Hmbown/CodeWhale · error
remote url is empty or oversized
Error message
remote url is empty or oversized
What it means
validate_git_remote_url rejects a remote URL that, after trimming, is empty or exceeds MAX_REMOTE_BYTES. This is the first gate before any `git clone` (direct or sandboxed), ensuring the argument to git is present and bounded in size.
Solutions
- Set the remote URL to a real forge URL such as https://github.com/org/repo.git.
- Trim the input and check it is non-empty before calling; surface a clear message to the user if blank.
- Check the URL length is within MAX_REMOTE_BYTES and shorten it (drop embedded tokens/queries you do not need).
- Fix the config/flag path that is producing an empty value (missing env var, unset default).
Example fix
// before
let url = std::env::var("REMOTE_URL").unwrap_or_default();
clone_repository(receipt, &url, path)?;
// after
let url = std::env::var("REMOTE_URL").unwrap_or_default();
let url = validate_git_remote_url(&url)?; // fails fast with the specific reason Defensive patterns
Strategy: validation
Validate before calling
fn remote_url_plausible(raw: &str) -> bool {
let url = raw.trim();
!url.is_empty() && url.len() <= MAX_REMOTE_BYTES
} Type guard
fn non_empty_bounded(s: &str, max: usize) -> Option<&str> {
let t = s.trim();
(!t.is_empty() && t.len() <= max).then_some(t)
} Try / catch
let url = match validate_git_remote_url(raw) {
Ok(u) => u,
Err(e) if e.to_string().contains("empty or oversized") => {
eprintln!("please provide a remote URL (non-empty, < MAX_REMOTE_BYTES)");
return;
}
Err(e) => return /* propagate */,
}; Prevention
- Make the remote URL a required, validated field in configs and CLIs.
- Trim whitespace at input boundaries.
- Reject empty values with a clear message instead of passing "" downstream.
- Document MAX_REMOTE_BYTES and check long pastes before submission.
When it happens
Trigger: Calling validate_git_remote_url, safe_git_remote_url, or clone_repository with an empty string, a whitespace-only string, or a URL longer than MAX_REMOTE_BYTES bytes.
Common situations: A config field `remote_url` left blank; an env var or CLI flag not set and defaulting to ""; a UI paste that only contained whitespace; a pathologically long URL pasted from a tool that embedded a whole command line.
Understand the failure class
Background: "must not be empty", "cannot be empty" — required-field validation errors across open-source libraries — this error's family across 41 libraries.
Related errors
- remote url contains control characters
- remote url is not a supported forge
- --base-url must use http or https
- baseline provenance must identify a clean source tree
- baseline provenance needs an exact source SHA
AI-assisted analysis of Hmbown/CodeWhale@73e0f67d83 (2026-09-22).
Data as JSON: /api/errors/b3f50669b1fd3de3.
Report an issue: GitHub.
Appendix: source
Thrown at crates/tui/src/cloud_dispatch.rs:408
)
}
/// Whether a git remote is safe to clone, show, or hand to a sandbox.
///
/// Rejects leading-dash injection (`--upload-pack=…`), embedded userinfo,
/// and network remotes that do not classify as a supported forge. Local
/// path remotes (offline fixtures) are allowed when they do not start
/// with `-` and carry no userinfo.
pub fn safe_git_remote_url(raw: &str) -> bool {
validate_git_remote_url(raw).is_ok()
}
/// Classify and validate `job.remote_url` before any `git clone` or
/// sandbox clone. Returns the trimmed URL on success.
pub fn validate_git_remote_url(raw: &str) -> Result<String> {
let url = raw.trim();
if url.is_empty() || url.len() > MAX_REMOTE_BYTES {
bail!("remote url is empty or oversized");
}
if url.starts_with('-') {
bail!("remote url must not start with '-'");
}
if url.chars().any(char::is_control) {
bail!("remote url contains control characters");
}
if remote_has_userinfo(url) {
bail!("remote url must not embed userinfo");
}
if looks_like_network_git_url(url) && classify_url(url).is_none() {
bail!("remote url is not a supported forge");
}
Ok(url.to_string())
}
/// Display form of a remote: userinfo is never printed.
pub fn redact_remote_url(raw: &str) -> String {View on GitHub (pinned to 73e0f67d83)