From 930aa1b5dd7d2fac98721cc0712cc70a1cf1f479 Mon Sep 17 00:00:00 2001 From: "@permadeath.com" Date: Wed, 26 Aug 2026 14:07:23 -0400 Subject: [PATCH] docs(plan): record the configure half of the unverified-key gap Filed in `configuration` beside the `clone --ssh` entry it repeats rather than in `repos`, because the subject is a failed lookup being read as an answer. Change-Id: Ie2008886874ecc1b92409074c8bc849c8a926c5e --- plan/configuration.md | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/plan/configuration.md b/plan/configuration.md index 682b1f2..e8ac606 100644 --- a/plan/configuration.md +++ b/plan/configuration.md @@ -95,6 +95,18 @@ that is a decision about precedence rather than about a parser. confirmed case was refused. An unverified key went ahead over SSH with no gate on it at all. `--ssh` now refuses on a lookup failure explicitly, the same way it already refused on a confirmed one +- [x] A third of the same shape, and the reason this sits here rather than in + `repos`: it is the entry above it happening again in the other command, + an unreachable service being read as an answer. `repo configure` warned + and exited 0 whenever the push-key lookup itself failed, after the + `[user]` identity for the new account had already been written — so + `--account B` against a stalled PDS left commits authored as B while + `core.sshCommand` went on offering A's key, and the next push + authenticated to the knot as A. With nothing pinned the warning stays, + because nothing is left wrong; with a pin already there it is now a + refusal that names the half-applied checkout, since that value is a + claim about a different account than the one just written. Decided by + one pure function so the choice is tested without a network - [x] `clients/endpoints.rs` — the five hostnames atgc has compiled in (`ATGC_PLC`, `ATGC_BOBBIN`, `ATGC_APPVIEW`, `ATGC_KNOT`, `ATGC_BSKY_APPVIEW`), each a whole base URL so a local instance on a -- 2.51.2