From ee21fa16f0cce229d91def7cb61a4ceb77bc4920 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Andr=C3=A9=20Padez?= Date: Wed, 12 Aug 2026 21:52:53 +0000 Subject: [PATCH] officer-setup: the repository URL is https MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit https://gitea.officer.dev/officerdev/platform.git, not the ssh form. The reachability check is now one test for either scheme: `git ls-remote` with both prompts disabled. That is the real question — not whether the host answers but whether this account can read the repository — and neither prompt fails cleanly on its own. Over https git asks for a username nobody is there to type; over ssh it asks for a password or stops on host-key verification. With GIT_TERMINAL_PROMPT=0 and BatchMode both off, an unreadable repository is an immediate non-zero rather than a hang. Co-Authored-By: Claude Opus 5 (1M context) --- scripts/setup/officer-setup.sh | 27 ++++++++++------------- scripts/setup/officer-setup/lib/repo.sh | 29 ++++++++++--------------- 2 files changed, 24 insertions(+), 32 deletions(-) diff --git a/scripts/setup/officer-setup.sh b/scripts/setup/officer-setup.sh index edb23428..9ea1fb0c 100755 --- a/scripts/setup/officer-setup.sh +++ b/scripts/setup/officer-setup.sh @@ -211,19 +211,16 @@ if ! skip; then CLONE_URL="$OFFICER_REPO" - # Checked before cloning. An ssh URL with no usable key does not fail - # cleanly: git prompts for a password nobody is there to type, or stops on - # host-key verification. - if [[ "$CLONE_URL" == ssh://* ]] && ! repo_ssh_ok "$CLONE_URL"; then + # Checked before cloning, for either scheme — see repo_reachable. + if ! repo_reachable "$CLONE_URL"; then echo "" - warn "${USERNAME} cannot authenticate to $(repo_ssh_host "$CLONE_URL") over ssh" - echo " Either add that account's public key to the git server, or clone" - echo " over https instead — which works without a key if the repository" - echo " is readable anonymously." + warn "${USERNAME} cannot read ${CLONE_URL}" + echo " Either the host is not answering yet, or the repository is not" + echo " readable without credentials." echo "" - echo " [1] https — $(repo_https_url "$CLONE_URL")" - echo " [2] ssh anyway — will fail if the key is genuinely missing" - echo " [3] stop here, and add the key first" + echo " [1] try it anyway" + echo " [2] use a different URL" + echo " [3] stop here" echo "" REPO_PICK="" while [[ -z "$REPO_PICK" ]]; do @@ -232,12 +229,12 @@ if ! skip; then fail "No answer." fi case "${REPO_CHOICE:-1}" in - 1) - CLONE_URL="$(repo_https_url "$CLONE_URL")" + 1) REPO_PICK=go ;; + 2) + ask_required CLONE_URL "Repository URL" "$CLONE_URL" REPO_PICK=go ;; - 2) REPO_PICK=go ;; - 3) fail "Stopped. Add ${USERNAME}'s public key to the git server and run this again." ;; + 3) fail "Stopped. Nothing below can run without the repository." ;; *) warn "Pick 1, 2 or 3." ;; esac done diff --git a/scripts/setup/officer-setup/lib/repo.sh b/scripts/setup/officer-setup/lib/repo.sh index 163a147b..bc5ec993 100644 --- a/scripts/setup/officer-setup/lib/repo.sh +++ b/scripts/setup/officer-setup/lib/repo.sh @@ -14,7 +14,7 @@ [[ -n "${OFFICER_SETUP_REPO_LOADED:-}" ]] && return 0 OFFICER_SETUP_REPO_LOADED=1 -OFFICER_REPO="${OFFICER_REPO:-ssh://git@gitea.officer.dev:2222/officerdev/platform.git}" +OFFICER_REPO="${OFFICER_REPO:-https://gitea.officer.dev/officerdev/platform.git}" platform_dir() { echo "${OFFICER_ROOT}/platform"; } @@ -30,21 +30,16 @@ repo_ssh_port() { sed -nE 's|^ssh://[^@]*@[^:]+:([0-9]+)/.*|\1|p' <<<"$1"; } # Can this account actually clone it? # -# Checked before the clone rather than after, because an ssh URL with no usable -# key does not fail cleanly — git either prompts for a password nobody is there -# to type, or hangs on host-key verification. BatchMode turns both into an -# immediate non-zero. -# -# Gitea answers a successful auth with a message and exit 1, so the test is -# whether the SERVER recognised us, not the exit code. -repo_ssh_ok() { - local url="$1" host port out - host="$(repo_ssh_host "$url")" - port="$(repo_ssh_port "$url")" - [[ -n "$host" ]] || return 1 - - out="$(as_owner "ssh -T -o BatchMode=yes -o StrictHostKeyChecking=accept-new -o ConnectTimeout=8 ${port:+-p $port} git@${host} 2>&1" || true)" - grep -qiE "authenticated|successfully|welcome|does not provide shell access" <<<"$out" +# `git ls-remote` is the real question — not "does the host answer" but "can this +# account read this repository". Both prompts are disabled, because neither fails +# cleanly on its own: over https git asks for a username nobody is there to type, +# and over ssh it asks for a password or stops on host-key verification. With +# both off, an unreachable or unreadable repository is an immediate non-zero +# instead of a hang. +repo_reachable() { + as_owner "GIT_TERMINAL_PROMPT=0 \ + GIT_SSH_COMMAND='ssh -o BatchMode=yes -o StrictHostKeyChecking=accept-new -o ConnectTimeout=8' \ + timeout 20 git ls-remote '$1' >/dev/null 2>&1" / } # The https form of the same repository, for a machine with no key. @@ -56,7 +51,7 @@ clone_repo() { local url="$1" dest dest="$(platform_dir)" install -d -m 0755 -o "$USERNAME" -g "$(user_group)" "$OFFICER_ROOT" - as_owner "git clone '${url}' '${dest}'" / + as_owner "GIT_TERMINAL_PROMPT=0 git clone '${url}' '${dest}'" / } pull_repo() { as_owner "git -C '$(platform_dir)' pull --ff-only" /; }