2 was added in 7.43.0, released in June 2015.\n+ *\n+ * The CURL_HTTP_VERSION_2 alias (but not CURL_HTTP_VERSION_2_0) has\n+ * always been a macro, not an enum field (checked on curl version\n+ * 7.78.0)\n+ */\n+#if LIBCURL_VERSION_NUM >= 0x072b00\n+#define GIT_CURL_HAVE_CURL_HTTP_VERSION_2 1\n+#endif\n+\n+/**\n+ * CURLSSLOPT_NO_REVOKE was added in 7.44.0, released in August 2015.\n+ *\n+ * The CURLSSLOPT_NO_REVOKE is, has always been a macro, not an enum\n+ * field (checked on curl version 7.78.0)\n+ */\n+#if LIBCURL_VERSION_NUM >= 0x072c00\n+#define GIT_CURL_HAVE_CURLSSLOPT_NO_REVOKE 1\n+#endif\n+\n+/**\n+ * CURLOPT_PROXY_CAINFO was added in 7.52.0, released in August 2017.\n+ */\n+#if LIBCURL_VERSION_NUM >= 0x073400\n+#define GIT_CURL_HAVE_CURLOPT_PROXY_CAINFO 1\n+#endif\n+\n+/**\n+ * CURLOPT_PROXY_{KEYPASSWD,SSLCERT,SSLKEY} was added in 7.52.0,\n+ * released in August 2017.\n+ */\n+#if LIBCURL_VERSION_NUM >= 0x073400\n+#define GIT_CURL_HAVE_CURLOPT_PROXY_KEYPASSWD 1\n+#endif\n+\n+/**\n+ * CURL_SSLVERSION_TLSv1_3 was added in 7.53.0, released in February\n+ * 2017.\n+ */\n+#if LIBCURL_VERSION_NUM >= 0x073400\n+#define GIT_CURL_HAVE_CURL_SSLVERSION_TLSv1_3 1\n+#endif\n+\n+/**\n+ * CURLSSLSET_{NO_BACKENDS,OK,TOO_LATE,UNKNOWN_BACKEND} were added in\n+ * 7.56.0, released in September 2017.\n+ */\n+#if LIBCURL_VERSION_NUM >= 0x073800\n+#define GIT_CURL_HAVE_CURLSSLSET_NO_BACKENDS\n+#endif\n+\n+#endif\ndiff --git a/http.c b/http.c\nindex 543faad9879..94eefe97089 100644\n--- a/http.c\n+++ b/http.c\n@@ -1,4 +1,5 @@\n #include \"git-compat-util.h\"\n+#include \"git-curl-compat.h\"\n #include \"http.h\"\n #include \"config.h\"\n #include \"pack.h\"\n@@ -47,19 +48,19 @@ static struct {\n \t{ \"sslv2\", CURL_SSLVERSION_SSLv2 },\n \t{ \"sslv3\", CURL_SSLVERSION_SSLv3 },\n \t{ \"tlsv1\", CURL_SSLVERSION_TLSv1 },\n-#if LIBCURL_VERSION_NUM >= 0x072200\n+#ifdef GIT_CURL_HAVE_CURL_SSLVERSION_TLSv1_0\n \t{ \"tlsv1.0\", CURL_SSLVERSION_TLSv1_0 },\n \t{ \"tlsv1.1\", CURL_SSLVERSION_TLSv1_1 },\n \t{ \"tlsv1.2\", CURL_SSLVERSION_TLSv1_2 },\n #endif\n-#if LIBCURL_VERSION_NUM >= 0x073400\n+#ifdef GIT_CURL_HAVE_CURL_SSLVERSION_TLSv1_3\n \t{ \"tlsv1.3\", CURL_SSLVERSION_TLSv1_3 },\n #endif\n };\n static const char *ssl_key;\n static const char *ssl_capath;\n static const char *curl_no_proxy;\n-#if LIBCURL_VERSION_NUM >= 0x072700\n+#ifdef GIT_CURL_HAVE_CURLOPT_PINNEDPUBLICKEY\n static const char *ssl_pinnedkey;\n #endif\n static const char *ssl_cainfo;\n@@ -373,7 +374,7 @@ static int http_options(const char *var, const char *value, void *cb)\n \t}\n \n \tif (!strcmp(\"http.pinnedpubkey\", var)) {\n-#if LIBCURL_VERSION_NUM >= 0x072700\n+#ifdef GIT_CURL_HAVE_CURLOPT_PINNEDPUBLICKEY\n \t\treturn git_config_pathname(&ssl_pinnedkey, var, value);\n #else\n \t\twarning(_(\"Public key pinning not supported with cURL < 7.39.0\"));\n@@ -500,7 +501,7 @@ static int has_cert_password(void)\n \treturn 1;\n }\n \n-#if LIBCURL_VERSION_NUM >= 0x073400\n+#ifdef GIT_CURL_HAVE_CURLOPT_PROXY_KEYPASSWD\n static int has_proxy_cert_password(void)\n {\n \tif (http_proxy_ssl_cert == NULL || proxy_ssl_cert_password_required != 1)\n@@ -516,7 +517,7 @@ static int has_proxy_cert_password(void)\n }\n #endif\n \n-#if LIBCURL_VERSION_NUM >= 0x071900\n+#ifdef GITCURL_HAVE_CURLOPT_TCP_KEEPALIVE\n static void set_curl_keepalive(CURL *c)\n {\n \tcurl_easy_setopt(c, CURLOPT_TCP_KEEPALIVE, 1);\n@@ -732,7 +733,7 @@ static long get_curl_allowed_protocols(int from_user)\n \treturn allowed_protocols;\n }\n \n-#if LIBCURL_VERSION_NUM >=0x072b00\n+#ifdef GIT_CURL_HAVE_CURL_HTTP_VERSION_2\n static int get_curl_http_version_opt(const char *version_string, long *opt)\n {\n \tint i;\n@@ -774,7 +775,7 @@ static CURL *get_curl_handle(void)\n \t\tcurl_easy_setopt(result, CURLOPT_SSL_VERIFYHOST, 2);\n \t}\n \n-#if LIBCURL_VERSION_NUM >= 0x072b00\n+#ifdef GIT_CURL_HAVE_CURL_HTTP_VERSION_2\n     if (curl_http_version) {\n \t\tlong opt;\n \t\tif (!get_curl_http_version_opt(curl_http_version, &opt)) {\n@@ -805,7 +806,7 @@ static CURL *get_curl_handle(void)\n \n \tif (http_ssl_backend && !strcmp(\"schannel\", http_ssl_backend) &&\n \t    !http_schannel_check_revoke) {\n-#if LIBCURL_VERSION_NUM >= 0x072c00\n+#ifdef GIT_CURL_HAVE_CURLSSLOPT_NO_REVOKE\n \t\tcurl_easy_setopt(result, CURLOPT_SSL_OPTIONS, CURLSSLOPT_NO_REVOKE);\n #else\n \t\twarning(_(\"CURLSSLOPT_NO_REVOKE not supported with cURL < 7.44.0\"));\n@@ -845,20 +846,20 @@ static CURL *get_curl_handle(void)\n \t\tcurl_easy_setopt(result, CURLOPT_SSLKEY, ssl_key);\n \tif (ssl_capath != NULL)\n \t\tcurl_easy_setopt(result, CURLOPT_CAPATH, ssl_capath);\n-#if LIBCURL_VERSION_NUM >= 0x072700\n+#ifdef GIT_CURL_HAVE_CURLOPT_PINNEDPUBLICKEY\n \tif (ssl_pinnedkey != NULL)\n \t\tcurl_easy_setopt(result, CURLOPT_PINNEDPUBLICKEY, ssl_pinnedkey);\n #endif\n \tif (http_ssl_backend && !strcmp(\"schannel\", http_ssl_backend) &&\n \t    !http_schannel_use_ssl_cainfo) {\n \t\tcurl_easy_setopt(result, CURLOPT_CAINFO, NULL);\n-#if LIBCURL_VERSION_NUM >= 0x073400\n+#ifdef GIT_CURL_HAVE_CURLOPT_PROXY_CAINFO\n \t\tcurl_easy_setopt(result, CURLOPT_PROXY_CAINFO, NULL);\n #endif\n \t} else if (ssl_cainfo != NULL || http_proxy_ssl_ca_info != NULL) {\n \t\tif (ssl_cainfo != NULL)\n \t\t\tcurl_easy_setopt(result, CURLOPT_CAINFO, ssl_cainfo);\n-#if LIBCURL_VERSION_NUM >= 0x073400\n+#ifdef GIT_CURL_HAVE_CURLOPT_PROXY_CAINFO\n \t\tif (http_proxy_ssl_ca_info != NULL)\n \t\t\tcurl_easy_setopt(result, CURLOPT_PROXY_CAINFO, http_proxy_ssl_ca_info);\n #endif\n@@ -939,7 +940,7 @@ static CURL *get_curl_handle(void)\n \t\telse if (starts_with(curl_http_proxy, \"socks\"))\n \t\t\tcurl_easy_setopt(result,\n \t\t\t\tCURLOPT_PROXYTYPE, CURLPROXY_SOCKS4);\n-#if LIBCURL_VERSION_NUM >= 0x073400\n+#ifdef GIT_CURL_HAVE_CURLOPT_PROXY_KEYPASSWD\n \t\telse if (starts_with(curl_http_proxy, \"https\")) {\n \t\t\tcurl_easy_setopt(result, CURLOPT_PROXYTYPE, CURLPROXY_HTTPS);\n \n@@ -1004,7 +1005,7 @@ void http_init(struct remote *remote, const char *url, int proactive_auth)\n \tfree(normalized_url);\n \tstring_list_clear(&config.vars, 1);\n \n-#if LIBCURL_VERSION_NUM >= 0x073800\n+#ifdef GIT_CURL_HAVE_CURLSSLSET_NO_BACKENDS\n \tif (http_ssl_backend) {\n \t\tconst curl_ssl_backend **backends;\n \t\tstruct strbuf buf = STRBUF_INIT;\ndiff --git a/imap-send.c b/imap-send.c\nindex 49a5f8aa597..e6090a0346a 100644\n--- a/imap-send.c\n+++ b/imap-send.c\n@@ -1441,7 +1441,7 @@ static CURL *setup_curl(struct imap_server_conf *srvc, struct credential *cred)\n \tcurl_easy_setopt(curl, CURLOPT_PORT, server.port);\n \n \tif (server.auth_method) {\n-#if LIBCURL_VERSION_NUM < 0x072200\n+#ifndef GIT_CURL_HAVE_CURLOPT_LOGIN_OPTIONS\n \t\twarning(\"No LOGIN_OPTIONS support in this cURL version\");\n #else\n \t\tstruct strbuf auth = STRBUF_INIT;\n-- \n2.33.0.984.gea2c3555113\n\n"},{"id":"435537","messageId":"patch-v3-9.9-4bdec34a545-20210911T092751Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-v3-0.9-00000000000-20210911T092751Z-avarab@gmail.com","subject":"[PATCH v3 9/9] http: don't hardcode the value of CURL_SOCKOPT_OK","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-09-11T09:34:23Z","receivedAt":"2021-09-11T09:34:40Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"Use the new git-curl-compat.h header to define CURL_SOCKOPT_OK to its\nknown value if we're on an older curl version that doesn't have it. It\nwas hardcoded in http.c in a15d069a198 (http: enable keepalive on TCP\nsockets, 2013-10-12).\n\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n git-curl-compat.h | 11 +++++++++++\n http.c            |  2 +-\n 2 files changed, 12 insertions(+), 1 deletion(-)\n\ndiff --git a/git-curl-compat.h b/git-curl-compat.h\nindex 7ad87e89ed5..a308bdb3b9b 100644\n--- a/git-curl-compat.h\n+++ b/git-curl-compat.h\n@@ -20,10 +20,21 @@\n  * GIT_CURL_HAVE_X. If multiple similar symbols with the same prefix\n  * were defined in the same version we pick one and check for that name.\n  *\n+ * We may also define a missing CURL_* symbol to its known value, if\n+ * doing so is sufficient to add support for it to older versions that\n+ * don't have it.\n+ *\n  * Keep any symbols in date order of when their support was\n  * introduced, oldest first, in the official version of cURL library.\n  */\n \n+/**\n+ * CURL_SOCKOPT_OK was added in 7.21.5, released in April 2011.\n+ */\n+#if LIBCURL_VERSION_NUM < 0x071505\n+#define CURL_SOCKOPT_OK 0\n+#endif\n+\n /**\n  * CURLOPT_TCP_KEEPALIVE was added in 7.25.0, released in March 2012.\n  */\ndiff --git a/http.c b/http.c\nindex 94eefe97089..d7c20493d7f 100644\n--- a/http.c\n+++ b/http.c\n@@ -537,7 +537,7 @@ static int sockopt_callback(void *client, curl_socket_t fd, curlsocktype type)\n \tif (rc < 0)\n \t\twarning_errno(\"unable to set SO_KEEPALIVE on socket\");\n \n-\treturn 0; /* CURL_SOCKOPT_OK only exists since curl 7.21.5 */\n+\treturn CURL_SOCKOPT_OK;\n }\n \n static void set_curl_keepalive(CURL *c)\n-- \n2.33.0.984.gea2c3555113\n\n"},{"id":"435553","messageId":"YTy+GH0I2KPnBCUY@coredump.intra.peff.net","threadId":"46547","inReplyTo":"1b18309a-93e8-60cc-1bd3-61857b1da819@gmail.com","subject":"Re: [PATCH v4 2/5] http: drop support for curl < 7.16.0","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2021-09-11T14:32:56Z","receivedAt":"2021-09-11T14:33:13Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Sat, Sep 11, 2021 at 12:28:25AM +0200, Andrei Rybak wrote:\n\n> >   enum http_follow_config http_follow_config = HTTP_FOLLOW_INITIAL;\n> > -#if LIBCURL_VERSION_NUM >= 0x071700\n> > -/* Use CURLOPT_KEYPASSWD as is */\n> > -#elif LIBCURL_VERSION_NUM >= 0x070903\n> > -#define CURLOPT_KEYPASSWD CURLOPT_SSLKEYPASSWD\n> > -#else\n> > -#define CURLOPT_KEYPASSWD CURLOPT_SSLCERTPASSWD\n> > -#endif\n> \n> In 0x071700, 0x17 == 23, so it seems that this chain of `#if`s\n> distinguishes between three categories of curl versions:\n> \n>   1. version < 7.9.3\n>   2. 7.9.3 <= version < 7.23.0\n>   3. 7.23.0 <= version\n> \n> So it seems that this patch [1] drops support for curl < 7.23.0, while\n> the subject line claims \"drop support for curl < 7.16.0\".\n> \n> [1]: already in branch master as commit 013c7e2b07 (http: drop support\n>      for curl < 7.16.0, 2021-07-30)\n\nYes, you're right, though there's a little more going on.\n\nThe same issue was raised in the original thread starting here:\n\n  https://lore.kernel.org/git/xmqq1sok7i82.fsf@gitster.mtv.corp.google.com/\n\nbut unfortunately that seems to have been missed when the patches were\nreposted more recently. :(\n\nThere's further discussion there, though. It turns out this was yet\nanother decimal/hex confusion, and the correct version is actually\n7.17.0. So it breaks things from 7.9.3 <= version < 7.17.0. But later in\nthe series we bump the minimum to 7.19.4 anyway.\n\nSo the patch is indeed wrong, but the series overall ends up correct.\n\n-Peff\n"},{"id":"435554","messageId":"YTzBUFY4p6obEqF+@coredump.intra.peff.net","threadId":"46547","inReplyTo":"cover-v3-0.9-00000000000-20210911T092751Z-avarab@gmail.com","subject":"Re: [PATCH v3 0/9] post-v2.33 \"drop support for ancient curl\" follow-up","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2021-09-11T14:46:40Z","receivedAt":"2021-09-11T14:46:43Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Sat, Sep 11, 2021 at 11:34:14AM +0200, Ævar Arnfjörð Bjarmason wrote:\n\n> This has relatively minor changes against v2. This addresses Jeff\n> King's comments about the INSTALL phrasing, I split up the more\n> general improvements into another commit.\n> \n> The CURL_SOCKOPT_OK is now defined in terms of LIBCURL_VERSION_NUM\n> like everything else.\n\nThanks, this version looks good to me.\n\nProbably not worth a re-roll, but maybe worth fixing up while applying:\n\n>  2:  4b653cee2d3 !  3:  dce6520a5c9 INSTALL: mention that we need libcurl 7.19.4 or newer to build\n>     @@ Commit message\n>      \n>       ## INSTALL ##\n>      @@ INSTALL: Issues of note:\n>     - \t- \"libcurl\" library is used by git-http-fetch, git-fetch, and, if\n>     - \t  the curl version >= 7.34.0, for git-imap-send.\n>     + \t  not need that functionality, use NO_CURL to build without\n>     + \t  it.\n>       \n>     -+\t  Git version \"7.19.4\" of \"libcurl\" or later to build. This\n>     -+\t  version requirement may be bumped in the future.\n>     ++\t  Git requires version \"7.19.4\" or later of \"libcurl\", to\n>     ++\t  build (without NO_CURL). This version requirement may be\n>     ++\t  bumped in the future.\n\nThe comma after libcurl (before \"to build\") is extraneous (and IMHO\nmakes the sentence harder to read).\n\n-Peff\n"},{"id":"435601","messageId":"xmqqzgsilrkm.fsf@gitster.g","threadId":"46547","inReplyTo":"YTy+GH0I2KPnBCUY@coredump.intra.peff.net","subject":"Re: [PATCH v4 2/5] http: drop support for curl < 7.16.0","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2021-09-11T21:39:53Z","receivedAt":"2021-09-11T21:39:56Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Jeff King <peff@peff.net> writes:\n\n> So the patch is indeed wrong, but the series overall ends up correct.\n\nI guess that bisectability in a documentation topic does not matter,\nso we can take the end result ;-)\n\n\n"},{"id":"435602","messageId":"YT0mdus+OFCve6MU@coredump.intra.peff.net","threadId":"46547","inReplyTo":"xmqqzgsilrkm.fsf@gitster.g","subject":"Re: [PATCH v4 2/5] http: drop support for curl < 7.16.0","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2021-09-11T21:58:14Z","receivedAt":"2021-09-11T21:58:18Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Sat, Sep 11, 2021 at 02:39:53PM -0700, Junio C Hamano wrote:\n\n> Jeff King <peff@peff.net> writes:\n> \n> > So the patch is indeed wrong, but the series overall ends up correct.\n> \n> I guess that bisectability in a documentation topic does not matter,\n> so we can take the end result ;-)\n\nYes (well, not quite documentation, but it only matters if you have very\nspecific antique versions of curl). But also, this is in the older\nseries that already hit master.  So while I would actually fix it up if\nit were currently in flight, the breakage is already enshrined in\nhistory.\n\n-Peff\n"},{"id":"435650","messageId":"xmqqilz5lisd.fsf@gitster.g","threadId":"46547","inReplyTo":"YTzBUFY4p6obEqF+@coredump.intra.peff.net","subject":"Re: [PATCH v3 0/9] post-v2.33 \"drop support for ancient curl\" follow-up","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2021-09-12T19:01:54Z","receivedAt":"2021-09-12T19:02:09Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Jeff King <peff@peff.net> writes:\n\n> Probably not worth a re-roll, but maybe worth fixing up while applying:\n>\n>>  2:  4b653cee2d3 !  3:  dce6520a5c9 INSTALL: mention that we need libcurl 7.19.4 or newer to build\n>>     @@ Commit message\n>>      \n>>       ## INSTALL ##\n>>      @@ INSTALL: Issues of note:\n>>     - \t- \"libcurl\" library is used by git-http-fetch, git-fetch, and, if\n>>     - \t  the curl version >= 7.34.0, for git-imap-send.\n>>     + \t  not need that functionality, use NO_CURL to build without\n>>     + \t  it.\n>>       \n>>     -+\t  Git version \"7.19.4\" of \"libcurl\" or later to build. This\n>>     -+\t  version requirement may be bumped in the future.\n>>     ++\t  Git requires version \"7.19.4\" or later of \"libcurl\", to\n>>     ++\t  build (without NO_CURL). This version requirement may be\n>>     ++\t  bumped in the future.\n>\n> The comma after libcurl (before \"to build\") is extraneous (and IMHO\n> makes the sentence harder to read).\n\nYes.  Also it would make it easier to follow if the parentheses\naround \"without NO_CURL\" are removed, I would think.\n"},{"id":"435720","messageId":"cover-v4-0.9-00000000000-20210913T144846Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-v3-0.9-00000000000-20210911T092751Z-avarab@gmail.com","subject":"[PATCH v4 0/9] post-v2.33 \"drop support for ancient curl\" follow-up","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-09-13T14:51:20Z","receivedAt":"2021-09-13T15:36:52Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"This is a follow-up to the already-integrated topic for dropping\nsupport for older curl versions submitted before the v2.33 release[1].\n\nSee\nhttps://lore.kernel.org/git/cover-v3-0.9-00000000000-20210911T092751Z-avarab@gmail.com\n[1] for v3.\n\nThis is a hopefully final re-roll with a small grammar improvement in\n3/8. See range-diff, pointed out/requested at\nhttps://lore.kernel.org/git/YTzBUFY4p6obEqF+@coredump.intra.peff.net/\n\nÆvar Arnfjörð Bjarmason (9):\n  INSTALL: don't mention the \"curl\" executable at all\n  INSTALL: reword and copy-edit the \"libcurl\" section\n  INSTALL: mention that we need libcurl 7.19.4 or newer to build\n  Makefile: drop support for curl < 7.9.8 (again)\n  http: drop support for curl < 7.18.0 (again)\n  http: correct version check for CURL_HTTP_VERSION_2\n  http: correct curl version check for CURLOPT_PINNEDPUBLICKEY\n  http: centralize the accounting of libcurl dependencies\n  http: don't hardcode the value of CURL_SOCKOPT_OK\n\n INSTALL           |  15 +++---\n Makefile          |  11 +---\n git-curl-compat.h | 128 ++++++++++++++++++++++++++++++++++++++++++++++\n http.c            |  35 ++++++-------\n imap-send.c       |   2 +-\n 5 files changed, 157 insertions(+), 34 deletions(-)\n create mode 100644 git-curl-compat.h\n\nRange-diff against v3:\n -:  ----------- >  1:  7b771aa70ef INSTALL: don't mention the \"curl\" executable at all\n 1:  3b0119958a3 =  2:  2f3a09c98d2 INSTALL: reword and copy-edit the \"libcurl\" section\n 2:  dce6520a5c9 !  3:  59c86f14cef INSTALL: mention that we need libcurl 7.19.4 or newer to build\n    @@ INSTALL: Issues of note:\n      \t  not need that functionality, use NO_CURL to build without\n      \t  it.\n      \n    -+\t  Git requires version \"7.19.4\" or later of \"libcurl\", to\n    -+\t  build (without NO_CURL). This version requirement may be\n    -+\t  bumped in the future.\n    ++\t  Git requires version \"7.19.4\" or later of \"libcurl\" to build\n    ++\t  without NO_CURL. This version requirement may be bumped in\n    ++\t  the future.\n     +\n      \t- \"expat\" library; git-http-push uses it for remote lock\n      \t  management over DAV.  Similar to \"curl\" above, this is optional\n 3:  98cdb7c35a9 =  4:  6edd01ad125 Makefile: drop support for curl < 7.9.8 (again)\n 4:  7919debfd89 =  5:  73ad0d4cb28 http: drop support for curl < 7.18.0 (again)\n 5:  67bc1992762 =  6:  f4d1de8a112 http: correct version check for CURL_HTTP_VERSION_2\n 6:  db7d6029dda =  7:  7aa5149c395 http: correct curl version check for CURLOPT_PINNEDPUBLICKEY\n 7:  e2e53cbfba1 =  8:  9890e4b662a http: centralize the accounting of libcurl dependencies\n 8:  4bdec34a545 =  9:  846b466fdd5 http: don't hardcode the value of CURL_SOCKOPT_OK\n-- \n2.33.0.1013.ge8323766266\n\n"},{"id":"435721","messageId":"patch-v4-1.9-7b771aa70ef-20210913T144846Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-v4-0.9-00000000000-20210913T144846Z-avarab@gmail.com","subject":"[PATCH v4 1/9] INSTALL: don't mention the \"curl\" executable at all","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-09-13T14:51:21Z","receivedAt":"2021-09-13T15:36:53Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"In 1d53f90ed97 (The \"curl\" executable is no longer required,\n2008-06-15) the wording for requiring curl(1) was changed to the\ncurrent \"you might also want...\".\n\nMentioning the \"curl\" executable at all is just confusing, someone\nbuilding git might want to use it to debug things, but they might also\njust use wget(1) or some other http client. The \"curl\" executable has\nthe advantage that you might be able to e.g. reproduce a bug in git's\nusage of libcurl with it, but anyone going to those extents is\nunlikely to be aided by this note in INSTALL.\n\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n INSTALL | 3 +--\n 1 file changed, 1 insertion(+), 2 deletions(-)\n\ndiff --git a/INSTALL b/INSTALL\nindex 66389ce0591..5b8bd5ccce1 100644\n--- a/INSTALL\n+++ b/INSTALL\n@@ -139,8 +139,7 @@ Issues of note:\n \t  (PPC_SHA1).\n \n \t- \"libcurl\" library is used by git-http-fetch, git-fetch, and, if\n-\t  the curl version >= 7.34.0, for git-imap-send.  You might also\n-\t  want the \"curl\" executable for debugging purposes. If you do not\n+\t  the curl version >= 7.34.0, for git-imap-send. If you do not\n \t  use http:// or https:// repositories, and do not want to put\n \t  patches into an IMAP mailbox, you do not have to have them\n \t  (use NO_CURL).\n-- \n2.33.0.1013.ge8323766266\n\n"},{"id":"435722","messageId":"patch-v4-2.9-2f3a09c98d2-20210913T144846Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-v4-0.9-00000000000-20210913T144846Z-avarab@gmail.com","subject":"[PATCH v4 2/9] INSTALL: reword and copy-edit the \"libcurl\" section","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-09-13T14:51:22Z","receivedAt":"2021-09-13T15:36:55Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"Make the \"libcurl\" section shorter and more to the point, this is\nmostly based on suggestions from [1].\n\n1. https://lore.kernel.org/git/YTtxcBdF2VQdWp5C@coredump.intra.peff.net/\n\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n INSTALL | 10 +++++-----\n 1 file changed, 5 insertions(+), 5 deletions(-)\n\ndiff --git a/INSTALL b/INSTALL\nindex 5b8bd5ccce1..d593f628749 100644\n--- a/INSTALL\n+++ b/INSTALL\n@@ -138,11 +138,11 @@ Issues of note:\n \t  BLK_SHA1.  Also included is a version optimized for PowerPC\n \t  (PPC_SHA1).\n \n-\t- \"libcurl\" library is used by git-http-fetch, git-fetch, and, if\n-\t  the curl version >= 7.34.0, for git-imap-send. If you do not\n-\t  use http:// or https:// repositories, and do not want to put\n-\t  patches into an IMAP mailbox, you do not have to have them\n-\t  (use NO_CURL).\n+\t- \"libcurl\" library is used for fetching and pushing\n+\t  repositories over http:// or https://, as well as by\n+\t  git-imap-send if the curl version is >= 7.34.0. If you do\n+\t  not need that functionality, use NO_CURL to build without\n+\t  it.\n \n \t- \"expat\" library; git-http-push uses it for remote lock\n \t  management over DAV.  Similar to \"curl\" above, this is optional\n-- \n2.33.0.1013.ge8323766266\n\n"},{"id":"435723","messageId":"patch-v4-3.9-59c86f14cef-20210913T144846Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-v4-0.9-00000000000-20210913T144846Z-avarab@gmail.com","subject":"[PATCH v4 3/9] INSTALL: mention that we need libcurl 7.19.4 or newer to build","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-09-13T14:51:23Z","receivedAt":"2021-09-13T15:36:56Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"Without NO_CURL=Y we require at least version \"7.19.4\" of libcurl, see\n644de29e220 (http: drop support for curl < 7.19.4, 2021-07-30). Let's\ndocument this in the \"INSTALL\" document.\n\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n INSTALL | 4 ++++\n 1 file changed, 4 insertions(+)\n\ndiff --git a/INSTALL b/INSTALL\nindex d593f628749..4140a3f5c8b 100644\n--- a/INSTALL\n+++ b/INSTALL\n@@ -144,6 +144,10 @@ Issues of note:\n \t  not need that functionality, use NO_CURL to build without\n \t  it.\n \n+\t  Git requires version \"7.19.4\" or later of \"libcurl\" to build\n+\t  without NO_CURL. This version requirement may be bumped in\n+\t  the future.\n+\n \t- \"expat\" library; git-http-push uses it for remote lock\n \t  management over DAV.  Similar to \"curl\" above, this is optional\n \t  (with NO_EXPAT).\n-- \n2.33.0.1013.ge8323766266\n\n"},{"id":"435724","messageId":"patch-v4-7.9-7aa5149c395-20210913T144846Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-v4-0.9-00000000000-20210913T144846Z-avarab@gmail.com","subject":"[PATCH v4 7/9] http: correct curl version check for CURLOPT_PINNEDPUBLICKEY","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-09-13T14:51:27Z","receivedAt":"2021-09-13T15:36:57Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"In aeff8a61216 (http: implement public key pinning, 2016-02-15) a\ndependency and warning() was added if curl older than 7.44.0 was used,\nbut the relevant code depended on CURLOPT_PINNEDPUBLICKEY, introduced\nin 7.39.0.\n\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n http.c | 8 ++++----\n 1 file changed, 4 insertions(+), 4 deletions(-)\n\ndiff --git a/http.c b/http.c\nindex b82b5b7a532..543faad9879 100644\n--- a/http.c\n+++ b/http.c\n@@ -59,7 +59,7 @@ static struct {\n static const char *ssl_key;\n static const char *ssl_capath;\n static const char *curl_no_proxy;\n-#if LIBCURL_VERSION_NUM >= 0x072c00\n+#if LIBCURL_VERSION_NUM >= 0x072700\n static const char *ssl_pinnedkey;\n #endif\n static const char *ssl_cainfo;\n@@ -373,10 +373,10 @@ static int http_options(const char *var, const char *value, void *cb)\n \t}\n \n \tif (!strcmp(\"http.pinnedpubkey\", var)) {\n-#if LIBCURL_VERSION_NUM >= 0x072c00\n+#if LIBCURL_VERSION_NUM >= 0x072700\n \t\treturn git_config_pathname(&ssl_pinnedkey, var, value);\n #else\n-\t\twarning(_(\"Public key pinning not supported with cURL < 7.44.0\"));\n+\t\twarning(_(\"Public key pinning not supported with cURL < 7.39.0\"));\n \t\treturn 0;\n #endif\n \t}\n@@ -845,7 +845,7 @@ static CURL *get_curl_handle(void)\n \t\tcurl_easy_setopt(result, CURLOPT_SSLKEY, ssl_key);\n \tif (ssl_capath != NULL)\n \t\tcurl_easy_setopt(result, CURLOPT_CAPATH, ssl_capath);\n-#if LIBCURL_VERSION_NUM >= 0x072c00\n+#if LIBCURL_VERSION_NUM >= 0x072700\n \tif (ssl_pinnedkey != NULL)\n \t\tcurl_easy_setopt(result, CURLOPT_PINNEDPUBLICKEY, ssl_pinnedkey);\n #endif\n-- \n2.33.0.1013.ge8323766266\n\n"},{"id":"435725","messageId":"patch-v4-6.9-f4d1de8a112-20210913T144846Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-v4-0.9-00000000000-20210913T144846Z-avarab@gmail.com","subject":"[PATCH v4 6/9] http: correct version check for CURL_HTTP_VERSION_2","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-09-13T14:51:26Z","receivedAt":"2021-09-13T15:37:00Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"In d73019feb44 (http: add support selecting http version, 2018-11-08)\na dependency was added on CURL_HTTP_VERSION_2, but this feature was\nintroduced in curl version 7.43.0, not 7.47.0, as the incorrect\nversion check led us to believe.\n\nAs looking through the history of that commit on the mailing list will\nreveal[1], the reason for this is that an earlier version of it\ndepended on CURL_HTTP_VERSION_2TLS, which was introduced in libcurl\n7.47.0.\n\nBut the version that made it in in d73019feb44 had dropped the\ndependency on CURL_HTTP_VERSION_2TLS, but the corresponding version\ncheck was not corrected.\n\nThe newest symbol we depend on is CURL_HTTP_VERSION_2. It was added in\n7.33.0, but the CURL_HTTP_VERSION_2 alias we used was added in\n7.47.0. So we could support an even older version here, but let's just\ncorrect the checked version.\n\n1. https://lore.kernel.org/git/pull.69.git.gitgitgadget@gmail.com/\n\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n http.c | 4 ++--\n 1 file changed, 2 insertions(+), 2 deletions(-)\n\ndiff --git a/http.c b/http.c\nindex 56856178bfe..b82b5b7a532 100644\n--- a/http.c\n+++ b/http.c\n@@ -732,7 +732,7 @@ static long get_curl_allowed_protocols(int from_user)\n \treturn allowed_protocols;\n }\n \n-#if LIBCURL_VERSION_NUM >=0x072f00\n+#if LIBCURL_VERSION_NUM >=0x072b00\n static int get_curl_http_version_opt(const char *version_string, long *opt)\n {\n \tint i;\n@@ -774,7 +774,7 @@ static CURL *get_curl_handle(void)\n \t\tcurl_easy_setopt(result, CURLOPT_SSL_VERIFYHOST, 2);\n \t}\n \n-#if LIBCURL_VERSION_NUM >= 0x072f00 // 7.47.0\n+#if LIBCURL_VERSION_NUM >= 0x072b00\n     if (curl_http_version) {\n \t\tlong opt;\n \t\tif (!get_curl_http_version_opt(curl_http_version, &opt)) {\n-- \n2.33.0.1013.ge8323766266\n\n"},{"id":"435726","messageId":"patch-v4-4.9-6edd01ad125-20210913T144846Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-v4-0.9-00000000000-20210913T144846Z-avarab@gmail.com","subject":"[PATCH v4 4/9] Makefile: drop support for curl < 7.9.8 (again)","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-09-13T14:51:24Z","receivedAt":"2021-09-13T15:37:01Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"In 1119a15b5c8 (http: drop support for curl < 7.11.1, 2021-07-30)\nsupport for curl versions older than 7.11.1 was removed, and we\ncurrently require at least version 7.19.4, see 644de29e220 (http: drop\nsupport for curl < 7.19.4, 2021-07-30).\n\nIn those changes this Makefile-specific check added in\n0890098780f (Decide whether to build http-push in the Makefile,\n2005-11-18) was missed, now that we're never going to use such an\nancient curl version we don't need to check that we have at least\n7.9.8 here. I have no idea what in http-push.c broke on versions older\nthan that.\n\nThis does not impact \"NO_CURL\" setups, as this is in the \"else\" branch\nafter that check.\n\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n Makefile | 11 ++---------\n 1 file changed, 2 insertions(+), 9 deletions(-)\n\ndiff --git a/Makefile b/Makefile\nindex 429c276058d..378f58b950d 100644\n--- a/Makefile\n+++ b/Makefile\n@@ -1436,15 +1436,8 @@ else\n \tREMOTE_CURL_NAMES = $(REMOTE_CURL_PRIMARY) $(REMOTE_CURL_ALIASES)\n \tPROGRAM_OBJS += http-fetch.o\n \tPROGRAMS += $(REMOTE_CURL_NAMES)\n-\tcurl_check := $(shell (echo 070908; $(CURL_CONFIG) --vernum | sed -e '/^70[BC]/s/^/0/') 2>/dev/null | sort -r | sed -ne 2p)\n-\tifeq \"$(curl_check)\" \"070908\"\n-\t\tifndef NO_EXPAT\n-\t\t\tPROGRAM_OBJS += http-push.o\n-\t\telse\n-\t\t\tEXCLUDED_PROGRAMS += git-http-push\n-\t\tendif\n-\telse\n-\t\tEXCLUDED_PROGRAMS += git-http-push\n+\tifndef NO_EXPAT\n+\t\tPROGRAM_OBJS += http-push.o\n \tendif\n \tcurl_check := $(shell (echo 072200; $(CURL_CONFIG) --vernum | sed -e '/^70[BC]/s/^/0/') 2>/dev/null | sort -r | sed -ne 2p)\n \tifeq \"$(curl_check)\" \"072200\"\n-- \n2.33.0.1013.ge8323766266\n\n"},{"id":"435727","messageId":"patch-v4-5.9-73ad0d4cb28-20210913T144846Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-v4-0.9-00000000000-20210913T144846Z-avarab@gmail.com","subject":"[PATCH v4 5/9] http: drop support for curl < 7.18.0 (again)","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-09-13T14:51:25Z","receivedAt":"2021-09-13T15:37:03Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"In 644de29e220 (http: drop support for curl < 7.19.4, 2021-07-30) we\ndropped support for curl < 7.19.4, so we can drop support for this\nnon-obvious dependency on curl < 7.18.0.\n\nIt's non-obvious because in curl's hex version notation 0x071800 is\nversion 7.24.0, *not* 7.18.0, so at a glance this patch looks\nincorrect.\n\nBut it's correct, because the existing version check being removed\nhere is wrong. The check guards use of the following curl defines:\n\n    CURLPROXY_SOCKS4                7.10\n    CURLPROXY_SOCKS4A               7.18.0\n    CURLPROXY_SOCKS5                7.10\n    CURLPROXY_SOCKS5_HOSTNAME       7.18.0\n\nI.e. the oldest version that has these is in fact 7.18.0, not\n7.24.0. That we were checking 7.24.0 is just an mistake in\n6d7afe07f29 (remote-http(s): support SOCKS proxies, 2015-10-26),\ni.e. its author confusing base 10 and base 16.\n\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n http.c | 2 --\n 1 file changed, 2 deletions(-)\n\ndiff --git a/http.c b/http.c\nindex a0f169d2fe5..56856178bfe 100644\n--- a/http.c\n+++ b/http.c\n@@ -927,7 +927,6 @@ static CURL *get_curl_handle(void)\n \t\t */\n \t\tcurl_easy_setopt(result, CURLOPT_PROXY, \"\");\n \t} else if (curl_http_proxy) {\n-#if LIBCURL_VERSION_NUM >= 0x071800\n \t\tif (starts_with(curl_http_proxy, \"socks5h\"))\n \t\t\tcurl_easy_setopt(result,\n \t\t\t\tCURLOPT_PROXYTYPE, CURLPROXY_SOCKS5_HOSTNAME);\n@@ -940,7 +939,6 @@ static CURL *get_curl_handle(void)\n \t\telse if (starts_with(curl_http_proxy, \"socks\"))\n \t\t\tcurl_easy_setopt(result,\n \t\t\t\tCURLOPT_PROXYTYPE, CURLPROXY_SOCKS4);\n-#endif\n #if LIBCURL_VERSION_NUM >= 0x073400\n \t\telse if (starts_with(curl_http_proxy, \"https\")) {\n \t\t\tcurl_easy_setopt(result, CURLOPT_PROXYTYPE, CURLPROXY_HTTPS);\n-- \n2.33.0.1013.ge8323766266\n\n"},{"id":"435728","messageId":"patch-v4-8.9-9890e4b662a-20210913T144846Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-v4-0.9-00000000000-20210913T144846Z-avarab@gmail.com","subject":"[PATCH v4 8/9] http: centralize the accounting of libcurl dependencies","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-09-13T14:51:28Z","receivedAt":"2021-09-13T15:37:04Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"As discussed in 644de29e220 (http: drop support for curl < 7.19.4,\n2021-07-30) checking against LIBCURL_VERSION_NUM isn't as reliable as\nchecking specific symbols present in curl, as some distros have been\nknown to backport features.\n\nHowever, while some of the curl_easy_setopt() arguments we rely on are\nmacros, others are enum, and we can't assume that those that are\nmacros won't change into enums in the future.\n\nSo we're still going to have to check LIBCURL_VERSION_NUM, but by\ndoing that in one central place and using a macro definition of our\nown, anyone who's backporting features can define it themselves, and\nthus have access to more modern curl features that they backported,\neven if they didn't bump the LIBCURL_VERSION_NUM.\n\nMore importantly, as shown in a preceding commit doing these version\nchecks makes for hard to read and possibly buggy code, as shown by the\nbug fixed there where we were conflating base 10 for base 16 when\ncomparing the version.\n\nBy doing them all in one place we'll hopefully reduce the chances of\nsuch future mistakes, furthermore it now becomes easier to see at a\nglance what the oldest supported version is, which makes it easier to\nreason about any future deprecation similar to the recent\ne48a623dea0 (Merge branch 'ab/http-drop-old-curl', 2021-08-24).\n\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n git-curl-compat.h | 117 ++++++++++++++++++++++++++++++++++++++++++++++\n http.c            |  29 ++++++------\n imap-send.c       |   2 +-\n 3 files changed, 133 insertions(+), 15 deletions(-)\n create mode 100644 git-curl-compat.h\n\ndiff --git a/git-curl-compat.h b/git-curl-compat.h\nnew file mode 100644\nindex 00000000000..7ad87e89ed5\n--- /dev/null\n+++ b/git-curl-compat.h\n@@ -0,0 +1,117 @@\n+#ifndef GIT_CURL_COMPAT_H\n+#define GIT_CURL_COMPAT_H\n+#include <curl/curl.h>\n+\n+/**\n+ * This header centralizes the declaration of our libcurl dependencies\n+ * to make it easy to discover the oldest versions we support, and to\n+ * inform decisions about removing support for older libcurl in the\n+ * future.\n+ *\n+ * The oldest supported version of curl is documented in the \"INSTALL\"\n+ * document.\n+ *\n+ * The source of truth for what versions have which symbols is\n+ * https://github.com/curl/curl/blob/master/docs/libcurl/symbols-in-versions;\n+ * the release dates are taken from curl.git (at\n+ * https://github.com/curl/curl/).\n+ *\n+ * For each X symbol we need from curl we define our own\n+ * GIT_CURL_HAVE_X. If multiple similar symbols with the same prefix\n+ * were defined in the same version we pick one and check for that name.\n+ *\n+ * Keep any symbols in date order of when their support was\n+ * introduced, oldest first, in the official version of cURL library.\n+ */\n+\n+/**\n+ * CURLOPT_TCP_KEEPALIVE was added in 7.25.0, released in March 2012.\n+ */\n+#if LIBCURL_VERSION_NUM >= 0x071900\n+#define GITCURL_HAVE_CURLOPT_TCP_KEEPALIVE 1\n+#endif\n+\n+\n+/**\n+ * CURLOPT_LOGIN_OPTIONS was added in 7.34.0, released in December\n+ * 2013.\n+ *\n+ * If we start requiring 7.34.0 we might also be able to remove the\n+ * code conditional on USE_CURL_FOR_IMAP_SEND in imap-send.c, see\n+ * 1e16b255b95 (git-imap-send: use libcurl for implementation,\n+ * 2014-11-09) and the check it added for \"072200\" in the Makefile.\n+\n+ */\n+#if LIBCURL_VERSION_NUM >= 0x072200\n+#define GIT_CURL_HAVE_CURLOPT_LOGIN_OPTIONS 1\n+#endif\n+\n+/**\n+ * CURL_SSLVERSION_TLSv1_[012] was added in 7.34.0, released in\n+ * December 2013.\n+ */\n+#if LIBCURL_VERSION_NUM >= 0x072200\n+#define GIT_CURL_HAVE_CURL_SSLVERSION_TLSv1_0\n+#endif\n+\n+/**\n+ * CURLOPT_PINNEDPUBLICKEY was added in 7.39.0, released in November\n+ * 2014.\n+ */\n+#if LIBCURL_VERSION_NUM >= 0x072c00\n+#define GIT_CURL_HAVE_CURLOPT_PINNEDPUBLICKEY 1\n+#endif\n+\n+/**\n+ * CURL_HTTP_VERSION_2 was added in 7.43.0, released in June 2015.\n+ *\n+ * The CURL_HTTP_VERSION_2 alias (but not CURL_HTTP_VERSION_2_0) has\n+ * always been a macro, not an enum field (checked on curl version\n+ * 7.78.0)\n+ */\n+#if LIBCURL_VERSION_NUM >= 0x072b00\n+#define GIT_CURL_HAVE_CURL_HTTP_VERSION_2 1\n+#endif\n+\n+/**\n+ * CURLSSLOPT_NO_REVOKE was added in 7.44.0, released in August 2015.\n+ *\n+ * The CURLSSLOPT_NO_REVOKE is, has always been a macro, not an enum\n+ * field (checked on curl version 7.78.0)\n+ */\n+#if LIBCURL_VERSION_NUM >= 0x072c00\n+#define GIT_CURL_HAVE_CURLSSLOPT_NO_REVOKE 1\n+#endif\n+\n+/**\n+ * CURLOPT_PROXY_CAINFO was added in 7.52.0, released in August 2017.\n+ */\n+#if LIBCURL_VERSION_NUM >= 0x073400\n+#define GIT_CURL_HAVE_CURLOPT_PROXY_CAINFO 1\n+#endif\n+\n+/**\n+ * CURLOPT_PROXY_{KEYPASSWD,SSLCERT,SSLKEY} was added in 7.52.0,\n+ * released in August 2017.\n+ */\n+#if LIBCURL_VERSION_NUM >= 0x073400\n+#define GIT_CURL_HAVE_CURLOPT_PROXY_KEYPASSWD 1\n+#endif\n+\n+/**\n+ * CURL_SSLVERSION_TLSv1_3 was added in 7.53.0, released in February\n+ * 2017.\n+ */\n+#if LIBCURL_VERSION_NUM >= 0x073400\n+#define GIT_CURL_HAVE_CURL_SSLVERSION_TLSv1_3 1\n+#endif\n+\n+/**\n+ * CURLSSLSET_{NO_BACKENDS,OK,TOO_LATE,UNKNOWN_BACKEND} were added in\n+ * 7.56.0, released in September 2017.\n+ */\n+#if LIBCURL_VERSION_NUM >= 0x073800\n+#define GIT_CURL_HAVE_CURLSSLSET_NO_BACKENDS\n+#endif\n+\n+#endif\ndiff --git a/http.c b/http.c\nindex 543faad9879..94eefe97089 100644\n--- a/http.c\n+++ b/http.c\n@@ -1,4 +1,5 @@\n #include \"git-compat-util.h\"\n+#include \"git-curl-compat.h\"\n #include \"http.h\"\n #include \"config.h\"\n #include \"pack.h\"\n@@ -47,19 +48,19 @@ static struct {\n \t{ \"sslv2\", CURL_SSLVERSION_SSLv2 },\n \t{ \"sslv3\", CURL_SSLVERSION_SSLv3 },\n \t{ \"tlsv1\", CURL_SSLVERSION_TLSv1 },\n-#if LIBCURL_VERSION_NUM >= 0x072200\n+#ifdef GIT_CURL_HAVE_CURL_SSLVERSION_TLSv1_0\n \t{ \"tlsv1.0\", CURL_SSLVERSION_TLSv1_0 },\n \t{ \"tlsv1.1\", CURL_SSLVERSION_TLSv1_1 },\n \t{ \"tlsv1.2\", CURL_SSLVERSION_TLSv1_2 },\n #endif\n-#if LIBCURL_VERSION_NUM >= 0x073400\n+#ifdef GIT_CURL_HAVE_CURL_SSLVERSION_TLSv1_3\n \t{ \"tlsv1.3\", CURL_SSLVERSION_TLSv1_3 },\n #endif\n };\n static const char *ssl_key;\n static const char *ssl_capath;\n static const char *curl_no_proxy;\n-#if LIBCURL_VERSION_NUM >= 0x072700\n+#ifdef GIT_CURL_HAVE_CURLOPT_PINNEDPUBLICKEY\n static const char *ssl_pinnedkey;\n #endif\n static const char *ssl_cainfo;\n@@ -373,7 +374,7 @@ static int http_options(const char *var, const char *value, void *cb)\n \t}\n \n \tif (!strcmp(\"http.pinnedpubkey\", var)) {\n-#if LIBCURL_VERSION_NUM >= 0x072700\n+#ifdef GIT_CURL_HAVE_CURLOPT_PINNEDPUBLICKEY\n \t\treturn git_config_pathname(&ssl_pinnedkey, var, value);\n #else\n \t\twarning(_(\"Public key pinning not supported with cURL < 7.39.0\"));\n@@ -500,7 +501,7 @@ static int has_cert_password(void)\n \treturn 1;\n }\n \n-#if LIBCURL_VERSION_NUM >= 0x073400\n+#ifdef GIT_CURL_HAVE_CURLOPT_PROXY_KEYPASSWD\n static int has_proxy_cert_password(void)\n {\n \tif (http_proxy_ssl_cert == NULL || proxy_ssl_cert_password_required != 1)\n@@ -516,7 +517,7 @@ static int has_proxy_cert_password(void)\n }\n #endif\n \n-#if LIBCURL_VERSION_NUM >= 0x071900\n+#ifdef GITCURL_HAVE_CURLOPT_TCP_KEEPALIVE\n static void set_curl_keepalive(CURL *c)\n {\n \tcurl_easy_setopt(c, CURLOPT_TCP_KEEPALIVE, 1);\n@@ -732,7 +733,7 @@ static long get_curl_allowed_protocols(int from_user)\n \treturn allowed_protocols;\n }\n \n-#if LIBCURL_VERSION_NUM >=0x072b00\n+#ifdef GIT_CURL_HAVE_CURL_HTTP_VERSION_2\n static int get_curl_http_version_opt(const char *version_string, long *opt)\n {\n \tint i;\n@@ -774,7 +775,7 @@ static CURL *get_curl_handle(void)\n \t\tcurl_easy_setopt(result, CURLOPT_SSL_VERIFYHOST, 2);\n \t}\n \n-#if LIBCURL_VERSION_NUM >= 0x072b00\n+#ifdef GIT_CURL_HAVE_CURL_HTTP_VERSION_2\n     if (curl_http_version) {\n \t\tlong opt;\n \t\tif (!get_curl_http_version_opt(curl_http_version, &opt)) {\n@@ -805,7 +806,7 @@ static CURL *get_curl_handle(void)\n \n \tif (http_ssl_backend && !strcmp(\"schannel\", http_ssl_backend) &&\n \t    !http_schannel_check_revoke) {\n-#if LIBCURL_VERSION_NUM >= 0x072c00\n+#ifdef GIT_CURL_HAVE_CURLSSLOPT_NO_REVOKE\n \t\tcurl_easy_setopt(result, CURLOPT_SSL_OPTIONS, CURLSSLOPT_NO_REVOKE);\n #else\n \t\twarning(_(\"CURLSSLOPT_NO_REVOKE not supported with cURL < 7.44.0\"));\n@@ -845,20 +846,20 @@ static CURL *get_curl_handle(void)\n \t\tcurl_easy_setopt(result, CURLOPT_SSLKEY, ssl_key);\n \tif (ssl_capath != NULL)\n \t\tcurl_easy_setopt(result, CURLOPT_CAPATH, ssl_capath);\n-#if LIBCURL_VERSION_NUM >= 0x072700\n+#ifdef GIT_CURL_HAVE_CURLOPT_PINNEDPUBLICKEY\n \tif (ssl_pinnedkey != NULL)\n \t\tcurl_easy_setopt(result, CURLOPT_PINNEDPUBLICKEY, ssl_pinnedkey);\n #endif\n \tif (http_ssl_backend && !strcmp(\"schannel\", http_ssl_backend) &&\n \t    !http_schannel_use_ssl_cainfo) {\n \t\tcurl_easy_setopt(result, CURLOPT_CAINFO, NULL);\n-#if LIBCURL_VERSION_NUM >= 0x073400\n+#ifdef GIT_CURL_HAVE_CURLOPT_PROXY_CAINFO\n \t\tcurl_easy_setopt(result, CURLOPT_PROXY_CAINFO, NULL);\n #endif\n \t} else if (ssl_cainfo != NULL || http_proxy_ssl_ca_info != NULL) {\n \t\tif (ssl_cainfo != NULL)\n \t\t\tcurl_easy_setopt(result, CURLOPT_CAINFO, ssl_cainfo);\n-#if LIBCURL_VERSION_NUM >= 0x073400\n+#ifdef GIT_CURL_HAVE_CURLOPT_PROXY_CAINFO\n \t\tif (http_proxy_ssl_ca_info != NULL)\n \t\t\tcurl_easy_setopt(result, CURLOPT_PROXY_CAINFO, http_proxy_ssl_ca_info);\n #endif\n@@ -939,7 +940,7 @@ static CURL *get_curl_handle(void)\n \t\telse if (starts_with(curl_http_proxy, \"socks\"))\n \t\t\tcurl_easy_setopt(result,\n \t\t\t\tCURLOPT_PROXYTYPE, CURLPROXY_SOCKS4);\n-#if LIBCURL_VERSION_NUM >= 0x073400\n+#ifdef GIT_CURL_HAVE_CURLOPT_PROXY_KEYPASSWD\n \t\telse if (starts_with(curl_http_proxy, \"https\")) {\n \t\t\tcurl_easy_setopt(result, CURLOPT_PROXYTYPE, CURLPROXY_HTTPS);\n \n@@ -1004,7 +1005,7 @@ void http_init(struct remote *remote, const char *url, int proactive_auth)\n \tfree(normalized_url);\n \tstring_list_clear(&config.vars, 1);\n \n-#if LIBCURL_VERSION_NUM >= 0x073800\n+#ifdef GIT_CURL_HAVE_CURLSSLSET_NO_BACKENDS\n \tif (http_ssl_backend) {\n \t\tconst curl_ssl_backend **backends;\n \t\tstruct strbuf buf = STRBUF_INIT;\ndiff --git a/imap-send.c b/imap-send.c\nindex 49a5f8aa597..e6090a0346a 100644\n--- a/imap-send.c\n+++ b/imap-send.c\n@@ -1441,7 +1441,7 @@ static CURL *setup_curl(struct imap_server_conf *srvc, struct credential *cred)\n \tcurl_easy_setopt(curl, CURLOPT_PORT, server.port);\n \n \tif (server.auth_method) {\n-#if LIBCURL_VERSION_NUM < 0x072200\n+#ifndef GIT_CURL_HAVE_CURLOPT_LOGIN_OPTIONS\n \t\twarning(\"No LOGIN_OPTIONS support in this cURL version\");\n #else\n \t\tstruct strbuf auth = STRBUF_INIT;\n-- \n2.33.0.1013.ge8323766266\n\n"},{"id":"435729","messageId":"patch-v4-9.9-846b466fdd5-20210913T144846Z-avarab@gmail.com","threadId":"46547","inReplyTo":"cover-v4-0.9-00000000000-20210913T144846Z-avarab@gmail.com","subject":"[PATCH v4 9/9] http: don't hardcode the value of CURL_SOCKOPT_OK","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2021-09-13T14:51:29Z","receivedAt":"2021-09-13T15:37:06Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"Use the new git-curl-compat.h header to define CURL_SOCKOPT_OK to its\nknown value if we're on an older curl version that doesn't have it. It\nwas hardcoded in http.c in a15d069a198 (http: enable keepalive on TCP\nsockets, 2013-10-12).\n\nSigned-off-by: Ævar Arnfjörð Bjarmason <avarab@gmail.com>\n---\n git-curl-compat.h | 11 +++++++++++\n http.c            |  2 +-\n 2 files changed, 12 insertions(+), 1 deletion(-)\n\ndiff --git a/git-curl-compat.h b/git-curl-compat.h\nindex 7ad87e89ed5..a308bdb3b9b 100644\n--- a/git-curl-compat.h\n+++ b/git-curl-compat.h\n@@ -20,10 +20,21 @@\n  * GIT_CURL_HAVE_X. If multiple similar symbols with the same prefix\n  * were defined in the same version we pick one and check for that name.\n  *\n+ * We may also define a missing CURL_* symbol to its known value, if\n+ * doing so is sufficient to add support for it to older versions that\n+ * don't have it.\n+ *\n  * Keep any symbols in date order of when their support was\n  * introduced, oldest first, in the official version of cURL library.\n  */\n \n+/**\n+ * CURL_SOCKOPT_OK was added in 7.21.5, released in April 2011.\n+ */\n+#if LIBCURL_VERSION_NUM < 0x071505\n+#define CURL_SOCKOPT_OK 0\n+#endif\n+\n /**\n  * CURLOPT_TCP_KEEPALIVE was added in 7.25.0, released in March 2012.\n  */\ndiff --git a/http.c b/http.c\nindex 94eefe97089..d7c20493d7f 100644\n--- a/http.c\n+++ b/http.c\n@@ -537,7 +537,7 @@ static int sockopt_callback(void *client, curl_socket_t fd, curlsocktype type)\n \tif (rc < 0)\n \t\twarning_errno(\"unable to set SO_KEEPALIVE on socket\");\n \n-\treturn 0; /* CURL_SOCKOPT_OK only exists since curl 7.21.5 */\n+\treturn CURL_SOCKOPT_OK;\n }\n \n static void set_curl_keepalive(CURL *c)\n-- \n2.33.0.1013.ge8323766266\n\n"},{"id":"435746","messageId":"YT+EH1O+kPrf4T8j@coredump.intra.peff.net","threadId":"46547","inReplyTo":"cover-v4-0.9-00000000000-20210913T144846Z-avarab@gmail.com","subject":"Re: [PATCH v4 0/9] post-v2.33 \"drop support for ancient curl\" follow-up","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2021-09-13T17:02:23Z","receivedAt":"2021-09-13T17:02:26Z","isPatch":true,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Mon, Sep 13, 2021 at 04:51:20PM +0200, Ævar Arnfjörð Bjarmason wrote:\n\n> This is a hopefully final re-roll with a small grammar improvement in\n> 3/8. See range-diff, pointed out/requested at\n> https://lore.kernel.org/git/YTzBUFY4p6obEqF+@coredump.intra.peff.net/\n\nWell, I did say \"no need to re-roll\". :) But thank you for addressing\nit. This version looks good to me.\n\n-Peff\n"},{"id":"435756","messageId":"xmqq4kaogyq1.fsf@gitster.g","threadId":"46547","inReplyTo":"YT+EH1O+kPrf4T8j@coredump.intra.peff.net","subject":"Re: [PATCH v4 0/9] post-v2.33 \"drop support for ancient curl\" follow-up","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2021-09-13T17:41:10Z","receivedAt":"2021-09-13T17:41:25Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Jeff King <peff@peff.net> writes:\n\n> On Mon, Sep 13, 2021 at 04:51:20PM +0200, Ævar Arnfjörð Bjarmason wrote:\n>\n>> This is a hopefully final re-roll with a small grammar improvement in\n>> 3/8. See range-diff, pointed out/requested at\n>> https://lore.kernel.org/git/YTzBUFY4p6obEqF+@coredump.intra.peff.net/\n>\n> Well, I did say \"no need to re-roll\". :) But thank you for addressing\n> it. This version looks good to me.\n\nYup, the word-diff from what was queued with a !fixup step looks\npleasing ;-)\n\nWill replace.\n\nLet me mark it for 'next' in the What's cooking report.\n\nThanks.\n\n\n$ git diff --word-diff @{1}\ndiff --git c/INSTALL w/INSTALL\nindex 5865e1630d..4140a3f5c8 100644\n--- c/INSTALL\n+++ w/INSTALL\n@@ -144,9 +144,9 @@ Issues of note:\n\t  not need that functionality, use NO_CURL to build without\n\t  it.\n\n\t  Git requires version \"7.19.4\" or later of \"libcurl\" to build\n\t  without NO_CURL. This version requirement may be bumped in\n\t  the future.\n\n\t- \"expat\" library; git-http-push uses it for remote lock\n\t  management over DAV.  Similar to \"curl\" above, this is optional\n\n"}]}