Skip to content

Match 401/403 only in git's own phrasing when classifying a refused probe [patch] - #72

Merged
matt-edmondson merged 1 commit into
mainfrom
fix/47-admission-status-digits
Oct 6, 2026
Merged

matt-edmondson merged 1 commit into
mainfrom
fix/47-admission-status-digits

Conversation

@matt-edmondson

Copy link
Copy Markdown
Contributor

Fixes #47

Problem

AdmissionGate.Classify checked git's lowercased stderr for the bare strings "401" and "403". Git echoes the repository URL in almost every failure, so these were all misreported as 401 "The upstream refused this credential":

  • a tunnel, DNS or connect failure for a URL such as studio/game-401.git
  • a URL with the port 4401
  • Azure DevOps's TF401019 "repository does not exist" message, which should be 404

Change

  • In AuthenticationMarkers, the bare digits are replaced with git's own phrasing: "returned error: 401", "returned error: 403", "http 401" and "http 403". The phrase markers that were already there (authentication failed, could not read username, and so on) are unchanged.
  • The <remarks> explain why a status code is only matched in git's phrasing.
  • NotFoundMarkers is left as it is. A URL can't contain a literal space, so "not found" can't come from the echoed URL. could not resolve host doesn't match it, and the existing AdmitAsync_WhenTheForgeIsUnreachable_StillRefuses test plus a new data row both check for 502.

Tests

  • AdmitAsync_WhenTheForgeIsUnreachableAtAUrlContainingAStatusCode_Is502 covers the issue's CONNECT tunnel failed output for game-401.git, Could not resolve host for game-403.git, and a connect failure on port 4401.
  • AdmitAsync_WhenGitReportsA401Or403_Is401 covers The requested URL returned error: 401 and 403 (with GitHub's Permission … denied line), and RPC failed; HTTP 403.
  • AdmitAsync_WhenAzureDevOpsReportsTF401019_Is404 covers the Azure DevOps message.
  • With the AdmissionGate change stashed, the three 502 rows and the TF401019 test fail (4 failures). With it, the full suite passes: 241 of 241.

🤖 Generated with Claude Code

https://claude.ai/code/session_01JE3qjjjTXN28xUcTq2h6vD


Generated by Claude Code

…robe [patch]

AdmissionGate matched bare "401" and "403" anywhere in git's output, and
git echoes the repository URL, so a DNS or proxy failure for a repository
whose URL contains those digits was reported as a refused credential, as
was Azure DevOps's TF401019 "repository does not exist". The markers are
now "returned error: 40x" and "HTTP 40x".

Fixes #47

Co-Authored-By: Claude Opus 5.5 <[email protected]>
Claude-Session: https://claude.ai/code/session_01JE3qjjjTXN28xUcTq2h6vD
@sonarqubecloud

sonarqubecloud Bot commented Oct 6, 2026

Copy link
Copy Markdown

@matt-edmondson
matt-edmondson merged commit 9660c63 into main Oct 6, 2026
14 checks passed
@matt-edmondson
matt-edmondson deleted the fix/47-admission-status-digits branch October 6, 2026 07:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Admission reports a network failure as 401 "credential refused" whenever the repository URL contains "401" or "403"

2 participants