From 942f717eb4e3b47ab08286b7612de0f42544e3ee Mon Sep 17 00:00:00 2001 From: Bryan Helmkamp Date: Fri, 6 Mar 2026 15:44:00 -0500 Subject: [PATCH] Fix GitHub App repo visibility check: treat 401/403 as private The is_repo_public function called GET /repos/{owner}/{repo} with the App JWT, but GitHub returns 401 for App JWTs on the repos endpoint (they need an installation token). Previously this 401 was treated as an auth error, failing sandbox init. Now 401 and 403 are treated like 404: assume private and proceed to create an installation access token, which has the right perms. Also add preflight phase to the DOT test runner. Co-Authored-By: Claude Opus 4.6 (1M context) --- crates/arc-workflows/src/github_app.rs | 13 ++++++++++--- test/docs/run_tests.sh | 15 ++++++++++++++- 2 files changed, 24 insertions(+), 4 deletions(-) diff --git a/crates/arc-workflows/src/github_app.rs b/crates/arc-workflows/src/github_app.rs index 7f4dc86be..27e32feac 100644 --- a/crates/arc-workflows/src/github_app.rs +++ b/crates/arc-workflows/src/github_app.rs @@ -60,8 +60,9 @@ pub fn sign_app_jwt(app_id: &str, private_key_pem: &str) -> Result&1); then + echo " PASS $rel" + pass=$((pass + 1)) + else + echo " FAIL $rel" + fail=$((fail + 1)) + fi + ;; dry-run|haiku|full) # cd into the dot file's directory so relative script paths resolve local target="$dot_name" @@ -56,7 +69,7 @@ run_one() { fi ;; *) - echo "Usage: $0 " + echo "Usage: $0 " exit 1 ;; esac