From a5cafb291c23168fcd268edd3fe855d74ef8a977 Mon Sep 17 00:00:00 2001 From: Ryan Hughes Date: Wed, 26 Aug 2026 17:44:10 -0400 Subject: [PATCH] Push over SSH from the tmp clones; keep reads on anonymous HTTPS MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The work/mirror clones were HTTPS end to end, so pushes went through git's credential-helper config — which breaks the moment a stale absolute gh path is baked into it (as gh auth setup-git once did with /usr/bin/gh). Reads stay anonymous HTTPS; pushes now use an SSH push URL (derived from the clone URL, overridable with OMARCHY_UPSTREAM_PUSH_URL), set idempotently on every run so existing cached clones self-repair. --- bin/omarchy-release | 15 +++++++++++++++ 1 file changed, 15 insertions(+) diff --git a/bin/omarchy-release b/bin/omarchy-release index 382ee1b..9a476ed 100755 --- a/bin/omarchy-release +++ b/bin/omarchy-release @@ -133,6 +133,19 @@ newest_release_branch() { # newest_release_branch [--untagged] open_train_branch() { newest_release_branch --untagged; } +# Reads go over anonymous HTTPS; pushes go over SSH like every checkout the +# operator owns. Pushing over HTTPS would drag in git's credential-helper +# config, which breaks the moment a stale absolute gh path is baked into it. +ssh_push_url() { # https://github.com/a/b.git -> git@github.com:a/b.git + local url="$1" + if [[ "$url" =~ ^https://github\.com/(.+)$ ]]; then + echo "git@github.com:${BASH_REMATCH[1]}" + else + echo "$url" + fi +} +UPSTREAM_PUSH_URL="${OMARCHY_UPSTREAM_PUSH_URL:-$(ssh_push_url "$UPSTREAM_URL")}" + ensure_mirror_clone() { if [[ -d "$MIRROR_CLONE" ]]; then git -C "$MIRROR_CLONE" fetch --quiet origin @@ -141,6 +154,7 @@ ensure_mirror_clone() { print_info "Cloning $UPSTREAM_URL (cached in $SRCDEST_DIR)..." git clone --mirror --quiet "$UPSTREAM_URL" "$MIRROR_CLONE" fi + git -C "$MIRROR_CLONE" remote set-url --push origin "$UPSTREAM_PUSH_URL" } ensure_work_clone() { @@ -151,6 +165,7 @@ ensure_work_clone() { print_info "Cloning $UPSTREAM_URL working copy..." git clone --quiet "$UPSTREAM_URL" "$WORK_CLONE" fi + git -C "$WORK_CLONE" remote set-url --push origin "$UPSTREAM_PUSH_URL" } # --- published channel state -------------------------------------------------