From 793f2e7157e26729d1ca64e9f7af53e30f4a9b21 Mon Sep 17 00:00:00 2001 From: Dai Ha Date: Thu, 13 Aug 2026 15:07:59 +0200 Subject: [PATCH] =?UTF-8?q?Revert=20"Commit=20.autoenv"=20=E2=80=94=20it?= =?UTF-8?q?=20wedges=20every=20worker=20spawn?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Regression I introduced one commit ago, caught by two consecutive spawn failures and reproduced end-to-end. Tracking `.autoenv` means git checks it out into every provisioned worktree. A worktree is a new path, and autoenv authorizes by path, so the file is always unauthorized there — autoenv prints "[autoenv] Authorize this file? (y/n/d)" and blocks on `read` (activate.sh:211-222). The pane's shell sits at that prompt, so `ccs ` never runs, the peer never becomes injectable, and CB-306's readiness gate closes the pane after 20s. Symptom is a bare "spawn timed out"; nothing names autoenv, which is what made it worth writing down. Confirmed rather than inferred: the peer lead's cb-537 worker, spawned BEFORE f8182e4, has no `.autoenv` in its worktree and is still alive; a throwaway worktree at HEAD reproduces the prompt on entry. The file is still worth committing — the reasoning in f8182e4 stands, and it is recoverable from there. What is missing is the other half: GitWorktrees already neutralizes `.mcp.json` in a provisioned worktree ("worker tool surface is launcher-mounted only"), and `.autoenv` needs exactly the same treatment for exactly the same reason — a worker's environment is launcher-supplied, never repo-supplied. Re-land it with that, tracked as CB-543. Rejected the quicker fix of exporting AUTOENV_ASSUME_YES: it auto-approves arbitrary repo-controlled shell code in every spawned worker, which is a worse trade than one unset variable. --- .autoenv | 27 --------------------------- 1 file changed, 27 deletions(-) delete mode 100644 .autoenv diff --git a/.autoenv b/.autoenv deleted file mode 100644 index d957e20..0000000 --- a/.autoenv +++ /dev/null @@ -1,27 +0,0 @@ -# Workspace environment — loaded by autoenv on entering this directory. -# -# Single source of truth for credentials is .secrets/ (gitignored, 0600). -# NO secret value belongs in this file; it only reads them, so it is committed. -# -# Why it exists: Claude Code expands ${VAR} in .mcp.json from the *process -# environment* and has no way to read a file, so without this its tokens must be -# duplicated as literals in .claude/settings.local.json. opencode does not need -# this file — it reads .secrets/ directly via {file:.secrets/...} — which keeps -# opencode working even when launched outside a login shell. - -_cb_dir="${${AUTOENV_CUR_FILE:-${(%):-%N}}:A:h}" -_cb_secrets="$_cb_dir/.secrets" - -# A git worktree receives tracked files only, so .secrets/ is absent there. -# Workers are fed by the launcher's env instead — do nothing rather than fail. -if [[ -d "$_cb_secrets" ]]; then - _cb_load() { - [[ -r "$_cb_secrets/$2" ]] && export "$1"="$(<"$_cb_secrets/$2")" - } - _cb_load CONTEXT7_TOKEN context7-token - _cb_load GITEA_ACCESS_TOKEN gitea-token - _cb_load GITEA_HOST gitea-host - unset -f _cb_load -fi - -unset _cb_dir _cb_secrets