Skip to content

fix(hosts): preserve malformed settings and require explicit retraction - #541

Open
jckail wants to merge 1 commit into
trailhq:mainfrom
jckail:fix/jck104-preserve-host-settings
Open

jckail wants to merge 1 commit into
trailhq:mainfrom
jckail:fix/jck104-preserve-host-settings

Conversation

@jckail

@jckail jckail commented Oct 2, 2026 •

Copy link
Copy Markdown

Claude initialization currently replaces malformed or non-object project settings with fresh configuration. This change refuses initialization before installation writes and preserves those bytes. Host retraction now mutates only when apply: true; omitted/false options remain previews.

Adds 12 inert temporary-repository/home cases covering invalid/missing/valid settings and explicit retraction.

Validation on the same proposal in fork PR #1: full CI succeeded. Linux: 1,369 total, 1,368 passed, 1 skipped, 0 failed. Windows: 1,369 total, 1,363 passed, 6 skipped, 0 failed. Node 24 WASM regression passed. Blast radius, Blast viewer, and Cursor Bugbot completed successfully.

The fork PR was ordinarily squash-merged as dbaf1ef3e3131cf305369b3419ad68a2faac0c66 on base fe30ead39d5e6f0c921018d364da2bdbc9d4b3ad; merged source retains upstream's separate init child-loader change. Fresh merged-main CI 37071143192 remains in progress at this evidence snapshot. Fork results do not imply upstream workflow admission or maintainer approval. No native hooks, provider, package installation, npm publication or application deployment was performed locally.

Tracks JCK-104: https://linear.app/jckail/issue/JCK-104/audit-and-improve-codex-agent-configuration-and-repository

@trailhq-graft

trailhq-graft Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

🌱 graft blast radius

2 areas changed → 1 area can be affected. 4 dependent symbols, depth 2.
Tests: 2 areas updated their tests.
Tag: @anirudhkumar-nanonets — 3 of 3 areas · @shhdwi — CLI Wiring

flowchart TB
  A0(("CLI Wiring<br/>4 symbols"))
  classDef reached fill:#D9EDF3,stroke:#3AA7C9,stroke-width:1.5px,color:#0E313C;
  class A0 reached;
Loading
Can be affected Symbols Nearest hop Reached from
CLI Wiring 4 src/cli.ts:L1240-L1338 wireTarget — calls, depth 1 Claude Initialization, Host Retraction
Who knows this code — 2 people across 3 areas
Area Who knows it
Claude Initialization · changed @anirudhkumar-nanonets — 9 commits, last 7d ago
Host Retraction · changed @anirudhkumar-nanonets — 3 commits, last 22d ago
CLI Wiring · affected @anirudhkumar-nanonets — 52 commits, last 3d ago · @shhdwi — 23 commits, last 2mo ago

Ownership is git history over each area's own files, weighted towards recent work (120-day half-life). Merge commits and bots are dropped, and you are dropped from your own PR. A name with no @ has no GitHub handle in its commit email — tag them by hand, or add a .mailmap entry. A suggestion from history, not a CODEOWNERS rule.

All 4 dependent symbols, grouped by area

CLI Wiring — 4 symbols in 2 files

  • src/cli.ts:L1240-L1338 — wireTarget (calls, depth 1)
    1272: runRetract(repo, { home, apply: true, global: opts.global, cache: false, exclude: ids }),
  • src/cli.ts:L1-L1939 — cli.ts (calls, depth 1)
    16: import { buildGraphIfMissing, runInit } from "./claude/init.js";
  • src/upkeep-run.ts:L42-L51 — rewriteWiring (calls, depth 1)
    47: runInit(repo, { build: false, cliPath: graftCliPath(), statusline: opts.statusline, global: opts.global });
  • src/cli.ts:L1012-L1229 — runInitCommand (calls, depth 2)
Test signal per changed area — 2 ✓

Reached = a node under a test path has a resolved edge into the changed symbol. It undercounts anything called indirectly — through a CLI, a spawned process or a dynamic import — so read a low ratio as “look here”, never as a coverage gate.

  • ✓ Claude Initialization — 1 of 1 reached · 1 test file changed here: test/graft-preservation.test.ts
  • ✓ Host Retraction — 1 of 1 reached · 1 test file changed here: test/graft-preservation.test.ts
3 test suites also reference this code

4 symbols, kept out of the diagram and the table so they cannot crowd out the areas a reviewer has to look at.

  • test/claude-init.test.ts
  • test/hosts-claude-global.test.ts
  • test/hosts-retract.test.ts

graft blast · origin/main...HEAD · depth 2 · 3 changed files

Open the interactive graph → — click an area to see its dependent symbols at file:line.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant