Skip to content

fix(register): drop a pending registration whose edit checkout was deleted - #123

Merged
bompus merged 1 commit into
mainfrom
fix/stale-pending
Oct 9, 2026
Merged

bompus merged 1 commit into
mainfrom
fix/stale-pending

Conversation

@bompus

@bompus bompus commented Oct 9, 2026 •

Copy link
Copy Markdown
Owner

A failed registration is kept as pending and retried on each prompt, together with the edit checkout that triggered it. If that checkout is deleted before the retry succeeds (for example a task worktree removed after its PR landed), the server refuses it with "worktree must belong to this project" and the hook repeats the warning on every prompt for the rest of the session.

registry.resume now drops a pending entry whose worktree no longer exists on disk. The session's next edit registers it again.

Tests: new registry test (fails without the change); the existing edit-checkout test now uses real directories, since the check reads the disk. bun run check passes and the full suite passes (1213 pass, 0 fail).

No release is part of this change; the CHANGELOG entry sits under Unreleased.

Summary by CodeRabbit

  • Bug Fixes
    • Prompts no longer remain stuck retrying a pending registration after its edit checkout is deleted. The stale pending entry is cleared, allowing the session to register again on its next edit.
    • Other pending registrations remain available for retry.

…leted

The server refuses a worktree that no longer exists, so the retry on each prompt could never succeed and the hook warned until the session ended. The pending entry is dropped; the next edit registers again.
@coderabbitai

coderabbitai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository YAML (base), Organization UI (inherited)
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 938f6ff9-1de3-4f23-8f78-1bcce794467a

📥 Commits

Reviewing files that changed from the base of the PR and between f8581a1 and 5482d59.


📒 Files selected for processing (3)
  • CHANGELOG.md
  • src/registry.ts
  • test/registry.test.js

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 4 remain after this review.



📝 Walkthrough

Walkthrough

The registry now removes a pending registration when its edit worktree no longer exists. Tests cover stale and existing worktrees, and the changelog describes re-registration on the session’s next edit.

Changes

Pending registration lifecycle

Layer / File(s) Summary
Check and clear stale pending registrations
src/registry.ts, test/registry.test.js, CHANGELOG.md
resume checks whether a pending worktree exists. It clears stale pending state and returns undefined, while retaining pending registrations with existing worktrees. Tests cover these cases and retries. The changelog describes the behavior.

Priority: ⬇️ Low

Merge Risk

Merge Risk: ⚪ Minimal · up to 5482d

A deleted edit checkout no longer causes repeated registration retries, and the next edit registers again. No merge-blocking risk was identified.

Security Architecture Review

Security architecture risk: ⚪ Minimal · up to 5482d

The change stops retries for deleted checkouts without weakening project validation or granting additional authority. No material security risk was identified in the changed behavior.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • observed — The new cleanup directly modifies one session's local retry metadata. Its stale branch does not delete a remote registration, release another session's reservations, or grant server privileges.

Security Findings and Attack Paths

  • inferred — Making the recorded checkout disappear can suppress that pending retry, but the changed path provides no route around project or lifecycle validation. An existing but substituted checkout remains subject to server-side validation when registration is attempted.

Trust Boundaries and Controls

  • observed — Hook-provided edit paths are resolved to checkout context, and session identifiers are checked before registry access. The pending worktree remains a client-supplied hint; the server checks Git project membership and canonicalizes accepted roots.

Resilience and Maintainability Implications

  • inferred — Remote registration may have completed before a response was lost; local pending deletion does not prove remote cleanup. This ambiguity predates the PR, and the previous retry against a deleted checkout also failed before agent mutation. Existing session-based reuse and separately configured idle retirement remain the recovery mechanisms, rather than pending cleanup acting as remote revocation.



Pre-merge checks | Passed 6
✅ Passed checks (6 passed)
Check name Status Explanation
Title check Passed The title clearly and concisely describes the primary change: dropping a pending registration when its edit checkout was deleted.
Description check Passed The description explains the problem, the implementation, the test coverage, the reported validation results, the changelog status, and the absence of a release. It addresses the required checklist it…
Linked Issues check Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check Passed Check skipped because no linked issues were found for this pull request.
Suppressions Explained Passed The pull request adds no lint, type-check, formatter, or ignore directive. The diff changes only CHANGELOG.md, src/registry.ts, and test/registry.test.js. No suppression directive or configuration ign…
Interface Changes Documented Passed The pull request changes CHANGELOG.md, src/registry.ts, and registry tests only. The diff adds no MCP tool or argument, swarmail command or flag, or environment variable. The required interface-…


✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR

🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR


  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@bompus
bompus merged commit a560deb into main Oct 9, 2026
3 checks passed
@bompus
bompus deleted the fix/stale-pending branch October 9, 2026 23:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant