Features: the model check is silent no longer for no-worktree spawns (#267)

Dai Ha
2026-09-04 08:50:26 +07:00
parent 6a22c4ba15
commit 2837d76bd9
+27
@@ -2851,6 +2851,33 @@ carry no provider prefix at all. So the id is always compared, the provider only
have one, and absent, incomplete or unparseable evidence is UNKNOWN — never a mismatch, never a
quarantine.
**The bigger gotcha: for a long time this check did not run at all for most spawns, and said
nothing (#267).** `checkModelMatch` has exactly one call site, and it sits *after* the #249 gate that
returns early when the spawn was given no fleetd-provisioned worktree — which the code itself calls
"the ordinary, expected shape of the large majority of spawns". So the detector built after the `xf`
incident was switched off for most of the spawns it existed to protect, silently.
Since #267 that case is no longer silent. Once per profile, when a model is configured:
```
opencode model-mismatch check (fleetd #175) cannot run for profile 'X': it was spawned
without a fleetd-provisioned worktree (fleetd #249), so its cwd may be shared with other
sessions and the actual model it is running cannot be safely told apart from a sibling's —
spawn with worktree:true to enable the check for this profile.
```
**The check itself still does not run there, and that is deliberate.** The model can only be read via
`actualModelForSessionId`, keyed on the *resolved* session id. The only other lookup is
`sessionIdForDirectory`, the "newest row for this directory" heuristic #249 exists to distrust: on a
shared cwd it can return a sibling's row, so a sibling running a different, correctly-configured
model would look like this profile's mismatch and quarantine an innocent credential. A false
quarantine takes real capacity away on bad evidence, which is worse than failing to detect. **Spawn
with `worktree:true` if you want the check.**
Worth naming as a shape, because it is not the same one as the entry above: **a safety check rode on
the same return value as an identity lookup.** #249 tightened the identity question for good reasons
and narrowed the safety check as a side effect. Neither change was wrong alone — the coupling was.
## Every file a member must read follows the member's own user
**What.** Two more places where fleetd used to write a file into its own process's filesystem and