Repository navigation
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
chore(tooling): 引入 opsx-worktree-provision 隔離 OpenSpec apply #53
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Uh oh!
There was an error while loading. Please reload this page.
chore(tooling): 引入 opsx-worktree-provision 隔離 OpenSpec apply #53
Changes from all commits
7f46eceFile filter
Filter by extension
Conversations
Uh oh!
There was an error while loading. Please reload this page.
Jump to
Uh oh!
There was an error while loading. Please reload this page.
There are no files selected for viewing
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
When
apply-and-verifyis invoked after provisioning, the caller can still be in the main worktree while the change artifacts live undermanifest.cwd_hint; however Layer 1 still runsopenspec validate <change-id> --strictwithoutcd "<cwd_hint>"or an equivalent cwd flag. In that context it validates main'sopenspec/changestree instead of the worktree, so a newly created or updated change can fail as missing or, worse, pass against stale main contents while the actual worktree specs are invalid.Useful? React with 👍 / 👎.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Test commands conflict with the declared tool allowlist.
The doc now uses
python -m pytest ..., butallowed-toolsonly permitsBash(pytest*). That mismatch can make these steps non-executable under policy enforcement.Suggested doc-aligned fix
🤖 Prompt for AI Agents
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The skill now tells the agent to run commands that start with
git -C, but the frontmatter still only whitelists prefixes such asBash(git push*)andBash(git diff*). In Claude Code's allowed-tools matching this means the new worktree-aware push/diff/status/add/commit commands are not covered by the declared permissions, so the apply flow can be blocked exactly when it tries to operate insidecwd_hint; add the appropriateBash(git -C*)entries or use an allowedcd "<cwd_hint>" && git ...form consistently.Useful? React with 👍 / 👎.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This gate says every later phase must use
manifest.cwd_hint, but Phase B still invokesopenspec-explore-twicewithout passing or changing cwd, and that skill writesopenspec/changes/<change-id>/...using relative paths. Under the new design assumption that the agent process stays in the main worktree, starting a new change will create or edit the OpenSpec artifacts in main before apply, making main dirty and bypassing the intended worktree isolation.Useful? React with 👍 / 👎.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The worktree-dirty gate requires
git -C <target_path> status --porcelainwhen a target path already exists, but this skill's allowed tools only cover prefixes likeBash(git status*), not commands that start withgit -C. In a reuse/dirty-check scenario the skill can be blocked before it can inspect the existing worktree, so either whitelistBash(git -C*)here or express the check as an allowedcd <target_path> && git status ...command.Useful? React with 👍 / 👎.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
When
<repo>/.worktrees/<change_id>already exists but is a clean worktree for a different branch or detached HEAD, this rule reuses it solely because the path exists. The manifest then advertisescodex/openspec/<id>, so downstream edits and commits can land on the wrong branch; checktarget_path's current HEAD/branch against the desired branch before reusing it, and stop or recreate if it differs.Useful? React with 👍 / 👎.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
If
<repo>/.worktrees/<change_id>exists as a leftover plain directory rather than a Git worktree, this branch reuses it without checkinggit worktree listfor that exact path. Because the directory is inside the main repo,git -C <target_path> ...can resolve to the parent repository while files under.worktrees/remain ignored, so downstream edits may not be committed tocodex/openspec/<id>at all; only reuse paths that are registered worktrees for the target branch.Useful? React with 👍 / 👎.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🧩 Analysis chain
🌐 Web query:
Doesgh pr createrequire being run inside a local git repository (or using--repo)? Please cite GitHub CLI docs.💡 Result:
No,
gh pr createdoes not strictly require being run inside a local git repository if using the--repoflag to specify the target repository explicitly. The official GitHub CLI manual documents the-R, --repo <[HOST/]OWNER/REPO>flag, which allows selecting another repository, enabling the command to work outside a local git repo as long as required flags like--title,--body,--head, and--baseare provided (since features like--fillrely on local git commits and will fail without a repo) [1][2]. A merged pull request specifically enabledgh pr create --repofrom outside a local git repository [2]. Without--repo(or a default repo set viagh repo set-default), it requires a local git repo to determine the repository from remotes [3].Citations:
gh pr createfrom outside of a local git repo cli/cli#6527gh pr createnow requires a default remote repository to be set, can't override on a per-PR basis cli/cli#7216Clarify conditions for
ghinvocation from arbitrary locations."可在任何位置呼叫" (can be called from any location) is misleading without context.
gh pr createrequires either a local git repository context OR the--repoflag. Calling it from arbitrary directories without--repowill fail. Revise to specify: "可使用 --repo 指令在任何位置呼叫" (can be called from any location using --repo flag) or document the repo/worktree path requirement explicitly.🤖 Prompt for AI Agents
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Step 6 copies service
.envfiles into the linked worktree, but this ignore rule only hides the.worktrees/directory from the main worktree; inside the linked worktree the copied paths such as_worker/.envor_bim-control/.envare still unignored. When those local files exist, the new worktree becomes dirty with untracked secrets and they can be accidentally staged by explicitgit add, so add ignore patterns for the copied.envtargets before relying on the copy step.Useful? React with 👍 / 👎.
Uh oh!
There was an error while loading. Please reload this page.