libgit2 / libgit2/pygit2

KeypairFromAgent throws fetch into an infinite loop

未关闭
#953 0 条评论 1 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

主要语言
Python
星标
1.7k
派生
408
平均合并
2 天 57 分钟
30 天内合并 PR
7

描述

I'm not sure I'm using it right, but the following code throws git_remote_fetch into some sort of infinite loop in case the agent can't find an appropriate key.

import pygit2

class MyCallbacks(pygit2.RemoteCallbacks):
    def credentials(self, url, username_from_url, allowed_types):
        # print('Credentials callback called')
        return pygit2.KeypairFromAgent(username_from_url)

repo = pygit2.Repository('foo')
repo.remotes['origin'].fetch(callbacks=MyCallbacks())
print("OK")

Here's an example:

$ git clone git@<some-ssh-repository> foo
Cloning into 'foo'...
remote: Enumerating objects: 3, done.
remote: Counting objects: 100% (3/3), done.
remote: Total 3 (delta 0), reused 0 (delta 0)
Receiving objects: 100% (3/3), done.
$ python3 test.py  # Using my regular ssh agent which has the correct key
OK
$ eval $(ssh-agent)  # Create a new ssh-agent with no key and update env variables
$ python3 test.py  # Never returns...

If I uncomment the print statement in the python snippet above, I can see that my callback is called over and over.

There's one more thing that is odd but might help: when I interrupt the script with ctrl-c, I don't always get the same traceback. In the second case bellow it seems that the "correct" exception (_pygit2.GitError: callback failed to initialize SSH credentials) is raised at some point but just doesn't reach my code:

❯❯❯ python3 test.py
# ^C
Traceback (most recent call last):
  File "test.py", line 11, in <module>
    repo.remotes['origin'].fetch(callbacks=MyCallbacks())
  File "/home/gregoire/.local/lib/python3.7/site-packages/pygit2/remote.py", line 406, in fetch
    err = C.git_remote_fetch(self._remote, arr, fetch_opts, to_bytes(message))
KeyboardInterrupt
❯❯❯ python3 test.py
# ^C
From cffi callback <function RemoteCallbacks._credentials_cb at 0x7f5e027700d0>:
Traceback (most recent call last):
  File "/home/gregoire/.local/lib/python3.7/site-packages/pygit2/remote.py", line 304, in _credentials_cb
    ccred = get_credentials(credentials, url, username, allowed)
  File "/home/gregoire/.local/lib/python3.7/site-packages/pygit2/remote.py", line 515, in get_credentials
    if pubkey is None and privkey is None:
KeyboardInterrupt
Traceback (most recent call last):
  File "test.py", line 11, in <module>
    repo.remotes['origin'].fetch(callbacks=MyCallbacks())
  File "/home/gregoire/.local/lib/python3.7/site-packages/pygit2/remote.py", line 409, in fetch
    check_error(err)
  File "/home/gregoire/.local/lib/python3.7/site-packages/pygit2/errors.py", line 64, in check_error
    raise GitError(message)
_pygit2.GitError: callback failed to initialize SSH credentials

贡献指南

打开贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

调研方向

从 traceback 中显示的 remote.py 路径开始,尤其是 RemoteCallbacks._credentials_cb 和 get_credentials。使用不包含任何密钥的 ssh-agent 重现 fetch,然后跟踪 callback 和 credential 错误处理。完成标准是:失败的 credential 查找停止重试,并且预期的 GitError 能够到达调用方。

由索引模型根据 Issue 内容生成。

评估

技术栈
git, python
领域
tooling
Issue 类型
缺陷
难度
3/5
预计耗时
1-2 天
活跃度
停滞
描述清晰度
基本清楚
新手友好度
35/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。