git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 2/5] http: correct curl version check for CURLOPT_PINNEDPUBLICKEY

From
Ævar Arnfjörð Bjarmason <avarab@gmail.com>
Date
Sep 10, 2021, 14:37 UTC
Message-ID
<87tuiscwso.fsf@evledraar.gmail.com>
In-Reply-To
<YTtpWADzTJEAIvk+@coredump.intra.peff.net>
On Fri, Sep 10 2021, Jeff King wrote:
Show 24 quoted lines
> On Thu, Sep 09, 2021 at 04:12:26PM -0700, Junio C Hamano wrote:
>
>> > But in terms of compiling, all we care about is that the constant is
>> > there. So I think the cutoff point you found is what we want. Presumably
>> > when the file format isn't supported we'd get some error, though it's
>> > not clear if that would come during the actual curl_*_perform(), or if
>> > we should be checking the curl_easy_setopt() result.
>> 
>> If we were evaluating a patch to add support for pinnedpublickey
>> afresh back in, say, 2017, perhaps we cared enough about the
>> distinction between 7.39 and 7.44 (Nov 2014 and Aug 2015,
>> respectively), but I'd say cut-off at 7.44 for this, once it is
>> written and committed in our codebase, is good enough for us.
>> 
>> If the code originally had cut-off at 7.39 and we were raising the
>> floor to 7.44 with "sha256 weren't usable before that version" as
>> the justification, it would be a totally different situation and it
>> may be worth the code change, but I am not sure if going backwards
>> is worth it.
>> 
>> So, I dunno.
>
> I don't have a sense of whether the functionality difference between
> 7.39 and 7.44 actually matters.

For what it's worth I tested this as part of re-rolling, i.e. I grabbed the tarball for 7.39[1].

By using the correct version number of 7.39 we'll support pinned public keys there, but if you supply e.g. the "sha256/[...]" format we'll instead of printing a warning about this version not supporting pinned keys, we'll die with an error from curl itself.

I think whatever happens with 7.39..7.44 doesn't matter much, but this does seem like more useful behavior, and we avoid the oddity of hardcoding the "wrong" version (until you start looking more into it, that is...).

Aside from 7.39..7.44 though it does seem like a really bad thing to do to just warn that we don't support pinned public keys, but proceed with the request anyway (which could also be a push).

I don't think it's worth changing that s/warning/die/g now, since the target audience for a new git release with such an ancient curl version is probably zero, or near enough to be zero.

I mean, we do have new git + old OS, but it tends to be *specific* old versions, namely for releases of this age the one released with RHEL. I think pretty nobody else does that (the rest are probably all RHEL-derived). Per 013c7e2b070 (http: drop support for curl < 7.16.0, 2021-07-30) none of the RHEL out there have a curl in the 7.39..7.44 range.

The commit doesn't note the RHEL 8 version (which b.t.w., is something I added to it, not you), but it seems to be 7.61.1[2]. So at least as far as RHEL goes we'll never be stuck in the 7.39..7.44 range..

1. protip: curl.git git tags are rather useless, since (at least for old
   versions) the embedded version number is bumped sometime *after* the
   release).
   I also ran "diff -ru" on at least one old tag/tarball (I forget
   which) and there were a lot of changes (and not just some "make dist"
   stuff like autoconf files, version numbers or whatever).
   So in testing this I stopped using curl.git for anything but "git log
   -G<str>" searching and the like, and just tested with archived
   release tarballs.
2. https://access.redhat.com/solutions/4174711
Previous: Jeff KingNext: Jeff King
Message 90 of 162 in “dropping support for older curl”
  1. 0/4 dropping support for older curlJeff King, Aug 9, 2017
  2. 1/4 http: drop support for curl < 7.11.1Jeff King, Aug 9, 2017
  3. 2/4 http: drop support for curl < 7.16.0Jeff King, Aug 9, 2017
  4. Stefan BellerAug 9, 2017
  5. Jeff KingAug 9, 2017
  6. Junio C HamanoAug 9, 2017
  7. Nicolas Morey-ChaisemartinAug 9, 2017
  8. Jeff KingAug 9, 2017
  9. Nicolas Morey-ChaisemartinAug 9, 2017
  10. Jeff KingAug 9, 2017
  11. Jeff KingAug 9, 2017
  12. 3/4 http: drop support for curl < 7.19.4Jeff King, Aug 9, 2017
  13. Ævar Arnfjörð BjarmasonAug 9, 2017
  14. Jeff KingAug 9, 2017
  15. 5/4 curl: remove ifdef'd code never used with curl >=7.19.4Ævar Arnfjörð Bjarmason, Aug 9, 2017
  16. Stefan BellerAug 9, 2017
  17. Jeff KingAug 9, 2017
  18. Mischa POSLAWSKYAug 10, 2017
  19. Jeff KingAug 10, 2017
  20. 4/4 http: #error on too-old curlJeff King, Aug 9, 2017
  21. Stefan BellerAug 9, 2017
  22. Johannes SchindelinAug 9, 2017
  23. Jeff KingAug 9, 2017
  24. Johannes SchindelinAug 10, 2017
  25. Jeff KingAug 10, 2017
  26. Junio C HamanoAug 10, 2017
  27. Jeff KingAug 10, 2017
  28. Jeff KingAug 11, 2017
  29. Tom G. ChristensenAug 10, 2017
  30. Jeff KingAug 10, 2017
  31. Tom G. ChristensenAug 10, 2017
  32. Jeff KingAug 10, 2017
  33. Tom G. ChristensenAug 10, 2017
  34. Jeff KingAug 10, 2017
  35. Tom G. ChristensenAug 10, 2017
  36. Tom G. ChristensenAug 10, 2017
  37. Ævar Arnfjörð BjarmasonAug 9, 2017
  38. 0/5 drop support for ancient curlÆvar Arnfjörð Bjarmason, Jul 21, 2021
  39. 1/5 http: drop support for curl < 7.11.1Ævar Arnfjörð Bjarmason, Jul 21, 2021
  40. Junio C HamanoJul 21, 2021
  41. 2/5 http: drop support for curl < 7.16.0Ævar Arnfjörð Bjarmason, Jul 21, 2021
  42. 3/5 http: drop support for curl < 7.19.4Ævar Arnfjörð Bjarmason, Jul 21, 2021
  43. Junio C HamanoJul 21, 2021
  44. 4/5 http: drop support for curl < 7.19.3 and < 7.16.4 (again)Ævar Arnfjörð Bjarmason, Jul 21, 2021
  45. Junio C HamanoJul 21, 2021
  46. 5/5 http: rename CURLOPT_FILE to CURLOPT_WRITEDATAÆvar Arnfjörð Bjarmason, Jul 21, 2021
  47. Junio C HamanoJul 21, 2021
  48. Junio C HamanoJul 21, 2021
  49. brian m. carlsonJul 21, 2021
  50. Ævar Arnfjörð BjarmasonJul 22, 2021
  51. brian m. carlsonJul 22, 2021
  52. Ævar Arnfjörð BjarmasonJul 23, 2021
  53. Bagas SanjayaJul 22, 2021
  54. Jeff KingJul 23, 2021
  55. Junio C HamanoJul 23, 2021
  56. Randall S. BeckerJul 23, 2021
  57. Jeff KingJul 24, 2021
  58. 0/7 drop support for ancient curl, improve version checksÆvar Arnfjörð Bjarmason, Jul 30, 2021
  59. 1/7 http: drop support for curl < 7.11.1Ævar Arnfjörð Bjarmason, Jul 30, 2021
  60. 2/7 http: drop support for curl < 7.16.0Ævar Arnfjörð Bjarmason, Jul 30, 2021
  61. 3/7 http: drop support for curl < 7.19.4Ævar Arnfjörð Bjarmason, Jul 30, 2021
  62. 5/7 http: drop support for curl < 7.18.0 (again)Ævar Arnfjörð Bjarmason, Jul 30, 2021
  63. Junio C HamanoJul 30, 2021
  64. 4/7 http: drop support for curl < 7.19.3 and <= 7.16.4 (or <7.17.0) (again)Ævar Arnfjörð Bjarmason, Jul 30, 2021
  65. Junio C HamanoJul 30, 2021
  66. 6/7 http: rename CURLOPT_FILE to CURLOPT_WRITEDATAÆvar Arnfjörð Bjarmason, Jul 30, 2021
  67. 7/7 http: centralize the accounting of libcurl dependenciesÆvar Arnfjörð Bjarmason, Jul 30, 2021
  68. Junio C HamanoJul 30, 2021
  69. 0/5 drop support for ancient curlÆvar Arnfjörð Bjarmason, Jul 30, 2021
  70. 1/5 http: drop support for curl < 7.11.1Ævar Arnfjörð Bjarmason, Jul 30, 2021
  71. 2/5 http: drop support for curl < 7.16.0Ævar Arnfjörð Bjarmason, Jul 30, 2021
  72. Andrei RybakSep 10, 2021
  73. Jeff KingSep 11, 2021
  74. Junio C HamanoSep 11, 2021
  75. Jeff KingSep 11, 2021
  76. 3/5 http: drop support for curl < 7.19.4Ævar Arnfjörð Bjarmason, Jul 30, 2021
  77. 4/5 http: drop support for curl < 7.19.3 and < 7.17.0 (again)Ævar Arnfjörð Bjarmason, Jul 30, 2021
  78. 5/5 http: rename CURLOPT_FILE to CURLOPT_WRITEDATAÆvar Arnfjörð Bjarmason, Jul 30, 2021
  79. Junio C HamanoJul 30, 2021
  80. Junio C HamanoJul 30, 2021
  81. Junio C HamanoJul 30, 2021
  82. 0/5 post-v2.33 "drop support for ancient curl" follow-upÆvar Arnfjörð Bjarmason, Sep 8, 2021
  83. 1/5 http: drop support for curl < 7.18.0 (again)Ævar Arnfjörð Bjarmason, Sep 8, 2021
  84. Junio C HamanoSep 9, 2021
  85. 2/5 http: correct curl version check for CURLOPT_PINNEDPUBLICKEYÆvar Arnfjörð Bjarmason, Sep 8, 2021
  86. Jeff KingSep 8, 2021
  87. Junio C HamanoSep 9, 2021
  88. Jeff KingSep 10, 2021
  89. Jeff KingSep 10, 2021
  90. Ævar Arnfjörð BjarmasonSep 10, 2021
  91. Jeff KingSep 10, 2021
  92. Daniel StenbergSep 10, 2021
  93. Ævar Arnfjörð BjarmasonSep 10, 2021
  94. Daniel StenbergSep 10, 2021
  95. 3/5 http: correct version check for CURL_HTTP_VERSION_2_0Ævar Arnfjörð Bjarmason, Sep 8, 2021
  96. Jeff KingSep 8, 2021
  97. 4/5 http: centralize the accounting of libcurl dependenciesÆvar Arnfjörð Bjarmason, Sep 8, 2021
  98. Jeff KingSep 8, 2021
  99. Junio C HamanoSep 9, 2021
  100. Jeff KingSep 9, 2021
  101. 5/5 http: don't hardcode the value of CURL_SOCKOPT_OKÆvar Arnfjörð Bjarmason, Sep 8, 2021
  102. Junio C HamanoSep 9, 2021
  103. Junio C HamanoSep 9, 2021
  104. Jeff KingSep 8, 2021
  105. 0/8 post-v2.33 "drop support for ancient curl" follow-upÆvar Arnfjörð Bjarmason, Sep 10, 2021
  106. 1/8 INSTALL: don't mention the "curl" executable at allÆvar Arnfjörð Bjarmason, Sep 10, 2021
  107. Jeff KingSep 10, 2021
  108. 2/8 INSTALL: mention that we need libcurl 7.19.4 or newer to buildÆvar Arnfjörð Bjarmason, Sep 10, 2021
  109. Jeff KingSep 10, 2021
  110. Junio C HamanoSep 10, 2021
  111. Jeff KingSep 10, 2021
  112. 3/8 Makefile: drop support for curl < 7.9.8 (again)Ævar Arnfjörð Bjarmason, Sep 10, 2021
  113. Jeff KingSep 10, 2021
  114. 4/8 http: drop support for curl < 7.18.0 (again)Ævar Arnfjörð Bjarmason, Sep 10, 2021
  115. 5/8 http: correct version check for CURL_HTTP_VERSION_2Ævar Arnfjörð Bjarmason, Sep 10, 2021
  116. Jeff KingSep 10, 2021
  117. Daniel StenbergSep 10, 2021
  118. Jeff KingSep 10, 2021
  119. Ævar Arnfjörð BjarmasonSep 10, 2021
  120. 6/8 http: correct curl version check for CURLOPT_PINNEDPUBLICKEYÆvar Arnfjörð Bjarmason, Sep 10, 2021
  121. Junio C HamanoSep 10, 2021
  122. 7/8 http: centralize the accounting of libcurl dependenciesÆvar Arnfjörð Bjarmason, Sep 10, 2021
  123. Jeff KingSep 10, 2021
  124. 8/8 http: don't hardcode the value of CURL_SOCKOPT_OKÆvar Arnfjörð Bjarmason, Sep 10, 2021
  125. Jeff KingSep 10, 2021
  126. Jeff KingSep 10, 2021
  127. Ævar Arnfjörð BjarmasonSep 10, 2021
  128. Jeff KingSep 10, 2021
  129. Junio C HamanoSep 10, 2021
  130. Randall S. BeckerSep 10, 2021
  131. Ævar Arnfjörð BjarmasonSep 10, 2021
  132. Junio C HamanoSep 10, 2021
  133. Junio C HamanoSep 10, 2021
  134. Konstantin RyabitsevSep 10, 2021
  135. Junio C HamanoSep 10, 2021
  136. Ævar Arnfjörð BjarmasonSep 10, 2021
  137. 0/9 post-v2.33 "drop support for ancient curl" follow-upÆvar Arnfjörð Bjarmason, Sep 11, 2021
  138. 1/9 INSTALL: don't mention the "curl" executable at allÆvar Arnfjörð Bjarmason, Sep 11, 2021
  139. 2/9 INSTALL: reword and copy-edit the "libcurl" sectionÆvar Arnfjörð Bjarmason, Sep 11, 2021
  140. 3/9 INSTALL: mention that we need libcurl 7.19.4 or newer to buildÆvar Arnfjörð Bjarmason, Sep 11, 2021
  141. 4/9 Makefile: drop support for curl < 7.9.8 (again)Ævar Arnfjörð Bjarmason, Sep 11, 2021
  142. 5/9 http: drop support for curl < 7.18.0 (again)Ævar Arnfjörð Bjarmason, Sep 11, 2021
  143. 6/9 http: correct version check for CURL_HTTP_VERSION_2Ævar Arnfjörð Bjarmason, Sep 11, 2021
  144. 7/9 http: correct curl version check for CURLOPT_PINNEDPUBLICKEYÆvar Arnfjörð Bjarmason, Sep 11, 2021
  145. 8/9 http: centralize the accounting of libcurl dependenciesÆvar Arnfjörð Bjarmason, Sep 11, 2021
  146. 9/9 http: don't hardcode the value of CURL_SOCKOPT_OKÆvar Arnfjörð Bjarmason, Sep 11, 2021
  147. Jeff KingSep 11, 2021
  148. Junio C HamanoSep 12, 2021
  149. 0/9 post-v2.33 "drop support for ancient curl" follow-upÆvar Arnfjörð Bjarmason, Sep 13, 2021
  150. 1/9 INSTALL: don't mention the "curl" executable at allÆvar Arnfjörð Bjarmason, Sep 13, 2021
  151. 2/9 INSTALL: reword and copy-edit the "libcurl" sectionÆvar Arnfjörð Bjarmason, Sep 13, 2021
  152. 3/9 INSTALL: mention that we need libcurl 7.19.4 or newer to buildÆvar Arnfjörð Bjarmason, Sep 13, 2021
  153. 7/9 http: correct curl version check for CURLOPT_PINNEDPUBLICKEYÆvar Arnfjörð Bjarmason, Sep 13, 2021
  154. 6/9 http: correct version check for CURL_HTTP_VERSION_2Ævar Arnfjörð Bjarmason, Sep 13, 2021
  155. 4/9 Makefile: drop support for curl < 7.9.8 (again)Ævar Arnfjörð Bjarmason, Sep 13, 2021
  156. 5/9 http: drop support for curl < 7.18.0 (again)Ævar Arnfjörð Bjarmason, Sep 13, 2021
  157. 8/9 http: centralize the accounting of libcurl dependenciesÆvar Arnfjörð Bjarmason, Sep 13, 2021
  158. 9/9 http: don't hardcode the value of CURL_SOCKOPT_OKÆvar Arnfjörð Bjarmason, Sep 13, 2021
  159. Jeff KingSep 13, 2021
  160. Junio C HamanoSep 13, 2021
  161. Tom G. ChristensenAug 10, 2017
  162. Johannes SchindelinAug 14, 2017

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.