Git development
 help / color / mirror / Atom feed
From: "Johannes Schindelin via GitGitGadget" <gitgitgadget@gmail.com>
To: git@vger.kernel.org
Cc: Jeff King <peff@peff.net>,
	Johannes Schindelin <johannes.schindelin@gmx.de>,
	Johannes Schindelin <johannes.schindelin@gmx.de>
Subject: [PATCH v2] ci: work around Debian 12's HTTP/2 authentication failures
Date: Thu, 24 Sep 2026 20:53:49 +0000	[thread overview]
Message-ID: <pull.2236.v2.git.1790283229626.gitgitgadget@gmail.com> (raw)
In-Reply-To: <pull.2236.git.1790118373340.gitgitgadget@gmail.com>

From: Johannes Schindelin <johannes.schindelin@gmx.de>

Since 00fa8502354 (ci: bump debian-11 job to debian-12, 2026-09-05), the
`debian-12` job has intermittently failed t5559's half-auth clone with:

  curl 92 Stream error in the HTTP/2 framing layer

Anonymous discovery succeeds, but the upload-pack POST requires
authentication. Apache can return an early 401 and close the HTTP/2
stream before libcurl finishes sending the request body. Debian 12's
curl 7.88.1 treats that closure as a transport error instead of allowing
an authentication retry. Curl fixed this handling in 331b89a319d0
(http2: polish things around POST), included in 8.3.0:
https://github.com/curl/curl/pull/11756

This did not happen before switching to Debian 12 because Debian 11
ships with libcurl 7.74.0-1.3+deb11u16, which does not have that bug, it
was only introduced in cURL 7.88.0.

Replacing the packaged libcurl with a modern build would defeat this
job's purpose of testing older supported distributions. So let's simply
skip the flaky test cases when a buggy libcurl version is detected.

Assisted-by: GPT-6 Astra, GPT-6 Sol
Helped-by: Jeff King <peff@peff.net>
Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
---
    ci: work around Debian 12's HTTP/2 authentication failures
    
    While this is a regression in v2.56, it does not affect production code,
    it's just working around a flaky test. In other words: This patch does
    not need to be fast-tracked into v2.56.0, but it would be good to get it
    into master pretty soon after that, to reduce developer friction.
    
    Changes since v1:
    
     * Instead of hard-coding the test case numbers specifically on Debian
       12, thanks to Jeff King the test cases now have a
       libcurl-version-gating prereq.

Published-As: https://github.com/gitgitgadget/git/releases/tag/pr-2236%2Fdscho%2Fwork-around-debian-curl-stream-error-92-v2
Fetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-2236/dscho/work-around-debian-curl-stream-error-92-v2
Pull-Request: https://github.com/gitgitgadget/git/pull/2236

Range-diff vs v1:

 1:  1dfabf3ece < -:  ---------- ci: work around Debian 12's HTTP/2 authentication failures
 -:  ---------- > 1:  e4c5658fb1 ci: work around Debian 12's HTTP/2 authentication failures


 t/t5551-http-fetch-smart.sh | 19 +++++++++++++++++--
 1 file changed, 17 insertions(+), 2 deletions(-)

diff --git a/t/t5551-http-fetch-smart.sh b/t/t5551-http-fetch-smart.sh
index 805bec025c..57f263ca5b 100755
--- a/t/t5551-http-fetch-smart.sh
+++ b/t/t5551-http-fetch-smart.sh
@@ -17,6 +17,19 @@ fi
 test "$HTTP_PROTO" = "HTTP/2" && enable_http2
 start_httpd
 
+# The cURL version which Debian 12 ships (v7.88.1) can fail to retry
+# authentication after an early HTTP/2 response. This bug was introduced
+# in cURL v7.88.0 (8c762f5998 (http2: minor buffer and error path fixes,
+# 2023-02-08)) and fixed in v8.3.0 (https://github.com/curl/curl/pull/11756).
+test_lazy_prereq HAVE_CURL_HTTP2_BUG "
+	test_have_prereq HTTP2 &&
+	build_option libcurl |
+	awk -F. '
+		($1 == 7 && $2 >= 88) || ($1 == 8 && $2 < 3) { broken = 1 }
+		END { exit !broken }
+	'
+"
+
 test_expect_success HTTP2 'enable client-side http/2' '
 	git config --global http.version HTTP/2
 '
@@ -224,7 +237,8 @@ test_expect_success 'clone from auth-only-for-push repository' '
 	test_cmp expect actual
 '
 
-test_expect_success 'clone from auth-only-for-objects repository' '
+test_expect_success !HAVE_CURL_HTTP2_BUG \
+	'clone from auth-only-for-objects repository' '
 	echo two >expect &&
 	set_askpass user@host pass@host &&
 	git clone --bare "$HTTPD_URL/auth-fetch/smart/repo.git" half-auth &&
@@ -233,7 +247,8 @@ test_expect_success 'clone from auth-only-for-objects repository' '
 	test_cmp expect actual
 '
 
-test_expect_success 'no-op half-auth fetch does not require a password' '
+test_expect_success !HAVE_CURL_HTTP2_BUG \
+	'no-op half-auth fetch does not require a password' '
 	set_askpass wrong &&
 
 	# NEEDSWORK: When using HTTP(S), protocol v0 supports a "half-auth"

base-commit: 3bc0341126508f78f5869cbfc0005e987efdf0c7
-- 
gitgitgadget

  parent reply	other threads:[~2026-09-24 20:53 UTC|newest]

Thread overview: 15+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-22 23:06 [PATCH] ci: work around Debian 12's HTTP/2 authentication failures Johannes Schindelin via GitGitGadget
2026-09-23 16:16 ` Junio C Hamano
2026-09-23 16:47 ` Jeff King
2026-09-23 16:53   ` Jeff King
2026-09-23 16:59     ` Jeff King
2026-09-23 17:17       ` Junio C Hamano
2026-09-23 19:25         ` Jeff King
2026-09-24 18:59           ` Johannes Schindelin
2026-09-24 19:42             ` Junio C Hamano
2026-09-24 23:22             ` Jeff King
2026-09-24 20:53 ` Johannes Schindelin via GitGitGadget [this message]
2026-10-06  3:43   ` [PATCH] t5551: fix quoting in curl version bug prereq Jeff King
2026-10-06  3:52     ` [PATCH 2/1] test-lib: allow lazy prerequisite snippets as here-docs Jeff King
2026-10-06  9:16     ` [PATCH] t5551: fix quoting in curl version bug prereq Johannes Schindelin
2026-10-06 12:25     ` Junio C Hamano

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=pull.2236.v2.git.1790283229626.gitgitgadget@gmail.com \
    --to=gitgitgadget@gmail.com \
    --cc=git@vger.kernel.org \
    --cc=johannes.schindelin@gmx.de \
    --cc=peff@peff.net \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox