Skip to content

Rebase to v2.56.0-rc1 - #6418

Open
dscho wants to merge 438 commits into
git-for-windows:mainfrom
dscho:rebase-to-v2.56.0-rc1
Open

dscho wants to merge 438 commits into
git-for-windows:mainfrom
dscho:rebase-to-v2.56.0-rc1

Conversation

@dscho

@dscho dscho commented Sep 17, 2026

Copy link
Copy Markdown
Member
Range-diff relative to main
  • 1: c40850d = 1: 754cba0 unix-socket: avoid leak when initialization fails

  • 2: 95142af = 2: 678d85c grep: prevent ^$ false match at end of file

  • 7: 587c4de ! 3: c12cea0 ci: bump actions/checkout from 6 to 7

    @@ .github/workflows/main.yml: jobs:
     -    - uses: actions/checkout@v6
     +    - uses: actions/checkout@v7
          - uses: git-for-windows/setup-git-for-windows-sdk@v2
    -     - name: build
    +     - name: Install GCC-compatible Rust target
            shell: bash
     @@ .github/workflows/main.yml: jobs:
            group: vs-build-${{ github.ref }}
  • 3: eef30cb = 4: 355b93c t9350: point out that refs are not updated correctly

  • 4: baf7d59 = 5: ed08414 transport-helper: add trailing --

  • 5: 8592dfd = 6: 1f837ee remote-helper: check helper status after import/export

  • 6: 5c9d8ea (upstream: b721ade) < -: ------------ mingw: include the Python parts in the build

  • 8: c3605aa = 7: b13b782 Always auto-gc after calling a fast-import transport

  • 9: 8d27eff = 8: 274dd26 mingw: prevent regressions with "drive-less" absolute paths

  • 20: c8beebf = 9: cf9a73b mingw: demonstrate a git add issue with NTFS junctions

  • 23: df9a02e = 10: c5bd4d4 strbuf_realpath(): use platform-dependent API if available

  • 22: 03fa4f4 = 11: 04d9a98 t5505/t5516: allow running without .git/branches/ in the templates

  • 25: cb43f5e = 12: 502aeed http: use new "best effort" strategy for Secure Channel revoke checking

  • 10: 6fb88bb = 13: c332cc8 transport: optionally disable side-band-64k

  • 11: d692620 = 14: b7565a1 mingw: fix fatal error working on mapped network drives on Windows

  • 12: ebd08c4 = 15: e09e19f clink.pl: fix MSVC compile script to handle libcurl-d.lib

  • 27: 354c641 = 16: d0443a4 mingw: implement a platform-specific strbuf_realpath()

  • 13: 1e25bb4 = 17: e370b43 ci(vs-build): adapt to Visual Studio 2026 default on windows-latest

  • 14: 61df6fb = 18: d66cb29 vcpkg_install: detect lack of Git

  • 15: 25732c5 = 19: f6d13f2 vcpkg_install: add comment regarding slow network connections

  • 16: b62f2d7 = 20: fafe5a8 vcbuild: install ARM64 dependencies when building ARM64 binaries

  • 17: 1890726 = 21: 38eedf0 vcbuild: add an option to install individual 'features'

  • 18: 429946d = 22: bde85a0 cmake: allow building for Windows/ARM64

  • 19: e53c7f0 = 23: ab4eee0 ci(vs-build) also build Windows/ARM64 artifacts

  • 21: b342b0f = 24: 83aeb46 vcbuild: stop hard-coding OpenSSL as a dependency

  • 24: 798dc29 = 25: 08d112e cmake(): allow setting HOST_CPU for cross-compilation

  • 32: 43ecdf4 = 26: 7df180b CMake: default Visual Studio generator has changed

  • 34: 48df73b = 27: 3a689df subtree: update contrib/subtree test target

  • 33: eb45aa4 = 28: 1842ee0 .gitignore: add Visual Studio CMakeSetting.json file

  • 26: 70f1c80 = 29: 795bca0 t5505/t5516: fix white-space around redirectors

  • 28: 8bee1fd = 30: ede430b t3701: verify that we can add lots of files interactively

  • 29: 6e34c83 = 31: 99c7fcc commit: accept "scissors" with CR/LF line endings

  • 30: dddb018 = 32: 2aaca00 t0014: fix indentation

  • 31: 2550471 = 33: 1277039 git-gui: accommodate for intent-to-add files

  • 39: cc6c3c5 = 34: 46bb937 mingw: allow for longer paths in parse_interpreter()

  • 40: 8a81150 = 35: 1a3225a compat/vcbuild: document preferred way to build in Visual Studio

  • 41: 263d125 = 36: fcbbb5c http: optionally send SSL client certificate

  • 42: 037238f = 37: 7d92acc ci: run contrib/subtree tests in CI builds

  • 35: ea5ab9f = 38: 13e7fd0 CMakeLists: add default "x64-windows" arch for Visual Studio

  • 36: 618a8a8 = 39: c8516d0 setup: properly use "%(prefix)/" when in WSL

  • 37: aa69a4a ! 40: 5057d5b Add config option windows.appendAtomically

    @@ compat/mingw.c: int mingw_open (const char *filename, int oflags, ...)
     +	 * Only set append_atomically to default value(1) when repo is initialized
     +	 * and fail to get config value
     +	 */
    -+	if (append_atomically < 0 && the_repository && the_repository->commondir &&
    ++	if ((oflags & O_APPEND) && append_atomically < 0 && the_repository && the_repository->commondir &&
     +		repo_config_get_bool(the_repository, "windows.appendatomically", &append_atomically))
     +		append_atomically = 1;
     +
  • 38: ca173b5 = 41: 3dd17ad MinGW: link as terminal server aware

  • 43: d14fa87 = 42: 2ca9f3f CMake: show Win32 and Generator_platform build-option values

  • 44: 31a085b = 43: 2114563 compat/mingw.c: do not warn when failing to get owner

  • 45: a84176e = 44: 976161f mingw: $env:TERM="xterm-256color" for newer OSes

  • 46: e951dbd = 45: c4cd431 winansi: check result and Buffer before using Name

  • 47: fa224c4 = 46: b92c9ec mingw: change core.fsyncObjectFiles = 1 by default

  • 48: 592db7d = 47: f69cbee Fix Windows version resources

  • 49: bc44196 (upstream: 0d5ce13) < -: ------------ windows: skip linking git-<command> for built-ins

  • 50: 171d7de (upstream: e0e94cc) < -: ------------ mingw: stop hard-coding CC = gcc

  • 51: 03737fa (upstream: 2de7b82) < -: ------------ mingw: drop the -D_USE_32BIT_TIME_T option

  • 52: a8165e8 (upstream: 59d4514) < -: ------------ mingw: only use -Wl,--large-address-aware for 32-bit builds

  • 53: fbd9602 (upstream: f243cc3) < -: ------------ mingw: avoid over-specifying --pic-executable

  • 54: f178073 (upstream: 59ab0a5) < -: ------------ mingw: set the prefix and HOST_CPU as per MSYS2's settings

  • 55: 22a9970 (upstream: 843047f) < -: ------------ mingw: only enable the MSYS2-specific stuff when compiling in MSYS2

  • 56: 5da2a33 (upstream: d69ec48) < -: ------------ mingw: rely on MSYS2's metadata instead of hard-coding it

  • 57: fab9e01 (upstream: 653884e) < -: ------------ mingw: always define ETC_* for MSYS2 environments

  • 66: 3de5e73 = 48: 9f658eb status: fix for old-style submodules with commondir

  • 58: 20c55d0 = 49: 14cc7c2 max_tree_depth: lower it for clang builds in general on Windows

  • 59: f685fa8 (upstream: 7904764) < -: ------------ mingw: ensure valid CTYPE

  • 60: cd85dd6 (upstream: caa5d9e) < -: ------------ mingw: allow git.exe to be used instead of the "Git wrapper"

  • 61: d9f9dca = 50: f9af1e6 mingw: ignore HOMEDRIVE/HOMEPATH if it points to Windows' system directory

  • 62: 6c95696 = 51: 3071c60 clink.pl: fix libexpatd.lib link error when using MSVC

  • 63: 6613638 = 52: 9fdd83d Makefile: clean up .ilk files when MSVC=1

  • 64: ff71d24 = 53: 8f86185 vcbuild: add support for compiling Windows resource files

  • 65: f414c76 = 54: 33e78c8 config.mak.uname: add git.rc to MSVC builds

  • 67: 532279f = 55: 17103b2 clink.pl: ignore no-stack-protector arg on MSVC=1 builds

  • 69: a435fcf = 56: c38cfbb clink.pl: move default linker options for MSVC=1 builds

  • 71: 1d53dcb = 57: 583c301 cmake: install headless-git.

  • 73: 21549c0 = 58: 03698ce git.rc: include winuser.h

  • 81: 76888ca = 59: 0579db0 revision: create mark_trees_uninteresting_dense()

  • 82: f9b8cc9 = 60: c5e699a survey: stub in new experimental 'git-survey' command

  • 83: 6591981 = 61: f77af3e survey: add command line opts to select references

  • 84: ce96282 = 62: e6ecc1d survey: start pretty printing data in table form

  • 85: b536fa1 = 63: 78f658f survey: add object count summary

  • 86: 9d2cf59 = 64: 7506a25 survey: summarize total sizes by object type

  • 87: 983b7ae = 65: 2c98158 survey: show progress during object walk

  • 68: c7b8be8 = 66: 9698a36 http: optionally load libcurl lazily

  • 89: 36b3c74 = 67: 4de9159 survey: add ability to track prioritized lists

  • 70: c85e9eb = 68: c997ec6 http: support lazy-loading libcurl also on Windows

  • 91: c08ddc4 = 69: 7f768ee survey: add report of "largest" paths

  • 72: 1f64288 = 70: bdd225d http: when loading libcurl lazily, allow for multiple SSL backends

  • 93: c5dd7d2 = 71: 94309ac survey: add --top= option and config

  • 74: 6912d08 = 72: a6c8b80 mingw: do load libcurl dynamically by default

  • 75: a8846df = 73: 2a0fc30 Add a GitHub workflow to verify that Git/Scalar work in Nano Server

  • 76: a98994a = 74: e3bf9fa mingw: suggest windows.appendAtomically in more cases

  • 77: 6d30cd0 = 75: a3e2688 win32: use native ANSI sequence processing, if possible

  • 78: cea66bc = 76: f33c7ee common-main.c: fflush stdout buffer upon exit

  • 79: 8ac6e08 = 77: 2dd37dd t5601/t7406(mingw): do run tests with symlink support

  • 80: 6a87007 = 78: e402090 Fallback to AppData if XDG_CONFIG_HOME is unset

  • 88: aebd49d = 79: 6799845 mingw: make sure errno is set correctly when socket operations fail

  • 103: 05621d5 = 80: af474ff t5563: verify that NTLM authentication works

  • 90: 7f7709f = 81: 7f92921 compat/mingw: handle WSA errors in strerror

  • 105: e81ff93 = 82: fba06e2 http: disallow NTLM authentication by default

  • 92: e4ccdcc = 83: 036020c compat/mingw: drop outdated comment

  • 107: 429ca2c = 84: d06273b http: warn if might have failed because of NTLM

  • 94: ac75455 = 85: 2aa7722 t0301: actually test credential-cache on Windows

  • 109: 3913548 = 86: febbabf credential: advertise NTLM suppression and allow helpers to re-enable

  • 95: dc330ec = 87: a38c1ba survey: clearly note the experimental nature in the output

  • 96: fcaa5fe = 88: 4afef9d credential-cache: handle ECONNREFUSED gracefully

  • 97: addf72e = 89: 4f80422 reftable: do make sure to use custom allocators

  • 98: ee43848 = 90: ca57818 check-whitespace: avoid alerts about upstream commits

  • 99: e8cf253 = 91: 2017cd0 t/t5571-prep-push-hook.sh: Add test with writing to stderr

  • 111: e68c829 = 92: 3b701aa dir: do not traverse mount points

  • 112: 1b9eff5 = 93: aea2858 win32: thread-utils: handle multi-socket systems

  • 113: f9fd88e = 94: f29e89e t5563: add tests for http.emptyAuth with Negotiate

  • 114: 8080f51 = 95: e2e75ee entry: flush fscache after creating directories and writing files

  • 115: 29c5f36 = 96: 702162c ci(macos): skip the git p4 tests

  • 100: 2622830 = 97: 730b882 mingw: Support git_terminal_prompt with more terminals

  • 101: 2de73af = 98: 5a12a29 compat/terminal.c: only use the Windows console if bash 'read -r' fails

  • 116: 9d4fefb = 99: 87020bd diff: stop truncating the deflated-binary-diff size on Windows

  • 102: c1f6c30 = 100: 3931834 mingw (git_terminal_prompt): do fall back to CONIN$/CONOUT$ method

  • 118: 06687de = 101: 3e08cb8 convert: widen gather_convert_stats() helpers to size_t

  • 117: c455bf9 = 102: 10066e1 Win32: symlink: move phantom symlink creation to a separate function

  • 120: 24a7e3f = 103: 6bdca9f read-cache: stop truncating index blob sizes on Windows

  • 104: 1ae80bd = 104: 315dc44 mingw: introduce code to detect whether we're inside a Windows container

  • 119: 8804c57 = 105: 2476d27 Introduce helper to create symlinks that knows about index_state

  • 122: c99db80 = 106: 569e285 xdiff-interface: widen buffer_is_binary() size parameter to size_t

  • 106: 6e6cf0f = 107: e4c50ba mingw: when running in a Windows container, try to rename() harder

  • 121: 26bcd89 = 108: 460d669 mingw: allow to specify the symlink type in .gitattributes

  • 124: e7273b7 = 109: 6a59761 combine-diff: stop truncating combined-diff blob sizes on Windows

  • 108: c6874c9 = 110: a1432ff mingw: move the file_attr_to_st_mode() function definition

  • 123: 849dce0 = 111: 8d8772d Win32: symlink: add test for symlink attribute

  • 126: bca0a57 = 112: 61073ba diff: widen textconv_object() size out-param to size_t

  • 110: 4528e9c = 113: 1492afb mingw: Windows Docker volumes are not symbolic links

  • 125: d798bb1 = 114: dfc18a4 clean: do not traverse mount points

  • 127: da8067b = 115: 886f3a6 pack-bitmap: stop truncating blob sizes used by --filter=blob:limit

  • 135: cc9a607 = 116: a745e1a diffcore: widen struct diff_filespec.size to size_t

  • 128: 469e682 = 117: 99e9402 mingw: work around rename() failing on a read-only file

  • 129: 7f71467 = 118: 3a34271 clean: remove mount points when possible

  • 130: 30acab3 = 119: 9787498 mingw: optionally enable wsl compability file mode bits

  • 131: 0aea2c1 = 120: bc66e69 Refuse to follow invalid paths in .git files

  • 132: 5b357f4 = 121: 6e36bd4 tree-walk: drop link_len cast in get_tree_entry_follow_symlinks()

  • 133: 8298ddc = 122: cb02f7e tree-walk: widen init_tree_desc() and init_tree_desc_gently() to size_t

  • 134: 152fd7e = 123: e3bf662 pack-objects: drop the two tree-walk casts in the preferred-base path

  • 136: 5b67be8 = 124: 83f1174 tree: widen struct tree.size and parse_tree_buffer() to size_t

  • 137: 8aaff57 = 125: 85ba3dc commit: widen the commit-buffer API to size_t

  • 138: 8235158 = 126: 0e2bdb4 blame: widen find_line_starts() len parameter to size_t

  • 139: 6c33d82 = 127: 311bfc4 grep: widen struct grep_source.size and grep_buffer() to size_t

  • 140: f5a8848 = 128: 5277a7d fast-export: drop the export_blob() size cast and widen anonymize_blob()

  • 141: b07f290 = 129: 65e68af repo: drop the inflated-size cast in count_objects()

  • 142: c9efcfc = 130: 663bbac unpack-objects: widen the size-passing infrastructure to size_t

  • 143: f0f649b = 131: 5321d03 pack-objects: drop cast_size_t_to_ulong shims in get_delta()

  • 144: c7263d4 = 132: 33f006c pack-objects: drop cast_size_t_to_ulong shims in try_delta()

  • 145: c6be84b = 133: 5f203b9 pack-objects: drop the last size shim in write_no_reuse_object()

  • 146: 583b4e2 = 134: 72ba09c blame: widen struct blame_scoreboard.final_buf_size to size_t

  • 147: 6972bc1 = 135: 675c04b fast-import: drop the six size casts in the object-read paths

  • 148: 6cc4439 = 136: 83a745e t/helper/test-pack-deltas: drop the delta_size cast in write_ref_delta()

  • 149: 1ed8620 = 137: 09dc308 Drop the cast_size_t_to_ulong() helper

  • 150: 2d4ab11 = 138: dc35b32 coverity: skip building with Rust, for now

  • 152: eaac418 = 139: 049c002 Win32: make FILETIME conversion functions public

  • 154: aa3abd2 = 140: b03e5d5 Win32: dirent.c: Move opendir down

  • 155: 5a51292 = 141: 3a14b18 mingw: make the dirent implementation pluggable

  • 156: e45d6c4 = 142: 068cea9 Win32: make the lstat implementation pluggable

  • 157: fc436b0 = 143: dedcced mingw: add infrastructure for read-only file system level caches

  • 158: 20c67d6 = 144: 1747e4e mingw: add a cache below mingw's lstat and dirent implementations

  • 159: e266b40 = 145: 95fbf1a fscache: load directories only once

  • 160: fc4c8bb = 146: 00c0a77 fscache: add key for GIT_TRACE_FSCACHE

  • 161: e256b7c = 147: 67dd5ad fscache: remember not-found directories

  • 162: 427565b = 148: 6a1c52c fscache: add a test for the dir-not-found optimization

  • 163: 8dc5c85 = 149: 6e49c48 add: use preload-index and fscache for performance

  • 164: ef52d1d = 150: ad0ef00 dir.c: make add_excludes aware of fscache during status

  • 165: d606bda = 151: e4d8335 fscache: make fscache_enabled() public

  • 166: 85fc9f6 = 152: 2bb973d dir.c: regression fix for add_excludes with fscache

  • 167: 40ca9e8 = 153: e0fa286 fetch-pack.c: enable fscache for stats under .git/objects

  • 168: e966b00 = 154: b72bb53 checkout.c: enable fscache for checkout again

  • 169: 1599c88 = 155: 93e8021 Enable the filesystem cache (fscache) in refresh_index().

  • 170: 273de1a = 156: 6f5fa12 fscache: use FindFirstFileExW to avoid retrieving the short name

  • 171: ce779c2 = 157: f621f94 fscache: add GIT_TEST_FSCACHE support

  • 172: deeca3a = 158: d0f69bb fscache: add fscache hit statistics

  • 173: d670196 = 159: 63dc7c7 unpack-trees: enable fscache for sparse-checkout

  • 174: 1a14880 = 160: 8c52147 status: disable and free fscache at the end of the status command

  • 175: ed1e062 = 161: 344bba4 mem_pool: add GIT_TRACE_MEMPOOL support

  • 176: 5c2725e = 162: f31d9f4 fscache: fscache takes an initial size

  • 177: add8a76 = 163: 1848982 fscache: update fscache to be thread specific instead of global

  • 178: 97bd2d2 = 164: 01227b5 fscache: teach fscache to use mempool

  • 179: c470997 = 165: 8f45216 fscache: make fscache_enable() thread safe

  • 151: 59c4ffe = 166: aa5decf git-gui--askyesno: fix funny text wrapping

  • 180: 14ae4c9 = 167: 8925b91 fscache: teach fscache to use NtQueryDirectoryFile

  • 153: 6ab7a60 = 168: ab2931c git-gui--askyesno (mingw): use Git for Windows' icon, if available

  • 181: 3a8fa5c = 169: 7b7da94 fscache: remember the reparse tag for each entry

  • 182: 5c615c8 = 170: 3e774e2 fscache: Windows Docker volumes are not symbolic links

  • 183: 6e28f28 = 171: 6749f92 fscache: optionally enable wsl compability file mode bits

  • 184: 8bf5447 = 172: 19bd15d fscache: implement an FSCache-aware is_mount_point()

  • 185: 952e3ea = 173: c579e9d clean: make use of FSCache

  • 186: 0365b5d = 174: 1539298 compat/poll: do not collect more handles than the wait supports

  • 187: 7954bc4 = 175: 9661f9f parallel-checkout: limit worker count to what poll() can wait on

  • 188: 1cbacd1 = 176: 3e36718 run-command: limit concurrent children to what poll() can wait on

  • 189: 667b01b = 177: 79ce8ad pack-objects (mingw): demonstrate a segmentation fault with large deltas

  • 190: a77615d = 178: 628d259 mingw: support long paths

  • 191: bdba649 = 179: 4212838 win32(long path support): leave drive-less absolute paths intact

  • 192: 36d96df = 180: cbd1932 compat/fsmonitor/fsm-*-win32: support long paths

  • 193: 6d71571 = 181: e2116de clean: suggest using core.longPaths if paths are too long to remove

  • 194: 79ce1ef = 182: 706c4a8 mingw: explicitly specify with which cmd to prefix the cmdline

  • 195: 6c92aff = 183: 5228e53 mingw: when path_lookup() failed, try BusyBox

  • 196: 2a7ba47 = 184: f187b3d test-tool: learn to act as a drop-in replacement for iconv

  • 197: ff10adb = 185: 5fd8e3c tests(mingw): if iconv is unavailable, use test-helper --iconv

  • 198: dad1077 = 186: 09950ae gitattributes: mark .png files as binary

  • 199: af77fa5 = 187: 9825f87 tests: move test PNGs into t/lib-diff/

  • 200: 46ce3ca = 188: 1515650 tests: only override sort & find if there are usable ones in /usr/bin/

  • 201: 57b6a34 = 189: 227932d tests: use the correct path separator with BusyBox

  • 202: ef148af = 190: f225e23 mingw: only use Bash-ism builtin pwd -W when available

  • 203: 95244de = 191: 4533660 tests (mingw): remove Bash-specific pwd option

  • 204: fb37494 = 192: 75adc21 test-lib: add BUSYBOX prerequisite

  • 205: 1569550 = 193: 4b6c43d t5003: use binary file from t/lib-diff/

  • 206: 81e7c58 = 194: b2b8ff8 t5532: workaround for BusyBox on Windows

  • 207: cdd9421 = 195: 82efda6 t5605: special-case hardlink test for BusyBox-w32

  • 208: 099a1bd = 196: c784721 t5813: allow for $PWD to be a Windows path

  • 209: ec7210a = 197: b741dfa t9200: skip tests when $PWD contains a colon

  • 210: 2c249e7 = 198: 7d53bf2 Partially un-revert "editor: save and reset terminal after calling EDITOR"

  • 218: 631f04e = 199: 1f2bf4a Add a GitHub workflow to monitor component updates

  • 220: be4ccfe = 200: 8fd6c76 reset: reinstate support for the deprecated --stdin option

  • 221: 9d0daf7 = 201: fb77a27 fsmonitor: reintroduce core.useBuiltinFSMonitor

  • 211: 0e81006 = 202: b459b83 Describe Git for Windows' architecture

  • 212: fb78f3a = 203: ab83bc1 Add an AGENTS.md file to help with AI-assisted debugging/development

  • 213: 5e3e03a = 204: df5b552 Modify the Code of Conduct for Git for Windows

  • 214: ecd6bbb = 205: c84f374 CONTRIBUTING.md: add guide for first-time contributors

  • 215: 5041f6b = 206: 7b76f21 README.md: Add a Windows-specific preamble

  • 216: af1cdf3 = 207: ce8640e Add an issue template

  • 217: e674481 = 208: ae6ae62 Modify the GitHub Pull Request template (to reflect Git for Windows)

  • 219: a62e04b = 209: c6a0a27 SECURITY.md: document Git for Windows' policies

  • 222: 22e814c = 210: 107b4a2 dependabot: help keeping GitHub Actions versions up to date

  • 223: 7502e7e = 211: 7bf8c9c ci: only run the expensive tests in the Windows tests for now

  • 224: 1f60ad3 = 212: a867bca build(deps): bump actions/cache from 5 to 6

  • 225: 5905644 = 213: 55c1c90 repo: split annotated tags out from total tag count in structure

  • 226: f9584af = 214: d8b024a repo: filter the structure scope via --ref-filter=

  • 227: 11ead4e = 215: c3a125f repo: report top-N paths by count, disk, and inflated size in structure

  • 228: d11303a = 216: 9813912 t1901: cover the --top option of git repo structure

  • 229: 50ee67f = 217: ff71a9e repo: read the --top default from repo.structure.top

  • 230: 015ec0b = 218: 44ad347 git-survey: announce the upcoming pivot into git repo structure

  • 232: 48a1d61 = 219: f817e4e survey: turn into a thin shim over git repo structure

  • 234: 7be713c = 220: 3ad7429 mingw: handle staging 4GB+ files correctly

  • 235: c0cf0e7 = 221: 2eb1516 mingw: support unpacking loose 4GB+ objects

  • 231: 8c27fe3 = 222: 8c04941 bundle-uri: refuse advertised URIs by protocol

  • 236: 58043fa = 223: 3e9d097 t: add an expensive test to verify that 4GB+ blobs can be staged/read

  • 233: ae18d95 = 224: 889707a git-for-windows: prepare for 2.55.0(5)

  • 237: c419d20 (was merged into upstream verbatim) < -: ------------ ci: bump debian-11 job to debian-12

  • 238: 13e7ca3 < -: ------------ fixup! Add config option windows.appendAtomically

  • 239: 9f131df = 225: d3367bb object-file: use size_t for object size in check_object_signature()

derrickstolee and others added 30 commits September 17, 2026 09:21
The 'git survey' builtin provides several detail tables, such as "top
files by on-disk size". The size of these tables defaults to 10,
currently.

Allow the user to specify this number via a new --top=<N> option or the
new survey.top config key.

Signed-off-by: Derrick Stolee <stolee@gmail.com>
Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
This will help with Git for Windows' maintenance going forward: It
allows Git for Windows to switch its primary libcurl to a variant
without the OpenSSL backend, while still loading an alternate when
setting `http.sslBackend = openssl`.

This is necessary to avoid maintenance headaches with upgrading OpenSSL:
its major version name is encoded in the shared library's file name and
hence major version updates (temporarily) break libraries that are
linked against the OpenSSL library.

Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
In Git for Windows v2.39.0, we fixed a regression where `git.exe` would
no longer work in Windows Nano Server (frequently used in Docker
containers).

This GitHub workflow can be used to verify manually that the Git/Scalar
executables work in Nano Server.

Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
When running Git for Windows on a remote APFS filesystem, it would
appear that the `mingw_open_append()`/`write()` combination would fail
almost exactly like on some CIFS-mounted shares as had been reported in
git-for-windows#2753, albeit with a
different `errno` value.

Let's handle that `errno` value just the same, by suggesting to set
`windows.appendAtomically=false`.

Signed-off-by: David Lomas <dl3@pale-eds.co.uk>
Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
Windows 10 version 1511 (also known as Anniversary Update), according to
https://learn.microsoft.com/en-us/windows/console/console-virtual-terminal-sequences
introduced native support for ANSI sequence processing. This allows
using colors from the entire 24-bit color range.

All we need to do is test whether the console's "virtual processing
support" can be enabled. If it can, we do not even need to start the
`console_thread` to handle ANSI sequences.

Or, almost all we need to do: When `console_thread()` does its work, it
uses the Unicode-aware `write_console()` function to write to the Win32
Console, which supports Git for Windows' implicit convention that all
text that is written is encoded in UTF-8. The same is not necessarily
true if native ANSI sequence processing is used, as the output is then
subject to the current code page. Let's ensure that the code page is set
to `CP_UTF8` as long as Git writes to it.

Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
By default, the buffer type of Windows' `stdout` is unbuffered (_IONBF),
and there is no need to manually fflush `stdout`.

But some programs, such as the Windows Filtering Platform driver
provided by the security software, may change the buffer type of
`stdout` to full buffering. This nees `fflush(stdout)` to be called
manually, otherwise there will be no output to `stdout`.

Signed-off-by: MinarKotonoha <chengzhuo5@qq.com>
Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
A long time ago, we decided to run tests in Git for Windows' SDK with
the default `winsymlinks` mode: copying instead of linking. This is
still the default mode of MSYS2 to this day.

However, this is not how most users run Git for Windows: As the majority
of Git for Windows' users seem to be on Windows 10 and newer, likely
having enabled Developer Mode (which allows creating symbolic links
without administrator privileges), they will run with symlink support
enabled.

This is the reason why it is crucial to get the fixes for CVE-2024-? to
the users, and also why it is crucial to ensure that the test suite
exercises the related test cases. This commit ensures the latter.

Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
In order to be a better Windows citizenship, Git should
save its configuration files on AppData folder. This can
enables git configuration files be replicated between machines
using the same Microsoft account logon which would reduce the
friction of setting up Git on new systems. Therefore, if
%APPDATA%\Git\config exists, we use it; otherwise
$HOME/.config/git/config is used.

Signed-off-by: Ariel Lourenco <ariellourenco@users.noreply.github.com>
The sparse tree walk algorithm was created in d5d2e93 (revision:
implement sparse algorithm, 2019-01-16) and involves using the
mark_trees_uninteresting_sparse() method. This method takes a repository
and an oidset of tree IDs, some of which have the UNINTERESTING flag and
some of which do not.

Create a method that has an equivalent set of preconditions but uses a
"dense" walk (recursively visits all reachable trees, as long as they
have not previously been marked UNINTERESTING). This is an important
difference from mark_tree_uninteresting(), which short-circuits if the
given tree has the UNINTERESTING flag.

A use of this method will be added in a later change, with a condition
set whether the sparse or dense approach should be used.

Signed-off-by: Derrick Stolee <stolee@gmail.com>
The winsock2 library provides functions that work on different data
types than file descriptors, therefore we wrap them.

But that is not the only difference: they also do not set `errno` but
expect the callers to enquire about errors via `WSAGetLastError()`.

Let's translate that into appropriate `errno` values whenever the socket
operations fail so that Git's code base does not have to change its
expectations.

This closes git-for-windows#2404

Helped-by: Jeff Hostetler <jeffhost@microsoft.com>
Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
We map WSAGetLastError() errors to errno errors in winsock_error_to_errno(),
but the MSVC strerror() implementation only produces "Unknown error" for
most of them. Produce some more meaningful error messages in these
cases.

Our builds for ARM64 link against the newer UCRT strerror() that does know
these errors, so we won't change the strerror() used there.

The wording of the messages is copied from glibc strerror() messages.

Reported-by: M Hickford <mirth.hickford@gmail.com>
Signed-off-by: Matthias Aßhauer <mha1993@live.de>
Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
Although NTLM authentication is considered weak (extending even to
NTLMv2, which purportedly allows brute-forcing reasonably complex
8-character passwords in a matter of days, given ample compute
resources), it _is_ one of the authentication methods supported by
libcurl.

Note: The added test case *cannot* reuse the existing `custom_auth`
facility. The reason is that that facility is backed by an NPH script
("No Parse Headers"), which does not allow handling the 3-phase NTLM
authentication correctly (in my hands, the NPH script would not even be
called upon the Type 3 message, a "200 OK" would be returned, but no
headers, let alone the `git http-backend` output as payload). Having a
separate NTLM authentication script makes the exact workings clearer and
more readable, anyway.

Co-authored-by: Matthew John Cheetham <mjcheetham@outlook.com>
Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
This comment has been true for the longest time; The combination of the
two preceding commits made it incorrect, so let's drop that comment.

Signed-off-by: Matthias Aßhauer <mha1993@live.de>
Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
NTLM authentication is relatively weak. This is the case even with the
default setting of modern Windows versions, where NTLMv1 and LanManager
are disabled and only NTLMv2 is enabled: NTLMv2 hashes of even
reasonably complex 8-character passwords can be broken in a matter of
days, given enough compute resources.

Even worse: On Windows, NTLM authentication uses Security Support
Provider Interface ("SSPI"), which provides the credentials without
requiring the user to type them in.

Which means that an attacker could talk an unsuspecting user into
cloning from a server that is under the attacker's control and extracts
the user's NTLMv2 hash without their knowledge.

For that reason, let's disallow NTLM authentication by default.

NTLM authentication is quite simple to set up, though, and therefore
there are still some on-prem Azure DevOps setups out there whose users
and/or automation rely on this type of authentication. To give them an
escape hatch, introduce the `http.<url>.allowNTLMAuth` config setting
that can be set to `true` to opt back into using NTLM for a specific
remote repository.

Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
Commit 2406bf5 (Win32: detect unix socket support at runtime,
2024-04-03) introduced a runtime detection for whether the operating
system supports unix sockets for Windows, but a mistake snuck into the
tests. When building and testing Git without NO_UNIX_SOCKETS we
currently skip t0301-credential-cache on Windows if unix sockets are
supported and run the tests if they aren't.

Flip that logic to actually work the way it was intended.

Signed-off-by: Matthias Aßhauer <mha1993@live.de>
Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
The new default of Git is to disable NTLM authentication by default.

To help users find the escape hatch of that config setting, should they
need it, suggest it when the authentication failed and the server had
offered NTLM, i.e. if re-enabling it would fix the problem.

Helped-by: Patrick Steinhardt <ps@pks.im>
Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
While this command is definitely something we _want_, chances are that
upstreaming this will require substantial changes.

We still want to be able to experiment with this before that, to focus
on what we need out of this command: To assist with diagnosing issues
with large repositories, as well as to help monitoring the growth and
the associated painpoints of such repositories.

To that end, we are about to integrate this command into
`microsoft/git`, to get the tool into the hands of users who need it
most, with the idea to iterate in close collaboration between these
users and the developers familar with Git's internals.

However, we will definitely want to avoid letting anybody have the
impression that this command, its exact inner workings, as well as its
output format, are anywhere close to stable. To make that fact utterly
clear (and thereby protect the freedom to iterate and innovate freely
before upstreaming the command), let's mark its output as experimental
in all-caps, as the first thing we do.

Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
In 245670c (credential-cache: check for windows specific errors, 2021-09-14)
we concluded that on Windows we would always encounter ENETDOWN where we
would expect ECONNREFUSED on POSIX systems, when connecting to unix sockets.
As reported in [1], we do encounter ECONNREFUSED on Windows if the
socket file doesn't exist, but the containing directory does and ENETDOWN if
neither exists. We should handle this case like we do on non-windows systems.

[1] git-for-windows#4762 (comment)

This fixes git-for-windows#5314

Helped-by: M Hickford <mirth.hickford@gmail.com>
Signed-off-by: Matthias Aßhauer <mha1993@live.de>
Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
The reftable library goes out of its way to use its own set of allocator
functions that can be configured using `reftable_set_alloc()`. However,
Git does not configure this.

That is not typically a problem, except when Git uses a custom allocator
via some definitions in `git-compat-util.h`, as is the case in Git for
Windows (which switched away from the long-unmaintained nedmalloc to
mimalloc).

Then, it is quite possible that Git assigns a `strbuf` (allocated via
the custom allocator) to, say, the `refname` field of a
`reftable_log_record` in `write_transaction_table()`, and later on asks
the reftable library function `reftable_log_record_release()` to release
it, but that function was compiled without using `git-compat-util.h` and
hence calls regular `free()` (i.e. _not_ the custom allocator's own
function).

This has been a problem for a long time and it was a matter of some sort
of "luck" that 1) reftables are not commonly used on Windows, and 2)
mimalloc can often ignore gracefully when it is asked to release memory
that it has not allocated.

However, a recent update to `seen` brought this problem to the
forefront, letting t1460 fail in Git for Windows, with symptoms much in
the same way as the problem I had to address in d02c37c
(t-reftable-basics: allow for `malloc` to be `#define`d, 2025-01-08)
where exit code 127 was also produced in lieu of
`STATUS_HEAP_CORRUPTION` (C0000374) because exit codes are only 7 bits
wide.

It was not possible to figure out what change in particular caused these
new failures within a reasonable time frame, as there are too many
changes in `seen` that conflict with Git for Windows' patches, I had to
stop the investigation after spending four hours on it fruitlessly.

To verify that this patch fixes the issue, I avoided using mimalloc and
temporarily patched in a "custom allocator" that would more reliably
point out problems, like this:

  diff --git a/refs/reftable-backend.c b/refs/reftable-backend.c
  index 68f3829..9421d630b9f5 100644
  --- a/refs/reftable-backend.c
  +++ b/refs/reftable-backend.c
  @@ -353,6 +353,69 @@ static int reftable_be_fsync(int fd)
   	return fsync_component(FSYNC_COMPONENT_REFERENCE, fd);
   }

  +#define DEBUG_REFTABLE_ALLOC
  +#ifdef DEBUG_REFTABLE_ALLOC
  +#include "khash.h"
  +
  +static inline khint_t __ac_X31_hash_ptr(void *ptr)
  +{
  +	union {
  +		void *ptr;
  +		char s[sizeof(void *)];
  +	} u;
  +	size_t i;
  +	khint_t h;
  +
  +	u.ptr = ptr;
  +	h = (khint_t)*u.s;
  +	for (i = 0; i < sizeof(void *); i++)
  +		h = (h << 5) - h + (khint_t)u.s[i];
  +	return h;
  +}
  +
  +#define kh_ptr_hash_func(key) __ac_X31_hash_ptr(key)
  +#define kh_ptr_hash_equal(a, b) ((a) == (b))
  +
  +KHASH_INIT(ptr, void *, int, 0, kh_ptr_hash_func, kh_ptr_hash_equal)
  +
  +static kh_ptr_t *my_malloced;
  +
  +static void *my_malloc(size_t sz)
  +{
  +	int dummy;
  +	void *ptr = malloc(sz);
  +	if (ptr)
  +		kh_put_ptr(my_malloced, ptr, &dummy);
  +	return ptr;
  +}
  +
  +static void *my_realloc(void *ptr, size_t sz)
  +{
  +	int dummy;
  +	if (ptr) {
  +		khiter_t pos = kh_get_ptr(my_malloced, ptr);
  +		if (pos >= kh_end(my_malloced))
  +			die("Was not my_malloc()ed: %p", ptr);
  +		kh_del_ptr(my_malloced, pos);
  +	}
  +	ptr = realloc(ptr, sz);
  +	if (ptr)
  +		kh_put_ptr(my_malloced, ptr, &dummy);
  +	return ptr;
  +}
  +
  +static void my_free(void *ptr)
  +{
  +	if (ptr) {
  +		khiter_t pos = kh_get_ptr(my_malloced, ptr);
  +		if (pos >= kh_end(my_malloced))
  +			die("Was not my_malloc()ed: %p", ptr);
  +		kh_del_ptr(my_malloced, pos);
  +	}
  +	free(ptr);
  +}
  +#endif
  +
   static struct ref_store *reftable_be_init(struct repository *repo,
   					  const char *gitdir,
   					  unsigned int store_flags)
  @@ -362,6 +425,11 @@ static struct ref_store *reftable_be_init(struct repository *repo,
   	int is_worktree;
   	mode_t mask;

  +#ifdef DEBUG_REFTABLE_ALLOC
  +	my_malloced = kh_init_ptr();
  +	reftable_set_alloc(my_malloc, my_realloc, my_free);
  +#endif
  +
   	mask = umask(0);
   	umask(mask);

I briefly considered contributing this "custom allocator" patch, too,
but it is unwieldy (for example, it would not work at all when compiling
with mimalloc support) and it would only waste space (or even time, if a
compile flag was introduced and exercised as part of the CI builds).
Given that it is highly unlikely that Git will lose the new
`reftable_set_alloc()` call by mistake, I rejected that idea as simply
too wasteful.

Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
Every once in a while, whitespace errors are introduced in Git for
Windows' rebases to newer Git versions, simply by virtue of integrating
upstream commits that do not follow upstream Git's own whitespace rule.
In Git v2.50.0-rc0, for example, 03f2915 (xdiff: disable
cleanup_records heuristic with --minimal, 2025-04-29) introduced a
trailing space.

Arguably, non-actionable alerts are worse than no alerts at all, so
let's suppress those alerts that we cannot do anything about, anyway.

Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
The 2.53.0.rc0.windows release candidate had a regression where
writing to stderr from a pre-push hook would error out.

The regression was fixed in 2.53.0.rc1.windows and the test here ensures
that this stays fixed.

Signed-off-by: Thomas Braun <thomas.braun@virtuell-zuhause.de>
The previous commits disabled NTLM authentication by default due to its
cryptographic weaknesses. Users can re-enable it via the config setting
http.<url>.allowNTLMAuth, but this requires manual intervention.

Credential helpers may have knowledge about which servers are trusted
for NTLM authentication (e.g., known on-prem Azure DevOps instances).
To allow them to signal this trust, introduce a simple negotiation:
when NTLM is suppressed and the server offered it, Git advertises
ntlm=suppressed to the credential helper. The helper can respond with
ntlm=allow to re-enable NTLM for this request.

This happens precisely at the point where we would otherwise warn the
user about NTLM being suppressed, ensuring the capability is only
advertised when relevant.

Helped-by: Matthew John Cheetham <mjcheetham@outlook.com>
Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
It was already decided in ef22148 (clean: do not traverse mount points,
2018-12-07) that we shouldn't traverse NTFS junctions/bind mounts when
using `git clean`, partly because they're sometimes used in worktrees.
But the same check wasn't applied to `remove_dir_recurse()` in `dir.c`,
which `git worktree remove` uses. So removing a worktree suffers the
same problem we had previously with `git clean`.

Let's add the same guard from ef22148.

Signed-off-by: Maks Kuznia <makskuznia244@gmail.com>
While the currently used way to detect the number of CPU cores on
Windows is nice and straight-forward, GetSystemInfo() only gives us
access to the number of processors within the current group. [1]

While that is usually fine for systems with a single physical CPU,
separate physical sockets are typically separate groups.

Switch to using GetLogicalProcessorInformationEx() to handle multi-socket
systems better.

[1] https://learn.microsoft.com/en-us/windows/win32/api/sysinfoapi/ns-sysinfoapi-system_info#members

This fixes git-for-windows#4766

Co-Authored-by: Herman Semenov <GermanAizek@yandex.ru>
Signed-off-by: Matthias Aßhauer <mha1993@live.de>
Add tests exercising the interaction between http.emptyAuth and
servers that advertise Negotiate (SPNEGO) authentication.

Verify that auto mode gives Negotiate a chance via empty auth
(resulting in two 401 responses before falling through to
credential_fill with Basic credentials), and that false mode
strips Negotiate immediately (only one 401 response).

Signed-off-by: Matthew John Cheetham <mjcheetham@outlook.com>
When checkout.workers > 1 and core.fscache is enabled on Windows,
'git checkout <tree> -- <pathspec>' fails when restoring files into
directories that do not yet exist on disk. Two failure modes occur:

1. create_directories(): the fscache returns a stale directory listing
   that does not include a just-created directory. has_dirs_only_path()
   reports it as non-existent, triggering the unlink+mkdir recovery
   path which fails with 'cannot create directory: Directory not empty'.

2. write_pc_item(): after writing and closing a file, lstat() cannot
   see it through the stale fscache, failing with 'unable to stat
   just-written file'.

With workers=1, write_entry() calls flush_fscache() after each file,
keeping the cache in sync. With workers>1, enqueue_checkout() defers
the write (and the flush), leaving the cache stale for subsequent
entries.

Fix both by adding flush_fscache() calls after mkdir() in
create_directories() and before lstat() in write_pc_item(). On
non-Windows platforms flush_fscache() is a no-op.

Assisted-by: Claude Opus 4.6
Signed-off-by: Tyrie Vella <tyrielv@gmail.com>
Historically, the macOS jobs have always been among the longest-running
ones, and recently the `git p4` tests became another liability: They
started to fail much more often (maybe as of the switch away from the
`macos-13` pool?), requiring re-runs of the jobs that already were
responsible for long CI build times.

Of the 35 test scripts that exercise `git p4`, 32 are actually run on
macOS (3 are skipped for reasons like case-sensitivee filesystem), and
they take an accumulated runtime of over half an hour.

Furthermore, the `git p4` command is not really affected by Git for
Windows' patches, at least not as far as macOS is concerned, therefore
it is not only causing developer friction to have these long-running,
frequently failing tests, it is also quite wasteful: There has not been
a single instance so far where any `git p4` test failure in Git for
Windows had demonstrated an actionable bug.

While upstream Git is confident to have addressed the flakiness of the
`git p4` tests via ffff0bb (Use Perforce arm64 binary on macOS CI
jobs, 2025-11-16) (which got slipped in at the 11th hour into the
v2.52.0 release, fast-tracked without ever hitting `seen` even after
-rc2 was released), I am not quite so confident, and besides, the
runtime penalty of running those tests in Git for Windows' CI runs is
still a worrisome burden.

So let's just disable those tests in the CI runs, at least on macOS.

Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
Continue the size_t evacuation around large object handling: with
deflate_it() and the locals around it widened, the
cast_size_t_to_ulong() shim the prior delta_delta() widening had to
leave behind in emit_binary_diff_body() goes away. deflate_it() is
file-static; the only callers are the two in emit_binary_diff_body()
already touched here.

emit_diff_symbol() formats the resulting sizes via uintmax_t / %"PRIuMAX",
so the diff output is not affected; only the per-process upper bound
on a binary patch chunk that this function can address grows beyond
4 GiB on Windows.

Assisted-by: Opus 4.7
Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
Prep for the upcoming read_blob_data_from_index() widening, whose
callers in convert.c feed the size they receive straight into these
two helpers. Both are file-static, so the change is contained.

Also fixes a small pre-existing narrowing on the get_wt_convert_stats_ascii()
path, where strbuf.len (size_t) was passed to a unsigned long
parameter.

Assisted-by: Opus 4.7
Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
Continue the size_t evacuation. read_blob_data_from_index() reads
the blob through the size_t odb_read_object() API but writes the
size back through an unsigned long out-parameter, silently
truncating anything past 4 GiB on Windows. Widen the out-parameter,
drop the cast_size_t_to_ulong() shim, and move the matching locals
in the two convert.c callers and the one in attr.c. Their
downstream consumers (gather_convert_stats() widened in the prior
commit and read_attr_from_buf() already size_t) take the new type
directly.

Assisted-by: Opus 4.7
Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
dscho and others added 20 commits September 17, 2026 09:22
This topic branch re-adds the deprecated --stdin/-z options to `git
reset`. Those patches were overridden by a different set of options in
the upstream Git project before we could propose `--stdin`.

We offered this in MinGit to applications that wanted a safer way to
pass lots of pathspecs to Git, and these applications will need to be
adjusted.

Instead of `--stdin`, `--pathspec-from-file=-` should be used, and
instead of `-z`, `--pathspec-file-nul`.

Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
The preceding commit added `--top=<n>` to `git repo structure`,
reporting the top-N paths per type ranked by count, on-disk size, and
inflated size. Cover the three behaviors that matter for that option:

  * Without `--top`, the key-value output emits no `top.*` keys, so
    existing parsers stay unaffected.

  * `--top=N` produces exactly N ranked entries on each of the six
    `objects.<type>.top.by_<axis>` axes (count/disk_size/inflated_size
    crossed with trees/blobs), and a constructed input where one blob
    is several orders of magnitude bigger than the other lets us
    assert the ordering on the disk-size and inflated-size axes.

  * A negative `--top` is rejected with a non-zero exit and a message
    naming the constraint, so a typo cannot silently degrade into the
    default zero.

Avoid grep patterns starting with `--`; grep would parse the leading
double dash as an option terminator.

Assisted-by: Opus 4.7
Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
Originally introduced as `core.useBuiltinFSMonitor` in Git for Windows
and developed, improved and stabilized there, the built-in FSMonitor
only made it into upstream Git (after unnecessarily long hemming and
hawing and throwing overly perfectionist style review sticks into the
spokes) as `core.fsmonitor = true`.

In Git for Windows, with this topic branch, we re-introduce the
now-obsolete config setting, with warnings suggesting to existing users
how to switch to the new config setting, with the intention to
ultimately drop the patch at some stage.

Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
`git survey` exposes its `--top` default via `survey.top` so that a
site or per-repository operator can switch the detail tables on once
and have every subsequent invocation include them. Mirror that
ergonomics for `git repo structure` so that, as `git survey`'s
functionality is folded into `git repo structure`, the configuration
side of the migration story stays equivalent.

Add a small `git_config_int` callback bound to `repo.structure.top`
and invoke it before `parse_options()`, so a `--top=<N>` on the
command line cleanly overrides the configured default (including
`--top=0` to opt out of the detail tables when configuration enables
them). Reject negative configured values with the same wording as the
command-line guard, since `git_config_int()` happily returns negative
integers.

Document the new variable in a fresh `Documentation/config/repo.adoc`
and wire it into the alphabetical includes in `Documentation/config.adoc`
between `repack.adoc` and `rerere.adoc`. Cover the precedence
behaviour with a t1901 test: a configured value enables the tables by
default, and a command-line `--top=0` suppresses them again.

Note that the reported paths respect the `core.quotePath` setting.

Assisted-by: Opus 4.7
Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
This is yet another set of `unsigned long` declarations that should have
been `size_t` ones.

Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
…updates

Start monitoring updates of Git for Windows' component in the open
`git survey` started life as an experimental scale-measurement tool;
the preceding commits give `git repo structure` the path-level detail
tables and ref-scoping mechanism that were `git survey`'s main draw,
so the two now overlap substantially. Plan the migration explicitly:
add a short notice at the top of the description making clear which
of `git survey`'s knobs map to which `git repo structure` option, and
state that a future release will turn `git survey` into a thin shim
over `git repo structure`.

Putting the notice in the description (rather than only the synopsis)
ensures it shows up in `git help survey` rendering before the reader
sees any option specifics, so an operator skimming the page learns
about the replacement before adopting any survey-specific flags.

Assisted-by: Opus 4.7
Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
Bumps [actions/cache](https://github.com/actions/cache) from 5 to 6.
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](actions/cache@v5...v6)

---
updated-dependencies:
- dependency-name: actions/cache
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
... and yet another round of `unsigned long` -> `size_t`
transmogrifications.

Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
Add a README.md for GitHub goodness.

Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
`git survey` was an experimental scale-measurement tool whose
distinctive features (ref-kind filters, top-N path tables) are now
all available in `git repo structure`. With the path-level reporting
in place (commits "repo: filter the structure scope via
--ref-filter=<pattern>" and "repo: report top-N paths by count, disk,
and inflated size in structure"), there is no functionality `git
survey` provides that `git repo structure` cannot.

Replace the 764-line `git survey` implementation with a roughly
hundred-line shim that:

  * Accepts the existing `git survey` command line so callers in
    scripts continue to parse without changes.
  * Emits a deprecation warning naming the replacement command, so
    interactive users learn about the migration target.
  * Translates the survey-specific knobs into the equivalent
    `git repo structure` invocation and re-execs the canonical
    command via `execv_git_cmd()`. Per-kind ref selectors fan out
    into the corresponding `refs/heads/*`, `refs/tags/*`, etc.
    `--ref-filter` patterns; `--top=<N>` is forwarded directly;
    `--all-refs` becomes the absence of any `--ref-filter`.

Two survey options have no `git repo structure` counterpart:
`--verbose` controlled per-step trace output the new command does
not emit, and `--detached` selected the detached HEAD which
`git repo structure` does not enumerate separately. Both are
silently accepted and produce a single warning each, so old
invocations keep working while the absence of these knobs in `git
repo structure` is made visible.

Rewrite t8100 to assert the shim's contract: the deprecation
warning is printed, the output is byte-identical to a corresponding
`git repo structure` invocation, and the per-kind selector
translation produces the right `--ref-filter` pattern. The
preceding survey-specific output assertions (the multi-column
plaintext tables) no longer apply, since `git repo structure`'s
output format is now the canonical one and is covered by t1901.

The `survey.*` configuration keys (`survey.top`, `survey.progress`,
`survey.verbose`) are no longer honored by the shim. They were
mirrored by the preceding `repo.structure.top` work for the most
useful knob; users with `survey.top` set in config should migrate
to `repo.structure.top`. This is a backward-incompatible removal
documented by the deprecation notice in `git-survey.adoc`.

Assisted-by: Opus 4.7
Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
Bumps [actions/cache](https://github.com/actions/cache) from 5 to 6.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/actions/cache/releases">actions/cache's
releases</a>.</em></p>
<blockquote>
<h2>v6.0.0</h2>
<h2>What's Changed</h2>
<ul>
<li>Update packages, migrate to ESM by <a
href="https://github.com/Samirat"><code>@​Samirat</code></a> in <a
href="https://redirect.github.com/actions/cache/pull/1760">actions/cache#1760</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/cache/compare/v5...v6.0.0">https://github.com/actions/cache/compare/v5...v6.0.0</a></p>
<h2>v5.1.0</h2>
<h2>What's Changed</h2>
<ul>
<li>Bump <code>@​actions/cache</code> to v5.1.0 - handle read-only cache
access by <a
href="https://github.com/jasongin"><code>@​jasongin</code></a> in <a
href="https://redirect.github.com/actions/cache/pull/1775">actions/cache#1775</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/cache/compare/v5...v5.1.0">https://github.com/actions/cache/compare/v5...v5.1.0</a></p>
<h2>v5.0.5</h2>
<h2>What's Changed</h2>
<ul>
<li>Update ts-http-runtime dependency by <a
href="https://github.com/yacaovsnc"><code>@​yacaovsnc</code></a> in <a
href="https://redirect.github.com/actions/cache/pull/1747">actions/cache#1747</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/cache/compare/v5...v5.0.5">https://github.com/actions/cache/compare/v5...v5.0.5</a></p>
<h2>v5.0.4</h2>
<h2>What's Changed</h2>
<ul>
<li>Add release instructions and update maintainer docs by <a
href="https://github.com/Link"><code>@​Link</code></a>- in <a
href="https://redirect.github.com/actions/cache/pull/1696">actions/cache#1696</a></li>
<li>Potential fix for code scanning alert no. 52: Workflow does not
contain permissions by <a
href="https://github.com/Link"><code>@​Link</code></a>- in <a
href="https://redirect.github.com/actions/cache/pull/1697">actions/cache#1697</a></li>
<li>Fix workflow permissions and cleanup workflow names / formatting by
<a href="https://github.com/Link"><code>@​Link</code></a>- in <a
href="https://redirect.github.com/actions/cache/pull/1699">actions/cache#1699</a></li>
<li>docs: Update examples to use the latest version by <a
href="https://github.com/XZTDean"><code>@​XZTDean</code></a> in <a
href="https://redirect.github.com/actions/cache/pull/1690">actions/cache#1690</a></li>
<li>Fix proxy integration tests by <a
href="https://github.com/Link"><code>@​Link</code></a>- in <a
href="https://redirect.github.com/actions/cache/pull/1701">actions/cache#1701</a></li>
<li>Fix cache key in examples.md for bun.lock by <a
href="https://github.com/RyPeck"><code>@​RyPeck</code></a> in <a
href="https://redirect.github.com/actions/cache/pull/1722">actions/cache#1722</a></li>
<li>Update dependencies &amp; patch security vulnerabilities by <a
href="https://github.com/Link"><code>@​Link</code></a>- in <a
href="https://redirect.github.com/actions/cache/pull/1738">actions/cache#1738</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/XZTDean"><code>@​XZTDean</code></a> made
their first contribution in <a
href="https://redirect.github.com/actions/cache/pull/1690">actions/cache#1690</a></li>
<li><a href="https://github.com/RyPeck"><code>@​RyPeck</code></a> made
their first contribution in <a
href="https://redirect.github.com/actions/cache/pull/1722">actions/cache#1722</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/cache/compare/v5...v5.0.4">https://github.com/actions/cache/compare/v5...v5.0.4</a></p>
<h2>v5.0.3</h2>
<h2>What's Changed</h2>
<ul>
<li>Bump <code>@actions/cache</code> to v5.0.5 (Resolves: <a
href="https://github.com/actions/cache/security/dependabot/33">https://github.com/actions/cache/security/dependabot/33</a>)</li>
<li>Bump <code>@actions/core</code> to v2.0.3</li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/cache/compare/v5...v5.0.3">https://github.com/actions/cache/compare/v5...v5.0.3</a></p>
<h2>v.5.0.2</h2>
<h1>v5.0.2</h1>
<h2>What's Changed</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/actions/cache/blob/main/RELEASES.md">actions/cache's
changelog</a>.</em></p>
<blockquote>
<h1>Releases</h1>
<h2>How to prepare a release</h2>
<blockquote>
<p>[!NOTE]
Relevant for maintainers with write access only.</p>
</blockquote>
<ol>
<li>Switch to a new branch from <code>main</code>.</li>
<li>Run <code>npm test</code> to ensure all tests are passing.</li>
<li>Update the version in <a
href="https://github.com/actions/cache/blob/main/package.json"><code>https://github.com/actions/cache/blob/main/package.json</code></a>.</li>
<li>Run <code>npm run build</code> to update the compiled files.</li>
<li>Update this <a
href="https://github.com/actions/cache/blob/main/RELEASES.md"><code>https://github.com/actions/cache/blob/main/RELEASES.md</code></a>
with the new version and changes in the <code>## Changelog</code>
section.</li>
<li>Run <code>licensed cache</code> to update the license report.</li>
<li>Run <code>licensed status</code> and resolve any warnings by
updating the <a
href="https://github.com/actions/cache/blob/main/.licensed.yml"><code>https://github.com/actions/cache/blob/main/.licensed.yml</code></a>
file with the exceptions.</li>
<li>Commit your changes and push your branch upstream.</li>
<li>Open a pull request against <code>main</code> and get it reviewed
and merged.</li>
<li>Draft a new release <a
href="https://github.com/actions/cache/releases">https://github.com/actions/cache/releases</a>
use the same version number used in <code>package.json</code>
<ol>
<li>Create a new tag with the version number.</li>
<li>Auto generate release notes and update them to match the changes you
made in <code>RELEASES.md</code>.</li>
<li>Toggle the set as the latest release option.</li>
<li>Publish the release.</li>
</ol>
</li>
<li>Navigate to <a
href="https://github.com/actions/cache/actions/workflows/release-new-action-version.yml">https://github.com/actions/cache/actions/workflows/release-new-action-version.yml</a>
<ol>
<li>There should be a workflow run queued with the same version
number.</li>
<li>Approve the run to publish the new version and update the major tags
for this action.</li>
</ol>
</li>
</ol>
<h2>Changelog</h2>
<h3>6.1.0</h3>
<ul>
<li>Bump <code>@actions/cache</code> to v6.1.0 to pick up <a
href="https://redirect.github.com/actions/toolkit/pull/2435">actions/toolkit#2435
Handle cache write error due to read-only token</a></li>
<li>Switch redundant &quot;Cache save failed&quot; warning to debug log
in save-only</li>
</ul>
<h3>6.0.0</h3>
<ul>
<li>Updated <code>@actions/cache</code> to ^6.0.1,
<code>@actions/core</code> to ^3.0.1, <code>@actions/exec</code> to
^3.0.0, <code>@actions/io</code> to ^3.0.2</li>
<li>Migrated to ESM module system</li>
<li>Upgraded Jest to v30 and test infrastructure to be ESM
compatible</li>
</ul>
<h3>5.0.4</h3>
<ul>
<li>Bump <code>minimatch</code> to v3.1.5 (fixes ReDoS via globstar
patterns)</li>
<li>Bump <code>undici</code> to v6.24.1 (WebSocket decompression bomb
protection, header validation fixes)</li>
<li>Bump <code>fast-xml-parser</code> to v5.5.6</li>
</ul>
<h3>5.0.3</h3>
<ul>
<li>Bump <code>@actions/cache</code> to v5.0.5 (Resolves: <a
href="https://github.com/actions/cache/security/dependabot/33">https://github.com/actions/cache/security/dependabot/33</a>)</li>
<li>Bump <code>@actions/core</code> to v2.0.3</li>
</ul>
<h3>5.0.2</h3>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/actions/cache/commit/55cc8345863c7cc4c66a329aec7e433d2d1c52a9"><code>55cc834</code></a>
Merge pull request <a
href="https://redirect.github.com/actions/cache/issues/1768">#1768</a>
from jasongin/readonly-cache</li>
<li><a
href="https://github.com/actions/cache/commit/d8cd72f230726cdf4457ebb61ec1b593a8d12337"><code>d8cd72f</code></a>
Bump <code>@​actions/cache</code> to v6.1.0 - handle cache write error
due to RO token</li>
<li><a
href="https://github.com/actions/cache/commit/2c8a9bd7457de244a408f35966fab2fb45fda9c8"><code>2c8a9bd</code></a>
Merge pull request <a
href="https://redirect.github.com/actions/cache/issues/1760">#1760</a>
from actions/samirat/esm_migration_and_package_update</li>
<li><a
href="https://github.com/actions/cache/commit/e9b91fdc3fea7d79165fceb79042ef45c2d51023"><code>e9b91fd</code></a>
Prettier fixes</li>
<li><a
href="https://github.com/actions/cache/commit/e4884b8ff7f92ef6b52c79eda480bbc86e685adb"><code>e4884b8</code></a>
Rebuild dist</li>
<li><a
href="https://github.com/actions/cache/commit/10baf0191a3c426ea0fa4a3253a5c04233b6e18f"><code>10baf01</code></a>
Fixed licenses</li>
<li><a
href="https://github.com/actions/cache/commit/e39b386c9004d72a15d864ade8c0b3a702d47a37"><code>e39b386</code></a>
Fix test mock return order</li>
<li><a
href="https://github.com/actions/cache/commit/b6928203372a8571ff984c0c883ef3a1adfb0c06"><code>b692820</code></a>
PR feedback</li>
<li><a
href="https://github.com/actions/cache/commit/60749128a44d25d3c520a489e576380cf00ff3f1"><code>6074912</code></a>
Rebuild dist bundles as ESM to match type:module</li>
<li><a
href="https://github.com/actions/cache/commit/5a912e8b4af820fa082a0e75cfd2c782f8fbfe0e"><code>5a912e8</code></a>
Fix lint and jest issues</li>
<li>Additional commits viewable in <a
href="https://github.com/actions/cache/compare/v5...v6">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=actions/cache&package-manager=github_actions&previous-version=5&new-version=6)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>
I should have added this test as soon as
git-for-windows#6012 was opened.

Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
Servers may advertise bundle URIs that are not HTTP(S);
copy_uri_to_file() then opens it as a local path. On Windows that can be
a UNC path like `//attacker/share/x`, i.e. a clone can be manipulated
into making an outbound SMB connection that leaks NTLM credentials
(CVE-2026-62960).

Subject advertised URIs to the usual protocol allow-list
(`protocol.*.allow`), which drops "file" (and bare/UNC paths) by default
but keeps http/https/git/ssh. Do it in fetch_bundle_list(), the
clone/fetch consume path, so ls-remote still lists everything; each
skipped URI is reported. A user-supplied `--bundle-uri` is unaffected,
and `protocol.file.allow=always` re-enables an advertised file URI.

Assisted-by: Opus 4.7
Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
…it-for-windows#6268)

`git survey` was always experimental, and I never got around to
upstreaming it to make it non-experimental.

In the meantime, the `git repo structure` command was upstreamed
upstream, which covers most of the same ground with a cleaner option
surface and a stable output contract. This PR closes the remaining gap
(annotated-tag breakdown, ref scoping, top-N paths by
count/disk/inflated, and the corresponding configuration knob) and then
turns `git survey` into a thin shim that warns about deprecation,
translates its old command line into the equivalent `git repo structure`
invocation, and re-execs the canonical command. Net result: one
user-facing tool to maintain and to teach instead of two.

The intent is that scripts pinned to `git survey` keep working (a
warning aside), and that operators have a single answer when they ask
"how do I see what's making my repository large?". The `survey.*`
configuration keys are intentionally dropped; the only one that
mattered, `survey.top`, has a direct replacement in
`repo.structure.top`.
Prepare a new Git for Windows release with the rebuilt Bash package that no longer carries the expired Authenticode signature.

Signed-off-by: Matthew John Cheetham <mjcheetham@outlook.com>
Signed-off-by: David PRUDHOMME <david7.prudhomme@gmail.com>
Git for Windows v2.55.0(4)

Changes since Git for Windows v2.55.0(3) (July 14th 2026):

Following the MSYS2 project, on which Git for Windows is based, Windows
8.1 support will be dropped after Git for Windows v2.55.

This is a security fix release, addressing CVE-2026-62960.

  * CVE-2026-62960, Git for Windows: Attacker-controlled servers may
    advertise bundle URIs that point to network shares, causing Windows
    to transparently perform NTLM authentication and disclose the
    user's NTLMv2 hash. Since NTLM hashing is weak, the captured hash
    can potentially be brute-forced to recover the user's credentials.
    This is addressed by limiting the bundle URIs that git clone
    respects by the same protocol.<name>.allow rules as usual, which
    excludes file:// URIs by default.

Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
Git for Windows v2.55.0(5)

Changes since Git for Windows v2.55.0(4) (August 11th 2026)

Following the MSYS2 project, on which Git for Windows is based, Windows
8.1 support will be dropped after Git for Windows v2.55.

New Features

  * The experimental git survey command (which was never upstreamed to
    the core Git project) was deprecated and converted into a small
    shim on top of git repo structure. In the future, git repo
    structure should be used instead, as the git survey command will be
    retired eventually.
  * Git for Windows' installer is now a 64-bit executable (x64 instead
    of 86).
  * Comes with the MSYS2 runtime (Git for Windows flavor) based on
    Cygwin v3.6.10.
  * Comes with OpenSSH v10.5.P1.

Bug Fixes

  * The long-standing bug where Git Bash's screen was cleared after
    git.exe called vim (e.g. to edit a commit message) was fixed.
  * The Bash executables in the 64-bit and ARM64 distributions no
    longer carry an invalid Authenticode signature.

Signed-off-by: Matthew John Cheetham <mjcheetham@outlook.com>
When I merged the massive amount of work in git-for-windows#6289, I thought that that
was the end of it. But simply staging and unpacking loose blobs that are
4GB or larger _still_ does not work. This PR addresses that.

This fixes git-for-windows#6012
@dscho dscho self-assigned this Sep 17, 2026
@rimrul

rimrul commented Sep 17, 2026

Copy link
Copy Markdown
Member

Just to clarify: we're staying on NO_RUST for 2.56, right?

@rimrul rimrul linked an issue Sep 17, 2026 that may be closed by this pull request
@dscho

dscho commented Sep 17, 2026

Copy link
Copy Markdown
Member Author

Just to clarify: we're staying on NO_RUST for 2.56, right?

@rimrul good call-out, thanks!

I think I want to stay on NO_RUST for the actual Git for Windows, yes. CI is building with Rust (as of -rc1), and unless I am mistaken, MSYS2's variant of mingw-w64-git already builds with Rust for some time already.

The reason I want to stay with NO_RUST is that we already embarked on MINGW64 -> UCRT64 and on upgrading to InnoSetup 7 (and really using its new features), and I don't want to add a third axis of risk ;-)

@dscho

dscho commented Sep 17, 2026

Copy link
Copy Markdown
Member Author

/git-artifacts

The tag-git workflow run was started

@gitforwindowshelper

Copy link
Copy Markdown

Validate the installer manually

The installer was built successfully;
Please download, install, and run through the pre-flight check-list.
@dscho ☝️

@dscho

dscho commented Sep 17, 2026

Copy link
Copy Markdown
Member Author

/release

The release-git workflow run was started

@dscho

dscho commented Sep 17, 2026

Copy link
Copy Markdown
Member Author

Hrm. The release build keeps failing (and when it doesn't fail, it is super slow to upload, something that GitHub Status apparently does not want to report...). I'll try again tomorrow morning.

@gitforwindowshelper

Copy link
Copy Markdown

@dscho, please Share on Bluesky and send the announcement email.

@dscho

dscho commented Sep 17, 2026

Copy link
Copy Markdown
Member Author

So the Release finally worked, but deploying the PacMan packages still runs into 500s all the time. I guess I'll keep doing what every GitHub user does. I keep hitting rerun until it finally works.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[New git version] v2.56.0-rc1