From: Patrick Steinhardt Date: Thu, 24 Sep 2026 07:59:16 GMT Subject: Re: [PATCH v7] http: add http.sslVerifyStatus to check stapled OCSP responses Message-ID: In-Reply-To: On Thu, Sep 24, 2026 at 09:41:41AM +0200, SZEDER Gábor wrote: > On Wed, Sep 23, 2026 at 02:47:18PM -0700, Junio C Hamano wrote: > > SZEDER Gábor writes: > > > > > On Tue, Sep 15, 2026 at 12:23:48PM -0400, graysongordon-gl wrote: > > >> From: Grayson Gordon > > >> > > >> git never sets CURLOPT_SSL_VERIFYSTATUS, so libcurl never requests the > > >> OCSP "Certificate Status Request" extension and any stapled response a > > >> server sends is ignored, including responses that explicitly state the > > >> certificate has been revoked. > > > ... > > > This patch was merged to 'next' the other day, and the last test in > > > the new t5585 fails on my system. > > > > Sorry about a premature merge. Since we are not in a hurry to take > > this topic in (or no new feature topic in general), let me revert it > > out of 'next' and give it a clean slate to try again. > > Well, if you hadn't merged it, we would perhaps still be none the > wiser, because, alas, I don't have the bandwidth to run tests on the > seen branch regularly... > > However, CI does, but I can't seem to find any CI runs that failed > because of this, which makes me worried that something is wrong on my > end. Do you maybe run with a curl backend that doesn't properly support OCSP? But even if so, our test suite should notice and skip the tests. Patrick