Repository navigation
Conversation
A failed Pull reported "git pull failed", tagged with a reason at best, so a dead SSH agent or a missing remote was named only by a code. Fetch failures already map authentication, network, missing-repository and reference-lock errors to fixed messages; pull now uses the same diagnoses and runs Git with LC_ALL=C so they match on any server locale. The reason tag is kept, raw Git output still never enters the error, and unrecognised failures keep the generic message. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Contributor
ApprovabilityVerdict: Not approved Macroscope's review found this PR not approvable — This focused fix changes production handling of Git authentication failures and potentially credential-bearing remote stderr while adding locale-dependent diagnosis behavior. Although the existing pull flow is largely preserved and redaction is tested, the sensitive-data and authentication implications warrant human review. You can add or adjust custom eligibility rules. Learn more. |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Supersedes #14702, which was closed because it did not name the model and harness used. This is a fresh rebuild on current
mainby the model and harness listed at the end, reviewed by two others.What Changed
pullCurrentBranchnow explains a failedgit pull --ff-onlywith the fixed diagnoses #12485 added for fetch. When Git's output matches a known case the detail says "Git could not authenticate with the remote…", "Git could not reach the remote…", "Git could not access the remote repository…" or the reference-lock message. Anything else keeps "git pull failed". Thereasontag from #8645 is kept as it is.Raw Git output still never enters the error; only the fixed messages do. To match them on any server,
git pullnow runs withLC_ALL=C, like the fetch path. The output cap guard for large fast-forwards (appendTruncationMarker) is unchanged.Two small changes to the shared diagnosis, both found in review: the network case now also recognises macOS and unroutable ssh wording (
Operation timed out,No route to host,Host is down), so an unreachable host on the main desktop platform is named; and the lock message says a lock "may be blocking Git" rather than "the fetch", since it now also covers pull'sindex.lock.Why
The triage of #11872 names this as its secondary problem: when a desktop SSH remote loses its forwarded agent, Pull fails and the
Permission denied (publickey)that explains it never reaches the UI. #12485 fixed that for fetches; the Pull action was left on the generic message. Since #14702 was opened, #8645 added a reason tag, somainnow shows a code rather than nothing, but still not an explanation:mainGit command failed in GitVcsDriver.pullCurrentBranch.pull (<repo>): git pull failed (authentication_failed)Git command failed in GitVcsDriver.pullCurrentBranch.pull (<repo>): Git could not authenticate with the remote. Check Git credentials or SSH access on the server, then retry. (authentication_failed)A small, focused fix for that defect: one call site, reusing the existing helper, with no change to what Pull does or to any default. It does not fix the agent lifetime bug in #11872 itself.
UI Changes
The toast text changes as in the table above. Screenshots from #14702, taken before #8645 added the trailing reason tag (so today's "before" also ends in
(authentication_failed)):Before:
After:
These were captured against a Linux host over SSH in the state #11872 describes; see #14702 for that setup.
Verification
vp test run src/vcs/GitVcsDriverCore.test.tsfromapps/server: 144 passed. New, all with real Git:sshprints OpenSSH'sPermission denied (publickey)line only under the C locale, so the test also proves pull fixes the locale; the error has the authentication detail andreason: "authentication_failed", and a marker printed alongside never appears in the message;reason: "remote_unreachable";mainand the new tests kept, both new pull tests fail (expected 'git pull failed' to include 'could not access the remote repository',… to include 'could not authenticate'). With the fix but withoutLC_ALL=Con pull, the SSH test fails the same way.vp exec tsc --noEmit -p .inapps/server: exit 0.vp lintandvp fmt --checkon the two changed files: clean apart from two existing warnings on lines this PR does not touch.Not checked in this rebuild: a fresh in-app run and the Linux/Windows test runs; #14702 did both for the same call-site change.
Review notes not acted on, deliberately out of scope:
LC_ALL=Calso reaches hooks run during the pull (post-merge), as it already does for fetch; and background auto-pull still runs withoutGIT_TERMINAL_PROMPT=0.Models