git/list[1] front-page[2] threads[3] people[4] search[5] about
 

GSS-Negotiate authentication requires that all data fit into postbuffer

From
brian m. carlson <sandals@crustytoothpaste.net>
Date
Oct 6, 2013, 00:42 UTC
Message-ID
<20131006004236.GB3460@vauxhall.crustytoothpaste.net>

One thing I just noticed is that if git is using GSS-Negotiate authentication, the entire POST contents have to fit into however much memory is specified by http.postbuffer:

  vauxhall ok % git push https://bmc@git.crustytoothpaste.net/git/bmc/test.git development
  Counting objects: 37994, done.
  Delta compression using up to 4 threads.
  Compressing objects: 100% (10683/10683), done.
  Writing objects: 100% (37994/37994), 9.15 MiB | 4.45 MiB/s, done.
  Total 37994 (delta 26760), reused 37633 (delta 26467)
  Unable to rewind rpc post data - try increasing http.postBuffer
  Password for 'https://bmc@git.crustytoothpaste.net': 
GSS-Negotiate authentication always requires a rewind with CURL.

The remote in question only supports Negotiate authentication, so prompting for a password in this case isn't going to help. I'm probably going to look into this over the next couple of days, but two things need to be done here: 1) do not prompt for a password if only Negotiate authentication is requested, since it just won't work, and 2) recreate the data as needed if we have to rewind, since otherwise pushing a fresh copy of the Linux kernel repo simply isn't going to work as the buffer will have to be too large. An alternative is to send a small amount of data, smaller than the postbuffer, in the first chunk and only fail to rewind if the second or subsequent chunks need rewinding.

-- 
brian m. carlson / brian with sandals: Houston, Texas, US
+1 832 623 2791 | http://www.crustytoothpaste.net/~bmc | My opinion only
OpenPGP: RSA v4 4096b: 88AC E9B2 9196 305B A994 7552 F1BA 225C 0223 B187
Next: Ilari Liusvaara
Message 1 of 8 in “GSS-Negotiate authentication requires that all data fit into postbuffer”
  1. brian m. carlsonOct 6, 2013
  2. Ilari LiusvaaraOct 6, 2013
  3. Daniel StenbergOct 6, 2013
  4. brian m. carlsonOct 6, 2013
  5. Daniel StenbergOct 6, 2013
  6. brian m. carlsonOct 6, 2013
  7. Jeff KingOct 7, 2013
  8. brian m. carlsonOct 7, 2013

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.