Skip to content

daemon: auto-accept EnterWorktree's permission-root relocation prompt for registry-verified trees - #316

Merged
m4ttheweric merged 9 commits into
mainfrom
rt-200
Sep 17, 2026
Merged

m4ttheweric merged 9 commits into
mainfrom
rt-200

Conversation

@m4ttheweric

Copy link
Copy Markdown
Collaborator

EnterWorktree's permission-root relocation prompt blocks panes constantly, and the folder-trust auto-accept does not recognize it, so a human clears each one by hand (live specimens today: board wrapper panes on gl worktrees).

The dialog names the worktree path in its own body, which gives it the provenance the trust dialog lacks: the parser (anchored on the reason line verified byte-for-byte against the installed Claude Code binary, plus the proceed question, so a transcript quoting the dialog never draws a keypress) extracts the path across wrapped screen lines, and the driver answers Yes only when that exact path is in rt's own worktree registry. The path is re-pinned on every cursor re-read, so a changing screen can stop the driver but never steer it. Same single-key, cursor-verified walk as the trust dialog.

Wired into both detection paths:

  • herd watchdog: offered on a modal pane before the trust accept and before parking; needs neither job.tree nor the trust accept's flag. Failure keeps the existing park + click-to-focus push.
  • reconciler: an accepted prompt opens no attention gate (silent, log line only); a prompt the daemon may not answer sends one click-to-focus notification and no gate; anything else keeps the attention-gate path unchanged. One attempt per blocked episode.

Gated on panes.relocationAutoAccept (machine scope, default on), resolved per attempt so a settings flip needs no daemon restart; rt-client dist rebuilt.

Verified: full unit suite green, plus the covering e2e files (herd-watchdog, reconciler) and repo-purity.

🤖 Generated with Claude Code

m4ttheweric and others added 6 commits September 17, 2026 12:39
Recognized only when the reason line and the proceed question are both on
screen, so a transcript quoting the dialog never draws a keypress. The
worktree path is reassembled across wrapped lines and returned for the
caller's registry check.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The relocation prompt's own path is checked against the injected registry
predicate before any key goes out (unregistered = zero keys), and pinned
across every re-read of the cursor walk so a changing screen can stop the
driver but never steer it.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Runs ahead of the RT-196 trust accept and needs neither job.tree nor its
flag: the dialog's own path checked against the worktree registry is the
provenance. Gated on panes.relocationAutoAccept (default on), read from
the pane family because the reconciler shares the switch.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Accepted prompts stay silent, a prompt the daemon may not answer sends
one click-to-focus notification and no gate, and everything else keeps
the attention-gate path unchanged. One attempt per blocked episode.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The dep resolves panes.relocationAutoAccept per attempt (a settings flip
needs no restart), drives the registry-gated accept on the pane's own
socket, and maps unregistered/stuck/unchecked to the notify-only path.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 17, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 57 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available. Your 82 included PR review attempts over the past 7 days set your current allowance at 1 review per hour.

Your organization has reached its usage spending cap. Adjust your spending cap in the billing tab.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: e912d65a-01e5-488a-916c-41659243fb86

📥 Commits

Reviewing files that changed from the base of the PR and between 67fd19d and 38c946f.

📒 Files selected for processing (13)
  • lib/daemon.ts
  • lib/daemon/__tests__/herd-watchdog-adapters.test.ts
  • lib/daemon/__tests__/herd-watchdog.test.ts
  • lib/daemon/__tests__/reconciler.test.ts
  • lib/daemon/__tests__/trust-accept.test.ts
  • lib/daemon/__tests__/trust-dialog.test.ts
  • lib/daemon/herd-watchdog-adapters.ts
  • lib/daemon/herd-watchdog.ts
  • lib/daemon/reconciler.ts
  • lib/daemon/trust-accept.ts
  • lib/daemon/trust-dialog.ts
  • packages/rt-client/src/settings/__tests__/registry.test.ts
  • packages/rt-client/src/settings/registry-defs.ts

Comment @coderabbitai help to get the list of available commands.

m4ttheweric and others added 3 commits September 17, 2026 13:18
Pre-merge review defeated the whole-screen parse with executed probes: a
transcript quote above an ordinary permission prompt drew a blind Enter,
a quote naming a registered path masked a dialog naming another, blanket
whitespace stripping collapsed a spaced path into a registered one, and
a numbered transcript list shifted the option walk. Everything now reads
from the last contiguous options block and the body above it up to the
box top; wraps rejoin without inventing or removing characters; and the
resolves-to real path, when the dialog shows one, must pass the registry
check too and is pinned across re-reads.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…alone

An unreadable screen proved nothing, so it no longer notifies as a stuck
relocation prompt or suppresses the attention gate for the episode. The
reconciler stands down entirely for panes an active herd job owns, so
one dialog can never be driven by both seams, and clear() drops the
agent's relocation memo.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…ions

The re-verification pass showed a partial capture with the box top
scrolled off letting transcript text inside the fallback window supply
the path. No box top now fails closed (the real dialog always paints
boxed), and the last reason match in the body wins, with resolves-to
read only from that match onward.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@m4ttheweric

Copy link
Copy Markdown
Collaborator Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Sep 17, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@m4ttheweric
m4ttheweric merged commit 4928a97 into main Sep 17, 2026
4 of 5 checks passed
@m4ttheweric
m4ttheweric deleted the rt-200 branch September 17, 2026 18:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant