Skip to content

fix(agent-manager): survive inaccessible historical project paths - #14557

Merged
marius-kilocode merged 2 commits into
mainfrom
research-worktree-session-binding-strategy
Sep 25, 2026
Merged

marius-kilocode merged 2 commits into
mainfrom
research-worktree-session-binding-strategy

Conversation

@marius-kilocode

Copy link
Copy Markdown
Collaborator

What Problem This Solves

A repository that was moved (or whose old location became inaccessible) could break Kilo startup entirely, even when the current checkout was valid.

Project.fromDirectory probes every saved sandbox with fs.exists(...).pipe(Effect.orDie). When a historical path returns PermissionDenied, that defect aborts initialization, so the current project does not boot and Agent Manager shows No providers. A healthy project added next to the failing opened workspace stayed blocked too: selecting it restored sessions and worktrees but never retried the failed config and provider bootstrap.

Fixes #13768.

Why This Change Was Made

Two independent failure boundaries are hardened, without changing project identity or adding automatic relocation:

  1. Historical sandbox probe. For a historical path, PermissionDenied no longer aborts startup. The association is retained (denied access does not prove deletion) and a warning is logged. The current checkout and non-permission filesystem errors still propagate, and missing historical paths continue to be pruned as before.
  2. Project activation recovery. Activating a project now retries config, provider, agent, skill, and command initialization when that bootstrap did not complete. This lets a healthy project recover without restarting VS Code, and a stale config response for a previous directory is now discarded.

Sessions and worktrees remain bound to folders. Moving a repository does not transfer sessions or worktrees, which is intentional.

User Impact

  • Opening a moved repository works for new work even if the previous location is unreachable.
  • Saved historical associations are preserved, so they become usable again if the path returns.
  • In multi-project Agent Manager, a healthy project is no longer blocked by a failing opened workspace.
  • Old sessions and worktrees are still not automatically reassigned to a moved folder.

Evidence

  • packages/opencode: bun test test/kilocode/project-sandbox.test.ts test/project/project.test.ts (39 pass), bun run typecheck.
  • packages/kilo-vscode: bun run build:check (host types, webview types, lint, bundle), bun run knip, and focused provider/Agent Manager tests (201 pass).
  • Repository guards: bun run script/check-opencode-annotations.ts --worktree, git diff --check.

Manual verification used an isolated VS Code instance with a rebuilt CLI and extension and disposable Git repositories:

  1. Historical path denied while the checkout is valid: providers load and a worktree and session are created; the denied path stays saved.
  2. Opened workspace stays broken by an independent filesystem error: selecting the healthy added project restores providers and creates a worktree and session without a restart.

Also confirmed the reproduction against current source before the fix: with the historical path denied, the opened workspace showed no providers and could not create a session. Test artifacts and fixtures were removed after verification.

A saved historical sandbox that returns PermissionDenied aborted
Project.fromDirectory, so an otherwise valid current checkout could not
initialize and Agent Manager showed no providers.

Isolate that probe for historical paths only: keep the saved association
for later recovery and log the warning. Errors for the current checkout
and non-permission filesystem failures still surface.

Retry config and provider initialization when Agent Manager activates a
project, so a healthy project recovers without a restart when the opened
workspace failed to initialize.

Fixes #13768
Comment thread packages/kilo-vscode/src/KiloProvider.ts Outdated
Comment thread packages/opencode/src/project/project.ts
Comment thread packages/kilo-vscode/src/KiloProvider.ts
@kilo-code-bot

kilo-code-bot Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Code Review Summary

Status: No Issues Found | Recommendation: Merge

Files Reviewed (3 files)
  • packages/kilo-vscode/src/KiloProvider.ts
  • packages/kilo-vscode/tests/unit/kilo-provider-provider-refresh.test.ts
  • packages/opencode/src/kilocode/session/transcript.ts
Previous Review Summary (commit 9a6abc0)

Current summary above is authoritative. Previous snapshots are kept for context only.

Previous review (commit 9a6abc0)

Status: 3 Issues Found | Recommendation: Address before merge

Overview

Severity Count
CRITICAL 0
WARNING 2
SUGGESTION 1
Issue Details (click to expand)

WARNING

File Line Issue
packages/kilo-vscode/src/KiloProvider.ts 1039 retryInitialization early-return guard is not directory-aware, so the recovery can be skipped for a newly selected project.
packages/opencode/src/project/project.ts 252 Retaining a denied sandbox exposes SessionTranscript.scoped()'s unguarded Filesystem.resolve, which throws EACCES/EPERM when attaching a past chat.

SUGGESTION

File Line Issue
packages/kilo-vscode/src/KiloProvider.ts 3942 New refreshConfig staleness guard has no test coverage.
Files Reviewed (9 files)
  • .changeset/quiet-project-recovery.md
  • packages/kilo-vscode/src/KiloProvider.ts - 2 issues
  • packages/kilo-vscode/src/agent-manager/AgentManagerProvider.ts
  • packages/kilo-vscode/src/agent-manager/host.ts
  • packages/kilo-vscode/src/agent-manager/vscode-host.ts
  • packages/kilo-vscode/tests/unit/kilo-provider-provider-refresh.test.ts
  • packages/opencode/src/kilocode/project/sandbox.ts
  • packages/opencode/src/project/project.ts - 1 issue
  • packages/opencode/test/kilocode/project-sandbox.test.ts

Fix these issues in Kilo Cloud


Reviewed by deepseek-v4.1-flash · Input: 0 · Output: 0 · Cached: 0

Review guidance: REVIEW.md from base branch main

Key the cached providers and config payloads to the directory they were
loaded for, so retryInitialization means "bootstrapped for this project"
rather than "bootstrapped for any project". Without this, switching to a
project whose bootstrap failed could silently reuse the previous project's
config and providers.

Guard SessionTranscript scope resolution against a retained inaccessible
sandbox. Filesystem.resolve throws EACCES/EPERM for such a path, which
previously could die when attaching a past chat. Unresolvable paths are now
treated as out of scope, matching the session family resolution.

Add coverage for the refreshConfig staleness guard.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Moving an existing project leaves stale worktree/sandbox paths in kilo.db and breaks Agent Manager with EACCES

2 participants