Re: t5563-simple-http-auth failures with v2.55.0-rc0
- From
Todd Zullinger <tmz@pobox.com>
- Date
- Jun 12, 2026, 18:02 UTC
- Message-ID
- <20260612180203.s2qSgDUs@teonanacatl.net>
- In-Reply-To
- <VI0PR03MB1163416D5C66FAB25AECAAE21C0182@VI0PR03MB11634.eurprd03.prod.outlook.com>
Hi,
Matthew John Cheetham wrote:
Show 15 quoted lines
> On 2026-06-11 22:04, Todd Zullinger wrote:
>> I notice that Fedora 44 (where the tests all pass) has
>> curl-8.18.0 while Fedora 45 has curl-8.21.0-rc2. The
>> version of httpd is the same between them, FWIW. I didn't
>> compare other package differences; it could be something
>> else entirely.
>
> Thanks for the report. The failure is not in Git, it is a libcurl
> behaviour change, and there is already an open upstream issue:
>
> https://github.com/curl/curl/issues/21943
> "Negotiate ignored with --anyauth" (Dan Fandrich, 2026-06-10)
>
> Dan also bisected it to the same commit I had locally,
> `8f71d0fde515` ("creds: hold credentials", curl PR #21548).[...]
> Daniel Stenberg has acknowledged the curl issue but has not yet > posted a fix. I will follow curl#21943 and, if the upstream answer > is "the new behaviour is intended", come back here with a proposal > for what Git should do about `http.emptyAuth` and test 18.
Excellent. This is it good hands all around.
With luck, curl is updated and the canary of distributions like Fedora's Rawhide will have served a useful purpose in flushing out issues before they affect most people. With the help of git's excellent and thorough test suite, of course. :)
If there is a curl update, I imagine it will be picked up reasonably quickly in Fedora (and elsewhere that was testing 8.21.0 release candidates) and there will hopefully be no strong need to make any changes on the git side.
Thanks!
-- Todd