{"thread":{"id":"66374","subject":"[PATCH] ci: work around Debian 12's HTTP/2 authentication failures","startedAt":"2026-09-22T23:06:16Z","lastAt":"2026-10-06T03:52:39Z","messageCount":13,"participants":["Johannes Schindelin via GitGitGadget","Junio C Hamano","Jeff King","Johannes Schindelin"],"isPatch":true,"patchVersion":1,"patchTotal":null},"messages":[{"id":"553027","messageId":"pull.2236.git.1790118373340.gitgitgadget@gmail.com","threadId":"66374","inReplyTo":null,"subject":"[PATCH] ci: work around Debian 12's HTTP/2 authentication failures","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-09-22T23:06:13Z","receivedAt":"2026-09-22T23:06:16Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nSince 00fa8502354 (ci: bump debian-11 job to debian-12, 2026-09-05), the\n`debian-12` job has intermittently failed t5559's half-auth clone with:\n\n  curl 92 Stream error in the HTTP/2 framing layer\n\nAnonymous discovery succeeds, but the upload-pack POST requires\nauthentication. Apache can return an early 401 and close the HTTP/2\nstream before libcurl finishes sending the request body. Debian 12's\ncurl 7.88.1 treats that closure as a transport error instead of allowing\nan authentication retry. Curl fixed this handling in 331b89a319d0\n(http2: polish things around POST), included in 8.3.0:\nhttps://github.com/curl/curl/pull/11756\n\nThis did not happen before switching to Debian 12 because Debian 11\nships with libcurl 7.74.0-1.3+deb11u16, which does not have that bug.\n\nReplacing the packaged libcurl with a modern build would defeat this\njob's purpose of testing older supported distributions. So let's simply\nexclude the flaky t5559.15 and its dependent t5559.16 on Debian 12 until\nthe packaged curl carries the fix (or until the end of time, whichever\ncomes first).\n\nAssisted-by: GPT-6 Astra\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n    ci: work around Debian 12's HTTP/2 authentication failures\n    \n    While this is a regression in v2.56, it does not affect production code,\n    it's just working around a flaky test. In other words: This patch does\n    not need to be fast-tracked into v2.56.0, but it would be good to get it\n    into master pretty soon after that, to reduce developer friction.\n\nPublished-As: https://github.com/gitgitgadget/git/releases/tag/pr-2236%2Fdscho%2Fwork-around-debian-curl-stream-error-92-v1\nFetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-2236/dscho/work-around-debian-curl-stream-error-92-v1\nPull-Request: https://github.com/gitgitgadget/git/pull/2236\n\n ci/lib.sh | 6 ++++++\n 1 file changed, 6 insertions(+)\n\ndiff --git a/ci/lib.sh b/ci/lib.sh\nindex c6ccbf8c17..1cf31b5a2c 100755\n--- a/ci/lib.sh\n+++ b/ci/lib.sh\n@@ -334,6 +334,12 @@ pull_request,*|push,*next*|push,*master*|push,*main*|push,*maint*)\n esac\n \n case \"$distro\" in\n+debian-12)\n+\t# Debian 12's curl 7.88.1 mishandles early HTTP/2 responses; see\n+\t# https://github.com/curl/curl/pull/11756. Skip the half-auth\n+\t# clone and its dependent fetch until Debian has the fix.\n+\texport GIT_SKIP_TESTS=\"$GIT_SKIP_TESTS t5559.15 t5559.16\"\n+\t;;\n ubuntu-*)\n \t# Python 2 is end of life, and Ubuntu 23.04 and newer don't actually\n \t# have it anymore. We thus only test with Python 2 on older LTS\n\nbase-commit: 3bc0341126508f78f5869cbfc0005e987efdf0c7\n-- \ngitgitgadget\n"},{"id":"553070","messageId":"xmqq1pakc59l.fsf@gitster.g","threadId":"66374","inReplyTo":"pull.2236.git.1790118373340.gitgitgadget@gmail.com","subject":"Re: [PATCH] ci: work around Debian 12's HTTP/2 authentication failures","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2026-09-23T16:16:22Z","receivedAt":"2026-09-23T16:16:24Z","isPatch":true,"body":"\"Johannes Schindelin via GitGitGadget\" <gitgitgadget@gmail.com>\nwrites:\n\n> From: Johannes Schindelin <johannes.schindelin@gmx.de>\n>\n> Since 00fa8502354 (ci: bump debian-11 job to debian-12, 2026-09-05), the\n> `debian-12` job has intermittently failed t5559's half-auth clone with:\n>\n>   curl 92 Stream error in the HTTP/2 framing layer\n>\n> Anonymous discovery succeeds, but the upload-pack POST requires\n> authentication. Apache can return an early 401 and close the HTTP/2\n> stream before libcurl finishes sending the request body. Debian 12's\n> curl 7.88.1 treats that closure as a transport error instead of allowing\n> an authentication retry. Curl fixed this handling in 331b89a319d0\n> (http2: polish things around POST), included in 8.3.0:\n> https://github.com/curl/curl/pull/11756\n>\n> This did not happen before switching to Debian 12 because Debian 11\n> ships with libcurl 7.74.0-1.3+deb11u16, which does not have that bug.\n\nSuperb.  A well written diagnosis like this is worth a ton.\n\n> Replacing the packaged libcurl with a modern build would defeat this\n> job's purpose of testing older supported distributions. So let's simply\n> exclude the flaky t5559.15 and its dependent t5559.16 on Debian 12 until\n> the packaged curl carries the fix (or until the end of time, whichever\n> comes first).\n\nOh, 100% agree with the reasoning.  Thanks for this workaround.\n\n>     it's just working around a flaky test. In other words: This patch does\n>     not need to be fast-tracked into v2.56.0, but it would be good to get it\n>     into master pretty soon after that, to reduce developer friction.\n\nYes.  I do not think there is any reason to cook it as long as other\nusual patches.  Fast-tracking would make sure other things do keep\nworking on older Debian.\n\nThanks.\n\n\n\n>\n> Published-As: https://github.com/gitgitgadget/git/releases/tag/pr-2236%2Fdscho%2Fwork-around-debian-curl-stream-error-92-v1\n> Fetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-2236/dscho/work-around-debian-curl-stream-error-92-v1\n> Pull-Request: https://github.com/gitgitgadget/git/pull/2236\n>\n>  ci/lib.sh | 6 ++++++\n>  1 file changed, 6 insertions(+)\n>\n> diff --git a/ci/lib.sh b/ci/lib.sh\n> index c6ccbf8c17..1cf31b5a2c 100755\n> --- a/ci/lib.sh\n> +++ b/ci/lib.sh\n> @@ -334,6 +334,12 @@ pull_request,*|push,*next*|push,*master*|push,*main*|push,*maint*)\n>  esac\n>  \n>  case \"$distro\" in\n> +debian-12)\n> +\t# Debian 12's curl 7.88.1 mishandles early HTTP/2 responses; see\n> +\t# https://github.com/curl/curl/pull/11756. Skip the half-auth\n> +\t# clone and its dependent fetch until Debian has the fix.\n> +\texport GIT_SKIP_TESTS=\"$GIT_SKIP_TESTS t5559.15 t5559.16\"\n> +\t;;\n>  ubuntu-*)\n>  \t# Python 2 is end of life, and Ubuntu 23.04 and newer don't actually\n>  \t# have it anymore. We thus only test with Python 2 on older LTS\n>\n> base-commit: 3bc0341126508f78f5869cbfc0005e987efdf0c7\n"},{"id":"553071","messageId":"20260923164700.GA28538@coredump.intra.peff.net","threadId":"66374","inReplyTo":"pull.2236.git.1790118373340.gitgitgadget@gmail.com","subject":"Re: [PATCH] ci: work around Debian 12's HTTP/2 authentication failures","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2026-09-23T16:47:00Z","receivedAt":"2026-09-23T16:47:04Z","isPatch":true,"body":"On Tue, Sep 22, 2026 at 11:06:13PM +0000, Johannes Schindelin via GitGitGadget wrote:\n\n> Anonymous discovery succeeds, but the upload-pack POST requires\n> authentication. Apache can return an early 401 and close the HTTP/2\n> stream before libcurl finishes sending the request body. Debian 12's\n> curl 7.88.1 treats that closure as a transport error instead of allowing\n> an authentication retry. Curl fixed this handling in 331b89a319d0\n> (http2: polish things around POST), included in 8.3.0:\n> https://github.com/curl/curl/pull/11756\n> \n> This did not happen before switching to Debian 12 because Debian 11\n> ships with libcurl 7.74.0-1.3+deb11u16, which does not have that bug.\n\nThanks for finding and fixing. I saw this yesterday but hadn't had time\nto dig in yet, and your explanation is very satisfying. :)\n\n> Replacing the packaged libcurl with a modern build would defeat this\n> job's purpose of testing older supported distributions. So let's simply\n> exclude the flaky t5559.15 and its dependent t5559.16 on Debian 12 until\n> the packaged curl carries the fix (or until the end of time, whichever\n> comes first).