{"thread":{"id":"65879","subject":"[PATCH] http: accept https:// proxies again","startedAt":"2026-06-27T17:17:59Z","lastAt":"2026-06-28T22:27:11Z","messageCount":4,"participants":["Johannes Schindelin via GitGitGadget","Junio C Hamano"],"isPatch":true,"patchVersion":1,"patchTotal":null},"messages":[{"id":"546547","messageId":"pull.2161.git.1782580676734.gitgitgadget@gmail.com","threadId":"65879","inReplyTo":null,"subject":"[PATCH] http: accept https:// proxies again","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-06-27T17:17:56Z","receivedAt":"2026-06-27T17:17:59Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nSince 663d7abe07ea (http: reject unsupported proxy URL schemes,\n2026-05-05), set_curl_proxy_type() returns 0 only for the \"http\"\nand SOCKS variants via dedicated early returns, and -1 for\neverything else. The \"https\" branch configures the CURL handle for\nHTTPS proxying but then falls through to the trailing `return -1`\nintended for unknown schemes, so the caller in get_curl_handle()\ntreats a perfectly valid https:// proxy URL as unsupported and\nrefuses to use it.\n\nNoticed while looking into a Coverity report against the same\nfunction; the unchecked curl_easy_setopt() return values it flags\nare orthogonal to this fix.\n\nAssisted-by: Opus 4.7\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n    http: accept https:// proxies again\n\nPublished-As: https://github.com/gitgitgadget/git/releases/tag/pr-2161%2Fdscho%2Ffix-bug-in-validate-proxy-url-scheme-v1\nFetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-2161/dscho/fix-bug-in-validate-proxy-url-scheme-v1\nPull-Request: https://github.com/gitgitgadget/git/pull/2161\n\n http.c | 2 ++\n 1 file changed, 2 insertions(+)\n\ndiff --git a/http.c b/http.c\nindex 8e5a4d8bcf..8c0f831365 100644\n--- a/http.c\n+++ b/http.c\n@@ -802,6 +802,8 @@ static int set_curl_proxy_type(CURL *result, const char *protocol)\n \t\tif (has_proxy_cert_password())\n \t\t\tcurl_easy_setopt(result, CURLOPT_PROXY_KEYPASSWD,\n \t\t\t\t\t proxy_cert_auth.password);\n+\n+\t\treturn 0;\n \t}\n \n \treturn -1;\n\nbase-commit: 663d7abe07ea376c2657019a03297ae87037c993\n-- \ngitgitgadget\n"},{"id":"546576","messageId":"xmqq8q7z4eg3.fsf@gitster.g","threadId":"65879","inReplyTo":"pull.2161.git.1782580676734.gitgitgadget@gmail.com","subject":"Re: [PATCH] http: accept https:// proxies again","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2026-06-28T01:54:36Z","receivedAt":"2026-06-28T01:54:39Z","isPatch":true,"body":"\"Johannes Schindelin via GitGitGadget\" <gitgitgadget@gmail.com>\nwrites:\n\n>  http.c | 2 ++\n>  1 file changed, 2 insertions(+)\n>\n> diff --git a/http.c b/http.c\n> index 8e5a4d8bcf..8c0f831365 100644\n> --- a/http.c\n> +++ b/http.c\n> @@ -802,6 +802,8 @@ static int set_curl_proxy_type(CURL *result, const char *protocol)\n>  \t\tif (has_proxy_cert_password())\n>  \t\t\tcurl_easy_setopt(result, CURLOPT_PROXY_KEYPASSWD,\n>  \t\t\t\t\t proxy_cert_auth.password);\n> +\n> +\t\treturn 0;\n>  \t}\n>  \n>  \treturn -1;\n\nThat lack of \"return 0\" is so glaringly obvious when you point it\nout like this patch does, and it is surprising it has been missed\ninitially.\n\nFrom this function nothing returns an error anymore, and looking at\nthe preimage of 663d7abe (http: reject unsupported proxy URL\nschemes, 2026-05-05) that is the source of the bug, the original did\nnot do anything when the corresponding code did not find and set any\nproxy settings, either.\n\nSo perhaps it is a better fix to make it just a function that\nreturns void with early returns?\n\nThanks.\n"},{"id":"546580","messageId":"xmqqjyrj2qsp.fsf@gitster.g","threadId":"65879","inReplyTo":"xmqq8q7z4eg3.fsf@gitster.g","subject":"Re: [PATCH] http: accept https:// proxies again","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2026-06-28T05:10:46Z","receivedAt":"2026-06-28T05:10:49Z","isPatch":true,"body":"Junio C Hamano <gitster@pobox.com> writes:\n\n> From this function nothing returns an error anymore, and looking at\n> the preimage of 663d7abe (http: reject unsupported proxy URL\n> schemes, 2026-05-05) that is the source of the bug, the original did\n> not do anything when the corresponding code did not find and set any\n> proxy settings, either.\n>\n> So perhaps it is a better fix to make it just a function that\n> returns void with early returns?\n\nNah, I was being stupid.  Disregard the above.\n\nThe whole point of 663d7abe was that we wanted to reject what we did\nnot recognise, and we cannot do so without returning \"good/bad\" from\nthat function.  The bug was that we did recognise https:// but still\nreturned -1 because of the bug, which the patch in the thread fixed.\n\nThanks.\n"},{"id":"546615","messageId":"xmqq1pdq1etf.fsf@gitster.g","threadId":"65879","inReplyTo":"xmqqjyrj2qsp.fsf@gitster.g","subject":"Re: [PATCH] http: accept https:// proxies again","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2026-06-28T22:27:08Z","receivedAt":"2026-06-28T22:27:11Z","isPatch":true,"body":"Junio C Hamano <gitster@pobox.com> writes:\n\n> Junio C Hamano <gitster@pobox.com> writes:\n>\n>> From this function nothing returns an error anymore, and looking at\n>> the preimage of 663d7abe (http: reject unsupported proxy URL\n>> schemes, 2026-05-05) that is the source of the bug, the original did\n>> not do anything when the corresponding code did not find and set any\n>> proxy settings, either.\n>>\n>> So perhaps it is a better fix to make it just a function that\n>> returns void with early returns?\n>\n> Nah, I was being stupid.  Disregard the above.\n>\n> The whole point of 663d7abe was that we wanted to reject what we did\n> not recognise, and we cannot do so without returning \"good/bad\" from\n> that function.  The bug was that we did recognise https:// but still\n> returned -1 because of the bug, which the patch in the thread fixed.\n\nAnd as an important bugfix, this patch of course has been\nfast-tracked.  I'll make sure we have it in 'master' before Git 2.55\ngets tagged.\n\nThanks.\n"}]}