Rewrite GitHub SSH remotes to HTTPS in the sandbox
The in-container clone inherits origin verbatim from the host, which is commonly an SSH URL. Nothing in the sandbox can satisfy SSH: there is no key and port 22 is closed. Only HTTPS carries the Authorization header the proxy substitutes the repository token into, so every push failed. Setup now writes a global insteadOf rewrite for both SSH spellings. Doing it globally rather than per-remote covers the clone, anything the agent clones later, and submodules, and leaves the host's own .git/config untouched under --direct, where the working tree is bind-mounted read-write.
This commit is contained in:
@@ -1101,6 +1101,28 @@ EOF
|
||||
' </dev/null >/dev/null 2>&1 || true
|
||||
}
|
||||
|
||||
# The in-container clone inherits origin verbatim from the host, which is
|
||||
# commonly an SSH URL. Nothing in the sandbox can satisfy SSH - there is no key
|
||||
# and port 22 is closed - and only HTTPS carries the Authorization header the
|
||||
# proxy substitutes the GitHub token into. Rewriting globally covers the clone,
|
||||
# any repository the agent clones later, and every submodule, while leaving the
|
||||
# host's own .git/config untouched under --direct.
|
||||
install_sandbox_git_https() {
|
||||
# shellcheck disable=SC2016
|
||||
sbx exec "$SANDBOX_NAME" bash -c '
|
||||
key="url.https://github.com/.insteadOf"
|
||||
|
||||
# insteadOf is multi-valued, so a plain set would replace the first
|
||||
# form with the second and a repeat setup would accumulate duplicates.
|
||||
git config --global --unset-all "$key" 2>/dev/null
|
||||
|
||||
git config --global --add "$key" "[email protected]:"
|
||||
git config --global --add "$key" "ssh://[email protected]/"
|
||||
' </dev/null >/dev/null 2>&1 ||
|
||||
printf 'Could not rewrite GitHub SSH remotes to HTTPS in %s.\n' \
|
||||
"$SANDBOX_NAME" >&2
|
||||
}
|
||||
|
||||
validate_launch_mode() {
|
||||
case "$1" in
|
||||
agent | tmux) ;;
|
||||
@@ -1383,6 +1405,10 @@ setup_command() {
|
||||
|
||||
install_sandbox_dotfiles
|
||||
|
||||
# After the dotfiles: the allowlist may carry a .gitconfig, which would
|
||||
# otherwise land on top of the rewrite.
|
||||
install_sandbox_git_https
|
||||
|
||||
install_sandbox_network
|
||||
|
||||
install_sandbox_secrets
|
||||
@@ -1435,6 +1461,8 @@ config_command() {
|
||||
|
||||
install_sandbox_dotfiles
|
||||
|
||||
install_sandbox_git_https
|
||||
|
||||
install_sandbox_network
|
||||
|
||||
install_sandbox_secrets
|
||||
|
||||
Reference in New Issue
Block a user