\n\nThat should reduce the immediate CI pain, though I can think of two\ndownsides:\n\n  - we're detecting based on CI job name, not on the presence of the\n    known bug. So it won't help anybody running the tests themselves\n    (even people on debian-12!)\n\n  - we're relying on test numbering, which can change over time. So if\n    we add new setup tests early in t5559 (actually, t5551 which it's\n    based on!) these will silently go out of sync.\n\nSo an ideal solution to me would be more like t5559 checking for the\nbuggy version itself, setting a prereq, and then marking the tests with\n!HAVE_CURL_HTTP2_BUG.\n\nThat said, I'm not sure how tricky that would be to implement. We give\nthe curl version with \"git version --build-options\", but we'd have to do\nsome version number comparisons. It might not be worth spending a lot of\ntime on this.\n\n-Peff\n"},{"id":"553072","messageId":"20260923165348.GA29229@coredump.intra.peff.net","threadId":"66374","inReplyTo":"20260923164700.GA28538@coredump.intra.peff.net","subject":"Re: [PATCH] ci: work around Debian 12's HTTP/2 authentication failures","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2026-09-23T16:53:48Z","receivedAt":"2026-09-23T16:53:50Z","isPatch":true,"body":"On Wed, Sep 23, 2026 at 12:47:01PM -0400, Jeff King wrote:\n\n> So an ideal solution to me would be more like t5559 checking for the\n> buggy version itself, setting a prereq, and then marking the tests with\n> !HAVE_CURL_HTTP2_BUG.\n> \n> That said, I'm not sure how tricky that would be to implement. We give\n> the curl version with \"git version --build-options\", but we'd have to do\n> some version number comparisons. It might not be worth spending a lot of\n> time on this.\n\nI guess our robot overlords^Whelpers could help with that. I passed your\npatch and my email to Astra, which came up with this:\n\ndiff --git a/t/t5551-http-fetch-smart.sh b/t/t5551-http-fetch-smart.sh\nindex 805bec025c..8f620f0b44 100755\n--- a/t/t5551-http-fetch-smart.sh\n+++ b/t/t5551-http-fetch-smart.sh\n@@ -17,6 +17,15 @@ fi\n test \"$HTTP_PROTO\" = \"HTTP/2\" && enable_http2\n start_httpd\n \n+# Curl 7.88.1 can fail to retry authentication after an early HTTP/2\n+# response. This was fixed in curl 8.3.0; see\n+# https://github.com/curl/curl/pull/11756. Match the known-broken version,\n+# since older versions (e.g., 7.74.0) work.\n+test_lazy_prereq HAVE_CURL_HTTP2_BUG '\n+\ttest_have_prereq HTTP2 &&\n+\ttest \"$(build_option libcurl)\" = 7.88.1\n+'\n+\n test_expect_success HTTP2 'enable client-side http/2' '\n \tgit config --global http.version HTTP/2\n '\n@@ -224,7 +233,7 @@ test_expect_success 'clone from auth-only-for-push repository' '\n \ttest_cmp expect actual\n '\n \n-test_expect_success 'clone from auth-only-for-objects repository' '\n+test_expect_success !HAVE_CURL_HTTP2_BUG 'clone from auth-only-for-objects repository' '\n \techo two >expect &&\n \tset_askpass user@host pass@host &&\n \tgit clone --bare \"$HTTPD_URL/auth-fetch/smart/repo.git\" half-auth &&\n@@ -233,7 +242,7 @@ test_expect_success 'clone from auth-only-for-objects repository' '\n \ttest_cmp expect actual\n '\n \n-test_expect_success 'no-op half-auth fetch does not require a password' '\n+test_expect_success !HAVE_CURL_HTTP2_BUG 'no-op half-auth fetch does not require a password' '\n \tset_askpass wrong &&\n \n \t# NEEDSWORK: When using HTTP(S), protocol v0 supports a \"half-auth\"\n\n\nNot too bad. I had envisioned checking the range of versions, since you\nfound the fix (but we'd have to either use 7.88.1 as the start, or find\nthe actual bug introduction). But this covers at least as much as the\nCI debian-12 specifier would.\n\n-Peff\n"},{"id":"553074","messageId":"20260923165922.GB29229@coredump.intra.peff.net","threadId":"66374","inReplyTo":"20260923165348.GA29229@coredump.intra.peff.net","subject":"Re: [PATCH] ci: work around Debian 12's HTTP/2 authentication failures","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2026-09-23T16:59:22Z","receivedAt":"2026-09-23T16:59:23Z","isPatch":true,"body":"On Wed, Sep 23, 2026 at 12:53:48PM -0400, Jeff King wrote:\n\n> I guess our robot overlords^Whelpers could help with that. I passed your\n> patch and my email to Astra, which came up with this:\n>\n> [...]\n>\n> Not too bad. I had envisioned checking the range of versions, since you\n> found the fix (but we'd have to either use 7.88.1 as the start, or find\n> the actual bug introduction). But this covers at least as much as the\n> CI debian-12 specifier would.\n\nOK, last email, I promise, since you could probably be feeding this to\nAstra just as easily as I am (and you did the actual interesting work on\nthe patch of figuring out the problem, so I'll leave it to you decide\nwhich approach you like). The range version is something like this:\n\ndiff --git a/t/t5551-http-fetch-smart.sh b/t/t5551-http-fetch-smart.sh\nindex 805bec025c..3d18f98c9d 100755\n--- a/t/t5551-http-fetch-smart.sh\n+++ b/t/t5551-http-fetch-smart.sh\n@@ -17,6 +17,21 @@ fi\n test \"$HTTP_PROTO\" = \"HTTP/2\" && enable_http2\n start_httpd\n \n+# Curl 7.88.1 can fail to retry authentication after an early HTTP/2\n+# response. This was fixed in curl 8.3.0; see\n+# https://github.com/curl/curl/pull/11756. The first affected version is\n+# unknown, so conservatively assume that versions from 7.88.1 up to (but\n+# not including) 8.3.0 are broken.\n+test_lazy_prereq HAVE_CURL_HTTP2_BUG '\n+\ttest_have_prereq HTTP2 &&\n+\tbuild_option libcurl |\n+\tawk -F. '\\''\n+\t\t($1 == 7 && ($2 > 88 || ($2 == 88 && $3 >= 1))) ||\n+\t\t($1 == 8 && $2 < 3) { broken = 1 }\n+\t\tEND { exit !broken }\n+\t'\\''\n+'\n+\n test_expect_success HTTP2 'enable client-side http/2' '\n \tgit config --global http.version HTTP/2\n '\n\nwhich is not _too_ ugly.\n\n-Peff\n"},{"id":"553081","messageId":"xmqqwlsbc2ge.fsf@gitster.g","threadId":"66374","inReplyTo":"20260923165922.GB29229@coredump.intra.peff.net","subject":"Re: [PATCH] ci: work around Debian 12's HTTP/2 authentication failures","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2026-09-23T17:17:05Z","receivedAt":"2026-09-23T17:17:08Z","isPatch":true,"body":"Jeff King <peff@peff.net> writes:\n\n> +# Curl 7.88.1 can fail to retry authentication after an early HTTP/2\n> +# response. This was fixed in curl 8.3.0; see\n> +# https://github.com/curl/curl/pull/11756. The first affected version is\n> +# unknown, so conservatively assume that versions from 7.88.1 up to (but\n> +# not including) 8.3.0 are broken.\n\nJust nitpicking the wording, but if the first affected version is\ntruly unknown, assuming that versions from 7.88.1 up is *not* a\nconservative thing to do at all, is it?\n\nIf 7.88.1 is from an irrelevantly ancient past, I would say that we\nshould just skip anything older than 8.3.0, but 7.88.1 is from early\n2023 and we cannot do such a simplification.\n\n> +test_lazy_prereq HAVE_CURL_HTTP2_BUG '\n> +\ttest_have_prereq HTTP2 &&\n> +\tbuild_option libcurl |\n> +\tawk -F. '\\''\n> +\t\t($1 == 7 && ($2 > 88 || ($2 == 88 && $3 >= 1))) ||\n> +\t\t($1 == 8 && $2 < 3) { broken = 1 }\n> +\t\tEND { exit !broken }\n> +\t'\\''\n> +'\n> +\n>  test_expect_success HTTP2 'enable client-side http/2' '\n>  \tgit config --global http.version HTTP/2\n>  '\n>\n> which is not _too_ ugly.\n>\n> -Peff\n"},{"id":"553101","messageId":"20260923192514.GA43344@coredump.intra.peff.net","threadId":"66374","inReplyTo":"xmqqwlsbc2ge.fsf@gitster.g","subject":"Re: [PATCH] ci: work around Debian 12's HTTP/2 authentication failures","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2026-09-23T19:25:14Z","receivedAt":"2026-09-23T19:25:21Z","isPatch":true,"body":"On Wed, Sep 23, 2026 at 10:17:05AM -0700, Junio C Hamano wrote:\n\n> Jeff King <peff@peff.net> writes:\n> \n> > +# Curl 7.88.1 can fail to retry authentication after an early HTTP/2\n> > +# response. This was fixed in curl 8.3.0; see\n> > +# https://github.com/curl/curl/pull/11756. The first affected version is\n> > +# unknown, so conservatively assume that versions from 7.88.1 up to (but\n> > +# not including) 8.3.0 are broken.\n> \n> Just nitpicking the wording, but if the first affected version is\n> truly unknown, assuming that versions from 7.88.1 up is *not* a\n> conservative thing to do at all, is it?\n> \n> If 7.88.1 is from an irrelevantly ancient past, I would say that we\n> should just skip anything older than 8.3.0, but 7.88.1 is from early\n> 2023 and we cannot do such a simplification.\n\nIt depends on what bad outcome we are being conservative against. If the\nbad outcome is skipping the test on a version for which we could\nreliably use it, then it is conservative to only select known-bad\nversions. If the bad outcome is somebody running the test and seeing a\nflaky fail, then yes, the more conservative thing would be extending to\nskip older unknown versions (potentially up to \"forever\").\n\nI think you could argue either way (and I am OK with either, or even\njust matching 7.88.1).\n\n-Peff\n"},{"id":"553225","messageId":"e94a9d4f-567e-83a0-e12a-908082365e77@gmx.de","threadId":"66374","inReplyTo":"20260923192514.GA43344@coredump.intra.peff.net","subject":"Re: [PATCH] ci: work around Debian 12's HTTP/2 authentication failures","fromName":"Johannes Schindelin","fromEmail":"johannes.schindelin@gmx.de","sentAt":"2026-09-24T18:59:24Z","receivedAt":"2026-09-24T18:59:33Z","isPatch":true,"body":"Hi Jeff,\n\nOn Wed, 23 Sep 2026, Jeff King wrote:\n\n> On Wed, Sep 23, 2026 at 10:17:05AM -0700, Junio C Hamano wrote:\n> \n> > Jeff King <peff@peff.net> writes:\n> > \n> > > +# Curl 7.88.1 can fail to retry authentication after an early HTTP/2\n> > > +# response. This was fixed in curl 8.3.0; see\n> > > +# https://github.com/curl/curl/pull/11756. The first affected version is\n> > > +# unknown, so conservatively assume that versions from 7.88.1 up to (but\n> > > +# not including) 8.3.0 are broken.\n> > \n> > Just nitpicking the wording, but if the first affected version is\n> > truly unknown, assuming that versions from 7.88.1 up is *not* a\n> > conservative thing to do at all, is it?\n> > \n> > If 7.88.1 is from an irrelevantly ancient past, I would say that we\n> > should just skip anything older than 8.3.0, but 7.88.1 is from early\n> > 2023 and we cannot do such a simplification.\n> \n> It depends on what bad outcome we are being conservative against. If the\n> bad outcome is skipping the test on a version for which we could\n> reliably use it, then it is conservative to only select known-bad\n> versions. If the bad outcome is somebody running the test and seeing a\n> flaky fail, then yes, the more conservative thing would be extending to\n> skip older unknown versions (potentially up to \"forever\").\n> \n> I think you could argue either way (and I am OK with either, or even\n> just matching 7.88.1).\n\nI had GPT-6 dig deeper into the issue, since you're right: This should not\nbe a CI/Debian-only gate, at the same time I didn't know what was the\nfirst version with the bug, so I suspected the version range to be subtly\ninaccurate. Turns out that the bug appeared first in cURL v7.88.0. So I\nadjusted your version range in preparation for the next patch iteration.\n\nThank you!\nJohannes\n"},{"id":"553228","messageId":"xmqqld8q1lnr.fsf@gitster.g","threadId":"66374","inReplyTo":"e94a9d4f-567e-83a0-e12a-908082365e77@gmx.de","subject":"Re: [PATCH] ci: work around Debian 12's HTTP/2 authentication failures","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2026-09-24T19:42:16Z","receivedAt":"2026-09-24T19:42:18Z","isPatch":true,"body":"Johannes Schindelin <Johannes.Schindelin@gmx.de> writes:\n\n>> I think you could argue either way (and I am OK with either, or even\n>> just matching 7.88.1).\n>\n> I had GPT-6 dig deeper into the issue, since you're right: This should not\n> be a CI/Debian-only gate, at the same time I didn't know what was the\n> first version with the bug, so I suspected the version range to be subtly\n> inaccurate. Turns out that the bug appeared first in cURL v7.88.0. So I\n> adjusted your version range in preparation for the next patch iteration.\n\nGreat digging.  So it is between 7.88.0 and 8.3.0?