Files
orca/src/shared
Neil 0459905ca4 fix(hosts): make the dispatch refusal reachable from a repo row
`getRepoExecutionHostId` is total: a repo row whose `executionHostId` is present
but unparseable (`ssh:`, `ssh:a|b`, a scheme from a future build) falls through
to `connectionId`, then to `local`. That collapse sits one layer ABOVE the
host-keyed dispatch from #18296, so `UnresolvableExecutionHostError` could never
fire on a repo row — dispatch was never asked. `local` means "execute on this
machine", so the one wrong answer is the one it gave.

Adds `resolveRepoExecutionHostId`, which answers `null` for that row, and uses it
at the sites whose job is routing. The total reading is deliberately unchanged:
~340 callers — sidebar grouping, host labels, index and cache keys, set
membership — only need a bucket, and for them the fall-through is harmless.
Splitting the two keeps them off the strict path instead of making 60 files
handle a `null` they have no use for.

A malformed id does not fall back to `connectionId`: the row's own declaration is
the more specific claim, and recovering a host from the field it overrode is the
same guess relocated. `host-repo-catalog-snapshot` already calls that pair a
contradiction.

Routing sites now refusing rather than executing here: the workspace-cleanup git
route, hosted review (`git`/`gh`/`glab`), the `git remote` identity probe, the
workspace-space `du`/stat scan, worktree removal and its owner resolution,
per-host project removal, local worktree materialization, profile transfer, the
renderer's repo update/remove, the paired-client PTY owner, and the two
`worktrees:list` calls that would otherwise be answered by the handler's default
host.

Also, independent of the malformed case:

- `resolveWorktreeExecutionHost` gains a `malformed` reason distinct from
  `unknown`. `unknown` is a verdict the launch path may legitimately dispose of
  as a plain local folder; `malformed` must fail closed. One word for two
  situations is the shape that lost the distinction in #18006.
- `readAllWorktreeMetaForRepo` / `readWorktreeMetaForRepo` replace four
  open-coded copies of the same host-qualified read (the F7/F8 lockstep pattern).
- `getExecutionHostLabel` answers 'Unknown host' rather than 'All hosts' for an
  id that names no host. Showing one unroutable row as though it were on every
  host is wrong on its own terms. Plain English like every other label in that
  module, none of which resolve through the renderer's i18n catalog.

No producer of a malformed id exists in this repo (see the PR body); this is
defence at the boundary where the encoding contract is unenforced, not a fix for
an observed failure.
2026-09-04 00:32:59 -07:00
..
2026-05-31 05:55:04 -07:00
2026-09-03 17:32:59 -07:00