fix(fleet): keep local project APIs off peer sessions - #133
Merged
Conversation
devswha
added a commit
that referenced
this pull request
Sep 6, 2026
#136) OpenCode's session watcher traversed unrelated cache subtrees even though its synchronizer only accepts `opencode.db`. Retain the parent directory to observe database creation and replacement, but limit traversal to depth zero and ignore every path except that root and its database. The historical direct-file-only approach missed a removal/replacement case in a real filesystem regression, so it is not copied verbatim. Other providers keep their existing recursive watch options. Validation: the 20-test filesystem/watcher/indexing group, type checks, and lint pass. Tests cover an existing or initially absent database, changes, deletion and recreation, excluded nested caches, and unchanged non-OpenCode options. `docs/evidence/issue131/review.md` records a disposition for all thirteen preserved commits and all six review groups, including already-shipped work, corrections in #133/#134/#135, and proposals intentionally not carried forward under the current Fleet contract. Merge after #134 and #135, with required checks rerun on that latest main. The preserved historical branch remains available. Closes #131.
6 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Selecting a peer project could read the hub's same-ID files and token usage, expose local Git/new-chat actions, or open an editor from an old file lookup after a host switch. Require both route and project locality, reject stale Git/file callbacks, discard late responses, and remove local editor access when its owning project is no longer selected. Peer token usage continues to come from host-qualified history.
Validation: two mounted regressions failed before the fix and passed afterward;
npm run verifypassed all gates with 2,382 repository tests (1,650 server, 50 real tmux/PTY, 682 client), plus Rust checks/tests. Chrome verified peer → local → peer palette transitions with simulated responses: no hub requests or local file/Git rows on peers, existing local behavior preserved. This is component browser evidence, not release-grade CUA.Reproduction steps and screenshots:
docs/evidence/issue131/README.md; runnable fixture:scripts/cua/fleet-local-api-fixture.html.Refs #131 (local-only API guards; follow-tail coverage already exists through #99). The preserved branch is not merged wholesale, and the remaining behavior groups are reviewed separately.