git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: git-fetch in 1.5.4 fails versus 1.5.3.8

From
Mike Hommey <mh@glandium.org>
Date
Feb 8, 2008, 07:18 UTC
Message-ID
<20080208071835.GA11807@glandium.org>
In-Reply-To
<20080208003239.GA18856@coredump.intra.peff.net>
On Thu, Feb 07, 2008 at 07:32:39PM -0500, Jeff King wrote:
Show 11 quoted lines
> On Thu, Feb 07, 2008 at 11:02:43PM +0100, Mike Hommey wrote:
> 
> > Sorry, I've had trouble opening my eyes and actually reading messages I
> > reply to... anyways, I tried to reproduce with curl-gnutls and...
> > couldn't... How did you manage that ? Is the server you were trying on
> > public ? Do you have any http.ssl* variables set in your configuration ?
> 
> No, my test repo is not public. I have no special ssl configuration
> (though I do use GIT_SSL_NO_VERIFY=1 since I just had a test self-signed
> cert). The exact recipe on my Debian system is:
> 
(...)

Okay, I've been able to reproduce the problem. I don't know what I've been doing wrong to have it hidden...

Anyways, the interesting thing is to look at what curl has to say in its verbose mode:

GIT_CURL_VERBOSE=1 git fetch
* Couldn't find host localhost in the .netrc file, using defaults
* About to connect() to localhost port 8443 (#0)
*   Trying 127.0.0.1... * connected
* Connected to localhost (127.0.0.1) port 8443 (#0)
* found 102 certificates in /etc/ssl/certs/ca-certificates.crt
*        server certificate verification FAILED
*        common name: localhost (matched)
*        server certificate expiration date OK
*        server certificate activation date OK
*        certificate public key: RSA
*        certificate version: #1
*        subject: C=GB,ST=Some-State,L=Some-Locality,O=One Organization,OU=One Organization Unit,CN=localhost,EMAIL=webmaster@localhost
*        start date: Thu, 07 Feb 2008 21:27:36 GMT
*        expire date: Sat, 08 Mar 2008 21:27:36 GMT
*        issuer: C=GB,ST=Some-State,L=Some-Locality,O=One Organization,OU=One Organization Unit,CN=localhost,EMAIL=webmaster@localhost
*        compression: DEFLATE
*        cipher: AES 256 CBC
*        MAC: SHA
> GET /foo/.git//info/refs HTTP/1.1
User-Agent: git/1.5.4.7.gd8534-dirty
Host: localhost:8443
Accept: */*
< HTTP/1.1 200 OK
< Date: Fri, 08 Feb 2008 07:10:09 GMT
< Server: Apache/2.2.8 (Debian) DAV/2 mod_ssl/2.2.8 OpenSSL/0.9.8g
< Last-Modified: Fri, 08 Feb 2008 06:52:19 GMT
< ETag: "61d82e-3b-445a0080d0ec0"
< Accept-Ranges: bytes
< Content-Length: 59
< Content-Type: text/plain
< 
* Connection #0 to host localhost left intact
* Couldn't find host localhost in the .netrc file, using defaults
* About to connect() to localhost port 8443 (#0)
*   Trying 127.0.0.1... * connected
* Connected to localhost (127.0.0.1) port 8443 (#0)
* error reading ca cert file /etc/ssl/certs/ca-certificates.crt (ASN1 parser: Element was not found.)
* gnutls_handshake() failed: ASN1 parser: Element was not found.
* Expire cleared
* Closing connection #0
error: gnutls_handshake() failed: ASN1 parser: Element was not found. (curl_result = 35, http_code = 0, sha1 = e0aa43ffb1a1e7052a936b9ed5e0a1462cfc343e)
Getting pack list for https://localhost:8443/foo/.git

So, it looks like either gnutls or curl is doing something wrong and can't parse /etc/ssl/certs/ca-certificates.crt a second time. This looks like a bug in either curl or gnutls.

A simplified testcase would probably be to do two requests in a row, but I don't have time right now to do this testing.

Mike
Previous: Jeff KingNext: Mike Hommey
Message 13 of 44 in “git-fetch in 1.5.4 fails versus 1.5.3.8”
  1. Anand KumriaFeb 4, 2008
  2. Jeff KingFeb 5, 2008
  3. Jari AaltoFeb 5, 2008
  4. Anand KumriaFeb 6, 2008
  5. Jeff KingFeb 7, 2008
  6. Mike HommeyFeb 7, 2008
  7. Anand KumriaFeb 7, 2008
  8. Jeff KingFeb 7, 2008
  9. Mike HommeyFeb 7, 2008
  10. Jeff KingFeb 7, 2008
  11. Mike HommeyFeb 7, 2008
  12. Jeff KingFeb 8, 2008
  13. Mike HommeyFeb 8, 2008
  14. Mike HommeyFeb 8, 2008
  15. Work around curl-gnutls not liking to be reinitializedMike Hommey, Feb 8, 2008
  16. Mike HommeyFeb 8, 2008
  17. Junio C HamanoFeb 8, 2008
  18. Mike HommeyFeb 8, 2008
  19. Mike HommeyFeb 8, 2008
  20. Work around curl-gnutls not liking to be reinitializedMike Hommey, Feb 8, 2008
  21. Johannes SchindelinFeb 8, 2008
  22. Work around curl-gnutls not liking to be reinitializedMike Hommey, Feb 8, 2008
  23. Mike HommeyFeb 8, 2008
  24. Work around curl-gnutls not liking to be reinitializedMike Hommey, Feb 9, 2008
  25. Daniel StenbergFeb 9, 2008
  26. Florian WeimerFeb 9, 2008
  27. Mike HommeyFeb 9, 2008
  28. Johannes SchindelinFeb 8, 2008
  29. Mike HommeyFeb 8, 2008
  30. Jeff KingFeb 9, 2008
  31. Frank LichtenheldFeb 7, 2008
  32. Linus TorvaldsFeb 7, 2008
  33. Frank LichtenheldFeb 7, 2008
  34. Linus TorvaldsFeb 7, 2008
  35. Anand KumriaFeb 7, 2008
  36. Jeff KingFeb 7, 2008
  37. Linus TorvaldsFeb 7, 2008
  38. Martin LanghoffFeb 7, 2008
  39. Dmitry PotapovFeb 7, 2008
  40. Jeff KingFeb 7, 2008
  41. Jeff KingFeb 7, 2008
  42. Dmitry PotapovFeb 7, 2008
  43. Anand KumriaFeb 8, 2008
  44. Dmitry PotapovFeb 8, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.