Revert "Commit .autoenv" — it wedges every worker spawn
CI / build (push) Successful in 53s
CI / contract (push) Successful in 1m24s

Regression I introduced one commit ago, caught by two consecutive spawn failures
and reproduced end-to-end.

Tracking `.autoenv` means git checks it out into every provisioned worktree. A
worktree is a new path, and autoenv authorizes by path, so the file is always
unauthorized there — autoenv prints "[autoenv] Authorize this file? (y/n/d)" and
blocks on `read` (activate.sh:211-222). The pane's shell sits at that prompt, so
`ccs <profile>` never runs, the peer never becomes injectable, and CB-306's
readiness gate closes the pane after 20s. Symptom is a bare "spawn timed out";
nothing names autoenv, which is what made it worth writing down.

Confirmed rather than inferred: the peer lead's cb-537 worker, spawned BEFORE
f8182e4, has no `.autoenv` in its worktree and is still alive; a throwaway
worktree at HEAD reproduces the prompt on entry.

The file is still worth committing — the reasoning in f8182e4 stands, and it is
recoverable from there. What is missing is the other half: GitWorktrees already
neutralizes `.mcp.json` in a provisioned worktree ("worker tool surface is
launcher-mounted only"), and `.autoenv` needs exactly the same treatment for
exactly the same reason — a worker's environment is launcher-supplied, never
repo-supplied. Re-land it with that, tracked as CB-543.

Rejected the quicker fix of exporting AUTOENV_ASSUME_YES: it auto-approves
arbitrary repo-controlled shell code in every spawned worker, which is a worse
trade than one unset variable.
This commit is contained in:
Dai Ha
2026-08-13 15:07:59 +02:00
parent cf48983046
commit 793f2e7157
-27
View File
@@ -1,27 +0,0 @@
# Workspace environment — loaded by autoenv on entering this directory.
#
# Single source of truth for credentials is .secrets/ (gitignored, 0600).
# NO secret value belongs in this file; it only reads them, so it is committed.
#
# Why it exists: Claude Code expands ${VAR} in .mcp.json from the *process
# environment* and has no way to read a file, so without this its tokens must be
# duplicated as literals in .claude/settings.local.json. opencode does not need
# this file — it reads .secrets/ directly via {file:.secrets/...} — which keeps
# opencode working even when launched outside a login shell.
_cb_dir="${${AUTOENV_CUR_FILE:-${(%):-%N}}:A:h}"
_cb_secrets="$_cb_dir/.secrets"
# A git worktree receives tracked files only, so .secrets/ is absent there.
# Workers are fed by the launcher's env instead — do nothing rather than fail.
if [[ -d "$_cb_secrets" ]]; then
_cb_load() {
[[ -r "$_cb_secrets/$2" ]] && export "$1"="$(<"$_cb_secrets/$2")"
}
_cb_load CONTEXT7_TOKEN context7-token
_cb_load GITEA_ACCESS_TOKEN gitea-token
_cb_load GITEA_HOST gitea-host
unset -f _cb_load
fi
unset _cb_dir _cb_secrets