fix(repo): resolve --cluster clone target via that cluster's core · Entire
fix(repo): resolve --cluster clone target via that cluster's core
bd94266→main·
toothbrush·2w ago·2 files·+35 added/-3 removed
An explicit --cluster may name a cluster in a different federation than
the active auth context. Listing mirrors from the active core misses it,
failing with "not mirrored on
Co-Authored-By: Claude Opus 4.8 (1M context) noreply@anthropic.com
Sessions
512cfb860203View transcript
[?
Add Entire Repo Clone CommandClaude Code·Opus 4.8[1m]·1 step](/content/gh/entireio/cli/session/e77355db-5c1c-4286-94f0-431cf4b77954#timeline-512cfb860203/index.html)
Changes
2
cmd/entire/cli
Mrepo_clone.go+21/-3
Mrepo_clone_test.go+14
75 unmodified lines
76
77
78
79
79
80
81
82
83
84
85
86
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
10 unmodified lines
118
119
120
103
121
122
123
124
75 unmodified lines
}
var mirrors []coreapi.Mirror
if err := runCore(cmd, func(ctx context.Context, c *coreapi.Client) error {
lister := func(ctx context.Context, c *coreapi.Client) error {
ms, err := listMirrorsForRepo(ctx, c, provider, owner, repo)
if err != nil {
return err
}
mirrors = ms
return nil
}); err != nil {
}
// An explicit --cluster may name a cluster in a different federation
// than the active context, whose mirrors the active-context core can't
// see (the original bug: cloning a royalcanin.partial.to mirror while a
// different context is active failed with "not mirrored on ..."). Dial
// the core fronting that cluster — discovered from its well-known and
// authenticated with the matching local context, the same path
// `mirror create <url> [cluster]` uses — so the lookup resolves against
// the right federation. With no --cluster, list from the active context.
runWithCore := runCore
if cluster != "" {
if err := validateClusterHost(cluster); err != nil {
return fmt.Errorf("invalid --cluster: %w", err)
}
runWithCore = func(cmd *cobra.Command, fn func(context.Context, *coreapi.Client) error) error {
return runCoreForCluster(cmd, cluster, fn)
}
}
if err := runWithCore(cmd, lister); err != nil {
return err
}
10 unmodified lines
return runGitClone(cmd.Context(), cmd, cloneURL, targetDir)
},
}
cmd.Flags().StringVar(&cluster, "cluster", "", "cluster host to clone from when the repo is mirrored on more than one")
cmd.Flags().StringVar(&cluster, "cluster", "", "cluster host to clone from when the repo is mirrored on more than one (may live in another auth context; resolved via that cluster's core)")
return cmd
}
Mcmd/entire/cli/repo_clone.go+21/-3
95 unmodified lines
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
95 unmodified lines
require.NotNil(t, cmd.Flags().Lookup("cluster"))
}
// TestRepoClone_InvalidClusterFlag locks in that a malformed --cluster is
// rejected up front (before any core is dialled), so the anti-token-leak guard
// validateClusterHost applies to the user-supplied cluster the clone routes to.
func TestRepoClone_InvalidClusterFlag(t *testing.T) {
t.Parallel()
cmd := newRepoCloneCmd()
cmd.SetOut(&nopWriter{})
cmd.SetErr(&nopWriter{})
cmd.SetArgs([]string{"/gh/entirehq/entire-api", "--cluster", "aws-us-east-2.entire.io@evil.com"})
err := cmd.ExecuteContext(t.Context())
require.Error(t, err)
require.Contains(t, err.Error(), "invalid --cluster")
}
func newCloneTestCmd() *cobra.Command {
cmd := newRepoCloneCmd()
cmd.SetOut(&nopWriter{})