{"thread":{"id":"65793","subject":"t5563-simple-http-auth failures with v2.55.0-rc0","startedAt":"2026-06-11T21:04:59Z","lastAt":"2026-06-18T16:18:58Z","messageCount":6,"participants":["Todd Zullinger","Matthew John Cheetham","Junio C Hamano"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"545315","messageId":"20260611210456.XYfhytSL@teonanacatl.net","threadId":"65793","inReplyTo":null,"subject":"t5563-simple-http-auth failures with v2.55.0-rc0","fromName":"Todd Zullinger","fromEmail":"tmz@pobox.com","sentAt":"2026-06-11T21:04:56Z","receivedAt":"2026-06-11T21:04:59Z","isPatch":false,"body":"Hi,\n\nI tested the freshly-tagged 2.55.0-rc0 and noticed some new\nfailures on the in-progress Fedora 45 (AKA Rawhide) for\nt5563.18 (http.emptyAuth=auto attempts Negotiate before\ncredential_fill) which was added in 9b1630b972 (t5563: add\ntests for http.emptyAuth with Negotiate, 2026-04-16).\n\nI notice that Fedora 44 (where the tests all pass) has\ncurl-8.18.0 while Fedora 45 has curl-8.21.0-rc2.  The\nversion of httpd is the same between them, FWIW.  I didn't\ncompare other package differences; it could be something\nelse entirely.\n\nHere is the output from a failing test run:\n\n--8<--\n++ test_when_finished per_test_cleanup                                                                                                                                                                             \n++ test 0 = 0                                                                                                                                                                                                      \n++ test_cleanup=$'{ per_test_cleanup\\n\\t\\t} || eval_ret=$?; :'                                                                                                                                                     \n++ set_credential_reply get                                                                                                                                                                                        \n+++ test -n ''                                                                                                                                                                                                     \n++ local suffix=                                                                                                                                                                                                   \n++ cat                                                                                                                                                                                                             \n++ cat                                                                                                                                                                                                             \n++ cat                                                                                                                                                                                                             \n++ test_config_global credential.helper test-helper                                                                                                                                                                \n++ test_when_finished 'test_unconfig --global '\\''credential.helper'\\'''                                                                                                                                           \n++ test 0 = 0                                                                                                                                                                                                      \n++ test_cleanup=$'{ test_unconfig --global \\'credential.helper\\'\\n\\t\\t} || eval_ret=$?; { per_test_cleanup\\n\\t\\t} || eval_ret=$?; :'                                                                               \n++ git config --global credential.helper test-helper                                                                                                                                                               \n++ GIT_TRACE_CURL='/builddir/build/BUILD/git-2.55.0_rc0-build/git-2.55.0.rc0/t/trash directory.t5563-simple-http-auth/trace-auto'                                                                                  \n++ git -c http.emptyAuth=auto ls-remote http://127.0.0.1:5563/custom_auth/repo.git                                                                                                                                 \nddd63c907a6168e9992caee4ef0e0fa1139e4eb3        HEAD                                                                                                                                                               \nddd63c907a6168e9992caee4ef0e0fa1139e4eb3        refs/heads/master                                                                                                                                                  \nddd63c907a6168e9992caee4ef0e0fa1139e4eb3        refs/tags/foo                                                                                                                                                      \n++ grep 'HTTP/[0-9.]* 401' '/builddir/build/BUILD/git-2.55.0_rc0-build/git-2.55.0.rc0/t/trash directory.t5563-simple-http-auth/trace-auto'                                                                         \n++ test_line_count = 3 actual_401s                                                                                                                                                                                 \n++ test 3 '!=' 3                                                                                                                                                                                                   \n+++ wc -l                                                                                                                                                                                                          \n++ test 2 = 3                                                                                                                                                                                                      \n++ echo 'test_line_count: line count for actual_401s != 3'                                                                                                                                                         \ntest_line_count: line count for actual_401s != 3                                                                                                                                                                   \n++ cat actual_401s                                                                                                                                                                                                 \n<= Recv header: HTTP/1.1 401 Authorization Required                                                                                                                                                                \n<= Recv header: HTTP/1.1 401 Authorization Required                                                                                                                                                                \n++ return 1                                                                                                                                                                                                        \nerror: last command exited with $?=1                                                                                                                                                                               \nnot ok 18 - http.emptyAuth=auto attempts Negotiate before credential_fill                                                                                                                                          \n--8<--\n\nAnd a diff of the trace-auto from Fedora 44 and 45 via\n./t5563-simple-http-auth.sh -dix --run='-18' (with the\nsending port normalized to 44444 to reduce the noise):\n\n--- /dev/fd/63\t2026-06-11 16:51:05.852135692 -0400\n+++ /dev/fd/62\t2026-06-11 16:51:05.853135711 -0400\n@@ -23,6 +23,7 @@\n <= Recv header:\n <= Recv data, 0000000000 bytes (0x00000000)\n == Info: shutting down connection #0\n+== Info: Could not find host 127.0.0.1 in the .netrc file; using defaults\n == Info: NTLM-proxy picked AND auth done set, clear picked\n == Info: Hostname 127.0.0.1 was found in DNS cache\n == Info:   Trying 127.0.0.1:5563...\n@@ -47,37 +48,8 @@\n == Info: no chunk, no close, no size. Assume close to signal end\n <= Recv header, 0000000001 bytes (0x00000001)\n <= Recv header:\n-== Info: shutting down connection #1\n-== Info: Issue another request to this URL: 'http://127.0.0.1:5563/custom_auth/repo.git/info/refs?service=git-upload-pack'\n-== Info: NTLM-proxy picked AND auth done set, clear picked\n-== Info: Hostname 127.0.0.1 was found in DNS cache\n-== Info:   Trying 127.0.0.1:5563...