\n"},{"id":"553241","messageId":"pull.2236.v2.git.1790283229626.gitgitgadget@gmail.com","threadId":"66374","inReplyTo":"pull.2236.git.1790118373340.gitgitgadget@gmail.com","subject":"[PATCH v2] ci: work around Debian 12's HTTP/2 authentication failures","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-09-24T20:53:49Z","receivedAt":"2026-09-24T20:53:52Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nSince 00fa8502354 (ci: bump debian-11 job to debian-12, 2026-09-05), the\n`debian-12` job has intermittently failed t5559's half-auth clone with:\n\n  curl 92 Stream error in the HTTP/2 framing layer\n\nAnonymous discovery succeeds, but the upload-pack POST requires\nauthentication. Apache can return an early 401 and close the HTTP/2\nstream before libcurl finishes sending the request body. Debian 12's\ncurl 7.88.1 treats that closure as a transport error instead of allowing\nan authentication retry. Curl fixed this handling in 331b89a319d0\n(http2: polish things around POST), included in 8.3.0:\nhttps://github.com/curl/curl/pull/11756\n\nThis did not happen before switching to Debian 12 because Debian 11\nships with libcurl 7.74.0-1.3+deb11u16, which does not have that bug, it\nwas only introduced in cURL 7.88.0.\n\nReplacing the packaged libcurl with a modern build would defeat this\njob's purpose of testing older supported distributions. So let's simply\nskip the flaky test cases when a buggy libcurl version is detected.\n\nAssisted-by: GPT-6 Astra, GPT-6 Sol\nHelped-by: Jeff King <peff@peff.net>\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n    ci: work around Debian 12's HTTP/2 authentication failures\n    \n    While this is a regression in v2.56, it does not affect production code,\n    it's just working around a flaky test. In other words: This patch does\n    not need to be fast-tracked into v2.56.0, but it would be good to get it\n    into master pretty soon after that, to reduce developer friction.\n    \n    Changes since v1:\n    \n     * Instead of hard-coding the test case numbers specifically on Debian\n       12, thanks to Jeff King the test cases now have a\n       libcurl-version-gating prereq.\n\nPublished-As: https://github.com/gitgitgadget/git/releases/tag/pr-2236%2Fdscho%2Fwork-around-debian-curl-stream-error-92-v2\nFetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-2236/dscho/work-around-debian-curl-stream-error-92-v2\nPull-Request: https://github.com/gitgitgadget/git/pull/2236\n\nRange-diff vs v1:\n\n 1:  1dfabf3ece < -:  ---------- ci: work around Debian 12's HTTP/2 authentication failures\n -:  ---------- > 1:  e4c5658fb1 ci: work around Debian 12's HTTP/2 authentication failures\n\n\n t/t5551-http-fetch-smart.sh | 19 +++++++++++++++++--\n 1 file changed, 17 insertions(+), 2 deletions(-)\n\ndiff --git a/t/t5551-http-fetch-smart.sh b/t/t5551-http-fetch-smart.sh\nindex 805bec025c..57f263ca5b 100755\n--- a/t/t5551-http-fetch-smart.sh\n+++ b/t/t5551-http-fetch-smart.sh\n@@ -17,6 +17,19 @@ fi\n test \"$HTTP_PROTO\" = \"HTTP/2\" && enable_http2\n start_httpd\n \n+# The cURL version which Debian 12 ships (v7.88.1) can fail to retry\n+# authentication after an early HTTP/2 response. This bug was introduced\n+# in cURL v7.88.0 (8c762f5998 (http2: minor buffer and error path fixes,\n+# 2023-02-08)) and fixed in v8.3.0 (https://github.com/curl/curl/pull/11756).\n+test_lazy_prereq HAVE_CURL_HTTP2_BUG \"\n+\ttest_have_prereq HTTP2 &&\n+\tbuild_option libcurl |\n+\tawk -F. '\n+\t\t($1 == 7 && $2 >= 88) || ($1 == 8 && $2 < 3) { broken = 1 }\n+\t\tEND { exit !broken }\n+\t'\n+\"\n+\n test_expect_success HTTP2 'enable client-side http/2' '\n \tgit config --global http.version HTTP/2\n '\n@@ -224,7 +237,8 @@ test_expect_success 'clone from auth-only-for-push repository' '\n \ttest_cmp expect actual\n '\n \n-test_expect_success 'clone from auth-only-for-objects repository' '\n+test_expect_success !HAVE_CURL_HTTP2_BUG \\\n+\t'clone from auth-only-for-objects repository' '\n \techo two >expect &&\n \tset_askpass user@host pass@host &&\n \tgit clone --bare \"$HTTPD_URL/auth-fetch/smart/repo.git\" half-auth &&\n@@ -233,7 +247,8 @@ test_expect_success 'clone from auth-only-for-objects repository' '\n \ttest_cmp expect actual\n '\n \n-test_expect_success 'no-op half-auth fetch does not require a password' '\n+test_expect_success !HAVE_CURL_HTTP2_BUG \\\n+\t'no-op half-auth fetch does not require a password' '\n \tset_askpass wrong &&\n \n \t# NEEDSWORK: When using HTTP(S), protocol v0 supports a \"half-auth\"\n\nbase-commit: 3bc0341126508f78f5869cbfc0005e987efdf0c7\n-- \ngitgitgadget\n"},{"id":"553250","messageId":"20260924232214.GA765100@coredump.intra.peff.net","threadId":"66374","inReplyTo":"e94a9d4f-567e-83a0-e12a-908082365e77@gmx.de","subject":"Re: [PATCH] ci: work around Debian 12's HTTP/2 authentication failures","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2026-09-24T23:22:14Z","receivedAt":"2026-09-24T23:22:21Z","isPatch":true,"body":"On Thu, Sep 24, 2026 at 08:59:24PM +0200, Johannes Schindelin wrote:\n\n> I had GPT-6 dig deeper into the issue, since you're right: This should not\n> be a CI/Debian-only gate, at the same time I didn't know what was the\n> first version with the bug, so I suspected the version range to be subtly\n> inaccurate. Turns out that the bug appeared first in cURL v7.88.0. So I\n> adjusted your version range in preparation for the next patch iteration.\n\nGreat, it feels nicer knowing the actual start point. Your v2 patch\nlooks good to me!\n\n-Peff\n"},{"id":"554232","messageId":"20261006034331.GA1325722@coredump.intra.peff.net","threadId":"66374","inReplyTo":"pull.2236.v2.git.1790283229626.gitgitgadget@gmail.com","subject":"[PATCH] t5551: fix quoting in curl version bug prereq","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2026-10-06T03:43:31Z","receivedAt":"2026-10-06T03:43:31Z","isPatch":true,"body":"On Thu, Sep 24, 2026 at 08:53:49PM +0000, Johannes Schindelin via GitGitGadget wrote:\n\n> +# The cURL version which Debian 12 ships (v7.88.1) can fail to retry\n> +# authentication after an early HTTP/2 response. This bug was introduced\n> +# in cURL v7.88.0 (8c762f5998 (http2: minor buffer and error path fixes,\n> +# 2023-02-08)) and fixed in v8.3.0 (https://github.com/curl/curl/pull/11756).\n> +test_lazy_prereq HAVE_CURL_HTTP2_BUG \"\n> +\ttest_have_prereq HTTP2 &&\n> +\tbuild_option libcurl |\n> +\tawk -F. '\n> +\t\t($1 == 7 && $2 >= 88) || ($1 == 8 && $2 < 3) { broken = 1 }\n> +\t\tEND { exit !broken }\n> +\t'\n> +\"\n\nDoh, this is totally broken. The prereq snippet is in double-quotes, so\nthe $1, etc in the awk invocation are interpolated before we even eval\nit. Fix is below.\n\n-- >8 --\nSubject: [PATCH] t5551: fix quoting in curl version bug prereq\n\nWe have a prereq snippet that invokes awk. The awk script's $1, etc,\nvariables need to be quoted to avoid shell interpolation. We correctly\nuse a single-quote inside the prereq snippet, but the snippet itself is\ncontained in double-quotes. So we interpolate \"$1\" into whatever value\nthat happens to have in the outer shell, and eval nonsense like:\n\n  awk '(--some-garbage == 7 && --other-garbage >= 88) ...'\n\nAs a result, we don't think we have a buggy curl version even when we\ndo, and run the test anyway. But of course it's easy not to notice,\nsince this prereq was protecting us from a racy bug. It only breaks\nsometimes.\n\nThere are a few options for fixing the quoting:\n\n  1. Backslash-escaping the dollar signs. This is perhaps the least-ugly\n     version, but it's a minor hassle to remember if somebody touches\n     the code later.\n\n  2. Single-quote the snippet, then quote interior single-quotes as\n     '\\''. Reasonably obvious, but ugly.\n\n  3. Use the '<<\\EOT' here-doc trick to specify the snippet. This would\n     look nice, but we don't yet support it for prereqs. ;)\n\nThis patch uses (2), and we can circle back to (3) to make it look nicer\nlater.\n\nSigned-off-by: Jeff King <peff@peff.net>\n---\nThis should go on top of js/ci-debian-12-http2-workaround.\n\nSince I know we both used GPT to work on this, I was curious if this\nslipped past it. Doesn't look like it from what I sent (which used\noption 2 above). I wonder if your agent flipped it, or if you saw how\nugly it was and flipped it yourself. Not blaming, but it's just a funny\nand interesting data point if a human second-guessing the AI output\nintroduced a bug.