Hmbown/CodeWhale · error
remote url is not a supported forge
Error message
remote url is not a supported forge
What it means
When a URL looks like a network-based git URL (looks_like_network_git_url) but classify_url cannot map it to a known forge (github / cnb / gitee), validation fails. The dispatcher only supports cloning from the forges it knows how to classify and sandbox.
Solutions
- Use a hosted URL on a supported forge: github.com, cnb, or gitee (named hosts win over URL classification).
- Fix the hostname typo and re-run; check that the scheme/host match the forge's canonical form.
- If you need another forge, that requires extending classify_url — not a caller-side workaround.
- Mirror the repository to a supported forge if the original host cannot change.
Example fix
// before let url = "https://gitlab.internal.corp/team/repo.git"; validate_git_remote_url(url)?; // after let url = "https://github.com/org/repo.git"; validate_git_remote_url(url)?;
Defensive patterns
Strategy: validation
Validate before calling
fn supported_forge_host(url: &str) -> bool {
["github.com", "cnb.cool", "gitee.com"].iter()
.any(|h| url.contains(h))
} Try / catch
match validate_git_remote_url(raw) {
Err(e) if e.to_string().contains("supported forge") => {
eprintln!("only github / cnb / gitee remotes are supported; got: {raw}");
}
other => { /* ... */ }
} Prevention
- Restrict remote inputs to the supported forge hosts in your product's UI.
- Document the supported forges next to the remote URL field.
- Watch for lookalike/typo domains; validate the host, not a substring.
- Extend classify_url (in the library) when adding forge support — do not bypass validation.
When it happens
Trigger: Calling validate_git_remote_url / safe_git_remote_url / clone_repository with a URL whose host is not a recognized forge — e.g. a self-hosted GitLab, Bitbucket, a raw IP, or a typo'd hostname like github.com.evil.io.
Common situations: Pointing the tool at an internal/enterprise forge it does not support; host typos or spoofed lookalike domains; mirrors hosted on generic domains; protocol forms (ssh:// with odd ports) the classifier does not recognize.
Understand the failure class
Background: UnsupportedOperationException and "is not supported" errors: when a library deliberately refuses a call — this error's family across 30 libraries.
Related errors
- remote url contains control characters
- remote url is empty or oversized
- --base-url must use http or https
- baseline provenance must identify a clean source tree
- baseline provenance needs an exact source SHA
AI-assisted analysis of Hmbown/CodeWhale@73e0f67d83 (2026-09-22).
Data as JSON: /api/errors/fc96fd2e2fd63003.
Report an issue: GitHub.
Appendix: source
Thrown at crates/tui/src/cloud_dispatch.rs:420
/// Classify and validate `job.remote_url` before any `git clone` or
/// sandbox clone. Returns the trimmed URL on success.
pub fn validate_git_remote_url(raw: &str) -> Result<String> {
let url = raw.trim();
if url.is_empty() || url.len() > MAX_REMOTE_BYTES {
bail!("remote url is empty or oversized");
}
if url.starts_with('-') {
bail!("remote url must not start with '-'");
}
if url.chars().any(char::is_control) {
bail!("remote url contains control characters");
}
if remote_has_userinfo(url) {
bail!("remote url must not embed userinfo");
}
if looks_like_network_git_url(url) && classify_url(url).is_none() {
bail!("remote url is not a supported forge");
}
Ok(url.to_string())
}
/// Display form of a remote: userinfo is never printed.
pub fn redact_remote_url(raw: &str) -> String {
redact_url_userinfo(raw)
}
fn remote_has_userinfo(url: &str) -> bool {
if let Ok(parsed) = reqwest::Url::parse(url) {
return !parsed.username().is_empty() || parsed.password().is_some();
}
// scp-style `user:token@host:path` (plain `git@host:path` is identity, not a secret).
if let Some((userinfo, _host)) = url.split_once('@') {
return userinfo.contains(':') && !userinfo.eq_ignore_ascii_case("git");
}
falseView on GitHub (pinned to 73e0f67d83)