git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: t5563-simple-http-auth failures with v2.55.0-rc0

From
Matthew John Cheetham <mjcheetham@outlook.com>
Date
Jun 12, 2026, 15:42 UTC
Message-ID
<VI0PR03MB1163416D5C66FAB25AECAAE21C0182@VI0PR03MB11634.eurprd03.prod.outlook.com>
In-Reply-To
<20260611210456.XYfhytSL@teonanacatl.net>
On 2026-06-11 22:04, Todd Zullinger wrote:
Show 13 quoted lines
> Hi,
> 
> I tested the freshly-tagged 2.55.0-rc0 and noticed some new
> failures on the in-progress Fedora 45 (AKA Rawhide) for
> t5563.18 (http.emptyAuth=auto attempts Negotiate before
> credential_fill) which was added in 9b1630b972 (t5563: add
> tests for http.emptyAuth with Negotiate, 2026-04-16).
> 
> I notice that Fedora 44 (where the tests all pass) has
> curl-8.18.0 while Fedora 45 has curl-8.21.0-rc2.  The
> version of httpd is the same between them, FWIW.  I didn't
> compare other package differences; it could be something
> else entirely.

Thanks for the report. The failure is not in Git, it is a libcurl behaviour change, and there is already an open upstream issue:

   https://github.com/curl/curl/issues/21943
   "Negotiate ignored with --anyauth" (Dan Fandrich, 2026-06-10)

Dan also bisected it to the same commit I had locally, `8f71d0fde515` ("creds: hold credentials", curl PR #21548).

His report describes the regression at the `curl(1)` level (`curl --anyauth -u : ...` no longer attempts Negotiate); t5563 test 18 is the same regression observed through `http.emptyAuth=auto`, which under the hood is the same `CURLOPT_USERPWD=":"` pattern.

Dan also notes a workaround: replacing `-u :` with `-u literally:anything` (any non-blank username, real or fake) puts libcurl back on the Negotiate path. That suggests a small Git-side escape hatch is possible if we want to unblock people running against current libcurl while we wait for an upstream fix; I have not tried it yet and would want to be sure it does not have side effects on other auth schemes before proposing it.

Daniel Stenberg has acknowledged the curl issue but has not yet posted a fix. I will follow curl#21943 and, if the upstream answer is "the new behaviour is intended", come back here with a proposal for what Git should do about `http.emptyAuth` and test 18.

Thanks, Matthew

Previous: Todd ZullingerNext: Todd Zullinger
Message 2 of 6 in “t5563-simple-http-auth failures with v2.55.0-rc0”
  1. Todd ZullingerJun 11, 2026
  2. Matthew John CheethamJun 12, 2026
  3. Todd ZullingerJun 12, 2026
  4. Todd ZullingerJun 18, 2026
  5. Matthew John CheethamJun 18, 2026
  6. Junio C HamanoJun 18, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.