Files
orca/src/main/worktree-removal-safety.ts
Neil 77f23b013f refactor(shared): drop the shared/types barrel and import from the real modules (#14447)
#14397 split `shared/types.ts` into 46 per-domain modules but kept the path as
a re-export barrel so the import sites did not have to change. This removes
the barrel: every consumer now imports from the module that actually declares
the type, and `src/shared/types.ts` is deleted.

Barrels hide where a type lives, make every consumer look like it depends on
the whole domain, and let an unrelated edit invalidate a module that ~2,000
files transitively import.

2,323 import declarations across 2,321 files. Rewritten mechanically: each
specifier was resolved to an absolute path via the TypeScript AST and
recomputed, rather than string-substituted, so alias forms (`@/../../shared/
types`) and per-specifier `type` modifiers survive.

Four cases the mechanical pass had to handle, each found by a gate rather than
by reading the diff:

- Modules inside `src/shared` import the barrel as `./types`, not
  `shared/types`. A pre-filter on the latter string skipped 176 of them and
  left imports dangling at a deleted file, which surfaced as confusing
  `Property 'x' is optional in type 'Repo' but required in Pick<Repo, ...>`
  errors rather than "module not found".
- The barrel RENAMED one type on the way through
  (`WorkspaceSource as WorkspaceCreateTelemetrySource`), so the original name
  in the owning module has to be re-aliased at each consumer.
- Three test files put `;(globalThis as ...)` on the line after the import.
  TypeScript parses that `;` as the import statement's terminator, so
  replacing through `statement.getEnd()` deletes it and breaks ASI. The
  rewrite now stops at the module specifier.
- A file that already imported directly from a module got a SECOND import
  from it, because the barrel re-exported those same names — which trips
  `import/no-duplicates` under `--deny-warnings`. A post-pass merges
  declarations sharing a specifier and type-only-ness; the `import type` plus
  `import` pair from one module is left alone, since that form is allowed.

Splitting one barrel import into several genuinely adds lines, which pushed
`terminal-layout-pty-ownership.ts` to 301 counted lines: its 107-character
import must wrap, and neither local type collapses onto one line (101 and 116
characters). Rather than contort a type declaration to fit a line budget,
`collectLeafIds` and `pruneLeaves` move to `terminal-pane-layout-tree.ts` —
they are pure structural operations on the layout tree and independent of PTY
ownership. `visible-worktrees.ts` similarly loses its own mini-barrel
re-export of `isDefaultBranchWorkspace`, with the four real consumers
repointed at the declaring module. No `max-lines` bypass added.

Verified: cold `tsc --noEmit` green on node, cli, and web (buildinfo deleted
first — these projects are `composite: true` and reuse stale caches); the full
`pnpm lint` green, not just bare oxlint — the narrower local check is what let
the duplicate imports reach CI; max-lines ratchet OK at 344.
2026-08-13 22:48:24 -07:00

