git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] ci: work around Debian 12's HTTP/2 authentication failures

From
Junio C Hamano <gitster@pobox.com>
Date
Sep 23, 2026, 16:16 UTC
Message-ID
<xmqq1pakc59l.fsf@gitster.g>
In-Reply-To
<pull.2236.git.1790118373340.gitgitgadget@gmail.com>

"Johannes Schindelin via GitGitGadget" <gitgitgadget@gmail.com> writes:

Show 17 quoted lines
> From: Johannes Schindelin <johannes.schindelin@gmx.de>
>
> Since 00fa8502354 (ci: bump debian-11 job to debian-12, 2026-09-05), the
> `debian-12` job has intermittently failed t5559's half-auth clone with:
>
>   curl 92 Stream error in the HTTP/2 framing layer
>
> Anonymous discovery succeeds, but the upload-pack POST requires
> authentication. Apache can return an early 401 and close the HTTP/2
> stream before libcurl finishes sending the request body. Debian 12's
> curl 7.88.1 treats that closure as a transport error instead of allowing
> an authentication retry. Curl fixed this handling in 331b89a319d0
> (http2: polish things around POST), included in 8.3.0:
> https://github.com/curl/curl/pull/11756
>
> This did not happen before switching to Debian 12 because Debian 11
> ships with libcurl 7.74.0-1.3+deb11u16, which does not have that bug.
Superb.  A well written diagnosis like this is worth a ton.
Show 5 quoted lines
> Replacing the packaged libcurl with a modern build would defeat this
> job's purpose of testing older supported distributions. So let's simply
> exclude the flaky t5559.15 and its dependent t5559.16 on Debian 12 until
> the packaged curl carries the fix (or until the end of time, whichever
> comes first).
Oh, 100% agree with the reasoning.  Thanks for this workaround.
>     it's just working around a flaky test. In other words: This patch does
>     not need to be fast-tracked into v2.56.0, but it would be good to get it
>     into master pretty soon after that, to reduce developer friction.

Yes. I do not think there is any reason to cook it as long as other usual patches. Fast-tracking would make sure other things do keep working on older Debian.

Thanks.
Show 27 quoted lines
>
> Published-As: https://github.com/gitgitgadget/git/releases/tag/pr-2236%2Fdscho%2Fwork-around-debian-curl-stream-error-92-v1
> Fetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-2236/dscho/work-around-debian-curl-stream-error-92-v1
> Pull-Request: https://github.com/gitgitgadget/git/pull/2236
>
>  ci/lib.sh | 6 ++++++
>  1 file changed, 6 insertions(+)
>
> diff --git a/ci/lib.sh b/ci/lib.sh
> index c6ccbf8c17..1cf31b5a2c 100755
> --- a/ci/lib.sh
> +++ b/ci/lib.sh
> @@ -334,6 +334,12 @@ pull_request,*|push,*next*|push,*master*|push,*main*|push,*maint*)
>  esac
>  
>  case "$distro" in
> +debian-12)
> +	# Debian 12's curl 7.88.1 mishandles early HTTP/2 responses; see
> +	# https://github.com/curl/curl/pull/11756. Skip the half-auth
> +	# clone and its dependent fetch until Debian has the fix.
> +	export GIT_SKIP_TESTS="$GIT_SKIP_TESTS t5559.15 t5559.16"
> +	;;
>  ubuntu-*)
>  	# Python 2 is end of life, and Ubuntu 23.04 and newer don't actually
>  	# have it anymore. We thus only test with Python 2 on older LTS
>
> base-commit: 3bc0341126508f78f5869cbfc0005e987efdf0c7
Previous: Johannes Schindelin via GitGitGadgetNext: Jeff King
Message 2 of 15 in “ci: work around Debian 12's HTTP/2 authentication failures”
  1. ci: work around Debian 12's HTTP/2 authentication failuresJohannes Schindelin via GitGitGadget, Sep 22, 2026
  2. Junio C HamanoSep 23, 2026
  3. Jeff KingSep 23, 2026
  4. Jeff KingSep 23, 2026
  5. Jeff KingSep 23, 2026
  6. Junio C HamanoSep 23, 2026
  7. Jeff KingSep 23, 2026
  8. Johannes SchindelinSep 24, 2026
  9. Junio C HamanoSep 24, 2026
  10. Jeff KingSep 24, 2026
  11. ci: work around Debian 12's HTTP/2 authentication failuresJohannes Schindelin via GitGitGadget, Sep 24, 2026
  12. t5551: fix quoting in curl version bug prereqJeff King, Oct 6, 2026
  13. 2/1 test-lib: allow lazy prerequisite snippets as here-docsJeff King, Oct 6, 2026
  14. Johannes SchindelinOct 6, 2026
  15. Junio C HamanoOct 6, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.