Repository navigation
refactor: trim A1 GitHub transport to what #638 asked for - #650
Merged
Merged
Conversation
Tryanks
marked this pull request as ready for review
October 8, 2026 11:26
This was referenced Oct 8, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Corrective follow-up to #647 (phase A1, #638): it removes what #638 did not ask for and simplifies the rest.
Refs #638, #649.
Evidence
After: re-entering the section already rescans gh (
GitHubSettingsPanel::show), so the button is gone. FreshTCODE_DATA_DIR, English, synthetic hostname, a fakeghwith loginssample-user/sample-work, and a synthetic saved token forgithub.example.com:secrets.jsonbecame a versioned envelope on the first secret write after feat: add GitHub transport and Source Control settings #647, which older builds cannot read.After: the file stays the flat profile map. GitHub tokens sit under
@github, a key no profile id can take: user ids are slugs of[a-z0-9-]and built-ins are fixed (Settings::allocate_profile_id,builtin_profile_id).github_secret_command_persists_separately_and_settings_never_replicate_itnow asserts:BTreeMap<String, BTreeMap<String, String>>(the shape older builds read);githubkeeps its secrets;Checks on the final commit:
gh auth token --hostname github.comexited 0 (stdout discarded). An uncommitted scratch example, since deleted, ran the authenticatedGET /userthroughGitHubApi::verified_credentialwith the env tokens removed and gotlogin=Tryanks.Tests deleted or rewritten (CONTRIBUTING, "When a test fails, or is met on the way"):
whole_response_result_deadline_includes_a_stalled_dns_resolver: deleted (step 2). It proved a result deadline around DNS that only the per-request thread provided. ureq 2 does not bound DNS (ureq-2.12.1/src/stream.rs:364, "TODO: Find a way to apply deadline to DNS lookup"). The system resolver bounds it instead, and that is carried in a comment atexecute. The connect, TLS, write and body deadline stays covered bybody_cap_and_deadline_cover_streaming_after_headers.github_secret_command_persists_separately_and_settings_never_replicate_it: envelope assertions removed with the envelope (version,profiles, unsupported version). The flat-format, legacy-github-profile and fail-closed contracts remain.secrets_keep_reconnect_delivery_keys_without_entering_the_persisted_outbox: the legacy-outbox purge assertions are removed with the purge. Restored entries are delivered from memory, and the next persist drops them from disk through the existingsnapshotfilter.Test declarations: 1030 → 1029. Production Rust and locales: +77/−260 lines; docs: +6. Tests: +23/−99.
Merge Danger
Door: two-way
Blast Radius: credentials
{"version":1,…}envelope. This build reads no provider secrets from it and refuses to write over it (settings_write_failed); it does not erase it. Fix by hand: moveprofiles.*to the root andgithubto@github. Check withjq 'has("version")' ~/.tcode/secrets.json. No release contains feat: add GitHub transport and Source Control settings #647 (git tag --contains ebd4f659is empty).@githubamong provider secret names (host names only, never values) and preserves it on writes.