Git development
 help / color / mirror / Atom feed
From: Jeff King <peff@peff.net>
To: Johannes Schindelin via GitGitGadget <gitgitgadget@gmail.com>
Cc: git@vger.kernel.org, Johannes Schindelin <johannes.schindelin@gmx.de>
Subject: Re: [PATCH] ci: work around Debian 12's HTTP/2 authentication failures
Date: Wed, 23 Sep 2026 12:47:00 -0400	[thread overview]
Message-ID: <20260923164700.GA28538@coredump.intra.peff.net> (raw)
In-Reply-To: <pull.2236.git.1790118373340.gitgitgadget@gmail.com>

On Tue, Sep 22, 2026 at 11:06:13PM +0000, Johannes Schindelin via GitGitGadget wrote:

> Anonymous discovery succeeds, but the upload-pack POST requires
> authentication. Apache can return an early 401 and close the HTTP/2
> stream before libcurl finishes sending the request body. Debian 12's
> curl 7.88.1 treats that closure as a transport error instead of allowing
> an authentication retry. Curl fixed this handling in 331b89a319d0
> (http2: polish things around POST), included in 8.3.0:
> https://github.com/curl/curl/pull/11756
> 
> This did not happen before switching to Debian 12 because Debian 11
> ships with libcurl 7.74.0-1.3+deb11u16, which does not have that bug.

Thanks for finding and fixing. I saw this yesterday but hadn't had time
to dig in yet, and your explanation is very satisfying. :)

> Replacing the packaged libcurl with a modern build would defeat this
> job's purpose of testing older supported distributions. So let's simply
> exclude the flaky t5559.15 and its dependent t5559.16 on Debian 12 until
> the packaged curl carries the fix (or until the end of time, whichever
> comes first).

That should reduce the immediate CI pain, though I can think of two
downsides:

  - we're detecting based on CI job name, not on the presence of the
    known bug. So it won't help anybody running the tests themselves
    (even people on debian-12!)

  - we're relying on test numbering, which can change over time. So if
    we add new setup tests early in t5559 (actually, t5551 which it's
    based on!) these will silently go out of sync.

So an ideal solution to me would be more like t5559 checking for the
buggy version itself, setting a prereq, and then marking the tests with
!HAVE_CURL_HTTP2_BUG.

That said, I'm not sure how tricky that would be to implement. We give
the curl version with "git version --build-options", but we'd have to do
some version number comparisons. It might not be worth spending a lot of
time on this.

-Peff

  parent reply	other threads:[~2026-09-23 16:47 UTC|newest]

Thread overview: 15+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-22 23:06 [PATCH] ci: work around Debian 12's HTTP/2 authentication failures Johannes Schindelin via GitGitGadget
2026-09-23 16:16 ` Junio C Hamano
2026-09-23 16:47 ` Jeff King [this message]
2026-09-23 16:53   ` Jeff King
2026-09-23 16:59     ` Jeff King
2026-09-23 17:17       ` Junio C Hamano
2026-09-23 19:25         ` Jeff King
2026-09-24 18:59           ` Johannes Schindelin
2026-09-24 19:42             ` Junio C Hamano
2026-09-24 23:22             ` Jeff King
2026-09-24 20:53 ` [PATCH v2] " Johannes Schindelin via GitGitGadget
2026-10-06  3:43   ` [PATCH] t5551: fix quoting in curl version bug prereq Jeff King
2026-10-06  3:52     ` [PATCH 2/1] test-lib: allow lazy prerequisite snippets as here-docs Jeff King
2026-10-06  9:16     ` [PATCH] t5551: fix quoting in curl version bug prereq Johannes Schindelin
2026-10-06 12:25     ` Junio C Hamano

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260923164700.GA28538@coredump.intra.peff.net \
    --to=peff@peff.net \
    --cc=git@vger.kernel.org \
    --cc=gitgitgadget@gmail.com \
    --cc=johannes.schindelin@gmx.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox