Urgent.News

What's breaking now, across thousands of outlets.

Tech

Comparing GitHub HTTPS ref discovery with HTTP/1.1

I built gitclone-doctor to compare Git's selected HTTPS transport with HTTP/1.1 for a public GitHub repository. It runs git ls-remote URL HEAD against the target with the selected settings and HTTP/1.1, then repeats those two requests against the git/git control repository. The control reuses the same frozen proxy and CA snapshot, so URL-specific transport settings do not quietly change between…

I constructed a tool called gitclone-doctor to compare the Git repository's selected HTTPS transport protocol with HTTP/1.1. This tool performs two sets of requests: one against the target repository using the chosen settings and another against the git/git control repository. The control repository uses the same frozen proxy and CA snapshot throughout the testing, ensuring that any settings specific to the target repository remain unchanged during the comparison.

The demonstration utilizes a controlled local environment, not a real GitHub incident. This setup generates a temporary certificate, accepts both HTTP/2 and HTTP/1.1 connections, and returns a deliberate 403 error for the target URL over HTTP/2. In contrast, it delivers a valid smart HTTP ref advertisement over HTTP/1.1. The control path experiences success with both protocols, while the test program examines the real Git trace and declines to provide a comparison if it cannot observe the relevant requests.

The report presents response protocols and numeric statuses, rather than raw stderr, headers, configuration values, or trace text. The child Git processes run in a rebuilt environment, devoid of helpers and extra headers, and disable redirects while requiring verified TLS. The tool rejects execution when a .netrc or _netrc file is present, as Git's libcurl may consult those files.

The report differentiates Git requests from direct network checks. Git employs the selected proxy when configured, whereas DNS and TLS checks operate independently, with their own deadlines. A direct DNS failure does not invalidate passing Git requests. The output is a JSON file containing fixed result codes and presence flags for helpers, headers, and URL rewrites, not the configured values.

This ref discovery check does not complete the clone pack transfer process and does not test LFS, submodules, or authenticated access. Although a shared failure may remain unresolved, a successful HTTP/1.1 response does not necessarily indicate a protocol defect. To observe the local example, run the command 'npm run demo'. The command-line interface (CLI) can be executed from GitHub using 'npx --yes --package=github:Arthur031221/gitclone-doctor gitclone-doctor git/git '.

I would appreciate feedback on whether the comparison is clear and whether its limitations are stated plainly. You can find the repository at https://github.com/Arthur031221/gitclone-doctor.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Six Backup Strategies for NoSQL Databases, and What Really Fails

Seis estrategias de respaldo para bases de datos NoSQL, y qué falla de verdad No uso MS SQL Server: el enunciado lo excluye y, además, el problema que quiero estudiar es el de los motores NoSQL, donde…

  • MongoDB uses mongodump for logical backup, creating compressed BSON files for collections.
  • Redis employs RDB dump, generating a binary file of the entire database for restoration.
  • Neo4j creates a binary dump file (.dump) containing the entire graph database for backup.

A threshold is a policy, not a number

A threshold is a policy, not a number Somewhere in a payments codebase there is a line that says: approve automatically when confidence is above 0.8. Nobody remembers the afternoon it was written.

  • The 0.8 confidence threshold in payments codebases determines automatic refunds or human review.
  • The origin of the 0.8 value is unclear, stemming from various unrelated sources.
  • Setting the threshold improperly can cause irreversible damage or hidden costs for the business.

More from Sunday 4 October →