318 lines
9.5 KiB
TypeScript

import { lstat, readFile } from 'node:fs/promises'
import { homedir } from 'node:os'
import { posix, win32 } from 'node:path'
import { isWindowsAbsolutePathLike } from '../shared/cross-platform-path'
import type { Repo } from '../shared/repo-types'
import type { WorktreeMeta } from '../shared/worktree/meta-types'
import type { GitWorktreeInfo } from '../shared/worktree/types'
import { areWorktreePathsEqual } from './ipc/worktree-logic'
import {
gitFileProvesOrphanedWorktreeDirectory,
type ReadPath,
type StatPath
} from './worktree-orphan-gitdir-proof'
type PathOps = typeof posix
const ORCA_CREATION_SOURCES = new Set<NonNullable<WorktreeMeta['orcaCreationSource']>>([
'desktop',
'runtime',
'cli',
'ssh'
])
const ORCA_OWNED_PROVENANCE_META_KEYS = [
'orcaCreatedAt',
'orcaCreationSource',
'orcaCreationWorkspaceLayout',
'automationProvenance',
'cliProvenance',
'creatorProvenance'
] as const
type UnregisteredOrcaCleanupMeta = Pick<
WorktreeMeta,
| 'orcaCreatedAt'
| 'orcaCreationSource'
| 'createdAt'
| 'createdWithAgent'
| 'pushTarget'
| 'sparseBaseRef'
| 'sparsePresetId'
| 'preserveBranchOnDelete'
>
export const ORPHANED_WORKTREE_DIRECTORY_MESSAGE =
'Worktree is no longer registered with Git but its directory remains.'
export const UNREGISTERED_MISSING_WORKTREE_MESSAGE =
'Worktree is no longer registered with Git and its directory is already gone.'
function getPathOps(...paths: string[]): PathOps {
// Why: forward-slash UNC roots need win32 ops; POSIX joins collapse `//Server` to `/Server`.
return paths.some(isWindowsAbsolutePathLike) ? win32 : posix
}
function containsPath(parentPath: string, childPath: string, pathOps: PathOps): boolean {
const relativePath = pathOps.relative(parentPath, childPath)
// Why: `..name` is a valid child name; only `..` and `../...` escape.
return (
relativePath === '' ||
(!!relativePath &&
relativePath !== '..' &&
!relativePath.startsWith(`..${pathOps.sep}`) &&
!pathOps.isAbsolute(relativePath))
)
}
export function isDangerousWorktreeRemovalPath(worktreePath: string, repoPath: string): boolean {
if (!worktreePath.trim()) {
return true
}
if (areWorktreePathsEqual(worktreePath, repoPath)) {
return true
}
const pathOps = getPathOps(worktreePath, repoPath)
const resolvedWorktreePath = pathOps.resolve(worktreePath)
const rootPath = pathOps.parse(resolvedWorktreePath).root
if (resolvedWorktreePath === rootPath) {
return true
}
const resolvedRepoPath = pathOps.resolve(repoPath)
if (containsPath(resolvedWorktreePath, resolvedRepoPath, pathOps)) {
return true
}
const homePath = homedir()
if (!!homePath && containsPath(resolvedWorktreePath, pathOps.resolve(homePath), pathOps)) {
return true
}
return isLikelyPosixHomeDirectory(resolvedWorktreePath, pathOps)
}
function isLikelyPosixHomeDirectory(resolvedWorktreePath: string, pathOps: PathOps): boolean {
if (pathOps !== posix) {
return false
}
return (
resolvedWorktreePath === '/home' ||
resolvedWorktreePath === '/root' ||
/^\/home\/[^/]+$/.test(resolvedWorktreePath) ||
/^\/Users\/[^/]+$/.test(resolvedWorktreePath)
)
}
export function getRegisteredDeletableWorktree(
repoPath: string,
requestedWorktreePath: string,
worktrees: readonly GitWorktreeInfo[]
): GitWorktreeInfo {
const worktree = findRegisteredDeletableWorktree(repoPath, requestedWorktreePath, worktrees)
if (!worktree) {
throw new Error(`Refusing to delete unregistered worktree path: ${requestedWorktreePath}`)
}
return worktree
}
export function findRegisteredDeletableWorktree(
repoPath: string,
requestedWorktreePath: string,
worktrees: readonly GitWorktreeInfo[]
): GitWorktreeInfo | null {
const worktree = worktrees.find((item) => areWorktreePathsEqual(item.path, requestedWorktreePath))
if (!worktree) {
return null
}
if (worktree.isMainWorktree || isDangerousWorktreeRemovalPath(worktree.path, repoPath)) {
throw new Error(`Refusing to delete protected worktree path: ${worktree.path}`)
}
assertWorktreeDoesNotContainRegisteredWorktree(worktree.path, worktrees)
return worktree
}
export function assertWorktreeDoesNotContainRegisteredWorktree(
worktreePath: string,
worktrees: readonly GitWorktreeInfo[]
): void {
const nestedWorktree = worktrees.find((item) => {
if (areWorktreePathsEqual(item.path, worktreePath)) {
return false
}
return containsPath(worktreePath, item.path, getPathOps(worktreePath, item.path))
})
if (nestedWorktree) {
// Why: `git worktree remove --force` treats nested worktrees as ordinary
// untracked directories and deletes their working files while leaving Git
// with a prunable child worktree record.
throw new Error(
`Refusing to delete worktree because it contains another registered worktree: ${nestedWorktree.path}`
)
}
}
export async function canSafelyRemoveOrphanedWorktreeDirectory(
worktreePath: string,
repoPath: string,
statPath: StatPath = lstat,
readPath: ReadPath = (path) => readFile(path, 'utf8')
): Promise<boolean> {
if (isDangerousWorktreeRemovalPath(worktreePath, repoPath)) {
return false
}
const pathOps = getPathOps(worktreePath, repoPath)
const gitFilePath = pathOps.join(worktreePath, '.git')
return gitFileProvesOrphanedWorktreeDirectory({
gitFilePath,
worktreePath,
repoPath,
pathOps,
statPath,
readPath
})
}
export function canCleanupUnregisteredOrcaWorktreeDirectory(args: {
meta: UnregisteredOrcaCleanupMeta | null | undefined
}): boolean {
if (hasCurrentOrcaCreationProvenance(args.meta)) {
return true
}
if (hasLegacyOrcaCreationEvidence(args.meta)) {
return true
}
// Why: path shape alone is not authority; users can create plain Git
// worktrees inside Orca's workspace directory too.
return false
}
export async function canCleanupUnregisteredOrcaLeftoverDirectory(args: {
meta: UnregisteredOrcaCleanupMeta | null | undefined
worktreePath: string
runtimeWorktreePath: string
repo: Pick<Repo, 'path'>
runtimeRepoPath: string
registeredWorktrees: readonly GitWorktreeInfo[]
statPath: StatPath
isGitRepository: (runtimeWorktreePath: string) => Promise<boolean>
}): Promise<boolean> {
// Why: this recovery state has already lost the worktree .git marker, so the
// existing .git-file orphan proof cannot establish ownership.
// Why: without a surviving .git file, path shape alone is too weak to prove
// ownership for recursive deletion; require persisted Orca-created evidence.
if (!hasCurrentOrcaCreationProvenance(args.meta) && !hasLegacyOrcaCreationEvidence(args.meta)) {
return false
}
if (
isDangerousWorktreeRemovalPath(args.worktreePath, args.repo.path) ||
isDangerousWorktreeRemovalPath(args.runtimeWorktreePath, args.runtimeRepoPath)
) {
return false
}
assertWorktreeDoesNotContainRegisteredWorktree(args.worktreePath, args.registeredWorktrees)
const targetEntry = await args.statPath(args.runtimeWorktreePath).catch(() => null)
if (!isDirectoryStat(targetEntry)) {
return false
}
const pathOps = getPathOps(args.runtimeWorktreePath, args.runtimeRepoPath)
const gitMarkerPath = pathOps.join(args.runtimeWorktreePath, '.git')
try {
await args.statPath(gitMarkerPath)
return false
} catch (error) {
if (!isMissingPathError(error)) {
return false
}
}
return !(await args.isGitRepository(args.runtimeWorktreePath))
}
function hasCurrentOrcaCreationProvenance(
meta: Pick<WorktreeMeta, 'orcaCreatedAt' | 'orcaCreationSource'> | null | undefined
): boolean {
return (
typeof meta?.orcaCreatedAt === 'number' &&
!!meta.orcaCreationSource &&
ORCA_CREATION_SOURCES.has(meta.orcaCreationSource)
)
}
function hasLegacyOrcaCreationEvidence(
meta: UnregisteredOrcaCleanupMeta | null | undefined
): boolean {
return Boolean(
meta?.createdAt ||
meta?.createdWithAgent ||
meta?.pushTarget ||
meta?.sparseBaseRef ||
meta?.sparsePresetId ||
meta?.preserveBranchOnDelete
)
}
export function stripOrcaProvenanceMetaUpdates(
updates: Partial<WorktreeMeta> | null | undefined
): Partial<WorktreeMeta> {
const sanitized = { ...updates }
for (const key of ORCA_OWNED_PROVENANCE_META_KEYS) {
delete sanitized[key]
}
return sanitized
}
function isMissingPathError(error: unknown): boolean {
const code =
error && typeof error === 'object' && 'code' in error
? String((error as NodeJS.ErrnoException).code)
: undefined
if (code === 'ENOENT' || code === 'ENOTDIR') {
return true
}
let message = ''
if (error instanceof Error) {
message = error.message
} else if (error && typeof error === 'object' && 'message' in error) {
message = String((error as { message: unknown }).message)
} else if (typeof error === 'string') {
message = error
}
return /\b(ENOENT|ENOTDIR)\b|no such file or directory|cannot find (?:the )?(?:file|path)|(?:file|path) not found/i.test(
message
)
}
function isDirectoryStat(stat: unknown): boolean {
const entry =
stat && typeof stat === 'object'
? (stat as { isDirectory?: () => boolean; isSymbolicLink?: () => boolean; type?: unknown })
: null
if (!entry) {
return false
}
if (entry.isSymbolicLink?.() === true || entry.type === 'symlink') {
return false
}
return entry.isDirectory?.() === true || entry.type === 'directory'
}
export async function isWorktreePathMissing(
worktreePath: string,
statPath: (path: string) => Promise<unknown> = lstat
): Promise<boolean> {
try {
await statPath(worktreePath)
return false
} catch (error) {
return isMissingPathError(error)
}
}