Skip to content

fix(desktop): use dedicated directories for projectless tasks - #5966

Draft
Colafornia wants to merge 5 commits into
apache:mainfrom
Colafornia:fix/5939-projectless-task-dir
Draft

Colafornia wants to merge 5 commits into
apache:mainfrom
Colafornia:fix/5939-projectless-task-dir

Conversation

@Colafornia

Copy link
Copy Markdown
Member
English

Summary

A new top-level local task with no explicit directory inherited the startup cwd or the app install path — often / — so task output could land in the filesystem root or inside application state. Projectless tasks now get a dedicated, persistent ~/Maka/tasks/task-<id> directory allocated by a managed-task-directory authority that validates root ownership and refuses symlink redirection into application state, credentials, or install files.

Allocation is wired into every top-level task creation path — sessions:create, bot sessions, external session import, WorkHub create_new, and offline session-local creation — behind the existing precedence: explicit cwd/projectId, configured default project/directory, then the selected project; only an implicit projectless path allocates. The pathSource field on the current selection reserves the seam for the configured-default-directory setting (#2998). The directory is stable across turns, restarts, and continuation via the persisted session cwd, shows in the titlebar, opens via the existing folder action, and child sessions inherit it.

Existing sessions are not rewritten. app:sessionProjectInfo reports the bound directory's class (managed / suspicious / other); a suspicious binding surfaces a repair banner, and every non-managed binding gets a titlebar menu item. Both call the new sessions:moveToDedicatedDirectory IPC, which allocates a fresh directory and rebinds the session through the same revision-check relocate as moveToProject, releasing the directory when the commit is refused. Remote Runtime Host semantics and CLI/TUI behavior are unchanged.

Fixes #5939

Verification

  • apps/desktop: npm run build:main, npm run typecheck, npm run check:architecture, npm run test:dist — 3264 tests pass, 0 failures
  • npx biome check on all 26 changed files — clean
  • New unit coverage: managed-directory authority (allocation, uniqueness, owner/symlink/reserved-root guards, classification, empty-only release); workspace resolution precedence (explicit directory, configured default, managed allocation); dedicated-directory IPC (single CAS commit, project-bound refusal, release-on-refusal, missing-authority refusal)
  • Not run: npm run e2e — the allocation policy is covered at the main-process integration layer, and the e2e fixture redirects the managed root under the isolated fixture workspace
  • Not run: packaged GUI launch — the code path is launch-mode independent, but a packaged build was not exercised locally
中文

摘要

此前新建一个没有显式目录的顶层本地任务,会继承启动时的工作目录或应用安装路径——常常是 /——导致任务输出落进文件系统根目录或应用状态目录里。现在无项目任务会由托管任务目录权威在 ~/Maka/tasks/task-<id> 下分配一个专属且持久的目录;该权威校验根目录属主,并拒绝符号链接重定向到应用状态、凭据或安装文件。

分配逻辑接入了所有顶层任务创建路径——sessions:create、bot 会话、外部会话导入、WorkHub create_new 和离线 session-local 创建——且排在既有优先级之后:显式 cwd/projectId、配置的默认项目/目录、当前选中项目,最后才对隐式无项目路径做分配。当前选择上的 pathSource 字段为「配置的默认目录」设置(#2998)预留了接缝。目录经由会话持久化的 cwd 在跨轮次、重启和续聊中保持稳定,显示在标题栏,可通过现有的「打开文件夹」操作打开,子会话会继承它。

既有会话不会被改写。app:sessionProjectInfo 上报绑定目录的分类(managed / suspicious / other);可疑绑定会出现修复提示条,所有非托管绑定都会在标题栏菜单中提供迁移项。两者都调用新的 sessions:moveToDedicatedDirectory IPC:分配新目录后,通过与 moveToProject 相同的带 revision 校验的 relocate 完成重绑,提交被拒绝时回收新目录。远程 Runtime Host 语义与 CLI/TUI 行为保持不变。

Fixes #5939

验证

  • apps/desktop:npm run build:main、npm run typecheck、npm run check:architecture、npm run test:dist——3264 个测试全部通过
  • 对全部 26 个变更文件执行 npx biome check——无问题
  • 新增单元覆盖:托管目录权威(分配、唯一性、属主/符号链接/保留根防护、分类、仅空目录回收);workspace 解析优先级(显式目录、配置的默认值、托管分配);专属目录 IPC(单次 CAS 提交、项目绑定拒绝、拒绝时回收、缺少权威时拒绝)
  • 未运行:npm run e2e——分配策略已在 main 进程集成层覆盖,且 e2e fixture 会把托管根重定向到隔离的 fixture workspace 下
  • 未运行:打包版 GUI 启动——代码路径与启动方式无关,但本地未实际验证打包构建

AI use

Select exactly one:

  • No generative tool made a substantive contribution
  • Generative tooling made a substantive contribution

Tool(s) and scope: Devin (Cognition) authored the implementation and tests end to end; the commit carries the Generated-with trailer.

Checklist

  • Tests cover the change and fail without it
  • Lint, format, typecheck and the affected suites pass locally

Does this PR entail a change in behavior?

  • Yes — described under Summary above

A new top-level local task with no explicit directory used to inherit
the process cwd or the app install path — often `/` — mixing task output
with unrelated files. Projectless sessions now get a dedicated
`~/Maka/tasks/task-<id>` directory allocated by a managed-task-directory
authority that validates root ownership and refuses symlink redirection
into application state, credentials, or install files.

Explicit directories, configured defaults, selected projects, and remote
Host workspace semantics keep their precedence; CLI/TUI is unchanged.

Existing sessions are not rewritten. `app:sessionProjectInfo` classifies
a session's bound directory; a suspicious binding surfaces a banner and a
titlebar action that moves that one task through a new
`sessions:moveToDedicatedDirectory` IPC — the same CAS relocation
safeguards as `moveToProject`, with the fresh directory released when the
commit is refused.

Fixes apache#5939

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@github-actions github-actions Bot added the effort/L Under 1000 readable lines label Oct 4, 2026
@Colafornia
Colafornia marked this pull request as draft October 4, 2026 17:30
Colafornia and others added 4 commits October 5, 2026 01:31
The managed-task-directory ownership test skips on Windows; register it
in the generated inventory.

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
The renderer architecture ledger ratchets every metric on app-shell.tsx
and forbids new files at the renderer root, so the share action, project
block, dedicated-directory menu item, and repair notice are composed in
useAppShellProjectContext — the hook that already owns the titlebar's
project projection — and app-shell only destructures the result. The
file's nonTriviaTokens debt drops below its base.

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Isolated e2e profiles redirect the fake home inside userData, so the
default ~/Maka/tasks root resolved into a reserved location and every
projectless sessions:create threw. Point the root at the isolated
workspace and drop the Client-data reserved roots for any sandboxed
profile, not only named fixture scenarios.

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
- remove the pathSource provenance seam: nothing produces a 'configured'
  host-path binding today, so the field, its pass-through, and the
  precedence branch were dead design (project-management-service and
  project-root-controller revert to upstream)
- drop the bespoke directory field on the relocation result; the
  relocated Session's cwd already names it, so the preload bridge
  collapses to the shared invokeSessionUpdate helper
- check session eligibility before allocating so refusals never
  create-then-release a directory
- flatten reservedRoots to a plain array; all call sites pass
  already-computed paths
- reuse ManagedTaskDirectoryAuthority for the dep types instead of
  redeclaring its shape inline

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

effort/L Under 1000 readable lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(desktop): use dedicated directories for projectless tasks

1 participant