Description
Copilot CLI retains the leading slash in an SCP-style GitHub remote when deriving the repository owner:
Remote: git@github.com:/Azure/AgentBaker.git
Expected repository: Azure/AgentBaker
Observed repository: /Azure/AgentBaker
Observed API owner: %2FAzure
This produces an invalid GitHub REST API request and repeated HTTP 404 errors for PR discovery. The repository in this report, Azure/AgentBaker, is public.
The same startup also reports an HTTP 400 while fetching MCP registry policy and blocks all three configured non-default MCP servers. The repository parsing error is directly demonstrated by the logs; its causal connection to the MCP policy error is not yet confirmed. The CLI does not log the policy request URL or response body, which makes that part difficult to diagnose.
Affected version / environment
- GitHub Copilot CLI
1.0.90-6
- Linux
- Terminal CLI, GitHub.com
- Public repository: https://github.com/Azure/AgentBaker
- Remote at the time of the failing startup:
git@github.com:/Azure/AgentBaker.git
Steps to reproduce
The following minimal recipe recreates the remote configuration from the affected checkout. The evidence below comes from that existing checkout, not a separately executed clean-clone reproduction.
-
Create a disposable checkout of the public repository:
git clone --depth 1 https://github.com/Azure/AgentBaker.git agentbaker-url-repro
cd agentbaker-url-repro
-
Set an SCP-style remote with a slash immediately after the colon:
git remote set-url origin git@github.com:/Azure/AgentBaker.git
git remote get-url origin
# git@github.com:/Azure/AgentBaker.git
-
With a GitHub-authenticated Copilot CLI, start a fresh process:
copilot --log-level debug
-
Inspect the process log under ~/.copilot/logs/ for repository identification and PR lookup. In the affected session, the repository is identified as /Azure/AgentBaker, and the PR lookup uses /repos/%2FAzure/AgentBaker/pulls.
-
If non-default MCP servers are configured, also check whether the startup reports MCP servers were blocked by policy and Failed to fetch MCP registry policy: 400 Bad Request. This additional symptom was observed, but may have another cause or require additional conditions.
Suggested A/B check
Change only the remote to the conventional form, then fully exit and start a new CLI process:
git remote set-url origin git@github.com:Azure/AgentBaker.git
copilot --log-level debug
The leading-slash form was observed during diagnosis; the remote has since been changed to the conventional form. A fresh-process A/B result has not yet been captured, so this is a proposed verification step, not a claim that the MCP failure is fixed.
Expected behavior
Normalize the GitHub repository identity to Azure/AgentBaker, without a leading slash in the owner. PR discovery should use:
https://api.github.com/repos/Azure/AgentBaker/pulls?head=Azure%3Amain&state=open&per_page=1
If this remote spelling is intentionally unsupported, report a clear remote-parsing error rather than silently constructing an invalid API owner.
A failure to retrieve MCP policy should remain distinct from an explicit policy denial in the user-facing message. Diagnostic logs should include a safely redacted endpoint and error response, without authentication material.
Actual behavior and sanitized log evidence
These are excerpts from the affected process log. Timestamps and GitHub request IDs have been removed; no full logs are attached.
Incorrect repository identity
[INFO] Session indexing debug: SESSION_INDEXING=true, repository=/Azure/AgentBaker
Invalid PR API request
[ERROR] Request to GitHub API at https://api.github.com/repos/%2FAzure/AgentBaker/pulls?head=%2FAzure%3Amain&state=open&per_page=1 failed with status 404 (request ID: [REDACTED]), body: {"message":"Not Found","documentation_url":"https://docs.github.com/rest/pulls/pulls#list-pull-requests","status":"404"}
[DEBUG] [branchPr] PR lookup failed for /Azure/AgentBaker: HttpError: Not Found - https://docs.github.com/rest/pulls/pulls#list-pull-requests
The same malformed PR request appears repeatedly in the process log, not just once at startup.
Concurrent MCP policy failure (causality unconfirmed)
[WARNING] Failed to fetch MCP registry policy: Failed to fetch MCP registry policy: 400 Bad Request. Non-default MCP servers will be blocked until the policy can be fetched.
The startup warning listed three configured non-default MCP servers as blocked. Their names and endpoints are omitted because they are not needed to demonstrate the parsing failure.
The managed-settings resolution logged source=none, bypassDisabled=false, and serverFetchFailed=false. No local /etc/github-copilot/managed-settings.json was present.
During diagnosis, a separate authenticated request using gh api /copilot/mcp_registry returned HTTP 200, with both returned registry entries reporting registry_access: "allow_all". Registry owner identities and configuration are intentionally omitted. This direct request is not an exact replay of the CLI request and does not prove why the latter returned HTTP 400.
Additional context
Privacy: this report excludes local usernames and absolute checkout paths, account/enterprise identities, session IDs, request IDs, credentials, and private MCP server names/URLs. Only the public repository example and selected sanitized diagnostic text are included.
Description
Copilot CLI retains the leading slash in an SCP-style GitHub remote when deriving the repository owner:
This produces an invalid GitHub REST API request and repeated HTTP 404 errors for PR discovery. The repository in this report,
Azure/AgentBaker, is public.The same startup also reports an HTTP 400 while fetching MCP registry policy and blocks all three configured non-default MCP servers. The repository parsing error is directly demonstrated by the logs; its causal connection to the MCP policy error is not yet confirmed. The CLI does not log the policy request URL or response body, which makes that part difficult to diagnose.
Affected version / environment
1.0.90-6git@github.com:/Azure/AgentBaker.gitSteps to reproduce
The following minimal recipe recreates the remote configuration from the affected checkout. The evidence below comes from that existing checkout, not a separately executed clean-clone reproduction.
Create a disposable checkout of the public repository:
git clone --depth 1 https://github.com/Azure/AgentBaker.git agentbaker-url-repro cd agentbaker-url-reproSet an SCP-style remote with a slash immediately after the colon:
git remote set-url origin git@github.com:/Azure/AgentBaker.git git remote get-url origin # git@github.com:/Azure/AgentBaker.gitWith a GitHub-authenticated Copilot CLI, start a fresh process:
Inspect the process log under
~/.copilot/logs/for repository identification and PR lookup. In the affected session, the repository is identified as/Azure/AgentBaker, and the PR lookup uses/repos/%2FAzure/AgentBaker/pulls.If non-default MCP servers are configured, also check whether the startup reports
MCP servers were blocked by policyandFailed to fetch MCP registry policy: 400 Bad Request. This additional symptom was observed, but may have another cause or require additional conditions.Suggested A/B check
Change only the remote to the conventional form, then fully exit and start a new CLI process:
The leading-slash form was observed during diagnosis; the remote has since been changed to the conventional form. A fresh-process A/B result has not yet been captured, so this is a proposed verification step, not a claim that the MCP failure is fixed.
Expected behavior
Normalize the GitHub repository identity to
Azure/AgentBaker, without a leading slash in the owner. PR discovery should use:If this remote spelling is intentionally unsupported, report a clear remote-parsing error rather than silently constructing an invalid API owner.
A failure to retrieve MCP policy should remain distinct from an explicit policy denial in the user-facing message. Diagnostic logs should include a safely redacted endpoint and error response, without authentication material.
Actual behavior and sanitized log evidence
These are excerpts from the affected process log. Timestamps and GitHub request IDs have been removed; no full logs are attached.
Incorrect repository identity
Invalid PR API request
The same malformed PR request appears repeatedly in the process log, not just once at startup.
Concurrent MCP policy failure (causality unconfirmed)
The startup warning listed three configured non-default MCP servers as blocked. Their names and endpoints are omitted because they are not needed to demonstrate the parsing failure.
The managed-settings resolution logged
source=none,bypassDisabled=false, andserverFetchFailed=false. No local/etc/github-copilot/managed-settings.jsonwas present.During diagnosis, a separate authenticated request using
gh api /copilot/mcp_registryreturned HTTP 200, with both returned registry entries reportingregistry_access: "allow_all". Registry owner identities and configuration are intentionally omitted. This direct request is not an exact replay of the CLI request and does not prove why the latter returned HTTP 400.Additional context
%2Fowner encoding.blocked by enterprise customization lockdown; the observed persistent MCP warning is the registry-policy HTTP 400.Privacy: this report excludes local usernames and absolute checkout paths, account/enterprise identities, session IDs, request IDs, credentials, and private MCP server names/URLs. Only the public repository example and selected sanitized diagnostic text are included.