Go to file
Jeff King 76524c2604 http: handle curl stripping creds from effective url
When we detect that curl performed a redirect of a URL we requested, we
update our base URL to match the new location and flush the http_auth
credentials. This goes back to c93c92f309 (http: update base URLs when
we see redirects, 2013-09-28).

We detect the redirect by comparing the requested URL to the response
from CURLINFO_EFFECTIVE_URL, using a simple string comparison. This has
worked fine for years, but a change in the upcoming curl 8.23.0 adds a
complication. If our URL directly contains credentials (like
"https://user:pass@example.com/foo.git"), then as of 7a6bd027d0
(getinfo: make sure CURLINFO_EFFECTIVE_URL does not contain creds,
2026-09-21), curl will strip the credentials from what it returns (so
just "https://example.com/foo.git" in this case).

This breaks our direct string comparison, and we believe that we've been
redirected. We flush our http_auth credentials, and now subsequent
requests will use the reduced URL, causing us to re-request credentials
from the user. Notably this causes t5550.15 (among others) to complain;
it tries a clone with credentials in the URL, and fails if the user is
prompted at all.

We can handle this new behavior by doing a more careful comparison: if
the direct string comparison fails, we'll strip out the credentials
ourselves and compare. This is a little extra work, but in practice it
should only happen once per process.

I've used curl's curl_url() interface to do the stripping here, mostly
because its behavior should match the stripping it does internally. And
also, though we have code to parse a URL, we don't have any to
reconstruct it, making a single string comparison hard.

One alternative would be to parse with url_parse() or similar, and
compare the individual fields (skipping username/password). I think that
would probably also work in practice, but it seemed to me that the
simplest change would be sticking with string comparisons.

The curl_url() interface appeared in 7.62.0. We document that 7.61.0 is
still supported, so I've made it conditional here. Only new versions
strip the result from CURLINFO_EFFECTIVE_URL, so it's OK for very old
versions to skip the extra comparison. Likewise if we encounter any
errors, we just quietly skip the comparison. That's fine if you don't
have creds in your URLs, and if you do, you'll get end up in the
existing error path (a redirect warning, and eventually an auth
failure).

Signed-off-by: Jeff King <peff@peff.net>
Signed-off-by: Junio C Hamano <gitster@pobox.com>
2026-09-28 10:49:29 -07:00
.github Merge branch 'js/rust-in-windows-ci' 2026-09-16 09:04:55 -07:00
Documentation Revert "Merge branch 'en/no-amend-during-conflicts'" 2026-09-23 11:18:51 -07:00
bin-wrappers
…
block-sha1
…
builtin Revert "Merge branch 'en/no-amend-during-conflicts'" 2026-09-23 11:18:51 -07:00
ci Merge branch 'js/rust-in-windows-ci' 2026-09-16 09:04:55 -07:00
compat Merge branch 'js/mingw-build-updates' 2026-09-11 09:45:10 -07:00
compiler-tricks
…
contrib cmake(windows): accommodate for Git for Windows' migration to UCRT64 2026-09-13 16:01:18 -07:00
ewah
…
git-gui
…
gitk-git Merge branch 'master' of https://github.com/j6t/gitk 2026-09-11 09:03:58 -07:00
gitweb
…
mergetools
…
negotiator
…
odb Merge branch 'ps/odb-pluggable-fsck' 2026-09-15 11:07:37 -07:00
oss-fuzz Merge branch 'js/pack-objects-delta-size-t' 2026-08-24 13:17:51 -07:00
perl
…
po l10n: af: fix review comments 2026-09-27 20:41:50 +08:00
refs Merge branch 'kn/reftable-optimize-reloading' 2026-09-07 09:32:05 -07:00
reftable Merge branch 'kn/reftable-optimize-reloading' 2026-09-07 09:32:05 -07:00
sha1
…
sha1collisiondetection@855827c583
…
sha1dc
…
sha256
…
src rust: respect CARGO_BUILD_TARGET when locating build output 2026-09-10 06:37:09 -07:00
subprojects
…
t Revert "Merge branch 'en/no-amend-during-conflicts'" 2026-09-23 11:18:51 -07:00
templates
…
tools
…
trace2
…
xdiff
…
.b4-config
…
.b4-cover-template
…
.cirrus.yml
…
.clang-format
…
.editorconfig
…
.gitattributes
…
.gitignore
…
.gitlab-ci.yml Merge branch 'jk/ci-bump-debian-to-12' 2026-09-11 09:45:10 -07:00
.gitmodules
…
.mailmap mailmap: normalize name for Yoichi NAKAYAMA 2026-09-17 09:43:13 -07:00
.tsan-suppressions
…
CODE_OF_CONDUCT.md
…
COPYING
…
Cargo.toml
…
GIT-BUILD-OPTIONS.in
…
GIT-VERSION-FILE.in
…
GIT-VERSION-GEN Git 2.56 2026-09-27 21:20:04 -07:00
INSTALL
…
LGPL-2.1
…
Makefile Merge branch 'js/rust-in-windows-ci' 2026-09-16 09:04:55 -07:00
README.md
…
RelNotes
…
SECURITY.md
…
abspath.c
…
abspath.h
…
aclocal.m4
…
add-interactive.c
…
add-interactive.h
…
add-patch.c
…
add-patch.h
…
advice.c
…
advice.h
…
alias.c
…
alias.h
…
alloc.c
…
alloc.h
…
apply.c
…
apply.h
…
archive-tar.c
…
archive-zip.c Merge branch 'js/pack-objects-delta-size-t' 2026-08-24 13:17:51 -07:00
archive.c
…
archive.h
…
attr.c
…
attr.h
…
banned.h
…
base85.c
…
base85.h
…
bisect.c Merge branch 'js/coverity-unchecked-returns-fix' 2026-08-24 13:17:50 -07:00
bisect.h
…
blame.c
…
blame.h
…
blob.c
…
blob.h
…
bloom.c
…
bloom.h
…
branch.c
…
branch.h
…
build.rs
…
builtin.h
…
bundle-uri.c
…
bundle-uri.h
…
bundle.c
…
bundle.h
…
cache-tree.c cache-tree: remove dependency on `the_repository` 2026-09-11 08:46:09 -07:00
cache-tree.h cache-tree: remove dependency on `the_repository` 2026-09-11 08:46:09 -07:00
cbtree.c
…
cbtree.h
…
chdir-notify.c
…
chdir-notify.h
…
checkout.c checkout: improve message for ambiguous remote branch name 2026-08-27 10:29:43 -07:00
checkout.h checkout: improve message for ambiguous remote branch name 2026-08-27 10:29:43 -07:00
chunk-format.c
…
chunk-format.h
…
color.c
…
color.h
…
column.c
…
column.h
…
combine-diff.c
…
command-list.txt doc: git: list gitdatamodel(7) as a concept guide 2026-09-05 17:37:49 -07:00
commit-graph.c
…
commit-graph.h
…
commit-reach.c Merge branch 'kk/merge-base-exhaustion' 2026-08-23 18:01:46 -07:00
commit-reach.h
…
commit-slab-decl.h
…
commit-slab-impl.h
…
commit-slab.h
…
commit.c
…
commit.h
…
common-exit.c
…
common-init.c
…
common-init.h
…
common-main.c
…
config.c Merge branch 'js/pack-objects-delta-size-t' 2026-08-24 13:17:51 -07:00
config.h
…
config.mak.dev
…
config.mak.in
…
config.mak.uname Merge branch 'js/rust-in-windows-ci' 2026-09-16 09:04:55 -07:00
configure.ac
…
connect.c
…
connect.h
…
connected.c
…
connected.h
…
convert.c
…
convert.h
…
copy.c
…
copy.h
…
credential.c
…
credential.h
…
csum-file.c
…
csum-file.h
…
ctype.c
…
daemon.c
…
date.c
…
date.h
…
decorate.c
…
decorate.h
…
delta-islands.c
…
delta-islands.h
…
delta.h
…
diagnose.c
…
diagnose.h
…
diff-delta.c
…
diff-lib.c
…
diff-merges.c
…
diff-merges.h
…
diff-no-index.c
…
diff.c Merge branch 'en/diff-l-opt-help' 2026-08-24 13:17:51 -07:00
diff.h
…
diffcore-break.c
…
diffcore-delta.c
…
diffcore-order.c
…
diffcore-pickaxe.c
…
diffcore-rename.c
…
diffcore-rotate.c
…
diffcore.h
…
dir-iterator.c
…
dir-iterator.h
…
dir.c Merge branch 'yt/pathspec-negative-prefix' 2026-09-17 09:48:17 -07:00
dir.h
…
editor.c
…
editor.h
…
entry.c
…
entry.h
…
environment.c
…
environment.h
…
exec-cmd.c
…
exec-cmd.h
…
fetch-negotiator.c
…
fetch-negotiator.h
…
fetch-object-info.c
…
fetch-object-info.h
…
fetch-pack.c Merge branch 'tn/fetch-pack-trace-packfile-uri' 2026-09-13 21:53:30 -07:00
fetch-pack.h
…
fmt-merge-msg.c
…
fmt-merge-msg.h
…
for-each-ref.h
…
fsck.c
…
fsck.h
…
fsmonitor--daemon.h
…
fsmonitor-ipc.c
…
fsmonitor-ipc.h
…
fsmonitor-ll.h
…
fsmonitor-path-utils.h
…
fsmonitor-settings.c
…
fsmonitor-settings.h
…
fsmonitor.c
…
fsmonitor.h
…
gettext.c
…
gettext.h
…
git-archimport.perl
…
git-compat-util.h
…
git-curl-compat.h http: handle curl stripping creds from effective url 2026-09-28 10:49:29 -07:00
git-cvsexportcommit.perl
…
git-cvsimport.perl
…
git-cvsserver.perl
…
git-difftool--helper.sh
…
git-filter-branch.sh
…
git-instaweb.sh
…
git-merge-octopus.sh
…
git-merge-one-file.sh
…
git-merge-resolve.sh
…
git-mergetool--lib.sh
…
git-mergetool.sh
…
git-p4.py
…
git-quiltimport.sh
…
git-request-pull.sh
…
git-send-email.perl
…
git-sh-i18n.sh
…
git-sh-setup.sh
…
git-submodule.sh
…
git-svn.perl
…
git-web--browse.sh
…
git-zlib.c
…
git-zlib.h
…
git.c Merge branch 'ty/repository-fetch-if-missing' 2026-09-02 09:21:59 -07:00
git.rc.in
…
gpg-interface.c
…
gpg-interface.h
…
graph.c
…
graph.h
…
grep.c
…
grep.h
…
hash-lookup.c
…
hash-lookup.h
…
hash.c
…
hash.h
…
hashmap.c
…
hashmap.h
…
help.c
…
help.h
…
hex-ll.c
…
hex-ll.h
…
hex.c
…
hex.h
…
hook.c
…
hook.h
…
http-backend.c
…
http-fetch.c
…
http-push.c Merge branch 'js/pack-objects-delta-size-t' 2026-08-24 13:17:51 -07:00
http-walker.c
…
http.c http: handle curl stripping creds from effective url 2026-09-28 10:49:29 -07:00
http.h
…
ident.c
…
ident.h
…
imap-send.c Merge branch 'wf/imap-send-draft' 2026-09-14 14:02:52 -07:00
iterator.h
…
json-writer.c
…
json-writer.h
…
khash.h
…
kwset.c
…
kwset.h
…
levenshtein.c
…
levenshtein.h
…
line-log.c
…
line-log.h
…
line-range.c
…
line-range.h
…
linear-assignment.c
…
linear-assignment.h
…
list-objects-filter-options.c
…
list-objects-filter-options.h
…
list-objects-filter.c
…
list-objects-filter.h
…
list-objects.c
…
list-objects.h
…
list.h
…
lockfile.c
…
lockfile.h
…
log-tree.c
…
log-tree.h
…
loose.c
…
loose.h
…
ls-refs.c
…
ls-refs.h
…
mailinfo.c
…
mailinfo.h
…
mailmap.c
…
mailmap.h
…
match-trees.c
…
match-trees.h
…
mem-pool.c
…
mem-pool.h
…
merge-blobs.c
…
merge-blobs.h
…
merge-ll.c
…
merge-ll.h
…
merge-ort-wrappers.c
…
merge-ort-wrappers.h
…
merge-ort.c
…
merge-ort.h
…
merge.c
…
merge.h
…
mergesort.h
…
meson.build Merge branch 'js/mingw-build-updates' 2026-09-11 09:45:10 -07:00
meson_options.txt mingw: allow `git.exe` to be used instead of the "Git wrapper" 2026-09-10 05:19:43 -07:00
midx-write.c
…
midx.c packfile: recover when a multi-pack-index names a removed pack 2026-08-30 13:37:42 -07:00
midx.h packfile: recover when a multi-pack-index names a removed pack 2026-08-30 13:37:42 -07:00
name-hash.c
…
name-hash.h
…
notes-cache.c
…
notes-cache.h
…
notes-merge.c
…
notes-merge.h
…
notes-utils.c
…
notes-utils.h
…
notes.c
…
notes.h
…
object-file-convert.c
…
object-file-convert.h
…
object-file.c Merge branch 'jt/receive-pack-pluggable-writes' 2026-08-31 08:25:00 -07:00
object-file.h
…
object-name.c Merge branch 'ps/odb-eagerly-load-alternates' 2026-08-31 08:24:59 -07:00
object-name.h
…
object.c
…
object.h
…
odb.c Merge branch 'ps/odb-pluggable-fsck' 2026-09-15 11:07:37 -07:00
odb.h Merge branch 'ps/odb-pluggable-fsck' 2026-09-15 11:07:37 -07:00
oid-array.c
…
oid-array.h
…
oidmap.c
…
oidmap.h
…
oidset.c
…
oidset.h
…
oidtree.c
…
oidtree.h
…
pack-bitmap-write.c
…
pack-bitmap.c builtin/fsck: move bitmap verification into the packed source 2026-09-11 09:14:44 -07:00
pack-bitmap.h builtin/fsck: move bitmap verification into the packed source 2026-09-11 09:14:44 -07:00
pack-check.c Merge branch 'js/pack-objects-delta-size-t' 2026-08-24 13:17:51 -07:00
pack-mtimes.c
…
pack-mtimes.h
…
pack-objects.c
…
pack-objects.h
…
pack-refs.c
…
pack-refs.h
…
pack-revindex.c
…
pack-revindex.h
…
pack-write.c
…
pack.h
…
packfile-list.c
…
packfile-list.h
…
packfile.c Merge branch 'ps/odb-eagerly-load-alternates' 2026-08-31 08:24:59 -07:00
packfile.h Merge branch 'ps/odb-eagerly-load-alternates' 2026-08-31 08:24:59 -07:00
pager.c
…
pager.h
…
parallel-checkout.c
…
parallel-checkout.h
…
parse-options-cb.c
…
parse-options.c
…
parse-options.h
…
parse.c
…
parse.h
…
patch-delta.c
…
patch-ids.c
…
patch-ids.h
…
path-walk.c
…
path-walk.h
…
path.c
…
path.h
…
pathspec.c Merge branch 'jc/pathspec-match-const' 2026-09-13 21:53:29 -07:00
pathspec.h pathspec: match and original in pathspec_item are const 2026-09-03 11:24:01 -07:00
pkt-line.c
…
pkt-line.h
…
preload-index.c
…
preload-index.h
…
pretty.c
…
pretty.h
…
prio-queue.c
…
prio-queue.h
…
progress.c
…
progress.h
…
promisor-remote.c
…
promisor-remote.h
…
prompt.c
…
prompt.h
…
protocol-caps.c
…
protocol-caps.h
…
protocol.c
…
protocol.h
…
prune-packed.c
…
prune-packed.h
…
pseudo-merge.c
…
pseudo-merge.h
…
quote.c
…
quote.h
…
range-diff.c
…
range-diff.h
…
reachable.c
…
reachable.h
…
read-cache-ll.h cache-tree: remove dependency on `the_repository` 2026-09-11 08:46:09 -07:00
read-cache.c cache-tree: remove dependency on `the_repository` 2026-09-11 08:46:09 -07:00
read-cache.h
…
rebase-interactive.c
…
rebase-interactive.h
…
rebase.c
…
rebase.h
…
ref-filter.c
…
ref-filter.h
…
reflog-walk.c
…
reflog-walk.h
…
reflog.c
…
reflog.h
…
refs.c
…
refs.h
…
refspec.c
…
refspec.h
…
remote-curl.c
…
remote.c
…
remote.h
…
repack-cruft.c
…
repack-filtered.c
…
repack-geometry.c
…
repack-midx.c
…
repack-promisor.c
…
repack.c
…
repack.h
…
replace-object.c
…
replace-object.h
…
replay.c Merge branch 'en/midx-missing-pack-fallback' 2026-09-10 05:36:17 -07:00
replay.h replay: offer an option to linearize the commit topology 2026-08-31 10:29:06 -07:00
repo-settings.c
…
repo-settings.h
…
repository.c Merge branch 'jk/submodule-error-leak' 2026-09-13 21:53:29 -07:00
repository.h
…
rerere.c builtin/maintenance: improve heuristic for "rerere gc" 2026-09-04 07:27:14 -07:00
rerere.h builtin/maintenance: improve heuristic for "rerere gc" 2026-09-04 07:27:14 -07:00
reset.c
…
reset.h
…
resolve-undo.c
…
resolve-undo.h
…
revision.c Merge branch 'jk/rev-info-argv-to-free' 2026-09-10 05:36:17 -07:00
revision.h revision: hang on to "freed" argv elements 2026-09-01 11:03:56 -07:00
run-command.c
…
run-command.h
…
sane-ctype.h
…
scalar.c
…
send-pack.c
…
send-pack.h
…
sequencer.c Revert "Merge branch 'en/no-amend-during-conflicts'" 2026-09-23 11:18:51 -07:00
sequencer.h Revert "Merge branch 'en/no-amend-during-conflicts'" 2026-09-23 11:18:51 -07:00
serve.c Merge branch 'en/serve-promisor-remote-fix' 2026-08-24 13:17:51 -07:00
serve.h
…
server-info.c
…
server-info.h
…
setup.c Merge branch 'yn/worktree-repair-relative' 2026-09-07 09:32:06 -07:00
setup.h worktree repair: detect relative path in .git file correctly 2026-08-28 10:22:04 -07:00
sh-i18n--envsubst.c
…
sha1dc_git.c
…
sha1dc_git.h
…
shallow.c
…
shallow.h
…
shared.mak
…
shell.c
…
shortlog.h
…
sideband.c
…
sideband.h
…
sigchain.c
…
sigchain.h
…
simple-ipc.h
…
sparse-index.c cache-tree: drop `the_repository` in `cache_tree_fully_valid()` 2026-09-11 08:46:09 -07:00
sparse-index.h
…
split-index.c
…
split-index.h
…
stable-qsort.c
…
stash.h stash: reserve exit status 1 for conflicts 2026-09-03 11:32:36 -07:00
statinfo.c
…
statinfo.h
…
strbuf.c
…
strbuf.h
…
string-list.c
…
string-list.h
…
strmap.c
…
strmap.h
…
strvec.c
…
strvec.h
…
sub-process.c
…
sub-process.h
…
submodule-config.c submodule-config: stop registering submodule sources 2026-09-11 08:46:10 -07:00
submodule-config.h submodule-config: remove uses of `the_repository` 2026-09-11 08:46:10 -07:00
submodule.c submodule-config: remove uses of `the_repository` 2026-09-11 08:46:10 -07:00
submodule.h
…
symlinks.c
…
symlinks.h
…
tag.c
…
tag.h
…
tar.h
…
tempfile.c
…
tempfile.h
…
thread-utils.c
…
thread-utils.h
…
tmp-objdir.c tmp-objdir: drop unused function to register alternate 2026-09-11 08:46:10 -07:00
tmp-objdir.h tmp-objdir: drop unused function to register alternate 2026-09-11 08:46:10 -07:00
trace.c
…
trace.h
…
trace2.c
…
trace2.h
…
trailer.c
…
trailer.h
…
transport-helper.c Merge branch 'js/coverity-unchecked-returns-fix' 2026-08-24 13:17:50 -07:00
transport-internal.h
…
transport.c
…
transport.h
…
tree-diff.c
…
tree-walk.c
…
tree-walk.h
…
tree.c
…
tree.h
…
unicode-width.h
…
unimplemented.sh
…
unix-socket.c
…
unix-socket.h
…
unix-stream-server.c
…
unix-stream-server.h
…
unpack-trees.c cache-tree: remove dependency on `the_repository` 2026-09-11 08:46:09 -07:00
unpack-trees.h
…
upload-pack.c
…
upload-pack.h
…
url.c
…
url.h
…
urlmatch.c
…
urlmatch.h
…
usage.c Merge branch 'jc/you-still-use-that' 2026-09-07 09:32:05 -07:00
userdiff.c
…
userdiff.h
…
utf8.c
…
utf8.h
…
varint.c
…
varint.h
…
version-def.h.in
…
version.c
…
version.h
…
versioncmp.c versioncmp: fix typo in versioncmp.c, t/t0022-crlf-rename.sh 2026-08-31 13:47:04 -07:00
versioncmp.h
…
walker.c
…
walker.h
…
wildmatch.c
…
wildmatch.h
…
worktree.c worktree repair: detect relative path in .git file correctly 2026-08-28 10:22:04 -07:00
worktree.h
…
wrapper.c
…
wrapper.h
…
write-or-die.c
…
write-or-die.h
…
ws.c
…
ws.h
…
wt-status.c
…
wt-status.h Revert "Merge branch 'en/no-amend-during-conflicts'" 2026-09-23 11:18:51 -07:00
xdiff-interface.c
…
xdiff-interface.h
…

README.md

GitHub build status GitLab build status

Git - fast, scalable, distributed revision control system

Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals.

Git is an Open Source project covered by the GNU General Public License version 2 (some parts of it are under different licenses, compatible with the GPLv2). It was originally written by Linus Torvalds with help of a group of hackers around the net.

Please read the file INSTALL for installation instructions.

Many Git online resources are accessible from https://git-scm.com/ including full documentation and Git related tools.

See Documentation/gittutorial.adoc to get started, then see Documentation/giteveryday.adoc for a useful minimum set of commands, and Documentation/git-<commandname>.adoc for documentation of each command. If git has been correctly installed, then the tutorial can also be read with man gittutorial or git help tutorial, and the documentation of each command with man git-<commandname> or git help <commandname>.

CVS users may also want to read Documentation/gitcvs-migration.adoc (man gitcvs-migration or git help cvs-migration if git is installed).

The user discussion and development of Git take place on the Git mailing list -- everyone is welcome to post bug reports, feature requests, comments and patches to git@vger.kernel.org (read Documentation/SubmittingPatches for instructions on patch submission and Documentation/CodingGuidelines).

Those wishing to help with error message, usage and informational message string translations (localization l10) should see po/README.md (a po file is a Portable Object file that holds the translations).

To subscribe to the list, send an email to git+subscribe@vger.kernel.org (see https://subspace.kernel.org/subscribing.html for details). The mailing list archives are available at https://lore.kernel.org/git/, https://marc.info/?l=git and other archival sites.

Issues which are security relevant should be disclosed privately to the Git Security mailing list git-security@googlegroups.com.

The maintainer frequently sends the "What's cooking" reports that list the current status of various development topics to the mailing list. The discussion following them give a good reference for project status, development direction and remaining tasks.

The name "git" was given by Linus Torvalds when he wrote the very first version. He described the tool as "the stupid content tracker" and the name as (depending on your mood):

  • random three-letter combination that is pronounceable, and not actually used by any common UNIX command. The fact that it is a mispronunciation of "get" may or may not be relevant.
  • stupid. contemptible and despicable. simple. Take your pick from the dictionary of slang.
  • "global information tracker": you're in a good mood, and it actually works for you. Angels sing, and a light suddenly fills the room.
  • "goddamn idiotic truckload of sh*t": when it breaks