Git development
 help / color / mirror / Atom feed
From: Jeff King <peff@peff.net>
To: Johannes Schindelin via GitGitGadget <gitgitgadget@gmail.com>
Cc: Junio C Hamano <gitster@pobox.com>,
	git@vger.kernel.org,
	Johannes Schindelin <johannes.schindelin@gmx.de>
Subject: [PATCH] t5551: fix quoting in curl version bug prereq
Date: Mon, 5 Oct 2026 23:43:31 -0400	[thread overview]
Message-ID: <20261006034331.GA1325722@coredump.intra.peff.net> (raw)
In-Reply-To: <pull.2236.v2.git.1790283229626.gitgitgadget@gmail.com>

On Thu, Sep 24, 2026 at 08:53:49PM +0000, Johannes Schindelin via GitGitGadget wrote:

> +# The cURL version which Debian 12 ships (v7.88.1) can fail to retry
> +# authentication after an early HTTP/2 response. This bug was introduced
> +# in cURL v7.88.0 (8c762f5998 (http2: minor buffer and error path fixes,
> +# 2023-02-08)) and fixed in v8.3.0 (https://github.com/curl/curl/pull/11756).
> +test_lazy_prereq HAVE_CURL_HTTP2_BUG "
> +	test_have_prereq HTTP2 &&
> +	build_option libcurl |
> +	awk -F. '
> +		($1 == 7 && $2 >= 88) || ($1 == 8 && $2 < 3) { broken = 1 }
> +		END { exit !broken }
> +	'
> +"

Doh, this is totally broken. The prereq snippet is in double-quotes, so
the $1, etc in the awk invocation are interpolated before we even eval
it. Fix is below.

-- >8 --
Subject: [PATCH] t5551: fix quoting in curl version bug prereq

We have a prereq snippet that invokes awk. The awk script's $1, etc,
variables need to be quoted to avoid shell interpolation. We correctly
use a single-quote inside the prereq snippet, but the snippet itself is
contained in double-quotes. So we interpolate "$1" into whatever value
that happens to have in the outer shell, and eval nonsense like:

  awk '(--some-garbage == 7 && --other-garbage >= 88) ...'

As a result, we don't think we have a buggy curl version even when we
do, and run the test anyway. But of course it's easy not to notice,
since this prereq was protecting us from a racy bug. It only breaks
sometimes.

There are a few options for fixing the quoting:

  1. Backslash-escaping the dollar signs. This is perhaps the least-ugly
     version, but it's a minor hassle to remember if somebody touches
     the code later.

  2. Single-quote the snippet, then quote interior single-quotes as
     '\''. Reasonably obvious, but ugly.

  3. Use the '<<\EOT' here-doc trick to specify the snippet. This would
     look nice, but we don't yet support it for prereqs. ;)

This patch uses (2), and we can circle back to (3) to make it look nicer
later.

Signed-off-by: Jeff King <peff@peff.net>
---
This should go on top of js/ci-debian-12-http2-workaround.

Since I know we both used GPT to work on this, I was curious if this
slipped past it. Doesn't look like it from what I sent (which used
option 2 above). I wonder if your agent flipped it, or if you saw how
ugly it was and flipped it yourself. Not blaming, but it's just a funny
and interesting data point if a human second-guessing the AI output
introduced a bug.

 t/t5551-http-fetch-smart.sh | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/t/t5551-http-fetch-smart.sh b/t/t5551-http-fetch-smart.sh
index f66d7ce7ac..cb681e644f 100755
--- a/t/t5551-http-fetch-smart.sh
+++ b/t/t5551-http-fetch-smart.sh
@@ -21,14 +21,14 @@ start_httpd
 # authentication after an early HTTP/2 response. This bug was introduced
 # in cURL v7.88.0 (8c762f5998 (http2: minor buffer and error path fixes,
 # 2023-02-08)) and fixed in v8.3.0 (https://github.com/curl/curl/pull/11756).
-test_lazy_prereq HAVE_CURL_HTTP2_BUG "
+test_lazy_prereq HAVE_CURL_HTTP2_BUG '
 	test_have_prereq HTTP2 &&
 	build_option libcurl |
-	awk -F. '
+	awk -F. '\''
 		($1 == 7 && $2 >= 88) || ($1 == 8 && $2 < 3) { broken = 1 }
 		END { exit !broken }
-	'
-"
+	'\''
+'
 
 test_expect_success HTTP2 'enable client-side http/2' '
 	git config --global http.version HTTP/2
-- 
2.56.0.399.g9e0ddc9b37


  reply	other threads:[~2026-10-06  3:50 UTC|newest]

Thread overview: 15+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-22 23:06 [PATCH] ci: work around Debian 12's HTTP/2 authentication failures Johannes Schindelin via GitGitGadget
2026-09-23 16:16 ` Junio C Hamano
2026-09-23 16:47 ` Jeff King
2026-09-23 16:53   ` Jeff King
2026-09-23 16:59     ` Jeff King
2026-09-23 17:17       ` Junio C Hamano
2026-09-23 19:25         ` Jeff King
2026-09-24 18:59           ` Johannes Schindelin
2026-09-24 19:42             ` Junio C Hamano
2026-09-24 23:22             ` Jeff King
2026-09-24 20:53 ` [PATCH v2] " Johannes Schindelin via GitGitGadget
2026-10-06  3:43   ` Jeff King [this message]
2026-10-06  3:52     ` [PATCH 2/1] test-lib: allow lazy prerequisite snippets as here-docs Jeff King
2026-10-06  9:16     ` [PATCH] t5551: fix quoting in curl version bug prereq Johannes Schindelin
2026-10-06 12:25     ` Junio C Hamano

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261006034331.GA1325722@coredump.intra.peff.net \
    --to=peff@peff.net \
    --cc=git@vger.kernel.org \
    --cc=gitgitgadget@gmail.com \
    --cc=gitster@pobox.com \
    --cc=johannes.schindelin@gmx.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox