Skip to content

Surface wrong-cluster clone errors clearly in git-remote-entire - #1575

Merged
Soph merged 4 commits into
mainfrom
git-remote-entire-wrong-cluster-error
Jul 3, 2026
Merged

Soph merged 4 commits into
mainfrom
git-remote-entire-wrong-cluster-error

Conversation

@toothbrush

@toothbrush toothbrush commented Jun 30, 2026 •

Copy link
Copy Markdown
Contributor

https://entire.io/gh/entireio/cli/trails/701

What

Cloning a repo whose audience host doesn't match where the repo actually lives produced an opaque error:

fatal: stateless-connect v2 info/refs: fetching info/refs from entry domain: repo-scoped token exchange: oauth token exchange: HTTP 400: {"error":"invalid_target","error_description":"audience host \"aws-us-east-2.entire.io\" does not host this repo; it lives on \"aws-eu-central-1.entire.io\" — re-target the request there"}

Now it prints:

fatal: this repository is not hosted on aws-us-east-2.entire.io; it lives on aws-eu-central-1.entire.io.
Re-run against the correct host, e.g.:

    git clone entire://aws-eu-central-1.entire.io/et/paul/dogbark

How

  • httputil.OAuthError now captures the error_description field.
  • git-remote-entire errors.As-digs the buried OAuthError, and for invalid_target whose description names the hosting cluster ("… lives on """) renders an actionable message with the corrected entire:// URL. Other errors fall back verbatim.

🤖 Generated with Claude Code


Note

Cursor Bugbot is generating a summary for commit 97aa0c9. Configure here.

When a repo lives on a different cluster than the one in the entire://
URL, the data plane rejects the token exchange with an RFC 8693
invalid_target carrying an error_description naming the correct host.
Previously this surfaced as a raw, multiply-wrapped HTTP 400 JSON blob.

Now git-remote-entire detects this case and prints an actionable message
naming the correct host and the corrected `git clone entire://...` URL.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Entire-Checkpoint: 7cf3c440ed71
Copilot AI review requested due to automatic review settings June 30, 2026 00:31
@toothbrush
toothbrush requested a review from a team as a code owner June 30, 2026 00:31

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR improves the UX of git-remote-entire when a clone/fetch fails due to targeting the wrong Entire cluster host by extracting the server-provided error_description (RFC 6749) and rendering an actionable “re-run against the correct host” message (including a corrected entire:// clone URL).

Changes:

  • Extend httputil.OAuthError to capture error_description from OAuth token exchange failures.
  • Add git-remote-entire error unwrapping to detect invalid_target wrong-cluster failures and print a clearer, copy/paste-friendly remediation message.
  • Add unit tests in cmd/git-remote-entire for the new fatal error rendering behavior.

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 2 comments.

File Description
internal/entireclient/httputil/oauth.go Captures OAuth error_description into OAuthError for downstream UX decisions.
cmd/git-remote-entire/main.go Adds specialized fatal error formatting for wrong-cluster invalid_target failures.
cmd/git-remote-entire/main_test.go Adds coverage for the new fatal message formatting logic.

Comment thread cmd/git-remote-entire/main.go Outdated
Comment thread internal/entireclient/httputil/oauth.go
toothbrush and others added 2 commits June 30, 2026 10:18
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
…caping

Addresses PR review:
- Pin OAuthError.Description extraction so the git-remote-entire
  wrong-cluster UX can't silently regress.
- Rebuild the corrected entire:// URL from the user's parsed URL with
  only the host swapped, preserving RawPath/query escaping.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Entire-Checkpoint: ef974a99a5c2
@toothbrush

Copy link
Copy Markdown
Contributor Author

I should note that this implementation is pretty ugly (trying to read the error string) - our backend doesn't at the moment make it super easy to raise anything other than a string error message. That's something we should improve.

Comment thread cmd/git-remote-entire/main.go
Co-authored-by: Paulo Gomes <paulo@entire.io>
@Soph
Soph merged commit e1367fb into main Jul 3, 2026
9 checks passed
@Soph
Soph deleted the git-remote-entire-wrong-cluster-error branch July 3, 2026 11:22
timothybrush pushed a commit to timothybrush/cli-2 that referenced this pull request Sep 15, 2026
fatalMessage special-cased an RFC 8693 invalid_target error whose
description named the cluster actually serving the repo, turning it into
"this repository is not hosted on X; it lives on Y" plus a corrected
clone command. Nothing can produce that error any more, so the branch has
never been reachable in main.

It was added in entireio#1575 (2026-06-30), built on the repo-scoped token
exchange the helper performed at the time. entireio#1621 removed that exchange
for the interactive path — merged 2026-07-03 05:17, six hours BEFORE
entireio#1575 merged at 11:22 — and entireio#1622 migrated the ENTIRE_TOKEN path the next
morning. Both PRs were the same author's; neither conflicted with entireio#1575
in any file, so nothing flagged it. The helper now presents a
jurisdiction token as a bearer and never exchanges, so no invalid_target
is ever returned to it.

Measured rather than reasoned. Cloning a single-placement repo from the
wrong cluster, against a helper built from main:

    $ git clone entire://aws-eu-central-1.entire.io/gh/entireio/cli-perf-benchmarks
    fatal: stateless-connect v2 info/refs: Repository not found

with ENTIRE_DEBUG showing the wire:

    GET /gh/entireio/cli-perf-benchmarks/info/refs?service=git-upload-pack
    HTTP/1.1 404 Not Found
    Repository not found

A plain 404 with a four-word body: no invalid_target, no
error_description, nothing naming the correct host. The same repo on its
own cluster clones fine with the same credentials, so that 404 is the
wrong-cluster response rather than an access failure.

So this is not repairable here. The 404 carries no information about
where the repo lives, and no client-side matcher can invent it. Restoring
the UX needs the data plane to say so on that response — worth noting the
helper already looks for an X-Entire-Replicas header there and logs its
absence, so the mechanism may partly exist. Filed separately; this commit
only removes code that cannot run.

TestFatalMessage went with it. It passed throughout by constructing the
invalid_target error itself, which verified the formatting and could
never observe that the input had no producer — the reason a dead branch
survived two years of green CI.

fatalMessage reduced to a single Sprintf with one caller, so it is
inlined rather than kept as a seam. If the hint returns it will match a
404 body, not an OAuth error, and would not reuse this shape.

Verified: identical stderr before and after (the point of the change),
lint clean, GOOS=windows vet clean, helper and remotehelper suites pass.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Entire-Checkpoint: 01M2863QYHMEQG3P93TAGG0FGW
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

4 participants