Skip to content

fix(install): pre-flight SSH github.com marketplace plugins over SSH - #3200

Open
Mohammed Alkindi (MohammedAlkindi) wants to merge 1 commit into
microsoft:mainfrom
MohammedAlkindi:fix/ssh-github-marketplace-preflight
Open

Mohammed Alkindi (MohammedAlkindi) wants to merge 1 commit into
microsoft:mainfrom
MohammedAlkindi:fix/ssh-github-marketplace-preflight

Conversation

@MohammedAlkindi

Copy link
Copy Markdown
Contributor

Description

An in-repo plugin from a github.com marketplace registered over SSH resolves with explicit_scheme="ssh", but _validate_package_exists sent it to the HTTPS-only downloader probes, so an SSH-key-only private marketplace failed pre-flight. It now takes the git ls-remote clone-root probe from #2063. HTTPS registrations are unchanged.

before: Expected '_validate_virtual_package' to not have been called. (4 failed, 1 passed)
after:  5 passed

Issue and approved scope

Issue: #3164

Human scope-approval comment: #3164 (comment)

Remaining: a CLI install against a real SSH-only private marketplace.

Type of change

  • Bug fix
  • New feature
  • Documentation
  • Maintenance / refactor

Testing

  • Tested locally
  • All existing tests pass (Windows symlink-privilege failures, same without the fix)
  • Added tests for new functionality (if applicable)

Spec conformance (OpenAPM v0.1)

  • Spec edit: docs/src/content/docs/specs/openapm-v0.1.md updated
  • Manifest edit: docs/src/content/docs/specs/manifests/openapm-v0.1.requirements.yml updated
  • Test edit: a @pytest.mark.req("req-XXX") test under tests/spec_conformance/
  • CONFORMANCE.{md,json} regenerated via gen_statement
  • N/A -- this PR does not change OpenAPM-observable behaviour.

An in-repository plugin from a github.com marketplace registered over
SSH resolves to a virtual subdirectory reference with
explicit_scheme == "ssh", but validation sent every GitHub-host virtual
package to the HTTPS-only downloader probes. With only an SSH key, a
private marketplace failed the pre-flight even though the download
step uses SSH.

Route such references to the git ls-remote clone-root probe that
non-GitHub hosts use since microsoft#2063, so strict SSH mode makes no HTTPS
probe. HTTPS registrations keep the downloader probes.

Fixes microsoft#3164

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Transport ownership, inaccurate SSH failure diagnostics, stale auth guidance, and missing type annotations remain unresolved.

4 open findings
What changed in this PR

Fixes SSH-only pre-flight validation for in-repository plugins from SSH-registered GitHub marketplaces.

Changes:

  • Routes explicit SSH GitHub subdirectories through git ls-remote.
  • Adds SSH/HTTPS regression coverage.
  • Updates marketplace documentation and changelog.
File Description
src/​apm_cli/​install/​validation.py Adds SSH-aware validation routing.
tests/​unit/​install/​test_validation_github_ssh_subdir.py Tests SSH-only and unchanged HTTPS behavior.
docs/​src/​content/​docs/​consumer/​installing-from-marketplaces.md Documents GitHub SSH marketplace support.
CHANGELOG.md Records the fix.

🧠 Review effort: Balanced


💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

# The same applies on a GitHub host when the dependency carries an
# explicit SSH scheme (e.g. an SSH-registered marketplace, #3164): the
# downloader probes are HTTPS-only, while the download step uses SSH.
explicit_ssh = (getattr(dep_ref, "explicit_scheme", None) or "").lower() == "ssh"
dep_ref.is_virtual
and dep_ref.is_virtual_subdirectory()
and not is_github_hostname(dep_ref.host or default_host())
and (not is_github_hostname(dep_ref.host or default_host()) or explicit_ssh)
Comment on lines +102 to +104
HTTPS. This includes a `github.com` marketplace registered over SSH: the
install pre-flight checks its in-repository plugins with `git ls-remote`
over SSH, so a private catalog needs only an SSH key, not a GitHub token.
Comment on lines +36 to +42
@pytest.fixture(autouse=True)
def _no_fallback_env(monkeypatch):
for name in ("APM_ALLOW_PROTOCOL_FALLBACK", "GITHUB_TOKEN", "GH_TOKEN", "GITHUB_APM_PAT"):
monkeypatch.delenv(name, raising=False)


def _resolve(url: str):

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants