Files
orca/src/shared/detected-worktree-provider-contract.ts
Neil 398aeccdfe fix(worktrees): retire runtime-host metadata a scan proved gone
A paired client's WorktreeMeta for a runtime host is exempt from
gcStaleWorktreeMeta -- that GC skips any row that is not local on both the
repo and the meta's hostId -- so a scan-proven removal is the only thing that
ever retires one. Both halves of that path were gated to `ssh:`, so the client
kept a row for every remote worktree it had ever seen and dropped none.

The renderer already computed the removals for runtime hosts and purged its
own in-memory state with them; only the persisted half bailed. Widen it, and
the matching main-side handler, to runtime hosts. `OffHostExecutionHostId`
names the set precisely: the hosts the local-only GC skips.

Also require `source === 'git'` before retiring anything. `session-fallback`
reports `authoritative: true` but is the truncated, visibility-filtered
`worktree.list` reply from a host too old for `worktree.detectedList`; its
omissions are no evidence a checkout is gone. That guard did not matter while
this only ran the in-memory purge, and does now that it deletes rows.

A repo that reaches its checkouts over a connection is still never condemned
under a runtime host id -- the host that executes owns that verdict.

Refs #17776
2026-09-01 17:20:17 -07:00

92 lines
2.7 KiB
TypeScript

import type { ExecutionHostId, LOCAL_EXECUTION_HOST_ID } from './execution-host'
import type { DirectSshAuthority } from './ssh-types'
import type { DetectedWorktreeListResult } from './worktree/types'
export const PROVIDER_REQUEST_ID_MAX_UTF8_BYTES = 128
export type ProviderRequestId = string & { readonly __providerRequestId: unique symbol }
export type SshExecutionHostId = Extract<ExecutionHostId, `ssh:${string}`>
export type LocalDetectedWorktreeRequest = {
providerRequestId: ProviderRequestId
repoId: string
executionHostId: typeof LOCAL_EXECUTION_HOST_ID
}
export type DirectSshDetectedWorktreeRequest = {
providerRequestId: ProviderRequestId
repoId: string
executionHostId: SshExecutionHostId
expectedAuthority: DirectSshAuthority
}
export type ListDetectedWorktreesArgs =
| LocalDetectedWorktreeRequest
| DirectSshDetectedWorktreeRequest
export type ListKnownWorktreesForExecutionHostArgs = {
repoId: string
executionHostId: SshExecutionHostId
}
export type HostQualifiedKnownWorktreeResult =
| {
status: 'complete'
repoId: string
executionHostId: SshExecutionHostId
result: DetectedWorktreeListResult
}
| {
status: 'rejected'
repoId: string
executionHostId: SshExecutionHostId
}
/**
* Hosts whose persisted metadata a scan can retire: exactly those `gcStaleWorktreeMeta` skips,
* because it only ever condemns rows that are local on both the repo and the meta's `hostId`.
*/
export type OffHostExecutionHostId = Extract<ExecutionHostId, `ssh:${string}` | `runtime:${string}`>
export type ForgetRemovedWorktreesForExecutionHostArgs = {
repoId: string
executionHostId: OffHostExecutionHostId
/** Ids an authoritative scan of this host proved gone — the only evidence that retires persisted metadata. */
worktreeIds: readonly string[]
}
export type ForgetRemovedWorktreesForExecutionHostResult = {
forgottenWorktreeIds: string[]
}
export type AuthoritativeDetectedWorktreeHost =
| {
kind: 'local'
executionHostId: typeof LOCAL_EXECUTION_HOST_ID
}
| ({
kind: 'direct-ssh'
executionHostId: SshExecutionHostId
} & DirectSshAuthority)
export type HostQualifiedDetectedWorktreeResult =
| {
status: 'complete' | 'non-authoritative'
providerRequestId: ProviderRequestId
repoId: string
authority: AuthoritativeDetectedWorktreeHost
result: DetectedWorktreeListResult
}
| {
providerRequestId: ProviderRequestId
executionHostId: ExecutionHostId
status:
| 'canceled'
| 'timed-out'
| 'stale'
| 'ambiguous-owner'
| 'authority-unknown'
| 'rejected'
}
export type LegacyDetectedWorktreeRequest = { repoId: string }