Catch Stale Forgejo Host Allowlists

Repaired the live islandflow PR routing failure and added a repo-aware doctor check so stale Forgejo host allowlists are diagnosed before Codex.app delegates to the real GitHub CLI.

ScopeDoctor diagnostics, current-repo host detection, and unit coverage.
Issuegh-forgejo-shim-bh7
Validation85 unit tests plus live no-create PR routing smoke checks passed.

Summary

islandflow now detects as git.dirtydishes.dev, but the local shim config only allowed the older git.deltaisland.io host. The shim therefore delegated PR creation to the real GitHub CLI, which rejected Codex.app's create-shaped command instead of calling Forgejo. The machine config was repaired, and the repo now teaches doctor to report the current checkout host explicitly.

Changes Made

Context

Logs showed repeated Codex.app PR status probes in /Users/kell/dev/islandflow and its Codex worktrees. Manual reproduction confirmed the key symptom: before the allowlist repair, shim routing did not engage and the real gh rejected flags such as -R or --json in the PR-create flow.

The live config repair added git.dirtydishes.dev to ~/.config/gh-forgejo-shim/config.toml. That machine-state change is documented separately in /Users/kell/docs/turns/2026-06-11-1310-repair-islandflow-pr-routing.html.

Important Implementation Details

Relevant Diff Snippets

This server-rendered Diffs excerpt shows the complete repo code change for the diagnostic and tests.

Expected Impact for End-Users

Developers running gh-forgejo-shim doctor inside a Forgejo checkout will now see whether that exact checkout's host is routed by the shim. If a repo changes from one host alias to another, the command points at the one-line allowlist repair instead of letting Codex.app fail later during PR creation.

Validation

Issues, Limitations, and Mitigations

Follow-up Work

No follow-up Beads issue is required right now. The main remaining operational step is to retry PR creation from Codex.app in islandflow; the CLI route is already healthy.