git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[BUG] credential wildcard does not match hostnames containing an underscore

From
AWAlex Waite <alex@waite.eu>
Date
Oct 12, 2021, 14:25 UTC
Message-ID
<28ff3572-1819-4e27-a46d-358eddd46e45@www.fastmail.com>
Hey Everyone,
This is my first time reporting a bug to this list. I attempted to follow the direction on the git website [1], and have followed the template provided by "git bugreport".
If my report should be formatted differently, or reported elsewhere, please let me know. :-)
---Alex
[1] https://git-scm.com/community
-------
What did you do before the bug happened? (Steps to reproduce your issue)
  I configured my ~/.gitconfig so that git credentials invoke a helper for a
  subdomain using wildcards. For example:
  [credential "https://*.example.com"]
          helper = "/usr/local/bin/custom_helper"
  This works for all tested subdomains /except/ for those which contain an
  underscore.
  authenticates without prompting:
    git clone https://testA.example.com
    git clone https://test-b.example.com
  prompts for authentication:
    git clone https://test_c.example.com
What did you expect to happen? (Expected behavior)
  I expected the pattern matching to work for all resolved URLs.
What happened instead? (Actual behavior)
  It does not match URLs which contain an underscore.
What's different between what you expected and what actually happened?
  It only matches URLs which do not contain an underscore.
Anything else you want to add:
  If I don't use pattern matching, and instead state the URL explicitly in
  ~/.gitconfig, it works as expected. For example, the following works:
  [credential "https://test_c.example.com"]
          helper = "/usr/local/bin/custom_helper"
  As part of writing this bug report, I learned that underscores are not valid
  DNS characters for hostnames (but are valid for other record types, which are
  largely irrelevant to git).
  What is notable is that git pattern matching enforces the spec more strictly
  than without pattern matching (and more strictly than the OS and every DNS
  server between my system and the authoritative DNS server).
  At minimum, git should be consistent with itself.
  As for which behavior is "correct", the question is whether git wishes to
  follow/enforce the spec tightly, or not get in the way of a real-world oddity
  that everything else seems to tolerate.
  This also likely affects patterns for http.<url>.*
  https://git-scm.com/docs/git-config#Documentation/git-config.txt-httplturlgt
Next: Junio C Hamano
Message 1 of 17 in “[BUG] credential wildcard does not match hostnames containing an underscore”
  1. Alex WaiteOct 12, 2021
  2. Junio C HamanoOct 12, 2021
  3. Alex WaiteOct 12, 2021
  4. Junio C HamanoOct 12, 2021
  5. Jeff KingOct 12, 2021
  6. Jeff KingOct 12, 2021
  7. Jeff KingOct 12, 2021
  8. urlmatch: add underscore to URL_HOST_CHARSJeff King, Oct 12, 2021
  9. brian m. carlsonOct 12, 2021
  10. Jeff KingOct 12, 2021
  11. brian m. carlsonOct 12, 2021
  12. Jeff KingOct 12, 2021
  13. brian m. carlsonOct 12, 2021
  14. Aaron SchrabOct 12, 2021
  15. Alex WaiteOct 13, 2021
  16. Philip OakleyOct 14, 2021
  17. brian m. carlsonOct 12, 2021

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.