Repository navigation
Fix SSH LocalCommand incompatibility with Fish shell #2749
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
96ca54e
a549e3f
ba43f2c
4e9c2c4
6559057
173f075
c43c1b4
9881d5f
0a833c3
f6ba979
80572fc
d6cbeac
60ee311
27f4a2a
570c15e
1498e30
4148ccd
2f4e1d4
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change | ||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| @@ -0,0 +1,61 @@ | ||||||||||||||||||||||||||||||||||||||||||
| name: Sync upstream | ||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||
| on: | ||||||||||||||||||||||||||||||||||||||||||
| schedule: | ||||||||||||||||||||||||||||||||||||||||||
| # Daily at 06:00 UTC | ||||||||||||||||||||||||||||||||||||||||||
| - cron: "0 6 * * *" | ||||||||||||||||||||||||||||||||||||||||||
| workflow_dispatch: | ||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||
| permissions: | ||||||||||||||||||||||||||||||||||||||||||
| contents: write | ||||||||||||||||||||||||||||||||||||||||||
| issues: write | ||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||
| jobs: | ||||||||||||||||||||||||||||||||||||||||||
| sync: | ||||||||||||||||||||||||||||||||||||||||||
| runs-on: ubuntu-latest | ||||||||||||||||||||||||||||||||||||||||||
|
Comment on lines
+9
to
+15
|
||||||||||||||||||||||||||||||||||||||||||
| steps: | ||||||||||||||||||||||||||||||||||||||||||
| - uses: actions/checkout@v4 | ||||||||||||||||||||||||||||||||||||||||||
| with: | ||||||||||||||||||||||||||||||||||||||||||
| ref: fix/ssh-fish-shell-compat | ||||||||||||||||||||||||||||||||||||||||||
| fetch-depth: 0 | ||||||||||||||||||||||||||||||||||||||||||
|
Comment on lines
+17
to
+20
|
||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||
| - name: Configure git | ||||||||||||||||||||||||||||||||||||||||||
| run: | | ||||||||||||||||||||||||||||||||||||||||||
| git config user.name "github-actions[bot]" | ||||||||||||||||||||||||||||||||||||||||||
| git config user.email "github-actions[bot]@users.noreply.github.com" | ||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||
| - name: Fetch upstream | ||||||||||||||||||||||||||||||||||||||||||
| run: | | ||||||||||||||||||||||||||||||||||||||||||
| git remote add upstream https://github.com/manaflow-ai/cmux.git || true | ||||||||||||||||||||||||||||||||||||||||||
| git fetch upstream main | ||||||||||||||||||||||||||||||||||||||||||
|
Comment on lines
+27
to
+30
|
||||||||||||||||||||||||||||||||||||||||||
| git remote add upstream https://github.com/manaflow-ai/cmux.git || true | |
| git fetch upstream main | |
| if git remote get-url upstream >/dev/null 2>&1; then | |
| git remote set-url upstream https://github.com/manaflow-ai/cmux.git | |
| else | |
| git remote add upstream https://github.com/manaflow-ai/cmux.git | |
| fi | |
| git fetch upstream main |
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In @.github/workflows/sync-upstream.yml around lines 29 - 30, Replace the
unconditional "git remote add upstream ... || true" with a deterministic
existence check and explicit add/update so real errors aren't masked: run a
check for the "upstream" remote (e.g., via "git remote get-url upstream" or
listing "git remote"), if it does not exist call "git remote add upstream
https://github.com/manaflow-ai/cmux.git", otherwise update it with "git remote
set-url upstream https://github.com/manaflow-ai/cmux.git"; remove the "|| true"
so failures surface and CI can fail on real setup errors.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
P1: This step pushes directly to main from a scheduled workflow with no human review gate. A bad upstream merge or misconfiguration could silently rewrite the default branch. Replace this with a PR creation step (e.g., gh pr create) so changes to main go through normal review, or remove this block entirely since the workflow's stated purpose is syncing the fix branch.
Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At .github/workflows/sync-upstream.yml, line 46:
<comment>This step pushes directly to `main` from a scheduled workflow with no human review gate. A bad upstream merge or misconfiguration could silently rewrite the default branch. Replace this with a PR creation step (e.g., `gh pr create`) so changes to `main` go through normal review, or remove this block entirely since the workflow's stated purpose is syncing the fix branch.</comment>
<file context>
@@ -0,0 +1,61 @@
+ if: steps.rebase.outputs.status == 'success'
+ run: git push --force-with-lease
+
+ - name: Update main from upstream
+ if: steps.rebase.outputs.status == 'success'
+ run: |
</file context>
Copilot
AI
Apr 9, 2026
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This workflow runs on a schedule with contents: write and performs a force-push plus pushes directly to main. That combination is high-risk: any mistake or unintended rebase/merge could rewrite history or update main without human review. Consider changing this to create/update a PR instead of pushing to main, removing the force-push, restricting triggers to workflow_dispatch (or gating with required approvals/environments), and scoping permissions to the minimum needed (e.g., avoid issues: write unless conflict-issue creation is required).
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Scope creep: this job mutates main, not just the fix branch.
This step goes beyond syncing fix/ssh-fish-shell-compat and can cause unexpected writes/failures on protected main (Line 49–Line 52). Keep this workflow scoped to the fix branch only.
Suggested change
- - name: Update main from upstream
- if: steps.rebase.outputs.status == 'success'
- run: |
- git checkout main
- git merge upstream/main --ff-only
- git push
+ # Intentionally omitted: this workflow should only sync fix/ssh-fish-shell-compat📝 Committable suggestion
‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.
| - name: Update main from upstream | |
| if: steps.rebase.outputs.status == 'success' | |
| run: | | |
| git checkout main | |
| git merge upstream/main --ff-only | |
| git push | |
| # Intentionally omitted: this workflow should only sync fix/ssh-fish-shell-compat | |
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In @.github/workflows/sync-upstream.yml around lines 46 - 52, The workflow step
named "Update main from upstream" mutates main directly; change it to update
only the target fix branch (e.g., fix/ssh-fish-shell-compat) by replacing the
hardcoded git checkout/merge/push sequence (git checkout main, git merge
upstream/main --ff-only, git push) with commands that checkout the
branch-to-update (use the branch variable like ${{ github.head_ref }} or a
dedicated input/ENV such as BRANCH_TO_UPDATE), merge upstream/main into that
branch (git merge upstream/main --ff-only) and push that branch only, ensuring
no direct writes to main or protected branches.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
P2: Conflict notification opens duplicate issues on repeated scheduled conflicts because issue creation is unconditional and not deduplicated.
Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At .github/workflows/sync-upstream.yml, line 56:
<comment>Conflict notification opens duplicate issues on repeated scheduled conflicts because issue creation is unconditional and not deduplicated.</comment>
<file context>
@@ -0,0 +1,61 @@
+ - name: Open issue on conflict
+ if: steps.rebase.outputs.status == 'conflict'
+ run: |
+ gh issue create \
+ --title "Upstream sync conflict on fix/ssh-fish-shell-compat" \
+ --body "Auto-rebase of \`fix/ssh-fish-shell-compat\` onto \`upstream/main\` failed with conflicts. Manual resolution needed." \
</file context>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Conflict handling is not idempotent and will spam issues.
If conflicts persist for multiple days, this creates a new issue every run. Add a guard to reuse an existing open conflict issue.
Suggested change
- name: Open issue on conflict
if: steps.rebase.outputs.status == 'conflict'
run: |
- gh issue create \
- --title "Upstream sync conflict on fix/ssh-fish-shell-compat" \
- --body "Auto-rebase of \`fix/ssh-fish-shell-compat\` onto \`upstream/main\` failed with conflicts. Manual resolution needed." \
- --label "sync-conflict"
+ TITLE="Upstream sync conflict on fix/ssh-fish-shell-compat"
+ EXISTING="$(gh issue list --state open --search "$TITLE in:title" --json number --jq '.[0].number')"
+ if [ -z "$EXISTING" ]; then
+ gh issue create \
+ --title "$TITLE" \
+ --body "Auto-rebase of \`fix/ssh-fish-shell-compat\` onto \`upstream/main\` failed with conflicts. Manual resolution needed." \
+ --label "sync-conflict"
+ fi
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}📝 Committable suggestion
‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.
| - name: Open issue on conflict | |
| if: steps.rebase.outputs.status == 'conflict' | |
| run: | | |
| gh issue create \ | |
| --title "Upstream sync conflict on fix/ssh-fish-shell-compat" \ | |
| --body "Auto-rebase of \`fix/ssh-fish-shell-compat\` onto \`upstream/main\` failed with conflicts. Manual resolution needed." \ | |
| --label "sync-conflict" | |
| - name: Open issue on conflict | |
| if: steps.rebase.outputs.status == 'conflict' | |
| run: | | |
| TITLE="Upstream sync conflict on fix/ssh-fish-shell-compat" | |
| EXISTING="$(gh issue list --state open --search "$TITLE in:title" --json number --jq '.[0].number')" | |
| if [ -z "$EXISTING" ]; then | |
| gh issue create \ | |
| --title "$TITLE" \ | |
| --body "Auto-rebase of \`fix/ssh-fish-shell-compat\` onto \`upstream/main\` failed with conflicts. Manual resolution needed." \ | |
| --label "sync-conflict" | |
| fi | |
| env: | |
| GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} |
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In @.github/workflows/sync-upstream.yml around lines 53 - 59, The "Open issue on
conflict" step currently always runs gh issue create, causing duplicate issues;
change it to first query open issues with the "sync-conflict" label and the same
title using gh issue list (or gh api) and, if an existing open issue is found,
reuse it by adding a comment or updating it (gh issue comment --issue <number>
or gh issue edit <number>), otherwise run gh issue create; implement this logic
in the step that checks steps.rebase.outputs.status == 'conflict' so the step
runs a small shell script that: calls gh issue list --label sync-conflict
--state open (or gh api) to find a matching title, extracts the issue number if
present, and branches to comment/update vs create accordingly.
Large diffs are not rendered by default.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The new
sync-upstream.ymlworkflow is not mentioned in the PR title/description and is unrelated to the stated goal of fixing SSHLocalCommandcompatibility. Please either (mandatory) remove this workflow from the PR or (optional) update the PR description/title to include the motivation, scope, and operational impact of adding upstream-sync automation so reviewers can evaluate it appropriately.