+ ();
+}
+
+# Stuff we may pass through to curl (as of 7.64.0), see curl manpage for
+# details, so most options which make sense for HTTP/HTTPS (including proxy
+# support for Tor and other methods of getting past weird networks).
+# Most of these are untested by us, some may not make sense for our use case
+# and typos below are likely.
+# n.b. some short options (-$NUMBER) are not supported since they conflict
+# with other "lei q" switches.
+# FIXME: Getopt::Long doesn't easily let us support support options with
+# '.' in them (e.g. --http1.1)
+# TODO: should we depend on "-c http.*" options for things which have
+# analogues in git(1)? that would reduce likelihood of conflicts with
+# our other CLI options
+# Note: some names are renamed to avoid potential conflicts,
+# see %lei2curl in lib/PublicInbox/LeiCurl.pm
+sub curl_opt { qw(
+ curl-config=s@
+ abstract-unix-socket=s anyauth basic cacert=s capath=s
+ cert-status cert-type cert=s ciphers=s
+ connect-timeout=s connect-to=s cookie-jar=s cookie=s crlfile=s
+ digest disable dns-interface=s dns-ipv4-addr=s dns-ipv6-addr=s
+ dns-servers=s doh-url=s egd-file=s engine=s false-start
+ happy-eyeballs-timeout-ms=s haproxy-protocol header=s@
+ http2-prior-knowledge http2 insecure
+ interface=s ipv4 ipv6 junk-session-cookies
+ key-type=s key=s limit-rate=s local-port=s location-trusted location
+ max-redirs=i max-time=s negotiate netrc-file=s netrc-optional netrc
+ no-alpn no-buffer no-npn no-sessionid noproxy=s ntlm-wb ntlm
+ pass=s pinnedpubkey=s post301 post302 post303 preproxy=s
+ proxy-anyauth proxy-basic proxy-cacert=s proxy-capath=s
+ proxy-cert-type=s proxy-cert=s proxy-ciphers=s proxy-crlfile=s
+ proxy-digest proxy-header=s@ proxy-insecure
+ proxy-key-type=s proxy-key proxy-negotiate proxy-ntlm proxy-pass=s
+ proxy-pinnedpubkey=s proxy-service-name=s proxy-ssl-allow-beast
+ proxy-tls13-ciphers=s proxy-tlsauthtype=s proxy-tlspassword=s
+ proxy-tlsuser=s proxy-tlsv1 proxy-user=s proxy=s
+ proxytunnel=s pubkey=s random-file=s referer=s resolve=s
+ retry-connrefused retry-delay=s retry-max-time=s retry=i
+ sasl-ir service-name=s socks4=s socks4a=s socks5-basic
+ socks5-gssapi-service-name=s socks5-gssapi socks5-hostname=s socks5=s
+ speed-limit speed-type ssl-allow-beast sslv2 sslv3
+ suppress-connect-headers tcp-fastopen tls-max=s
+ tls13-ciphers=s tlsauthtype=s tlspassword=s tlsuser=s
+ tlsv1 trace-ascii=s trace-time trace=s
+ unix-socket=s user-agent=s user=s
+)