feat(mcp): let agents change thread workspaces - #8680

Open
juliusmarminge wants to merge 17 commits into
agents/mcp-workspaces/inventoryfrom
agents/mcp-workspaces/checkout
Open

feat(mcp): let agents change thread workspaces#8680
juliusmarminge wants to merge 17 commits into
agents/mcp-workspaces/inventoryfrom
agents/mcp-workspaces/checkout

Conversation

@juliusmarminge

@juliusmarmingejuliusmarminge commented Aug 29, 2026

Copy link
Copy Markdown
Member

Problem

Existing threads cannot safely move between their project root, branches, and worktrees through MCP. Updating only the recorded branch can leave durable thread state out of sync with Git, and a workspace change can detach the caller before follow-up work is queued.

Change

  • add typed t3_thread_checkout targets for branch switch/create, canonical inventory worktree reuse, project-root return, and new-worktree creation
  • resolve symlinked and nested paths to canonical repository and physical-worktree identity before ownership checks
  • serialize each physical checkout across callers and re-read bindings across projects after acquiring the guard, failing closed when a possible same-repository owner cannot be resolved
  • invoke Git's real remote/tracking resolution, including a verified detached remote result, and verify post-switch ref and commit identity before durable binding
  • recheck caller lifecycle, checkout state, and physical owners immediately before mutation, then enforce the archive constraint inside the serialized V2 metadata decision
  • use one conservative rollback rule that rechecks ref, dirty state, HEAD commit, physical owners, and caller lifecycle; retain created branches when safe cleanup cannot be proven
  • preserve the committed handoff result and queued continuation across caller detachment or later fallible work
  • recover stale thread bindings by selecting a healthy listed checkout or creating from the project root without touching the missing checkout

Behavior

Workspace path changes queue an optional continuation after the binding commits and before the calling provider session detaches. Same-workspace retries are idempotent. Failures report whether Git changed, whether the binding committed, and whether rollback completed, failed, or was unsafe. Unknown, unattested, or concurrently changed Git state is preserved. The workflow never stashes or drops files, removes existing worktrees, or implements retention, pruning, or revival.

Validation

  • vp test run apps/server/src/mcp/WorktreeMcpService.test.ts (107 tests)
  • vp test run apps/server/src/vcs/GitVcsDriverCore.test.ts (59 tests)
  • focused Git workflow, V2 runtime/continuation, MCP registration, contracts, client-runtime, and provider adapter tests
  • real Git explicit-remote/detached, nested-repository identity, and conservative rollback coverage
  • real V2 archive constraint plus persisted detach receipt, queued continuation, and fake-provider cwd coverage
  • targeted server TypeScript check and targeted lint

Dependency

Upper member of native stack #8711. Depends on workspace inventory PR #8685 and remains independent of lifecycle PR #5589.

Implemented by GPT-5.6-Sol via Codex in T3 Code.


Note

Medium Risk
Large changes to Git mutation, durable thread bindings, and concurrency guards in MCP worktree paths; incorrect rollback or binding logic could leave Git and recorded thread state diverged, though scope is limited to worktree MCP tooling rather than core auth or data stores.

Overview
Adds t3_thread_checkout so MCP agents can move a thread between the project root, an existing listed worktree, a branch switch/create (including remote refs), or a new worktree—mutating Git first, then updating durable thread metadata only after ref/commit verification. Workspace moves can queue a continuation before the provider session detaches.

Handoff is aligned with the same model: attached threads can hand off to another worktree, transitions are serialized per thread and per physical checkout, cross-project ownership is checked via canonical Git identity, and failures can return partial_failure with rollback hints instead of always tearing down created worktrees/branches.

Orchestrator thread.metadata.update now supports compare-and-set via expectedBranch and expectedArchived (alongside existing worktree expectations). GitWorkflowService.resolveCommit is exposed for HEAD/ref verification during these flows.

Reviewed by Cursor Bugbot for commit 0e3839f. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Add t3_thread_checkout MCP tool to let agents switch thread workspaces

  • Introduces WorktreeMcpService.checkout and the t3_thread_checkout MCP tool, enabling agents to move a thread to an existing branch, return to the project root, reuse or create a worktree, and create-and-switch new branches
  • Adds compare-and-swap guards (expectedBranch, expectedArchived) to the thread.metadata.update command in Orchestrator.ts; the dispatch fails with OrchestratorDispatchError when expectations don't match current thread state
  • Replaces per-thread handoff guards with per-physical-workspace serialization (workspaceTransitionsInFlight) in WorktreeMcpService.ts to prevent concurrent mutations to the same checkout
  • Hardens gitWorkflow.createRef in GitVcsDriverCore.ts to validate branch names via git check-ref-format and use git branch -- <name> so option-like names are rejected
  • Risk: transitionIds key format changes (binding/continuation suffixes replace worktree-handoff values), affecting commandId/messageId identifiers emitted during metadata updates and continuations; status handler now treats a non-repo path with an existing workspace inventory as an error rather than benign

Macroscope summarized 0e3839f.

@coderabbitai

coderabbitaiBot commented Aug 29, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: a2fe674c-aa02-4f15-950f-20e9f297b529

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Warning

Your free Security trial is over. An organization admin can activate Security or dismiss this notice.


Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XXL 1,000+ changed lines (additions + deletions). labels Aug 29, 2026
@github-actions

github-actionsBot commented Aug 29, 2026

Copy link
Copy Markdown
Contributor

Thread transfer impact

⚠️ The latest CI run did not produce a thread transfer result for 0e3839f.

This comment will update automatically after the next completed run.

Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
@juliusmarminge
juliusmarminge changed the base branch from t3code/codex-turn-mapping to agents/mcp-workspaces/inventoryAugust 29, 2026 21:55
Comment threaddocs/orchestration-v2/orchestrator-mcp-server.md
Comment threaddocs/user/source-control.md Outdated
@juliusmarminge
juliusmarminge marked this pull request as ready for review August 29, 2026 22:44
Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
@macroscopeapp

macroscopeappBot commented Aug 29, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This PR adds a substantial destructive MCP workflow that can switch branches, create or reuse worktrees, update durable thread bindings, and detach or restart provider sessions. Its cross-component concurrency, rollback, and lifecycle behavior is too broad for automatic approval despite extensive test coverage.

You can add or adjust custom eligibility rules. Learn more.

Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
@juliusmarminge
juliusmarmingeforce-pushed the agents/mcp-workspaces/checkout branch from 03d0e2b to 4453207CompareAugust 30, 2026 17:29
Comment threaddocs/orchestration-v2/orchestrator-mcp-server.md Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
@juliusmarminge
juliusmarmingeforce-pushed the agents/mcp-workspaces/checkout branch from 4453207 to 1d54579CompareAugust 30, 2026 18:10
Comment threaddocs/orchestration-v2/orchestrator-mcp-server.md Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
@juliusmarminge
juliusmarmingeforce-pushed the agents/mcp-workspaces/checkout branch from 76ccdb2 to 69afd25CompareAugust 30, 2026 18:41
Comment threaddocs/user/source-control.md Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Effect service conventions review of the new WorktreeMcpService.checkout path: service tag, inline interface, make/layer, subpath namespace imports, dependency acquisition (yield* Foo.Foo), and error construction all follow the conventions. One test-organization issue noted inline.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/server/src/mcp/WorktreeMcpService.test.ts Outdated
@juliusmarminge
juliusmarmingeforce-pushed the agents/mcp-workspaces/checkout branch from 1ed8ca4 to d653ad1CompareAugust 30, 2026 20:14
Comment threadapps/server/src/mcp/WorktreeMcpService.ts

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

Bugbot Autofix is ON, but a cloud agent failed to start.

Reviewed by Cursor Bugbot for commit d653ad1. Configure here.

Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XXL1,000+ changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@juliusmarminge
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

feat(mcp): let agents change thread workspaces - #8680

Open
juliusmarminge wants to merge 17 commits into
agents/mcp-workspaces/inventoryfrom
agents/mcp-workspaces/checkout
Open

feat(mcp): let agents change thread workspaces#8680
juliusmarminge wants to merge 17 commits into
agents/mcp-workspaces/inventoryfrom
agents/mcp-workspaces/checkout

Conversation

@juliusmarminge

@juliusmarmingejuliusmarminge commented Aug 29, 2026

Copy link
Copy Markdown
Member

Problem

Existing threads cannot safely move between their project root, branches, and worktrees through MCP. Updating only the recorded branch can leave durable thread state out of sync with Git, and a workspace change can detach the caller before follow-up work is queued.

Change

  • add typed t3_thread_checkout targets for branch switch/create, canonical inventory worktree reuse, project-root return, and new-worktree creation
  • resolve symlinked and nested paths to canonical repository and physical-worktree identity before ownership checks
  • serialize each physical checkout across callers and re-read bindings across projects after acquiring the guard, failing closed when a possible same-repository owner cannot be resolved
  • invoke Git's real remote/tracking resolution, including a verified detached remote result, and verify post-switch ref and commit identity before durable binding
  • recheck caller lifecycle, checkout state, and physical owners immediately before mutation, then enforce the archive constraint inside the serialized V2 metadata decision
  • use one conservative rollback rule that rechecks ref, dirty state, HEAD commit, physical owners, and caller lifecycle; retain created branches when safe cleanup cannot be proven
  • preserve the committed handoff result and queued continuation across caller detachment or later fallible work
  • recover stale thread bindings by selecting a healthy listed checkout or creating from the project root without touching the missing checkout

Behavior

Workspace path changes queue an optional continuation after the binding commits and before the calling provider session detaches. Same-workspace retries are idempotent. Failures report whether Git changed, whether the binding committed, and whether rollback completed, failed, or was unsafe. Unknown, unattested, or concurrently changed Git state is preserved. The workflow never stashes or drops files, removes existing worktrees, or implements retention, pruning, or revival.

Validation

  • vp test run apps/server/src/mcp/WorktreeMcpService.test.ts (107 tests)
  • vp test run apps/server/src/vcs/GitVcsDriverCore.test.ts (59 tests)
  • focused Git workflow, V2 runtime/continuation, MCP registration, contracts, client-runtime, and provider adapter tests
  • real Git explicit-remote/detached, nested-repository identity, and conservative rollback coverage
  • real V2 archive constraint plus persisted detach receipt, queued continuation, and fake-provider cwd coverage
  • targeted server TypeScript check and targeted lint

Dependency

Upper member of native stack #8711. Depends on workspace inventory PR #8685 and remains independent of lifecycle PR #5589.

Implemented by GPT-5.6-Sol via Codex in T3 Code.


Note

Medium Risk
Large changes to Git mutation, durable thread bindings, and concurrency guards in MCP worktree paths; incorrect rollback or binding logic could leave Git and recorded thread state diverged, though scope is limited to worktree MCP tooling rather than core auth or data stores.

Overview
Adds t3_thread_checkout so MCP agents can move a thread between the project root, an existing listed worktree, a branch switch/create (including remote refs), or a new worktree—mutating Git first, then updating durable thread metadata only after ref/commit verification. Workspace moves can queue a continuation before the provider session detaches.

Handoff is aligned with the same model: attached threads can hand off to another worktree, transitions are serialized per thread and per physical checkout, cross-project ownership is checked via canonical Git identity, and failures can return partial_failure with rollback hints instead of always tearing down created worktrees/branches.

Orchestrator thread.metadata.update now supports compare-and-set via expectedBranch and expectedArchived (alongside existing worktree expectations). GitWorkflowService.resolveCommit is exposed for HEAD/ref verification during these flows.

Reviewed by Cursor Bugbot for commit 0e3839f. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Add t3_thread_checkout MCP tool to let agents switch thread workspaces

  • Introduces WorktreeMcpService.checkout and the t3_thread_checkout MCP tool, enabling agents to move a thread to an existing branch, return to the project root, reuse or create a worktree, and create-and-switch new branches
  • Adds compare-and-swap guards (expectedBranch, expectedArchived) to the thread.metadata.update command in Orchestrator.ts; the dispatch fails with OrchestratorDispatchError when expectations don't match current thread state
  • Replaces per-thread handoff guards with per-physical-workspace serialization (workspaceTransitionsInFlight) in WorktreeMcpService.ts to prevent concurrent mutations to the same checkout
  • Hardens gitWorkflow.createRef in GitVcsDriverCore.ts to validate branch names via git check-ref-format and use git branch -- <name> so option-like names are rejected
  • Risk: transitionIds key format changes (binding/continuation suffixes replace worktree-handoff values), affecting commandId/messageId identifiers emitted during metadata updates and continuations; status handler now treats a non-repo path with an existing workspace inventory as an error rather than benign

Macroscope summarized 0e3839f.

@coderabbitai

coderabbitaiBot commented Aug 29, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: a2fe674c-aa02-4f15-950f-20e9f297b529

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Warning

Your free Security trial is over. An organization admin can activate Security or dismiss this notice.


Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XXL 1,000+ changed lines (additions + deletions). labels Aug 29, 2026
@github-actions

github-actionsBot commented Aug 29, 2026

Copy link
Copy Markdown
Contributor

Thread transfer impact

⚠️ The latest CI run did not produce a thread transfer result for 0e3839f.

This comment will update automatically after the next completed run.

Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
@juliusmarminge
juliusmarminge changed the base branch from t3code/codex-turn-mapping to agents/mcp-workspaces/inventoryAugust 29, 2026 21:55
Comment threaddocs/orchestration-v2/orchestrator-mcp-server.md
Comment threaddocs/user/source-control.md Outdated
@juliusmarminge
juliusmarminge marked this pull request as ready for review August 29, 2026 22:44
Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
@macroscopeapp

macroscopeappBot commented Aug 29, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This PR adds a substantial destructive MCP workflow that can switch branches, create or reuse worktrees, update durable thread bindings, and detach or restart provider sessions. Its cross-component concurrency, rollback, and lifecycle behavior is too broad for automatic approval despite extensive test coverage.

You can add or adjust custom eligibility rules. Learn more.

Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
@juliusmarminge
juliusmarmingeforce-pushed the agents/mcp-workspaces/checkout branch from 03d0e2b to 4453207CompareAugust 30, 2026 17:29
Comment threaddocs/orchestration-v2/orchestrator-mcp-server.md Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
@juliusmarminge
juliusmarmingeforce-pushed the agents/mcp-workspaces/checkout branch from 4453207 to 1d54579CompareAugust 30, 2026 18:10
Comment threaddocs/orchestration-v2/orchestrator-mcp-server.md Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
@juliusmarminge
juliusmarmingeforce-pushed the agents/mcp-workspaces/checkout branch from 76ccdb2 to 69afd25CompareAugust 30, 2026 18:41
Comment threaddocs/user/source-control.md Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Effect service conventions review of the new WorktreeMcpService.checkout path: service tag, inline interface, make/layer, subpath namespace imports, dependency acquisition (yield* Foo.Foo), and error construction all follow the conventions. One test-organization issue noted inline.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/server/src/mcp/WorktreeMcpService.test.ts Outdated
@juliusmarminge
juliusmarmingeforce-pushed the agents/mcp-workspaces/checkout branch from 1ed8ca4 to d653ad1CompareAugust 30, 2026 20:14
Comment threadapps/server/src/mcp/WorktreeMcpService.ts

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

Bugbot Autofix is ON, but a cloud agent failed to start.

Reviewed by Cursor Bugbot for commit d653ad1. Configure here.

Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XXL1,000+ changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@juliusmarminge
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(mcp): let agents change thread workspaces - #8680

Open
juliusmarminge wants to merge 17 commits into
agents/mcp-workspaces/inventoryfrom
agents/mcp-workspaces/checkout
Open

feat(mcp): let agents change thread workspaces#8680
juliusmarminge wants to merge 17 commits into
agents/mcp-workspaces/inventoryfrom
agents/mcp-workspaces/checkout

Conversation

@juliusmarminge

@juliusmarmingejuliusmarminge commented Aug 29, 2026

Copy link
Copy Markdown
Member

Problem

Existing threads cannot safely move between their project root, branches, and worktrees through MCP. Updating only the recorded branch can leave durable thread state out of sync with Git, and a workspace change can detach the caller before follow-up work is queued.

Change

  • add typed t3_thread_checkout targets for branch switch/create, canonical inventory worktree reuse, project-root return, and new-worktree creation
  • resolve symlinked and nested paths to canonical repository and physical-worktree identity before ownership checks
  • serialize each physical checkout across callers and re-read bindings across projects after acquiring the guard, failing closed when a possible same-repository owner cannot be resolved
  • invoke Git's real remote/tracking resolution, including a verified detached remote result, and verify post-switch ref and commit identity before durable binding
  • recheck caller lifecycle, checkout state, and physical owners immediately before mutation, then enforce the archive constraint inside the serialized V2 metadata decision
  • use one conservative rollback rule that rechecks ref, dirty state, HEAD commit, physical owners, and caller lifecycle; retain created branches when safe cleanup cannot be proven
  • preserve the committed handoff result and queued continuation across caller detachment or later fallible work
  • recover stale thread bindings by selecting a healthy listed checkout or creating from the project root without touching the missing checkout

Behavior

Workspace path changes queue an optional continuation after the binding commits and before the calling provider session detaches. Same-workspace retries are idempotent. Failures report whether Git changed, whether the binding committed, and whether rollback completed, failed, or was unsafe. Unknown, unattested, or concurrently changed Git state is preserved. The workflow never stashes or drops files, removes existing worktrees, or implements retention, pruning, or revival.

Validation

  • vp test run apps/server/src/mcp/WorktreeMcpService.test.ts (107 tests)
  • vp test run apps/server/src/vcs/GitVcsDriverCore.test.ts (59 tests)
  • focused Git workflow, V2 runtime/continuation, MCP registration, contracts, client-runtime, and provider adapter tests
  • real Git explicit-remote/detached, nested-repository identity, and conservative rollback coverage
  • real V2 archive constraint plus persisted detach receipt, queued continuation, and fake-provider cwd coverage
  • targeted server TypeScript check and targeted lint

Dependency

Upper member of native stack #8711. Depends on workspace inventory PR #8685 and remains independent of lifecycle PR #5589.

Implemented by GPT-5.6-Sol via Codex in T3 Code.


Note

Medium Risk
Large changes to Git mutation, durable thread bindings, and concurrency guards in MCP worktree paths; incorrect rollback or binding logic could leave Git and recorded thread state diverged, though scope is limited to worktree MCP tooling rather than core auth or data stores.

Overview
Adds t3_thread_checkout so MCP agents can move a thread between the project root, an existing listed worktree, a branch switch/create (including remote refs), or a new worktree—mutating Git first, then updating durable thread metadata only after ref/commit verification. Workspace moves can queue a continuation before the provider session detaches.

Handoff is aligned with the same model: attached threads can hand off to another worktree, transitions are serialized per thread and per physical checkout, cross-project ownership is checked via canonical Git identity, and failures can return partial_failure with rollback hints instead of always tearing down created worktrees/branches.

Orchestrator thread.metadata.update now supports compare-and-set via expectedBranch and expectedArchived (alongside existing worktree expectations). GitWorkflowService.resolveCommit is exposed for HEAD/ref verification during these flows.

Reviewed by Cursor Bugbot for commit 0e3839f. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Add t3_thread_checkout MCP tool to let agents switch thread workspaces

  • Introduces WorktreeMcpService.checkout and the t3_thread_checkout MCP tool, enabling agents to move a thread to an existing branch, return to the project root, reuse or create a worktree, and create-and-switch new branches
  • Adds compare-and-swap guards (expectedBranch, expectedArchived) to the thread.metadata.update command in Orchestrator.ts; the dispatch fails with OrchestratorDispatchError when expectations don't match current thread state
  • Replaces per-thread handoff guards with per-physical-workspace serialization (workspaceTransitionsInFlight) in WorktreeMcpService.ts to prevent concurrent mutations to the same checkout
  • Hardens gitWorkflow.createRef in GitVcsDriverCore.ts to validate branch names via git check-ref-format and use git branch -- <name> so option-like names are rejected
  • Risk: transitionIds key format changes (binding/continuation suffixes replace worktree-handoff values), affecting commandId/messageId identifiers emitted during metadata updates and continuations; status handler now treats a non-repo path with an existing workspace inventory as an error rather than benign

Macroscope summarized 0e3839f.

@coderabbitai

coderabbitaiBot commented Aug 29, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: a2fe674c-aa02-4f15-950f-20e9f297b529

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Warning

Your free Security trial is over. An organization admin can activate Security or dismiss this notice.


Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XXL 1,000+ changed lines (additions + deletions). labels Aug 29, 2026
@github-actions

github-actionsBot commented Aug 29, 2026

Copy link
Copy Markdown
Contributor

Thread transfer impact

⚠️ The latest CI run did not produce a thread transfer result for 0e3839f.

This comment will update automatically after the next completed run.

Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
@juliusmarminge
juliusmarminge changed the base branch from t3code/codex-turn-mapping to agents/mcp-workspaces/inventoryAugust 29, 2026 21:55
Comment threaddocs/orchestration-v2/orchestrator-mcp-server.md
Comment threaddocs/user/source-control.md Outdated
@juliusmarminge
juliusmarminge marked this pull request as ready for review August 29, 2026 22:44
Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
@macroscopeapp

macroscopeappBot commented Aug 29, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This PR adds a substantial destructive MCP workflow that can switch branches, create or reuse worktrees, update durable thread bindings, and detach or restart provider sessions. Its cross-component concurrency, rollback, and lifecycle behavior is too broad for automatic approval despite extensive test coverage.

You can add or adjust custom eligibility rules. Learn more.

Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
@juliusmarminge
juliusmarmingeforce-pushed the agents/mcp-workspaces/checkout branch from 03d0e2b to 4453207CompareAugust 30, 2026 17:29
Comment threaddocs/orchestration-v2/orchestrator-mcp-server.md Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
@juliusmarminge
juliusmarmingeforce-pushed the agents/mcp-workspaces/checkout branch from 4453207 to 1d54579CompareAugust 30, 2026 18:10
Comment threaddocs/orchestration-v2/orchestrator-mcp-server.md Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
@juliusmarminge
juliusmarmingeforce-pushed the agents/mcp-workspaces/checkout branch from 76ccdb2 to 69afd25CompareAugust 30, 2026 18:41
Comment threaddocs/user/source-control.md Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Effect service conventions review of the new WorktreeMcpService.checkout path: service tag, inline interface, make/layer, subpath namespace imports, dependency acquisition (yield* Foo.Foo), and error construction all follow the conventions. One test-organization issue noted inline.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/server/src/mcp/WorktreeMcpService.test.ts Outdated
@juliusmarminge
juliusmarmingeforce-pushed the agents/mcp-workspaces/checkout branch from 1ed8ca4 to d653ad1CompareAugust 30, 2026 20:14
Comment threadapps/server/src/mcp/WorktreeMcpService.ts

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

Bugbot Autofix is ON, but a cloud agent failed to start.

Reviewed by Cursor Bugbot for commit d653ad1. Configure here.

Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XXL1,000+ changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@juliusmarminge
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(mcp): let agents change thread workspaces - #8680

Open
juliusmarminge wants to merge 17 commits into
agents/mcp-workspaces/inventoryfrom
agents/mcp-workspaces/checkout
Open

feat(mcp): let agents change thread workspaces#8680
juliusmarminge wants to merge 17 commits into
agents/mcp-workspaces/inventoryfrom
agents/mcp-workspaces/checkout

Conversation

@juliusmarminge

@juliusmarmingejuliusmarminge commented Aug 29, 2026

Copy link
Copy Markdown
Member

Problem

Existing threads cannot safely move between their project root, branches, and worktrees through MCP. Updating only the recorded branch can leave durable thread state out of sync with Git, and a workspace change can detach the caller before follow-up work is queued.

Change

  • add typed t3_thread_checkout targets for branch switch/create, canonical inventory worktree reuse, project-root return, and new-worktree creation
  • resolve symlinked and nested paths to canonical repository and physical-worktree identity before ownership checks
  • serialize each physical checkout across callers and re-read bindings across projects after acquiring the guard, failing closed when a possible same-repository owner cannot be resolved
  • invoke Git's real remote/tracking resolution, including a verified detached remote result, and verify post-switch ref and commit identity before durable binding
  • recheck caller lifecycle, checkout state, and physical owners immediately before mutation, then enforce the archive constraint inside the serialized V2 metadata decision
  • use one conservative rollback rule that rechecks ref, dirty state, HEAD commit, physical owners, and caller lifecycle; retain created branches when safe cleanup cannot be proven
  • preserve the committed handoff result and queued continuation across caller detachment or later fallible work
  • recover stale thread bindings by selecting a healthy listed checkout or creating from the project root without touching the missing checkout

Behavior

Workspace path changes queue an optional continuation after the binding commits and before the calling provider session detaches. Same-workspace retries are idempotent. Failures report whether Git changed, whether the binding committed, and whether rollback completed, failed, or was unsafe. Unknown, unattested, or concurrently changed Git state is preserved. The workflow never stashes or drops files, removes existing worktrees, or implements retention, pruning, or revival.

Validation

  • vp test run apps/server/src/mcp/WorktreeMcpService.test.ts (107 tests)
  • vp test run apps/server/src/vcs/GitVcsDriverCore.test.ts (59 tests)
  • focused Git workflow, V2 runtime/continuation, MCP registration, contracts, client-runtime, and provider adapter tests
  • real Git explicit-remote/detached, nested-repository identity, and conservative rollback coverage
  • real V2 archive constraint plus persisted detach receipt, queued continuation, and fake-provider cwd coverage
  • targeted server TypeScript check and targeted lint

Dependency

Upper member of native stack #8711. Depends on workspace inventory PR #8685 and remains independent of lifecycle PR #5589.

Implemented by GPT-5.6-Sol via Codex in T3 Code.


Note

Medium Risk
Large changes to Git mutation, durable thread bindings, and concurrency guards in MCP worktree paths; incorrect rollback or binding logic could leave Git and recorded thread state diverged, though scope is limited to worktree MCP tooling rather than core auth or data stores.

Overview
Adds t3_thread_checkout so MCP agents can move a thread between the project root, an existing listed worktree, a branch switch/create (including remote refs), or a new worktree—mutating Git first, then updating durable thread metadata only after ref/commit verification. Workspace moves can queue a continuation before the provider session detaches.

Handoff is aligned with the same model: attached threads can hand off to another worktree, transitions are serialized per thread and per physical checkout, cross-project ownership is checked via canonical Git identity, and failures can return partial_failure with rollback hints instead of always tearing down created worktrees/branches.

Orchestrator thread.metadata.update now supports compare-and-set via expectedBranch and expectedArchived (alongside existing worktree expectations). GitWorkflowService.resolveCommit is exposed for HEAD/ref verification during these flows.

Reviewed by Cursor Bugbot for commit 0e3839f. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Add t3_thread_checkout MCP tool to let agents switch thread workspaces

  • Introduces WorktreeMcpService.checkout and the t3_thread_checkout MCP tool, enabling agents to move a thread to an existing branch, return to the project root, reuse or create a worktree, and create-and-switch new branches
  • Adds compare-and-swap guards (expectedBranch, expectedArchived) to the thread.metadata.update command in Orchestrator.ts; the dispatch fails with OrchestratorDispatchError when expectations don't match current thread state
  • Replaces per-thread handoff guards with per-physical-workspace serialization (workspaceTransitionsInFlight) in WorktreeMcpService.ts to prevent concurrent mutations to the same checkout
  • Hardens gitWorkflow.createRef in GitVcsDriverCore.ts to validate branch names via git check-ref-format and use git branch -- <name> so option-like names are rejected
  • Risk: transitionIds key format changes (binding/continuation suffixes replace worktree-handoff values), affecting commandId/messageId identifiers emitted during metadata updates and continuations; status handler now treats a non-repo path with an existing workspace inventory as an error rather than benign

Macroscope summarized 0e3839f.

@coderabbitai

coderabbitaiBot commented Aug 29, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: a2fe674c-aa02-4f15-950f-20e9f297b529

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Warning

Your free Security trial is over. An organization admin can activate Security or dismiss this notice.


Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XXL 1,000+ changed lines (additions + deletions). labels Aug 29, 2026
@github-actions

github-actionsBot commented Aug 29, 2026

Copy link
Copy Markdown
Contributor

Thread transfer impact

⚠️ The latest CI run did not produce a thread transfer result for 0e3839f.

This comment will update automatically after the next completed run.

Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
@juliusmarminge
juliusmarminge changed the base branch from t3code/codex-turn-mapping to agents/mcp-workspaces/inventoryAugust 29, 2026 21:55
Comment threaddocs/orchestration-v2/orchestrator-mcp-server.md
Comment threaddocs/user/source-control.md Outdated
@juliusmarminge
juliusmarminge marked this pull request as ready for review August 29, 2026 22:44
Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
@macroscopeapp

macroscopeappBot commented Aug 29, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This PR adds a substantial destructive MCP workflow that can switch branches, create or reuse worktrees, update durable thread bindings, and detach or restart provider sessions. Its cross-component concurrency, rollback, and lifecycle behavior is too broad for automatic approval despite extensive test coverage.

You can add or adjust custom eligibility rules. Learn more.

Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
@juliusmarminge
juliusmarmingeforce-pushed the agents/mcp-workspaces/checkout branch from 03d0e2b to 4453207CompareAugust 30, 2026 17:29
Comment threaddocs/orchestration-v2/orchestrator-mcp-server.md Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
@juliusmarminge
juliusmarmingeforce-pushed the agents/mcp-workspaces/checkout branch from 4453207 to 1d54579CompareAugust 30, 2026 18:10
Comment threaddocs/orchestration-v2/orchestrator-mcp-server.md Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
@juliusmarminge
juliusmarmingeforce-pushed the agents/mcp-workspaces/checkout branch from 76ccdb2 to 69afd25CompareAugust 30, 2026 18:41
Comment threaddocs/user/source-control.md Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Effect service conventions review of the new WorktreeMcpService.checkout path: service tag, inline interface, make/layer, subpath namespace imports, dependency acquisition (yield* Foo.Foo), and error construction all follow the conventions. One test-organization issue noted inline.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/server/src/mcp/WorktreeMcpService.test.ts Outdated
@juliusmarminge
juliusmarmingeforce-pushed the agents/mcp-workspaces/checkout branch from 1ed8ca4 to d653ad1CompareAugust 30, 2026 20:14
Comment threadapps/server/src/mcp/WorktreeMcpService.ts

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

Bugbot Autofix is ON, but a cloud agent failed to start.

Reviewed by Cursor Bugbot for commit d653ad1. Configure here.

Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XXL1,000+ changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@juliusmarminge
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

feat(mcp): let agents change thread workspaces - #8680

Open
juliusmarminge wants to merge 17 commits into
agents/mcp-workspaces/inventoryfrom
agents/mcp-workspaces/checkout
Open

feat(mcp): let agents change thread workspaces#8680
juliusmarminge wants to merge 17 commits into
agents/mcp-workspaces/inventoryfrom
agents/mcp-workspaces/checkout

Conversation

@juliusmarminge

@juliusmarmingejuliusmarminge commented Aug 29, 2026

Copy link
Copy Markdown
Member

Problem

Existing threads cannot safely move between their project root, branches, and worktrees through MCP. Updating only the recorded branch can leave durable thread state out of sync with Git, and a workspace change can detach the caller before follow-up work is queued.

Change

  • add typed t3_thread_checkout targets for branch switch/create, canonical inventory worktree reuse, project-root return, and new-worktree creation
  • resolve symlinked and nested paths to canonical repository and physical-worktree identity before ownership checks
  • serialize each physical checkout across callers and re-read bindings across projects after acquiring the guard, failing closed when a possible same-repository owner cannot be resolved
  • invoke Git's real remote/tracking resolution, including a verified detached remote result, and verify post-switch ref and commit identity before durable binding
  • recheck caller lifecycle, checkout state, and physical owners immediately before mutation, then enforce the archive constraint inside the serialized V2 metadata decision
  • use one conservative rollback rule that rechecks ref, dirty state, HEAD commit, physical owners, and caller lifecycle; retain created branches when safe cleanup cannot be proven
  • preserve the committed handoff result and queued continuation across caller detachment or later fallible work
  • recover stale thread bindings by selecting a healthy listed checkout or creating from the project root without touching the missing checkout

Behavior

Workspace path changes queue an optional continuation after the binding commits and before the calling provider session detaches. Same-workspace retries are idempotent. Failures report whether Git changed, whether the binding committed, and whether rollback completed, failed, or was unsafe. Unknown, unattested, or concurrently changed Git state is preserved. The workflow never stashes or drops files, removes existing worktrees, or implements retention, pruning, or revival.

Validation

  • vp test run apps/server/src/mcp/WorktreeMcpService.test.ts (107 tests)
  • vp test run apps/server/src/vcs/GitVcsDriverCore.test.ts (59 tests)
  • focused Git workflow, V2 runtime/continuation, MCP registration, contracts, client-runtime, and provider adapter tests
  • real Git explicit-remote/detached, nested-repository identity, and conservative rollback coverage
  • real V2 archive constraint plus persisted detach receipt, queued continuation, and fake-provider cwd coverage
  • targeted server TypeScript check and targeted lint

Dependency

Upper member of native stack #8711. Depends on workspace inventory PR #8685 and remains independent of lifecycle PR #5589.

Implemented by GPT-5.6-Sol via Codex in T3 Code.


Note

Medium Risk
Large changes to Git mutation, durable thread bindings, and concurrency guards in MCP worktree paths; incorrect rollback or binding logic could leave Git and recorded thread state diverged, though scope is limited to worktree MCP tooling rather than core auth or data stores.

Overview
Adds t3_thread_checkout so MCP agents can move a thread between the project root, an existing listed worktree, a branch switch/create (including remote refs), or a new worktree—mutating Git first, then updating durable thread metadata only after ref/commit verification. Workspace moves can queue a continuation before the provider session detaches.

Handoff is aligned with the same model: attached threads can hand off to another worktree, transitions are serialized per thread and per physical checkout, cross-project ownership is checked via canonical Git identity, and failures can return partial_failure with rollback hints instead of always tearing down created worktrees/branches.

Orchestrator thread.metadata.update now supports compare-and-set via expectedBranch and expectedArchived (alongside existing worktree expectations). GitWorkflowService.resolveCommit is exposed for HEAD/ref verification during these flows.

Reviewed by Cursor Bugbot for commit 0e3839f. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Add t3_thread_checkout MCP tool to let agents switch thread workspaces

  • Introduces WorktreeMcpService.checkout and the t3_thread_checkout MCP tool, enabling agents to move a thread to an existing branch, return to the project root, reuse or create a worktree, and create-and-switch new branches
  • Adds compare-and-swap guards (expectedBranch, expectedArchived) to the thread.metadata.update command in Orchestrator.ts; the dispatch fails with OrchestratorDispatchError when expectations don't match current thread state
  • Replaces per-thread handoff guards with per-physical-workspace serialization (workspaceTransitionsInFlight) in WorktreeMcpService.ts to prevent concurrent mutations to the same checkout
  • Hardens gitWorkflow.createRef in GitVcsDriverCore.ts to validate branch names via git check-ref-format and use git branch -- <name> so option-like names are rejected
  • Risk: transitionIds key format changes (binding/continuation suffixes replace worktree-handoff values), affecting commandId/messageId identifiers emitted during metadata updates and continuations; status handler now treats a non-repo path with an existing workspace inventory as an error rather than benign

Macroscope summarized 0e3839f.

@coderabbitai

coderabbitaiBot commented Aug 29, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: a2fe674c-aa02-4f15-950f-20e9f297b529

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Warning

Your free Security trial is over. An organization admin can activate Security or dismiss this notice.


Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XXL 1,000+ changed lines (additions + deletions). labels Aug 29, 2026
@github-actions

github-actionsBot commented Aug 29, 2026

Copy link
Copy Markdown
Contributor

Thread transfer impact

⚠️ The latest CI run did not produce a thread transfer result for 0e3839f.

This comment will update automatically after the next completed run.

Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
@juliusmarminge
juliusmarminge changed the base branch from t3code/codex-turn-mapping to agents/mcp-workspaces/inventoryAugust 29, 2026 21:55
Comment threaddocs/orchestration-v2/orchestrator-mcp-server.md
Comment threaddocs/user/source-control.md Outdated
@juliusmarminge
juliusmarminge marked this pull request as ready for review August 29, 2026 22:44
Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
@macroscopeapp

macroscopeappBot commented Aug 29, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This PR adds a substantial destructive MCP workflow that can switch branches, create or reuse worktrees, update durable thread bindings, and detach or restart provider sessions. Its cross-component concurrency, rollback, and lifecycle behavior is too broad for automatic approval despite extensive test coverage.

You can add or adjust custom eligibility rules. Learn more.

Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
@juliusmarminge
juliusmarmingeforce-pushed the agents/mcp-workspaces/checkout branch from 03d0e2b to 4453207CompareAugust 30, 2026 17:29
Comment threaddocs/orchestration-v2/orchestrator-mcp-server.md Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
@juliusmarminge
juliusmarmingeforce-pushed the agents/mcp-workspaces/checkout branch from 4453207 to 1d54579CompareAugust 30, 2026 18:10
Comment threaddocs/orchestration-v2/orchestrator-mcp-server.md Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
@juliusmarminge
juliusmarmingeforce-pushed the agents/mcp-workspaces/checkout branch from 76ccdb2 to 69afd25CompareAugust 30, 2026 18:41
Comment threaddocs/user/source-control.md Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Effect service conventions review of the new WorktreeMcpService.checkout path: service tag, inline interface, make/layer, subpath namespace imports, dependency acquisition (yield* Foo.Foo), and error construction all follow the conventions. One test-organization issue noted inline.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/server/src/mcp/WorktreeMcpService.test.ts Outdated
@juliusmarminge
juliusmarmingeforce-pushed the agents/mcp-workspaces/checkout branch from 1ed8ca4 to d653ad1CompareAugust 30, 2026 20:14
Comment threadapps/server/src/mcp/WorktreeMcpService.ts

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

Bugbot Autofix is ON, but a cloud agent failed to start.

Reviewed by Cursor Bugbot for commit d653ad1. Configure here.

Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XXL1,000+ changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@juliusmarminge
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(mcp): let agents change thread workspaces - #8680

Open
juliusmarminge wants to merge 17 commits into
agents/mcp-workspaces/inventoryfrom
agents/mcp-workspaces/checkout
Open

feat(mcp): let agents change thread workspaces#8680
juliusmarminge wants to merge 17 commits into
agents/mcp-workspaces/inventoryfrom
agents/mcp-workspaces/checkout

Conversation

@juliusmarminge

@juliusmarmingejuliusmarminge commented Aug 29, 2026

Copy link
Copy Markdown
Member

Problem

Existing threads cannot safely move between their project root, branches, and worktrees through MCP. Updating only the recorded branch can leave durable thread state out of sync with Git, and a workspace change can detach the caller before follow-up work is queued.

Change

  • add typed t3_thread_checkout targets for branch switch/create, canonical inventory worktree reuse, project-root return, and new-worktree creation
  • resolve symlinked and nested paths to canonical repository and physical-worktree identity before ownership checks
  • serialize each physical checkout across callers and re-read bindings across projects after acquiring the guard, failing closed when a possible same-repository owner cannot be resolved
  • invoke Git's real remote/tracking resolution, including a verified detached remote result, and verify post-switch ref and commit identity before durable binding
  • recheck caller lifecycle, checkout state, and physical owners immediately before mutation, then enforce the archive constraint inside the serialized V2 metadata decision
  • use one conservative rollback rule that rechecks ref, dirty state, HEAD commit, physical owners, and caller lifecycle; retain created branches when safe cleanup cannot be proven
  • preserve the committed handoff result and queued continuation across caller detachment or later fallible work
  • recover stale thread bindings by selecting a healthy listed checkout or creating from the project root without touching the missing checkout

Behavior

Workspace path changes queue an optional continuation after the binding commits and before the calling provider session detaches. Same-workspace retries are idempotent. Failures report whether Git changed, whether the binding committed, and whether rollback completed, failed, or was unsafe. Unknown, unattested, or concurrently changed Git state is preserved. The workflow never stashes or drops files, removes existing worktrees, or implements retention, pruning, or revival.

Validation

  • vp test run apps/server/src/mcp/WorktreeMcpService.test.ts (107 tests)
  • vp test run apps/server/src/vcs/GitVcsDriverCore.test.ts (59 tests)
  • focused Git workflow, V2 runtime/continuation, MCP registration, contracts, client-runtime, and provider adapter tests
  • real Git explicit-remote/detached, nested-repository identity, and conservative rollback coverage
  • real V2 archive constraint plus persisted detach receipt, queued continuation, and fake-provider cwd coverage
  • targeted server TypeScript check and targeted lint

Dependency

Upper member of native stack #8711. Depends on workspace inventory PR #8685 and remains independent of lifecycle PR #5589.

Implemented by GPT-5.6-Sol via Codex in T3 Code.


Note

Medium Risk
Large changes to Git mutation, durable thread bindings, and concurrency guards in MCP worktree paths; incorrect rollback or binding logic could leave Git and recorded thread state diverged, though scope is limited to worktree MCP tooling rather than core auth or data stores.

Overview
Adds t3_thread_checkout so MCP agents can move a thread between the project root, an existing listed worktree, a branch switch/create (including remote refs), or a new worktree—mutating Git first, then updating durable thread metadata only after ref/commit verification. Workspace moves can queue a continuation before the provider session detaches.

Handoff is aligned with the same model: attached threads can hand off to another worktree, transitions are serialized per thread and per physical checkout, cross-project ownership is checked via canonical Git identity, and failures can return partial_failure with rollback hints instead of always tearing down created worktrees/branches.

Orchestrator thread.metadata.update now supports compare-and-set via expectedBranch and expectedArchived (alongside existing worktree expectations). GitWorkflowService.resolveCommit is exposed for HEAD/ref verification during these flows.

Reviewed by Cursor Bugbot for commit 0e3839f. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Add t3_thread_checkout MCP tool to let agents switch thread workspaces

  • Introduces WorktreeMcpService.checkout and the t3_thread_checkout MCP tool, enabling agents to move a thread to an existing branch, return to the project root, reuse or create a worktree, and create-and-switch new branches
  • Adds compare-and-swap guards (expectedBranch, expectedArchived) to the thread.metadata.update command in Orchestrator.ts; the dispatch fails with OrchestratorDispatchError when expectations don't match current thread state
  • Replaces per-thread handoff guards with per-physical-workspace serialization (workspaceTransitionsInFlight) in WorktreeMcpService.ts to prevent concurrent mutations to the same checkout
  • Hardens gitWorkflow.createRef in GitVcsDriverCore.ts to validate branch names via git check-ref-format and use git branch -- <name> so option-like names are rejected
  • Risk: transitionIds key format changes (binding/continuation suffixes replace worktree-handoff values), affecting commandId/messageId identifiers emitted during metadata updates and continuations; status handler now treats a non-repo path with an existing workspace inventory as an error rather than benign

Macroscope summarized 0e3839f.

@coderabbitai

coderabbitaiBot commented Aug 29, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: a2fe674c-aa02-4f15-950f-20e9f297b529

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Warning

Your free Security trial is over. An organization admin can activate Security or dismiss this notice.


Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XXL 1,000+ changed lines (additions + deletions). labels Aug 29, 2026
@github-actions

github-actionsBot commented Aug 29, 2026

Copy link
Copy Markdown
Contributor

Thread transfer impact

⚠️ The latest CI run did not produce a thread transfer result for 0e3839f.

This comment will update automatically after the next completed run.

Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
@juliusmarminge
juliusmarminge changed the base branch from t3code/codex-turn-mapping to agents/mcp-workspaces/inventoryAugust 29, 2026 21:55
Comment threaddocs/orchestration-v2/orchestrator-mcp-server.md
Comment threaddocs/user/source-control.md Outdated
@juliusmarminge
juliusmarminge marked this pull request as ready for review August 29, 2026 22:44
Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
@macroscopeapp

macroscopeappBot commented Aug 29, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This PR adds a substantial destructive MCP workflow that can switch branches, create or reuse worktrees, update durable thread bindings, and detach or restart provider sessions. Its cross-component concurrency, rollback, and lifecycle behavior is too broad for automatic approval despite extensive test coverage.

You can add or adjust custom eligibility rules. Learn more.

Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
@juliusmarminge
juliusmarmingeforce-pushed the agents/mcp-workspaces/checkout branch from 03d0e2b to 4453207CompareAugust 30, 2026 17:29
Comment threaddocs/orchestration-v2/orchestrator-mcp-server.md Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
@juliusmarminge
juliusmarmingeforce-pushed the agents/mcp-workspaces/checkout branch from 4453207 to 1d54579CompareAugust 30, 2026 18:10
Comment threaddocs/orchestration-v2/orchestrator-mcp-server.md Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
@juliusmarminge
juliusmarmingeforce-pushed the agents/mcp-workspaces/checkout branch from 76ccdb2 to 69afd25CompareAugust 30, 2026 18:41
Comment threaddocs/user/source-control.md Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Effect service conventions review of the new WorktreeMcpService.checkout path: service tag, inline interface, make/layer, subpath namespace imports, dependency acquisition (yield* Foo.Foo), and error construction all follow the conventions. One test-organization issue noted inline.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/server/src/mcp/WorktreeMcpService.test.ts Outdated
@juliusmarminge
juliusmarmingeforce-pushed the agents/mcp-workspaces/checkout branch from 1ed8ca4 to d653ad1CompareAugust 30, 2026 20:14
Comment threadapps/server/src/mcp/WorktreeMcpService.ts

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

Bugbot Autofix is ON, but a cloud agent failed to start.

Reviewed by Cursor Bugbot for commit d653ad1. Configure here.

Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XXL1,000+ changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@juliusmarminge
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(mcp): let agents change thread workspaces - #8680

Open
juliusmarminge wants to merge 17 commits into
agents/mcp-workspaces/inventoryfrom
agents/mcp-workspaces/checkout
Open

feat(mcp): let agents change thread workspaces#8680
juliusmarminge wants to merge 17 commits into
agents/mcp-workspaces/inventoryfrom
agents/mcp-workspaces/checkout

Conversation

@juliusmarminge

@juliusmarmingejuliusmarminge commented Aug 29, 2026

Copy link
Copy Markdown
Member

Problem

Existing threads cannot safely move between their project root, branches, and worktrees through MCP. Updating only the recorded branch can leave durable thread state out of sync with Git, and a workspace change can detach the caller before follow-up work is queued.

Change

  • add typed t3_thread_checkout targets for branch switch/create, canonical inventory worktree reuse, project-root return, and new-worktree creation
  • resolve symlinked and nested paths to canonical repository and physical-worktree identity before ownership checks
  • serialize each physical checkout across callers and re-read bindings across projects after acquiring the guard, failing closed when a possible same-repository owner cannot be resolved
  • invoke Git's real remote/tracking resolution, including a verified detached remote result, and verify post-switch ref and commit identity before durable binding
  • recheck caller lifecycle, checkout state, and physical owners immediately before mutation, then enforce the archive constraint inside the serialized V2 metadata decision
  • use one conservative rollback rule that rechecks ref, dirty state, HEAD commit, physical owners, and caller lifecycle; retain created branches when safe cleanup cannot be proven
  • preserve the committed handoff result and queued continuation across caller detachment or later fallible work
  • recover stale thread bindings by selecting a healthy listed checkout or creating from the project root without touching the missing checkout

Behavior

Workspace path changes queue an optional continuation after the binding commits and before the calling provider session detaches. Same-workspace retries are idempotent. Failures report whether Git changed, whether the binding committed, and whether rollback completed, failed, or was unsafe. Unknown, unattested, or concurrently changed Git state is preserved. The workflow never stashes or drops files, removes existing worktrees, or implements retention, pruning, or revival.

Validation

  • vp test run apps/server/src/mcp/WorktreeMcpService.test.ts (107 tests)
  • vp test run apps/server/src/vcs/GitVcsDriverCore.test.ts (59 tests)
  • focused Git workflow, V2 runtime/continuation, MCP registration, contracts, client-runtime, and provider adapter tests
  • real Git explicit-remote/detached, nested-repository identity, and conservative rollback coverage
  • real V2 archive constraint plus persisted detach receipt, queued continuation, and fake-provider cwd coverage
  • targeted server TypeScript check and targeted lint

Dependency

Upper member of native stack #8711. Depends on workspace inventory PR #8685 and remains independent of lifecycle PR #5589.

Implemented by GPT-5.6-Sol via Codex in T3 Code.


Note

Medium Risk
Large changes to Git mutation, durable thread bindings, and concurrency guards in MCP worktree paths; incorrect rollback or binding logic could leave Git and recorded thread state diverged, though scope is limited to worktree MCP tooling rather than core auth or data stores.

Overview
Adds t3_thread_checkout so MCP agents can move a thread between the project root, an existing listed worktree, a branch switch/create (including remote refs), or a new worktree—mutating Git first, then updating durable thread metadata only after ref/commit verification. Workspace moves can queue a continuation before the provider session detaches.

Handoff is aligned with the same model: attached threads can hand off to another worktree, transitions are serialized per thread and per physical checkout, cross-project ownership is checked via canonical Git identity, and failures can return partial_failure with rollback hints instead of always tearing down created worktrees/branches.

Orchestrator thread.metadata.update now supports compare-and-set via expectedBranch and expectedArchived (alongside existing worktree expectations). GitWorkflowService.resolveCommit is exposed for HEAD/ref verification during these flows.

Reviewed by Cursor Bugbot for commit 0e3839f. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Add t3_thread_checkout MCP tool to let agents switch thread workspaces

  • Introduces WorktreeMcpService.checkout and the t3_thread_checkout MCP tool, enabling agents to move a thread to an existing branch, return to the project root, reuse or create a worktree, and create-and-switch new branches
  • Adds compare-and-swap guards (expectedBranch, expectedArchived) to the thread.metadata.update command in Orchestrator.ts; the dispatch fails with OrchestratorDispatchError when expectations don't match current thread state
  • Replaces per-thread handoff guards with per-physical-workspace serialization (workspaceTransitionsInFlight) in WorktreeMcpService.ts to prevent concurrent mutations to the same checkout
  • Hardens gitWorkflow.createRef in GitVcsDriverCore.ts to validate branch names via git check-ref-format and use git branch -- <name> so option-like names are rejected
  • Risk: transitionIds key format changes (binding/continuation suffixes replace worktree-handoff values), affecting commandId/messageId identifiers emitted during metadata updates and continuations; status handler now treats a non-repo path with an existing workspace inventory as an error rather than benign

Macroscope summarized 0e3839f.

@coderabbitai

coderabbitaiBot commented Aug 29, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: a2fe674c-aa02-4f15-950f-20e9f297b529

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Warning

Your free Security trial is over. An organization admin can activate Security or dismiss this notice.


Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XXL 1,000+ changed lines (additions + deletions). labels Aug 29, 2026
@github-actions

github-actionsBot commented Aug 29, 2026

Copy link
Copy Markdown
Contributor

Thread transfer impact

⚠️ The latest CI run did not produce a thread transfer result for 0e3839f.

This comment will update automatically after the next completed run.

Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
@juliusmarminge
juliusmarminge changed the base branch from t3code/codex-turn-mapping to agents/mcp-workspaces/inventoryAugust 29, 2026 21:55
Comment threaddocs/orchestration-v2/orchestrator-mcp-server.md
Comment threaddocs/user/source-control.md Outdated
@juliusmarminge
juliusmarminge marked this pull request as ready for review August 29, 2026 22:44
Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
@macroscopeapp

macroscopeappBot commented Aug 29, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This PR adds a substantial destructive MCP workflow that can switch branches, create or reuse worktrees, update durable thread bindings, and detach or restart provider sessions. Its cross-component concurrency, rollback, and lifecycle behavior is too broad for automatic approval despite extensive test coverage.

You can add or adjust custom eligibility rules. Learn more.

Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
@juliusmarminge
juliusmarmingeforce-pushed the agents/mcp-workspaces/checkout branch from 03d0e2b to 4453207CompareAugust 30, 2026 17:29
Comment threaddocs/orchestration-v2/orchestrator-mcp-server.md Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
@juliusmarminge
juliusmarmingeforce-pushed the agents/mcp-workspaces/checkout branch from 4453207 to 1d54579CompareAugust 30, 2026 18:10
Comment threaddocs/orchestration-v2/orchestrator-mcp-server.md Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
@juliusmarminge
juliusmarmingeforce-pushed the agents/mcp-workspaces/checkout branch from 76ccdb2 to 69afd25CompareAugust 30, 2026 18:41
Comment threaddocs/user/source-control.md Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Effect service conventions review of the new WorktreeMcpService.checkout path: service tag, inline interface, make/layer, subpath namespace imports, dependency acquisition (yield* Foo.Foo), and error construction all follow the conventions. One test-organization issue noted inline.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/server/src/mcp/WorktreeMcpService.test.ts Outdated
@juliusmarminge
juliusmarmingeforce-pushed the agents/mcp-workspaces/checkout branch from 1ed8ca4 to d653ad1CompareAugust 30, 2026 20:14
Comment threadapps/server/src/mcp/WorktreeMcpService.ts

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

Bugbot Autofix is ON, but a cloud agent failed to start.

Reviewed by Cursor Bugbot for commit d653ad1. Configure here.

Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XXL1,000+ changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@juliusmarminge
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

feat(mcp): let agents change thread workspaces - #8680

Open
juliusmarminge wants to merge 17 commits into
agents/mcp-workspaces/inventoryfrom
agents/mcp-workspaces/checkout
Open

feat(mcp): let agents change thread workspaces#8680
juliusmarminge wants to merge 17 commits into
agents/mcp-workspaces/inventoryfrom
agents/mcp-workspaces/checkout

Conversation

@juliusmarminge

@juliusmarmingejuliusmarminge commented Aug 29, 2026

Copy link
Copy Markdown
Member

Problem

Existing threads cannot safely move between their project root, branches, and worktrees through MCP. Updating only the recorded branch can leave durable thread state out of sync with Git, and a workspace change can detach the caller before follow-up work is queued.

Change

  • add typed t3_thread_checkout targets for branch switch/create, canonical inventory worktree reuse, project-root return, and new-worktree creation
  • resolve symlinked and nested paths to canonical repository and physical-worktree identity before ownership checks
  • serialize each physical checkout across callers and re-read bindings across projects after acquiring the guard, failing closed when a possible same-repository owner cannot be resolved
  • invoke Git's real remote/tracking resolution, including a verified detached remote result, and verify post-switch ref and commit identity before durable binding
  • recheck caller lifecycle, checkout state, and physical owners immediately before mutation, then enforce the archive constraint inside the serialized V2 metadata decision
  • use one conservative rollback rule that rechecks ref, dirty state, HEAD commit, physical owners, and caller lifecycle; retain created branches when safe cleanup cannot be proven
  • preserve the committed handoff result and queued continuation across caller detachment or later fallible work
  • recover stale thread bindings by selecting a healthy listed checkout or creating from the project root without touching the missing checkout

Behavior

Workspace path changes queue an optional continuation after the binding commits and before the calling provider session detaches. Same-workspace retries are idempotent. Failures report whether Git changed, whether the binding committed, and whether rollback completed, failed, or was unsafe. Unknown, unattested, or concurrently changed Git state is preserved. The workflow never stashes or drops files, removes existing worktrees, or implements retention, pruning, or revival.

Validation

  • vp test run apps/server/src/mcp/WorktreeMcpService.test.ts (107 tests)
  • vp test run apps/server/src/vcs/GitVcsDriverCore.test.ts (59 tests)
  • focused Git workflow, V2 runtime/continuation, MCP registration, contracts, client-runtime, and provider adapter tests
  • real Git explicit-remote/detached, nested-repository identity, and conservative rollback coverage
  • real V2 archive constraint plus persisted detach receipt, queued continuation, and fake-provider cwd coverage
  • targeted server TypeScript check and targeted lint

Dependency

Upper member of native stack #8711. Depends on workspace inventory PR #8685 and remains independent of lifecycle PR #5589.

Implemented by GPT-5.6-Sol via Codex in T3 Code.


Note

Medium Risk
Large changes to Git mutation, durable thread bindings, and concurrency guards in MCP worktree paths; incorrect rollback or binding logic could leave Git and recorded thread state diverged, though scope is limited to worktree MCP tooling rather than core auth or data stores.

Overview
Adds t3_thread_checkout so MCP agents can move a thread between the project root, an existing listed worktree, a branch switch/create (including remote refs), or a new worktree—mutating Git first, then updating durable thread metadata only after ref/commit verification. Workspace moves can queue a continuation before the provider session detaches.

Handoff is aligned with the same model: attached threads can hand off to another worktree, transitions are serialized per thread and per physical checkout, cross-project ownership is checked via canonical Git identity, and failures can return partial_failure with rollback hints instead of always tearing down created worktrees/branches.

Orchestrator thread.metadata.update now supports compare-and-set via expectedBranch and expectedArchived (alongside existing worktree expectations). GitWorkflowService.resolveCommit is exposed for HEAD/ref verification during these flows.

Reviewed by Cursor Bugbot for commit 0e3839f. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Add t3_thread_checkout MCP tool to let agents switch thread workspaces

  • Introduces WorktreeMcpService.checkout and the t3_thread_checkout MCP tool, enabling agents to move a thread to an existing branch, return to the project root, reuse or create a worktree, and create-and-switch new branches
  • Adds compare-and-swap guards (expectedBranch, expectedArchived) to the thread.metadata.update command in Orchestrator.ts; the dispatch fails with OrchestratorDispatchError when expectations don't match current thread state
  • Replaces per-thread handoff guards with per-physical-workspace serialization (workspaceTransitionsInFlight) in WorktreeMcpService.ts to prevent concurrent mutations to the same checkout
  • Hardens gitWorkflow.createRef in GitVcsDriverCore.ts to validate branch names via git check-ref-format and use git branch -- <name> so option-like names are rejected
  • Risk: transitionIds key format changes (binding/continuation suffixes replace worktree-handoff values), affecting commandId/messageId identifiers emitted during metadata updates and continuations; status handler now treats a non-repo path with an existing workspace inventory as an error rather than benign

Macroscope summarized 0e3839f.

@coderabbitai

coderabbitaiBot commented Aug 29, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: a2fe674c-aa02-4f15-950f-20e9f297b529

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Warning

Your free Security trial is over. An organization admin can activate Security or dismiss this notice.


Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XXL 1,000+ changed lines (additions + deletions). labels Aug 29, 2026
@github-actions

github-actionsBot commented Aug 29, 2026

Copy link
Copy Markdown
Contributor

Thread transfer impact

⚠️ The latest CI run did not produce a thread transfer result for 0e3839f.

This comment will update automatically after the next completed run.

Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
@juliusmarminge
juliusmarminge changed the base branch from t3code/codex-turn-mapping to agents/mcp-workspaces/inventoryAugust 29, 2026 21:55
Comment threaddocs/orchestration-v2/orchestrator-mcp-server.md
Comment threaddocs/user/source-control.md Outdated
@juliusmarminge
juliusmarminge marked this pull request as ready for review August 29, 2026 22:44
Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
@macroscopeapp

macroscopeappBot commented Aug 29, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This PR adds a substantial destructive MCP workflow that can switch branches, create or reuse worktrees, update durable thread bindings, and detach or restart provider sessions. Its cross-component concurrency, rollback, and lifecycle behavior is too broad for automatic approval despite extensive test coverage.

You can add or adjust custom eligibility rules. Learn more.

Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
@juliusmarminge
juliusmarmingeforce-pushed the agents/mcp-workspaces/checkout branch from 03d0e2b to 4453207CompareAugust 30, 2026 17:29
Comment threaddocs/orchestration-v2/orchestrator-mcp-server.md Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
@juliusmarminge
juliusmarmingeforce-pushed the agents/mcp-workspaces/checkout branch from 4453207 to 1d54579CompareAugust 30, 2026 18:10
Comment threaddocs/orchestration-v2/orchestrator-mcp-server.md Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Comment threadapps/server/src/mcp/WorktreeMcpService.ts
@juliusmarminge
juliusmarmingeforce-pushed the agents/mcp-workspaces/checkout branch from 76ccdb2 to 69afd25CompareAugust 30, 2026 18:41
Comment threaddocs/user/source-control.md Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts Outdated
Comment threadapps/server/src/mcp/WorktreeMcpService.ts

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Effect service conventions review of the new WorktreeMcpService.checkout path: service tag, inline interface, make/layer, subpath namespace imports, dependency acquisition (yield* Foo.Foo), and error construction all follow the conventions. One test-organization issue noted inline.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/server/src/mcp/WorktreeMcpService.test.ts Outdated
@juliusmarminge
juliusmarmingeforce-pushed the agents/mcp-workspaces/checkout branch from 1ed8ca4 to d653ad1CompareAugust 30, 2026 20:14
Comment threadapps/server/src/mcp/WorktreeMcpService.ts

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

Bugbot Autofix is ON, but a cloud agent failed to start.

Reviewed by Cursor Bugbot for commit d653ad1. Configure here.

Comment threadapps/server/src/mcp/WorktreeMcpService.ts
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XXL1,000+ changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@juliusmarminge