CB-543: neutralize tracked opencode.json and .autoenv in provisioned worktrees #22

Merged
ltms merged 1 commits from worker/cb-543-neutralize-worktree-hostile-configs-f13dba-12 into main 2026-08-13 19:39:55 +02:00
Member

Fixes live bug: a tracked opencode.json lands in every bridged worktree carrying {file:.secrets/...} references to gitignored secrets (.secrets/ is gitignored), so opencode refuses to start — 100% reproducible for opencode workers.

Generalizes the existing single-file .mcp.json neutralization in GitWorktrees.isolateToolSurface to a LIST of worktree-hostile configs, each with a format-valid neutral stub and a create-if-absent policy:

  • .mcp.json — existing behavior preserved verbatim (create-always, must not regress)
  • opencode.json — new: neutralized when present, skipped when absent (CB-543)
  • .autoenv — new: neutralized when present, skipped when absent (original CB-543 scope; not tracked today but re-landing it must be safe since autoenv authorizes by path)

Each stub is valid for its format: an explicitly empty mcpServers map, an empty JSON object, and an empty env file. Absent configs are skipped silently — never fails provisioning, never invents stubs for files the repo doesn't have. Neutralized copies are marked git update-index --skip-worktree so they never surface as a pending modification.

Does NOT copy or reference .secrets/ anywhere — secrets stay workspace-scoped.

Tests (GitWorktreesTest, +3): tracked opencode.json neutralized + skip-worktree hidden; absent config skipped without error / no stub invented; all three configured files covered. Existing 4 tests (incl. .mcp.json create-always) unregressed.

Build: mvn clean install — Tests run: 524, Failures: 0, Errors: 0, Skipped: 0 — BUILD SUCCESS. Based on origin/main @ 6dee84c.

Fixes live bug: a tracked `opencode.json` lands in every bridged worktree carrying `{file:.secrets/...}` references to gitignored secrets (.secrets/ is gitignored), so opencode refuses to start — 100% reproducible for opencode workers. Generalizes the existing single-file .mcp.json neutralization in GitWorktrees.isolateToolSurface to a LIST of worktree-hostile configs, each with a format-valid neutral stub and a create-if-absent policy: - .mcp.json — existing behavior preserved verbatim (create-always, must not regress) - opencode.json — new: neutralized when present, skipped when absent (CB-543) - .autoenv — new: neutralized when present, skipped when absent (original CB-543 scope; not tracked today but re-landing it must be safe since autoenv authorizes by path) Each stub is valid for its format: an explicitly empty mcpServers map, an empty JSON object, and an empty env file. Absent configs are skipped silently — never fails provisioning, never invents stubs for files the repo doesn't have. Neutralized copies are marked `git update-index --skip-worktree` so they never surface as a pending modification. Does NOT copy or reference .secrets/ anywhere — secrets stay workspace-scoped. Tests (GitWorktreesTest, +3): tracked opencode.json neutralized + skip-worktree hidden; absent config skipped without error / no stub invented; all three configured files covered. Existing 4 tests (incl. .mcp.json create-always) unregressed. Build: mvn clean install — Tests run: 524, Failures: 0, Errors: 0, Skipped: 0 — BUILD SUCCESS. Based on origin/main @ 6dee84c.
agent added 1 commit 2026-08-13 19:36:34 +02:00
CB-543: neutralize tracked opencode.json and .autoenv in provisioned worktrees
CI / contract (pull_request) Successful in 45s
CI / build (pull_request) Successful in 1m26s
0114bd1fa7
ltms merged commit 4637c68295 into main 2026-08-13 19:39:55 +02:00
ltms deleted branch worker/cb-543-neutralize-worktree-hostile-configs-f13dba-12 2026-08-13 19:39:55 +02:00
Sign in to join this conversation.