{"thread":{"id":"62305","subject":"minimum curl version effectively changed","startedAt":"2024-10-10T18:25:09Z","lastAt":"2024-10-10T21:52:26Z","messageCount":4,"participants":["Alejandro R. Sedeño","brian m. carlson"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"504728","messageId":"CAOO-Oz0NUA-YeyFT1MJ=XKyLWJvQoFH1b-F0EFOzvy8iWka3KA@mail.gmail.com","threadId":"62305","inReplyTo":null,"subject":"minimum curl version effectively changed","fromName":"Alejandro R. Sedeño","fromEmail":"asedeno@mit.edu","sentAt":"2024-10-10T18:24:52Z","receivedAt":"2024-10-10T18:25:09Z","isPatch":false,"sender":{"key":"asedeno@mit.edu","avatar":"https://avatars.githubusercontent.com/u/28302?v=4"},"body":"As of ad9bb6dfe6e598d87ffe6e2285b4b86dac3bc726, http.c depends on\nsymbols introduced curl 7.37.0, which is newer than the documented\nminimum version of 7.21.3 in INSTALL.\n\n```\nIn file included from /usr/include/curl/curl.h:2238:0,\n                 from git-curl-compat.h:3,\n                 from http.c:4:\nhttp.c: In function ‘set_proxyauth_name_password’:\nhttp.c:655:28: error: ‘CURLOPT_PROXYHEADER’ undeclared (first use in\nthis function)\n   curl_easy_setopt(result, CURLOPT_PROXYHEADER,\n                            ^\nhttp.c:655:28: note: each undeclared identifier is reported only once\nfor each function it appears in\nmake: *** [http.o] Error 1\n```\n\n-Alejandro\n"},{"id":"504754","messageId":"ZwhF0OZ2gpLWUfHD@tapette.crustytoothpaste.net","threadId":"62305","inReplyTo":"CAOO-Oz0NUA-YeyFT1MJ=XKyLWJvQoFH1b-F0EFOzvy8iWka3KA@mail.gmail.com","subject":"Re: minimum curl version effectively changed","fromName":"brian m. carlson","fromEmail":"sandals@crustytoothpaste.net","sentAt":"2024-10-10T21:23:28Z","receivedAt":"2024-10-10T21:23:36Z","isPatch":false,"sender":{"key":"sandals@crustytoothpaste.net","avatar":"https://avatars.githubusercontent.com/u/497054?v=4"},"body":"On 2024-10-10 at 18:24:52, Alejandro R. Sedeño wrote:\n> As of ad9bb6dfe6e598d87ffe6e2285b4b86dac3bc726, http.c depends on\n> symbols introduced curl 7.37.0, which is newer than the documented\n> minimum version of 7.21.3 in INSTALL.\n> \n> ```\n> In file included from /usr/include/curl/curl.h:2238:0,\n>                  from git-curl-compat.h:3,\n>                  from http.c:4:\n> http.c: In function ‘set_proxyauth_name_password’:\n> http.c:655:28: error: ‘CURLOPT_PROXYHEADER’ undeclared (first use in\n> this function)\n>    curl_easy_setopt(result, CURLOPT_PROXYHEADER,\n>                             ^\n> http.c:655:28: note: each undeclared identifier is reported only once\n> for each function it appears in\n> make: *** [http.o] Error 1\n> ```\n\nFrom the curl changelog, I do agree that that feature was added in\n7.37.0.  I think that's okay, since that was released in May 2014, over\na decade ago, so we probably need to update INSTALL appropriately.  I\ndon't think any major Linux distros are still offering complementary\nsecurity support for such an old version of libcurl, so I don't see us\nrestoring support for older libcurl.\n\nIt will probably also involve ripping out appropriate parts of\n`git-curl-compat.h` and the option flags. If nobody else gets to it over\nthe next couple of days, I'll try to, but of course anyone is free to\nsend in a patch.\n-- \nbrian m. carlson (they/them or he/him)\nToronto, Ontario, CA\n"},{"id":"504755","messageId":"CAOO-Oz1KhFcyErVx1Qb142PtPJS=UpgSD-FacckqNS4_okAtFQ@mail.gmail.com","threadId":"62305","inReplyTo":"ZwhF0OZ2gpLWUfHD@tapette.crustytoothpaste.net","subject":"Re: minimum curl version effectively changed","fromName":"Alejandro R. Sedeño","fromEmail":"asedeno@mit.edu","sentAt":"2024-10-10T21:30:04Z","receivedAt":"2024-10-10T21:30:21Z","isPatch":false,"sender":{"key":"asedeno@mit.edu","avatar":"https://avatars.githubusercontent.com/u/28302?v=4"},"body":"I have a patch I plan to send in tomorrow that will properly\nconditionalize using the symbol on versions of curl that have it, and\nemitting a warning otherwise. It will also follow up with some\ncorrections to errors in git-curl-compat.h.\n\nI don't think a new feature should unilaterally change the minimum\nrequirements of git without some announcement and forethought.\n\n-Alejandro\n\nOn Thu, Oct 10, 2024 at 5:23 PM brian m. carlson\n<sandals@crustytoothpaste.net> wrote:\n>\n> On 2024-10-10 at 18:24:52, Alejandro R. Sedeño wrote:\n> > As of ad9bb6dfe6e598d87ffe6e2285b4b86dac3bc726, http.c depends on\n> > symbols introduced curl 7.37.0, which is newer than the documented\n> > minimum version of 7.21.3 in INSTALL.\n> >\n> > ```\n> > In file included from /usr/include/curl/curl.h:2238:0,\n> >                  from git-curl-compat.h:3,\n> >                  from http.c:4:\n> > http.c: In function ‘set_proxyauth_name_password’:\n> > http.c:655:28: error: ‘CURLOPT_PROXYHEADER’ undeclared (first use in\n> > this function)\n> >    curl_easy_setopt(result, CURLOPT_PROXYHEADER,\n> >                             ^\n> > http.c:655:28: note: each undeclared identifier is reported only once\n> > for each function it appears in\n> > make: *** [http.o] Error 1\n> > ```\n>\n> From the curl changelog, I do agree that that feature was added in\n> 7.37.0.  I think that's okay, since that was released in May 2014, over\n> a decade ago, so we probably need to update INSTALL appropriately.  I\n> don't think any major Linux distros are still offering complementary\n> security support for such an old version of libcurl, so I don't see us\n> restoring support for older libcurl.\n>\n> It will probably also involve ripping out appropriate parts of\n> `git-curl-compat.h` and the option flags. If nobody else gets to it over\n> the next couple of days, I'll try to, but of course anyone is free to\n> send in a patch.\n> --\n> brian m. carlson (they/them or he/him)\n> Toronto, Ontario, CA\n"},{"id":"504757","messageId":"ZwhMmGt0kZvaSzSL@tapette.crustytoothpaste.net","threadId":"62305","inReplyTo":"CAOO-Oz1KhFcyErVx1Qb142PtPJS=UpgSD-FacckqNS4_okAtFQ@mail.gmail.com","subject":"Re: minimum curl version effectively changed","fromName":"brian m. carlson","fromEmail":"sandals@crustytoothpaste.net","sentAt":"2024-10-10T21:52:24Z","receivedAt":"2024-10-10T21:52:26Z","isPatch":false,"sender":{"key":"sandals@crustytoothpaste.net","avatar":"https://avatars.githubusercontent.com/u/497054?v=4"},"body":"On 2024-10-10 at 21:30:04, Alejandro R. Sedeño wrote:\n> I have a patch I plan to send in tomorrow that will properly\n> conditionalize using the symbol on versions of curl that have it, and\n> emitting a warning otherwise. It will also follow up with some\n> corrections to errors in git-curl-compat.h.\n> \n> I don't think a new feature should unilaterally change the minimum\n> requirements of git without some announcement and forethought.\n\nWe already have a platform support policy, which guides our behaviour\nhere, and it was discussed very recently.  It says this:\n\n  Uses versions of dependencies which are generally accepted as stable and\n  supportable, e.g., in line with the version used by other long-term-support\n  distributions\n\nNo major Linux distributions are still using such an old version of\nlibcurl.  CentOS 7 is dead, and we don't typically support extended\nlong-term support because it comes at a cost, and it's not fair to\nGit developers to require them to pay for a secure system to test\nagainst.  I don't know of any other major OS which is providing support\nfor such an old version of curl either.  Usually the BSDs have a much\nshorter life span for versions, for example.\n\nSo I think the oldest supported version we're going to be willing to\naccept is in a clone of RHEL 8, which would be curl 7.61.  It's\ncertainly a mistake on our part that we neglected to update INSTALL\naccordingly, but it's not a mistake that we unconditionally added\nsupport for a feature from over a decade ago.\n-- \nbrian m. carlson (they/them or he/him)\nToronto, Ontario, CA\n"}]}