Re: t5563-simple-http-auth failures with v2.55.0-rc0
- From
Matthew John Cheetham <mjcheetham@outlook.com>
- Date
- Jun 12, 2026, 15:42 UTC
- Message-ID
- <VI0PR03MB1163416D5C66FAB25AECAAE21C0182@VI0PR03MB11634.eurprd03.prod.outlook.com>
- In-Reply-To
- <20260611210456.XYfhytSL@teonanacatl.net>
On 2026-06-11 22:04, Todd Zullinger wrote:
Show 13 quoted lines
> Hi, > > I tested the freshly-tagged 2.55.0-rc0 and noticed some new > failures on the in-progress Fedora 45 (AKA Rawhide) for > t5563.18 (http.emptyAuth=auto attempts Negotiate before > credential_fill) which was added in 9b1630b972 (t5563: add > tests for http.emptyAuth with Negotiate, 2026-04-16). > > I notice that Fedora 44 (where the tests all pass) has > curl-8.18.0 while Fedora 45 has curl-8.21.0-rc2. The > version of httpd is the same between them, FWIW. I didn't > compare other package differences; it could be something > else entirely.
Thanks for the report. The failure is not in Git, it is a libcurl behaviour change, and there is already an open upstream issue:
https://github.com/curl/curl/issues/21943 "Negotiate ignored with --anyauth" (Dan Fandrich, 2026-06-10)
Dan also bisected it to the same commit I had locally, `8f71d0fde515` ("creds: hold credentials", curl PR #21548).
His report describes the regression at the `curl(1)` level (`curl --anyauth -u : ...` no longer attempts Negotiate); t5563 test 18 is the same regression observed through `http.emptyAuth=auto`, which under the hood is the same `CURLOPT_USERPWD=":"` pattern.
Dan also notes a workaround: replacing `-u :` with `-u literally:anything` (any non-blank username, real or fake) puts libcurl back on the Negotiate path. That suggests a small Git-side escape hatch is possible if we want to unblock people running against current libcurl while we wait for an upstream fix; I have not tried it yet and would want to be sure it does not have side effects on other auth schemes before proposing it.
Daniel Stenberg has acknowledged the curl issue but has not yet posted a fix. I will follow curl#21943 and, if the upstream answer is "the new behaviour is intended", come back here with a proposal for what Git should do about `http.emptyAuth` and test 18.
Thanks, Matthew