threads / patch / 1217

patchSupport more http features: https no cert, .netrc -> auth

Subject: [PATCH] Support more http features: https no cert, .netrc -> auth

## tl;dr

3 messages between Jul 13, 2005 and Jul 13, 2005. Diffs are folded; open one to read it.

replies: 2people: 2as markdown or json

Darrin Thompson· Jul 13, 2005, 02:12 UTC · lore

Cause setting environment variable GIT_SSL_NO_VERIFY to turn off curl's ssl peer verification.

Only use curl for http transfers, instead of curl and wget.
Make curl check ~/.netrc for credentials.

--- commit 229718f5723f81304c7c038c18d1e1bd630026ae tree 501594e7b424855f08d7bef6bd4f9721d40d4a3c parent e30e814dbfef7a6e89418863e5d7291a2d53b18f author Darrin Thompson <darrint@progeny.com> Tue, 12 Jul 2005 16:27:05 -0500

 git-fetch-script |    7 +++++--
 http-pull.c      |    6 ++++++
 2 files changed, 11 insertions(+), 2 deletions(-)
Show changes to 2 files +11 −2

git-fetch-script, http-pull.c

diff --git a/git-fetch-script b/git-fetch-script
--- a/git-fetch-script
+++ b/git-fetch-script
@@ -14,8 +14,11 @@ fi
 TMP_HEAD="$GIT_DIR/TMP_HEAD"
 
 case "$merge_repo" in
-http://*)
-	head=$(wget -q -O - "$merge_repo/$merge_name") || exit 1
+http://*|https://*)
+        if [ -n "$GIT_SSL_NO_VERIFY" ]; then
+            curl_extra_args="-k"
+        fi
+	head=$(curl -ns $curl_extra_args "$merge_repo/$merge_name") || exit 1
 	echo Fetching $head using http
 	git-http-pull -v -a "$head" "$merge_repo/"
 	;;
diff --git a/http-pull.c b/http-pull.c
--- a/http-pull.c
+++ b/http-pull.c
@@ -16,6 +16,8 @@ static z_stream stream;
 static int local;
 static int zret;
 
+static int curl_ssl_verify;
+
 struct buffer
 {
         size_t posn;
@@ -173,6 +175,10 @@ int main(int argc, char **argv)
 
 	curl = curl_easy_init();
 
+	curl_ssl_verify = gitenv("GIT_SSL_NO_VERIFY") ? 0 : 1;
+	curl_easy_setopt(curl, CURLOPT_SSL_VERIFYPEER, curl_ssl_verify);
+	curl_easy_setopt(curl, CURLOPT_NETRC, CURL_NETRC_OPTIONAL);
+
 	base = url;
 
 	if (pull(commit_id))
Junio C Hamano· Jul 13, 2005, 20:11 UTC · re: Darrin Thompson · lore

[PATCH (contingency)] Document "curl" requirements.

darrint@progeny.com (Darrin Thompson) writes:
> Cause setting environment variable GIT_SSL_NO_VERIFY to turn off
> curl's ssl peer verification.
>
> Only use curl for http transfers, instead of curl and wget.

I do not mind curl per se, since we already require libcurl for http-pull, but it would be nice if we document what external software we depend on in one place. Something like this on top of what you posted?

------------ Not just libcurl, but now we require curl executable as well.

Signed-off-by: Junio C Hamano <junkio@cox.net>
---
Show changes to INSTALL +4 −2
diff --git a/INSTALL b/INSTALL
--- a/INSTALL
+++ b/INSTALL
@@ -41,8 +41,10 @@ Issues of note:
 	  can avoid the bignum support by excising git-rev-list support
 	  for "--merge-order" (by hand).
 
-	- "libcurl".  git-http-pull uses this.  You can disable building of
-	  that program if you just want to get started. 
+	- "libcurl" and "curl" (executable).  git-http-pull and
+	  git-fetch-script use them.  If you do not use http
+	  transfer, you are probabaly OK if you do not have
+	  these two.
 
 	- "GNU diff" to generate patches.  Of course, you don't _have_ to
 	  generate patches if you don't want to, but let's face it, you'll
Darrin Thompson· Jul 13, 2005, 20:50 UTC · re: Junio C Hamano · lore

Re: [PATCH (contingency)] Document "curl" requirements.

On Wed, 2005-07-13 at 13:11 -0700, Junio C Hamano wrote:
Show 11 quoted lines
> darrint@progeny.com (Darrin Thompson) writes:
> 
> > Cause setting environment variable GIT_SSL_NO_VERIFY to turn off
> > curl's ssl peer verification.
> >
> > Only use curl for http transfers, instead of curl and wget.
> 
> I do not mind curl per se, since we already require libcurl for
> http-pull, but it would be nice if we document what external
> software we depend on in one place.  Something like this on top
> of what you posted?
I have no problem with it. Do I need to take some action?

-- Darrin

← back to recent threads