mirror of
https://github.com/fabro-sh/fabro.git
synced 2026-10-11 03:40:05 +00:00
Since the Petri cutover, a run with a GitHub target started in an empty workspace, nothing pushed its run branch to GitHub, and nothing asked for the automatic pull request when it succeeded. Fabro's hooks now check a fresh run's GitHub target out inside the sandbox when Petri hands them the scope, before the first stage: the workspace fetches the selected commit, tag or branch at the run's clone depth, with a read-only token the server resolves at each worker launch. The worker scrubs the token from its environment at startup and presents it only to the fetch, so it never lands in the repository or its remote. The files belong to the sandbox user, so git accepts them. The same checkout seeds the workspace's snapshot repository with the starting commit. Checkpoint bundles from a shallow clone then import, a stage's own commits never make a bundle carry the source's history, a restore into a fresh sandbox fetches the base again and applies the run's commits, and a fork carries the base with its checkpoints. When a successful GitHub-target run ends, the server pushes its final commit from the snapshot repository to fabro/run/<id> with its own write credentials, then, when the run changed files and asks for one, records the pull request request for the existing creation supervisor. A failed push or request is a warning notice on the run. The manual pull request endpoint shares the request step. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| brainstorms | ||
| ideation | ||
| internal | ||
| plans | ||
| public | ||
| superpowers | ||