Catch Stale Forgejo Host Allowlists
Repaired the live islandflow PR routing failure and added a repo-aware doctor check so stale Forgejo host allowlists are diagnosed before Codex.app delegates to the real GitHub CLI.
gh-forgejo-shim-bh7Summary
islandflow now detects as git.dirtydishes.dev, but the local shim config only allowed the older git.deltaisland.io host. The shim therefore delegated PR creation to the real GitHub CLI, which rejected Codex.app's create-shaped command instead of calling Forgejo. The machine config was repaired, and the repo now teaches doctor to report the current checkout host explicitly.
Changes Made
- Added current-repo host detection to
run_checksusing existing git remote parsing. - Report an ok check when the current Forgejo host is allowlisted.
- Report a warning with the exact
gh-forgejo-shim config add-host HOSTrepair command when a non-GitHub host is detected but not allowlisted. - Keep ordinary GitHub remotes healthy by marking
github.comas delegated to the real GitHub CLI. - Added unit coverage for stale Forgejo hosts, healthy allowlisted hosts, and GitHub delegation.
Context
Logs showed repeated Codex.app PR status probes in /Users/kell/dev/islandflow and its Codex worktrees. Manual reproduction confirmed the key symptom: before the allowlist repair, shim routing did not engage and the real gh rejected flags such as -R or --json in the PR-create flow.
The live config repair added git.dirtydishes.dev to ~/.config/gh-forgejo-shim/config.toml. That machine-state change is documented separately in /Users/kell/docs/turns/2026-06-11-1310-repair-islandflow-pr-routing.html.
Important Implementation Details
- The new check is enabled by default for the real CLI path, where
doctorloads config itself. - Tests that pass a synthetic
Configkeep the previous default unless they opt intocheck_current_repo=True, which avoids accidental coupling to the developer's current checkout. - The warning is intentionally scoped to non-GitHub hosts so GitHub repositories still delegate normally.
Relevant Diff Snippets
This server-rendered Diffs excerpt shows the complete repo code change for the diagnostic and tests.
Expected Impact for End-Users
Developers running gh-forgejo-shim doctor inside a Forgejo checkout will now see whether that exact checkout's host is routed by the shim. If a repo changes from one host alias to another, the command points at the one-line allowlist repair instead of letting Codex.app fail later during PR creation.
Validation
python3 -m unittest tests.test_doctorpassed: 13 tests.PYTHONPATH=src python3 -m unittest discover -s testspassed: 85 tests.PYTHONPATH=src python3 -m gh_forgejo_shim doctorreportsgit.dirtydishes.devallowlisted fordirtydishes/islandflow.gh repo view -R git.dirtydishes.dev/dirtydishes/islandflow --json ...returned Forgejo-shaped repo metadata.gh pr create ... --web --json ...returned the Forgejo compare URL without creating a PR.
Issues, Limitations, and Mitigations
- The code change improves diagnostics; the live PR repair came from adding the new host to the user's shim config.
- Only the public GitHub hosts are treated as known delegation hosts. Other non-allowlisted enterprise hosts will warn, which is safer for this Forgejo-focused shim.
- No real PR was created during validation; the smoke test used
--webso it exercised routing and parsing without POSTing to Forgejo.
Follow-up Work
No follow-up Beads issue is required right now. The main remaining operational step is to retry PR creation from Codex.app in islandflow; the CLI route is already healthy.