git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] t5551: fix quoting in curl version bug prereq

From
Junio C Hamano <gitster@pobox.com>
Date
Oct 6, 2026, 12:25 UTC
Message-ID
<xmqqik3fhv81.fsf@gitster.g>
In-Reply-To
<20261006034331.GA1325722@coredump.intra.peff.net>
Jeff King <peff@peff.net> writes:
Show 18 quoted lines
> On Thu, Sep 24, 2026 at 08:53:49PM +0000, Johannes Schindelin via GitGitGadget wrote:
>
>> +# The cURL version which Debian 12 ships (v7.88.1) can fail to retry
>> +# authentication after an early HTTP/2 response. This bug was introduced
>> +# in cURL v7.88.0 (8c762f5998 (http2: minor buffer and error path fixes,
>> +# 2023-02-08)) and fixed in v8.3.0 (https://github.com/curl/curl/pull/11756).
>> +test_lazy_prereq HAVE_CURL_HTTP2_BUG "
>> +	test_have_prereq HTTP2 &&
>> +	build_option libcurl |
>> +	awk -F. '
>> +		($1 == 7 && $2 >= 88) || ($1 == 8 && $2 < 3) { broken = 1 }
>> +		END { exit !broken }
>> +	'
>> +"
>
> Doh, this is totally broken. The prereq snippet is in double-quotes, so
> the $1, etc in the awk invocation are interpolated before we even eval
> it. Fix is below.

Ah, I missed that "double-quote outside, single-quote inside" anti-pattern.

I also like your "HERE-doc solves many such issues" approach in the other message.

Thanks.
Show 68 quoted lines
> -- >8 --
> Subject: [PATCH] t5551: fix quoting in curl version bug prereq
>
> We have a prereq snippet that invokes awk. The awk script's $1, etc,
> variables need to be quoted to avoid shell interpolation. We correctly
> use a single-quote inside the prereq snippet, but the snippet itself is
> contained in double-quotes. So we interpolate "$1" into whatever value
> that happens to have in the outer shell, and eval nonsense like:
>
>   awk '(--some-garbage == 7 && --other-garbage >= 88) ...'
>
> As a result, we don't think we have a buggy curl version even when we
> do, and run the test anyway. But of course it's easy not to notice,
> since this prereq was protecting us from a racy bug. It only breaks
> sometimes.
>
> There are a few options for fixing the quoting:
>
>   1. Backslash-escaping the dollar signs. This is perhaps the least-ugly
>      version, but it's a minor hassle to remember if somebody touches
>      the code later.
>
>   2. Single-quote the snippet, then quote interior single-quotes as
>      '\''. Reasonably obvious, but ugly.
>
>   3. Use the '<<\EOT' here-doc trick to specify the snippet. This would
>      look nice, but we don't yet support it for prereqs. ;)
>
> This patch uses (2), and we can circle back to (3) to make it look nicer
> later.
>
> Signed-off-by: Jeff King <peff@peff.net>
> ---
> This should go on top of js/ci-debian-12-http2-workaround.
>
> Since I know we both used GPT to work on this, I was curious if this
> slipped past it. Doesn't look like it from what I sent (which used
> option 2 above). I wonder if your agent flipped it, or if you saw how
> ugly it was and flipped it yourself. Not blaming, but it's just a funny
> and interesting data point if a human second-guessing the AI output
> introduced a bug.
>
>  t/t5551-http-fetch-smart.sh | 8 ++++----
>  1 file changed, 4 insertions(+), 4 deletions(-)
>
> diff --git a/t/t5551-http-fetch-smart.sh b/t/t5551-http-fetch-smart.sh
> index f66d7ce7ac..cb681e644f 100755
> --- a/t/t5551-http-fetch-smart.sh
> +++ b/t/t5551-http-fetch-smart.sh
> @@ -21,14 +21,14 @@ start_httpd
>  # authentication after an early HTTP/2 response. This bug was introduced
>  # in cURL v7.88.0 (8c762f5998 (http2: minor buffer and error path fixes,
>  # 2023-02-08)) and fixed in v8.3.0 (https://github.com/curl/curl/pull/11756).
> -test_lazy_prereq HAVE_CURL_HTTP2_BUG "
> +test_lazy_prereq HAVE_CURL_HTTP2_BUG '
>  	test_have_prereq HTTP2 &&
>  	build_option libcurl |
> -	awk -F. '
> +	awk -F. '\''
>  		($1 == 7 && $2 >= 88) || ($1 == 8 && $2 < 3) { broken = 1 }
>  		END { exit !broken }
> -	'
> -"
> +	'\''
> +'
>  
>  test_expect_success HTTP2 'enable client-side http/2' '
>  	git config --global http.version HTTP/2
Previous: Johannes Schindelin
Message 15 of 15 in “ci: work around Debian 12's HTTP/2 authentication failures”
  1. ci: work around Debian 12's HTTP/2 authentication failuresJohannes Schindelin via GitGitGadget, Sep 22, 2026
  2. Junio C HamanoSep 23, 2026
  3. Jeff KingSep 23, 2026
  4. Jeff KingSep 23, 2026
  5. Jeff KingSep 23, 2026
  6. Junio C HamanoSep 23, 2026
  7. Jeff KingSep 23, 2026
  8. Johannes SchindelinSep 24, 2026
  9. Junio C HamanoSep 24, 2026
  10. Jeff KingSep 24, 2026
  11. ci: work around Debian 12's HTTP/2 authentication failuresJohannes Schindelin via GitGitGadget, Sep 24, 2026
  12. t5551: fix quoting in curl version bug prereqJeff King, Oct 6, 2026
  13. 2/1 test-lib: allow lazy prerequisite snippets as here-docsJeff King, Oct 6, 2026
  14. Johannes SchindelinOct 6, 2026
  15. Junio C HamanoOct 6, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.