\n-== Info: Established connection to 127.0.0.1 (127.0.0.1 port 5563) from 127.0.0.1 port 44444\n-== Info: using HTTP/1.x\n-== Info: gss_init_sec_context() failed: No credentials were supplied, or the credentials were unavailable or inaccessible. SPNEGO cannot find mechanisms to negotiate. \n-== Info: Server auth using Negotiate with user ''\n-=> Send header, 0000000214 bytes (0x000000d6)\n-=> Send header: GET /custom_auth/repo.git/info/refs?service=git-upload-pack HTTP/1.1\n-=> Send header: Host: 127.0.0.1:5563\n-=> Send header: User-Agent: git/2.55.0.rc0\n-=> Send header: Accept: */*\n-=> Send header: Accept-Encoding: deflate, gzip, br\n-=> Send header: Pragma: no-cache\n-=> Send header: Git-Protocol: version=2\n-=> Send header:\n-== Info: Request completely sent off\n-<= Recv header, 0000000036 bytes (0x00000024)\n-<= Recv header: HTTP/1.1 401 Authorization Required\n-== Info: gss_init_sec_context() failed: No credentials were supplied, or the credentials were unavailable or inaccessible. SPNEGO cannot find mechanisms to negotiate. \n-<= Recv header, 0000000028 bytes (0x0000001c)\n-<= Recv header: WWW-Authenticate: Negotiate\n-<= Recv header, 0000000044 bytes (0x0000002c)\n-<= Recv header: WWW-Authenticate: Basic realm=\"example.com\"\n-== Info: no chunk, no close, no size. Assume close to signal end\n-<= Recv header, 0000000001 bytes (0x00000001)\n-<= Recv header:\n <= Recv data, 0000000000 bytes (0x00000000)\n-== Info: shutting down connection #2\n+== Info: shutting down connection #1\n == Info: NTLM-proxy picked AND auth done set, clear picked\n == Info: Hostname 127.0.0.1 was found in DNS cache\n == Info:   Trying 127.0.0.1:5563...\n@@ -113,7 +85,7 @@\n <= Recv data: orn.0020fetch=shallow wait-for-done.0012server-option.0017ob\n <= Recv data: ject-format=sha1.0000\n <= Recv data, 0000000000 bytes (0x00000000)\n-== Info: shutting down connection #3\n+== Info: shutting down connection #2\n == Info: NTLM-proxy picked AND auth done set, clear picked\n == Info: Hostname 127.0.0.1 was found in DNS cache\n == Info:   Trying 127.0.0.1:5563...\n@@ -154,4 +126,4 @@\n <= Recv data: 9e4eb3 refs/heads/master.003bddd63c907a6168e9992caee4ef0e0fa\n <= Recv data: 1139e4eb3 refs/tags/foo.0000\n <= Recv data, 0000000000 bytes (0x00000000)\n-== Info: shutting down connection #4\n+== Info: shutting down connection #3\n\nThe absence of one of the requests stands out.  Anyone\nfamiliar with this area have suggestions for how to further\ndebug it?  It should reproduce easily in a Fedora 45\ncontainer, if anyone wants to poke at it more directly.\n\nThanks,\n\n-- \nTodd\n"},{"id":"545395","messageId":"VI0PR03MB1163416D5C66FAB25AECAAE21C0182@VI0PR03MB11634.eurprd03.prod.outlook.com","threadId":"65793","inReplyTo":"20260611210456.XYfhytSL@teonanacatl.net","subject":"Re: t5563-simple-http-auth failures with v2.55.0-rc0","fromName":"Matthew John Cheetham","fromEmail":"mjcheetham@outlook.com","sentAt":"2026-06-12T15:42:18Z","receivedAt":"2026-06-12T15:42:23Z","isPatch":false,"body":"On 2026-06-11 22:04, Todd Zullinger wrote:\n\n> Hi,\n> \n> I tested the freshly-tagged 2.55.0-rc0 and noticed some new\n> failures on the in-progress Fedora 45 (AKA Rawhide) for\n> t5563.18 (http.emptyAuth=auto attempts Negotiate before\n> credential_fill) which was added in 9b1630b972 (t5563: add\n> tests for http.emptyAuth with Negotiate, 2026-04-16).\n> \n> I notice that Fedora 44 (where the tests all pass) has\n> curl-8.18.0 while Fedora 45 has curl-8.21.0-rc2.  The\n> version of httpd is the same between them, FWIW.  I didn't\n> compare other package differences; it could be something\n> else entirely.\n\nThanks for the report. The failure is not in Git, it is a libcurl\nbehaviour change, and there is already an open upstream issue:\n\n   https://github.com/curl/curl/issues/21943\n   \"Negotiate ignored with --anyauth\" (Dan Fandrich, 2026-06-10)\n\nDan also bisected it to the same commit I had locally,\n`8f71d0fde515` (\"creds: hold credentials\", curl PR #21548).\n\nHis report describes the regression at the `curl(1)` level (`curl\n--anyauth -u : ...` no longer attempts Negotiate); t5563 test 18 is\nthe same regression observed through `http.emptyAuth=auto`, which\nunder the hood is the same `CURLOPT_USERPWD=\":\"` pattern.\n\nDan also notes a workaround: replacing `-u :` with `-u\nliterally:anything` (any non-blank username, real or fake) puts\nlibcurl back on the Negotiate path. That suggests a small Git-side\nescape hatch is possible if we want to unblock people running\nagainst current libcurl while we wait for an upstream fix; I have\nnot tried it yet and would want to be sure it does not have side\neffects on other auth schemes before proposing it.\n\nDaniel Stenberg has acknowledged the curl issue but has not yet\nposted a fix. I will follow curl#21943 and, if the upstream answer\nis \"the new behaviour is intended\", come back here with a proposal\nfor what Git should do about `http.emptyAuth` and test 18.\n\nThanks,\nMatthew\n\n"},{"id":"545405","messageId":"20260612180203.s2qSgDUs@teonanacatl.net","threadId":"65793","inReplyTo":"VI0PR03MB1163416D5C66FAB25AECAAE21C0182@VI0PR03MB11634.eurprd03.prod.outlook.com","subject":"Re: t5563-simple-http-auth failures with v2.55.0-rc0","fromName":"Todd Zullinger","fromEmail":"tmz@pobox.com","sentAt":"2026-06-12T18:02:03Z","receivedAt":"2026-06-12T18:02:06Z","isPatch":false,"body":"Hi,\n\nMatthew John Cheetham wrote:\n> On 2026-06-11 22:04, Todd Zullinger wrote:\n>> I notice that Fedora 44 (where the tests all pass) has\n>> curl-8.18.0 while Fedora 45 has curl-8.21.0-rc2.  