git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH/RFC] http_init: only initialize SSL for https

From
Erik Faye-Lund <kusmabite@gmail.com>
Date
Mar 18, 2013, 10:38 UTC
Message-ID
<CABPQNSasFV-vZSMygu16xc-C2d3jTt7mtzFsYQyNUhS5jL-EoQ@mail.gmail.com>
In-Reply-To
<7vli9lpsqe.fsf@alter.siamese.dyndns.org>
On Sun, Mar 17, 2013 at 11:27 PM, Junio C Hamano <gitster@pobox.com> wrote:
Show 33 quoted lines
> Daniel Stenberg <daniel@haxx.se> writes:
>
>> On Sun, 17 Mar 2013, Antoine Pelisse wrote:
>>
>>>> With redirects taken into account, I can't think of any really good way
>>>> around avoiding this init...
>>>
>>> Is there any way for curl to initialize SSL on-demand ?
>>
>> Yes, but not without drawbacks.
>>
>> If you don't call curl_global_init() at all, libcurl will notice that
>> on first use and then libcurl will call global_init by itself with a
>> default bitmask.
>>
>> That automatic call of course will prevent the application from being
>> able to set its own bitmask choice, and also the global_init function
>> is not (necessarily) thread safe while all other libcurl functions are
>> so the internal call to global_init from an otherwise thread-safe
>> function is unfortunate.
>
> So in short, unless you are writing a custom application to talk to
> servers that you know will never redirect you to HTTPS, passing
> custom masks such as ALL&~SSL to global-init is not going to be a
> valid optimization.
>
> I think that is a reasonable API; your custom application may want
> to go around your intranet servers all of which serve their status
> over plain HTTP, and it is a valid optimization to initialize the
> library with ALL&~SSL.  It is just that such an optimization does
> not apply to us---we let our users go to random hosts we have no
> control over, and they may redirect us in ways we cannot anticipate.
>

I wonder. Our libcurl is build with "-winssl" (USE_WINDOWS_SSPI=1), it seems. Perhaps switching to openssl (which we already have libraries for) would make the init-time better?

-- 
-- 
*** Please reply-to-all at all times ***
*** (do not pretend to know who is subscribed and who is not) ***
*** Please avoid top-posting. ***
The msysGit Wiki is here: https://github.com/msysgit/msysgit/wiki - Github accounts are free.

You received this message because you are subscribed to the Google
Groups "msysGit" group.
To post to this group, send email to msysgit@googlegroups.com
To unsubscribe from this group, send email to
msysgit+unsubscribe@googlegroups.com
For more options, and view previous threads, visit this group at
http://groups.google.com/group/msysgit?hl=en_US?hl=en

--- 
You received this message because you are subscribed to the Google Groups "msysGit" group.
To unsubscribe from this group and stop receiving emails from it, send an email to msysgit+unsubscribe@googlegroups.com.
For more options, visit https://groups.google.com/groups/opt_out.
Previous: Junio C HamanoNext: Erik Faye-Lund
Message 17 of 21 in “http_init: only initialize SSL for https”
  1. http_init: only initialize SSL for httpsErik Faye-Lund, Mar 14, 2013
  2. Erik Faye-LundMar 14, 2013
  3. Johannes SchindelinMar 14, 2013
  4. Erik Faye-LundMar 14, 2013
  5. Junio C HamanoMar 14, 2013
  6. Johannes SchindelinMar 14, 2013
  7. Junio C HamanoMar 14, 2013
  8. Erik Faye-LundMar 14, 2013
  9. Daniel StenbergMar 15, 2013
  10. Junio C HamanoMar 15, 2013
  11. Daniel StenbergMar 15, 2013
  12. Jeff KingMar 16, 2013
  13. Daniel StenbergMar 16, 2013
  14. Antoine PelisseMar 17, 2013
  15. Daniel StenbergMar 17, 2013
  16. Junio C HamanoMar 17, 2013
  17. Erik Faye-LundMar 18, 2013
  18. Erik Faye-LundMar 18, 2013
  19. Junio C HamanoMar 14, 2013
  20. Johannes SchindelinMar 14, 2013
  21. Junio C HamanoMar 14, 2013

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.