Rewrite GitHub SSH remotes to HTTPS in the sandbox

The in-container clone inherits origin verbatim from the host, which is
commonly an SSH URL. Nothing in the sandbox can satisfy SSH: there is no key
and port 22 is closed. Only HTTPS carries the Authorization header the proxy
substitutes the repository token into, so every push failed.

Setup now writes a global insteadOf rewrite for both SSH spellings. Doing it
globally rather than per-remote covers the clone, anything the agent clones
later, and submodules, and leaves the host's own .git/config untouched under
--direct, where the working tree is bind-mounted read-write.
This commit is contained in:
2026-08-05 13:30:09 -05:00
parent b5dfae0696
commit e0f6113320
3 changed files with 104 additions and 0 deletions
+69
View File
@@ -0,0 +1,69 @@
#!/usr/bin/env bash
set -euo pipefail
# shellcheck source-path=SCRIPTDIR
# shellcheck source=tasks/ai/sbx
source "$(dirname "${BASH_SOURCE[0]}")/../tasks/ai/sbx"
failures=0
work="$(mktemp -d)"
trap 'rm -rf "$work"' EXIT
fail() {
printf 'FAIL: %s\n' "$1" >&2
failures=$((failures + 1))
}
HOME="$work/home"
SANDBOX_NAME=ai-test
mkdir -p "$HOME"
sbx() {
[[ "$1" == exec && "$2" == "$SANDBOX_NAME" && "$3" == bash && "$4" == -c ]] ||
fail "unexpected sbx invocation: $*"
HOME="$HOME" bash -c "$5"
}
resolved() {
git -C "$work/repo" ls-remote --get-url origin
}
git init --quiet "$work/repo"
for remote in \
'[email protected]:owner/repo.git' \
'ssh://[email protected]/owner/repo.git'; do
rm -f "$HOME/.gitconfig"
git -C "$work/repo" remote remove origin 2>/dev/null || true
git -C "$work/repo" remote add origin "$remote"
[[ "$(resolved)" == "$remote" ]] ||
fail "$remote was already rewritten before the sandbox was configured"
install_sandbox_git_https
[[ "$(resolved)" == 'https://github.com/owner/repo.git' ]] ||
fail "$remote resolved to $(resolved), not an HTTPS URL"
done
install_sandbox_git_https
install_sandbox_git_https
values="$(HOME="$HOME" git config --global --get-all \
'url.https://github.com/.insteadOf' | wc -l)"
[[ "$values" -eq 2 ]] ||
fail "repeated setup left $values insteadOf values, expected 2"
git -C "$work/repo" remote set-url origin '[email protected]:owner/repo.git'
[[ "$(resolved)" == '[email protected]:owner/repo.git' ]] ||
fail "a non-GitHub remote was rewritten to $(resolved)"
((failures == 0)) ||
exit 1
printf 'ok: GitHub SSH remotes are rewritten to HTTPS inside the sandbox\n'