Skip to content

fix(remote): resolve every remote repo to a trusted endpoint; fail closed otherwise - #649

Open
Ziinc wants to merge 8 commits into
mainfrom
claude/prd-gaps-remote-path-guards
Open

Ziinc wants to merge 8 commits into
mainfrom
claude/prd-gaps-remote-path-guards

Conversation

@Ziinc

@Ziinc Ziinc commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

…loopback test endpoint

A typed InspectRepository runs on the remote host, so its descriptor says
the repository is local. activeRepositoryFromRemote took that location, so a
repository opened through the descriptor/trust path was treated as local.

Remote workspace UI tests now open through the saved-descriptor restore over
a loopback endpoint whose typed commands run through remote_dispatch_local,
instead of the endpoint-less legacy blob.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MbYSPHBRmDYwPJpHG33Y4t
activeRepositoryFromRemote fell back to a local transport when a remote
repository had no endpoint, so every transport helper ran the operation as a
local Tauri command against the remote path. It is now an explicit
"unresolved" transport: routed reads and mutations throw
endpoint_unresolved, and assertLocalOperation keeps rejecting local-only
calls. The launch-time restore of the endpoint-less legacy blob is removed;
a repository reopens only through the saved descriptor and trust sequence.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MbYSPHBRmDYwPJpHG33Y4t
…ndpoint path

Alias mode on the "Your own VM" form opened the legacy "Open via SSH"
dialog. That dialog stored a RemoteRepository with no endpoint, used the
first local identity instead of the registered one, and relied on the
endpoint-less restore. The alias now resolves to the host and port it names.
The record keeps the registered fingerprint and identity, and the endpoint
goes through the same descriptor path as a hand-entered host.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MbYSPHBRmDYwPJpHG33Y4t
Alias mode now registers a trust-pinned endpoint, so nothing opens the
legacy dialog. That dialog stored endpoint-less repositories and ignored
the registered identity.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MbYSPHBRmDYwPJpHG33Y4t
@Ziinc Ziinc changed the title fix(remote): keep ssh location when remote inspection reports local; loopback test endpoint fix(remote): resolve every remote repo to a trusted endpoint; fail closed otherwise Oct 1, 2026

Ziinc commented Oct 1, 2026

Copy link
Copy Markdown
Collaborator Author

test-js / test:integration failed on a 5s timeout in test/integration/review/commit-auto-reload.test.tsx; the other 412 tests passed. This PR changes remote endpoint resolution and alias mode, not the review tab. The suite ran 561s against roughly 330s on fast runs, and the same 5s-timeout pattern has hit unrelated tests on other PRs; it's tracked in the handoff backlog (OPS-03). Re-running the failed job once.


Generated by Claude Code

@Ziinc Ziinc left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review at b23cfec9: Reviewed endpoint-backed remote descriptors, unresolved-transport rejection, alias resolution/trust retention, and removal of endpoint-less restore. No actionable correctness or code-quality issues found in this diff.

Validation: static review of the diff, surrounding implementation and tests; PR-head CI reports success. Rust/integration tests were not rerun locally because this environment has no Cargo toolchain.

claude added 3 commits October 3, 2026 00:47
Trust and connect resolved the alias a second time and overwrote the
confirmed host and port. With no Port in ~/.ssh/config the resolver's
default 22 replaced a typed 2222; with no HostName the alias name
replaced a typed address. The pinned endpoint then differed from the
one shown in the trust prompt. Registration now saves the confirmed
values unchanged; "Autofill from alias" still resolves the alias into
the form before the confirm step.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01E1poGWXMSFcPsJ8V5gujWG
…mmands with no callers

The removed "Open via SSH" dialog was the only caller of
remote_probe_repo_over_ssh, remote_open_repo_over_ssh,
remote_clone_repo_over_ssh and build_explicit_alias_ssh_endpoint. This
drops those Tauri commands, their API wrappers, the core helpers only
they used (probe/open/clone_repo_native, endpoint_label,
remote_repository_from_inspection, RemoteRepository,
build_explicit_alias_endpoint) and the tests that exercised only them.
Typed dispatch over SSH and ~/.ssh/config alias resolution stay.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01E1poGWXMSFcPsJ8V5gujWG
Restore reads only last_opened_remote_repo_id and the saved descriptor,
so nothing reads the legacy blob any more. Opening and restoring a
remote repository no longer writes it; clearing still blanks it.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01E1poGWXMSFcPsJ8V5gujWG

This branch was successfully deployed

1 active deployment
preview — 73e0b1ff Deployed Oct 3, 2026 by Ziinc via build #1649
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants