fix(desktop): use dedicated directories for projectless tasks - #5966
Draft
Colafornia wants to merge 5 commits into
Draft
Colafornia wants to merge 5 commits into
Colafornia wants to merge 5 commits into
Conversation
A new top-level local task with no explicit directory used to inherit the process cwd or the app install path — often `/` — mixing task output with unrelated files. Projectless sessions now get a dedicated `~/Maka/tasks/task-<id>` directory allocated by a managed-task-directory authority that validates root ownership and refuses symlink redirection into application state, credentials, or install files. Explicit directories, configured defaults, selected projects, and remote Host workspace semantics keep their precedence; CLI/TUI is unchanged. Existing sessions are not rewritten. `app:sessionProjectInfo` classifies a session's bound directory; a suspicious binding surfaces a banner and a titlebar action that moves that one task through a new `sessions:moveToDedicatedDirectory` IPC — the same CAS relocation safeguards as `moveToProject`, with the fresh directory released when the commit is refused. Fixes apache#5939 Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Colafornia
marked this pull request as draft
October 4, 2026 17:30
The managed-task-directory ownership test skips on Windows; register it in the generated inventory. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
The renderer architecture ledger ratchets every metric on app-shell.tsx and forbids new files at the renderer root, so the share action, project block, dedicated-directory menu item, and repair notice are composed in useAppShellProjectContext — the hook that already owns the titlebar's project projection — and app-shell only destructures the result. The file's nonTriviaTokens debt drops below its base. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Isolated e2e profiles redirect the fake home inside userData, so the default ~/Maka/tasks root resolved into a reserved location and every projectless sessions:create threw. Point the root at the isolated workspace and drop the Client-data reserved roots for any sandboxed profile, not only named fixture scenarios. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
- remove the pathSource provenance seam: nothing produces a 'configured' host-path binding today, so the field, its pass-through, and the precedence branch were dead design (project-management-service and project-root-controller revert to upstream) - drop the bespoke directory field on the relocation result; the relocated Session's cwd already names it, so the preload bridge collapses to the shared invokeSessionUpdate helper - check session eligibility before allocating so refusals never create-then-release a directory - flatten reservedRoots to a plain array; all call sites pass already-computed paths - reuse ManagedTaskDirectoryAuthority for the dep types instead of redeclaring its shape inline Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
English
Summary
A new top-level local task with no explicit directory inherited the startup cwd or the app install path — often
/— so task output could land in the filesystem root or inside application state. Projectless tasks now get a dedicated, persistent~/Maka/tasks/task-<id>directory allocated by a managed-task-directory authority that validates root ownership and refuses symlink redirection into application state, credentials, or install files.Allocation is wired into every top-level task creation path —
sessions:create, bot sessions, external session import, WorkHubcreate_new, and offline session-local creation — behind the existing precedence: explicitcwd/projectId, configured default project/directory, then the selected project; only an implicit projectless path allocates. ThepathSourcefield on the current selection reserves the seam for the configured-default-directory setting (#2998). The directory is stable across turns, restarts, and continuation via the persisted session cwd, shows in the titlebar, opens via the existing folder action, and child sessions inherit it.Existing sessions are not rewritten.
app:sessionProjectInforeports the bound directory's class (managed/suspicious/other); a suspicious binding surfaces a repair banner, and every non-managed binding gets a titlebar menu item. Both call the newsessions:moveToDedicatedDirectoryIPC, which allocates a fresh directory and rebinds the session through the same revision-check relocate asmoveToProject, releasing the directory when the commit is refused. Remote Runtime Host semantics and CLI/TUI behavior are unchanged.Fixes #5939
Verification
apps/desktop:npm run build:main,npm run typecheck,npm run check:architecture,npm run test:dist— 3264 tests pass, 0 failuresnpx biome checkon all 26 changed files — cleannpm run e2e— the allocation policy is covered at the main-process integration layer, and the e2e fixture redirects the managed root under the isolated fixture workspace中文
摘要
此前新建一个没有显式目录的顶层本地任务,会继承启动时的工作目录或应用安装路径——常常是
/——导致任务输出落进文件系统根目录或应用状态目录里。现在无项目任务会由托管任务目录权威在~/Maka/tasks/task-<id>下分配一个专属且持久的目录;该权威校验根目录属主,并拒绝符号链接重定向到应用状态、凭据或安装文件。分配逻辑接入了所有顶层任务创建路径——
sessions:create、bot 会话、外部会话导入、WorkHubcreate_new和离线 session-local 创建——且排在既有优先级之后:显式cwd/projectId、配置的默认项目/目录、当前选中项目,最后才对隐式无项目路径做分配。当前选择上的pathSource字段为「配置的默认目录」设置(#2998)预留了接缝。目录经由会话持久化的 cwd 在跨轮次、重启和续聊中保持稳定,显示在标题栏,可通过现有的「打开文件夹」操作打开,子会话会继承它。既有会话不会被改写。
app:sessionProjectInfo上报绑定目录的分类(managed/suspicious/other);可疑绑定会出现修复提示条,所有非托管绑定都会在标题栏菜单中提供迁移项。两者都调用新的sessions:moveToDedicatedDirectoryIPC:分配新目录后,通过与moveToProject相同的带 revision 校验的 relocate 完成重绑,提交被拒绝时回收新目录。远程 Runtime Host 语义与 CLI/TUI 行为保持不变。Fixes #5939
验证
apps/desktop:npm run build:main、npm run typecheck、npm run check:architecture、npm run test:dist——3264 个测试全部通过npx biome check——无问题npm run e2e——分配策略已在 main 进程集成层覆盖,且 e2e fixture 会把托管根重定向到隔离的 fixture workspace 下AI use
Select exactly one:
Tool(s) and scope: Devin (Cognition) authored the implementation and tests end to end; the commit carries the Generated-with trailer.
Checklist
Does this PR entail a change in behavior?