\n\n t/t5551-http-fetch-smart.sh | 8 ++++----\n 1 file changed, 4 insertions(+), 4 deletions(-)\n\ndiff --git a/t/t5551-http-fetch-smart.sh b/t/t5551-http-fetch-smart.sh\nindex f66d7ce7ac..cb681e644f 100755\n--- a/t/t5551-http-fetch-smart.sh\n+++ b/t/t5551-http-fetch-smart.sh\n@@ -21,14 +21,14 @@ start_httpd\n # authentication after an early HTTP/2 response. This bug was introduced\n # in cURL v7.88.0 (8c762f5998 (http2: minor buffer and error path fixes,\n # 2023-02-08)) and fixed in v8.3.0 (https://github.com/curl/curl/pull/11756).\n-test_lazy_prereq HAVE_CURL_HTTP2_BUG \"\n+test_lazy_prereq HAVE_CURL_HTTP2_BUG '\n \ttest_have_prereq HTTP2 &&\n \tbuild_option libcurl |\n-\tawk -F. '\n+\tawk -F. '\\''\n \t\t($1 == 7 && $2 >= 88) || ($1 == 8 && $2 < 3) { broken = 1 }\n \t\tEND { exit !broken }\n-\t'\n-\"\n+\t'\\''\n+'\n \n test_expect_success HTTP2 'enable client-side http/2' '\n \tgit config --global http.version HTTP/2\n-- \n2.56.0.399.g9e0ddc9b37\n\n\n"},{"id":"554233","messageId":"20261006035239.GA1335881@coredump.intra.peff.net","threadId":"66374","inReplyTo":"20261006034331.GA1325722@coredump.intra.peff.net","subject":"[PATCH 2/1] test-lib: allow lazy prerequisite snippets as here-docs","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2026-10-06T03:52:39Z","receivedAt":"2026-10-06T03:52:39Z","isPatch":true,"body":"On Mon, Oct 05, 2026 at 11:43:32PM -0400, Jeff King wrote:\n\n>   2. Single-quote the snippet, then quote interior single-quotes as\n>      '\\''. Reasonably obvious, but ugly.\n> \n>   3. Use the '<<\\EOT' here-doc trick to specify the snippet. This would\n>      look nice, but we don't yet support it for prereqs. ;)\n> \n> This patch uses (2), and we can circle back to (3) to make it look nicer\n> later.\n\nDoing (3) turned out easier than I thought it would. Patch is below. I\nthink it still makes sense to do the immediate fix with (2), and then\nthis on top as cleanup (or as a separate topic, though obviously there\nis a textual dependency).\n\n-- >8 --\nSubject: test-lib: allow lazy prerequisite snippets as here-docs\n\nCommit 1d133ae91f (test-lib: allow test snippets as here-docs, 2024-07-10)\nlet test_expect_success and test_expect_failure read their snippets from\nstdin, making it easier to use single quotes within them. I mentioned\nthere that we could extend this to lazy prerequisites, but left it for\nlater.\n\nLet's finish that off now. Since test_body_or_stdin() takes the name of\nthe variable to fill, we can use it directly to populate the saved prereq\nsnippet. We read the body when the prereq is declared, but still evaluate\nit only when the prereq is used.\n\nConverting the curl version check in t5551 shows how this can reduce\nawkward quoting.\n\nSigned-off-by: Jeff King <peff@peff.net>\n---\n t/t5551-http-fetch-smart.sh | 8 ++++----\n t/test-lib-functions.sh     | 2 +-\n 2 files changed, 5 insertions(+), 5 deletions(-)\n\ndiff --git a/t/t5551-http-fetch-smart.sh b/t/t5551-http-fetch-smart.sh\nindex cb681e644f..9dd20d1c65 100755\n--- a/t/t5551-http-fetch-smart.sh\n+++ b/t/t5551-http-fetch-smart.sh\n@@ -21,14 +21,14 @@ start_httpd\n # authentication after an early HTTP/2 response. This bug was introduced\n # in cURL v7.88.0 (8c762f5998 (http2: minor buffer and error path fixes,\n # 2023-02-08)) and fixed in v8.3.0 (https://github.com/curl/curl/pull/11756).\n-test_lazy_prereq HAVE_CURL_HTTP2_BUG '\n+test_lazy_prereq HAVE_CURL_HTTP2_BUG - <<\\EOT\n \ttest_have_prereq HTTP2 &&\n \tbuild_option libcurl |\n-\tawk -F. '\\''\n+\tawk -F. '\n \t\t($1 == 7 && $2 >= 88) || ($1 == 8 && $2 < 3) { broken = 1 }\n \t\tEND { exit !broken }\n-\t'\\''\n-'\n+\t'\n+EOT\n \n test_expect_success HTTP2 'enable client-side http/2' '\n \tgit config --global http.version HTTP/2\ndiff --git a/t/test-lib-functions.sh b/t/test-lib-functions.sh\nindex 809c662124..de75ae842c 100644\n--- a/t/test-lib-functions.sh\n+++ b/t/test-lib-functions.sh\n@@ -760,7 +760,7 @@ lazily_testable_prereq= lazily_tested_prereq=\n # Usage: test_lazy_prereq PREREQ 'script'\n test_lazy_prereq () {\n \tlazily_testable_prereq=\"$lazily_testable_prereq$1 \"\n-\teval test_prereq_lazily_$1=\\$2\n+\ttest_body_or_stdin \"test_prereq_lazily_$1\" \"$2\"\n }\n \n test_run_lazy_prereq_ () {\n-- \n2.56.0.399.g9e0ddc9b37\n\n\n"}]}