{"thread":{"id":"65558","subject":"[PATCH] t5564: use a short path for the SOCKS proxy socket","startedAt":"2026-04-27T14:21:13Z","lastAt":"2026-05-01T06:47:47Z","messageCount":4,"participants":["Johannes Schindelin via GitGitGadget","Jeff King"],"isPatch":true,"patchVersion":1,"patchTotal":null},"messages":[{"id":"542390","messageId":"pull.2100.git.1777299669889.gitgitgadget@gmail.com","threadId":"65558","inReplyTo":null,"subject":"[PATCH] t5564: use a short path for the SOCKS proxy socket","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-27T14:21:09Z","receivedAt":"2026-04-27T14:21:13Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nThe SOCKS proxy test introduced in 0ca365c2ed4 (http: do not ignore\nproxy path, 2024-08-02) creates a Unix domain socket in\n`$TRASH_DIRECTORY`. When the trash directory path is long (e.g.\nwhen running from a deeply nested worktree), the socket path can\nexceed the 108-character limit for `struct sockaddr_un.sun_path` on\nLinux, causing the test to fail with \"Path length ... is longer\nthan maximum supported length (108)\".\n\nMove the socket to `$TMPDIR` (defaulting to `/tmp`) where the path\nis short, following the same approach used in t7528 for the SSH\nagent socket in b7fb2194b96 (t7528: work around ETOOMANY in OpenSSH\n10.1 and newer, 2025-10-23).\n\nAssisted-by: Claude Opus 4.6\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n    t5564: use a short path for the SOCKS proxy socket\n    \n    When trying to run the entire test suite in a slightly deeper path than\n    usual, I was surprised to see that this test failed due to our old\n    friend, the 108 character limit of Unix sockets.\n\nPublished-As: https://github.com/gitgitgadget/git/releases/tag/pr-2100%2Fdscho%2Favoid-too-long-unix-socket-path-in-socks-proxy-test-v1\nFetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-2100/dscho/avoid-too-long-unix-socket-path-in-socks-proxy-test-v1\nPull-Request: https://github.com/gitgitgadget/git/pull/2100\n\n t/t5564-http-proxy.sh | 10 ++++++++--\n 1 file changed, 8 insertions(+), 2 deletions(-)\n\ndiff --git a/t/t5564-http-proxy.sh b/t/t5564-http-proxy.sh\nindex 3bcbdef409..cb7ede4ca4 100755\n--- a/t/t5564-http-proxy.sh\n+++ b/t/t5564-http-proxy.sh\n@@ -50,14 +50,19 @@ start_socks() {\n \n # The %30 tests that the correct amount of percent-encoding is applied to the\n # proxy string passed to curl.\n+# Use a short path for the socket to avoid exceeding the 108-character\n+# Unix domain socket limit when the trash directory path is long.\n+SOCKS_SOCK=\"${TMPDIR:-/tmp}/git-test-socks-%30.sock\"\n+\n test_lazy_prereq SOCKS_PROXY '\n \ttest_have_prereq PERL &&\n-\tstart_socks \"$TRASH_DIRECTORY/%30.sock\"\n+\tstart_socks \"$SOCKS_SOCK\"\n '\n \n test_atexit '\n \ttest ! -e \"$TRASH_DIRECTORY/socks.pid\" ||\n \tkill \"$(cat \"$TRASH_DIRECTORY/socks.pid\")\"\n+\trm -f \"$SOCKS_SOCK\"\n '\n \n # The below tests morally ought to be gated on a prerequisite that Git is\n@@ -70,7 +75,8 @@ old_libcurl_error() {\n \n test_expect_success SOCKS_PROXY 'clone via Unix socket' '\n \ttest_when_finished \"rm -rf clone\" &&\n-\ttest_config_global http.proxy \"socks4://localhost$PWD/%2530.sock\" && {\n+\tsocks_proxy_url=\"socks4://localhost$(echo \"$SOCKS_SOCK\" | sed \"s/%/%25/g\")\" &&\n+\ttest_config_global http.proxy \"$socks_proxy_url\" && {\n \t\t{\n \t\t\tGIT_TRACE_CURL=$PWD/trace \\\n \t\t\tGIT_TRACE_CURL_COMPONENTS=socks \\\n\nbase-commit: 94f057755b7941b321fd11fec1b2e3ca5313a4e0\n-- \ngitgitgadget\n"},{"id":"542410","messageId":"20260428023350.GB660154@coredump.intra.peff.net","threadId":"65558","inReplyTo":"pull.2100.git.1777299669889.gitgitgadget@gmail.com","subject":"Re: [PATCH] t5564: use a short path for the SOCKS proxy socket","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2026-04-28T02:33:50Z","receivedAt":"2026-04-28T02:33:51Z","isPatch":true,"body":"On Mon, Apr 27, 2026 at 02:21:09PM +0000, Johannes Schindelin via GitGitGadget wrote:\n\n> The SOCKS proxy test introduced in 0ca365c2ed4 (http: do not ignore\n> proxy path, 2024-08-02) creates a Unix domain socket in\n> `$TRASH_DIRECTORY`. When the trash directory path is long (e.g.\n> when running from a deeply nested worktree), the socket path can\n> exceed the 108-character limit for `struct sockaddr_un.sun_path` on\n> Linux, causing the test to fail with \"Path length ... is longer\n> than maximum supported length (108)\".\n\nOK. We try to work around this with a chdir in our own socket code, but\nI guess we're not using it here:\n\n  1. The socket is created by our socks4-proxy.pl script, which just\n     feeds it to perl's IO::Socket::UNIX. And it looks like it\n     recognizes the long path and complains. We could fix that, but...\n\n  2. The reading side is implemented by libcurl, not by us. And it seems\n     to similarly detect and complain. We _could_ work around that with\n     a chdir, but it would be quite nasty, as we'd have to do it before\n     every curl call. So that's probably off the table.\n\nAnd so we are stuck with either using a relative path, or a known-small\none.\n\n> Move the socket to `$TMPDIR` (defaulting to `/tmp`) where the path\n> is short, following the same approach used in t7528 for the SSH\n> agent socket in b7fb2194b96 (t7528: work around ETOOMANY in OpenSSH\n> 10.1 and newer, 2025-10-23).\n\nOK, there we went with the known-small solution, since openssh made it\neasy to do so. I think that is OK here, but...\n\n>  # The %30 tests that the correct amount of percent-encoding is applied to the\n>  # proxy string passed to curl.\n> +# Use a short path for the socket to avoid exceeding the 108-character\n> +# Unix domain socket limit when the trash directory path is long.\n> +SOCKS_SOCK=\"${TMPDIR:-/tmp}/git-test-socks-%30.sock\"\n\nThis is a static path in /tmp, so:\n\n  1. Multiple instances of the test suite will stomp on each other\n     (e.g., a --stress run).\n\n  2. It creates a tmpdir-race vulnerability if an attacker links that\n     path to something precious writeable by the user running the tests.\n\nI think it would be sufficient to use mktemp to get a unique name. We\ndon't want a file, of course, so we perhaps need \"mktemp -d\" to get a\ntemp directory, and then we can use whatever short name we like inside\nit.\n\n>  test_lazy_prereq SOCKS_PROXY '\n>  \ttest_have_prereq PERL &&\n> -\tstart_socks \"$TRASH_DIRECTORY/%30.sock\"\n> +\tstart_socks \"$SOCKS_SOCK\"\n>  '\n>  \n>  test_atexit '\n>  \ttest ! -e \"$TRASH_DIRECTORY/socks.pid\" ||\n>  \tkill \"$(cat \"$TRASH_DIRECTORY/socks.pid\")\"\n> +\trm -f \"$SOCKS_SOCK\"\n>  '\n\nAnd the rest of your path can remain as-is, since SOCKS_SOCK will have\nthe unique name in it.\n\n-Peff\n"},{"id":"542465","messageId":"pull.2100.v2.git.1777450974159.gitgitgadget@gmail.com","threadId":"65558","inReplyTo":"pull.2100.git.1777299669889.gitgitgadget@gmail.com","subject":"[PATCH v2] t5564: use a short path for the SOCKS proxy socket","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-29T08:22:54Z","receivedAt":"2026-04-29T08:22:56Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nThe SOCKS proxy test introduced in 0ca365c2ed4 (http: do not ignore\nproxy path, 2024-08-02) creates a Unix domain socket in\n`$TRASH_DIRECTORY`. When the trash directory path is long (e.g.\nwhen running from a deeply nested worktree), the socket path can\nexceed the 108-character limit for `struct sockaddr_un.sun_path` on\nLinux, causing the test to fail with \"Path length ... is longer\nthan maximum supported length (108)\".\n\nWe cannot work around this using the chdir trick our own socket code\nemploys, because both sides of the connection are outside our control:\nthe socket is created by socks4-proxy.pl via Perl's IO::Socket::UNIX,\nand the client side is libcurl.\n\nUse `mktemp -d` to create a unique temporary directory with a short\npath, and place the socket inside it. This avoids collisions between\nconcurrent test runs (e.g. `--stress`) and tmpdir-race vulnerabilities\nthat a static `/tmp` path would be susceptible to.\n\nHelped-by: Jeff King <peff@peff.net>\nAssisted-by: Claude Opus 4.6\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n    t5564: use a short path for the SOCKS proxy socket\n    \n    When trying to run the entire test suite in a slightly deeper path than\n    usual, I was surprised to see that this test failed due to our old\n    friend, the 108 character limit of Unix sockets.\n    \n    Changes since v1:\n    \n     * Uses mktemp -d now, to handle --stress better (thanks, Jeff!)\n\nPublished-As: https://github.com/gitgitgadget/git/releases/tag/pr-2100%2Fdscho%2Favoid-too-long-unix-socket-path-in-socks-proxy-test-v2\nFetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-2100/dscho/avoid-too-long-unix-socket-path-in-socks-proxy-test-v2\nPull-Request: https://github.com/gitgitgadget/git/pull/2100\n\nRange-diff vs v1:\n\n 1:  16826e612c ! 1:  256b76a999 t5564: use a short path for the SOCKS proxy socket\n     @@ Commit message\n          Linux, causing the test to fail with \"Path length ... is longer\n          than maximum supported length (108)\".\n      \n     -    Move the socket to `$TMPDIR` (defaulting to `/tmp`) where the path\n     -    is short, following the same approach used in t7528 for the SSH\n     -    agent socket in b7fb2194b96 (t7528: work around ETOOMANY in OpenSSH\n     -    10.1 and newer, 2025-10-23).\n     +    We cannot work around this using the chdir trick our own socket code\n     +    employs, because both sides of the connection are outside our control:\n     +    the socket is created by socks4-proxy.pl via Perl's IO::Socket::UNIX,\n     +    and the client side is libcurl.\n      \n     +    Use `mktemp -d` to create a unique temporary directory with a short\n     +    path, and place the socket inside it. This avoids collisions between\n     +    concurrent test runs (e.g. `--stress`) and tmpdir-race vulnerabilities\n     +    that a static `/tmp` path would be susceptible to.\n     +\n     +    Helped-by: Jeff King <peff@peff.net>\n          Assisted-by: Claude Opus 4.6\n          Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n      \n     @@ t/t5564-http-proxy.sh: start_socks() {\n       # proxy string passed to curl.\n      +# Use a short path for the socket to avoid exceeding the 108-character\n      +# Unix domain socket limit when the trash directory path is long.