The\n>> version of httpd is the same between them, FWIW.  I didn't\n>> compare other package differences; it could be something\n>> else entirely.\n> \n> Thanks for the report. The failure is not in Git, it is a libcurl\n> behaviour change, and there is already an open upstream issue:\n> \n>   https://github.com/curl/curl/issues/21943\n>   \"Negotiate ignored with --anyauth\" (Dan Fandrich, 2026-06-10)\n> \n> Dan also bisected it to the same commit I had locally,\n> `8f71d0fde515` (\"creds: hold credentials\", curl PR #21548).\n[...]\n> Daniel Stenberg has acknowledged the curl issue but has not yet\n> posted a fix. I will follow curl#21943 and, if the upstream answer\n> is \"the new behaviour is intended\", come back here with a proposal\n> for what Git should do about `http.emptyAuth` and test 18.\n\nExcellent.  This is it good hands all around.\n\nWith luck, curl is updated and the canary of distributions\nlike Fedora's Rawhide will have served a useful purpose in\nflushing out issues before they affect most people.  With\nthe help of git's excellent and thorough test suite, of\ncourse. :)\n\nIf there is a curl update, I imagine it will be picked up\nreasonably quickly in Fedora (and elsewhere that was testing\n8.21.0 release candidates) and there will hopefully be no\nstrong need to make any changes on the git side.\n\nThanks!\n\n-- \nTodd\n"},{"id":"545853","messageId":"20260618144953.l6Ng-dvv@teonanacatl.net","threadId":"65793","inReplyTo":"20260612180203.s2qSgDUs@teonanacatl.net","subject":"Re: t5563-simple-http-auth failures with v2.55.0-rc0","fromName":"Todd Zullinger","fromEmail":"tmz@pobox.com","sentAt":"2026-06-18T14:49:53Z","receivedAt":"2026-06-18T14:49:55Z","isPatch":false,"body":"Hi,\n\nI wrote:\n> Matthew John Cheetham wrote:\n>> Thanks for the report. The failure is not in Git, it is a libcurl\n>> behaviour change, and there is already an open upstream issue:\n>> \n>>   https://github.com/curl/curl/issues/21943\n>>   \"Negotiate ignored with --anyauth\" (Dan Fandrich, 2026-06-10)\n>> \n>> Dan also bisected it to the same commit I had locally,\n>> `8f71d0fde515` (\"creds: hold credentials\", curl PR #21548).\n> [...]\n>> Daniel Stenberg has acknowledged the curl issue but has not yet\n>> posted a fix. I will follow curl#21943 and, if the upstream answer\n>> is \"the new behaviour is intended\", come back here with a proposal\n>> for what Git should do about `http.emptyAuth` and test 18.\n> \n> Excellent.  This is it good hands all around.\n[...]\n> \n> If there is a curl update, I imagine it will be picked up\n> reasonably quickly in Fedora (and elsewhere that was testing\n> 8.21.0 release candidates) and there will hopefully be no\n> strong need to make any changes on the git side.\n\nI saw Fedora picked up curl-8.21.0-rc3 this morning and\nconfirmed it resolves the git test failures.  Someone else\nhas already commented on the upstream curl issue to note\nthat.\n\nThanks,\n\n-- \nTodd\n"},{"id":"545855","messageId":"VI0PR03MB11634D905F0167747B1DB8096C0E32@VI0PR03MB11634.eurprd03.prod.outlook.com","threadId":"65793","inReplyTo":"20260618144953.l6Ng-dvv@teonanacatl.net","subject":"Re: t5563-simple-http-auth failures with v2.55.0-rc0","fromName":"Matthew John Cheetham","fromEmail":"mjcheetham@outlook.com","sentAt":"2026-06-18T15:02:50Z","receivedAt":"2026-06-18T15:02:55Z","isPatch":false,"body":"On 2026-06-18 15:49, Todd Zullinger wrote:\n\n> I saw Fedora picked up curl-8.21.0-rc3 this morning and\n> confirmed it resolves the git test failures.  Someone else\n> has already commented on the upstream curl issue to note\n> that.\nThanks for confirming rc3 fixes things!\n\nThe CURLOPT_USERPWD = \":\" behaviour was never codified in curl's \ndocumentation, but given the fix they've put in place it's probably a \ngood sign we can continue to rely on this.\n\nI may propose a patch to curl documentation's patch to say that this\nbehaviour is expected and supported, if the they don't do it themselves \nsoon already.\n\nThanks,\nMatthew\n\n"},{"id":"545867","messageId":"xmqq8q8bstxr.fsf@gitster.g","threadId":"65793","inReplyTo":"20260618144953.l6Ng-dvv@teonanacatl.net","subject":"Re: t5563-simple-http-auth failures with v2.55.0-rc0","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2026-06-18T16:18:56Z","receivedAt":"2026-06-18T16:18:58Z","isPatch":false,"body":"Todd Zullinger <tmz@pobox.com> writes:\n\n> I saw Fedora picked up curl-8.21.0-rc3 this morning and\n> confirmed it resolves the git test failures.  Someone else\n> has already commented on the upstream curl issue to note\n> that.\n\nThanks.\n"}]}