git-curl-compat: remove check for curl 7.39.0

libcurl 7.39.0 was released in November 2014, which is almost ten years ago, and no major operating system vendor is still providing security support for it. Debian 9 and Ubuntu 16.04, both of which are out of mainstream security support, have supported a newer version, and RHEL 8, which is still in support, also has a newer version. Remove the check for this version and use this functionality unconditionally. Signed-off-by: brian m. carlson <sandals@crustytoothpaste.net> Signed-off-by: Taylor Blau <me@ttaylorr.com>

brian m. carlson committed Oct 23, 2024 at 00:45 UTC 05dd4ec507f022462125afb1af3c8b42861dcdc5
2 files changed -20
git-curl-compat.h
-9
@@ -28,15 +28,6 @@
28 * introduced, oldest first, in the official version of cURL library.
29 */
30
31 -/**
32 - * CURLOPT_PINNEDPUBLICKEY was added in 7.39.0, released in November
33 - * 2014. CURLE_SSL_PINNEDPUBKEYNOTMATCH was added in that same version.
34 - */
35 -#if LIBCURL_VERSION_NUM >= 0x072c00
36 -#define GIT_CURL_HAVE_CURLOPT_PINNEDPUBLICKEY 1
37 -#define GIT_CURL_HAVE_CURLE_SSL_PINNEDPUBKEYNOTMATCH 1
38 -#endif
39 -
31 /**
32 * CURL_HTTP_VERSION_2 was added in 7.43.0, released in June 2015.
33 *
http.c
-11
@@ -63,9 +63,7 @@ static char *ssl_key;
63 static char *ssl_key_type;
64 static char *ssl_capath;
65 static char *curl_no_proxy;
66 -#ifdef GIT_CURL_HAVE_CURLOPT_PINNEDPUBLICKEY
66 static char *ssl_pinnedkey;
68 -#endif
67 static char *ssl_cainfo;
68 static long curl_low_speed_limit = -1;
69 static long curl_low_speed_time = -1;
@@ -509,12 +507,7 @@ static int http_options(const char *var, const char *value,
507 }
508
509 if (!strcmp("http.pinnedpubkey", var)) {
512 -#ifdef GIT_CURL_HAVE_CURLOPT_PINNEDPUBLICKEY
510 return git_config_pathname(&ssl_pinnedkey, var, value);
514 -#else
515 - warning(_("Public key pinning not supported with cURL < 7.39.0"));
516 - return 0;
517 -#endif
511 }
512
513 if (!strcmp("http.extraheader", var)) {
@@ -1104,10 +1097,8 @@ static CURL *get_curl_handle(void)
1097 curl_easy_setopt(result, CURLOPT_SSLKEYTYPE, ssl_key_type);
1098 if (ssl_capath)
1099 curl_easy_setopt(result, CURLOPT_CAPATH, ssl_capath);
1107 -#ifdef GIT_CURL_HAVE_CURLOPT_PINNEDPUBLICKEY
1100 if (ssl_pinnedkey)
1101 curl_easy_setopt(result, CURLOPT_PINNEDPUBLICKEY, ssl_pinnedkey);
1110 -#endif
1102 if (http_ssl_backend && !strcmp("schannel", http_ssl_backend) &&
1103 !http_schannel_use_ssl_cainfo) {
1104 curl_easy_setopt(result, CURLOPT_CAINFO, NULL);
@@ -1825,10 +1816,8 @@ static int handle_curl_result(struct slot_results *results)
1816 */
1817 credential_reject(&cert_auth);
1818 return HTTP_NOAUTH;
1828 -#ifdef GIT_CURL_HAVE_CURLE_SSL_PINNEDPUBKEYNOTMATCH
1819 } else if (results->curl_result == CURLE_SSL_PINNEDPUBKEYNOTMATCH) {
1820 return HTTP_NOMATCHPUBLICKEY;
1831 -#endif
1821 } else if (missing_target(results))
1822 return HTTP_MISSING_TARGET;
1823 else if (results->http_code == 401) {