\n     -+SOCKS_SOCK=\"${TMPDIR:-/tmp}/git-test-socks-%30.sock\"\n     ++SOCKS_TMPDIR=$(mktemp -d)\n     ++SOCKS_SOCK=\"$SOCKS_TMPDIR/%30.sock\"\n      +\n       test_lazy_prereq SOCKS_PROXY '\n       \ttest_have_prereq PERL &&\n     @@ t/t5564-http-proxy.sh: start_socks() {\n       test_atexit '\n       \ttest ! -e \"$TRASH_DIRECTORY/socks.pid\" ||\n       \tkill \"$(cat \"$TRASH_DIRECTORY/socks.pid\")\"\n     -+\trm -f \"$SOCKS_SOCK\"\n     ++\trm -rf \"$SOCKS_TMPDIR\"\n       '\n       \n       # The below tests morally ought to be gated on a prerequisite that Git is\n\n\n t/t5564-http-proxy.sh | 11 +++++++++--\n 1 file changed, 9 insertions(+), 2 deletions(-)\n\ndiff --git a/t/t5564-http-proxy.sh b/t/t5564-http-proxy.sh\nindex 3bcbdef409..b4d95b12ca 100755\n--- a/t/t5564-http-proxy.sh\n+++ b/t/t5564-http-proxy.sh\n@@ -50,14 +50,20 @@ start_socks() {\n \n # The %30 tests that the correct amount of percent-encoding is applied to the\n # proxy string passed to curl.\n+# Use a short path for the socket to avoid exceeding the 108-character\n+# Unix domain socket limit when the trash directory path is long.\n+SOCKS_TMPDIR=$(mktemp -d)\n+SOCKS_SOCK=\"$SOCKS_TMPDIR/%30.sock\"\n+\n test_lazy_prereq SOCKS_PROXY '\n \ttest_have_prereq PERL &&\n-\tstart_socks \"$TRASH_DIRECTORY/%30.sock\"\n+\tstart_socks \"$SOCKS_SOCK\"\n '\n \n test_atexit '\n \ttest ! -e \"$TRASH_DIRECTORY/socks.pid\" ||\n \tkill \"$(cat \"$TRASH_DIRECTORY/socks.pid\")\"\n+\trm -rf \"$SOCKS_TMPDIR\"\n '\n \n # The below tests morally ought to be gated on a prerequisite that Git is\n@@ -70,7 +76,8 @@ old_libcurl_error() {\n \n test_expect_success SOCKS_PROXY 'clone via Unix socket' '\n \ttest_when_finished \"rm -rf clone\" &&\n-\ttest_config_global http.proxy \"socks4://localhost$PWD/%2530.sock\" && {\n+\tsocks_proxy_url=\"socks4://localhost$(echo \"$SOCKS_SOCK\" | sed \"s/%/%25/g\")\" &&\n+\ttest_config_global http.proxy \"$socks_proxy_url\" && {\n \t\t{\n \t\t\tGIT_TRACE_CURL=$PWD/trace \\\n \t\t\tGIT_TRACE_CURL_COMPONENTS=socks \\\n\nbase-commit: 94f057755b7941b321fd11fec1b2e3ca5313a4e0\n-- \ngitgitgadget\n"},{"id":"542542","messageId":"20260501064746.GC2038915@coredump.intra.peff.net","threadId":"65558","inReplyTo":"pull.2100.v2.git.1777450974159.gitgitgadget@gmail.com","subject":"Re: [PATCH v2] t5564: use a short path for the SOCKS proxy socket","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2026-05-01T06:47:46Z","receivedAt":"2026-05-01T06:47:47Z","isPatch":true,"body":"On Wed, Apr 29, 2026 at 08:22:54AM +0000, Johannes Schindelin via GitGitGadget wrote:\n\n> From: Johannes Schindelin <johannes.schindelin@gmx.de>\n> \n> The SOCKS proxy test introduced in 0ca365c2ed4 (http: do not ignore\n> proxy path, 2024-08-02) creates a Unix domain socket in\n> `$TRASH_DIRECTORY`. When the trash directory path is long (e.g.\n> when running from a deeply nested worktree), the socket path can\n> exceed the 108-character limit for `struct sockaddr_un.sun_path` on\n> Linux, causing the test to fail with \"Path length ... is longer\n> than maximum supported length (108)\".\n> \n> We cannot work around this using the chdir trick our own socket code\n> employs, because both sides of the connection are outside our control:\n> the socket is created by socks4-proxy.pl via Perl's IO::Socket::UNIX,\n> and the client side is libcurl.\n> \n> Use `mktemp -d` to create a unique temporary directory with a short\n> path, and place the socket inside it. This avoids collisions between\n> concurrent test runs (e.g. `--stress`) and tmpdir-race vulnerabilities\n> that a static `/tmp` path would be susceptible to.\n\nThanks, this looks great to me (and thank you for fleshing out the\nexplanation in the commit message, too).\n\n-Peff\n"}]}