Repository navigation
Conversation
KuSh
force-pushed
the
fix/pi-omp-ownership-lifecycle
branch
6 times, most recently
from
September 20, 2026 23:01
f497ce1 to
0bfa30a
Compare
KuSh
force-pushed
the
fix/pi-omp-ownership-lifecycle
branch
from
September 21, 2026 05:49
0bfa30a to
8615434
Compare
5 tasks done
KuSh
force-pushed
the
fix/pi-omp-ownership-lifecycle
branch
from
September 28, 2026 01:10
8615434 to
fed0895
Compare
KuSh
force-pushed
the
fix/pi-omp-ownership-lifecycle
branch
from
October 7, 2026 16:17
fed0895 to
2dfbe3f
Compare
Follow-up to rtk-ai#3707. The ownership sidecar could not protect the case it exists for, and several destructive paths had no way back. Ownership: - Record ownership for an extension that pre-dates the sidecar, marking the record partial instead of claiming sole ownership. Without this the sidecar is never created for an upgrading user, so shared-file protection is inert for everyone who already had the extension. - Preserve entries written by a newer RTK across rewrites, and keep the recorded owners when one entry cannot be parsed. - Merge into an existing record rather than resetting it: deleting the file does not unconfigure an agent that still resolves to that path. - Re-read the record immediately before writing, since a confirmation prompt sits between the caller's read and the write. - On uninstall, drop only the departing agent when the extension itself survives (removing a symlink leaves the target and its other owner). Recovery: - Give uninstall the same Ask/Auto/Skip policy as install, so a hand-edited or fork-built extension stays removable with --auto-patch instead of being permanently stuck. - Copy non-stock content aside before replacing or removing it, never overwriting an earlier backup. - Make --dry-run describe what the real run does, including the backup. Symlinks: - Detect an alias at any path component, not just the last one. - Write through a dangling link to its target instead of replacing the link. - Route an unresolvable link through the same confirmation as any other content the user put there. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
KuSh
force-pushed
the
fix/pi-omp-ownership-lifecycle
branch
from
October 7, 2026 16:34
2dfbe3f to
58b5c56
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to #3707, split out so it could merge without waiting on this.
#3707 introduced the
.rtk-agentsownership sidecar to stop one agent's uninstall from deleting an extension the other agent shares. The mechanism is right, but it could not engage in the case it exists for, and several destructive paths had no way back. None of this is a regression againstdevelop— OMP support did not exist there before #3707 — which is why it was kept out of that PR.Ownership
The sidecar was never created for an extension that pre-dated it, so shared-file protection was inert for every upgrading user: install OMP over an existing Pi extension, uninstall OMP, and Pi's extension is deleted with no warning and exit 0.
The underlying problem was that
record_managed_agenthad two outcomes for three facts — "nobody else owns this", "someone else does", and "someone installed this and I cannot know who". The third now has a representation (prior_unknown), so a record can be created for a pre-existing extension while staying explicitly partial.Also in this area:
Recovery
--auto-patchinstead of being permanently stuck behind "remove the file manually".--dry-rundescribes what the real run does, including the backup.The copy callers go through one adapter over the shared
free_backup_slot, so the probe, the ceiling and the notion of "already preserved" exist once. The uninstall prompt matches the slot directly, because it is the only caller whose wording depends on why no copy will be made: content already preserved reads differently from a source RTK cannot read.Symlinks
Tests
test_global_uninstall_detects_shared_pi_omp_extensionno longer creates a project-local OMP directory: global-scope share detection never reads one, and its relative path put an empty.omp/in the checkout on every run. Its assertion now names what it checks. Thetestjob'sfetch-depth: 0inci.ymlgets a comment naming the Pi extension history guard that depends on it.Verification
cargo fmt --all --check,cargo clippy --all-targetsandcargo test --allclean: 3974 unit tests and 28 OMP/Pi integration tests, 33 test binaries in all. Also type-checked forx86_64-pc-windows-gnuwith--all-targets, since the Unix-gated tests are invisible to a Linux run.🤖 Generated with Claude Code