Files
orca/src/main/runtime/runtime-git-execution-host-ownership.test.ts
T
Neil d5750648c2 fix(runtime): route runtime Git by resolved execution host, not repo connectionId (#18307)
`RuntimeGitTarget` carried `connectionId?: string` and no host id, so `undefined`
spelled three different answers at once — "runtime: host", "unresolved", and
"genuinely local". Its sole resolver read `store.getRepo(worktree.repoId)?.connectionId`
and never looked at `worktree.hostId`, which outranks every repo row, so one
arbitrarily chosen row decided the execution host for 36 downstream dispatches.

The target now carries `executionHostId: ExecutionHostId` (never null, never
optional), resolved through the shared rule that landed with #17909/#17919 and
dispatched through the host-keyed routes from #18296. Dispatch sites call
`requireRuntimeGitProvider`, where `null` means exactly one thing: the host is
`local` and the command runs here as free functions.

Four answers that used to collapse into one:

- `ssh:x` with a rival row on `ssh:y` — routes to x. Previously the first row won,
  which is the reproduced cross-host leak.
- `local` with a surviving `connectionId` — a row contradicting itself; no SSH
  connection is handed out.
- `runtime:<env>` — throws `ExecutionHostNotDispatchableError`. Its repo row's
  connection names a target in the *server's* namespace; dialling it here reaches a
  same-named target on this client.
- rival rows disagreeing with no worktree host — `worktree_execution_host_unresolved`,
  matching the launch path rather than guessing a row.

An unreachable SSH host still throws `SSH_GIT_PROVIDER_UNAVAILABLE_MESSAGE`; loss of
contact is never evidence of locality (docs/reference/ssh-execution-boundary.md).

`resolveWorktreeLaunchHost` keeps its exact signature and now delegates to
`resolveWorktreeHostRouting`, the same resolution answering "which host is this on"
rather than "what may this client dial" — the git target needs the first question
because `local` and `runtime:` are two different non-SSH answers.

No wire change: `RuntimeGitTarget` is main-process internal, and the SSH and local
model-discovery host keys are byte-identical to before.

`RuntimeFileTarget` has the same defect in ~30 filesystem dispatches and is
deliberately left for a follow-up.
2026-09-02 19:26:07 -07:00

71 lines
2.5 KiB
TypeScript

import { beforeEach, describe, expect, it, vi } from 'vitest'
import type { GlobalSettings } from '../../shared/global-settings-types'
import type * as GitRemoteModule from '../git/remote'
import type * as GitStatusModule from '../git/status'
import type * as SshGitDispatchModule from '../providers/ssh-git-dispatch'
import type { ResolvedRuntimeGitWorktree } from './orca-runtime-git'
import { RuntimeGitCommands } from './orca-runtime-git'
import { SSH_GIT_PROVIDER_UNAVAILABLE_MESSAGE } from '../providers/ssh-git-dispatch'
const mocks = vi.hoisted(() => ({
getSshGitProvider: vi.fn(),
getStatus: vi.fn(),
gitFetch: vi.fn(),
stageFile: vi.fn()
}))
vi.mock('../providers/ssh-git-dispatch', async () => ({
...(await vi.importActual<typeof SshGitDispatchModule>('../providers/ssh-git-dispatch')),
getSshGitProvider: mocks.getSshGitProvider
}))
vi.mock('../git/status', async () => ({
...(await vi.importActual<typeof GitStatusModule>('../git/status')),
getStatus: mocks.getStatus,
stageFile: mocks.stageFile
}))
vi.mock('../git/remote', async () => ({
...(await vi.importActual<typeof GitRemoteModule>('../git/remote')),
gitFetch: mocks.gitFetch
}))
function remoteCommands(): RuntimeGitCommands {
const worktree = {
id: 'wt-1',
repoId: 'repo-1',
path: '/remote/repo',
git: { path: '/remote/repo', branch: 'main', isBare: false, isMainWorktree: false }
} as unknown as ResolvedRuntimeGitWorktree
return new RuntimeGitCommands({
resolveRuntimeGitTarget: async () => ({ worktree, executionHostId: 'ssh:ssh-1' }),
getRuntimeSettings: () => ({}) as GlobalSettings
})
}
describe('runtime Git execution-host ownership', () => {
beforeEach(() => {
mocks.getSshGitProvider.mockReset().mockReturnValue(undefined)
mocks.getStatus.mockReset()
mocks.gitFetch.mockReset()
mocks.stageFile.mockReset()
})
it('never substitutes local reads, sync, or mutations when the SSH provider is absent', async () => {
const commands = remoteCommands()
await expect(commands.getRuntimeGitStatus('id:wt-1')).rejects.toThrow(
SSH_GIT_PROVIDER_UNAVAILABLE_MESSAGE
)
await expect(commands.fetchRuntimeGit('id:wt-1')).rejects.toThrow(
SSH_GIT_PROVIDER_UNAVAILABLE_MESSAGE
)
await expect(commands.stageRuntimeGitPath('id:wt-1', 'src/a.ts')).rejects.toThrow(
SSH_GIT_PROVIDER_UNAVAILABLE_MESSAGE
)
expect(mocks.getStatus).not.toHaveBeenCalled()
expect(mocks.gitFetch).not.toHaveBeenCalled()
expect(mocks.stageFile).not.toHaveBeenCalled()
})
})