Fix macOS Git proxy discovery for system proxies - #4
jiale-wangOwO merged 2 commits into
Conversation
jiale-wangOwO
left a comment
There was a problem hiding this comment.
????:????????(Request changes)?
-
[P2] ??????????????
gitdrop/git_sync.py?_run()????? URL ??git -c http.proxy=...???? URL ????????,??????????????????????????????? Git,????????????? URL,??????????????? -
[P2] ?? Git ????????????
????? GitHub Token?? Git ? stderr ?????? URL,_proxy_display_name()??????????,???????????????????(?? URL ????)??????? -
[P3] ?????????????
?? 11 ???????????,???unittest discover????????,Release workflow ????????????tests/__init__.py,?? CI/release workflow ??????
??????macOS ???????bypass ??? README ?????????????
The review text was corrupted by an encoding issue. Superseded by a corrected UTF-8 review.
jiale-wangOwO
left a comment
There was a problem hiding this comment.
审阅结论:建议先修改后合并。
-
[P2] 代理账号密码会出现在进程命令行中。
_run()把完整代理 URL 放进git -c http.proxy=...。如果 URL 含用户名和密码,其他本地进程可能读取凭据。建议不要把含凭据的代理 URL 放入命令行。 -
[P2] Git 原始错误可能泄露代理密码。当前只脱敏 Token;如果 stderr 回显完整代理 URL,
_proxy_display_name()只保护追加提示,不能保护原始错误。建议展示错误前同时脱敏代理凭据及其 URL 编码形式。 -
[P3] 新增测试没有接入自动流程。11 个测试可单独运行并通过,但标准
unittest discover当前发现不到测试,Release workflow 也没有执行测试。建议增加tests/__init__.py并在 CI 中运行测试。
代理优先级、macOS 系统代理读取、bypass 处理和 README 说明暂未发现其他阻塞问题。
What changed
This pull request makes GitDrop's external Git subprocess honor proxy settings on macOS.
Proxy resolution now follows this order:
GITDROP_HTTPS_PROXYHTTPS_PROXY/https_proxyALL_PROXY/all_proxyHTTP_PROXY/http_proxyurllib.request.getproxies()The implementation respects the system proxy bypass list for
github.com. A proxy without credentials is passed through both standard proxy environment variables and a per-command configuration:Credentialed proxy URLs are passed only through the subprocess environment so their usernames and passwords never appear in process command-line arguments. This does not modify the user's global Git configuration.
Network failures now include a targeted proxy troubleshooting hint. Git output is defensively scrubbed of the GitHub token, raw proxy credentials, complete credentialed proxy URLs, and their URL-encoded forms.
Why
A macOS app launched from Finder does not normally inherit shell proxy environment variables. When Shadowrocket or another Fake-IP/TUN proxy is enabled,
github.commay resolve to an address in198.18.0.0/15. Without the system proxy, Git attempts to connect directly to that Fake-IP and fails with errors such as:Explicitly setting
http.proxy=http://127.0.0.1:<port>makes clone and push work, confirming that the problem is missing proxy propagation rather than GitHub TLS, repository permissions, or authentication.This is a separate network path from the GitHub API certificate and retry fix in #2.
Tests
Added 13 standard-library
unittestcases covering:Validation performed:
A local Git integration check also confirmed that the per-command
http.proxyvalue is visible to Git.Added
tests/__init__.pyso standard root-level unittest discovery finds the suite. A new pull-request test workflow runs the suite automatically, and release builds now run the same tests before packaging.Documentation
Added a macOS proxy troubleshooting section covering Shadowrocket, Clash, Surge, Fake-IP/TUN behavior, proxy precedence, and the explicit
GITDROP_HTTPS_PROXYoverride.Security
TLS verification remains enabled. The implementation does not:
http.sslVerify;Closes #3.