P-REPO.1: every session names its repo and where its commits go; spokes start from a repo picker (ADR-0406) - #393
Merged
Merged
Conversation
…es start from a repo picker (ADR-0404)
This was referenced Sep 26, 2026
mlcyclops
requested changes
Sep 26, 2026
mlcyclops
left a comment
Owner
There was a problem hiding this comment.
Integration is clean (merged on top of #389, #392 and #391: tsc clean in root, desktop and server configs; the full bun suite passes 5881 / 0 fail; make demo-P-REPO.1 passes). I also drove it live on an isolated engine. The titlebar chip, sidebar bar, spoke banner and orbit node all showed ws · main -> mlcyclops/qa-demo-repo, and the New spoke picker listed the local checkout plus the gh repos. The UX works. Four defects need fixing before merge:
- Blocker, security: the engine probes model-named paths on the host before the gate decides.
observeToolCall(desktop/repo_probe.ts ~164) takes paths straight from the initialtool_callnotification. It then runsstat()(existingDir) andgit -C <dir> rev-parseon them in the unsandboxed engine, for any absolute path, and it does this before atool_call_updatecan say the call was denied. On Windows, a\\host\share\...path in a deniedreadmakes the engine open SMB to that host as the user, which is the classic NTLM hash leak, and the AppContainer sandbox does not cover it. Confine candidates to the session's workspace plus granted roots (real-path compared), and drop UNC and device paths, beforerepoRootOf. cleanToolPaththrows on a malformedfile://escape.cleanToolPath("file:///C:/a%zz.ts")throwsURIError(reproduced). It runs synchronously inside thetool_callcase ofAcpBackend'sonNotify(acp_backend.ts ~842), before the P-TASK subagent detection and the tool emit, so one bad path drops that tool card. Catch the decode failure and ignore the path.- Lookalike hosts get rewritten to github.com.
webUrlFor("github.com-evil.example", "github", "owner", "repo")returnshttps://github.com/owner/repo(reproduced). The chip says GitHub while pushes go elsewhere, and Open on GitHub opens an unrelated repo. Anchor the alias form (for example^github\.com-[A-Za-z0-9_]+$, with no dots after the hyphen) or show the real host. - The push target claims a destination where a bare
git pushrefuses. InpushTarget(repo_identity.ts ~122), with the defaultpush.default=simple, a new branch with no upstream makesgit pusherror out.push.default=nothingerrors too, and so does a detached HEAD. The chip still namesorigin/<branch>in all three cases. Return "no push target (set upstream)" for the refusal cases rather than a destination git will not use.
Non-blocking follow-ups:
- Touches are committed on the initial
tool_call, so a denied or failed edit still becomes the active repo. Stage them bytoolCallIdand apply them on a successful terminal update. - All paths in one call share a
seq, so the first path wins: a move recordsoldPath, andcwdbeatsgit -C.
Needs a rebase after #391 merges. Makefile demo targets and the fleet_orbit.ts ui import conflict, and both sides are additive. The import line becomes import { popover, showToast } from "./ui.ts"; plus your two repo imports.
…dentity # Conflicts: # Makefile # desktop/renderer/fleet_orbit.ts
mlcyclops
added a commit
that referenced
this pull request
Sep 27, 2026
… renumber P-PROGRESS.1 to ADR-0409 Two merged branches (#396 P-SWITCH.2 and #397 P-PROGRESS.1) both claimed ADR-0404; P-PROGRESS.1 moves to ADR-0409 in DECISIONS.md, the Makefile, PROGRESS.md and its demo (harness/adr_numbering.test.ts caught it). Version 2.3.0-beta.9 in desktop/package.json and desktop/version.ts; README beta call, bug template and HANDOFF refreshed. #351 (desktop dependabot) left out: its Windows test gate failed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Owner request: it is hard to tell which repo a session works on and which GitHub repo its commits go to; in hub and spoke, typing a URL to start a spoke is cumbersome.
What changes
Verification
ADR-0406: 0402 is P-FLEET.L20 (#391), 0403 P-SWITCH.1 (#392), 0404 P-PROGRESS.1 (not yet in a PR), 0405 P-SCROLL.1 (#394). Master (073755b, #391 + #392) is merged in; conflicts in Makefile and fleet_orbit.ts imports resolved by keeping both sides; full bun test 5881 pass after the merge.