From: Jeff King Date: Fri, 11 Sep 2020 13:59:28 GMT Subject: Re: Git doesn't honor NO_PROXY environment variable while cloning Message-ID: <20200911135928.GA1986935@coredump.intra.peff.net> In-Reply-To: [tl;dr This looks to me like a problem in libcurl. I've included my whole line of reasoning below. Folks interested in libcurl might want to jump straight to the backtrace]. On Fri, Sep 11, 2020 at 02:15:59PM +0200, Ondrej Pohorelsky wrote: > we've got a bug[0] reported in Red Hat Bugzilla. It seems like Git > doesn't honor NO_PROXY environment variable while cloning repositories It's not so much "doesn't honor NO_PROXY" as "NO_PROXY seems to trigger another bug". Here's a slightly simplified recipe: [set up our bogus proxy] $ export HTTPS_PROXY=https://user:pass@bad.proxy [so far so good; we expect this to complain about the proxy] $ git clone https://github.com/git/git Cloning into 'git'... fatal: unable to access 'https://github.com/git/git/': Could not resolve proxy: bad.proxy [now let's set NO_PROXY] $ export NO_PROXY=github.com $ git clone https://github.com/git/git Cloning into 'git'... $ echo $? 128 So we are looking at the variable, but then we exit with failure (and with nothing to stderr!). That was with v2.28 above. But let's try it with the current tip of master: $ git clone https://github.com/git/git Cloning into 'git'... error: git-remote-https died of signal 11 Ah, that's interesting. The switch in behavior is due to 675df192c5 (transport-helper: do not run git-remote-ext etc. in dashed form, 2020-08-26). Before that patch the transport code ran git-remote-https directly. If it returned a non-zero exit code, we just assumed it had printed its own error to stdout and exited. But after that patch we run "git remote-https", and the git.c wrapper has code to complain about segfaults. So that's a little digression from our real bug. But it points us in the right direction: remote-https is segfaulting. So here's a more direct reproduction: export HTTPS_PROXY=https://user:pass@bad.proxy export NO_PROXY=github.com echo list | ./git-remote-https https://github.com/git/git which results in a segfault. And we can run that process under gdb to get a backtrace: echo list >input gdb -ex 'set args https://github.com/git/git