CtrlK
BlogDocsLog inGet started
Tessl Logo

jbaruch/coding-policy

General-purpose coding policy for Baruch's AI agents

74

Quality

93%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Medium

Suggest reviewing before use

Overview
Quality
Evals
Security
Files

origin-repo.pyskills/release/

#!/usr/bin/env python3
"""Name the GitHub repository a checkout's `origin` remote points at.

A script that pushes to, deletes on, or reads from `origin` with git and asks
`gh` about the same repository passes this `<owner>/<repo>` to every `gh`
call, never letting `gh` pick its own default (`gh repo set-default`). The
parse is one answer per URL, so it lives here once for every caller
(`rules/script-delegation.md`).

Accepted origin URL forms, each with or without a trailing `.git` or `/`:
  https://github.com/<owner>/<repo>          (userinfo before the host allowed)
  ssh://[<user>@]github.com[:<port>]/<owner>/<repo>
  [<user>@]github.com:<owner>/<repo>         (scp form)
Every other scheme, host or path shape is not a GitHub repository URL. The
fetch URL and every push URL (`git remote get-url --push --all origin`) must
name the same repository, compared case-insensitively as GitHub does, or the
script refuses. The emitted names keep the fetch URL's spelling.

Contract:
  argv  : <checkout>
  stdout: one JSON object — {"repo": "<owner>/<repo>", "owner": "<owner>",
          "name": "<repo>"}
  stderr: diagnostics only, never the remote URL: it can carry credentials.
  exit  : 0 resolved,
          1 precondition unmet (usage, git absent, git failed, no origin),
          2 origin is not a GitHub repository URL, or its fetch and push
            URLs name different repositories.
"""

import json
import re
import subprocess
import sys

#: The only host whose repositories `gh` is asked about.
GITHUB_HOST = "github.com"

SCHEME_URL = re.compile(r"^(?P<scheme>https|ssh)://(?:[^@/]*@)?(?P<host>[^/:@]+)(?::\d*)?/(?P<path>[^/].*)$")
SCP_URL = re.compile(r"^(?:[^@/:]+@)?(?P<host>[^/:@]+):(?P<path>[^/].*)$")
REPO_PATH = re.compile(r"^(?P<owner>[A-Za-z0-9](?:[A-Za-z0-9-]*[A-Za-z0-9])?)/(?P<name>[A-Za-z0-9._-]+)$")


def parse_github_url(url):
    """(owner, name) for a GitHub repository URL, None for anything else."""
    if "://" in url:
        match = SCHEME_URL.match(url)
    else:
        match = SCP_URL.match(url)
    if match is None or match.group("host").lower() != GITHUB_HOST:
        return None
    path = match.group("path")
    if path.endswith("/"):
        path = path[:-1]
    if path.endswith(".git"):
        path = path[:-4]
    repo = REPO_PATH.match(path)
    if repo is None or repo.group("name") in (".", ".."):
        return None
    return repo.group("owner"), repo.group("name")


def fail(code, message):
    print("origin-repo: {}".format(message), file=sys.stderr)
    return code


def remote_urls(checkout, push):
    """origin's fetch URL, or every push URL; raises RuntimeError with the rerun command."""
    command = ["git", "-C", checkout, "remote", "get-url"] + (["--push", "--all"] if push else []) + ["origin"]
    try:
        done = subprocess.run(command, capture_output=True, text=True, check=False)
    except FileNotFoundError:
        raise RuntimeError("git not found on PATH — install it, then re-run") from None
    if done.returncode != 0:
        # git's own message is not relayed: a misconfigured remote can echo its URL.
        raise RuntimeError("`{}` exited {} — run it to see why; add an origin with "
                           "`git -C {} remote add origin <github-url>` if there is none".format(
                               " ".join(command), done.returncode, checkout))
    return [line.strip() for line in done.stdout.splitlines() if line.strip()]


def same_repo(a, b):
    """GitHub owner and repository names compare case-insensitively."""
    return a is not None and b is not None and (a[0].lower(), a[1].lower()) == (b[0].lower(), b[1].lower())


def main(argv):
    if len(argv) != 1:
        return fail(1, "usage: origin-repo.py <checkout>")
    checkout = argv[0]
    try:
        fetch_urls = remote_urls(checkout, push=False)
        push_urls = remote_urls(checkout, push=True)
    except RuntimeError as exc:
        return fail(1, str(exc))
    fetch = parse_github_url(fetch_urls[0]) if fetch_urls else None
    if fetch is None:
        return fail(2, "origin in {} is not a GitHub repository URL (https://github.com/<owner>/<repo>, "
                       "ssh://git@github.com/<owner>/<repo> or git@github.com:<owner>/<repo>), so gh cannot be "
                       "bound to it — inspect it with `git -C {} remote get-url origin`; nothing falls back to "
                       "gh's default repository".format(checkout, checkout))
    if not push_urls or not all(same_repo(parse_github_url(url), fetch) for url in push_urls):
        return fail(2, "origin in {} fetches from {}/{} but pushes elsewhere, so no single repository answers for "
                       "it — inspect `git -C {} remote get-url --push --all origin` and align every push URL".format(
                           checkout, fetch[0], fetch[1], checkout))
    owner, name = fetch
    print(json.dumps({"repo": "{}/{}".format(owner, name), "owner": owner, "name": name}, sort_keys=True))
    return 0


if __name__ == "__main__":
    sys.exit(main(sys.argv[1:]))

skills

README.md

tile.json