Skip to content

Rebase shears/main: 4 conflict(s) (0 skipped, 4 resolved) (#23879956000)#81

Open
gitforwindowshelper[bot] wants to merge 287 commits intobase/shears/main-23879956000from
shears/main-23879956000
Open

Rebase shears/main: 4 conflict(s) (0 skipped, 4 resolved) (#23879956000)#81
gitforwindowshelper[bot] wants to merge 287 commits intobase/shears/main-23879956000from
shears/main-23879956000

Conversation

@gitforwindowshelper
Copy link
Copy Markdown

Workflow run

Rebase Summary: main

From: 4fe64dbc74 (Don't traverse mount points in remove_dir_recurse() (git-for-windows#6151), 2026-03-31) (b4cd1d3aef..4fe64dbc74)

Resolved: a3c8829 (http: use new "best effort" strategy for Secure Channel revoke checking, 2020-03-04)

replaced http_schannel_check_revoke with http_schannel_check_revoke_mode (best-effort Secure Channel revoke checking) while preserving upstream's new HTTP retry variables

Range-diff
  • 1: a3c8829 ! 1: 45ce214 http: use new "best effort" strategy for Secure Channel revoke checking

    @@ http.c: static char *cached_accept_language;
     +#else
     +	CURLSSLOPT_NO_REVOKE;
     +#endif
    -+
    - /*
    -  * With the backend being set to `schannel`, setting sslCAinfo would override
    -  * the Certificate Store in cURL v7.60.0 and later, which is not what we want
    + 
    + static long http_retry_after = 0;
    + static long http_max_retries = 0;
     @@ http.c: static int http_options(const char *var, const char *value,
      	}
      

Resolved: 9f34f45 (http: optionally send SSL client certificate, 2021-06-23)

kept both CURLINFO_RETRY_AFTER and CURLSSLOPT_AUTO_CLIENT_CERT defines in date order

Range-diff
  • 1: 9f34f45 ! 1: ae83585 http: optionally send SSL client certificate

    @@ Documentation/config/http.adoc: http.schannelUseSSLCAInfo::
     
      ## git-curl-compat.h ##
     @@
    - #define GIT_CURL_NEED_TRANSFER_ENCODING_HEADER
    + #define GIT_CURL_HAVE_CURLINFO_RETRY_AFTER 1
      #endif
      
     +/**
    @@ git-curl-compat.h
       * released in August 2022.
     
      ## http.c ##
    -@@ http.c: static long http_schannel_check_revoke_mode =
    +@@ http.c: static long http_max_retry_time = 300;
       */
      static int http_schannel_use_ssl_cainfo;
      

Resolved: f491146 (Merge branch 'disallow-ntlm-auth-by-default', 2026-02-12)

kept both upstream HTTP 429 retry additions and downstream NTLM auth additions in http.c and t/lib-httpd.sh

Range-diff
  • 1: f491146 ! 1: 72f281a Merge branch 'disallow-ntlm-auth-by-default'

    @@ Commit message
     
         Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
     
    - ## Documentation/config/http.adoc ##
    -@@ Documentation/config/http.adoc: http.sslKeyType::
    - 	See also libcurl `CURLOPT_SSLKEYTYPE`. Can be overridden by the
    - 	`GIT_SSL_KEY_TYPE` environment variable.
    - 
    -+http.allowNTLMAuth::
    -+	Whether or not to allow NTLM authentication. While very convenient to set
    -+	up, and therefore still used in many on-prem scenarios, NTLM is a weak
    -+	authentication method and therefore deprecated. Defaults to "false".
    -+
    - http.schannelCheckRevoke::
    - 	Used to enforce or disable certificate revocation checks in cURL
    - 	when http.sslBackend is set to "schannel" via "true" and "false",
    -
    - ## credential.c ##
    -@@ credential.c: int credential_read(struct credential *c, FILE *fp,
    - 				credential_set_capability(&c->capa_authtype, op_type);
    - 			else if (!strcmp(value, "state"))
    - 				credential_set_capability(&c->capa_state, op_type);
    -+		} else if (!strcmp(key, "ntlm")) {
    -+			if (!strcmp(value, "allow"))
    -+				c->ntlm_allow = 1;
    - 		} else if (!strcmp(key, "continue")) {
    - 			c->multistage = !!git_config_bool("continue", value);
    - 		} else if (!strcmp(key, "password_expiry_utc")) {
    -@@ credential.c: void credential_write(const struct credential *c, FILE *fp,
    - 		if (c->ephemeral)
    - 			credential_write_item(c, fp, "ephemeral", "1", 0);
    - 	}
    -+	if (c->ntlm_suppressed)
    -+		credential_write_item(c, fp, "ntlm", "suppressed", 0);
    - 	credential_write_item(c, fp, "protocol", c->protocol, 1);
    - 	credential_write_item(c, fp, "host", c->host, 1);
    - 	credential_write_item(c, fp, "path", c->path, 0);
    -
    - ## credential.h ##
    -@@ credential.h: struct credential {
    - 	struct credential_capability capa_authtype;
    - 	struct credential_capability capa_state;
    - 
    -+	unsigned ntlm_suppressed:1,
    -+		 ntlm_allow:1;
    -+
    - 	char *username;
    - 	char *password;
    - 	char *credential;
    -
      ## http.c ##
    -@@ http.c: enum http_follow_config http_follow_config = HTTP_FOLLOW_INITIAL;
    - 
    - static struct credential cert_auth = CREDENTIAL_INIT;
    - static int ssl_cert_password_required;
    --static unsigned long http_auth_methods = CURLAUTH_ANY;
    -+static unsigned long http_auth_any = CURLAUTH_ANY & ~CURLAUTH_NTLM;
    -+static unsigned long http_auth_methods;
    - static int http_auth_methods_restricted;
    - /* Modes for which empty_auth cannot actually help us. */
    - static unsigned long empty_auth_useless =
    -@@ http.c: static int http_options(const char *var, const char *value,
    - 		return 0;
    - 	}
    - 
    -+	if (!strcmp("http.allowntlmauth", var)) {
    -+		if (git_config_bool(var, value)) {
    -+			http_auth_any |= CURLAUTH_NTLM;
    -+		} else {
    -+			http_auth_any &= ~CURLAUTH_NTLM;
    -+		}
    -+		return 0;
    -+	}
    -+
    - 	if (!strcmp("http.schannelcheckrevoke", var)) {
    - 		if (value && !strcmp(value, "best-effort")) {
    - 			http_schannel_check_revoke_mode =
    -@@ http.c: static void init_curl_http_auth(CURL *result)
    - 
    - 	credential_fill(the_repository, &http_auth, 1);
    - 
    -+	if (http_auth.ntlm_allow && !(http_auth_methods & CURLAUTH_NTLM)) {
    -+		http_auth_methods |= CURLAUTH_NTLM;
    -+		curl_easy_setopt(result, CURLOPT_HTTPAUTH, http_auth_methods);
    -+	}
    -+
    - 	if (http_auth.password) {
    - 		if (always_auth_proactively()) {
    - 			/*
    -@@ http.c: static void init_curl_proxy_auth(CURL *result)
    - 		if (i == ARRAY_SIZE(proxy_authmethods)) {
    - 			warning("unsupported proxy authentication method %s: using anyauth",
    - 					http_proxy_authmethod);
    --			curl_easy_setopt(result, CURLOPT_PROXYAUTH, CURLAUTH_ANY);
    -+			curl_easy_setopt(result, CURLOPT_PROXYAUTH, http_auth_any);
    - 		}
    - 	}
    - 	else
    --		curl_easy_setopt(result, CURLOPT_PROXYAUTH, CURLAUTH_ANY);
    -+		curl_easy_setopt(result, CURLOPT_PROXYAUTH, http_auth_any);
    - }
    - 
    - static int has_cert_password(void)
    -@@ http.c: static CURL *get_curl_handle(void)
    -     }
    - 
    - 	curl_easy_setopt(result, CURLOPT_NETRC, CURL_NETRC_OPTIONAL);
    --	curl_easy_setopt(result, CURLOPT_HTTPAUTH, CURLAUTH_ANY);
    -+	curl_easy_setopt(result, CURLOPT_HTTPAUTH, http_auth_any);
    - 
    - #ifdef CURLGSSAPI_DELEGATION_FLAG
    - 	if (curl_deleg) {
    + remerge CONFLICT (content): Merge conflict in http.c
    + index 1ab7e20d41..d568abd13b 100644
    + --- http.c
    + +++ http.c
     @@ http.c: void http_init(struct remote *remote, const char *url, int proactive_auth)
      	set_long_from_env(&curl_tcp_keepintvl, "GIT_TCP_KEEPINTVL");
      	set_long_from_env(&curl_tcp_keepcnt, "GIT_TCP_KEEPCNT");
      
    -+	http_auth_methods = http_auth_any;
    +-<<<<<<< cfdc713289 (Merge 'readme' into HEAD)
    + 	set_long_from_env(&http_retry_after, "GIT_HTTP_RETRY_AFTER");
    + 	set_long_from_env(&http_max_retries, "GIT_HTTP_MAX_RETRIES");
    + 	set_long_from_env(&http_max_retry_time, "GIT_HTTP_MAX_RETRY_TIME");
    +-=======
     +
    + 	http_auth_methods = http_auth_any;
    +->>>>>>> 816db62d10 (credential: advertise NTLM suppression and allow helpers to re-enable)
    + 
      	curl_default = get_curl_handle();
      }
    - 
    -@@ http.c: static int handle_curl_result(struct slot_results *results)
    - 	} else if (missing_target(results))
    - 		return HTTP_MISSING_TARGET;
    - 	else if (results->http_code == 401) {
    -+		http_auth.ntlm_suppressed = (results->auth_avail & CURLAUTH_NTLM) &&
    -+					    !(http_auth_any & CURLAUTH_NTLM);
    -+		if (http_auth.ntlm_suppressed && http_auth.ntlm_allow) {
    -+			http_auth_methods |= CURLAUTH_NTLM;
    -+			return HTTP_REAUTH;
    -+		}
    - 		if ((http_auth.username && http_auth.password) ||\
    - 		    (http_auth.authtype && http_auth.credential)) {
    - 			if (http_auth.multistage) {
    -@@ http.c: static int handle_curl_result(struct slot_results *results)
    - 			credential_reject(the_repository, &http_auth);
    - 			if (always_auth_proactively())
    - 				http_proactive_auth = PROACTIVE_AUTH_NONE;
    -+			if (http_auth.ntlm_suppressed) {
    -+				warning(_("Due to its cryptographic weaknesses, "
    -+					  "NTLM authentication has been\n"
    -+					  "disabled in Git by default. You can "
    -+					  "re-enable it for trusted servers\n"
    -+					  "by running:\n\n"
    -+					  "git config set "
    -+					  "http.%s://%s.allowNTLMAuth true"),
    -+					http_auth.protocol, http_auth.host);
    -+			}
    - 			return HTTP_NOAUTH;
    - 		} else {
    - 			http_auth_methods &= ~CURLAUTH_GSSNEGOTIATE;
     
      ## t/lib-httpd.sh ##
    + remerge CONFLICT (content): Merge conflict in t/lib-httpd.sh
    + index 5e304f2eba..7150a2a2f2 100644
    + --- t/lib-httpd.sh
    + +++ t/lib-httpd.sh
     @@ t/lib-httpd.sh: prepare_httpd() {
      	install_script error.sh
      	install_script apply-one-time-script.sh
      	install_script nph-custom-auth.sh
    -+	install_script ntlm-handshake.sh
    +-<<<<<<< cfdc713289 (Merge 'readme' into HEAD)
    + 	install_script http-429.sh
    +-=======
    + 	install_script ntlm-handshake.sh
    +->>>>>>> 816db62d10 (credential: advertise NTLM suppression and allow helpers to re-enable)
      
      	ln -s "$LIB_HTTPD_MODULE_PATH" "$HTTPD_ROOT_PATH/modules"
      
    -
    - ## t/lib-httpd/apache.conf ##
    -@@ t/lib-httpd/apache.conf: SetEnv PERL_PATH ${PERL_PATH}
    - 	CGIPassAuth on
    - 	</IfDefine>
    - </LocationMatch>
    -+<LocationMatch /ntlm_auth/>
    -+	SetEnv GIT_EXEC_PATH ${GIT_EXEC_PATH}
    -+	SetEnv GIT_HTTP_EXPORT_ALL
    -+	<IfDefine USE_CGIPASSAUTH>
    -+	CGIPassAuth on
    -+	</IfDefine>
    -+</LocationMatch>
    - ScriptAlias /smart/incomplete_length/git-upload-pack incomplete-length-upload-pack-v2-http.sh/
    - ScriptAlias /smart/incomplete_body/git-upload-pack incomplete-body-upload-pack-v2-http.sh/
    - ScriptAlias /smart/no_report/git-receive-pack error-no-report.sh/
    -@@ t/lib-httpd/apache.conf: ScriptAlias /error_smart/ error-smart-http.sh/
    - ScriptAlias /error/ error.sh/
    - ScriptAliasMatch /one_time_script/(.*) apply-one-time-script.sh/$1
    - ScriptAliasMatch /custom_auth/(.*) nph-custom-auth.sh/$1
    -+ScriptAliasMatch /ntlm_auth/(.*) ntlm-handshake.sh/$1
    - <Directory ${GIT_EXEC_PATH}>
    - 	Options FollowSymlinks
    - </Directory>
    -
    - ## t/lib-httpd/ntlm-handshake.sh (new) ##
    -@@
    -+#!/bin/sh
    -+
    -+case "$HTTP_AUTHORIZATION" in
    -+'')
    -+	# No Authorization header -> send NTLM challenge
    -+	echo "Status: 401 Unauthorized"
    -+	echo "WWW-Authenticate: NTLM"
    -+	echo
    -+	;;
    -+"NTLM TlRMTVNTUAAB"*)
    -+	# Type 1 -> respond with Type 2 challenge (hardcoded)
    -+	echo "Status: 401 Unauthorized"
    -+	# Base64-encoded version of the Type 2 challenge:
    -+	# signature: 'NTLMSSP\0'
    -+	# message_type: 2
    -+	# target_name: 'NTLM-GIT-SERVER'
    -+	# flags: 0xa2898205 =
    -+	#   NEGOTIATE_UNICODE, REQUEST_TARGET, NEGOTIATE_NT_ONLY,
    -+	#   TARGET_TYPE_SERVER, TARGET_TYPE_SHARE, REQUEST_NON_NT_SESSION_KEY,
    -+	#   NEGOTIATE_VERSION, NEGOTIATE_128, NEGOTIATE_56
    -+	# challenge: 0xfa3dec518896295b
    -+	# context: '0000000000000000'
    -+	# target_info_present: true
    -+	# target_info_len: 128
    -+	# version: '10.0 (build 19041)'
    -+	echo "WWW-Authenticate: NTLM TlRMTVNTUAACAAAAHgAeADgAAAAFgomi+j3sUYiWKVsAAAAAAAAAAIAAgABWAAAACgBhSgAAAA9OAFQATABNAC0ARwBJAFQALQBTAEUAUgBWAEUAUgACABIAVwBPAFIASwBHAFIATwBVAFAAAQAeAE4AVABMAE0ALQBHAEkAVAAtAFMARQBSAFYARQBSAAQAEgBXAE8AUgBLAEcAUgBPAFUAUAADAB4ATgBUAEwATQAtAEcASQBUAC0AUwBFAFIAVgBFAFIABwAIAACfOcZKYNwBAAAAAA=="
    -+	echo
    -+	;;
    -+"NTLM TlRMTVNTUAAD"*)
    -+	# Type 3 -> accept without validation
    -+	exec "$GIT_EXEC_PATH"/git-http-backend
    -+	;;
    -+*)
    -+	echo "Status: 500 Unrecognized"
    -+	echo
    -+	echo "Unhandled auth: '$HTTP_AUTHORIZATION'"
    -+	;;
    -+esac
    -
    - ## t/t5563-simple-http-auth.sh ##
    -@@ t/t5563-simple-http-auth.sh: test_expect_success 'access using three-legged auth' '
    - 	EOF
    - '
    - 
    -+test_lazy_prereq NTLM 'curl --version | grep -q NTLM'
    -+
    -+test_expect_success NTLM 'access using NTLM auth' '
    -+	test_when_finished "per_test_cleanup" &&
    -+
    -+	set_credential_reply get <<-EOF &&
    -+	username=user
    -+	password=pwd
    -+	EOF
    -+
    -+	test_config_global credential.helper test-helper &&
    -+	test_must_fail env GIT_TRACE_CURL=1 git \
    -+		ls-remote "$HTTPD_URL/ntlm_auth/repo.git" 2>err &&
    -+	test_grep "allowNTLMAuth" err &&
    -+
    -+	# Can be enabled via config
    -+	GIT_TRACE_CURL=1 git -c http.$HTTPD_URL.allowNTLMAuth=true \
    -+		ls-remote "$HTTPD_URL/ntlm_auth/repo.git" &&
    -+
    -+	# Or via credential helper responding with ntlm=allow
    -+	set_credential_reply get <<-EOF &&
    -+	username=user
    -+	password=pwd
    -+	ntlm=allow
    -+	EOF
    -+
    -+	git ls-remote "$HTTPD_URL/ntlm_auth/repo.git"
    -+'
    -+
    - test_done

Resolved: ec87da9 (mingw: use strftime() directly in UCRT builds (git-for-windows#6130), 2026-03-25)

took HEAD's version for all 5 files since the topic branch does not modify any of them; conflicts were from upstream evolution only

Range-diff
  • 1: ec87da9 ! 1: 53737c7 mingw: use strftime() directly in UCRT builds (mingw: use strftime() directly in UCRT builds git#6130)

    @@ Commit message
         since ec47a33fd2c3b679c3d8cbd440752414adb56ce9, i.e. for a _really_ long
         time.
     
    - ## Documentation/git-svn.adoc ##
    -@@ Documentation/git-svn.adoc: SYNOPSIS
    - --------
    - [verse]
    - 'git svn' <command> [<options>] [<arguments>]
    -+(UNSUPPORTED!)
    - 
    - DESCRIPTION
    - -----------
    + ## builtin/reset.c ##
    + remerge CONFLICT (content): Merge conflict in builtin/reset.c
    + index e7f85f51b6..1cd7e61fe4 100644
    + --- builtin/reset.c
    + +++ builtin/reset.c
    +@@ builtin/reset.c: int cmd_reset(int argc,
    + 	struct object_id oid;
    + 	struct pathspec pathspec;
    + 	int intent_to_add = 0;
    +-<<<<<<< 973552e1b8 (`git svn`: remove deprecation note (since it is no longer included in Git for Windows, anyway) (#6142))
    + 	struct interactive_options interactive_opts = INTERACTIVE_OPTIONS_INIT;
    +-=======
    +-	struct add_p_opt add_p_opt = ADD_P_OPT_INIT;
    +->>>>>>> 1253fdbf0c (mingw: use strftime() directly in UCRT builds)
    + 	int nul_term_line = 0, read_from_stdin = 0;
    + 	const struct option options[] = {
    + 		OPT__QUIET(&quiet, N_("be quiet, only report errors")),
     
    - ## compat/mingw.c ##
    -@@ compat/mingw.c: int mingw_utime (const char *file_name, const struct utimbuf *times)
    - size_t mingw_strftime(char *s, size_t max,
    - 		      const char *format, const struct tm *tm)
    - {
    -+#ifdef _UCRT
    -+	size_t ret = strftime(s, max, format, tm);
    -+#else
    - 	/* a pointer to the original strftime in case we can't find the UCRT version */
    - 	static size_t (*fallback)(char *, size_t, const char *, const struct tm *) = strftime;
    - 	size_t ret;
    -@@ compat/mingw.c: size_t mingw_strftime(char *s, size_t max,
    - 		ret = strftime(s, max, format, tm);
    - 	else
    - 		ret = fallback(s, max, format, tm);
    -+#endif
    + ## git-curl-compat.h ##
    + remerge CONFLICT (content): Merge conflict in git-curl-compat.h
    + index e3f97c4fe6..5c8ceb076a 100644
    + --- git-curl-compat.h
    + +++ git-curl-compat.h
    +@@
    + #endif
      
    - 	if (!ret && errno == EINVAL)
    - 		die("invalid strftime format: '%s'", format);
    -
    - ## git-svn.perl ##
    -@@ git-svn.perl: sub term_init {
    - 			: new Term::ReadLine 'git-svn';
    - }
    + /**
    +-<<<<<<< 973552e1b8 (`git svn`: remove deprecation note (since it is no longer included in Git for Windows, anyway) (#6142))
    +  * CURLINFO_RETRY_AFTER was added in 7.66.0, released in September 2019.
    +  * It allows curl to automatically parse Retry-After headers.
    +  */
    +@@
    + #endif
      
    -+sub deprecated_warning {
    -+    my @lines = @_;
    -+    if (-t STDERR) {
    -+        @lines = map { "\e[33m$_\e[0m" } @lines;
    -+    }
    -+    warn join("\n", @lines), "\n";
    -+}
    -+
    -+deprecated_warning(
    -+	"WARNING: \`git svn\` is no longer supported by the Git for Windows project.",
    -+	"See https://github.com/git-for-windows/git/issues/5405 for details."
    -+);
    -+
    - my $cmd;
    - for (my $i = 0; $i < @ARGV; $i++) {
    - 	if (defined $cmd{$ARGV[$i]}) {
    + /**
    +-=======
    +->>>>>>> 1253fdbf0c (mingw: use strftime() directly in UCRT builds)
    +  * CURLSSLOPT_AUTO_CLIENT_CERT was added in 7.77.0, released in May
    +  * 2021.
    +  */
     
    - ## t/t9108-git-svn-glob.sh ##
    -@@ t/t9108-git-svn-glob.sh: test_expect_success 'test disallow multi-globs' '
    - 		svn_cmd commit -m "try to try"
    - 	) &&
    - 	test_must_fail git svn fetch three 2> stderr.three &&
    --	test_cmp expect.three stderr.three
    -+	sed "/^WARNING.*no.* supported/{N;d}" <stderr.three >stderr.three.clean &&
    -+	test_cmp expect.three stderr.three.clean
    - 	'
    + ## http.c ##
    + remerge CONFLICT (content): Merge conflict in http.c
    + index 914b2eea0c..5bc2ad8b87 100644
    + --- http.c
    + +++ http.c
    +@@ http.c: static long http_schannel_check_revoke_mode =
    + 	CURLSSLOPT_NO_REVOKE;
    + #endif
      
    - test_done
    -
    - ## t/t9109-git-svn-multi-glob.sh ##
    -@@ t/t9109-git-svn-multi-glob.sh: test_expect_success 'test disallow multiple globs' '
    - 		svn_cmd commit -m "try to try"
    - 	) &&
    - 	test_must_fail git svn fetch three 2> stderr.three &&
    --	test_cmp expect.three stderr.three
    -+	sed "/^WARNING.*no.* supported/{N;d}" <stderr.three >stderr.three.clean &&
    -+	test_cmp expect.three stderr.three.clean
    - 	'
    +-<<<<<<< 973552e1b8 (`git svn`: remove deprecation note (since it is no longer included in Git for Windows, anyway) (#6142))
    + static long http_retry_after = 0;
    + static long http_max_retries = 0;
    + static long http_max_retry_time = 300;
      
    - test_done
    +-=======
    +->>>>>>> 1253fdbf0c (mingw: use strftime() directly in UCRT builds)
    + /*
    +  * With the backend being set to `schannel`, setting sslCAinfo would override
    +  * the Certificate Store in cURL v7.60.0 and later, which is not what we want
     
    - ## t/t9168-git-svn-partially-globbed-names.sh ##
    -@@ t/t9168-git-svn-partially-globbed-names.sh: test_expect_success 'test disallow prefixed multi-globs' '
    - 		svn_cmd commit -m "try to try"
    - 	) &&
    - 	test_must_fail git svn fetch four 2>stderr.four &&
    --	test_cmp expect.four stderr.four &&
    -+	sed "/^WARNING.*no.* supported/{N;d}" <stderr.four >stderr.four.clean &&
    -+	test_cmp expect.four stderr.four.clean &&
    - 	git config --unset svn-remote.four.branches &&
    - 	git config --unset svn-remote.four.tags
    - 	'
    -@@ t/t9168-git-svn-partially-globbed-names.sh: test_expect_success 'test disallow multiple asterisks in one word' '
    - 		svn_cmd commit -m "try to try"
    - 	) &&
    - 	test_must_fail git svn fetch six 2>stderr.six &&
    --	test_cmp expect.six stderr.six
    -+	sed "/^WARNING.*no.* supported/{N;d}" <stderr.six >stderr.six.clean &&
    -+	test_cmp expect.six stderr.six.clean
    - 	'
    + ## refs/reftable-backend.c ##
    + remerge CONFLICT (content): Merge conflict in refs/reftable-backend.c
    + index cf837733b8..23b18837c8 100644
    + --- refs/reftable-backend.c
    + +++ refs/reftable-backend.c
    +@@ refs/reftable-backend.c: static struct ref_store *reftable_be_init(struct repository *repo,
    + 	mask = umask(0);
    + 	umask(mask);
      
    - test_done
    +-<<<<<<< 973552e1b8 (`git svn`: remove deprecation note (since it is no longer included in Git for Windows, anyway) (#6142))
    + 	refs_compute_filesystem_location(gitdir, payload, &is_worktree, &refdir,
    + 					 &ref_common_dir);
    + 
    + 	reftable_set_alloc(malloc, realloc, free);
    + 	base_ref_store_init(&refs->base, repo, refdir.buf, &refs_be_reftable);
    +-=======
    +-	reftable_set_alloc(malloc, realloc, free);
    +-	base_ref_store_init(&refs->base, repo, gitdir, &refs_be_reftable);
    +->>>>>>> 1253fdbf0c (mingw: use strftime() directly in UCRT builds)
    + 	strmap_init(&refs->worktree_backends);
    + 	refs->store_flags = store_flags;
    + 	refs->log_all_ref_updates = repo_settings_get_log_all_ref_updates(repo);
    +
    + ## t/meson.build ##
    + remerge CONFLICT (content): Merge conflict in t/meson.build
    + index d7118cd1ab..81591f64bf 100644
    + --- t/meson.build
    + +++ t/meson.build
    +@@ t/meson.build: integration_tests = [
    +   't7422-submodule-output.sh',
    +   't7423-submodule-symlinks.sh',
    +   't7424-submodule-mixed-ref-formats.sh',
    +-<<<<<<< 973552e1b8 (`git svn`: remove deprecation note (since it is no longer included in Git for Windows, anyway) (#6142))
    +   't7425-submodule-gitdir-path-extension.sh',
    +   't7426-submodule-get-default-remote.sh',
    +-=======
    +->>>>>>> 1253fdbf0c (mingw: use strftime() directly in UCRT builds)
    +   't7429-submodule-long-path.sh',
    +   't7450-bad-git-dotfiles.sh',
    +   't7500-commit-template-squash-signoff.sh',

To: 8279c02a0f (Don't traverse mount points in remove_dir_recurse() (git-for-windows#6151), 2026-03-31) (30ae3040ec..8279c02a0f)

Statistics

Metric Count
Total conflicts 4
Skipped (upstreamed) 0
Resolved surgically 4
Range-diff (click to expand)

jglathe and others added 30 commits April 2, 2026 02:10
For some reason, this test case was indented with 4 spaces instead of 1
horizontal tab. The other test cases in the same test script are fine.

Signed-off-by: Jens Glathe <jens.glathe@oldschoolsolutions.biz>
Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
As of Git v2.28.0, the diff for files staged via `git add -N` marks them
as new files. Git GUI was ill-prepared for that, and this patch teaches
Git GUI about them.

Please note that this will not even fix things with v2.28.0, as the
`rp/apply-cached-with-i-t-a` patches are required on Git's side, too.

This fixes git-for-windows#2779

Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
Signed-off-by: Pratyush Yadav <me@yadavpratyush.com>
The vcpkg downloads may not succeed. Warn careful readers of the time out.

A simple retry will usually resolve the issue.

Signed-off-by: Philip Oakley <philipoakley@iee.email>
Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
Signed-off-by: Dennis Ameling <dennis@dennisameling.com>
Git's regular Makefile mentions that HOST_CPU should be defined when cross-compiling Git: https://github.com/git-for-windows/git/blob/37796bca76ef4180c39ee508ca3e42c0777ba444/Makefile#L438-L439

This is then used to set the GIT_HOST_CPU variable when compiling Git: https://github.com/git-for-windows/git/blob/37796bca76ef4180c39ee508ca3e42c0777ba444/Makefile#L1337-L1341

Then, when the user runs `git version --build-options`, it returns that value: https://github.com/git-for-windows/git/blob/37796bca76ef4180c39ee508ca3e42c0777ba444/help.c#L658

This commit adds the same functionality to the CMake configuration. Users can now set -DHOST_CPU= to set the target architecture.

Signed-off-by: Dennis Ameling <dennis@dennisameling.com>
As reported in newren/git-filter-repo#225, it
looks like 99 bytes is not really sufficient to represent e.g. the full
path to Python when installed via Windows Store (and this path is used
in the hasb bang line when installing scripts via `pip`).

Let's increase it to what is probably the maximum sensible path size:
MAX_PATH. This makes `parse_interpreter()` in line with what
`lookup_prog()` handles.

Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
Signed-off-by: Vilius Šumskas <vilius@sumskas.eu>
We used to have that `make vcxproj` hack, but a hack it is. In the
meantime, we have a much cleaner solution: using CMake, either
explicitly, or even more conveniently via Visual Studio's built-in CMake
support (simply open Git's top-level directory via File>Open>Folder...).

Let's let the `README` reflect this.

Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
This is no longer true in general, not with supporting Clang out of the
box.

Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
This option was added in fa93bb2 (MinGW: Fix stat definitions to
work with MinGW runtime version 4.0, 2013-09-11), i.e. a _long_ time
ago. So long, in fact, that it still targeted MinGW. But we switched to
mingw-w64 in 2015, which seems not to share the problem, and therefore
does not require a fix.

Even worse: This flag is incompatible with UCRT64, which we are about to
support by way of upstreaming `mingw-w64-git` to the MSYS2 project, see
msys2/MINGW-packages#26470 for details.

So let's send that option into its well-deserved retirement.

Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
That option only matters there, and is in fact only really understood in
those builds; UCRT64 versions of GCC, for example, do not know what to
do with that option.

Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
On LLP64 systems, such as Windows, the size of `long`, `int`, etc. is
only 32 bits (for backward compatibility). Git's use of `unsigned long`
for file memory sizes in many places, rather than size_t, limits the
handling of large files on LLP64 systems (commonly given as `>4GB`).

Provide a minimum test for handling a >4GB file. The `hash-object`
command, with the  `--literally` and without `-w` option avoids
writing the object, either loose or packed. This avoids the code paths
hitting the `bigFileThreshold` config test code, the zlib code, and the
pack code.

Subsequent patches will walk the test's call chain, converting types to
`size_t` (which is larger in LLP64 data models) where appropriate.

Signed-off-by: Philip Oakley <philipoakley@iee.email>
Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
In bf2d5d8 (Don't let ld strip relocations, 2016-01-16) (picked from
git-for-windows@6a237925bf10),
Git for Windows introduced the `-Wl,-pic-executable` flag, specifying
the exact entry point via `-e`. This required discerning between i686
and x86_64 code because the former required the symbol to be prefixed
with an underscore, the latter did not.

As per https://sourceware.org/bugzilla/show_bug.cgi?id=10865, the
specified symbols are already the default, though.

So let's drop the overly-specific definition.

Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
Continue walking the code path for the >4GB `hash-object --literally`
test. The `hash_object_file_literally()` function internally uses both
`hash_object_file()` and `write_object_file_prepare()`. Both function
signatures use `unsigned long` rather than `size_t` for the mem buffer
sizes. Use `size_t` instead, for LLP64 compatibility.

While at it, convert those function's object's header buffer length to
`size_t` for consistency. The value is already upcast to `uintmax_t` for
print format compatibility.

Note: The hash-object test still does not pass. A subsequent commit
continues to walk the call tree's lower level hash functions to identify
further fixes.

Signed-off-by: Philip Oakley <philipoakley@iee.email>
Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
MSYS2 already defines a couple of helpful environment variables, and we
can use those to infer the installation location as well as the CPU. No
need for hard-coding ;-)

Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
Correct some wording and inform users regarding the Visual Studio
changes (from V16.6) to the default generator.

Subsequent commits ensure that Git for Windows can be directly
opened in modern Visual Studio without needing special configuration
of the CMakeLists settings.

It appeares that internally Visual Studio creates it's own version of the
.sln file (etc.) for extension tools that expect them.

The large number of references below document the shifting of Visual Studio
default and CMake setting options.

refs: https://docs.microsoft.com/en-us/search/?scope=C%2B%2B&view=msvc-150&terms=Ninja

1. https://docs.microsoft.com/en-us/cpp/linux/cmake-linux-configure?view=msvc-160
(note the linux bit)
 "In Visual Studio 2019 version 16.6 or later ***, Ninja is the default
generator for configurations targeting a remote system or WSL. For more
information, see this post on the C++ Team Blog
[https://devblogs.microsoft.com/cppblog/linux-development-with-visual-studio-first-class-support-for-gdbserver-improved-build-times-with-ninja-and-updates-to-the-connection-manager/].

For more information about these settings, see CMakeSettings.json reference
[https://docs.microsoft.com/en-us/cpp/build/cmakesettings-reference?view=msvc-160]."

2. https://docs.microsoft.com/en-us/cpp/build/cmake-presets-vs?view=msvc-160
"CMake supports two files that allow users to specify common configure,
build, and test options and share them with others: CMakePresets.json
and CMakeUserPresets.json."

" Both files are supported in Visual Studio 2019 version 16.10 or later.
***"
3. https://devblogs.microsoft.com/cppblog/linux-development-with-visual-studio-first-class-support-for-gdbserver-improved-build-times-with-ninja-and-updates-to-the-connection-manager/
" Ninja has been the default generator (underlying build system) for
CMake configurations targeting Windows for some time***, but in Visual
Studio 2019 version 16.6 Preview 3*** we added support for Ninja on Linux."

4. https://docs.microsoft.com/en-us/cpp/build/cmakesettings-reference?view=msvc-160
" `generator`: specifies CMake generator to use for this configuration.
May be one of:

    Visual Studio 2019 only:
        Visual Studio 16 2019
        Visual Studio 16 2019 Win64
        Visual Studio 16 2019 ARM

    Visual Studio 2017 and later:
        Visual Studio 15 2017
        Visual Studio 15 2017 Win64
        Visual Studio 15 2017 ARM
        Visual Studio 14 2015
        Visual Studio 14 2015 Win64
        Visual Studio 14 2015 ARM
        Unix Makefiles
        Ninja

Because Ninja is designed for fast build speeds instead of flexibility
and function, it is set as the default. However, some CMake projects may
be unable to correctly build using Ninja. If this occurs, you can
instruct CMake to generate Visual Studio projects instead.

To specify a Visual Studio generator in Visual Studio 2017, open the
settings editor from the main menu by choosing CMake | Change CMake
Settings. Delete "Ninja" and type "V". This activates IntelliSense,
which enables you to choose the generator you want."

"To specify a Visual Studio generator in Visual Studio 2019, right-click
on the CMakeLists.txt file in Solution Explorer and choose CMake
Settings for project > Show Advanced Settings > CMake Generator.

When the active configuration specifies a Visual Studio generator, by
default MSBuild.exe is invoked with` -m -v:minimal` arguments."

5. https://docs.microsoft.com/en-us/cpp/build/cmake-presets-vs?view=msvc-160#enable-cmakepresetsjson-integration-in-visual-studio-2019
"Enable CMakePresets.json integration in Visual Studio 2019

CMakePresets.json integration isn't enabled by default in Visual Studio
2019. You can enable it for all CMake projects in Tools > Options >
CMake > General: (tick a box)" ... see more.

6. https://docs.microsoft.com/en-us/cpp/build/cmakesettings-reference?view=msvc-140
(whichever v140 is..)
"CMake projects are supported in Visual Studio 2017 and later."

7. https://docs.microsoft.com/en-us/cpp/overview/what-s-new-for-cpp-2017?view=msvc-150
"Support added for the CMake Ninja generator."

8. https://docs.microsoft.com/en-us/cpp/overview/what-s-new-for-cpp-2017?view=msvc-150#cmake-support-via-open-folder
"CMake support via Open Folder
Visual Studio 2017 introduces support for using CMake projects without
converting to MSBuild project files (.vcxproj). For more information,
see CMake projects in Visual
Studio[https://docs.microsoft.com/en-us/cpp/build/cmake-projects-in-visual-studio?view=msvc-150].
Opening CMake projects with Open Folder automatically configures the
environment for C++ editing, building, and debugging." ... +more!

9. https://docs.microsoft.com/en-us/cpp/build/cmake-presets-vs?view=msvc-160#supported-cmake-and-cmakepresetsjson-versions
"Visual Studio reads and evaluates CMakePresets.json and
CMakeUserPresets.json itself and doesn't invoke CMake directly with the
--preset option. So, CMake version 3.20 or later isn't strictly required
when you're building with CMakePresets.json inside Visual Studio. We
recommend using CMake version 3.14 or later."

10. https://docs.microsoft.com/en-us/cpp/build/cmake-presets-vs?view=msvc-160#enable-cmakepresetsjson-integration-in-visual-studio-2019
"If you don't want to enable CMakePresets.json integration for all CMake
projects, you can enable CMakePresets.json integration for a single
CMake project by adding a CMakePresets.json file to the root of the open
folder. You must close and reopen the folder in Visual Studio to
activate the integration.

11. https://docs.microsoft.com/en-us/cpp/build/cmake-presets-vs?view=msvc-160#default-configure-presets
***(doesn't actually say which version..)
"Default Configure Presets
If no CMakePresets.json or CMakeUserPresets.json file exists, or if
CMakePresets.json or CMakeUserPresets.json is invalid, Visual Studio
will fall back*** on the following default Configure Presets:

Windows example
JSON
{
  "name": "windows-default",
  "displayName": "Windows x64 Debug",
  "description": "Sets Ninja generator, compilers, x64 architecture,
build and install directory, debug build type",
  "generator": "Ninja",
  "binaryDir": "${sourceDir}/out/build/${presetName}",
  "architecture": {
    "value": "x64",
    "strategy": "external"
  },
  "cacheVariables": {
    "CMAKE_BUILD_TYPE": "Debug",
    "CMAKE_INSTALL_PREFIX": "${sourceDir}/out/install/${presetName}"
  },
  "vendor": {
    "microsoft.com/VisualStudioSettings/CMake/1.0": {
      "hostOS": [ "Windows" ]
    }
  }
},
"

Signed-off-by: Philip Oakley <philipoakley@iee.email>
Continue walking the code path for the >4GB `hash-object --literally`
test to the hash algorithm step for LLP64 systems.

This patch lets the SHA1DC code use `size_t`, making it compatible with
LLP64 data models (as used e.g. by Windows).

The interested reader of this patch will note that we adjust the
signature of the `git_SHA1DCUpdate()` function without updating _any_
call site. This certainly puzzled at least one reviewer already, so here
is an explanation:

This function is never called directly, but always via the macro
`platform_SHA1_Update`, which is usually called via the macro
`git_SHA1_Update`. However, we never call `git_SHA1_Update()` directly
in `struct git_hash_algo`. Instead, we call `git_hash_sha1_update()`,
which is defined thusly:

    static void git_hash_sha1_update(git_hash_ctx *ctx,
                                     const void *data, size_t len)
    {
        git_SHA1_Update(&ctx->sha1, data, len);
    }

i.e. it contains an implicit downcast from `size_t` to `unsigned long`
(before this here patch). With this patch, there is no downcast anymore.

With this patch, finally, the t1007-hash-object.sh "files over 4GB hash
literally" test case is fixed.

Signed-off-by: Philip Oakley <philipoakley@iee.email>
Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
The tell-tale is the presence of the `MSYSTEM` value while compiling, of
course. In that case, we want to ensure that `MSYSTEM` is set when
running `git.exe`, and also enable the magic MSYS2 tty detection.

Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
The CMakeSettings.json file is tool generated. Developers may track it
should they provide additional settings.

Signed-off-by: Philip Oakley <philipoakley@iee.email>
Just like the `hash-object --literally` code path, the `--stdin` code
path also needs to use `size_t` instead of `unsigned long` to represent
memory sizes, otherwise it would cause problems on platforms using the
LLP64 data model (such as Windows).

To limit the scope of the test case, the object is explicitly not
written to the object store, nor are any filters applied.

The `big` file from the previous test case is reused to save setup time;
To avoid relying on that side effect, it is generated if it does not
exist (e.g. when running via `sh t1007-*.sh --long --run=1,41`).

Signed-off-by: Philip Oakley <philipoakley@iee.email>
Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
MSYS2 defines some helpful environment variables, e.g. `MSYSTEM`. There
is code in Git for Windows to ensure that that `MSYSTEM` variable is
set, hard-coding a default.

However, the existing solution jumps through hoops to reconstruct the
proper default, and is even incomplete doing so, as we found out when we
extended it to support CLANGARM64.

This is absolutely unnecessary because there is already a perfectly
valid `MSYSTEM` value we can use at build time. This is even true when
building the MINGW32 variant on a MINGW64 system because `makepkg-mingw`
will override the `MSYSTEM` value as per the `MINGW_ARCH` array.

The same is equally true for the `/mingw64`, `/mingw32` and
`/clangarm64` prefix: those values are already available via the
`MINGW_PREFIX` environment variable, and we just need to pass that
setting through.

Only when `MINGW_PREFIX` is not set (as is the case in Git for Windows'
minimal SDK, where only `MSYSTEM` is guaranteed to be set correctly), we
use as fall-back the top-level directory whose name is the down-cased
value of the `MSYSTEM` variable.

Incidentally, this also broadens the support to all the configurations
supported by the MSYS2 project, i.e. clang64 & ucrt64, too.

Note: This keeps the same, hard-coded MSYSTEM platform support for CMake
as before, but drops it for Meson (because it is unclear how Meson could
do this in a more flexible manner).

Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
A change between versions 2.4.1 and 2.6.0 of the MSYS2 runtime modified
how Cygwin's runtime (and hence Git for Windows' MSYS2 runtime
derivative) handles locales: d16a56306d (Consolidate wctomb/mbtowc calls
for POSIX-1.2008, 2016-07-20).

An unintended side-effect is that "cold-calling" into the POSIX
emulation will start with a locale based on the current code page,
something that Git for Windows is very ill-prepared for, as it expects
to be able to pass a command-line containing non-ASCII characters to the
shell without having those characters munged.

One symptom of this behavior: when `git clone` or `git fetch` shell out
to call `git-upload-pack` with a path that contains non-ASCII
characters, the shell tried to interpret the entire command-line
(including command-line parameters) as executable path, which obviously
must fail.

This fixes git-for-windows#1036

Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
The intention of this change is to align with how the top-level git
`Makefile` defines its own test target (which also internally calls
`$(MAKE) -C t/ all`). This change also ensures the consistency of
`make -C contrib/subtree test` with other testing in CI executions
(which rely on `$DEFAULT_TEST_TARGET` being defined as `prove`).

Signed-off-by: Victoria Dye <vdye@github.com>
In Git-for-Windows, work on using ARM64 has progressed. The
commit 2d94b77 (cmake: allow building for Windows/ARM64, 2020-12-04)
failed to notice that /compat/vcbuild/vcpkg_install.bat will default to
using the "x64-windows" architecture for the vcpkg installation if not set,
but CMake is not told of this default. Commit 635b6d9 (vcbuild: install
ARM64 dependencies when building ARM64 binaries, 2020-01-31) later updated
vcpkg_install.bat to accept an arch (%1) parameter, but retained the default.

This default is neccessary for the use case where the project directory is
opened directly in Visual Studio, which will find and build a CMakeLists.txt
file without any parameters, thus expecting use of the default setting.

Also Visual studio will generate internal .sln solution and .vcxproj project
files needed for some extension tools. Inform users of the additional
.sln/.vcxproj generation.

** How to test:
 rm -rf '.vs' # remove old visual studio settings
 rm -rf 'compat/vcbuild/vcpkg' # remove any vcpkg downloads
 rm -rf 'contrib/buildsystems/out' # remove builds & CMake artifacts
 with a fresh Visual Studio Community Edition, File>>Open>>(git *folder*)
   to load the project (which will take some time!).
 check for successful compilation.
The implicit .sln (etc.) are in the hidden .vs directory created by
Visual Studio.

Signed-off-by: Philip Oakley <philipoakley@iee.email>
To complement the `--stdin` and `--literally` test cases that verify
that we can hash files larger than 4GB on 64-bit platforms using the
LLP64 data model, here is a test case that exercises `hash-object`
_without_ any options.

Just as before, we use the `big` file from the previous test case if it
exists to save on setup time, otherwise generate it.

Signed-off-by: Philip Oakley <philipoakley@iee.email>
Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
Signed-off-by: Derrick Stolee <derrickstolee@github.com>
Special-casing even more configurations simply does not make sense.

Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
Git for Windows wants to add `git.exe` to the users' `PATH`, without
cluttering the latter with unnecessary executables such as `wish.exe`.
To that end, it invented the concept of its "Git wrapper", i.e. a tiny
executable located in `C:\Program Files\Git\cmd\git.exe` (originally a
CMD script) whose sole purpose is to set up a couple of environment
variables and then spawn the _actual_ `git.exe` (which nowadays lives in
`C:\Program Files\Git\mingw64\bin\git.exe` for 64-bit, and the obvious
equivalent for 32-bit installations).

Currently, the following environment variables are set unless already
initialized:

- `MSYSTEM`, to make sure that the MSYS2 Bash and the MSYS2 Perl
  interpreter behave as expected, and

- `PLINK_PROTOCOL`, to force PuTTY's `plink.exe` to use the SSH
  protocol instead of Telnet,

- `PATH`, to make sure that the `bin` folder in the user's home
  directory, as well as the `/mingw64/bin` and the `/usr/bin`
  directories are included. The trick here is that the `/mingw64/bin/`
  and `/usr/bin/` directories are relative to the top-level installation
  directory of Git for Windows (which the included Bash interprets as
  `/`, i.e. as the MSYS pseudo root directory).

Using the absence of `MSYSTEM` as a tell-tale, we can detect in
`git.exe` whether these environment variables have been initialized
properly. Therefore we can call `C:\Program Files\Git\mingw64\bin\git`
in-place after this change, without having to call Git through the Git
wrapper.

Obviously, above-mentioned directories must be _prepended_ to the `PATH`
variable, otherwise we risk picking up executables from unrelated Git
installations. We do that by constructing the new `PATH` value from
scratch, appending `$HOME/bin` (if `HOME` is set), then the MSYS2 system
directories, and then appending the original `PATH`.

Side note: this modification of the `PATH` variable is independent of
the modification necessary to reach the executables and scripts in
`/mingw64/libexec/git-core/`, i.e. the `GIT_EXEC_PATH`. That
modification is still performed by Git, elsewhere, long after making the
changes described above.

While we _still_ cannot simply hard-link `mingw64\bin\git.exe` to `cmd`
(because the former depends on a couple of `.dll` files that are only in
`mingw64\bin`, i.e. calling `...\cmd\git.exe` would fail to load due to
missing dependencies), at least we can now avoid that extra process of
running the Git wrapper (which then has to wait for the spawned
`git.exe` to finish) by calling `...\mingw64\bin\git.exe` directly, via
its absolute path.

Testing this is in Git's test suite tricky: we set up a "new" MSYS
pseudo-root and copy the `git.exe` file into the appropriate location,
then verify that `MSYSTEM` is set properly, and also that the `PATH` is
modified so that scripts can be found in `$HOME/bin`, `/mingw64/bin/`
and `/usr/bin/`.

This addresses git-for-windows#2283

Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
This adds support for a new http.sslAutoClientCert config value.

In cURL 7.77 or later the schannel backend does not automatically send
client certificates from the Windows Certificate Store anymore.

This config value is only used if http.sslBackend is set to "schannel",
and can be used to opt in to the old behavior and force cURL to send
client certificates.

This fixes git-for-windows#3292

Signed-off-by: Pascal Muller <pascalmuller@gmail.com>
Because `git subtree` (unlike most other `contrib` modules) is included as
part of the standard release of Git for Windows, its stability should be
verified as consistently as it is for the rest of git. By including the
`git subtree` tests in the CI workflow, these tests are as much of a gate to
merging and indicator of stability as the standard test suite.

Signed-off-by: Victoria Dye <vdye@github.com>
Ensure key CMake option values are part of the CMake output to
facilitate user support when tool updates impact the wider CMake
actions, particularly ongoing 'improvements' in Visual Studio.

These CMake displays perform the same function as the build-options.txt
provided in the main Git for Windows. CMake is already chatty.
The setting of CMAKE_EXPORT_COMPILE_COMMANDS is also reported.

Include the environment's CMAKE_EXPORT_COMPILE_COMMANDS value which
may have been propogated to CMake's internal value.

Testing the CMAKE_EXPORT_COMPILE_COMMANDS processing can be difficult
in the Visual Studio environment, as it may be cached in many places.
The 'environment' may include the OS, the user shell, CMake's
own environment, along with the Visual Studio presets and caches.

See previous commit for arefacts that need removing for a clean test.

Signed-off-by: Philip Oakley <philipoakley@iee.email>
dscho and others added 30 commits April 2, 2026 02:10
The Git for Windows project has grown quite complex over the years,
certainly much more complex than during the first years where the
`msysgit.git` repository was abusing Git for package management purposes
and the `git/git` fork was called `4msysgit.git`.

Let's describe the status quo in a thorough way.

Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
The Git project followed Git for Windows' lead and added their Code of
Conduct, based on the Contributor Covenant v1.4, later updated to v2.0.

We adapt it slightly to Git for Windows.

Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
Previously, we did not install any handler for Ctrl+C, but now we really
want to because the MSYS2 runtime learned the trick to call the
ConsoleCtrlHandler when Ctrl+C was pressed.

With this, hitting Ctrl+C while `git log` is running will only terminate
the Git process, but not the pager. This finally matches the behavior on
Linux and on macOS.

Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
This patch introduces support to set special NTFS attributes that are
interpreted by the Windows Subsystem for Linux as file mode bits, UID
and GID.

Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
Getting started contributing to Git can be difficult on a Windows
machine. CONTRIBUTING.md contains a guide to getting started, including
detailed steps for setting up build tools, running tests, and
submitting patches to upstream.

[includes an example by Pratik Karki how to submit v2, v3, v4, etc.]

Signed-off-by: Derrick Stolee <dstolee@microsoft.com>
…ITOR"

In e3f7e01 (Revert "editor: save and reset terminal after calling
EDITOR", 2021-11-22), we reverted the commit wholesale where the
terminal state would be saved and restored before/after calling an
editor.

The reverted commit was intended to fix a problem with Windows Terminal
where simply calling `vi` would cause problems afterwards.

To fix the problem addressed by the revert, but _still_ keep the problem
with Windows Terminal fixed, let's revert the revert, with a twist: we
restrict the save/restore _specifically_ to the case where `vi` (or
`vim`) is called, and do not do the same for any other editor.

This should still catch the majority of the cases, and will bridge the
time until the original patch is re-done in a way that addresses all
concerns.

Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
Handle Ctrl+C in Git Bash nicely

Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
Includes touch-ups by 마누엘, Philip Oakley and 孙卓识.

Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
The `--stdin` option was a well-established paradigm in other commands,
therefore we implemented it in `git reset` for use by Visual Studio.

Unfortunately, upstream Git decided that it is time to introduce
`--pathspec-from-file` instead.

To keep backwards-compatibility for some grace period, we therefore
reinstate the `--stdin` option on top of the `--pathspec-from-file`
option, but mark it firmly as deprecated.

Helped-by: Victoria Dye <vdye@github.com>
Helped-by: Matthew John Cheetham <mjcheetham@outlook.com>
Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
A fix for calling `vim` in Windows Terminal caused a regression and was
reverted. We partially un-revert this, to get the fix again.

Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
With improvements by Clive Chan, Adric Norris, Ben Bodenmiller and
Philip Oakley.

Helped-by: Clive Chan <cc@clive.io>
Helped-by: Adric Norris <landstander668@gmail.com>
Helped-by: Ben Bodenmiller <bbodenmiller@hotmail.com>
Helped-by: Philip Oakley <philipoakley@iee.org>
Signed-off-by: Brendan Forster <brendan@github.com>
Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
Rather than using private IFTTT Applets that send mails to this
maintainer whenever a new version of a Git for Windows component was
released, let's use the power of GitHub workflows to make this process
publicly visible.

This workflow monitors the Atom/RSS feeds, and opens a ticket whenever a
new version was released.

Note: Bash sometimes releases multiple patched versions within a few
minutes of each other (i.e. 5.1p1 through 5.1p4, 5.0p15 and 5.0p16). The
MSYS2 runtime also has a similar system. We can address those patches as
a group, so we shouldn't get multiple issues about them.

Note further: We're not acting on newlib releases, OpenSSL alphas, Perl
release candidates or non-stable Perl releases. There's no need to open
issues about them.

Co-authored-by: Matthias Aßhauer <mha1993@live.de>
Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
Reintroduce the 'core.useBuiltinFSMonitor' config setting (originally added
in 0a756b2 (fsmonitor: config settings are repository-specific,
2021-03-05)) after its removal from the upstream version of FSMonitor.

Upstream, the 'core.useBuiltinFSMonitor' setting was rendered obsolete by
"overloading" the 'core.fsmonitor' setting to take a boolean value. However,
several applications (e.g., 'scalar') utilize the original config setting,
so it should be preserved for a deprecation period before complete removal:

* if 'core.fsmonitor' is a boolean, the user is correctly using the new
  config syntax; do not use 'core.useBuiltinFSMonitor'.
* if 'core.fsmonitor' is unspecified, use 'core.useBuiltinFSMonitor'.
* if 'core.fsmonitor' is a path, override and use the builtin FSMonitor if
  'core.useBuiltinFSMonitor' is 'true'; otherwise, use the FSMonitor hook
  indicated by the path.

Additionally, for this deprecation period, advise users to switch to using
'core.fsmonitor' to specify their use of the builtin FSMonitor.

Signed-off-by: Victoria Dye <vdye@github.com>
This topic branch re-adds the deprecated --stdin/-z options to `git
reset`. Those patches were overridden by a different set of options in
the upstream Git project before we could propose `--stdin`.

We offered this in MinGit to applications that wanted a safer way to
pass lots of pathspecs to Git, and these applications will need to be
adjusted.

Instead of `--stdin`, `--pathspec-from-file=-` should be used, and
instead of `-z`, `--pathspec-file-nul`.

Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
Git for Windows accepts pull requests; Core Git does not. Therefore we
need to adjust the template (because it only matches core Git's
project management style, not ours).

Also: direct Git for Windows enhancements to their contributions page,
space out the text for easy reading, and clarify that the mailing list
is plain text, not HTML.

Signed-off-by: Philip Oakley <philipoakley@iee.org>
Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
Originally introduced as `core.useBuiltinFSMonitor` in Git for Windows
and developed, improved and stabilized there, the built-in FSMonitor
only made it into upstream Git (after unnecessarily long hemming and
hawing and throwing overly perfectionist style review sticks into the
spokes) as `core.fsmonitor = true`.

In Git for Windows, with this topic branch, we re-introduce the
now-obsolete config setting, with warnings suggesting to existing users
how to switch to the new config setting, with the intention to
ultimately drop the patch at some stage.

Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
This is the recommended way on GitHub to describe policies revolving around
security issues and about supported versions.

Helped-by: Sven Strickroth <email@cs-ware.de>
Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
…updates

Start monitoring updates of Git for Windows' component in the open
Add a README.md for GitHub goodness.

Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
This topic branch addresses the following vulnerability:

- **CVE-2025-66413**:
  When a user clones a repository from an attacker-controlled server,
  Git may attempt NTLM authentication and disclose the user's NTLMv2 hash
  to the remote server. Since NTLM hashing is weak, the captured hash can
  potentially be brute-forced to recover the user's credentials. This is
  addressed by disabling NTLM authentication by default.
  (GHSA-hv9c-4jm9-jh3x)

Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
In 816db62 (credential: advertise NTLM suppression and allow
helpers to re-enable, 2026-02-09), Git learned to advertise that NTLM
authentication was suppressed to credential helpers. It also introduced
a way to allow credential helpers to opt-back-in to NTLM authentication
via the `ntlm_allow=1` credential protocol flag.

There is a bug in the logic of 816db62 that means we are responding
to the `ntlm_allow=1` signal too late in the auth retry codepath; we've
already made the second-attempt request!

Move adding of NTLM as a valid auth method to `http_request_reauth`
right after the credential helper is consulted following the first
request, but (now) before we made the second request.

Signed-off-by: Matthew John Cheetham <mjcheetham@outlook.com>
The `osx-clang` and `osx-reftable` CI jobs on macOS started failing
with:

    compat/regcomp_enhanced.c:7:13: error: use of undeclared identifier
    'REG_ENHANCED'

The failure coincides with the GitHub Actions `macos-14-arm64` runner
image being updated from `20260302.0147` to `20260317.0174`.  The key
change in that image update is the Homebrew version bump from 5.0.15 to
5.1.0.

Homebrew 5.1.0 introduced automatic linking for versioned keg-only
formulae when the unversioned sibling is absent (see
Homebrew/brew#21676, announced at
https://brew.sh/2026/03/10/homebrew-5.1.0/).  The runner image installs
`llvm@15` (keg-only) but not unversioned `llvm`.  Under Homebrew 5.0.x
that formula stayed in its keg and its `clang` binary only lived at
`$(brew --prefix llvm@15)/bin/clang`.  Under 5.1.0, because unversioned
`llvm` is absent, `llvm@15` is now auto-linked into
`/opt/homebrew/bin/`, which sits earlier in PATH than `/usr/bin`.

The net effect is that `CC=clang` in CI now silently resolves to
Homebrew's LLVM 15.0.7 clang instead of Apple's system clang (Apple
clang 15.0.0, bundled with Xcode 15.4).  The runner image README
confirms this: the reported "Clang/LLVM" version flipped from 15.0.0 to
15.0.7 between image releases, matching the Homebrew LLVM version
exactly.

Homebrew's LLVM clang uses different include paths from Apple's clang.
In particular, the `regex.h` it sees does not define `REG_ENHANCED`,
which is an Apple-specific extension present in the macOS SDK headers
since at least macOS 10.12.  The Makefile unconditionally sets
`USE_ENHANCED_BASIC_REGULAR_EXPRESSIONS` for all Darwin builds via
`config.mak.uname`, which pulls in `compat/regcomp_enhanced.c`, which
references `REG_ENHANCED`, hence the build failure.

The `osx-gcc` job (CC=gcc-13) is unaffected because Homebrew GCC is
configured to use Apple's SDK sysroot, so it still picks up Apple's
`regex.h` which defines `REG_ENHANCED`.  The `osx-meson` job is
unaffected because Meson does a compile-time test for `REG_ENHANCED`
(via `compiler.get_define`) and simply skips the feature when it is
absent.

Work around this by setting `NO_REGEX` when `CC=clang` on Darwin, which
makes the build use Git's bundled regex implementation instead of the
system one.  This sidesteps the missing `REG_ENHANCED` define entirely.

Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
As of git-for-windows/MINGW-packages#187, Git
for Windows no longer includes `git svn` in its installers and portable
Git editions.

As a consequence, the deprecation note is no longer necessary.

Even worse: Since the recommendation for users who want (or at least
need) to continue using `git svn` is to use the MSYS2 package instead,
and that MSYS2 package is built from Git for Windows' source code, they
would now be bothered by a note that they do not need.

So let's drop that deprecation note.

Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
In 816db62 (credential: advertise NTLM suppression and allow helpers
to re-enable, 2026-02-09), Git learned to advertise that NTLM
authentication was suppressed to credential helpers. It also introduced
a way to allow credential helpers to opt-back-in to NTLM authentication
via the `ntlm_allow=1` credential protocol flag.

There is a bug in the logic of 816db62 that means we are responding
to the `ntlm_allow=1` signal too late in the auth retry codepath; we've
already made the second-attempt request!

Move adding of NTLM as a valid auth method to `http_request_reauth`
right after the credential helper is consulted following the first
request, but (now) before we made the second request.
… Git for Windows, anyway) (git-for-windows#6142)

As of git-for-windows/MINGW-packages#187, Git
for Windows no longer includes `git svn` in its installers and portable
Git editions.

As a consequence, the deprecation note is no longer necessary.

Even worse: Since the recommendation for users who want (or at least
need) to continue using `git svn` is to use the MSYS2 package instead,
and that MSYS2 package is built from Git for Windows' source code, they
would now be bothered by a note that they do not need.

So let's drop that deprecation note.
Currently, Git for Windows is built off of the MINGW64 tool chain. But
this will have to change because [the MSYS2 project deprecated this tool
chain in favor of
UCRT64](https://www.msys2.org/news/#2026-03-15-deprecating-the-mingw64-environment).
Of course, that's only possible because they dropped support for Windows
8.1, which Git for Windows will probably have to do relatively soon. The
best time to do that is probably [the Git 3.0 inflection
point](git-for-windows#6018) when we
already promised to drop support for older Windows versions.

To prepare for such a huge change, I investigated what needs to be
changed in Git for Windows' source code. And the good news is there's
actually not very much. This here patch seems to be the only change
that's necessary, and not even _strictly_ necessary: the
`mingw_strftime()` wrapper would still do the right thing. It would just
uselessly load the same function that's already loaded, dynamically,
again.

- The `strerror()` override [is guarded by an `#ifndef
_UCRT`](https://github.com/git-for-windows/git/blob/v2.53.0.windows.2/compat/mingw-posix.h#L294-L296),
- `PRIuMAX` resolves to standard `"llu"` [via
`<inttypes.h>`](https://github.com/git-for-windows/git/blob/v2.53.0.windows.2/compat/mingw-posix.h#L449-L454)
(note that `__MINGW64_VERSION_MAJOR` is defined both in MINGW64 and
UCRT64, by virtue of using the `mingw-w64-headers`),
-
[`__USE_MINGW_ANSI_STDIO=0`](https://github.com/git-for-windows/git/blob/v2.53.0.windows.2/config.mak.uname#L751C19-L751C33)
is irrelevant because [`_UCRT` short-circuits
it](https://github.com/git-for-windows/git-sdk-64/blob/08933e673c79b5db48419917a2b02746b390afc4/mingw64/include/inttypes.h#L33),
and
- `SNPRINTF_RETURNS_BOGUS` hasn't been set for Git for Windows' builds
since ec47a33, i.e. for a _really_ long
time.
It was already decided in ef22148 (clean: do not traverse mount points,
2018-12-07) that we shouldn't traverse NTFS junctions/bind mounts when
using `git clean`, partly because they're sometimes used in worktrees.
But the same check wasn't applied to `remove_dir_recurse()` in `dir.c`,
which `git worktree remove` uses. So removing a worktree suffers the
same problem we had previously with `git clean`.

Let's add the same guard from ef22148.

Signed-off-by: Maks Kuznia <makskuznia244@gmail.com>
…s#6151)

`remove_dir_recurse()` in `dir.c` doesn't check for mount points, even
though this check was already added for `git clean` in git-for-windows#2268. So `git
worktree remove` (or anything else that calls it) will traverse NTFS
junctions and delete whatever is there. Similar to git-for-windows#607.

This extends the same check from git-for-windows#2268 but for anything that calls
`remove_dir_recurse()`.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.