Files
orca/src/main/runtime/runtime-git-command-target.test.ts
T
Neil d5750648c2 fix(runtime): route runtime Git by resolved execution host, not repo connectionId (#18307)
`RuntimeGitTarget` carried `connectionId?: string` and no host id, so `undefined`
spelled three different answers at once — "runtime: host", "unresolved", and
"genuinely local". Its sole resolver read `store.getRepo(worktree.repoId)?.connectionId`
and never looked at `worktree.hostId`, which outranks every repo row, so one
arbitrarily chosen row decided the execution host for 36 downstream dispatches.

The target now carries `executionHostId: ExecutionHostId` (never null, never
optional), resolved through the shared rule that landed with #17909/#17919 and
dispatched through the host-keyed routes from #18296. Dispatch sites call
`requireRuntimeGitProvider`, where `null` means exactly one thing: the host is
`local` and the command runs here as free functions.

Four answers that used to collapse into one:

- `ssh:x` with a rival row on `ssh:y` — routes to x. Previously the first row won,
  which is the reproduced cross-host leak.
- `local` with a surviving `connectionId` — a row contradicting itself; no SSH
  connection is handed out.
- `runtime:<env>` — throws `ExecutionHostNotDispatchableError`. Its repo row's
  connection names a target in the *server's* namespace; dialling it here reaches a
  same-named target on this client.
- rival rows disagreeing with no worktree host — `worktree_execution_host_unresolved`,
  matching the launch path rather than guessing a row.

An unreachable SSH host still throws `SSH_GIT_PROVIDER_UNAVAILABLE_MESSAGE`; loss of
contact is never evidence of locality (docs/reference/ssh-execution-boundary.md).

`resolveWorktreeLaunchHost` keeps its exact signature and now delegates to
`resolveWorktreeHostRouting`, the same resolution answering "which host is this on"
rather than "what may this client dial" — the git target needs the first question
because `local` and `runtime:` are two different non-SSH answers.

No wire change: `RuntimeGitTarget` is main-process internal, and the SSH and local
model-discovery host keys are byte-identical to before.

`RuntimeFileTarget` has the same defect in ~30 filesystem dispatches and is
deliberately left for a follow-up.
2026-09-02 19:26:07 -07:00

88 lines
3.1 KiB
TypeScript

import { afterEach, describe, expect, it } from 'vitest'
import { ExecutionHostNotDispatchableError } from '../providers/execution-host-provider-dispatch'
import { registerSshGitProvider, unregisterSshGitProvider } from '../providers/ssh-git-dispatch'
import {
localGitOptionsForTarget,
requireRuntimeGitProvider,
runtimeGitRouteForTarget,
type RuntimeGitTarget
} from './runtime-git-command-target'
const worktree = {
id: 'wt-1',
repoId: 'repo-1',
path: '/srv/app',
git: { path: '/srv/app', branch: 'main', isBare: false, isMainWorktree: false }
} as unknown as RuntimeGitTarget['worktree']
function target(overrides: Partial<RuntimeGitTarget>): RuntimeGitTarget {
return { worktree, executionHostId: 'local', ...overrides }
}
describe('runtime Git target routing', () => {
const registered: string[] = []
function register(connectionId: string) {
const provider = { getStatus: async () => ({ entries: [] }) }
registerSshGitProvider(connectionId, provider as never)
registered.push(connectionId)
return provider
}
afterEach(() => {
for (const connectionId of registered.splice(0)) {
unregisterSshGitProvider(connectionId)
}
})
it('routes each ssh host to its own provider', () => {
const m4air = register('m4air')
const openclaw = register('openclaw')
expect(runtimeGitRouteForTarget(target({ executionHostId: 'ssh:m4air' }))).toEqual({
kind: 'ssh',
connectionId: 'm4air',
provider: m4air
})
expect(requireRuntimeGitProvider(target({ executionHostId: 'ssh:openclaw' }))).toBe(openclaw)
})
it('answers `local` with no provider, which is the only meaning `null` carries', () => {
expect(runtimeGitRouteForTarget(target({}))).toEqual({ kind: 'local' })
expect(requireRuntimeGitProvider(target({}))).toBeNull()
})
// Loss of contact is never evidence of locality (docs/reference/ssh-execution-boundary.md).
it('keeps an unreachable ssh host remote instead of degrading it to local', () => {
const route = runtimeGitRouteForTarget(target({ executionHostId: 'ssh:gone' }))
expect(route).toEqual({ kind: 'ssh', connectionId: 'gone', provider: null })
expect(() => requireRuntimeGitProvider(target({ executionHostId: 'ssh:gone' }))).toThrow(
/Remote connection dropped/
)
})
it('refuses a runtime host even when a same-named target is registered here', () => {
register('nested-1')
expect(() => runtimeGitRouteForTarget(target({ executionHostId: 'runtime:env-a' }))).toThrow(
ExecutionHostNotDispatchableError
)
expect(() => requireRuntimeGitProvider(target({ executionHostId: 'runtime:env-a' }))).toThrow(
ExecutionHostNotDispatchableError
)
})
it('keeps WSL routing on the local host and off every other one', () => {
const localGitOptions = { wslDistro: 'Ubuntu' }
expect(localGitOptionsForTarget(target({ localGitOptions }))).toEqual(localGitOptions)
expect(
localGitOptionsForTarget(target({ executionHostId: 'ssh:m4air', localGitOptions }))
).toEqual({})
expect(
localGitOptionsForTarget(target({ executionHostId: 'runtime:env-a', localGitOptions }))
).toEqual({})
})
})