Skip to content

fix(server): enforce owned worktrees for coding launches - #28

Draft
nullStack65 wants to merge 1 commit into
mainfrom
fix/dev-worktree-isolation-20261007
Draft

nullStack65 wants to merge 1 commit into
mainfrom
fix/dev-worktree-isolation-20261007

Conversation

@nullStack65

@nullStack65 nullStack65 commented Oct 7, 2026 •

Copy link
Copy Markdown
Owner

New coding launches can reuse a project checkout without proving exclusive thread ownership. Require a dedicated, destination-qualified worktree before thread creation and provider execution, preserve ownership during retries and accepted sends, and expose explicit Coding and Coordinator choices on desktop and mobile. Existing imported histories retain their recorded paths.

Validated with focused server and real-Git integration tests, web draft tests, mobile recovery/outbox tests, scoped typechecks and lint, plus independent review of the exact committed tree. One paid-provider integration remains opt-in and was skipped.

Normal CI passed on the latest commit: Check, Test, all three server shards, Rust, Release Smoke, and native-change gates. Paid preview was skipped.

Draft pending actual before/after UI evidence. Cloud browser/computer use is explicitly authorized. The supported browser controller is not exposed in the current session, so capture has not been performed; this is a tool-availability blocker, not a permission gate. The exact source head and current main base remain unchanged and normal CI remains green. No UI evidence, merge, or installed acceptance is claimed. Shared artifact sequencing and host incorporation remain with the existing release20/ENV owners once source landing is qualified.

Models: GPT-6.1 Sol outcome owner and native GPT-6 Luna implementation/review agents. Harness: Codex managed cloud.

@github-actions github-actions Bot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XXL labels Oct 7, 2026
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

Provider Metric Main baseline This PR Impact PR ceiling
Codex Total thread wire 13.6 KiB 13.6 KiB +19 B (+0.1%) 15.1 KiB ✅
Codex Thread snapshot wire 7.1 KiB 7.1 KiB +16 B (+0.2%) 7.3 KiB ✅
Codex Live turn WebSocket wire 6.5 KiB 6.5 KiB +3 B (+0.0%) 7.8 KiB ✅
Codex Live turn WebSocket decoded 56.3 KiB 56.3 KiB 0 B (0.0%) 66.4 KiB ✅
Codex Live turn messages 10 10 0 (0.0%) 21 ✅
Claude Total thread wire 13.6 KiB 13.6 KiB +7 B (+0.1%) 15.1 KiB ✅
Claude Thread snapshot wire 7.1 KiB 7.1 KiB +10 B (+0.1%) 7.3 KiB ✅
Claude Live turn WebSocket wire 6.4 KiB 6.4 KiB −3 B (−0.0%) 7.8 KiB ✅
Claude Live turn WebSocket decoded 57.0 KiB 57.0 KiB 0 B (0.0%) 66.4 KiB ✅
Claude Live turn messages 9 9 0 (0.0%) 21 ✅

Baseline: 59152d9 · PR result: 1e070b2 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 114.1 KiB
  • Claude decoded thread snapshot: 114.8 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XXL vouch:trusted PR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants